Old Vulnerabilities Keep Fueling Ransomware Attacks
Ransomware Vulnerability Management Still Has Gaps
Ransomware vulnerability management remains a major challenge as attackers continue to exploit known weaknesses that organizations have had time to fix. In this Techstrong TV interview, Mike Vizard talks with Shawn Dorsey, Senior Director of Global Managed Services at ThreatDown, about why groups such as Akira keep finding success through familiar tactics.
Dorsey explains that many incidents still involve exposed or unpatched devices, including SonicWall appliances used for initial access. The problem is not always neglect. Small and midsized businesses often have limited staff, limited budget and too many operational demands competing for attention.
Patch Management Is Harder for Smaller Teams
Large enterprises usually have formal security programs, automated processes and teams that track common vulnerabilities. Smaller organizations often do not. A single IT generalist may be responsible for everything from user support to infrastructure, cloud systems, networking and endpoint protection.
That creates a dangerous opening for ransomware operators. Ransomware vulnerability management requires visibility into assets, patch status, remote access systems and exposed services. Without that visibility, teams may not know which systems create the most risk until an attacker has already found them.
AI Could Accelerate Both Attackers and Defenders
The conversation also looks at how AI may change the speed and scale of cyberattacks. Dorsey warns that attackers can use AI to discover opportunities faster, automate parts of the attack chain and increase the number of campaigns they can run at once.
Defenders can also benefit from AI. It can help resource-constrained teams prioritize patching, check configurations and respond more quickly to alerts. The key is to use AI as a force multiplier while keeping strong security practices in place.
Regulation and Insurance May Raise the Baseline
Dorsey expects more pressure from regulators, insurers and business partners. Organizations that handle customer data may face stronger expectations for minimum cybersecurity practices. Vendors may also be asked to prove they can protect data before they are trusted by customers.
For technology leaders, the takeaway is practical. Ransomware vulnerability management cannot wait for a crisis. Teams need better asset visibility, faster patching, managed detection and response where needed, and a plan for using AI to keep pace with machine-scale threats.
Transcript
Hey guys, thanks for the Threat. We're here with Sean Darcy, who's the senior director for Managed Services at ThreatDown, and we're having a little chat about, well, what's going on with all these vulnerabilities that are so old and yet continue to be exploited and well, things don't seem to be getting a whole lot better. Sean, welcome to the show.
Hey, thank you. Thank you. Good to be here.
Walk us through, if you would, some of the examples that we're seeing out there. The secure thing is a constant problem, but I'm sure it's not the only one. And are we stuck in some sort of infinite loop here?
I don't know about infinite loop, but certainly it does feel that way at times. So Akira is a very, very prolific malware group, one of the best-known ransomware operators out there right now and has been for a few years. Honestly, they haven't had to change their playbook up a whole heck of a lot because a lot of their TTPs, their tactics, techniques, procedures that they use, they're still effective.
They're still effective even after word has gotten out that, hey, this is how they're doing it. These are the things you need to do to patch up. These are the things you need to do to prevent yourself from being hit by Akira.
And obviously, our research here lays it out pretty clearly, but our research, not just our research, but also our experience with the MDR team, specifically, we've dealt with a number of Akira cases post-incident and pre-incident. Often we're able to catch them before they're able to execute the ransomware. But one thing that is almost invariable with the cases that we see is there was a SonicWall device somewhere in the mix that was compromised because it was unpatched or one of a couple of other reasons why Akira, the operators were able to get through using that for initial access, and getting into the network and then doing the usual things they do to maintain persistence, elevate privileges, so on and so forth, prior to going ahead and executing ransomware in the network.
This isn't the first time that something wasn't patched, and SonicWall is probably one of many. So why don't we patch these things? We know the patch is out there.
Is it just plain old oversight, or are we too lazy, or are we afraid it's going to break something? What prevents us from doing the right thing? I think a lot of times, yeah.
I wouldn't say it's laziness. I would say that often it is overlooked, especially when you're talking about devices. Usually, when you're talking about, say, a large enterprise, large enterprises generally aren't going to be caught off guard by this sort of thing.
At this stage in the game in 2026, they usually have very robust programs, very robust IT and information security departments that are keeping on top of the most common vulnerabilities, and have it very programmatized and often automated to a great extent. On the other hand, when you're talking about small to medium business, when you're talking about mid-market to some extent, but especially small to medium business, you're usually talking about folks who have a setup. They may outsource their IT to a small one-man shop.
They may, if they're lucky, especially on the smaller end of the scale, they may have one full-time IT employee, but often they don't. And if they do, that person is usually overwhelmed with the sheer volume of stuff that they have to deal with day to day. It's not that security is an afterthought.
It's just that they will do a number of things to stay secure, but things that maybe aren't in their face immediately day to day, or maybe that they just don't have awareness of because they're not security experts, they're IT people, which is not quite the same thing. There's a lot of overlap. It's not the same thing, obviously.
I think that they'll have these old devices, especially, again, small to medium business. You're not going to lay out a bunch of money to get the latest and greatest hardware every year or two. You're going to work on what you got until it don't work no more, basically.
Drive it until the wheels fall off. Mm-hmm. And I think that that is very much what you're seeing here is that there are these older devices.
SonicWall makes good, reliable devices that are affordable. A lot of small to medium businesses have SonicWall devices as a result. And interestingly, to your point earlier, this is a bug that was found that has been patched for two years.
They knew about the vulnerability. They patched the vulnerability. They released the patches.
But in a lot of cases, in the cases where Akira is successful using the exploit to get in, they are either unpatched and they haven't upgraded and patched to the latest and greatest that they really need to ensure that this can't be exploited. Or in some of the cases, even if they apply a patch, they may not have updated certain things, and certain things such as old compromised accounts may still be in there. They may have some default, God forbid, default admin passwords and accounts, which is an absolute no-no in any enterprise.
But sometimes, again, depending on the level of sophistication and the level of expertise that the IT people have that are putting this together, it gets missed. It gets missed and Akira's operating at scale, and they aren't just going after big fish. They're going after anybody they can see out there that has an internet-facing device that matches the criteria they're looking for, and they methodically go and just hit them in a row and are very successful at doing so.
Is this always going to be the case? Because I think the IT people, and if there is a couple of security people involved, and certainly the MSPs are telling the business owners that they should upgrade, but for whatever reason, they opt, to use your language, to drive it till the wheels fall off. Yeah.
And we're surprised with the outcome? So at the end of the day, do we just don't understand what their cost of doing business is these days? Yeah, that's a great question.
I don't know what the answer is, honestly, when I look at this. How do we encourage folks to do this? One of the things I found throughout my career is that if you go back 20 years, 20-plus years, for many, security was an afterthought.
Cybersecurity was something that happened to other companies. That was something that happened to governments and big enterprises and people who had things people wanted to steal. And then even when ransomware came around, before ransomware became the monster that it is today, back when it was first out there, ransomware tended to be either heavily targeted towards, again, those very high-value targets, or alternately, you would have a tax of opportunity, and it was very often you would see somebody's grandmother would get hit with it, clicking the wrong thing and have their personal photos held ransom and had pay $100 or something.
That's obviously evolved massively since then. And unfortunately, it's been my experience that when a company or an individual, but usually companies, when they don't take the threat as seriously as it merits, they get religion after either they get hit or someone that they know gets hit and they see the repercussions. They see the downtime.
They see the financial cost. They see the reputational hits. It is absolutely devastating, especially if you are in any kind of business where you deal with very confidential or sensitive data, if you deal with medical data, say, if you deal with financial data.
Heck, if you deal with finances in any way, you need to take cybersecurity super seriously, because it can be an existential threat to your business. It can completely wipe you out between the reputational hit, the fines, and then the actual cost of dealing with it. So it comes down to that simple kind of calculus of, is this worth the outlay of money now to fix this problem, or am I just going to go ahead and roll the dice and see if I can just- hide in the background.
Well, what you're describing is the herd mentality where you're hoping that the lions and tigers catch somebody else besides you. But sometimes inevitably, that's going to wind up being you, and I happen to wonder, in the age of AI, is it more likely going to happen to me? Because I feel like finding these vulnerabilities and the exploits for creating them is now becoming something that can be done in an instant.
Yeah. Well, I'll tell you, Mikey, you read my mind. That's exactly where my head's at on that.
We are finding that vulnerabilities are being generated in the age of frontier model AI. We are finding that vulnerabilities are being found, and the zero-days effectively are being generated at a massively increased rate, like a 10x plus rate. I just read something literally 20 minutes before we got on this call together.
I just read something talking about Microsoft Patch Tuesday has yet another record number of vulnerabilities it's addressing in its security patch. That is going to continue. There's going to be more vulnerabilities, and here's where it gets really scary.
Not only are there way more vulnerabilities that you have to make sure you're patched, make sure you're up on, make sure you're aware of, and that you are taking some kind of mitigating measure. But now you have to worry about the attackers because it's not just defenders that are using AI to help to plug the holes and find the holes in the first place. The bad guys also have these AI models, and they're also using them at scale.
And I think that to your point, where it used to be, you would have the lions at the edge of the herd taking out one or two of the weaker ones from the edge. I think now we're getting to a point where the lions have now multiplied by 100 and have rocket packs. They can go after everybody all at once.
I think that security through obscurity is going to go the way of the dodo in the coming months and years. I think that the only way to be truly safe is honestly to take the precautions you need to take to make sure your stuff is patched, to make sure that you are hewing to very solid security practices. Because I think that the attacks are getting faster, they're getting better, they're getting cheaper, and I think you're going to see them proliferate at scale over the coming months.
As you think that through for a minute, is this going to be something that we all wake up to all together at once? " That's a great question. I think that it's not going to be gradual over the course of years.
I think it might be gradual over the course of weeks and months, but I think that we are going to see a significant increase in successful ransomware and other cybersecurity threats. I think we're going to see not only more success as a result of capability to launch far more attacks concurrently, but I think that you're also going to see attacks succeed more because of the sheer number of zero-day threats, the sheer number of new unpatched threats that are going to be leveraged by these attackers. And I think that it's going to be something you can't ignore in coming months.
I think that everybody is going to become very aware of it. And I think it's a matter of months. I think it's a matter of maybe six months, maybe a little longer, maybe a little less.
But I don't think we have a lot of time before we start to see the actual effects scale up pretty heavily in the wild. Will regulation be a forcing function here? Because it's not much different in my mind than the city comes around and inspects your restaurant to make sure that you're not having unsafe practices as you run your business.
And so will there be a similar thing for cybersecurity? " Yeah, I think so. I think that it is very likely that you'll see increased regulation around any kind of customer data.
I think that you'll see, especially in the United States, it's very much a patchwork. Some states are much more hardcore about it than others. For instance, New York, California have very strong laws dealing with data privacy and so forth.
Whereas other states, it's very much a lot less. But you already see it in certain verticals, right? You see it in healthcare.
You see it in-- Healthcare and finance always immediately come to mind because of the sensitivity of the data they store. You also see it with people who hold government contracts. There are a ton of regulations around who can get a contract if you're dealing with government data and what you must do as part of that.
So I think that you are definitely going to see an increase in awareness, and it's going to change that calculus. That calculus we talked about with the wheels, driving till the wheels fall off. That calculus certainly changes when you are facing the kind of fines and penalties that'll just put you out of business if you get hit.
And I think that that is definitely one way to change behavior out there in the various industries that handle any kind of data. Do you think the insurance folks may come around and force this as well? " And so a lot of small businesses, I think, thought it was cheaper to buy the insurance earlier on than it was to upgrade the IT environment.
But has that come full circle? Yes. I think absolutely.
I think if you're a cyber insurer, and my understanding, now, I'm not a cyber insurance expert by any means, but my understanding and things I've read and seen and heard over the last few years is that cyber insurance it's actually getting more difficult to insure because of the likelihood of somebody getting hit. Insurance obviously works on the idea that you're playing the odds, essentially, and making sure that your actuary tables allow you to set a price where you, as a business, make money with the amount that you're paying out. If we are finding that more businesses are vulnerable, that more customers, insurance customers, are likely to get hit, I think a lot of cyber insurers already have some pretty good restrictions on the policy and things that they make their insureds do to ensure good cybersecurity or at least halfway decent cybersecurity.
I think they are going to tighten it up. I think they're absolutely going to tighten it up. And I think that that is for the best.
I think it's a good thing. " We want to make sure that you're doing things properly and staying out of the field of fire here. And I agree.
Is it going to raise the overall cost of being able to afford insurance? Of course. Yeah.
But it's also going to force, I think, a lot of folks to clean house. Or again, as a business decision, to just accept the risk of the results of a significant breach or a ransomware incident. " But at some point, are we getting to the point where maybe we do need to blame the victim a bit because, well, it's just wrinkles?
Yeah. That is a tough thing to strike a right balance on. It really is.
It truly is. Because ultimately, anybody who gets hit with a ransomware attack, they are, by definition, a victim of crime. They absolutely did nothing to incur it, generally speaking.
I think it's a rare person who invites an attacker to come in. But it's almost always, even when people have made good faith efforts, they are victims here. m.
You technically have a legal right to do that, but it's probably not a good idea. Just common sense dictates that may not end well for you. Well, kind of the same thing here.
To your point, though, and to your question, how much responsibility does the person who gets hit, or the organization, I should say, the business that get hit, how much of it is their fault? How much responsibility do they bear? And that's a difficult question to get right.
I think that we already know that answer when, and again, I keep coming back to it, but when we talk about people who handle very sensitive data, when we talk about your healthcare providers and your banks and your credit unions and so forth, they have a duty to take care of that data and to ensure that that data is protected. And I think that what we're going to find, especially as data regulations, I think they're likely to get more restrictive. I think they're likely to get more punitive whenever there is a breach, and you didn't meet some standard of care.
And I think that that's what we're going to see change. I think that cyber insurance can be a very large part of driving that change, and what cyber insurance doesn't take care of, I think legislation will take care of over time. Also, I think vendors themselves, or not vendors, I think larger organizations that purchase a vendor's services, a lot of them nowadays, it used to be you would get a handful of them.
Now you get them pretty frequently, and I think that this is a more frequent thing. They have vendor surveys. " So I think those are the things that are going to drive that behavior.
I think it's going to be a combination of legislation, of insurance companies demanding these things from their insureds, as well as companies that do business with other companies demanding a certain base level of cybersecurity. On the plus side, will it become easier to meet those standards because we have AI, and maybe I can use these tools to keep things up to date, more secure, and maybe even the AI will tell me that running this thing is a bad idea? Yeah.
Yes. AI, it's very much a double-edged sword when it comes to cybersecurity. When it comes to many things.
But when it comes to cybersecurity particularly, it's very much a double-edged sword. Yeah, the attackers can use it to great effect to do some very, very nasty things. The time frames speed up dramatically, and the scale of what can be done by a particular, like a single threat actor, is much wider than it used to be.
The flip side, though, is that the expertise that the bad guys can leverage via AI, and the efficiencies they can leverage via AI, can be leveraged by the good guys, too, and it can be leveraged by individuals and by businesses. It can be leveraged by that lone IT guy to be able to help him keep up with the flood of patching that needs to be done, to help him make sure that all of the things he's trying to implement are correctly implemented. And I think it's going to enable folks like us in the cybersecurity industry, vendors like us, to be able to operate very rapidly at scale at a very affordable price as well, as far as for companies that need help and need outsource that help.
But yes, I think it can absolutely be leveraged. But it's coming fast. If you haven't started getting familiar with AI, how to use it, how to implement it in your workflows, you really want to consider doing it sooner rather than later so you can stay ahead of the tsunami that's coming.
All right, folks. Well, you heard it here. The world is changing for better or worse.
We got to get on board and get in front of this thing because the only thing that's worse than possibly getting hit or just waiting for something to happen is the simple fact that you're doing nothing. Hey, Sean, thanks for being on the show. Hey, thanks for having me, Mike.
All right. And back to you guys in the studio.