Signal INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
Summary
The Hacker News reported on August 3, 2026, that the INC ransomware group has become the dominant actor behind attacks chaining two SonicWall SMA1000 appliance vulnerabilities, CVE-2026-15409 and CVE-2026-15410, which allow unauthenticated attackers to open a WebSocket tunnel and escalate privileges to root. Both flaws were patched on July 14, 2026, and added to CISA's Known Exploited Vulnerabilities catalog the same day, but researchers found they had already been exploited as zero-days since at least June 22, 2026. INC ransomware activity accelerated through early August 2026, with the group posting a wave of new victims on its data leak site between July 17 and August 1, spanning private-sector and government organizations in the United States, Australia, Colombia, Switzerland, and the United Arab Emirates. The most recent victim was listed on August 2, 2026, bringing the group's claimed total to 885 victims. Several newly listed victims reported receiving emails and phone calls from unidentified parties claiming to represent a hacker group and offering negotiation contacts.
Classification
Evidence 1
- The Hacker News 2026-08-03 accessed 2026-08-05T02:02:05+00:00
Part of trends 0
No objects.
Directly linked issues 0
No objects.
Public id: fm-522fbbfbe78a