Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
SonicWall Vulnerabilities Exploited in Ransomware Surge

SonicWall Vulnerabilities Exploited in Ransomware Surge

Posted on August 3, 2026 By CWS

The recent surge in ransomware attacks has been attributed to vulnerabilities in SonicWall’s SMA1000 secure remote access devices. According to a report by Resecurity, the INC Ransomware group is primarily responsible for exploiting these security flaws.

Details of the SonicWall Vulnerabilities

The identified vulnerabilities, CVE-2026-15409 and CVE-2026-15410, have been given a CVSS score of 10 and 7.2, respectively. These flaws allow attackers to create a WebSocket tunnel into restricted services and escalate privileges to root, posing a significant threat to affected systems.

Patches for these vulnerabilities were released on July 14, coinciding with their inclusion in CISA’s Known Exploited Vulnerabilities catalog. However, evidence suggests that these security gaps were being exploited as zero-day vulnerabilities since at least June 22.

Exploitation Patterns and Threat Actors

Volexity, a cybersecurity firm, has linked the exploitation of these vulnerabilities to a threat actor known as UTA0533. This actor has been involved in credential theft from compromised devices and deploying malicious files, although lateral movement to other systems has been limited.

Another firm, Rapid7, observed attackers using the compromised SMA1000 devices as a launchpad into internal corporate networks, possibly by installing backdoors on the affected appliances.

INC Ransomware Group’s Aggressive Tactics

Resecurity’s findings indicate that the INC Ransomware group is the most active in leveraging these vulnerabilities. Since the beginning of August 2026, there has been an uptick in their operations, with numerous new victims appearing on their Data Leak Site.

Victims have spanned various sectors, including private and government organizations across the US, Australia, UAE, Colombia, and Switzerland. Resecurity has been assisting these victims with digital forensics and incident response to identify and mitigate the root cause of the breaches.

Victims of the ransomware attacks have also been targeted with deceptive communications from actors claiming to offer assistance with ransomware issues. In one instance, these communications originated from a domain registered through a Chinese domain registrar, further complicating the response efforts.

Recommendations for Users

As ransomware groups continue to target the SonicWall vulnerabilities, it is critical for users to promptly apply patches to their SMA1000 devices and engage in proactive threat hunting to detect potential intrusions. Staying informed and vigilant is key to safeguarding against these evolving cyber threats.

Security Week News Tags:CVE-2026-15409, CVE-2026-15410, cyber attacks, cyber defense, Cybersecurity, INC ransomware, Patching, Ransomware, SMA1000, SonicWall, Threat Actors, Vulnerabilities

Post navigation

Previous Post: Chinese Threat Actor Utilizes Leaked DarkSword for iOS Attacks
Next Post: Coldcard Wallet Flaw Leads to Major Bitcoin Heist

Related Posts

Chrome 140 Update Patches Sixth Zero-Day of 2025 Chrome 140 Update Patches Sixth Zero-Day of 2025 Security Week News
LiteLLM Supply Chain Attack Affects Over 2,500 Organizations LiteLLM Supply Chain Attack Affects Over 2,500 Organizations Security Week News
Exploitation of Critical Adobe Commerce Flaw Puts Many eCommerce Sites at Risk Exploitation of Critical Adobe Commerce Flaw Puts Many eCommerce Sites at Risk Security Week News
AI Tools Vulnerable to Comment-Based Prompt Injection AI Tools Vulnerable to Comment-Based Prompt Injection Security Week News
US Sentences Two for North Korean IT Scheme Involvement US Sentences Two for North Korean IT Scheme Involvement Security Week News
Hackers Abuse ConnectWise to Hide Malware Hackers Abuse ConnectWise to Hide Malware Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI Malware Evolves Hourly to Evade Detection
  • Microsoft Updates Address AI and Cloud Vulnerabilities
  • Plugin4Shell Exploit Threatens AI Coding Tools
  • Security Flaw Exposes OpenAI Code via AI-Generated Exploit
  • Brevo Attack Compromises Over 100,000 WordPress Sites

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI Malware Evolves Hourly to Evade Detection
  • Microsoft Updates Address AI and Cloud Vulnerabilities
  • Plugin4Shell Exploit Threatens AI Coding Tools
  • Security Flaw Exposes OpenAI Code via AI-Generated Exploit
  • Brevo Attack Compromises Over 100,000 WordPress Sites

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark