logo

RaaS meets misconfiguration: How Akira is exploiting SonicWall SSLVPN weaknesses

ID: dac85ec4-56c6-5e64-82d3-6eaf18e0191e

STIX ID: report--dac85ec4-56c6-5e64-82d3-6eaf18e0191e

Feed Name: ThreatLocker Blog

Threat Score
72/100

Date Published: 2025-08-08

Date Updated: 2026-05-01

...
...

SonicWall has linked a late-July surge in Akira ransomware activity to credential-based access and CVE-2024-40766 affecting Gen 7 and newer SSL VPN appliances, particularly where local accounts were migrated without password resets; this is not believed to be a zero-day. The report details affected firmware versions, attacker techniques, detection indicators (e.g., VPN logins from VPS-hosted IPs), and recommends immediate actions (disable or restrict SSLVPN, reset migrated local account passwords, enable MFA, apply firmware updates) plus longer-term hygiene and monitoring controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.