Toggle light / dark theme

INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws

INC Ransomware operation has emerged as the “dominant threat actor” exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1,000 series VPN appliances.

In a report published over the weekend, Resecurity said it observed the INC Ransomware accelerating its activity since the beginning of August 2026, listing multiple victims on its data leak site. Per statistics listed on Ransomware. Live, the group has claimed 885 victims to date, with the most recent victim listed on August 2, 2026.

The attacks are suspected to involve the exploitation of CVE-2026–15409 and CVE-2026–15410, which could be chained to facilitate arbitrary command execution and take over susceptible devices. Fixes for the vulnerability pair were released by SonicWall in mid-July 2026.

Leave a Comment

Lifeboat Foundation respects your privacy! Your email address will not be published.

/* */