Home / Aug 05, 2026 / Story
0
#5 CyberScoop general August 04, 2026 at 15:20 UTC

Prolific ransomware group behind SonicWall zero-day attacks

By Matt Kapko

AI Summary

INC ransomware group has been chaining two SonicWall zero-day vulnerabilities in SMA1000 appliances to gain root access, move laterally, and exfiltrate and encrypt data for extortion. INC was not the first group to exploit these flaws but has been the most aggressive and effective in operationalizing the vulnerability chain. Organizations running SonicWall SMA1000 should apply patches immediately and audit for signs of lateral movement.

Relevance score: 86.0/100

# More from August 05