Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
INC Ransomware Exploits SonicWall Vulnerabilities

INC Ransomware Exploits SonicWall Vulnerabilities

Posted on August 3, 2026 By CWS

The INC Ransomware group has positioned itself as a leading threat by exploiting vulnerabilities in SonicWall’s Secure Mobile Access (SMA) 1000 series VPN appliances. This development follows the identification of significant security flaws, prompting urgent attention from cybersecurity experts worldwide.

Escalation of Ransomware Attacks

In a recent analysis by Resecurity, INC Ransomware activities have surged since early August 2026, with multiple entities listed on their data leak site. According to Ransomware.Live, the group has so far claimed 885 victims, with the latest attack reported on August 2, 2026. The exploitation primarily targets vulnerabilities identified as CVE-2026-15409 and CVE-2026-15410, which allow attackers to execute arbitrary commands and compromise vulnerable systems. SonicWall released patches for these issues in mid-July 2026.

Technical Exploitation and Tactics

The vulnerabilities have been reportedly used as zero-day exploits. Rapid7 has observed that attackers utilized these flaws to obtain crucial credentials, access active session databases, and manipulate Time-Based One-Time Password (TOTP) MFA configurations. These actions aim to secure persistent access and enable lateral movement within corporate networks. Volexity’s follow-up investigation unveiled pre-disclosure exploitation activities traced to a threat cluster known as UTA0533, which used a Python script, KNUCKLEBALL, to deploy tools such as Suo5 and a customized Java web shell named ORANGETAIL.

Rapid7’s research aligns with these findings, indicating potential coordination among threat actors who first discovered and exploited this zero-day vulnerability. Douglas McKee of Rapid7 emphasized the technical alignment, suggesting a singular or collective effort in capitalizing on these flaws.

Impact on Global Organizations

Between July 17 and August 1, 2026, INC Ransomware listed new victims, including private and government sectors from countries like Australia, the United States, the UAE, Colombia, and Switzerland. Resecurity reported that affected organizations received communications from unknown entities offering ransomware assistance, sometimes involving a caller named “Andrew,” using a specific phone number, and providing an email for further contact. These tactics are common pressure strategies employed by ransomware operators.

Preventative Measures and Recommendations

Experts advise organizations to quickly update their SMA 1000 appliances to the newest software version. Alongside patching, Resecurity recommends thorough threat hunting, credential updates, and integrity checks to mitigate the risks associated with these vulnerabilities. It is also advised to monitor external interactions with critical network parameters and correlate these with internal authentication activities to detect unusual patterns and prevent lateral movements.

As cyber threats evolve, maintaining robust cybersecurity measures and staying informed about potential vulnerabilities remain crucial for safeguarding organizational networks.

The Hacker News Tags:cyber attacks, Cybercrime, Cybersecurity, data breach, INC ransomware, IT security, network security, Ransomware, SonicWall, Threat Actors, VPN, Vulnerabilities, vulnerability management

Post navigation

Previous Post: Critical Vulnerability in DNA Software Threatens Data Integrity
Next Post: Liechtenstein’s Company Register Data Breach Exposed

Related Posts

Eclipse Foundation Revokes Leaked Open VSX Tokens Following Wiz Discovery Eclipse Foundation Revokes Leaked Open VSX Tokens Following Wiz Discovery The Hacker News
Gentlemen RaaS Targets Security with EDR Framework Gentlemen RaaS Targets Security with EDR Framework The Hacker News
Researchers Uncover 30+ Flaws in AI Coding Tools Enabling Data Theft and RCE Attacks Researchers Uncover 30+ Flaws in AI Coding Tools Enabling Data Theft and RCE Attacks The Hacker News
New Brazilian Malware Targets Financial Platforms New Brazilian Malware Targets Financial Platforms The Hacker News
AI-Driven Malware Campaign Targets India with Mass-Produced Implants AI-Driven Malware Campaign Targets India with Mass-Produced Implants The Hacker News
Hackers Use LinkedIn Messages to Spread RAT Malware Through DLL Sideloading Hackers Use LinkedIn Messages to Spread RAT Malware Through DLL Sideloading The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Rails Vulnerability Threatens Cloud Security
  • Malicious npm Packages Target Alibaba Users with RAT
  • Malware Exploits Google Passkey Vulnerabilities
  • Liechtenstein’s Company Register Data Breach Exposed
  • INC Ransomware Exploits SonicWall Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Rails Vulnerability Threatens Cloud Security
  • Malicious npm Packages Target Alibaba Users with RAT
  • Malware Exploits Google Passkey Vulnerabilities
  • Liechtenstein’s Company Register Data Breach Exposed
  • INC Ransomware Exploits SonicWall Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark