INC Ransomware Exploits SonicWall Vulnerabilities, Calls Victims Directly
Article Content
- •INC Ransomware exploited SonicWall vulnerabilities CVE-2026-15409 and CVE-2026-15410.
- •The campaign affected nearly 900 victims across 71 countries, including Colombia.
- •Attackers called victims directly to pressure them during the extortion process.
The INC Ransomware group has exploited two critical vulnerabilities in SonicWall devices, specifically CVE-2026-15409 and CVE-2026-15410, affecting organizations in 71 countries, including Colombia. This campaign began three weeks prior to the patch release on July 14, 2026, and has reportedly impacted nearly 900 victims. Notably, INC Ransomware employed a unique tactic by calling victims directly to pressure them during extortion efforts. The vulnerabilities were publicly disclosed and patched by SonicWall, but active exploitation was confirmed to have started at least three weeks earlier. The attack vector primarily targeted SonicWall SMA 1000 devices, which are widely used in various sectors. The situation remains critical as organizations are urged to ensure their systems are updated to mitigate risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track INC, Sonicwall and CVE-2026-15409 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
SonicWall SMA1000 Faces Critical Zero-Day Exploitation SonicWall disclosed two critical vulnerabilities in its SMA1000 series appliances, CVE-2026-83548 and CVE-2026-83549, which are being actively exploited. CVE-2026-83548 is a pre-authentication server-side request forgery (SSRF) vulnerability rated 10.0 on the CVSS scale, allowing unauthenticated attackers to access…
Critical SSRF and UAF Vulnerabilities Discovered in SonicWall and Linux Kernel Two critical vulnerabilities have been reported on September 7, 2026. CVE-2026-15409 is a critical Server-Side Request Forgery (SSRF) vulnerability in SonicWall SMA1000 series devices, allowing remote attackers to execute unintended HTTP requests. This vulnerability has been actively exploited since its disclosure on…