#5
CyberScoop
general
August 04, 2026 at 15:20 UTC
Prolific ransomware group behind SonicWall zero-day attacks
By Matt Kapko
AI Summary
INC ransomware group has been chaining two SonicWall zero-day vulnerabilities in SMA1000 appliances to gain root access, move laterally, and exfiltrate and encrypt data for extortion. INC was not the first group to exploit these flaws but has been the most aggressive and effective in operationalizing the vulnerability chain. Organizations running SonicWall SMA1000 should apply patches immediately and audit for signs of lateral movement.
Relevance score: 86.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →