Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Smart ring maker Ora expects sales to reach $2 billion next year

    November 12, 2025

    Is iRobot dying? What to know before buying Roomba Black Friday deals

    November 12, 2025

    Free Webinar Nov 19: Rise Above the Noise: How to Build Your Personal Brand to Grow Your Business

    November 12, 2025
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»Exploitation of Akira Rainmware is important sonicwall sslvpn bug again
    Security

    Exploitation of Akira Rainmware is important sonicwall sslvpn bug again

    PineapplesUpdateBy PineapplesUpdateSeptember 14, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Exploitation of Akira Rainmware is important sonicwall sslvpn bug again
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Exploitation of Akira Rainmware is important sonicwall sslvpn bug again

    Akira ransomware gang is actively exploiting CVE-2024-40766 to achieve unauthorized access to gang sonicwall equipment.

    Hackers are taking advantage of the security problem to achieve access to the target network through SSL VPN & Points without any sonicwall SSL.

    Sonicwall released a patch for CVE-2024–40766 last year in August, in which it was actively exploited. The defect allows unauthorized resource access and can cause firewall accidents.

    At that time, Sonicwall strongly recommended that applying updates should be with a password reset for users with locally managed SSLVPN accounts.

    Without turning the password after the update, actor can use credentials exposed for assured accounts to configure and obtain access to actor multi-factor authentication (MFA) or Time-based One-Time SASSWORD (TOTP) system and obtain access.

    Akira was one of the first ransomware groups starting from September 2024.

    An alert by the Australian Cyber ​​Security Center (ACSC) warns new malicious activity outfits tomorrow, which urges immediate action.

    “ACSC of ASD is aware of the recent increase in active exploitation of 2024 important vulnerability in Sonicwall SSL VPN (CVE -2024-40766),” Advisor reads,

    “We know about Akira Rainmware targeting weak Australian outfits through Sonicwall SSL VPN,” says Australian Cyber ​​Security Center.

    Cyber ​​security firm is rapid 7 Similar observationReporting that the Akira ransomware attacks on Sonicwall devices have recently ignited, possibly tied for incomplete treatment.

    Rapid7 highlighted the methods of infiltration such as exploit the wide access permission of the default user group and to connect and connect to VPN, and the default public access to the virtual office portal on Sonicwall devices.

    It should be noted that this activity has recently created confusion in the cyber security community, with several reporting that ransomware actor Sonicwall is actively exploiting a zero-day vulnerability in Sonicwall products.

    The seller published a new security advisor stating that he is “highly confident that the recent SSLVPN activity is not associated with a zero-day vulnerability” and it was found to be a significant correlation with danger activity related to CVE-2024-40766. “

    Last month, Sonicwall said it was investigating 40 security incidents related to this activity.

    CVE-2024-40766 affects the following firewall versions:

    • General 5: Soho device running version 5.9.2.14-12o and more than that
    • General 6: Various TZ, NSA, and SM models running versions 6.5.4.14-109n and older
    • General 7: TZ and NSA Model Sonicos Build Edition 7.0.1-5035 and older

    System administrators are recommended to follow the patching and mitigation advice provided by the seller Respective bulletin,

    Admins should rotate the firmware version of 7.3.0 or later, the sonicwall account password should apply the multi-factor authentication (MFA), reduce the risk of SSLVPN default groups, and the virtual office portal access will have to limit to the worldable/internal networks.


    Picus Blue Report 2025

    The passwords broke in 46% of the atmosphere, almost doubled by 25% last year.

    Picus Blue Report 2025 Now get a wider look at more conclusions on prevention, detection and data exfIs.

    Akira Bug exploitation important Rainmware Sonicwall sslvpn
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleI compared iPhone 17, iPhone Air, 17 Pro, and 17 Pro Max: Who is here
    Next Article New VMSCAPE attack broke the guest-host separation on AMD, Intel CPUS
    PineapplesUpdate
    • Website

    Related Posts

    Startups

    Windows 11 users affected by bizarre Task Manager duplication bug – here’s how to avoid it

    October 31, 2025
    Startups

    Updated to Android 16? You should enable these 2 important security features ASAP – here’s why

    October 19, 2025
    Security

    Your Uber driver has a new endeavor: training an AI for cash

    October 18, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    10,000 steps or Japanese walk? We ask experts if you should walk ahead or fast

    June 16, 20250 Views

    FIFA Club World Cup Soccer: Stream Palmirus vs. Porto lives from anywhere

    June 16, 20250 Views

    What do chatbott is careful about punctuation? I tested it with chat, Gemini and Cloud

    June 16, 20250 Views
    Our Picks

    Smart ring maker Ora expects sales to reach $2 billion next year

    November 12, 2025

    Is iRobot dying? What to know before buying Roomba Black Friday deals

    November 12, 2025

    Free Webinar Nov 19: Rise Above the Noise: How to Build Your Personal Brand to Grow Your Business

    November 12, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2025 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.