CyberSecurity News
INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
AI summary
The INC Ransomware operation is now the primary threat actor exploiting security vulnerabilities in SonicWall's SMA 1000 series VPN appliances. This development comes after recently disclosed flaws in these appliances. Resecurity has reported that INC Ransomware activity has increased since early August 2026. The group has listed multiple victims on its data leak site, indicating successful exploitation of the vulnerabilities. INC Ransomware's accelerated activity suggests it is actively targeting these flaws. The vulnerabilities are being used to compromise SonicWall Secure Mobile Access appliances.
Threat groups mentioned
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

