SonicWall has confirmed there is no zero-day vulnerability currently being exploited in its products, despite reports of targeted ransomware attacks. The attacks are linked to previously disclosed vulnerabilities, specifically CVE-2024-40766, often exploited through inadequate password management during device migration. #CVE202440766 #AkiraRansomware
Keypoints
- SonicWall investigated reports of zero-day exploits but found no evidence of such vulnerabilities affecting its products.
- The recent ransomware attacks are associated with known vulnerabilities, primarily CVE-2024-40766.
- Threat actors exploited compromised device credentials, especially due to weak password practices during firmware migrations.
- Users are advised to reset passwords and ensure their devices are fully patched to prevent unauthorized access.
- Multiple threat actors, including UNC6148, have targeted SonicWall devices with different malware, like Overstep.
Read More: https://www.securityweek.com/sonicwall-says-recent-attacks-dont-involve-zero-day-vulnerability/