Urgent Advisory: SonicWall Customers Must Disable SSL‑VPN Amid Ransomware Surge
Enterprise security provider SonicWall has issued an urgent advisory urging users of its Gen 7 firewall devices to disable SSL‑VPN services immediately, following a sharp rise in Akira ransomware attacks targeting these appliances. What's Happening In the past 72 hours, SonicWall has observed a "notable increase" in security incidents involving Gen 7 devices with SSL‑VPN enabled. While SonicWall investigates whether the root cause is a known issue or a zero‑day vulnerability, third-party researchers strongly suspect the latter. Why This Is Critical The attack vector begins with SSL‑VPN providing initial access, then attackers rapidly escalate to domain controllers, exfiltrate credentials, disable defences, and encrypt systems. The speed and success-especially in MFA-protected environments-indicate a likely zero‑day exploit in firmware versions 7.2.0‑7015 and earlier, particularly affecting TZ and NSa‑series devices with SSL‑VPN enabled. Recommended Immediate Actions Until SonicWall confirms and patches any vulnerability, Critical Path clients should immediately: Disable SSL‑VPN services where feasible. If disabling…
