SonicWall firewall devices hit in surge of Akira ransomware attacks
ID: 72cc03e2-2751-5a71-8761-6173ebbfa209
STIX ID: report--72cc03e2-2751-5a71-8761-6173ebbfa209
Feed Name: Bleeping Computer
**SonicWall devices targeted in Akira ransomware surge:** Arctic Wolf reports multiple intrusions beginning mid-July that abused SonicWall SSL VPN access to deploy Akira ransomware (and related OVERSTEP activity against SMA 100 appliances), potentially leveraging a zero-day while credential-based attacks remain possible; Arctic Wolf and SonicWall published IOCs, mitigation advice (disable SSL VPN, enhance logging/monitoring, block hosting-provider auth), and SonicWall alerted to CVE-2025-40599 affecting SMA 100 appliances.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
