SonicWall’s Zero-Day Problem: What Small Businesses Need to Know About INC Ransomware

18th August 2026 | Blog SonicWall’s Zero-Day Problem: What Small Businesses Need to Know About INC Ransomware

Author: Craig Taylor

I got started nearly 35 years ago in Cybersecurity working for a firewall company. Back then the WWW did not exist, email was a text based tool that was opening communications like never before. My psychology degree didn’t help me much initially, but those O’Reilly books – well they became my bible. TCP/IP, DNS & Bind, SMTP, does anyone reading this remember passive FTP?

Back to firewalls, we spent too much time convincing companies connecting their internal networks (Token Ring, IPX/SPX, Vines, NetBeui, Appletalk) to the Internet. Firewalls were split into two camps – Proxy-based and Stateful Inspection (Checkpoint). They were the major security perimeter protecting most companies pre and post-WWW. When a firewall had a security issue, the highest priority in anyone’s world was patching or mitigating that risk.

With Frontier Models systematically testing software, including firewalls, with more capabilities than any human ever had, it’s no wonder we’re seeing a spate of vulnerability announcements and patches like never before witnessed in history! Across the major vendors, in the past 6 months, we’ve seen not a doubling or tripling of patches, but 10x to 25x more patches than ever before!

That’s the context with which I write about two recent zero-days found in SonicWall’s firewall. They are not the only Firewall vendor to have zero-days, rather, they are emblematic of a recent explosion in Frontier AI penetration testing and vulnerability identification. This is the early waves of a storm that’s coming. The storm could be a category 5 hurricane leading to more breaches than we’ve seen in recent history. According to this Five Eyes advisory, we have months to prepare, not years.

My advice to all of you? Get busy with an AI readiness assessment. Focus on these 6 things:

  1. Reduce Attack Surface: turn down ports/protocols from the Internet. Boarding up windows and doors.
  2. Patch Faster: automate patching where permitted, shorten patch windows to the barest minimum possible.
  3. Isolate aging systems that cannot be upgraded or patched: short term fix. Longer term, use AI to port to modern developer languages and support.
  4. Reduce Sensitive/Critical Data: eliminate as much archival data as you can from your internal networks as possible. In a breach you do NOT want to be contacting clients from 10 years ago, let alone 25 years ago.
  5. Deploy a Honeypot: for quick detection of a breach giving you a head start to preventing enormous damage to your business.
  6. Continue User Education: while frontier AI models will cause trouble for the next year or two, before and after this storm, humans will remain the weakest link in your defenses. Continue to encourage engagement, reward good behaviors, and recognize high performers publicly.

The article below covers a single vendor, but this will apply to every vendor you use. Their bug bounty programs are paused because they cannot keep up with submissions. Their developers are overwhelmed with bug fixes to be tested and deployed. Things are heating up and it’s all hands on deck… the time to prepare and batten down the hatches is now. Don’t wait until it’s too late.

What Happened with SonicWall

Security AI researchers found two vulnerabilities in SonicWall firewalls, tracked as CVE-2026-15409 and CVE-2026-15410. Attackers exploited both flaws for about three weeks before SonicWall released a patch on July 14. During those three weeks, hackers chained the two vulnerabilities together to gain full access to affected devices, steal data, and lock networks down with ransomware.

Who’s Behind It

A ransomware group named INC emerged as the most active attacker exploiting these flaws after the patch came out. INC has run a ransomware-for-hire business since 2023 and has claimed close to 900 victims across 71 countries. Security firm Rapid7 tracked the group’s activity and found INC moved from breaking in to deploying ransomware faster than earlier attackers who tested the same vulnerabilities before the public disclosure.

Rapid7 said it stopped data theft and encryption in most recent cases it responded to, though ransomware was deployed successfully in at least one incident. Another firm, Resecurity, found INC listed new victims from Australia, the United States, the United Arab Emirates, Colombia, and Switzerland on its dark web leak site. Some victims received calls and emails from people pressuring them to pay.

Why This Matters for Your Business

This is not the first security issue tied to SonicWall devices. Ten of the seventeen SonicWall vulnerabilities added to the federal government’s Known Exploited Vulnerabilities list since 2021 tie back to ransomware campaigns. Last week alone, researchers spotted an attack spree that hit 30 SonicWall customers in two days using stolen login credentials.

If your business runs a SonicWall firewall, or any internet-facing security device, this pattern applies to you too. Attackers target popular, widely deployed hardware because one working exploit affects thousands of organizations using the same equipment.

Practical Tips to Implement Today

  • Patch Faster: With SonicWall 7.1.1 or later, you can enable automated firmware updates during fixed schedules. Enable this nightly for between 1 and 2am. Given the pace of attacks following patch releases, this is a prudent measure.
  • Reduce Attack Surface: Review the ports and protocols you allow through your firewall inbound. Pay attention to VPN traffic or other one-off solutions. If you simply must tunnel SSH through, limit it to specific online IP addresses rather than ANY IP.
  • Identify any Signs of Intrusion: Check your logs for unusual activity going back to late June. Look for login attempts, config changes, or traffic you don’t recognize.
  • Proactively change Admin passwords and reset credentials tied to your firewall and VPN, especially if you have not rotated them recently.
  • Validate that multi-factor authentication is enabled for all remote access (no exceptions have been granted). This one habit stops most credential-based break-ins before they start.

None of these steps require a big budget or a dedicated security team. A few focused hours protect your business from becoming the next name on a leak site.

The CyberHoot Takeaway

Firewalls sometimes fail and when they do, it can be a big deal. Vendors patch more quickly today than ever before. Attackers adapt and attack more quickly too. Just when we didn’t think things could speed up any more, they do. Enabling daily firmware updates may sound risky, but the question to ask is this: Is a rare outage from a failed firmware install better than a breach?

Your Next Move

Set aside an hour today to review your firewall’s setup. Enable automated windows for firmware updates (daily if possible). Close unneeded ports, confirm MFA on all remote access solutions, reduce data on your internal network, and deploy a honeypot.

Forward this article to whoever handles IT at your company, even if that person is you. A few proactive measures today will provide you peace of mind, a better chance against the attack speeds we see today, and some defensible proactive measures you can share with senior leadership in the face of growing concerns around AI frontier model attacks. Oh, and always remember to Hoot Up!


Sources:


Frequently Asked Questions

What Sonicwall Vulnerabilities (CVE-2026-15409 and CVE-2026-15410) were announced recently? They are two zero-day vulnerabilities affecting SonicWall firewalls that were exploited in the wild for about three weeks before SonicWall disclosed and patched them on July 14, 2026. Attackers have been chaining the two flaws together to gain full access to affected devices.

Who is behind the attacks? Multiple actors probed the flaws before they were publicly disclosed, but INC ransomware, a ransomware-as-a-service group active since 2023, has become the most prominent and effective attacker exploiting the vulnerability chain since disclosure.

How many organizations have been affected? The exact number is unknown. Rapid7 has responded to several incidents and prevented data theft or encryption in most of them, but researchers say the full scope likely extends well beyond what any single security vendor can see. INC has listed new victims spanning several countries on its leak site.

Is this the first time SonicWall has faced this kind of issue? No. SonicWall has dealt with a string of security problems in recent years, including other actively exploited zero-days, a mass credential-based attack spree that hit 30 customers in two days, and a prior incident in which attackers stole firewall configuration files from every SonicWall customer.

What should SonicWall customers do now? Apply the available patches immediately, review logs for suspicious activity going back to late June, rotate any credentials associated with affected devices, and closely monitor internet-facing SonicWall appliances for unusual behavior.

Latest Blogs

Stay sharp with the latest security insights

Discover and share the latest cybersecurity trends, tips and best practices – alongside new threats to watch out for.

SonicWall’s Zero-Day Problem: What Small Businesses Need to Know About INC Ransomware

SonicWall’s Zero-Day Problem: What Small Businesses Need to Know About INC Ransomware

Author: Craig Taylor I got started nearly 35 years ago in Cybersecurity working for a firewall company. Back...

Read more
Your Team Is Already Talking to AI. Here’s How to Keep IT Safe.

Your Team Is Already Talking to AI. Here’s How to Keep IT Safe.

AI tools moved into our everyday work-life incredibly fast! Someone on your team writes an email with ChatGPT....

Read more
What Flock Cameras Teach Every Business About Data and Trust

What Flock Cameras Teach Every Business About Data and Trust

You have seen them before. A small black camera on a pole near an intersection, a solar panel on top, quietly...

Read more