Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
SonicWall Vulnerabilities Exploited in Ransomware Surge

SonicWall Vulnerabilities Exploited in Ransomware Surge

Posted on August 3, 2026 By CWS

The recent surge in ransomware attacks has been attributed to vulnerabilities in SonicWall’s SMA1000 secure remote access devices. According to a report by Resecurity, the INC Ransomware group is primarily responsible for exploiting these security flaws.

Details of the SonicWall Vulnerabilities

The identified vulnerabilities, CVE-2026-15409 and CVE-2026-15410, have been given a CVSS score of 10 and 7.2, respectively. These flaws allow attackers to create a WebSocket tunnel into restricted services and escalate privileges to root, posing a significant threat to affected systems.

Patches for these vulnerabilities were released on July 14, coinciding with their inclusion in CISA’s Known Exploited Vulnerabilities catalog. However, evidence suggests that these security gaps were being exploited as zero-day vulnerabilities since at least June 22.

Exploitation Patterns and Threat Actors

Volexity, a cybersecurity firm, has linked the exploitation of these vulnerabilities to a threat actor known as UTA0533. This actor has been involved in credential theft from compromised devices and deploying malicious files, although lateral movement to other systems has been limited.

Another firm, Rapid7, observed attackers using the compromised SMA1000 devices as a launchpad into internal corporate networks, possibly by installing backdoors on the affected appliances.

INC Ransomware Group’s Aggressive Tactics

Resecurity’s findings indicate that the INC Ransomware group is the most active in leveraging these vulnerabilities. Since the beginning of August 2026, there has been an uptick in their operations, with numerous new victims appearing on their Data Leak Site.

Victims have spanned various sectors, including private and government organizations across the US, Australia, UAE, Colombia, and Switzerland. Resecurity has been assisting these victims with digital forensics and incident response to identify and mitigate the root cause of the breaches.

Victims of the ransomware attacks have also been targeted with deceptive communications from actors claiming to offer assistance with ransomware issues. In one instance, these communications originated from a domain registered through a Chinese domain registrar, further complicating the response efforts.

Recommendations for Users

As ransomware groups continue to target the SonicWall vulnerabilities, it is critical for users to promptly apply patches to their SMA1000 devices and engage in proactive threat hunting to detect potential intrusions. Staying informed and vigilant is key to safeguarding against these evolving cyber threats.

Security Week News Tags:CVE-2026-15409, CVE-2026-15410, cyber attacks, cyber defense, Cybersecurity, INC ransomware, Patching, Ransomware, SMA1000, SonicWall, Threat Actors, Vulnerabilities

Post navigation

Previous Post: Chinese Threat Actor Utilizes Leaked DarkSword for iOS Attacks
Next Post: Coldcard Wallet Flaw Leads to Major Bitcoin Heist

Related Posts

Key Questions Enterprises Must Ask About Frontier AI Security Key Questions Enterprises Must Ask About Frontier AI Security Security Week News
Trump Directs Federal Agencies to Cease Anthropic Technology Trump Directs Federal Agencies to Cease Anthropic Technology Security Week News
Analog Devices Reports Cybersecurity Breach Analog Devices Reports Cybersecurity Breach Security Week News
Microsoft to Address ‘RoguePlanet’ Security Flaw in Defender Microsoft to Address ‘RoguePlanet’ Security Flaw in Defender Security Week News
Recent Fortra GoAnywhere MFT Vulnerability Exploited as Zero-Day Recent Fortra GoAnywhere MFT Vulnerability Exploited as Zero-Day Security Week News
Several Vulnerabilities Patched in AI Code Editor Cursor  Several Vulnerabilities Patched in AI Code Editor Cursor  Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Cybercriminals Exploit AI for Sophisticated Scams
  • AI Chatbots’ Vulnerability to Account Hijacking Threats
  • Google Eliminates AI Workflows Over GitHub Security Flaw
  • Keyv npm Package Breach in Major Supply Chain Attack
  • Obsidian Security Secures $85M, Hits $1.1B Valuation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Cybercriminals Exploit AI for Sophisticated Scams
  • AI Chatbots’ Vulnerability to Account Hijacking Threats
  • Google Eliminates AI Workflows Over GitHub Security Flaw
  • Keyv npm Package Breach in Major Supply Chain Attack
  • Obsidian Security Secures $85M, Hits $1.1B Valuation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark