The record
Written from the 1 report below. Nothing here is unsourced.
- The INC Ransomware group has become the dominant threat exploiting security flaws in SonicWall Secure Mobile Access 1000 series VPN appliances, claiming 885 victims to date, with new victims listed between July 17 and August 1, 2026, including private and government organizations in Australia, the U.S., the U.A.E., Colombia, and Switzerland.
- The attacks are suspected to involve chaining two vulnerabilities, CVE-2026-15409 and CVE-2026-15410, which were exploited as zero-days starting June 22, 2026, before SonicWall released fixes in mid-July 2026.
- Attackers reportedly extracted credentials, session databases, and MFA seed configurations to maintain persistent access and move into internal corporate networks.
- Some victims have also received pressure-tactic calls and emails from unknown parties offering ransomware help.
- SonicWall customers are advised to patch their appliances immediately, rotate credentials, and conduct threat hunting.
What to watch next
- Whether more victims are added to INC Ransomware's leak site and in which countries or sectors.
- SonicWall customers applying the mid-July 2026 patches and performing credential rotation and threat hunting.
- Any new findings from Rapid7, Volexity, or Resecurity on the actor UTA0533 and the KNUCKLEBALL, Suo5, and ORANGETAIL tooling.
Coverage1
1 report
English national1
All filed from India
Named Australia · United States · United Arab Emirates · Colombia · Switzerland · SonicWall Secure Mobile Access 1000 · Andrew · Douglas McKee · INC Ransomware · Ransomware.Live · Rapid7 · Resecurity
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
