SonicWall VPN Zero-Days Fuel Ransomware Surge
Two flaws in SonicWall SMA1000 VPN appliances, one with a maximum severity score, have been exploited as zero-days since June. The INC Ransomware gang is now the dominant group using the flaws to breach networks worldwide.
Researchers say the INC Ransomware gang has become the dominant threat actor exploiting two SonicWall SMA1000 VPN flaws, CVE-2026-15409 (CVSS 10) and CVE-2026-15410 (CVSS 7.2), which were weaponized as zero-days since June 22, 2026, weeks before SonicWall's July patch. The gang has claimed 885 victims across the US, Australia, the UAE, Colombia and Switzerland, stealing credentials and multi-factor authentication seeds for persistent access.
Published on