Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    Visa to Acquire Fraud Intelligence Firm BioCatch for $2.4 Billion

    August 3, 2026

    Louisiana Students Loft Payloads from NASA Balloon Facility in Texas

    August 3, 2026

    Satechi Thunderbolt 5 CubeDock review

    August 3, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks
    Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks
    Cybersecurity

    Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks

    The Tech GuyBy The Tech GuyAugust 3, 2026No Comments3 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    The INC Ransomware group is responsible for most of the recent activity surrounding two fresh vulnerabilities in SonicWall’s SMA1000 secure remote access appliances, Resecurity reports.

    Advertisement

    Tracked as CVE-2026-15409 (CVSS score of 10) and CVE-2026-15410 (CVSS score of 7.2), the security defects allow unauthenticated remote attackers to open a WebSocket tunnel to restricted services and escalate their privileges to root.

    Patched on July 14 and added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on the same day, the two flaws had been exploited in the wild as zero-days since at least June 22.

    Cybersecurity firm Volexity attributed the observed exploitation to a threat actor tracked as UTA0533, noting that it was harvesting credentials from the hacked appliances and deploying malicious files, but was less successful in moving laterally to other systems.

    Rapid7, on the other hand, observed threat actors pivoting from SMA1000 devices into internal corporate networks, likely after deploying a backdoor on the compromised appliances.

    Now, Resecurity says that, of the various threat actors chaining CVE-2026-15409 and CVE-2026-15410 for SMA1000 compromise, the INC Ransomware gang has emerged as the most active one.

    Advertisement. Scroll to continue reading.

    “Notably, as of the beginning of August 2026, INC Ransomware has accelerated its activity. Multiple new victims have been published on their Data Leak Site (DLS),” the company says.

    Over the past couple of weeks, the ransomware group has listed on its leak site private and government sector organizations from the US, Australia, UAE, Colombia, and Switzerland, among others.

    “Resecurity has assisted several victims with DFIR and vulnerability assessments to contain the root cause of the compromise, but also learned about the following new developments: many of the new victims received emails, as well as phone calls from unknown organizations claiming to assist with ransomware issues,” the company says.

    In one instance, the email came from a domain registered after the exploitation activity, through a Chinese domain registrar.

    The victims were also contacted by phone by a threat actor calling themselves Andrew and claiming to be representing a group of hackers. 

    “At the end of the call, the individual provided the email address info@helprans[.]com for further negotiations and then ended the call. Such methods are frequently used by ransomware groups as ‘pressure tactics’,” Resecurity notes.

    As ransomware groups continue to target the SonicWall vulnerabilities, users are advised to patch their SMA1000 appliances as soon as possible and to perform threat hunting to identify potential compromises.

    Related: US Water Cyberattacks Extend Beyond Minnesota to at Least 6 Other States

    Related: Ruby on Rails Patches Critical Vulnerability

    Related: Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace

    Related: Critical Flaw Allowed to Azure Cosmos DB Pwnage

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    Visa to Acquire Fraud Intelligence Firm BioCatch for $2.4 Billion

    August 3, 2026

    Black Hat USA 2026 – Summary of Vendor Announcements (Part 1)

    August 3, 2026

    Critical Code Execution Vulnerability Patched in TeamCity 

    August 2, 2026

    CareCloud Data Breach Impacts Over 350,000

    August 2, 2026

    Critical Flaw Allowed to Azure Cosmos DB Pwnage

    August 2, 2026

    Ruby on Rails Patches Critical Vulnerability

    August 1, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 2026391 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 2026210 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202516 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    Visa to Acquire Fraud Intelligence Firm BioCatch for $2.4 Billion

    August 3, 2026

    Louisiana Students Loft Payloads from NASA Balloon Facility in Texas

    August 3, 2026

    Satechi Thunderbolt 5 CubeDock review

    August 3, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.