🔴 Critical  |  Source: The Hacker News


The INC Ransomware group has been identified as the primary threat actor actively exploiting recently disclosed vulnerabilities in SonicWall SMA 1000 series VPN appliances. Activity has accelerated significantly since August 2026, with multiple victims listed on the group’s data leak site. This is particularly concerning as VPN appliances sit at the network perimeter and their compromise can provide attackers with broad access to internal and cloud-connected environments.

Security Architect’s Take: If your organisation uses SonicWall SMA 1000 series appliances, apply available patches immediately and audit access logs for signs of exploitation or unauthorised sessions. Consider temporarily restricting management interfaces to trusted IP ranges and review any cloud environment access that may be reachable via the compromised VPN.

Original advisory: INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws