CVE Tools

INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws

The Hacker NewsBy The Hacker News

Reported exploitedSonicWall SMA 1000INC Ransomware

Our summary

The INC Ransomware group has become the leading threat actor exploiting two critical vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series appliances—CVE-2026-15409 and CVE-2026-15410—which allow for arbitrary command execution and device compromise. These zero-day flaws were patched by SonicWall in mid-July 2026 but continue to be actively weaponized, enabling attackers to steal credentials and gain persistent access to networks. Resecurity reported a sharp increase in incidents since early August, with more than 800 victims globally. Organizations are urged to apply patches immediately and conduct thorough network assessments to prevent further breaches.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store