Find notable cyber news and cases, enriched with sources, timelines, and signals.
Campaign Exploitation Wave Vulnerability

Akira exploitation of SonicWall SSL VPN flaw CVE-2024-40766

Updated 04.12.2025 00:06
Case score 68
Case score 68 Members 4 Latest activity 04.12.2025 00:06
Active exploitation Patch available CVSS: 9.3 Critical
Members 4 First seen 11.09.2025 13:33 Last seen 28.09.2025 21:49 Updated 04.12.2025 00:06

Overview

**CVE-2024-40766** exploitation against **SonicWall SSL VPN** endpoints has become an Akira-linked intrusion and ransomware story, with attackers using malicious logins on exposed devices and, in some cases, abusing or bypassing OTP MFA. Activity observed from **October 4, 2025** spread across more than **100 accounts** in **16 environments** and in some intrusions quickly moved to scanning and Windows account access attempts. **Marquis Software Solutions** later disclosed a ransomware intrusion through a SonicWall firewall that exposed data tied to **74 banks and credit unions** and affected more than **400,000 customers**. SonicWall customers have been urged to patch, rotate credentials, remove unused accounts, and tighten portal and lockout controls.

Signals

8 derived
Impact signals
Exploitation
Exploitation Active exploitation CVSS 9.3 Critical
CVEs/products
CVE
Remediation
Remediation Patch available
Status
Campaign status Active
Threat context
Tooling Ransomware Akira
Affected surface
Affected organizations 74

Malware context

9 families · 9 tools
Tools
Impacket AnyDesk Datto LogMeIn Megazord Ngrok AdaptixC2 Quick Assist +1

Member happenings

4 related
Campaign Akira ransomware group SonicWall initial-access campaign
Updated 11.09.2025 13:33 Lead Contribution 62
Objective Financial Extortion Campaign Active

The **Akira ransomware group** is associated with a continuing **SonicWall SSL VPN** initial-access campaign that uses **CVE-2024-40766** and related credential abuse to breach victim networks. A newer victim-impact update shows **Marquis Software Solutions** was hit by a **ransomware attack on August 14, 2025** through a **SonicWall firewall**, exposing files with personal information for customers of **74 banks and credit unions** and affecting **over 400,000 customers**. Marquis says there is **no evidence** the data has been misused or published, while the breach details reinforce the campaign’s focus on **SonicWall VPN** access and post-compromise theft.

Campaign Akira SonicWall SSL VPN MFA-bypass campaign
Updated 28.09.2025 21:49 Scoring Support Contribution 2
Objective Financial Extortion Campaign Active Patch Patch Available

**Akira-affiliated** actors are causing **widespread compromise** of **SonicWall SSL VPN devices**, with Huntress reporting activity that began on **October 4, 2025** and impacted **more than 100 accounts** across **16 customer environments**. The observed logins appear to use **valid credentials** rather than brute force, and some intrusions included **network scanning** and attempts to access **local Windows accounts**. Huntress said authentications on the compromised devices came from **202.155.8[.]73**. The disclosure follows SonicWall's report of unauthorized exposure of **firewall configuration backup files** in **MySonicWall** accounts, but Huntress said there is **no evidence** linking that exposure to the recent spike in compromises.

Exploitation Wave SonicWall SSL VPN exploitation wave (Akira-linked)
Updated 11.09.2025 13:33 Scoring Support Contribution 2
Exploitation Active Exploitation CVSS 9.3 Critical Patch Patch Available

An **Akira ransomware**-linked **exploitation wave** is driving a **widespread compromise** of **SonicWall SSL VPN devices** for initial access, with attacks using **CVE-2024-40766** and, in some cases, rapidly moving from login activity to **network scanning** and attempts to access **Windows accounts**. Huntress said the latest activity began on **October 4, 2025** and impacted **more than 100 accounts** across **16 customer environments**, with authentications in its cases originating from **202.155.8[.]73**. SonicWall also disclosed unauthorized exposure of **firewall configuration backup files** in **MySonicWall** accounts, but Huntress said there is **no evidence yet** linking that incident to the spike in compromises.

Vulnerability SonicWall SSL VPN access control flaw actively exploited (CVE-2024-40766)
Updated 11.09.2025 19:32 Scoring Support
Exploitation Active Exploitation Exploit No Known Public Exploit Data Type Passwords CVSS 9.3 Critical +1

**CVE-2024-40766** is a **SonicWall SSL VPN** access control flaw that has been **actively exploited** to breach exposed devices, with **Akira ransomware** tied to the campaign. Recent reporting says attackers used **malicious SSL VPN logins** and, in some cases, were able to bypass or abuse **OTP MFA**, then move to **port scanning**, **Impacket SMB activity**, and rapid ransomware deployment. The campaign has been observed across multiple victims and has remained active since **mid-2024**, with new infrastructure and incidents continuing into **2025**.