ArticWolf say they have observed Akira ransomware incidents gaining access via fully patched SonicWall SSL VPN boxes with accounts with MFA enabled, speculate they have another zero day.
arcticwolf.com/resources/blog/…
Arctic Wolf Observes July 2025 Uptick in Akira Ransomware Activity Targeting SonicWall SSL VPN I Arctic Wolf
In late July 2025, Arctic Wolf observed an increase in ransomware activity targeting SonicWall firewall devices for initial access.Julian Tuin (Arctic Wolf Networks)
Bitslingers-R-Us
in reply to Kevin Beaumont • • •Kevin Beaumont
in reply to Kevin Beaumont • • •Huntress also believe a zero day is likely being exploited by Akira ransomware group in SonicWall firewalls. huntress.com/blog/exploitation…
To add my own analysis, I track Akira ransomware victims not just by their portal but via uploaded payloads - there’s been a significant uptick, and those victims largely use SonicWall. I think orgs probably want to urgently transition away from SonicWall SSL VPN to a different product (I know this is easier said than done).
Huntress Threat Advisory: Active Exploitation of SonicWall VPNs
undefined undefined (huntress.com)Kevin Beaumont
in reply to Kevin Beaumont • • •There continues to be an evolution where ransomware groups have better technical exploitation capability than nation states, because victims are giving them R&D budgets of hundreds of millions of dollars.
It’s also super depressing as governments worldwide continue to put their heads in the sand rather than tackle the problem head on, and the security industry love it as it keeps their line going up as the industry is based on failure as a business model.
Graham Sutherland / Polynomial
in reply to Kevin Beaumont • • •Oriel Jutty
in reply to Kevin Beaumont • • •System Adminihater
in reply to Kevin Beaumont • • •JA
in reply to Kevin Beaumont • • •Marius (windsheep)
in reply to Kevin Beaumont • • •job security. In the time of AI.
It's luxury.
Kevin Beaumont
in reply to Kevin Beaumont • • •System Adminihater
in reply to Kevin Beaumont • • •Chris
in reply to Kevin Beaumont • • •StarkZarn
in reply to Kevin Beaumont • • •MemoryLeech
in reply to Kevin Beaumont • • •VessOnSecurity
in reply to Kevin Beaumont • • •Nemo
in reply to Kevin Beaumont • • •