SonicWall Firewalls Targeted: Zero-Day Suspected in Akira Ransomware Wave
Автор: Security Daily Review
Загружено: 2025-08-05
Просмотров: 105
Описание:
A dangerous wave of ransomware attacks is exploiting a likely zero-day vulnerability in SonicWall Gen 7 firewalls with SSL VPN enabled.
⚠️ Key Findings
Attacks bypassed MFA and strong credential hygiene
Targeted devices: SonicWall firmware 7.2.0-7015 and earlier
Immediate privilege escalation via over-privileged accounts
Persistence achieved with tunnels, SSH, and remote tools
Akira ransomware deployed after disabling defenses and deleting backups
🔍 Attack Chain
Unauthorized VPN access without brute force or phishing
Credential dumping and lateral movement with WMI/PowerShell
Targeting Domain Controllers via wbadmin.exe
Exfiltration using tools like FileZilla and Advanced_IP_Scanner
Final ransomware stage after wiping shadow copies
🔒 Mitigation Steps
Disable or strictly restrict SSL VPN access
Audit firewall and VPN logs for unusual successful logins
Remove unnecessary administrative rights from service accounts
Monitor SonicWall advisories for emergency fixes
Investigations are ongoing, but evidence strongly suggests a device-side exploit. Organizations using SonicWall SSL VPN appliances should act immediately to reduce exposure.
#SonicWall #ZeroDay #AkiraRansomware #CyberSecurity #Ransomware #SSLVPN
FIND US AT
https://dailysecurityreview.com/
FOLLOW US ON SOCIAL
Get updates or reach out to Get updates on our Social Media Profiles!
Twitter: / securitydailyr
Facebook: https://www.facebook.com/profile.php?...
LinkedIn: / security-daily-review
Повторяем попытку...
Доступные форматы для скачивания:
Скачать видео
-
Информация по загрузке: