Akira Ransomware Actors Exploit SonicWall Bug for RCE
ID: d7c8db40-d7a6-557e-9b8f-63d79417ff77
STIX ID: report--d7c8db40-d7a6-557e-9b8f-63d79417ff77
Feed Name: Dark Reading
Threat Score
CISA added CVE-2024-40766 — a critical (CVSS 9.3) improper-access-control RCE in SonicWall SonicOS affecting Gen 5/6 and some Gen 7 devices — to its Known Exploited Vulnerabilities list after Akira ransomware affiliates were observed exploiting the flaw to compromise local SSLVPN accounts, gain full control of devices, and in some cases crash firewalls; SonicWall has issued patches and mitigation guidance and CISA has urged federal agencies to remediate promptly.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
