SonicWall’s Zero-Day Problem: What Small Businesses Need to Know About INC Ransomware

18th August 2026 | Blog SonicWall’s Zero-Day Problem: What Small Businesses Need to Know About INC Ransomware

Author: Craig Taylor

I cannot visit a coffee shop, go for a round of golf, have a friendly conversation with an old friend without AI coming up. What’s it doing to your life, your job, your company. Everything seems to focus on AI Frontier models and AI’s impact on our day-to-day lives. AI centers in the SonicWall Zero-Day article below front and center because, well, these zero days were most likely discovered by a frontier model, weaponized by a frontier model with a proof of concept, and then mitigated by patches coded by a frontier AI model.

Frontier AI models are now systematically probing all online software, including firewalls and network devices for vulnerabilities. They test at a speed and depth no human team has ever matched. In the past six months, major firewall vendors have released 10x to 25x more patches than any prior period. Bug bounty programs at some vendors are paused because submissions are outpacing review capacity. Development teams are overwhelmed with fixes to test and deploy. The Five Eyes alliance issued a joint advisory in June 2026 warning that organizations have months to prepare, not years. Two recent zero-day vulnerabilities in SonicWall firewalls are not an isolated event. They represent a pattern now affecting every vendor with internet-facing products.

The article below covers a single vendor, but this will apply to every vendor you use. Their bug bounty programs are paused because they cannot keep up with submissions. Their developers are overwhelmed with bug fixes to be tested and deployed. Things are heating up and it’s all hands on deck… the time to prepare and batten down the hatches is now. Don’t wait until it’s too late.

What Happened with SonicWall

Security AI researchers found two vulnerabilities in SonicWall firewalls, tracked as CVE-2026-15409 and CVE-2026-15410. Attackers exploited both flaws for about three weeks before SonicWall released a patch on July 14. During those three weeks, hackers chained the two vulnerabilities together to gain full access to affected devices, steal data, and lock networks down with ransomware.

Who’s Behind It

A ransomware group named INC emerged as the most active attacker exploiting these flaws after the patch came out. INC has run a ransomware-for-hire business since 2023 and has claimed close to 900 victims across 71 countries. Security firm Rapid7 tracked the group’s activity and found INC moved from breaking in to deploying ransomware faster than earlier attackers who tested the same vulnerabilities before the public disclosure.

Rapid7 said it stopped data theft and encryption in most recent cases it responded to, though ransomware was deployed successfully in at least one incident. Another firm, Resecurity, found INC listed new victims from Australia, the United States, the United Arab Emirates, Colombia, and Switzerland on its dark web leak site. Some victims received calls and emails from people pressuring them to pay.

Why This Matters for Your Business

This is not the first security issue tied to SonicWall devices. Ten of the seventeen SonicWall vulnerabilities added to the federal government’s Known Exploited Vulnerabilities list since 2021 tie back to ransomware campaigns. Last week alone, researchers spotted an attack spree that hit 30 SonicWall customers in two days using stolen login credentials.

If your business runs a SonicWall firewall, or any internet-facing security device, this pattern applies to you too. Attackers target popular, widely deployed hardware because one working exploit affects thousands of organizations using the same equipment.

Practical Tips to Implement Today

  • Patch Faster: With SonicWall 7.1.1 or later, you can enable automated firmware updates during fixed schedules. Enable this nightly for between 1 and 2am. Given the pace of attacks following patch releases, this is a prudent measure.
  • Reduce Attack Surface: Review the ports and protocols you allow through your firewall inbound. Pay attention to VPN traffic or other one-off solutions. If you simply must tunnel SSH through, limit it to specific online IP addresses rather than ANY IP.
  • Identify any Signs of Intrusion: Check your logs for unusual activity going back to late June. Look for login attempts, config changes, or traffic you don’t recognize.
  • Proactively change Admin passwords and reset credentials tied to your firewall and VPN, especially if you have not rotated them recently.
  • Validate that multi-factor authentication is enabled for all remote access (no exceptions have been granted). This one habit stops most credential-based break-ins before they start.

None of these steps require a big budget or a dedicated security team. A few focused hours protect your business from becoming the next name on a leak site.

The CyberHoot Takeaway

Firewalls sometimes fail and when they do, it can be a big deal. Vendors patch more quickly today than ever before. Attackers adapt and attack more quickly too. Just when we didn’t think things could speed up any more, they do. Enabling daily firmware updates may sound risky, but the question to ask is this: Is a rare outage from a failed firmware install better than a breach?

Your Next Move

Set aside an hour today to review your firewall’s setup. Enable automated windows for firmware updates (daily if possible). Close unneeded ports, confirm MFA on all remote access solutions, reduce data on your internal network, and deploy a honeypot.

Forward this article to whoever handles IT at your company, even if that person is you. A few proactive measures today will provide you peace of mind, a better chance against the attack speeds we see today, and some defensible proactive measures you can share with senior leadership in the face of growing concerns around AI frontier model attacks. Oh, and always remember to Hoot Up!


Sources:


Frequently Asked Questions

What Sonicwall Vulnerabilities (CVE-2026-15409 and CVE-2026-15410) were announced recently? They are two zero-day vulnerabilities affecting SonicWall firewalls that were exploited in the wild for about three weeks before SonicWall disclosed and patched them on July 14, 2026. Attackers have been chaining the two flaws together to gain full access to affected devices.

Who is behind the attacks? Multiple actors probed the flaws before they were publicly disclosed, but INC ransomware, a ransomware-as-a-service group active since 2023, has become the most prominent and effective attacker exploiting the vulnerability chain since disclosure.

How many organizations have been affected? The exact number is unknown. Rapid7 has responded to several incidents and prevented data theft or encryption in most of them, but researchers say the full scope likely extends well beyond what any single security vendor can see. INC has listed new victims spanning several countries on its leak site.

Is this the first time SonicWall has faced this kind of issue? No. SonicWall has dealt with a string of security problems in recent years, including other actively exploited zero-days, a mass credential-based attack spree that hit 30 customers in two days, and a prior incident in which attackers stole firewall configuration files from every SonicWall customer.

What should SonicWall customers do now? Apply the available patches immediately, review logs for suspicious activity going back to late June, rotate any credentials associated with affected devices, and closely monitor internet-facing SonicWall appliances for unusual behavior.

Latest Blogs

Stay sharp with the latest security insights

Discover and share the latest cybersecurity trends, tips and best practices – alongside new threats to watch out for.

When “Apple Support” Calls You Back, Hang Up

When “Apple Support” Calls You Back, Hang Up

Author: Katie Boquetti | Editorial: Craig Taylor Editorial by Craig Taylor: This week's blog has a...

Read more
Meet Manic: The Android Malware With a Sneaky Backup Plan

Meet Manic: The Android Malware With a Sneaky Backup Plan

Every so often a piece of malware comes along with a trick clever enough to make security researchers pause and...

Read more
SonicWall’s Zero-Day Problem: What Small Businesses Need to Know About INC Ransomware

SonicWall’s Zero-Day Problem: What Small Businesses Need to Know About INC Ransomware

Author: Craig Taylor I cannot visit a coffee shop, go for a round of golf, have a friendly conversation with...

Read more