LIVE · cybersecurity feed
Live wire
CVE-2026-66066 · KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066)Rails patches critical Active Storage flaw with RCE potentialCVE-2026-48449 · Adobe fixed a maximum-severity vulnerability flaw in Campaign ClassicRuby on Rails Patches Critical VulnerabilityHackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer SitesHijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance MalwareCaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theftHollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law FirmCVE-2026-33017 · Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability ExploitsThis month in security with Tony Anscombe – July 2026 edition
ransomware

Prolific ransomware group behind SonicWall zero-day attacks

INC ransomware wasn’t the first group to exploit the zero-days, but it’s been the most assertive and effective in chaining both vulnerabilities to steal and encrypt data for extortion. The post Prolific ransomware group behind SonicWall zero-day attacks appeared first on CyberScoop.

zeroday.news · 2h ago

INC ransomware, a prominent ransomware-as-a-service operation, has been identified as a primary threat actor exploiting a pair of recently disclosed SonicWall zero-day vulnerabilities, CVE-2026-15409 and CVE-2026-15410. While other actors engaged in exploitation prior to public disclosure, INC ransomware has been particularly effective in chaining these vulnerabilities to achieve data theft and encryption for extortion purposes.

The vulnerabilities were actively exploited for approximately three weeks before SonicWall disclosed and patched them on July 14. Initial exploitation, observed as early as June 22, utilized common hosted infrastructure and was largely unsuccessful. However, INC ransomware's confirmed activity, which began after the public disclosure, demonstrated a higher level of operational tempo and skill, moving rapidly from initial access to ransomware deployment.

Security researchers note that while INC ransomware is driving the post-disclosure wave of attacks, the full scope of exploitation cannot be attributed solely to this group. Rapid7, a security vendor, has reported successfully preventing data theft and encryption in the majority of recent cases they observed, though ransomware was deployed in at least one instance.

Since its emergence three years ago, INC ransomware has claimed nearly 900 victims across 71 countries. The group has listed several new alleged victims on its data leak site, including organizations and government agencies in Australia, the United States, the United Arab Emirates, Colombia, and Switzerland. Some victims have reportedly received emails and phone calls from alleged hackers pressuring them into negotiations.

These latest zero-days add to a series of security challenges for SonicWall customers. Ten of the 17 SonicWall defects added to the Cybersecurity and Infrastructure Security Agency's (CISA) known exploited vulnerabilities (KEV) catalog since late 2021 are known to have been used in ransomware campaigns. Last year, a state-sponsored threat group reportedly stole firewall configurations from every SonicWall customer. More recently, researchers observed an attack spree that compromised 30 SonicWall customers in less than two days.

ransomwarevulnerabilityzero-day
ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Landmark Deal Would Officially Add Laser Weapons to US Army Arsenal

Facing a growing drone threat, the Pentagon is poised to sign a first-of-its-kind contract for “Enduring High Energy Lasers”—and make directed energy weapons an official part of the Army’s kit.

malware

Massive ChainDrop npm supply-chain attack infects hundreds of packages

Self-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry. [...]

security

Tennessee congressional hopeful accused of shooting license plate cameras

Cops arrest budding politician for allegedly dealing with Flock's expansion the American way

security

2026 Cybersecurity Excellence Awards: Community Choice Winners Selected Through 80,000 Votes

Las Vegas, Nevada, 4th August 2026, CyberNewswire

phishing

How legitimate cloud platforms enable phishers to bypass MFA

We cover a cloud-based AitM attack scenario leveraging service workers and Ultraviolet, and provide detailed phishing hosting statistics across platforms like Cloudflare Workers, Vercel, Netlify, GitHub Pages, and IPFS.

ai

Securonix enhances Unified Defense SIEM with AI agent detection and lower data costs

Securonix has announced expanded cybersecurity cost reduction, expanded Threat Analytics for Microsoft Sentinel, and new Governed AI Agent Detection and Response capabilities. The additions extend the Securonix Unified Defense SIEM platform to help enterprises and managed security providers control data costs, improve detection coverage and response, and govern risks created by enterprise AI adopt