<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

INC Ransomware Gang Leads Attacks Exploiting Critical SonicWall Flaws

INC Ransomware exploits SonicWall vulnerabilities; urgent patching advised as victims face pressure tactics from attackers.
Content Team

The INC Ransomware group has emerged as the most active threat actor exploiting two critical SonicWall SMA1000 vulnerabilities — CVE-2026-15409 (CVSS 10) and CVE-2026-15410 (CVSS 7.2) — which allow unauthenticated attackers to tunnel into restricted services and escalate privileges to root.

Zero-day exploitation began at least June 22, with patches and CISA KEV listings arriving July 14. Since early August, INC has accelerated attacks, listing victims from the US, Australia, UAE, Colombia, and Switzerland on its leak site.

In a disturbing twist, some victims received follow-up calls from someone named "Andrew" offering ransomware help — a known pressure tactic. Patch immediately.

Source: SecurityWeek

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo