threat-intel CVE-2024-40766: The Patch Fixed the Bug. Nobody Fixed the Configuration., (Tue, Jun 23rd) This report details a significant ongoing cyber threat targeting SonicWall firewalls exploiting CVE-2024-40766, a critical access control vulnerability. Ransomware groups, notably Akira and Fog, have been actively leveraging this flaw since September 2024, primarily targeting businesses using SSLVPN for remote access.… SANS Internet Storm Center · Jun 23, 2026 Critical CVE-2024-40766CVE-2024-12802USGBvpncredential theftransomware
threat-intel Hackers bypass SonicWall VPN MFA due to incomplete patching Hackers exploited a vulnerability (CVE-2024-12802) in SonicWall Gen6 SSL-VPN appliances to bypass multi-factor authentication and deploy ransomware tools. The attackers gained access to networks within 30-60 minutes, lev… BleepingComputer · May 20, 2026 High CVE-2024-12802USvpnmfacredential theft