logo

Akira ransomware crims abusing trifecta of SonicWall security holes for extortion attacks

ID: f4e71c46-ca61-5f02-83b7-b7d6dc7e1a50

STIX ID: report--f4e71c46-ca61-5f02-83b7-b7d6dc7e1a50

Feed Name: The Register (Security)

Threat Score
80/100

Date Published: 2025-09-10

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Affiliates of the Akira ransomware group are actively exploiting the critical SonicWall CVE-2024-40766 and SSLVPN misconfigurations to gain initial access and deploy ransomware; the flaw (CVSS 9.8) was previously disclosed but remains widely exploitable, with security firms reporting confirmed compromises and hundreds of thousands of SonicWall devices publicly accessible. Rapid7, ThreatLocker, Arctic Wolf and others advise applying patches, enabling MFA, and restricting access to SonicWall Virtual Office to prevent further incidents.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.