RaaS meets misconfiguration: How Akira is exploiting SonicWall SSLVPN weaknesses
ID: dac85ec4-56c6-5e64-82d3-6eaf18e0191e
STIX ID: report--dac85ec4-56c6-5e64-82d3-6eaf18e0191e
Feed Name: ThreatLocker Blog
SonicWall has linked a late-July surge in Akira ransomware activity to credential-based access and CVE-2024-40766 affecting Gen 7 and newer SSL VPN appliances, particularly where local accounts were migrated without password resets; this is not believed to be a zero-day. The report details affected firmware versions, attacker techniques, detection indicators (e.g., VPN logins from VPS-hosted IPs), and recommends immediate actions (disable or restrict SSLVPN, reset migrated local account passwords, enable MFA, apply firmware updates) plus longer-term hygiene and monitoring controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
