惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

aimingoo的专栏
aimingoo的专栏
B
Blog RSS Feed
Recent Announcements
Recent Announcements
Vercel News
Vercel News
M
MIT News - Artificial intelligence
阮一峰的网络日志
阮一峰的网络日志
L
LangChain Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Microsoft Security Blog
Microsoft Security Blog
H
Help Net Security
T
The Blog of Author Tim Ferriss
Y
Y Combinator Blog
G
Google Developers Blog
罗磊的独立博客
爱范儿
爱范儿
宝玉的分享
宝玉的分享
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园_首页
S
SegmentFault 最新的问题
WordPress大学
WordPress大学
月光博客
月光博客
人人都是产品经理
人人都是产品经理
Apple Machine Learning Research
Apple Machine Learning Research

Ransomware – ThreatDown by Malwarebytes

Prinz Eugen ransomware: a deep dive into a new Go-based encryptor - ThreatDown by Malwarebytes The anatomy of an Akira ransomware attack AI-orchestrated cyberattacks Tracking remote ransomware attacks at their source Ransomware in April 2025—RansomHub is gone Ransomware in March 2025 Living Off the Land (LOTL) Attacks: Detect Ransomware Gangs - ThreatDown by Malwarebytes One in five Fortune 500 companies had leaked credentials in the past 30 days - ThreatDown by Malwarebytes Ransomware group Mora_001 targets Fortinet applications - ThreatDown by Malwarebytes Ransomware in February 2025—Cl0p and RansomHub run riot - ThreatDown by Malwarebytes Infighting brings down the Black Basta ransomware group
This SonicWall bug is 2 years old. Akira ransomware is st...
L. Travis · 2026-09-09 · via Ransomware – ThreatDown by Malwarebytes

No zero-day required. Just a patch left unapplied.

The Akira ransomware gang is still breaking into networks through a firewall bug SonicWall fixed two years ago. The critical vulnerability, CVE-2024-40766, carries a CVSS score of 9.3 out of 10. SonicWall published a fix in August 2024, but two years on, our MDR team has handled multiple Akira ransomware cases with a SonicWall device in the environment in just the past few weeks. Detections like this are on pace to run roughly 30% ahead of last year’s total by the time 2026 closes out. 

A patch has existed for two years. It hasn’t slowed Akira down.

The gap is every device the patch never reached. Roughly 213,900 SonicWall VPN and management interfaces are reachable from the public internet right now. 

MDR ties the pattern (not each case individually) to CVE-2024-40766, and it isn’t alone in that read: the Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities Catalog in September 2024, and updated its joint Akira ransomware advisory in November 2025 to state that Akira threat actors have likely used it for initial access.

SonicWall hasn’t disclosed much information about the flaw publicly, other than to say that it is an improper access control vulnerability requiring a software fix and, unusually, to advise affected customers to reset passwords for locally managed SSLVPN accounts in addition to patching.

In 2025, SonicWall investigated attacks against patched appliances and found that many involved credentials carried over from older, vulnerable configurations without being reset. The reach isn’t limited to one organization at a time, either. One MSP turned up in our case data twice, hit through two separate customer environments.

Roughly 213,900 SonicWall interfaces are reachable right now

On August 24, 2026, a ThreatDown search found roughly 213,900 SonicWall VPN and management interfaces reachable from the public internet — the exact two components SonicWall’s own advisory ties to this vulnerability. Reachable isn’t the same as vulnerable, but it represents a vast potential attack surface for Akira to explore.

SearchWhat it capturesReachable instances
“Server: SonicWALL SSL-VPN Web Server”VPN portals10,956
“Server: SonicWALL” (excluding SSL-VPN)Management interfaces202,940
CombinedTotal reachable213,896
SonicWall VPN and management interfaces reachable from the public internet, ThreatDown search, August 24, 2026

This doesn’t confirm any single device is unpatched or exploitable, only how much of the surface sits in plain view, including to threat actors.

The Mythos effect

Akira’s routine weaponization of a two-year-old critical vulnerability is just the latest in a long list of examples of ransomware groups exploiting organizations’ inability to apply security patches in a timely manner.

For cybercriminals, the longer the gap between security patches being published and being applied, the better. Unfortunately, for organizations that struggle to stay on top of their patch management, that gap is about to widen significantly because of AI.

In a July 2026 blog post, Windows Executive Vice President Pavan Davuluri wrote that as AI helps defenders find more issues, customers will see a higher volume of security updates in every release. The change is already showing up in the numbers: Microsoft’s May Patch Tuesday fixed 120 vulnerabilities, in June that figured climbed to 200, and in July, that jumped to a record-breaking 570, with Microsoft pointing to AI as the reason.

Call this the “Mythos effect.” The capacity to apply patches doesn’t scale just because the number of patches does. Ten times the fixes doesn’t mean ten times the people available to apply them. And that gap doesn’t stay flat: it compounds. Every release adds to a “patch debt” that teams already submerged in never fully pay down, so the backlog only grows.

A single, two-year-old, publicly documented bug is already sustaining an active ransomware campaign. That’s patch debt playing out in real time. AI-accelerated vulnerability discovery is about to make it far more common.

As the patch queue compounds, another AI-enabled danger is looming. As assessed in our recent report, Cybercrime in the age of AI, the Mythos-class AI that’s fueling the increase in vulnerability discovery is likely to reach criminal marketplaces in a matter of months. When it does, the same acceleration reshaping defenders’ patch queues turns into an offensive automation tool for criminals, capable of discovering and chaining together vulnerabilities.

Patch like the clock is running

The fix for the SonicWall vulnerability has existed for two years. Update to SonicOS 7.3.0 or later, reset local account passwords (especially on devices migrated from Gen 6), enforce MFA across every VPN and admin portal, and restrict management access to trusted networks only. None of it is complicated. What’s hard is doing it consistently, on every device, before Akira finds the one that got missed.

AI is reshaping this fight on both sides at once: faster vulnerability discovery for defenders, and soon, faster exploitation for attackers.

Campaigns like this one live in the gap between the two. ThreatDown Patch Management, delivered through your ThreatDown console, closes that gap at the point most organizations actually lose it: getting the fix onto every device, not just knowing one exists. What gets through anyway is exactly what ThreatDown MDR exists to catch.

Get a demo