Ransomware Group Targets SonicWall Gen 7 Firewalls via CVE-2024-40766
ID: 63417138-1292-50d9-a1a0-96eb3e7e41f1
STIX ID: report--63417138-1292-50d9-a1a0-96eb3e7e41f1
Feed Name: ThreatCluster
Threat Score
In June 2026 threat actors have actively exploited SonicWall Gen 7 firewalls using CVE-2024-40766 to gain unauthorized access—frequently during Gen 6→Gen 7 migrations where local passwords were not reset—and have deployed Akira ransomware after entering networks via SSL VPNs; security vendors advise resetting local user passwords and updating firmware to mitigate rapid, often domain-controller-directed lateral movement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
