SonicWall Faces Multiple Security Breaches and Urges Customer Action

TL;DR Summary
Akira ransomware attacks on SonicWall VPNs continue despite MFA, exploiting stolen OTP seeds and a known access control flaw (CVE-2024-40766). Threat actors use stolen credentials and advanced techniques like BYOVD to bypass security, emphasizing the need for immediate credential resets and firmware updates to mitigate ongoing risks.
- Akira ransomware breaching MFA-protected SonicWall VPN accounts BleepingComputer
- SonicWall customers told to reset passwords after cloud backup service breach SC Media
- Hackers get their hands on SonicWall firewall backups: users urged to reset credentials Cybernews
- SonicWall customers warned about brute force attacks against cloud backup service Cybersecurity Dive
Reading Insights
Total Reads
0
Unique Readers
11
Time Saved
3 min
vs 4 min read
Condensed
93%
645 → 47 words
Want the full story? Read the original article
Read on BleepingComputer