SonicWall VPN accounts breached by Akira ransomware -and even those using MFA are at risk




  • Akira ransomware exploits CVE-2024-40766 to access SonicWall VPNs despite patches and MFA
  • Researchers suspect OTP seeds were stolen, enabling bypass of one-time password protections
  • Google links attacks to UNC6148 targeting patched, end-of-life SonicWall SMA 100 appliances

Akira ransomware operators are still finding ways to infiltrate SonicWall SSL VPN devices, despite known vulnerabilities being patched, and victims having multi-factor authentication (MFA) enabled on all accounts.

Multiple security researchers have confirmed the attacks taking place – but they have different (but somewhat similar) theories on what is actually happening.

https://cdn.mos.cms.futurecdn.net/vMUveYxRmvL3pWvV4ptQyL-1920-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img