SonicWall Firewalls Under Siege: Ransomware Attackers Exploit Critical Flaw!

Ransomware affiliates are having a field day exploiting a critical SonicWall SonicOS vulnerability, CVE-2024-40766. This flaw affects multiple firewall generations and is now being used in attacks. SonicWall urges immediate patching, while Arctic Wolf and Rapid7 echo the warning. Federal agencies have until September 30…

Hot Take:

Looks like SonicWall’s new slogan should be “Patch or Prepare to Panic” as CVE-2024-40766 turns their firewalls into Swiss cheese for ransomware affiliates!

Key Points:

  • Security flaw CVE-2024-40766 affects SonicWall Gen 5, 6, and 7 firewalls.
  • Patch released on August 22, but the flaw also impacts the SSLVPN feature.
  • Akira ransomware affiliates linked to recent attacks exploiting this vulnerability.
  • CISA mandates federal agencies to patch vulnerable devices by September 30.
  • SonicWall advises restricting access, enabling MFA, and patching immediately.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here