Prolific ransomware group behind SonicWall zero-day attacks

Prolific ransomware group behind SonicWall zero-day attacks
Researchers said INC ransomware has become the most active threat actor exploiting two recently disclosed SonicWall zero-days, chaining the flaws for full access soon after public disclosure. The attacks have affected multiple organizations, with evidence of attempted extortion and new alleged victims appearing on INC’s leak site. #INC #SonicWall #CVE-2026-15409 #CVE-2026-15410

Keypoints

  • INC ransomware is exploiting two SonicWall zero-days.
  • The flaws were actively used before SonicWall disclosed them.
  • Researchers say INC chained both vulnerabilities for full access.
  • Rapid7 observed attacks after disclosure using different infrastructure.
  • INC has added new alleged victims to its data leak site.

Read More: https://cyberscoop.com/inc-ransomware-sonicwall-zero-day-attacks/