SonicWall Under Siege: INC Ransomware Turns Zero-Day Flaws Into a Global Extortion Threat + Video

Listen to this Post

Featured ImageIntroduction: When the Firewall Becomes the Entry Point

Firewalls are designed to stand between an organization and the dangers of the internet. They are supposed to inspect traffic, block malicious activity, protect sensitive systems, and provide security teams with a reliable line of defense. But when attackers discover a critical weakness inside the firewall itself, that protective barrier can become one of the most dangerous entry points in the entire network.

That is the growing concern surrounding two recently disclosed SonicWall zero-day vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410. Security researchers say the prolific INC ransomware operation has emerged as the most prominent threat actor exploiting the vulnerability chain after the flaws became public.

The attacks are particularly troubling because the vulnerabilities were reportedly exploited for weeks before SonicWall disclosed and patched them. Since the public disclosure, attackers have moved quickly, combining the two flaws to gain deeper access and accelerate ransomware operations.

The situation is another warning that perimeter security devices are now high-value targets. A compromised endpoint may expose one employee or one workstation. A compromised firewall, however, may provide attackers with a direct path into an organization’s broader network.

Original Summary: INC Ransomware Emerges as the Main Post-Disclosure Threat

Researchers have identified INC ransomware as the most frequently named threat actor exploiting the SonicWall vulnerability chain following public disclosure of the flaws. Although INC was not necessarily responsible for the earliest attacks, its activity has become one of the most aggressive and operationally concerning examples observed after the vulnerabilities were publicly revealed.

According to Rapid7 incident-response director Brett Deroche, the full history of exploitation cannot be attributed to INC alone. Early attacks observed from June 22 were associated with shared hosted infrastructure and were largely unsuccessful. However, confirmed INC activity appeared after public disclosure and used different infrastructure, demonstrating a faster and more capable attack pattern.

The group reportedly moved from initial access to ransomware deployment in a short period of time. Rapid7 said it successfully prevented data theft and encryption in most of the recent incidents it investigated, although ransomware deployment was confirmed in at least one case.

The number of organizations affected remains unknown. Security visibility is limited, and some attacks may have occurred outside the telemetry available to incident-response companies.

INC ransomware has reportedly claimed nearly 900 victims across 71 countries since its emergence around three years ago. The group has also allegedly added new victims to its leak site, including organizations and government entities in Australia, the United States, the United Arab Emirates, Colombia, and Switzerland.

Some victims reportedly received emails and phone calls from individuals claiming to be the attackers, pressuring organizations to begin ransom negotiations.

The Vulnerabilities: A Dangerous Chain Rather Than an Isolated Bug

The two SonicWall vulnerabilities, CVE-2026-15409 and CVE-2026-15410, appear to be especially dangerous when used together. Attackers often gain more value by chaining vulnerabilities than by exploiting a single flaw in isolation.

A vulnerability chain can allow an attacker to move through several stages of compromise. One weakness may help bypass a security control, while another may provide elevated access or enable deeper interaction with internal systems. When combined, the result can be far more serious than the individual vulnerabilities suggest.

For ransomware operators, this creates a highly efficient path. Instead of spending days searching for exposed credentials, phishing employees, or exploiting multiple internal systems, attackers may be able to use an internet-facing security appliance as their initial foothold.

That speed matters. The shorter the period between initial access and ransomware deployment, the less time defenders have to detect suspicious activity, isolate affected systems, and prevent encryption or data theft.

A Three-Week Window That Increased the Risk

The SonicWall flaws were reportedly exploited for approximately three weeks before the vendor disclosed and patched them on July 14. This period is especially important because organizations may have been exposed without knowing the vulnerabilities existed.

Zero-day attacks are difficult to defend against because security teams may not have a patch, a public advisory, or reliable detection guidance when exploitation begins. Attackers can use that uncertainty to test techniques, identify vulnerable targets, and refine their operations.

Once a vulnerability becomes public, the situation changes rapidly. Security researchers begin publishing indicators, defenders start applying patches, and attackers race to exploit organizations that have not yet updated their systems.

The appearance of INC ransomware after disclosure demonstrates how quickly financially motivated groups can operationalize public vulnerability information.

Public disclosure improves defensive awareness, but it can also accelerate opportunistic attacks against organizations with slow patching processes.

INC Ransomware: A Global Operation With Expanding Reach

INC ransomware has become one of the more active ransomware operations worldwide. Since its discovery, the group has allegedly targeted hundreds of organizations across dozens of countries.

Like many ransomware-as-a-service operations, INC is believed to operate within a broader criminal ecosystem. Such models can involve developers who maintain ransomware tools, affiliates who conduct intrusions, and negotiators who pressure victims into paying.

This structure allows ransomware groups to scale rapidly. Multiple affiliates may target different regions and industries simultaneously, while shared infrastructure and tooling reduce the cost of launching attacks.

The group’s reported use of data leak sites also reflects the evolution of ransomware extortion. Modern ransomware attacks are not limited to encrypting files. Attackers may steal sensitive information before encryption and threaten to publish it if a victim refuses to negotiate.

This approach creates multiple forms of pressure. Even if an organization restores its systems from backups, it may still face reputational, legal, regulatory, and commercial consequences if stolen information is exposed.

From Network Access to Ransomware Deployment

Rapid7’s observations suggest that INC moved from initial access to ransomware deployment quickly. This operational tempo is a major concern because many organizations still rely on manual investigation processes that require hours or days to confirm an intrusion.

A fast ransomware operation may follow a sequence similar to this:

Initial Access: Exploiting the Internet-Facing Device

Attackers identify vulnerable SonicWall appliances exposed to the internet and attempt to exploit the available weaknesses.

Internal Discovery: Mapping the Environment

After gaining access, attackers may attempt to identify important systems, administrative accounts, file servers, domain infrastructure, and security tools.

Privilege Expansion: Seeking Greater Control

The attackers may attempt to obtain higher privileges or access additional credentials that allow them to move through the network.

Data Collection: Preparing for Double Extortion

Sensitive documents, financial records, internal communications, customer information, or operational data may be collected before ransomware is deployed.

Ransomware Deployment: Disrupting the Organization

Attackers may attempt to encrypt systems across multiple network segments while leaving ransom instructions and threatening to publish stolen data.

The speed of this sequence means organizations cannot assume that a patch applied after an attack begins will automatically remove the attacker.

Patching closes the vulnerable entry point, but incident response is still required to determine whether the network was already compromised.

SonicWall’s Growing Security Challenge

The latest vulnerabilities are part of a broader series of security concerns affecting SonicWall customers.

The company’s products have faced multiple actively exploited vulnerabilities, previously disclosed defects, and a major security incident last year involving the theft of firewall configurations belonging to SonicWall customers.

Firewall configuration data can be highly valuable to attackers. It may reveal network architecture, security rules, VPN settings, device relationships, and other information that could help adversaries understand how an organization is protected.

The latest attacks therefore arrive in an environment where many security teams may already be concerned about the exposure of edge devices.

Security appliances are attractive targets because they sit at critical points in the network. A successful compromise can potentially provide access to traffic, authentication systems, remote connections, or internal services.

Huntress Detects a Rapid Attack Spree

Huntress researchers recently identified an attack campaign that compromised approximately 30 SonicWall customers in less than two days.

That level of activity highlights how quickly exploitation can spread once attackers identify a reliable method.

Automated scanning allows threat actors to search the internet for vulnerable devices at enormous scale. Once an exposed target is identified, attackers can attempt exploitation within minutes.

This creates a difficult reality for defenders: the time between vulnerability disclosure and real-world attacks may be extremely short.

Organizations that wait for a routine maintenance window may discover that attackers do not follow the same schedule.

For internet-facing security appliances, emergency patching and temporary exposure reduction may be necessary when active exploitation is confirmed.

Why Ransomware Groups Keep Targeting SonicWall

Ransomware operators have repeatedly shown interest in SonicWall vulnerabilities.

Since late 2021, 10 of the 17 SonicWall vulnerabilities added to the U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog have reportedly been associated with ransomware activity.

This pattern suggests that attackers see SonicWall products as strategically valuable targets rather than isolated opportunities.

The reason is straightforward: edge appliances can provide access to organizations before traditional endpoint defenses have an opportunity to intervene.

A compromised employee laptop may be detected by endpoint security software. A compromised network appliance, however, may operate in a different security layer and may not have the same monitoring capabilities.

Attackers are increasingly searching for weaknesses in VPN gateways, firewalls, remote-access systems, identity platforms, and cloud management tools because these technologies often sit at the intersection of external access and internal infrastructure.

The Human Pressure Behind the Technical Attack

The reported emails and phone calls to victims reveal another important aspect of modern ransomware operations.

Ransomware is not only a technical attack. It is also a psychological and business-pressure campaign.

Attackers may contact executives, legal teams, customers, employees, or government representatives to increase the urgency of negotiations. They may claim that sensitive information will be published or sold if the organization refuses to engage.

Phone calls can make the threat feel more immediate and personal. They may also create confusion during an already stressful incident.

Organizations should establish clear procedures for handling attacker communications. Negotiation decisions should involve executive leadership, legal counsel, incident-response specialists, cyber-insurance representatives where applicable, and law-enforcement guidance.

Employees should not respond independently or disclose internal information to individuals claiming to represent the attackers.

Deep Analysis: How Organizations Should Investigate Potential SonicWall Exposure

Immediate Patch Verification

Organizations should first confirm that all affected SonicWall appliances are running the vendor-recommended patched versions.

Security teams should not assume that a device is protected simply because a patch was scheduled or deployed. The update should be verified through the management interface and documented.

Administrators can also maintain a local inventory of exposed systems:

Review network devices discovered through an internal asset inventory

nmap -sV -Pn <approved-network-range>

Identify systems responding on common HTTPS services

nmap -p 443,8443 --open <approved-network-range>

These commands should only be used on networks and systems the organization owns or is authorized to assess.

Reviewing Firewall and VPN Logs

Security teams should review logs for unusual administrative access, unexpected authentication events, configuration changes, unfamiliar source addresses, or abnormal management activity.

On a centralized Linux log server, analysts may search for suspicious patterns:

Search recent logs for authentication failures

grep -Ei "failed|invalid|denied|authentication" /var/log/.log

Search for administrative or configuration activity

grep -Ei "admin|configuration|management|privilege" /var/log/.log

Log formats vary between environments, so organizations should adapt searches to their own systems and vendor documentation.

Looking for Unexpected Outbound Connections

Ransomware operators may establish command-and-control connections or transfer data to external infrastructure.

Security teams should investigate unusual outbound traffic from security appliances and critical servers.

Review active network connections on a monitored Linux host

ss -tulpn

Display recent network connections where supported

journalctl --since "48 hours ago" | grep -Ei "connection|network|remote"

Unexpected encrypted connections, unusual destinations, or repeated traffic to unfamiliar infrastructure should be investigated.

Checking for New Accounts and Privilege Changes

Attackers may create new accounts or modify existing privileges to preserve access.

Review recently modified local account information

getent passwd

Review recent account-related events

grep -Ei "useradd|usermod|sudo|privilege" /var/log/auth.log

The exact log location may differ depending on the operating system and configuration.

Searching for Ransomware Indicators

Security teams should look for unexpected file extensions, ransom notes, mass file modifications, disabled security tools, or unusual activity involving administrative utilities.

Search for recently modified files

find /important-data -type f -mtime -3 -print

Identify unusually large or recently created files

find /important-data -type f -size +500M -mtime -7 -print

These checks should be performed carefully to avoid disrupting evidence or modifying potentially compromised systems.

Isolating Suspected Systems

If a compromise is suspected, affected systems should be isolated according to the organization’s incident-response plan.

Isolation should preserve evidence whenever possible. Simply rebooting a device may destroy valuable forensic information.

Organizations should capture logs, network information, system state, and relevant security alerts before making major changes when circumstances allow.

Resetting Credentials After Confirmed Exposure

If an attacker may have accessed authentication information, organizations should rotate potentially affected credentials.

Priority should be given to:

Firewall and VPN administrator accounts.

Domain administrator credentials.

Service accounts.

Remote-access credentials.

API keys and security tokens.

Privileged cloud identities.

Credential rotation should be coordinated carefully because uncontrolled changes can disrupt critical services.

What Undercode Say:

The Firewall Is No Longer Just a Defensive Tool

The SonicWall attacks show that security appliances must be treated as high-value computing systems rather than passive network equipment.

Edge Devices Require Continuous Monitoring

Organizations often monitor endpoints closely while giving less attention to firewalls, VPN gateways, and remote-access appliances.

Public Disclosure Creates a Race

Once a vulnerability becomes public, defenders race to patch while attackers race to find organizations that remain exposed.

The Exploitation Window Can Be Extremely Short

Security teams should assume that active exploitation may begin immediately after technical details become available.

Zero-Day Activity Changes Patch Priorities

A vulnerability under active attack should not always follow the normal maintenance schedule.

Vulnerability Chaining Increases Impact

Two moderate or severe weaknesses can become critical when attackers combine them into a reliable attack path.

INC Demonstrates Operational Speed

The group’s reported movement from access to ransomware deployment suggests a mature and highly organized operation.

Fast Attacks Reduce Detection Opportunities

Traditional security processes may be too slow when attackers can escalate within hours.

Patching Does Not Remove Existing Attackers

Applying an update closes the vulnerable door but does not automatically remove someone who entered earlier.

Incident Response Must Follow Exposure

Organizations should investigate logs and network activity even after successful patch deployment.

Asset Visibility Is Essential

Security teams cannot protect devices they do not know exist.

Internet Exposure Should Be Minimized

Administrative interfaces should not be publicly accessible unless operationally necessary.

Strong Authentication Remains Important

Multi-factor authentication can reduce some forms of unauthorized access, although it does not replace vulnerability patching.

Network Segmentation Limits Damage

A compromised edge device should not automatically provide unrestricted access to critical systems.

Privileged Access Requires Additional Controls

Administrative accounts should be protected through strict access policies and continuous monitoring.

Centralized Logging Improves Investigation

Logs stored away from the affected device are more likely to remain available during an incident.

Backups Must Be Protected

Offline or immutable backups can reduce the operational impact of ransomware encryption.

Data Theft Changes the Recovery Equation

Restoring encrypted systems may not resolve the risks created by stolen information.

Ransomware Is Now a Multi-Layered Extortion Model

Attackers may combine encryption, data leaks, public pressure, and direct communication.

Victim Communication Is Part of the Attack

Emails and phone calls are designed to increase urgency and influence decision-making.

Organizations Need a Negotiation Policy

Leadership should know in advance who is authorized to communicate during a ransomware incident.

Threat Intelligence Must Be Actionable

Security alerts are valuable only when they lead to concrete defensive actions.

Vendor Advisories Should Be Closely Monitored

Organizations using internet-facing security products should subscribe to official security notifications.

Emergency Patching Requires Preparation

Teams should maintain tested procedures for rapid updates outside routine maintenance windows.

Configuration Backups Are Important

Secure backups of firewall configurations can support recovery after compromise or hardware replacement.

Configuration Files Are Sensitive Assets

Network configurations may reveal valuable information about infrastructure and security architecture.

Security Appliances Need Hardening

Unused services, unnecessary management access, and weak authentication should be eliminated.

Exposure Management Must Be Continuous

Organizations should repeatedly identify systems that are accessible from the internet.

Detection Engineering Should Include Edge Devices

Security teams should build alerts for unusual firewall administration and configuration changes.

Ransomware Groups Follow Opportunity

Attackers will continue targeting technologies that provide broad access to valuable networks.

The Threat Is Global

The alleged victim activity across multiple countries shows that geographic distance provides little protection.

Smaller Organizations Are Also at Risk

Attackers may automate scanning and exploitation, making large-scale targeting economically viable.

Security Vendors Need Rapid Communication

Clear advisories and practical mitigation guidance can reduce confusion during active exploitation.

Organizations Must Practice Incident Response

A documented plan is useful, but rehearsed procedures are more effective during a real emergency.

Forensics Should Be Preserved

Evidence can help determine how attackers entered, what they accessed, and whether they remain active.

Defensive Speed Is Becoming a Competitive Advantage

Organizations that detect and contain attacks quickly can significantly reduce financial damage.

Cyber Resilience Is More Than Prevention

Modern security strategies must include detection, containment, recovery, and communication.

The SonicWall Campaign Is a Broader Warning

The core lesson applies to all internet-facing infrastructure, not only SonicWall products.

Trust in Security Products Must Be Continuously Verified

Deploying a firewall is not the end of security work; it begins an ongoing operational responsibility.

✅ INC Ransomware Has Been Linked to Post-Disclosure Exploitation

Researchers identified INC ransomware as the most commonly named threat actor weaponizing the SonicWall vulnerability chain after public disclosure. However, the available evidence does not establish that INC was responsible for every attack.

✅ The Vulnerabilities Were Actively Exploited Before Public Disclosure

The reported exploitation period began weeks before SonicWall disclosed and patched the vulnerabilities, making the flaws a significant zero-day threat.

✅ Rapid7 Observed Faster Activity From INC

Rapid7 reported that confirmed INC activity used different infrastructure and moved from initial access toward ransomware deployment more rapidly than the earlier observed attacks.

✅ SonicWall Vulnerabilities Have a Documented Ransomware History

Multiple SonicWall vulnerabilities have been associated with ransomware campaigns and added to CISA’s Known Exploited Vulnerabilities catalog.

❌ The Full Number of Victims Is Not Confirmed

Researchers have not determined how many organizations were compromised through the latest SonicWall zero-days. Public victim claims and security telemetry may represent only part of the total impact.

❌ All Exploitation Cannot Be Attributed to INC

The earliest observed attacks were linked to common hosted infrastructure and were largely unsuccessful. Attribution remains incomplete, and multiple threat actors may have exploited the vulnerabilities.

❌ Patching Alone Cannot Prove an Organization Is Safe

A patched appliance may no longer be vulnerable to the same exploit, but organizations still need to investigate whether attackers gained access before the update was installed.

Prediction

(-1) Ransomware Operators Will Continue Targeting Internet-Facing Security Appliances

The continued exploitation of SonicWall vulnerabilities suggests that ransomware groups will increase their focus on firewalls, VPN gateways, identity platforms, and remote-access systems. These technologies offer high-value access because they sit directly between the public internet and internal networks.

(+1) Faster Patching Will Become a Core Security Requirement

Organizations will likely invest more heavily in automated asset discovery, exposure monitoring, emergency patching, and continuous validation of internet-facing systems.

(-1) Double-Extortion Campaigns Will Become More Aggressive

Attackers are expected to continue combining encryption with data theft, leak-site threats, emails, and direct phone calls to increase pressure on victims.

(+1) Edge-Device Monitoring Will Improve

Security teams will increasingly treat firewalls and network appliances as critical monitored assets, integrating their logs into centralized detection and response platforms.

(-1) Public Vulnerability Disclosure Will Trigger Faster Attack Waves

As exploit information becomes available, attackers will continue scanning for unpatched devices within hours or days, leaving organizations with increasingly narrow response windows.

(+1) Cyber Resilience Will Receive Greater Executive Attention

The SonicWall incidents may push more organizations to strengthen incident-response planning, immutable backups, network segmentation, privileged-access controls, and crisis communication procedures.

Final Outlook: The Perimeter Must Be Defended From the Inside

The latest SonicWall zero-day attacks demonstrate how quickly a vulnerability in a trusted security product can become a global ransomware opportunity.

INC ransomware’s reported activity is especially concerning because of its speed, scale, and ability to move from initial access toward ransomware deployment in a short period. Yet the broader lesson extends beyond one group or one vendor.

Every internet-facing security appliance should be treated as a critical asset. It must be inventoried, patched, monitored, hardened, and included in incident-response planning.

The firewall remains a vital layer of defense. But in the modern threat landscape, organizations must also defend the firewall itself.

▶️ Related Video (82% Match):

🕵️‍📝Let’s dive deep and fact‑check.

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

References:

Reported By: cyberscoop.com
Extra Source Hub (Possible Sources for article):
https://stackoverflow.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube