惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

N
News and Events Feed by Topic
爱范儿
爱范儿
Apple Machine Learning Research
Apple Machine Learning Research
博客园 - 叶小钗
Last Week in AI
Last Week in AI
博客园 - 三生石上(FineUI控件)
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
月光博客
月光博客
大猫的无限游戏
大猫的无限游戏
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
博客园 - Franky
人人都是产品经理
人人都是产品经理
The Cloudflare Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 司徒正美
罗磊的独立博客
博客园 - 聂微东
T
Troy Hunt's Blog
美团技术团队
IT之家
IT之家
A
Arctic Wolf
腾讯CDC
雷峰网
雷峰网
SecWiki News
SecWiki News
博客园_首页
L
LINUX DO - 最新话题
Cloudbric
Cloudbric
量子位
N
News and Events Feed by Topic
小众软件
小众软件
C
CXSECURITY Database RSS Feed - CXSecurity.com
Cyberwarzone
Cyberwarzone
J
Java Code Geeks
V
V2EX
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
Latest news
Latest news
Webroot Blog
Webroot Blog
F
Fortinet All Blogs
P
Privacy International News Feed
NISL@THU
NISL@THU
Google Online Security Blog
Google Online Security Blog
WordPress大学
WordPress大学
PCI Perspectives
PCI Perspectives
GbyAI
GbyAI
宝玉的分享
宝玉的分享
阮一峰的网络日志
阮一峰的网络日志
S
Secure Thoughts
Simon Willison's Weblog
Simon Willison's Weblog
P
Palo Alto Networks Blog
V
Visual Studio Blog

Todyl Blog

CyberChef: How to Decode & Decrypt Malicious Scripts (Step-by-Step Guide) Achieving Zero Trust with SASE: A Practical Roadmap for Modern Network Securityso like MSP Security Maturity Assessment: Why 79% of MSPs Are Stuck in 2025 The Rising Threat of Malicious AI: What Every Organization Needs to Know Iran Cyber Threat 2026: What SMBs and MSPs Need to Know The OneStart AI Browser Deception Cyber Insurance Requirements Based on Industry Why Third-Party Security Certification Is Your MSP's Competitive Edge Why Cyber Insurance Carriers Are Shifting to Security Assurance Iran Conflict and Cyber Risk: What North American Organizations Need to Know ‍ Why Cyber Resilience Requires Security, Compliance, and Insurance MSP Security Services: How to Position Identity Protection as Competitive Advantage Identity Security Gap Assessment: A Step-by-Step Guide for MSPs How Credential Theft Attacks Are Costing MSP Clients Millions Do I Need Cyber Insurance as a Small Business? Advanced Persistent Threats (APTs) Explained Preparing for CMMC Level 1: What Your Organization Needs to Do The Real Cost of Doing Nothing in Cybersecurity MSP Security: Build vs Buy SOC The Rise of a Cybercrime Alliance: What LockBit, Qilin, and DragonForce Mean for Business Risk Cyber Threat Recovery Strategies for MSPs What MSPs Need to Know about CIRCIA Final Rule ClickFix: The Evolution of Copy-Paste Social Engineering Akira Ransomware: Threat Assessment of a Scalable RaaS Operation The Dos and Don’ts of Applying for a Cyber Insurance Policy What Is Threat Hunting? A Practical Guide for MSPs and SMBs The Business Case for Cyber Threat Management Evaluating Free and Open Source SIEM Tools in 2026 How organizations can combat BEC Using SASE to help meet cyber insurance requirements Introducing the Anomaly Framework Stopping Identity Threats with ITDR through MXDR Security Operations Over Tools Beyond Tools: A Strategic Approach to Data Security Cyber Threat Response Strategies for MSPs Threat Advisory: Email Account Compromise BECs In the Wild: When Millions of People Are Expecting the Same Email Michigan and Wisconsin Proposed Age Verification Bills and the Impact on VPNs and SASE: What You Need to Know Cyber Threat Detection Strategies for MSPs Cyber Threat Prevention Strategies for MSPs Simplifying CMMC Level 1 with Todyl GRC How to Complete Your CMMC Level 1 Self-Assessment: A Step-by-Step Walkthrough Cyber Threats Don't Take Time Off How MSPs Build Lasting Client Relationships Through Proactive Operations Risk Management for MSPs: Why Business Context Changes Everything 5 Pillars for Security Program Growth in 2025 One Action MSPs can take to Address Risk and Secure Clients Building Resilience in a Perimeter-less World with Defense-in-Depth Aligning Technology Implementation to Business Outcomes Top 5 Myths about Cybersecurity How Conditional Access Transforms Your Cybersecurity Program Why MSPs need to embrace a prescriptive model How Texas SB 2610 Positions MSPs as Strategic Risk Advisors Simplifying cybersecurity maturity with managed cloud SIEM Addressing firewall vulnerabilities Understanding the Pitfalls of RDP MSP Zero-Day Response Plan: When Security Tools Can't Help You Old is Gold: Tackling Persistent Vulnerabilities How MXDR drives operational efficiencies Using SASE for secure remote access How to find the best endpoint security solution The Cyber Insurance Crisis: Why MSPs and Their Clients Are Struggling What to ask of a prospective endpoint security vendor Thinking Red, Acting Blue: Turning Attack Tactics in Your Favor Zero-Day Attacks and False Alarms: Lessons for MSPs Dissecting the Recent Rise in 2025 Zero Days MSP Security Monitoring Strategy: Identity and Cloud Blind Spots Introducing the Todyl Community: A Collaborative Platform for MSPs Threat Advisory: PDFast Freeware Compromise Navigating Today’s Cybersecurity Threat Landscape: Where MSPs Should Start Partner Spotlight: GoTech IT Solutions Threat Advisory: SQL Injection in FortiClient CVE-2023-48788 The Importance of SSL Inspection Navigating Compliance Frameworks: Common Challenges and Effective Solutions Making the most of SASE Web Filtering Iran & Middle-East Geopolitical Shifts: Emerging Cyber Risks for SMBs MSP Security KPIs That Matter: Beyond Vanity Metrics to Business Outcomes MSP Challenges Looking into 2025 Combining EDR and NGAV for Defense-in-Depth Starting Your Security Framework Journey: A Practical Implementation Guide Cyber Insurance vs. Warranties: Key Risk Management Elements Akira Ransomware: A Persistent Threat to MSP Operations Transforming Cyber Insurance for MSPs and Their Clients Two Truths, Double Whammy: Why Vulnerability Remediation Needs a Rethink Using LAN ZeroTrust for segmentation The role of SIEM in incident response Partner Spotlight: 917 Solutions Threat Advisory: Business Email Compromise Campaign using OVPN for Obfuscation Beyond Implementation: Creating an Ongoing Security Framework Program ClickFix: Fake Captcha Leads to Real Damage Streamlining Security and Compliance Information Gathering with Assessments EpiBrowser: A Sophisticated PUP Masquerading as Chromium Partner Spotlight: AnchorSix Tips to Help MSPs Set Goals for the New Year How SIEM helps detect insider threats Massive Wave of Network Security Vulnerabilities Demands Immediate Action FortiJump: The FortiManager Zero-Day Vulnerability Explained Use cases of SASE: Software-defined perimeter Threat Advisory: LightPerlGirl Malware Why MSPs Must Prioritize CIS Critical Security Controls v8.1 for Client Success
Threat Advisory: Understanding the Recent SonicWall SSL VPN Vulnerability and How to Protect Your Clients
Andrew Scott · 2026-01-09 · via Todyl Blog

Update, September 18: MySonicWall Breach Update - Immediate Action Required

SonicWall confirmed on September 17, 2025 that attackers accessed firewall configuration backup files in MySonicWall accounts, exposing credentials and network details that could accelerate the ransomware attacks we’ve been tracking.

Check your MySonicWall.com account immediately, any affected serial numbers will show notification banners. If flagged, follow SonicWall’s credential reset guidance across all 7 categories they’ve outlined, starting with core authentication systems.

This breach amplifies the risks from the Akira and Sinobi campaigns discussed below. Even if unaffected, use this as your catalyst to implement comprehensive security hardening.

We’re monitoring the situation and will update as needed.

Update, September 15:

Over the past few months, the Akira and Sinobi ransomware groups have carried out sophisticated attack campaigns targeting SonicWall SSL VPNs and other firewall VPNs at significant scale. This continued wave of attacks and their specific attack techniques demonstrate why a layered security approach across prevention, detection, and response is essential.

The Threat

Akira and Sinobi ransomware groups are key players in the evolution of cybercrime as attackers adapt to defender capabilities, now focusing on data theft and extortion (DTE) attacks. These attacks differ from traditional ransomware attacks in that adversaries focus on accessing victim environments to identify sensitive and potentially damaging information for victims, if leaked. Notably, they then extract and steal this information before deploying ransomware as a mechanism to extort and pressure victims to pay.

This continued shift towards DTE demands that cyber defenders adapt their own defenses to focus on restricting access and movement within environments, increase observability across system, cloud, identity, and network ecosystems, and work to prevent data exfiltration in addition to system disruption experienced by system encryption via ransomware.

To support this adaptation, we unpack how specific Todyl Platform capabilities can protect against each stage of these observed attacks and the evolving attack techniques of Akira and Sinobi:

Prevention: Reducing Your Attack Surface

SASE Static IPs and Conditional Access

Lock down firewall administrative interfaces using Todyl SASE's static IP egress capabilities. By restricting admin access to only come from known Todyl SASE exit points, you eliminate the ability for external threat actors to brute force credentials or to use stolen credentials from arbitrary internet locations. Combine this with conditional access policies that verify device identity, user authentication, and geographic location before allowing administrative connections. Todyl also strongly encourages leveraging  MFA with O365 identity integrations to further strengthen security postures.

Secure Cloud and SaaS Application Access

Lock down IaaS and PaaS environments such as AWS, Microsoft Entra, and Google Cloud to only authorized systems and IP ranges, using Todyl SASE and Static IPs. This additional protection secures access to sensitive data that may be held within those ecosystems. Additionally, enumerate and secure access to key business applications, such as O365, CRMs, Gsuite, Github, SAP, etc using Todyl SASE’s Static IP to further secure these applications from unauthorized access.

Zero Trust Network Access (ZTNA)

Replace traditional VPN connections with identity-based access control. Even if credentials are compromised, ZTNA ensures attackers can only access specifically authorized resources based on user identity and device posture—not broad network segments.

Application Blocklisting via EDR

Define unauthorized or unused applications such as unauthorized remote management tools, file sharing solutions, and other legitimate applications that could be used to exfiltrate data or enable backdoor access to environments. Akira and Sinobi both leverage legitimate RMM, file sharing, and other solutions to maintain persistence and support data exfiltration. Preventing installation and use of these also reduces risk across ecosystems.

Least Privilege of Shared Accounts

A common tactic is for the threat actor to leverage compromised credentials in LDAP to enumerate other devices within a network, helping them identify where to spread laterally. Ensure that you follow password best practices by not reusing the same passwords across your admin accounts, as well as considering the use of specific administrator and service accounts unique to privileged rights and access for certain applications and functions. Leverage Todyl’s SASE NGFW rules to apply Role Based Access Control across key administrators, service accounts, and user groups. These rules can also include restrictions to only use allowed ports, protocols, and services, limiting lateral movement and environment enumeration or pivoting throughout a potentially compromised environment,

Apply Network Segmentation: Leverage LAN Zero Trust to microsegment the network, thereby limiting potential for lateral movement or malware propagation. By restricting network connectivity between devices and network segments, crown jewel systems holding sensitive information can be proactively isolated and protected from access, further securing any desireable or sensitive information that may live on them.

Detection: Rapid Threat and Risk Identification

Integrated SIEM Analytics and Correlation

Todyl SIEM's detection rules automatically correlate authentication logs with endpoint and network activity. Additionally, SIEM ensures full observability across environments to include network, cloud, identity, and other key integration points to identify potential compromise of data or systems not managed or covered by the firewall VPN. This helps identify successful credential compromises faster, detecting patterns like:

  • Multiple failed authentication attempts followed by successful login
  • Administrative access from unusual geographic locations or devices
  • Rapid enumeration of network resources post-authentication
  • Shifts in technology environment indicative of threat actors installing their own tools

Behavioral Analytics Across the Kill Chain

ML-driven detection identifies the rapid reconnaissance and lateral movement patterns characteristic of these ransomware groups. The platform correlates activities across endpoints, network traffic, and cloud applications to detect attack progression even when individual actions appear benign.

Response: Automated Containment

SOAR Automated Response Playbooks

Deploy pre-configured playbooks that automatically execute containment actions when specific threat indicators are detected:

  • Immediately disable compromised user accounts
  • Isolate affected endpoints from network resources
  • Block suspicious file transfers or data exfiltration attempts
  • Escalate critical incidents to the MXDR team

LAN Zero Trust Lateral Movement Prevention

LAN Zero Trust operates as a software-defined firewall on each device, denying all inter-device communications by default unless explicitly permitted by policy. When properly configured, this architecture fundamentally prevents the lateral movement that ransomware groups depend on. Even if attackers compromise one endpoint through credentials, they cannot automatically spread to other systems—each connection attempt is evaluated against specific allow rules rather than relying on traditional network trust assumptions.

24x7 MXDR Expert Response

Todyl MXDR provides immediate expert analysis and response guidance. When indicators of compromise or attack are detected, dedicated analysts investigate the full scope of compromise and provide specific remediation steps—critical given the speed at which these ransomware groups operate.

Integrated Platform Advantage

The key differentiator is how these capabilities work together through a single agent and management interface. When a compromise occurs, the integrated platform can:

  1. Prevent attacks by reducing attack surface area with SASE’s identity integration
  2. Immediately contain the threat through automated SOAR responses
  3. Prevent lateral movement using LAN Zero Trust microsegmentation
  4. Control data access through SASE conditional access policies that verify user and device identity before allowing access to sensitive resources
  5. Provide full visibility into attack progression across all security telemetry, including anomaly detections to identify shifts in ITops software
  6. Enable rapid response with expert MXDR guidance and pre-built remediation playbooks

This integrated approach transforms what would typically be a successful ransomware deployment into a contained security incident with minimal business impact.

SonicWall SSL Vulnerability

Over the past few days, the cybersecurity community has been buzzing about a SonicWall vulnerability that ransomware groups, including Akira, have been actively exploiting. While initial reports suggested a zero-day threat affecting even fully patched systems, the situation has been clarified—but the risk remains very real.

What We Know Now

The threat centers around CVE-2024-40766, a known vulnerability that affects SonicWall Gen 6 to Gen 7 firewall migrations. The vulnerability occurs specifically when local user passwords were carried over during migration and not reset, potentially leading to unauthorized resource access and system crashes.

According to SonicWall's official guidance, this isn't the zero-day many initially feared, but it's still being actively exploited by threat actors who use it to establish initial access to victim environments.

Why This Matters for MSPs

The Akira ransomware group and others are opportunistic, focusing on financial gain rather than targeting specific organizations. This puts SMBs and mid-market companies—and the MSPs who serve them—at heightened risk, especially given the common use of SonicWall network security solutions in these markets.

Akira employs double extortion techniques, stealing sensitive data before deploying ransomware. This creates additional pressure on victims to pay—not just to unlock encrypted data, but to prevent the leak of confidential information.

The Broader Security Challenge

This incident highlights a critical blind spot: organizations that focus primarily on endpoint and backup-centric defenses often miss intrusion attempts, unauthorized system access, and data exfiltration happening at the network level.

When threat actors gain initial access through vulnerabilities like this one, they move quickly. The window between initial compromise and ransomware deployment is often measured in hours, not days.

How Todyl Helps Mitigate These Risks

Our platform is designed to address exactly these types of multi-vector attacks:

Immediate Detection and Response

  • Our MXDR team continuously monitors and hunts for threat actor activity specifically related to SonicWall vulnerabilities
  • Our teams are working around the clock to keep you and your clients safe
  • Detection Engineering and MXDR teams are prepared to update rules within the Todyl Platform as needed

Network-Level Protection

  • Todyl SASE can serve as an alternative VPN solution while SonicWall vulnerabilities are addressed
  • Conditional access policies restrict access to only protected devices
  • Network segmentation through LAN Zero Trust prevents lateral movement and ransomware spread

Comprehensive Visibility

  • SIEM integration provides unified visibility across all security tools and data sources
  • EDR/NGAV in prevent mode stops malicious activity before it can cause damage
  • Application blocklist policies prevent unauthorized remote access tools commonly used in attacks

Todyl's Mitigation Recommendations

Our Field CISO and Security teams recommend the following steps to mitigate the risks of initial access, data exfiltration, and ransomware deployment:

  1. Apply any recommended SonicWall remediation steps
  2. Enable MFA for locally managed SSL VPN accounts - this appears to be the primary initial vector for CVE-2024-40766
  3. Consider temporarily disabling SonicWall VPN services and enabling Todyl SASE as an always-on VPN until full root cause analysis and patching is complete
  4. Apply conditional access policies using Todyl SASE NGFW to restrict access to only Todyl protected devices
  5. Enforce MFA by policy for all users via Todyl SASE, especially for access to sensitive or mission critical systems
  6. Restrict internal access via Todyl SASE to sensitive systems using least privilege principles
  7. Ensure EDR/NGAV policies are in Prevent mode and apply application blocklist policies for unapproved remote management tools
  8. Apply network segmentation through LAN Zero Trust to prevent lateral movement and ransomware spread
  9. Ensure Todyl SIEM ingests all available integration data, especially from systems that monitor or hold sensitive information
  10. Hunt for indicators of compromise or leverage Todyl MXDR for continuous monitoring and investigation
  11. Review incident response plans and ensure backups and disaster recovery plans are current and maintained

The Bottom Line

While this SonicWall vulnerability has been clarified and isn't the zero-day initially feared, it demonstrates why layered security and continuous monitoring are essential. Threat actors are constantly looking for ways to establish initial access, and they move fast once they're in.

The organizations that weather these storms best are those with comprehensive security platforms, proactive monitoring, and rapid response capabilities in place before an incident occurs.

Need Help?

If you have questions about this threat or want to discuss how Todyl can help protect your clients from these types of attacks, reach out to your Channel Account Manager. Our team is here to help you navigate these challenges and keep your clients secure.