
- Akira ransomware is exploiting a year-old SonicWall SSLVPN flaw, targeting unpatched Gen5–Gen7 firewalls
- Attackers also abuse default LDAP group settings and public access to the Virtual Office Portal
- Rapid7 warns that Akira combines multiple weaknesses, urging businesses to patch systems
A vulnerability in SonicWall’s SSLVPN instances, discovered and patched more than a year ago, is now being abused by Akira ransomware operators, security researchers are warning.