Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-04 ยท updated: 2026-08-18 ยท tags: [] ยท confidence: not-rated ยท affected_sectors: [] ยท au_impact: false

INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws

Summary

Resecurity reports the INC Ransomware operation has become the dominant threat actor exploiting CVE-2026-15409 and CVE-2026-15410 in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. The group has claimed 885 victims to date, with activity accelerating since the beginning of August 2026.

Details

The CVEs were patched in mid-July 2026 and assessed to have been weaponised as zero-days. Rapid7 noted attackers leveraged the foothold to extract high-value credentials and active session data. Risky.Biz additionally notes a non-profit has offered a $22,000 bounty for information on the INC ransomware group.

Related

Sources