As cited
Copy frozen at (site build).
ransomware
Prolific ransomware group behind SonicWall zero-day attacks
The INC ransomware group has become the primary threat actor exploiting two SonicWall zero-day vulnerabilities (CVE-2026-15409 and CVE-2026-15410) disclosed on July 14. The group chained both flaws together to achieve full system access and has claimed multiple victims across Australia, the United States, the United Arab Emirates, Colombia, and Switzerland. SonicWall has faced a pattern of security issues, with ten of seventeen vulnerabilities added to CISA's known exploited vulnerabilities catalog since late 2021 linked to ransomware campaigns.
Why it matters: Organizations running SonicWall firewalls face immediate risk from active ransomware exploitation of these zero-days; patching CVE-2026-15409 and CVE-2026-15410 is critical as INC has demonstrated rapid weaponization and victims have received extortion demands.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ransomware
Prolific ransomware group behind SonicWall zero-day attacks
The INC ransomware group has become the primary threat actor exploiting two SonicWall zero-day vulnerabilities (CVE-2026-15409 and CVE-2026-15410) disclosed on July 14. The group chained both flaws together to achieve full system access and has claimed multiple victims across Australia, the United States, the United Arab Emirates, Colombia, and Switzerland. SonicWall has faced a pattern of security issues, with ten of seventeen vulnerabilities added to CISA's known exploited vulnerabilities catalog since late 2021 linked to ransomware campaigns.
Why it matters: Organizations running SonicWall firewalls face immediate risk from active ransomware exploitation of these zero-days; patching CVE-2026-15409 and CVE-2026-15410 is critical as INC has demonstrated rapid weaponization and victims have received extortion demands.
- Source published
- First seen by Cybersecurity Tracker