INC Ransomware has been leveraging a zero-day exploit in SonicWall's Secure Mobile Access (SMA) 1000 to target global organizations, with a notable surge in operations since early August. The threat actor has been using pressure tactics, including phone calls and emails, to extort victims during its campaigns. Resecurity's research reveals that INC Ransomware has become a dominant force in exploiting the SonicWall vulnerability, affecting organizations in multiple countries, including the United States, Australia, and the United Arab Emirates. The exploit allows the group to compromise SMA 1000 devices, enabling them to launch ransomware attacks. This exploitation is particularly concerning as it occurs before patches are available, putting defenders at a disadvantage1. The use of zero-day exploits by INC Ransomware underscores the need for organizations to prioritize vulnerability management and implement robust security measures to prevent such attacks, as the lack of patches leaves them vulnerable to these types of threats.