SonicWall firewalls targeted by fresh Akira ransomware surge
ID: c2cdfb42-8658-5705-ad01-35792422ceab
STIX ID: report--c2cdfb42-8658-5705-ad01-35792422ceab
Feed Name: CyberScoop
Threat Score
Researchers and authorities report a rise in Akira ransomware attacks exploiting SonicWall SSL VPN vulnerability CVE-2024-40766 and common device misconfigurations; Rapid7, CISA, and the Australian Cyber Security Centre have observed multiple waves of exploitation where attackers leverage patched-but-misconfigured devices, unchanged passwords after migration, and LDAP overprovisioning to gain initial access and deploy ransomware.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
