SonicWall Faces Multiple Security Breaches and Urges Customer Action

TL;DR
Akira ransomware attacks on SonicWall VPNs continue despite MFA, exploiting stolen OTP seeds and a known access control flaw (CVE-2024-40766). Threat actors use stolen credentials and advanced techniques like BYOVD to bypass security, emphasizing the need for immediate credential resets and firmware updates to mitigate ongoing risks.
Topics:businesscybersecurity#akira-ransomware#cve-2024-40766#cybersecurity#mfa-bypass#otp-seeds#sonicwall-vpn
- Akira ransomware breaching MFA-protected SonicWall VPN accounts BleepingComputer
- SonicWall customers told to reset passwords after cloud backup service breach SC Media
- Hackers get their hands on SonicWall firewall backups: users urged to reset credentials Cybernews
- SonicWall customers warned about brute force attacks against cloud backup service Cybersecurity Dive
Want the full story? Read the original reporting
Read on BleepingComputer