INC ransomware wasn’t the first group to exploit the zero-days, but it’s been the most assertive and effective in chaining both vulnerabilities to steal and encrypt data for extortion. The post Prolific ransomware group behind SonicWall zero-day attacks appeared first on CyberScoop.

INC ransomware, a prominent ransomware-as-a-service operation, has been identified as a primary threat actor exploiting a pair of recently disclosed SonicWall zero-day vulnerabilities, CVE-2026-15409 and CVE-2026-15410. While other actors engaged in exploitation prior to public disclosure, INC ransomware has been particularly effective in chaining these vulnerabilities to achieve data theft and encryption for extortion purposes.
The vulnerabilities were actively exploited for approximately three weeks before SonicWall disclosed and patched them on July 14. Initial exploitation, observed as early as June 22, utilized common hosted infrastructure and was largely unsuccessful. However, INC ransomware's confirmed activity, which began after the public disclosure, demonstrated a higher level of operational tempo and skill, moving rapidly from initial access to ransomware deployment.
Security researchers note that while INC ransomware is driving the post-disclosure wave of attacks, the full scope of exploitation cannot be attributed solely to this group. Rapid7, a security vendor, has reported successfully preventing data theft and encryption in the majority of recent cases they observed, though ransomware was deployed in at least one instance.
Since its emergence three years ago, INC ransomware has claimed nearly 900 victims across 71 countries. The group has listed several new alleged victims on its data leak site, including organizations and government agencies in Australia, the United States, the United Arab Emirates, Colombia, and Switzerland. Some victims have reportedly received emails and phone calls from alleged hackers pressuring them into negotiations.
These latest zero-days add to a series of security challenges for SonicWall customers. Ten of the 17 SonicWall defects added to the Cybersecurity and Infrastructure Security Agency's (CISA) known exploited vulnerabilities (KEV) catalog since late 2021 are known to have been used in ransomware campaigns. Last year, a state-sponsored threat group reportedly stole firewall configurations from every SonicWall customer. More recently, researchers observed an attack spree that compromised 30 SonicWall customers in less than two days.



On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs