Researchers said INC ransomware has become the most active threat actor exploiting two recently disclosed SonicWall zero-days, chaining the flaws for full access soon after public disclosure. The attacks have affected multiple organizations, with evidence of attempted extortion and new alleged victims appearing on INCβs leak site. #INC #SonicWall #CVE-2026-15409 #CVE-2026-15410
Keypoints
- INC ransomware is exploiting two SonicWall zero-days.
- The flaws were actively used before SonicWall disclosed them.
- Researchers say INC chained both vulnerabilities for full access.
- Rapid7 observed attacks after disclosure using different infrastructure.
- INC has added new alleged victims to its data leak site.
Read More: https://cyberscoop.com/inc-ransomware-sonicwall-zero-day-attacks/