INC Ransomware exploits SonicWall flaws in new attacks

 

INC Ransomware exploits SonicWall flaws in new attacks

The INC Ransomware group has been observed exploiting two recently disclosed SonicWall vulnerabilities, using the flaws to gain access, steal data, and encrypt files for extortion.

The vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, affect SonicWall’s Secure Mobile Access (SMA) 1000 series appliances. SonicWall released security patches on July 14, 2026, after researchers observed active exploitation beginning on June 22, 2026.

Security researchers said INC Ransomware was not the first group to abuse the flaws, but it has been the most aggressive in combining both vulnerabilities into a full attack chain. The group used the weaknesses to gain high-level access to affected systems before carrying out ransomware operations.

The INC Ransomware RaaS operation has claimed nearly 900 victims across 71 countries since it was first spotted three years ago. Researchers have not yet confirmed how many organizations were affected by the latest SonicWall attacks.

The initial exploitation was linked to a threat actor tracked as UTA0533, which used the vulnerabilities to gain root-level access to targeted SonicWall devices. Further analysis by security firms found similarities between the attacks and activity later linked to INC ransomware.

Organizations that use affected SMA devices are strongly advised to apply the available patches and review the systems for signs of compromise.


Back to the list