
- Akira ransomware exploits CVE-2024-40766 to access SonicWall VPNs despite patches and MFA
- Researchers suspect OTP seeds were stolen, enabling bypass of one-time password protections
- Google links attacks to UNC6148 targeting patched, end-of-life SonicWall SMA 100 appliances
Akira ransomware operators are still finding ways to infiltrate SonicWall SSL VPN devices, despite known vulnerabilities being patched, and victims having multi-factor authentication (MFA) enabled on all accounts.