Arctic Wolf Observes July 2025 Uptick in Akira Ransomware Activity Targeting SonicWall SSL VPN – Copy
ID: 7f459c76-b38a-51c7-8972-e1a95c38e697
STIX ID: report--7f459c76-b38a-51c7-8972-e1a95c38e697
Feed Name: Arctic Wolf
Arctic Wolf reports an active campaign involving Akira ransomware that has increased targeting of SonicWall SSLVPNs (observed since July 2025 and instances back to October 2024), possibly tied to exploitation of CVE-2024-40766; the bulletin includes numerous IoCs (IP addresses and ASNs), recommends disabling SSLVPN where possible, rotating credentials, applying SonicOS updates (7.3.0), enabling MFA and security services, and deploying log/agent monitoring to detect and mitigate intrusions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
