Close Menu
TechUpdateAlert

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    My Health Anxiety Means I Won’t Use Apple’s or Samsung’s Smartwatches. Here’s Why

    December 22, 2025

    You can now buy the OnePlus 15 in the US and score free earbuds if you hurry

    December 22, 2025

    Today’s NYT Connections: Sports Edition Hints, Answers for Dec. 22 #455

    December 22, 2025
    Facebook X (Twitter) Instagram
    Trending
    • My Health Anxiety Means I Won’t Use Apple’s or Samsung’s Smartwatches. Here’s Why
    • You can now buy the OnePlus 15 in the US and score free earbuds if you hurry
    • Today’s NYT Connections: Sports Edition Hints, Answers for Dec. 22 #455
    • Android might finally stop making you tap twice for Wi-Fi
    • Today’s NYT Mini Crossword Answers for Dec. 22
    • Waymo’s robotaxis didn’t know what to do when a city’s traffic lights failed
    • Today’s NYT Wordle Hints, Answer and Help for Dec. 22 #1647
    • You Asked: OLED Sunlight, VHS on 4K TVs, and HDMI Control Issues
    Facebook X (Twitter) Instagram Pinterest Vimeo
    TechUpdateAlertTechUpdateAlert
    • Home
    • Gaming
    • Laptops
    • Mobile
    • Software
    • Reviews
    • AI & Tech
    • Gadgets
    • How-To
    TechUpdateAlert
    Home»How-To»This long-exposed SonicWall flaw is being used to infect organizations with Akira ransomware – so patch now
    How-To

    This long-exposed SonicWall flaw is being used to infect organizations with Akira ransomware – so patch now

    techupdateadminBy techupdateadminSeptember 11, 2025No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Best free Linux firewalls
    Share
    Facebook Twitter LinkedIn Pinterest Email


    • Akira ransomware is exploiting a year-old SonicWall SSLVPN flaw, targeting unpatched Gen5–Gen7 firewalls
    • Attackers also abuse default LDAP group settings and public access to the Virtual Office Portal
    • Rapid7 warns that Akira combines multiple weaknesses, urging businesses to patch systems

    A vulnerability in SonicWall’s SSLVPN instances, discovered and patched more than a year ago, is now being abused by Akira ransomware operators, security researchers are warning.

    The miscreants are going after companies that did not yet apply the patch, or otherwise mitigate the risk.

    In a newly published security advisory, experts from Rapid7 said that an improper access control vulnerability for SSLVPN, affecting Gen5, Gen6, and Gen7 firewall appliances, has seen an uptick in abuse, starting in August 2025.


    You may like

    Combining risks

    Rapid7 also said that Akira is using other means to gain unauthorized access, besides targeting outdated firewall instances. It said that SonicWall posted additional security guidance around the firewall’s Default Users Group Security Risk, a risk which can provision access to the services based on the Default LDAP group configurations (in some instances). This allows users without proper permissions to gain access to the SSLVPN.

    The threat actors are also accessing the Virtual Office Portal hosted by SonicWall appliances, the outfit further stated. This service can be used to initially set up MFA/TOTP configurations for SSLVPN users and, in certain default configurations, allows public access to the portal, which allows miscreants to configure MFA/TOTP with valid, previously exposed, accounts.

    “Evidence collected during Rapid7’s investigations suggests that the Akira group is potentially utilizing a combination of all three of these security risks to gain unauthorized access and conduct ransomware operations,” the researchers warned.

    To mitigate the risk, businesses should rotate passwords on all SonicWall accounts, ensure MFA policies are properly configured, and check if Virtual Office Portal is restricted to LAN/internal access (or trusted network access only). Other mitigations include monitoring access to the Virtual Office Portal and making sure everything’s patched up.

    Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

    Akira has been active for at least two years now, and is known for aggressively targeting edge devices, the researchers concluded.

    You might also like

    Akira Flaw infect longexposed organizations patch ransomware SonicWall
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleThursday Night Football: How to Watch Commanders vs. Packers Tonight
    Next Article What is the max level in Borderlands 4?
    techupdateadmin
    • Website

    Related Posts

    Gaming

    Nightreign’s new patch fixes the most annoying part about prepping for its toughest bosses

    December 3, 2025
    AI & Tech

    Ransomware attack hits LG battery subsidiary

    November 19, 2025
    AI & Tech

    How Kraken ransomware benchmarks your system first, then encrypts everything without warning, and steals data in the background silently

    November 19, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    NYT Strands hints and answers for Monday, August 11 (game #526)

    August 11, 202545 Views

    These 2 Cities Are Pushing Back on Data Centers. Here’s What They’re Worried About

    September 13, 202542 Views

    Today’s NYT Connections: Sports Edition Hints, Answers for Sept. 4 #346

    September 4, 202540 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Best Fitbit fitness trackers and watches in 2025

    July 9, 20250 Views

    There are still 200+ Prime Day 2025 deals you can get

    July 9, 20250 Views

    The best earbuds we’ve tested for 2025

    July 9, 20250 Views
    Our Picks

    My Health Anxiety Means I Won’t Use Apple’s or Samsung’s Smartwatches. Here’s Why

    December 22, 2025

    You can now buy the OnePlus 15 in the US and score free earbuds if you hurry

    December 22, 2025

    Today’s NYT Connections: Sports Edition Hints, Answers for Dec. 22 #455

    December 22, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact us
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    © 2026 techupdatealert. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.