INC Ransomware has become the dominant threat actor exploiting newly disclosed flaws in SonicWall SMA 1000 VPN appliances, with attacks linked to CVE-2026-15409 and CVE-2026-15410. The campaign has targeted organizations across multiple countries, used pressure tactics through calls and emails, and aimed to steal credentials, session data, and MFA seeds for persistent access. #INC_Ransomware #SonicWall #CVE-2026-15409 #CVE-2026-15410 #UTA0533 #KNUCKLEBALL #Suo5 #ORANGETAIL
Keypoints
- INC Ransomware is actively exploiting SonicWall SMA 1000 VPN flaws.
- The attacks are linked to CVE-2026-15409 and CVE-2026-15410.
- Exploitation may allow arbitrary command execution and device takeover.
- Victims include government and private organizations in several countries.
- Resecurity urges immediate patching, credential rotation, and threat hunting.
Read More: https://thehackernews.com/2026/08/inc-ransomware-emerges-as-dominant.html