preloader

· digital-security devops ransomware cve sonicwall vpn remote-access vulnerability-management europe incident-response

You Patched SonicWall Weeks Ago. INC Ransomware May Already Have Your Passwords

Source: The Hacker News

Three weeks ago the story was a pair of chained SonicWall SMA 1000 zero-days, CVE-2026-15409 and CVE-2026-15410, giving an unauthenticated attacker a direct route to full appliance control. This week the story is who has been using them since, and what they took while they had the chance. Resecurity and other researchers now identify INC Ransomware as the dominant group behind ongoing exploitation, with victims published on its dark web leak site accelerating sharply since the start of August.

Patching the hole does not undo what walked through it

The detail that should change how organisations respond is what INC actually does once inside. Rather than moving straight to encryption, the group has been extracting credentials, active session tokens and TOTP seeds, the secrets that generate one-time multi-factor codes, before doing anything visible. That gives attackers a route back into an environment that has nothing to do with the SonicWall appliance itself. A device patched today can still leave an organisation exposed if the accounts and MFA tokens harvested from it during the three-week window before a fix existed were never rotated.

A pattern spreading past the SonicWall install base

INC has claimed 885 victims to date, with private-sector and government organisations across multiple countries appearing on its leak site through early August. The group’s use of stolen sessions and TOTP seeds is not appliance-specific behaviour, it is a template for how they treat any remote access compromise, and organisations running other VPN or SSL-gateway products should read this as a preview of what a similar flaw elsewhere would look like in their environment, not as a SonicWall-only concern.

What actually needs to happen now

If your organisation runs SMA 1000 appliances, applying SonicWall’s hotfix is necessary but not sufficient. Every credential and active session tied to the appliance during the exposure window, from 22 June through to your patch date, should be treated as compromised: force password resets, reissue MFA seeds rather than just requiring re-enrolment, and review authentication logs for logins from unfamiliar locations or at unusual hours in that period. Skipping straight to “we patched it” is exactly the gap INC is counting on.

If you need help establishing whether credentials or sessions tied to your remote access infrastructure were exposed during this window, or want a structured incident response plan in place before the next appliance advisory lands, contact Excello Digital. We help European organisations turn a patch notification into a complete response, not just a version number update.

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!