INC Ransomware is exploiting vulnerabilities in SonicWall SMA 1000 as part of its extortion tactics, utilizing phone calls and emails to pressure victims. The research from Resecurity indicates that these methods have been particularly aggressive since August 2026, with attacks targeting organizations globally. Two critical vulnerabilities, CVE-2026-15409 and CVE-2026-15410, have been highlighted for their role in aiding Initial Access Brokers (IABs) in unauthorized access.
Organizations are advised to promptly patch their systems and investigate for any signs of compromise, as failure to do so leaves them vulnerable to further attacks. A specific example mentions a threat actor reaching out via the phone, indicating a coordinated effort to intimidate victims into compliance.