type: incident ยท created: 2026-08-04 ยท updated: 2026-08-18 ยท tags: [] ยท confidence: not-rated ยท affected_sectors: [] ยท au_impact: false
INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
Summary
Resecurity reports the INC Ransomware operation has become the dominant threat actor exploiting CVE-2026-15409 and CVE-2026-15410 in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. The group has claimed 885 victims to date, with activity accelerating since the beginning of August 2026.
Details
The CVEs were patched in mid-July 2026 and assessed to have been weaponised as zero-days. Rapid7 noted attackers leveraged the foothold to extract high-value credentials and active session data. Risky.Biz additionally notes a non-profit has offered a $22,000 bounty for information on the INC ransomware group.
Related
- Cve 2026 15409 โ SonicWall SMA 1000 zero-day (CVSS 10.0)
- Cve 2026 15410 โ SonicWall SMA 1000 vulnerability (CVSS 7.2)
- Sonicwall Sma Zero Day โ Combined CVE analysis
Sources
- The Hacker News
- Resecurity
- Rapid7
- Risky.Biz