A recent wave of ransomware attacks has been linked to the exploitation of vulnerabilities in SonicWall's SMA1000 appliances, with the INC Ransomware gang specifically targeting these devices to gain root access and facilitate lateral movement. The attackers are leveraging newly discovered flaws to compromise the security of these appliances, which are widely used in enterprise networks. The vulnerabilities, if left unpatched, can allow malicious actors to gain control of the affected systems and demand ransom in exchange for restoring access to the compromised data. This campaign highlights the importance of keeping security appliances up to date with the latest patches, as failure to do so can have devastating consequences. The fact that these vulnerabilities are being actively exploited by ransomware gangs1 underscores the need for prompt action to mitigate these threats, so what matters most to security practitioners is the urgent need to patch and secure their SonicWall appliances to prevent similar attacks.