Arctic Wolf Observes Akira Ransomware Campaign Targeting SonicWall SSLVPN Accounts
ID: c5341177-1b9d-591f-a372-616560dd153f
STIX ID: report--c5341177-1b9d-591f-a372-616560dd153f
Feed Name: Arctic Wolf Blog
Arctic Wolf reports CVE-2024-40766, an RCE in SonicOS affecting multiple SonicWall firewall generations; the advisory was later updated indicating potential active exploitation. Arctic Wolf observed Akira ransomware affiliates gaining initial access by compromising locally-managed SSLVPN accounts (with MFA disabled) on vulnerable devices and strongly recommends updating SonicOS to fixed versions, resetting local SSLVPN passwords, enabling MFA, and restricting WAN/SSLVPN management.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
