INC Ransomware Gang Leads Attacks Exploiting Critical SonicWall Flaws
Want more insights like this?
The INC Ransomware group has emerged as the most active threat actor exploiting two critical SonicWall SMA1000 vulnerabilities — CVE-2026-15409 (CVSS 10) and CVE-2026-15410 (CVSS 7.2) — which allow unauthenticated attackers to tunnel into restricted services and escalate privileges to root.
Zero-day exploitation of the chain began at least 22 June, attributed by Volexity to a separate actor tracked as UTA0533. Patches and CISA KEV listings arrived 14 July. INC's own victims start appearing from 17 July, and since early August it has accelerated attacks, listing victims from the US, Australia, UAE, Colombia, and Switzerland on its leak site.
In a disturbing twist, some victims received follow-up calls from someone named "Andrew" offering ransomware help — a known pressure tactic. Patch immediately: the fixes are platform hotfix versions 12.4.3-03453 and 12.5.0-02835.
Source: SecurityWeek