Drooid Logo
Back to today’s briefing

Story perspectives

Surge in Akira Ransomware Targets SonicWall VPNs

9/29/2025

24 5

1 of 1

Story summary
  • Arctic Wolf researchers report surge in Akira ransomware targeting SonicWall SSL VPN appliances since July 2025.
  • Attackers exploit SonicWall CVE-2024-40766 to harvest credentials and bypass MFA.
  • Initial access leads to rapid network compromise, with ransomware deployed within four hours.
  • Malicious logins originate from unusual sources, indicating compromised credentials.
  • Organizations should reset all SSL VPN credentials and monitor for suspicious activity.