Isc.Sans.Edu CVE-2024-40766 Exploited by Ransomware Groups Targeting SonicWall Firewalls
Article Content
- •CVE-2024-40766 affects SonicWall firewalls, allowing unauthorized access and potential crashes.
- •Over 48,000 devices remain unpatched, making them prime targets for ransomware groups.
- •The MySonicWall breach has compromised configuration backups, increasing vulnerability.
CVE-2024-40766 is an improper access control vulnerability in SonicWall SonicOS affecting Gen 5, Gen 6, and Gen 7 firewalls. The vulnerability, with a CVSS score of 9.3, allows unauthorized access and can crash the device. SonicWall serves approximately 500,000 businesses, many of which lack dedicated security teams. Ransomware groups Akira and Fog have exploited this vulnerability since September 2024, with significant compromises reported. By December 2024, nearly 49,000 devices were still publicly exposed and unpatched. Dwell times for attacks have been alarmingly short, with encryption occurring in under four hours in many cases. SonicWall's MySonicWall platform was also breached, exposing configuration backups and encrypted credentials. The exploitation has escalated in 2026, with ongoing attacks reported.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Akira, Sonicwall and CVE-2024-12802 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Chinese Smishing Gang Targets Ireland and Four Other EU Countries Ireland is identified as one of five EU countries targeted by the Chinese text-scam group known as Smishing Triad, as reported by the EU cyber security agency Enisa. This group conducts large-scale smishing operations, which involve sending fraudulent text messages that impersonate legitimate organizations to steal…
Network Segmentation Failures Heighten Cyberattack Risks in 2026 Forescout's analysis of 47,700 network segments across 209 organizations reveals significant network segmentation failures, particularly involving IT, OT, IoT, and IoMT devices. The study found that 62% of segments contained only one device category, while 29% had two and 9% had three or more. Notably, only 13% of…