Resecurity | From WSProxy to Root: INC ransomware and SonicWall SMA Exploit Chain

SonicWall’s SMA 1000 series was hit by two actively exploited zero-days, CVE-2026-15409 and CVE-2026-15410, which let attackers chain a pre-auth /wsproxy bypass and a path-traversal flaw to gain root access on exposed VPN appliances. The abuse was attributed to UTA0533 and later linked to INC Ransomware, with observed malware including ROOTRUN, KNUCKLEBALL, Suo5, and ORANGETAIL. #SonicWall #SMA1000 #CVE-2026-15409 #CVE-2026-15410 #UTA0533 #INCRansomware #ROOTRUN #KNUCKLEBALL #Suo5 #ORANGETAIL

Read More
DNSC Assistance to Techventures Bank After Ransomware Attack

A seller using the name dreamss is allegedly offering a Branch Furniture customer database containing 480,276 records for $200, but the claim remains unverified. The sample data reportedly includes names, addresses, phone numbers, email addresses, country, and partial birth dates, raising identity theft and fraud concerns. #BranchFurniture #dreamss…

Read More
DNSC Assistance to Techventures Bank After Ransomware Attack

A threat actor posting as bytetobreach claims to have compromised Magyar Államkincstár, Hungary’s State Treasury, and says the intrusion reached Oracle Identity Manager vaults and VMware vCenter. The claim is unverified and is supported only by 13 screenshots, with no data sample, no ransom demand, and no open sale. #MagyarÁllamkincstár #bytetobreach…

Read More
DNSC Assistance to Techventures Bank After Ransomware Attack

A threat actor claiming to be WInQ7wk9sA3a says they breached Baltas Online and exfiltrated more than 500GB of data affecting 750+ Turkish company clients. The alleged leak includes executive psychometric profiles, candidate records, interview audio/video, exam materials, and source code, but the claim remains unverified. #BaltasOnline #WInQ7wk9sA3a #Turkey…

Read More