CYBERSECURITYTRACKER
TRACKING6,916 stories in this site build1,447 vulnerability news stories in this site build
Permanent story citation

Prolific ransomware group behind SonicWall zero-day attacks

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3834

As cited

Copy frozen at (site build).

ransomware

Prolific ransomware group behind SonicWall zero-day attacks

The INC ransomware group has become the primary threat actor exploiting two SonicWall zero-day vulnerabilities (CVE-2026-15409 and CVE-2026-15410) disclosed on July 14. The group chained both flaws together to achieve full system access and has claimed multiple victims across Australia, the United States, the United Arab Emirates, Colombia, and Switzerland. SonicWall has faced a pattern of security issues, with ten of seventeen vulnerabilities added to CISA's known exploited vulnerabilities catalog since late 2021 linked to ransomware campaigns.

Why it matters: Organizations running SonicWall firewalls face immediate risk from active ransomware exploitation of these zero-days; patching CVE-2026-15409 and CVE-2026-15410 is critical as INC has demonstrated rapid weaponization and victims have received extortion demands.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

Prolific ransomware group behind SonicWall zero-day attacks

The INC ransomware group has become the primary threat actor exploiting two SonicWall zero-day vulnerabilities (CVE-2026-15409 and CVE-2026-15410) disclosed on July 14. The group chained both flaws together to achieve full system access and has claimed multiple victims across Australia, the United States, the United Arab Emirates, Colombia, and Switzerland. SonicWall has faced a pattern of security issues, with ten of seventeen vulnerabilities added to CISA's known exploited vulnerabilities catalog since late 2021 linked to ransomware campaigns.

Why it matters: Organizations running SonicWall firewalls face immediate risk from active ransomware exploitation of these zero-days; patching CVE-2026-15409 and CVE-2026-15410 is critical as INC has demonstrated rapid weaponization and victims have received extortion demands.

VendorsSonicWall
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary