Story perspectives
Surge in Akira Ransomware Targets SonicWall VPNs
9/29/2025
24 5
1 of 1
Story summary
- Arctic Wolf researchers report surge in Akira ransomware targeting SonicWall SSL VPN appliances since July 2025.
- Attackers exploit SonicWall CVE-2024-40766 to harvest credentials and bypass MFA.
- Initial access leads to rapid network compromise, with ransomware deployed within four hours.
- Malicious logins originate from unusual sources, indicating compromised credentials.
- Organizations should reset all SSL VPN credentials and monitor for suspicious activity.
