Find notable cyber news and cases, enriched with sources, timelines, and signals.
Campaign Exploitation Wave Vulnerability

Akira exploitation of SonicWall SSL VPN flaw CVE-2024-40766

Updated 04.12.2025 00:06
Case score 68
Case score 68 Members 4 Latest activity 04.12.2025 00:06 Active exploitation Patch available CVSS: 9.3 Critical
Active exploitation Patch available CVSS: 9.3 Critical
Members 4 First seen 11.09.2025 13:33 Last seen 28.09.2025 21:49 Updated 04.12.2025 00:06

Overview

**CVE-2024-40766** exploitation against **SonicWall SSL VPN** endpoints has become an Akira-linked intrusion and ransomware story, with attackers using malicious logins on exposed devices and, in some cases, abusing or bypassing OTP MFA. Activity observed from **October 4, 2025** spread across more than **100 accounts** in **16 environments** and in some intrusions quickly moved to scanning and Windows account access attempts. **Marquis Software Solutions** later disclosed a ransomware intrusion through a SonicWall firewall that exposed data tied to **74 banks and credit unions** and affected more than **400,000 customers**. SonicWall customers have been urged to patch, rotate credentials, remove unused accounts, and tighten portal and lockout controls.