CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

The Dangers of Storing Unencrypted Passwords

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 819

As cited

Copy frozen at (site build).

ransomware

The Dangers of Storing Unencrypted Passwords

Threat actors exploited a SonicWall VPN vulnerability to gain initial access, deployed Akira ransomware, and uninstalled Huntress Managed Endpoint Detection and Response (EDR) agents after discovering plaintext recovery codes stored on the compromised systems. The incident demonstrates the risk posed by inadequate credential protection and the importance of secure credential management practices.

Why it matters: Organizations using SonicWall VPN and relying on EDR protection need to audit for unencrypted passwords and recovery codes, patch the VPN vulnerability, and implement defense-in-depth measures to prevent Akira ransomware deployment and agent evasion.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

The Dangers of Storing Unencrypted Passwords

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

The Dangers of Storing Unencrypted Passwords

Threat actors exploited a SonicWall virtual private network (VPN) vulnerability to deploy Akira ransomware and uninstall Huntress endpoint detection and response (EDR) agents after discovering plaintext recovery codes in the environment. The incident demonstrates the operational risk of storing credentials without encryption. Organizations should implement encryption for sensitive credentials and harden VPN security controls.

Why it matters: Any organization using SonicWall VPN or storing unencrypted recovery codes faces immediate risk of ransomware deployment and EDR bypass; practitioners should audit credential storage and patch VPN infrastructure today.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

The Dangers of Storing Unencrypted Passwords

Threat actors exploited a SonicWall virtual private network (VPN) vulnerability to deploy Akira ransomware and uninstall Huntress endpoint detection and response (EDR) agents after discovering plaintext recovery codes in the environment. The incident demonstrates the operational risk of storing credentials without encryption. Organizations should implement encryption for sensitive credentials and harden VPN security controls.

Why it matters: Any organization using SonicWall VPN or storing unencrypted recovery codes faces immediate risk of ransomware deployment and EDR bypass; practitioners should audit credential storage and patch VPN infrastructure today.

VendorsSonicWall
Actorsakira
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary