A prominent ransomware group, INC ransomware, has been identified as the primary exploiter of two recently disclosed SonicWall zero-day vulnerabilities. Following the public disclosure of these flaws on July 14, INC ransomware emerged as the most aggressive group to target and chain both vulnerabilities together, allowing for full access to compromised systems1. The group's exploits began after an initial three-week period of active exploitation by other actors, prior to the vendor's disclosure and patching of the defects. INC ransomware's assertive exploitation of these zero-days is particularly concerning, given the group's reputation as one of the most active ransomware-as-a-service operations globally. The fact that INC ransomware has been able to leverage these zero-days to gain full access to systems underscores the challenges faced by defenders in keeping pace with emerging threats, so what matters most to practitioners is the need to prioritize swift patching and mitigation strategies to stay ahead of such exploits.
Prolific ransomware group behind SonicWall zero-day attacks
⚠️ Critical Alert
Why This Matters
Zero-day exploitation means the vulnerability is being used before patches exist — defenders are already behind.
References
- CyberScoop. (2026, August 4). Prolific ransomware group behind SonicWall zero-day attacks. Cyberscoop. https://cyberscoop.com/inc-ransomware-sonicwall-zero-day-attacks/
Original Source
CyberScoop
Read original →