Arctic Wolf Observes Akira Ransomware Campaign Targeting SonicWall SSLVPN Accounts
ID: 7770cb1a-6d5f-517e-b1e2-775fc6d60212
STIX ID: report--7770cb1a-6d5f-517e-b1e2-775fc6d60212
Feed Name: Arctic Wolf
A remote code execution vulnerability (CVE-2024-40766) in SonicOS was disclosed and later advisory updates indicated potential active exploitation; Arctic Wolf observed Akira ransomware affiliates gaining initial access by compromising locally-managed SSLVPN accounts on vulnerable SonicWall devices (with MFA disabled). The report lists affected device families and fixed firmware versions and strongly recommends immediate SonicOS updates, resetting local SSLVPN passwords, enabling MFA, and restricting WAN/SSLVPN access as mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
