Circuit Wire — a daily news update from the Circuit.

INC ransomware has become the main group exploiting two SonicWall VPN flaws, weeks after the vendor disclosed and patched them on July 14. CyberScoop reported on August 4 that the prolific operation moved quickly once the bugs went public, chaining both to seize full control of exposed appliances. The group has claimed close to 900 victims across 71 countries since it first surfaced three years ago.

The flaws sit in SonicWall Secure Mobile Access (SMA) 1000 series appliances, which give remote staff and contractors a route into internal systems. One is a server-side request forgery bug, tracked as CVE-2026-15409. The other, CVE-2026-15410, allows command injection. Both affect the SMA1000 6210, 7210, and 8200v models. SonicWall released fixes and urged customers to install them at once, but attackers had already used the pair as zero-days for weeks.

Incident response firm Volexity traced the earliest signs of compromise to June 22 and linked them to a group it tracks as UTA0533. As BleepingComputer reported, the attackers abused an endpoint on the device to open hidden tunnels to internal services, then ran commands as root through the management console. From there they installed custom malware built for these appliances. Those early intrusions showed real technical skill, yet often failed to spread deeper into victim networks. INC ransomware emerged only after public disclosure, using different infrastructure and moving from break-in to encryption in short order.

New victims on INC's leak site include companies and government agencies in Australia, the United States, the United Arab Emirates, Colombia, and Switzerland. Several were then contacted by phone and email from people claiming to be the hackers, pressing them toward negotiations. "Since public disclosure, INC ransomware has emerged as the most commonly named threat actor actively weaponizing this vulnerability chain," said Brett Deroche of Rapid7. Rapid7 said it had stopped theft and encryption in most cases it saw, though ransomware landed in at least one. SonicWall remains one of the most targeted vendors in this space, and ten of its flaws in the US government's known-exploited catalog are tied to ransomware campaigns. Last week, researchers at Huntress logged a separate spree that hit 30 SonicWall customers in under two days.

Want a weekly roundup of the major stories shaping the security industry? The On The Circuit newsletter is read by more than 12,000 protection professionals.

Spotted something we should cover? Send tips and feedback via circuit-magazine.com.

Keep Reading