Critical

INC Ransomware is Calling Victims – Pressure Tactics Post SonicWall Zero-Day Exploit

Security Affairs
Actively Exploited

Overview

The INC Ransomware group is actively exploiting vulnerabilities in SonicWall's Secure Mobile Access (SMA) 1000 series devices. This campaign has been marked by aggressive tactics, including phone calls and emails aimed at pressuring victims into paying ransoms. Resecurity researchers have identified this group as the primary threat actor taking advantage of these recently disclosed flaws. Organizations worldwide that utilize SonicWall products may be at risk, as the group has ramped up its operations in response to these vulnerabilities. It’s crucial for companies to assess their security measures and consider immediate actions to prevent potential breaches and data loss.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: SonicWall SMA 1000 series devices.
  • Action Required: Organizations using SonicWall SMA 1000 devices should apply any available patches and updates from SonicWall immediately.
  • Timeline: Newly disclosed

Original Article Summary

INC Ransomware exploits SonicWall SMA 1000 flaws, using calls and emails to pressure victims during extortion campaigns targeting global organizations. Resecurity disclosed that INC Ransomware has emerged as the dominant threat actor exploiting the recently disclosed SonicWall Secure Mobile Access (SMA) 1000 vulnerabilities. According to the company’s research, the group has accelerated its operations since […]

Impact

SonicWall SMA 1000 series devices.

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Newly disclosed

Remediation

Organizations using SonicWall SMA 1000 devices should apply any available patches and updates from SonicWall immediately. They should also review their security configurations and monitor for any unusual activity that could indicate exploitation attempts.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Ransomware, Zero-day, Exploit.

Related Coverage

Police arrests dozens of suspects in global cybercrime crackdown

BleepingComputer

In a significant global effort against cybercrime, law enforcement agencies from 22 countries collaborated to identify 263 suspects and arrest 58 individuals tied to criminal networks primarily based in Africa. This crackdown is part of a broader initiative to combat organized cybercrime, which has been a growing concern worldwide. The arrested suspects are believed to be involved in various cybercrimes, including fraud and identity theft, affecting numerous victims across different regions. By targeting these networks, authorities aim to disrupt the operations of these cybercriminals and protect potential victims from future attacks. This operation underscores the need for international collaboration in tackling cyber threats that span multiple borders.

Aug 25, 2026

Fake Minecraft Clients Deliver WeedHack Malware Despite Infrastructure Takedown

Infosecurity Magazine

Despite the takedown of its original infrastructure in July, the WeedHack malware continues to target Minecraft players through fake client downloads. This malware is particularly concerning as it can compromise user accounts and potentially lead to further security breaches. The ongoing distribution of WeedHack highlights the resilience of cybercriminals and their ability to adapt after losing access to their previous systems. Players who download these malicious clients are at risk, as the malware can steal sensitive information. This situation serves as a reminder for gamers to be cautious about where they download software and to be aware of the risks associated with unofficial game clients.

Aug 25, 2026

Unpatched Zimbra servers are falling to CVE-2026-73570 attacks

Help Net Security

At least 274 Zimbra servers have been compromised by attackers exploiting a vulnerability identified as CVE-2026-73570. This particular flaw is a code injection issue in the Zimbra Collaboration Suite (ZCS), which is widely used by organizations that prefer to manage their own data instead of relying on more expensive services like Microsoft 365 or Google Workspace. The vulnerability was patched by Synacor in version 10.1.20 of ZCS, released on July 20, 2026. However, many instances remain unpatched, leaving them vulnerable to exploitation. This incident highlights the risks associated with not keeping software updated, especially for platforms that handle sensitive communication and collaboration.

Aug 25, 2026

Silent Patches Don’t Stop Attackers—They Blind Defenders

SecurityWeek

The article discusses the issue of silent patches, which are updates made to software to fix vulnerabilities without publicly disclosing the details. While these patches can help secure systems, they also create a problem for defenders. Attackers can exploit these vulnerabilities without defenders knowing the full context of the risks they face. This lack of transparency can lead to misprioritization of security efforts, leaving organizations vulnerable. The piece emphasizes the need for better communication about vulnerabilities and updates to ensure that defenders have the information they need to protect against potential exploits.

Aug 25, 2026

ReliaQuest Rejects Compromise Claims After ShinyHunters Incident

Infosecurity Magazine

ReliaQuest has addressed a recent social engineering attack associated with the hacking group ShinyHunters. The company clarified that while there were attempts to compromise its systems, the attackers did not succeed in breaching their defenses. This incident serves as a reminder of the growing threat posed by social engineering tactics, where attackers manipulate individuals into divulging confidential information. Despite the denial of a successful compromise, the event raises concerns about the effectiveness of security measures and the importance of employee awareness training. Companies must remain vigilant against such tactics to protect sensitive data and maintain trust with their clients.

Aug 25, 2026

US Sanctions Mabna Institute Hackers for Iranian Cyber-Attacks

Infosecurity Magazine

The U.S. government has imposed sanctions on several individuals linked to the Mabna Institute, a hacking group based in Iran known for cyber-attacks. This group has been involved in various hacking activities, including stealing data from universities and businesses around the world. The sanctions target the group's members to disrupt their operations and deter similar actions in the future. By penalizing these individuals, the U.S. aims to hold them accountable for their cyber activities that threaten both national security and economic interests. This move also signals to other state-sponsored hacking groups that there are consequences for such cyber crimes.

Aug 25, 2026