INC Ransomware Targets SonicWall Flaws
Threat actors are actively chaining two critical SonicWall vulnerabilities to deploy ransomware and escalate privileges to root.
Security researchers have identified a surge in exploitation activity targeting SonicWall SMA1000 secure remote access appliances. The campaign centers on two severe security flaws, now being leveraged by threat actors to gain unauthorized access and compromise corporate networks.
Exploitation of Critical Vulnerabilities
The vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, enable unauthenticated remote attackers to establish WebSocket tunnels to restricted services. By chaining these defects, adversaries can escalate their access to the root level of the targeted appliance. While the vendor issued patches for these issues on July 14, the flaws were exploited as zero-days for several weeks prior to the update.
- CVE-2026-15409 carries a CVSS severity score of 10.
- CVE-2026-15410 holds a CVSS severity score of 7.2.
- Exploitation of these zero-days was observed in the wild beginning at least as early as June 22.
INC Ransomware Activity Surges
According to reports from Resecurity, the INC Ransomware group has emerged as the most prominent actor utilizing these exploits. Following the initial disclosure, the group significantly ramped up its operations, targeting organizations across diverse sectors, including government and private entities in the US, Australia, UAE, Colombia, and Switzerland.
Notably, as of the beginning of August 2026, INC Ransomware has accelerated its activity. Multiple new victims have been published on their Data Leak Site (DLS).
— Resecurity
Tactical Evolution in Extortion
Beyond technical exploitation, researchers have documented a shift in how these threat actors interact with their victims. Following the compromise of internal networks, victims have reported receiving unsolicited phone calls and emails from entities claiming to provide assistance with ransomware recovery. These communications often feature high-pressure tactics, including direct negotiation attempts via specific external email addresses.
Implications for Security Posture
The persistence of threat actors in this campaign suggests that patching remains only the first step in remediation. Because attackers have demonstrated the ability to pivot from the SMA1000 gateway into broader corporate networks, organizations that have not yet performed deep-dive threat hunting may still face residual risk. The use of deceptive recovery services underscores the importance of verifying any external outreach following a security incident, as these interactions are increasingly used as tools for further exploitation rather than genuine resolution.
Sources
- SecurityWeek Original source
Continue Reading
Coldcard Wallet Firmware Flaw Disclosed
A firmware vulnerability in Coinkite devices has been linked to the loss of over 1,300 Bitcoin in recent address sweeps.
Minnesota Nudify App Ban Stays in Effect
A federal judge declined to block a Minnesota law targeting image-manipulation software, citing significant delays in legal filing.
Autonomous AI Weaponization at Scale
Researchers have identified a threat actor using the DeepSeek AI model to automate the lifecycle of cyberattacks on exposed servers.