Ransomware groups continue to evolve, taking advantage of known weaknesses and skipped security steps. In early September, the Cyflare SOC issued an advisory about the Akira ransomware SonicWall vulnerability (CVE-2024-40766). Only a few days later, one of our customers faced an incident that showed both the value of strong SOC coverage and the risks that appear when organizations leave gaps in protection.
This case lines up with recent research. SecurityWeek reports that Akira ransomware attacks exploiting SonicWall CVE-2024-40766 have surged in recent months. Researchers also found that the group often uses everyday IT tools like Datto RMM and backup agents to hide their activity. In some cases, they even bypassed weaker forms of MFA on older SonicOS versions.

What Happened: The Akira Ransomware Incident
The customer had Cyflare’s mXDR and mEDR services in place. However, two critical safeguards were not fully deployed:
- EDR agents were missing on part of the environment
- A shared SonicWall admin account had no MFA
Attackers took advantage of these gaps. They entered through Remote Desktop Protocol (RDP) and VPN, moved inside the network, exfiltrated data, and then launched ransomware.
Cyflare’s SOC and SentinelOne detections responded quickly and stopped malicious activity on systems under management. Even so, attackers compromised endpoints that were not covered. As a result, those unmanaged systems were encrypted, which led to data loss and business disruption.
This shows a clear truth: security services can only work when organizations fully deploy them. Complete coverage and strong authentication are both required to block ransomware.
Lessons from the Frontline and the Field
- Enforce MFA everywhere: Shared accounts and unprotected credentials remain a leading attack vector. Industry reports confirm that some SonicWall devices running older SonicOS versions were even susceptible to brute force attacks against MFA credentials. Strong MFA across all accounts is essential.
- Ensure complete endpoint coverage: Partial EDR deployment creates exploitable blind spots. Adversaries are known to leverage legitimate RMM and backup tools to move laterally, which only behavioral detection and complete coverage can stop.
- Refresh end-of-life operating systems: Unsupported systems leave exploitable gaps. Regular lifecycle management is required to close them.
- Maintain accurate asset and entity management: You can’t defend what you can’t see. A complete inventory allows monitoring to work as designed.
- Patch SonicWall VPNs (CVE-2024-40766): SecurityWeek confirms that the Akira ransomware SonicWall vulnerability remains under active exploitation. Unpatched VPNs remain one of the most reliable entry points for attackers.
Immediate Next Steps for Organizations
- Reset SonicWall credentials and enforce MFA
- Confirm 100% endpoint coverage with EDR agents
- Patch SonicWall VPNs against CVE-2024-40766
- Audit asset inventories and address lifecycle gaps
- Validate incident response readiness
Why This Matters
This incident and outside research on Akira ransomware show two important lessons. First, managed SOC coverage delivers real value because it can stop attacks where protections are in place. Second, even one gap — such as a missing patch, a system without an agent, or an account without MFA — gives attackers the chance they need.
Because ransomware groups move quickly, often within hours, organizations must close every gap. Strong deployment, full coverage, and constant monitoring together create true resilience.
How Cyflare Can Help
Cyflare’s SOC tracks ransomware campaigns like Akira in real time. We identify SonicWall VPN exploit attempts, MFA bypass activity, and the use of standard IT tools for lateral movement. Our managed XDR, managed EDR, and vulnerability scanning services give organizations visibility and quick response to contain threats before they spread.
If you need urgent help or want to validate your defenses against the Akira ransomware SonicWall vulnerability, contact us: [email protected] | 877-729-3527 (Option 2)

