Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
INC Ransomware Exploits SonicWall Vulnerabilities

INC Ransomware Exploits SonicWall Vulnerabilities

Posted on August 3, 2026 By CWS

The INC Ransomware group has positioned itself as a leading threat by exploiting vulnerabilities in SonicWall’s Secure Mobile Access (SMA) 1000 series VPN appliances. This development follows the identification of significant security flaws, prompting urgent attention from cybersecurity experts worldwide.

Escalation of Ransomware Attacks

In a recent analysis by Resecurity, INC Ransomware activities have surged since early August 2026, with multiple entities listed on their data leak site. According to Ransomware.Live, the group has so far claimed 885 victims, with the latest attack reported on August 2, 2026. The exploitation primarily targets vulnerabilities identified as CVE-2026-15409 and CVE-2026-15410, which allow attackers to execute arbitrary commands and compromise vulnerable systems. SonicWall released patches for these issues in mid-July 2026.

Technical Exploitation and Tactics

The vulnerabilities have been reportedly used as zero-day exploits. Rapid7 has observed that attackers utilized these flaws to obtain crucial credentials, access active session databases, and manipulate Time-Based One-Time Password (TOTP) MFA configurations. These actions aim to secure persistent access and enable lateral movement within corporate networks. Volexity’s follow-up investigation unveiled pre-disclosure exploitation activities traced to a threat cluster known as UTA0533, which used a Python script, KNUCKLEBALL, to deploy tools such as Suo5 and a customized Java web shell named ORANGETAIL.

Rapid7’s research aligns with these findings, indicating potential coordination among threat actors who first discovered and exploited this zero-day vulnerability. Douglas McKee of Rapid7 emphasized the technical alignment, suggesting a singular or collective effort in capitalizing on these flaws.

Impact on Global Organizations

Between July 17 and August 1, 2026, INC Ransomware listed new victims, including private and government sectors from countries like Australia, the United States, the UAE, Colombia, and Switzerland. Resecurity reported that affected organizations received communications from unknown entities offering ransomware assistance, sometimes involving a caller named “Andrew,” using a specific phone number, and providing an email for further contact. These tactics are common pressure strategies employed by ransomware operators.

Preventative Measures and Recommendations

Experts advise organizations to quickly update their SMA 1000 appliances to the newest software version. Alongside patching, Resecurity recommends thorough threat hunting, credential updates, and integrity checks to mitigate the risks associated with these vulnerabilities. It is also advised to monitor external interactions with critical network parameters and correlate these with internal authentication activities to detect unusual patterns and prevent lateral movements.

As cyber threats evolve, maintaining robust cybersecurity measures and staying informed about potential vulnerabilities remain crucial for safeguarding organizational networks.

The Hacker News Tags:cyber attacks, Cybercrime, Cybersecurity, data breach, INC ransomware, IT security, network security, Ransomware, SonicWall, Threat Actors, VPN, Vulnerabilities, vulnerability management

Post navigation

Previous Post: Critical Vulnerability in DNA Software Threatens Data Integrity
Next Post: Liechtenstein’s Company Register Data Breach Exposed

Related Posts

Critical Vulnerability in Cursor Allows Windows Code Execution Critical Vulnerability in Cursor Allows Windows Code Execution The Hacker News
Microsoft Device Code Phishing Campaign Targets M365 Accounts Microsoft Device Code Phishing Campaign Targets M365 Accounts The Hacker News
Canada’s Spy Agency Neutralizes Botnets with Unique Warrant Canada’s Spy Agency Neutralizes Botnets with Unique Warrant The Hacker News
U.S. Takes Down Domains of Major DDoS-for-Hire Service U.S. Takes Down Domains of Major DDoS-for-Hire Service The Hacker News
ValleyRAT Malware Concealed in Trusted Adware ValleyRAT Malware Concealed in Trusted Adware The Hacker News
175 Malicious npm Packages with 26,000 Downloads Used in Credential Phishing Campaign 175 Malicious npm Packages with 26,000 Downloads Used in Credential Phishing Campaign The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Flaws in BIND DNS Servers Threaten Security
  • Orkes Conductor Flaw Exploited in Recent Cyber Attacks
  • Iran-Affiliated Hackers Exploit Telegram for Data Breaches
  • FBI Shuts Down Major DDoS-for-Hire Platform NightmareStresser
  • MIND’s $72M Boost for AI-Enhanced Data Protection

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Flaws in BIND DNS Servers Threaten Security
  • Orkes Conductor Flaw Exploited in Recent Cyber Attacks
  • Iran-Affiliated Hackers Exploit Telegram for Data Breaches
  • FBI Shuts Down Major DDoS-for-Hire Platform NightmareStresser
  • MIND’s $72M Boost for AI-Enhanced Data Protection

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark