A SANS Internet Storm Center audit of 14 SonicWall firewalls patched for CVE-2024-40766 (CVSS 9.8) found that Akira and Fog ransomware operators had compromised several of them post-patch. The core finding: firmware patching alone is not remediation. Attackers pre-created accounts, harvested credentials, and enrolled their own TOTP devices before patches were applied. Key gaps found across audited devices include stale SSLVPN accounts (12/14), no credential rotation post-patch (11/14), overly permissive LDAP group mappings giving all AD users VPN access (9/14), and publicly reachable TOTP enrollment portals (7/14). Gen 6 hardware is now end-of-life with no further firmware fixes. The recommended checklist covers account auditing, credential rotation, LDAP reconfiguration, portal access restriction, upgrading to SonicOS 7.3.0+, and external log forwarding to a SIEM.