INC Ransomware has become the most active group exploiting two SonicWall SMA1000 vulnerabilities, CVE-2026-15409 and CVE-2026-15410, which were used as zero-days before being patched and added to CISA’s KEV catalog. Resecurity says the group is using the flaws to compromise organizations worldwide and applying pressure tactics through emails and phone calls to push ransom negotiations. #INC_Ransomware #CVE-2026-15409 #CVE-2026-15410 #SonicWall #SMA1000 #CISA #UTA0533
Keypoints
- INC Ransomware is the most active group exploiting the SonicWall SMA1000 flaws.
- CVE-2026-15409 and CVE-2026-15410 allow remote access and root privilege escalation.
- The vulnerabilities were exploited in the wild as zero-days before the July 14 patch.
- Attackers used compromised SMA1000 devices to steal credentials and move into internal networks.
- Victims were also contacted with emails and calls as pressure tactics for ransom negotiations.
Read More: https://www.securityweek.com/recent-sonicwall-vulnerabilities-exploited-in-ransomware-attacks/