INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws

INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
INC Ransomware has become the dominant threat actor exploiting newly disclosed flaws in SonicWall SMA 1000 VPN appliances, with attacks linked to CVE-2026-15409 and CVE-2026-15410. The campaign has targeted organizations across multiple countries, used pressure tactics through calls and emails, and aimed to steal credentials, session data, and MFA seeds for persistent access. #INC_Ransomware #SonicWall #CVE-2026-15409 #CVE-2026-15410 #UTA0533 #KNUCKLEBALL #Suo5 #ORANGETAIL

Keypoints

  • INC Ransomware is actively exploiting SonicWall SMA 1000 VPN flaws.
  • The attacks are linked to CVE-2026-15409 and CVE-2026-15410.
  • Exploitation may allow arbitrary command execution and device takeover.
  • Victims include government and private organizations in several countries.
  • Resecurity urges immediate patching, credential rotation, and threat hunting.

Read More: https://thehackernews.com/2026/08/inc-ransomware-emerges-as-dominant.html