Bottom line: Since August 2026, the ransomware group INC has been deliberately exploiting vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 VPN appliances and, according to Resecurity, has become the leading attacker in this area.
According to a report by Resecurity, the ransomware group INC has emerged as the dominant actor in exploiting recently disclosed security vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 VPN appliances. Since early August 2026, the group has significantly stepped up its activity.
Resecurity published a report last weekend stating that the INC ransomware operation has noticeably increased its attack pace since early August 2026. The group is exploiting recently disclosed security vulnerabilities in SonicWall SMA 1000 series VPN appliances. Multiple victims have been listed on the group’s own data-leak site, indicating systematic exploitation of the affected devices.
This is immediately relevant for security leaders at organizations running SonicWall SMA 1000 infrastructure, since VPN access points are classic entry vectors for initial access. If such an appliance is compromised, attackers potentially gain direct access to internal networks, laying the groundwork for subsequent ransomware encryption and data exfiltration. INC’s positioning as the “dominant actor” for this specific vulnerability class signals a targeted, coordinated campaign rather than isolated opportunistic attacks.
CISOs operating SonicWall SMA 1000 appliances should immediately verify the patch status of these devices and ensure that available security updates from SonicWall have been applied. Additionally, it is advisable to review access logs for unusual authentication attempts or session activity during the period in question. The report itself does not cite specific CVE identifiers; those responsible should consult SonicWall’s security advisories directly for technical details on affected versions and patch availability.
Source: thehackernews.com · Published August 3, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.