Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Akira Ransomware Exploits SonicWall VPNs in Likely Zero-Day Attack on Fully-Patched Devices

Akira Ransomware Exploits SonicWall VPNs in Likely Zero-Day Attack on Fully-Patched Devices

Posted on August 2, 2025August 2, 2025 By CWS

Aug 02, 2025Ravie LakshmananVulnerability / Zero Day
SonicWall SSL VPN units have turn out to be the goal of Akira ransomware assaults as a part of a newfound surge in exercise noticed in late July 2025.
“Within the intrusions reviewed, a number of pre-ransomware intrusions had been noticed inside a brief time frame, every involving VPN entry by means of SonicWall SSL VPNs,” Arctic Wolf Labs researcher Julian Tuin mentioned in a report.
The cybersecurity firm steered that the assaults might be exploiting an as-yet-undetermined safety flaw within the home equipment, which means a zero-day flaw, provided that a few of the incidents affected fully-patched SonicWall units. Nevertheless, the potential of credential-based assaults for preliminary entry hasn’t been dominated out.
The uptick in assaults involving SonicWall SSL VPNs was first registered on July 15, 2025, though Arctic Wolf mentioned that it has noticed comparable malicious VPN logins way back to October 2024, suggesting sustained efforts to focus on the units.
“A brief interval was noticed between preliminary SSL VPN account entry and ransomware encryption,” it mentioned. “In distinction with professional VPN logins which generally originate from networks operated by broadband web service suppliers, ransomware teams usually use Digital Personal Server internet hosting for VPN authentication in compromised environments.”

Queries despatched to SonicWall for additional particulars on the exercise didn’t elicit a response till the publishing of this text. As mitigations, organizations are suggested to think about disabling the SonicWall SSL VPN service till a patch is made obtainable and deployed, given the probability of a zero-day vulnerability.
Different greatest practices embody imposing multi-factor authentication (MFA) for distant entry, deleting inactive or unused native firewall person accounts, and following password hygiene.
As of early 2024, Akira ransomware actors are estimated to have extorted roughly $42 million in illicit proceeds after concentrating on greater than 250 victims. It first emerged in March 2023.
Statistics shared by Verify Level present that Akira was the second most lively group within the second quarter of 2025 after Qilin, claiming 143 victims throughout the time interval.
“Akira ransomware maintains a particular give attention to Italy, with 10% of its victims from Italian corporations in comparison with 3% within the basic ecosystem,” the cybersecurity firm mentioned.

The Hacker News Tags:Akira, Attack, Devices, Exploits, FullyPatched, Ransomware, SonicWall, VPNs, ZeroDay

Post navigation

Previous Post: Lazarus Hackers Weaponized 234 Packages Across npm and PyPI to Infect Developers
Next Post: SonicWall Firewall Devices 0-day Vulnerability Actively Exploited by Akira Ransomware

Related Posts

⚡ Weekly Recap — SharePoint Breach, Spyware, IoT Hijacks, DPRK Fraud, Crypto Drains and More ⚡ Weekly Recap — SharePoint Breach, Spyware, IoT Hijacks, DPRK Fraud, Crypto Drains and More The Hacker News
U.S. Arrests Key Facilitator in North Korean IT Worker Scheme, Seizes .74 Million U.S. Arrests Key Facilitator in North Korean IT Worker Scheme, Seizes $7.74 Million The Hacker News
B Crypto Bust, Satellite Spying, Billion-Dollar Smishing, Android RATs & More $15B Crypto Bust, Satellite Spying, Billion-Dollar Smishing, Android RATs & More The Hacker News
The Hidden Risk of Orphan Accounts The Hidden Risk of Orphan Accounts The Hacker News
INTERPOL’s Major Cybercrime Bust: 45,000 IPs Dismantled INTERPOL’s Major Cybercrime Bust: 45,000 IPs Dismantled The Hacker News
North Korean Hackers Launch 1,700 Malicious Packages North Korean Hackers Launch 1,700 Malicious Packages The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • F5 Resolves Over 50 Security Flaws in Software
  • Windows Vulnerabilities: BitLocker Bypass and CTFMON Exploit
  • Seedworm Group Exploits Signed Binaries for Cyber Attacks
  • Vulnerability in PraisonAI Exploited Within Hours
  • Langflow Vulnerability Exploited for AWS Key Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • F5 Resolves Over 50 Security Flaws in Software
  • Windows Vulnerabilities: BitLocker Bypass and CTFMON Exploit
  • Seedworm Group Exploits Signed Binaries for Cyber Attacks
  • Vulnerability in PraisonAI Exploited Within Hours
  • Langflow Vulnerability Exploited for AWS Key Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark