INC Ransomware Targets SonicWall Flaws
Threat actors are actively chaining two critical SonicWall vulnerabilities to deploy ransomware and escalate privileges to root.
Security researchers have identified a surge in exploitation activity targeting SonicWall SMA1000 secure remote access appliances. The campaign centers on two severe security flaws, now being leveraged by threat actors to gain unauthorized access and compromise corporate networks.
Exploitation of Critical Vulnerabilities
The vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, enable unauthenticated remote attackers to establish WebSocket tunnels to restricted services. By chaining these defects, adversaries can escalate their access to the root level of the targeted appliance. While the vendor issued patches for these issues on July 14, the flaws were exploited as zero-days for several weeks prior to the update.
- CVE-2026-15409 carries a CVSS severity score of 10.
- CVE-2026-15410 holds a CVSS severity score of 7.2.
- Exploitation of these zero-days was observed in the wild beginning at least as early as June 22.
INC Ransomware Activity Surges
According to reports from Resecurity, the INC Ransomware group has emerged as the most prominent actor utilizing these exploits. Following the initial disclosure, the group significantly ramped up its operations, targeting organizations across diverse sectors, including government and private entities in the US, Australia, UAE, Colombia, and Switzerland.
Notably, as of the beginning of August 2026, INC Ransomware has accelerated its activity. Multiple new victims have been published on their Data Leak Site (DLS).
— Resecurity
Tactical Evolution in Extortion
Beyond technical exploitation, researchers have documented a shift in how these threat actors interact with their victims. Following the compromise of internal networks, victims have reported receiving unsolicited phone calls and emails from entities claiming to provide assistance with ransomware recovery. These communications often feature high-pressure tactics, including direct negotiation attempts via specific external email addresses.
Implications for Security Posture
The persistence of threat actors in this campaign suggests that patching remains only the first step in remediation. Because attackers have demonstrated the ability to pivot from the SMA1000 gateway into broader corporate networks, organizations that have not yet performed deep-dive threat hunting may still face residual risk. The use of deceptive recovery services underscores the importance of verifying any external outreach following a security incident, as these interactions are increasingly used as tools for further exploitation rather than genuine resolution.
Sources
- SecurityWeek Original source
Continue Reading
APT36 Uses GitHub Repos as Stealth C2
Zscaler ThreatLabz says Transparent Tribe is running four new tools against Indian and Afghan government targets, hiding command traffic inside private GitHub repositories.
WaterPlum's Fake Interviews Hit 30,000 Devices
A joint advisory says North Korean recruiters posed as hiring managers, using bogus coding tests to breach 30,000 devices and 7,000 crypto wallets.
Fake Cop Scams Cost Victims $1.6B
FBI's IC3 logged nearly 61,000 impersonation complaints from January 2025 to July 2026, with average losses exceeding $26,000.