Cyber CrimeDeveloping Story

INC Ransomware Targets SonicWall Flaws

Threat actors are actively chaining two critical SonicWall vulnerabilities to deploy ransomware and escalate privileges to root.

··1 hour ago·2 min read
Close-up of server cooling fans in a vibrant data center.
Photo by Winston Chen on Unsplash

Security researchers have identified a surge in exploitation activity targeting SonicWall SMA1000 secure remote access appliances. The campaign centers on two severe security flaws, now being leveraged by threat actors to gain unauthorized access and compromise corporate networks.

Exploitation of Critical Vulnerabilities

The vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, enable unauthenticated remote attackers to establish WebSocket tunnels to restricted services. By chaining these defects, adversaries can escalate their access to the root level of the targeted appliance. While the vendor issued patches for these issues on July 14, the flaws were exploited as zero-days for several weeks prior to the update.

  • CVE-2026-15409 carries a CVSS severity score of 10.
  • CVE-2026-15410 holds a CVSS severity score of 7.2.
  • Exploitation of these zero-days was observed in the wild beginning at least as early as June 22.

INC Ransomware Activity Surges

According to reports from Resecurity, the INC Ransomware group has emerged as the most prominent actor utilizing these exploits. Following the initial disclosure, the group significantly ramped up its operations, targeting organizations across diverse sectors, including government and private entities in the US, Australia, UAE, Colombia, and Switzerland.

Notably, as of the beginning of August 2026, INC Ransomware has accelerated its activity. Multiple new victims have been published on their Data Leak Site (DLS).

— Resecurity

Tactical Evolution in Extortion

Beyond technical exploitation, researchers have documented a shift in how these threat actors interact with their victims. Following the compromise of internal networks, victims have reported receiving unsolicited phone calls and emails from entities claiming to provide assistance with ransomware recovery. These communications often feature high-pressure tactics, including direct negotiation attempts via specific external email addresses.

Implications for Security Posture

The persistence of threat actors in this campaign suggests that patching remains only the first step in remediation. Because attackers have demonstrated the ability to pivot from the SMA1000 gateway into broader corporate networks, organizations that have not yet performed deep-dive threat hunting may still face residual risk. The use of deceptive recovery services underscores the importance of verifying any external outreach following a security incident, as these interactions are increasingly used as tools for further exploitation rather than genuine resolution.

#ransomware#sonicwall#vulnerabilities#cybersecurity

Sources

Xploitwire Editorial Team

Xploitwire Newsroom

This article's narrative text was drafted by AI (Google Gemini) from the sources listed above, and passed through our automated fact-check gate before publication. It has not been individually reviewed by a human editor prior to going live. Our AI Policy →

← Back to all stories