The INC Ransomware group is behind most recent activity exploiting two fresh vulnerabilities in SonicWall’s SMA1000 secure remote access appliances, according to Resecurity.
Tracked as CVE-2026-15409, a flaw scored a perfect 10, and CVE-2026-15410, scored 7.2, the defects let unauthenticated remote attackers open a WebSocket tunnel to restricted services and escalate privileges to root. SonicWall patched them on July 14, and CISA added both to its Known Exploited Vulnerabilities catalog the same day. The bugs had been exploited as zero-days since at least June 22.
Volexity attributed earlier exploitation to an actor tracked as UTA0533, which harvested credentials and dropped malicious files. Rapid7 observed attackers pivoting from compromised SMA1000 devices into internal corporate networks, likely after deploying a backdoor.
Resecurity says INC Ransomware has accelerated: since the start of August, its data leak site has listed new victims in the US, Australia, UAE, Colombia and Switzerland. The firm has helped several victims with incident response and vulnerability assessments.
Resecurity also flagged pressure tactics: victims received emails from unknown organizations claiming to help with ransomware issues, one from a domain registered after the exploitation activity through a Chinese registrar, plus phone calls from someone calling themselves Andrew who offered an email address for negotiations.
Users should patch SMA1000 appliances immediately and hunt for signs of compromise.
