According to a report by Resecurity, the INC Ransomware operation has emerged as the “dominant threat actor” exploiting recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. The group has been accelerating its activity since the beginning of August 2026 and is now listing multiple victims on its data leak site.

This development follows earlier reports of the SonicWall SMA 1000 zero-days (CVE-2026-15409 and CVE-2026-15410) being actively exploited since June. What makes INC notable is their rapid operationalization of these vulnerabilities and their aggressive victim selection strategy, suggesting a well-resourced operation with deep technical expertise.

Why This Matters: The SonicWall SMA 1000 is deployed by thousands of organizations worldwide. With INC Ransomware now dominating exploitation activity, organizations using these appliances must ensure they have applied patches or implemented network-level mitigations. The rapid escalation from initial discovery to active ransomware campaigns underscores the importance of proactive vulnerability management.

Sources:
The Hacker News — Full Article
Resecurity Report

By Allan