Organizations Warned of Cisco Secure FMC Exploitation
Cisco and CISA have flagged exploitation of CVE-2026-20079, a vulnerability disclosed in March 2026.
The post Organizations Warned of Cisco Secure FMC Exploitation appeared first on SecurityWeek.
Cisco and CISA have flagged exploitation of CVE-2026-20079, a vulnerability disclosed in March 2026.
The post Organizations Warned of Cisco Secure FMC Exploitation appeared first on SecurityWeek.
Researchers said INC ransomware, one of the most active ransomware groups globally, has been the main attacker exploiting a pair of SonicWall zero-days soon after they were disclosed last month.
The prolific ransomware-as-a-service operation wasn’t the first group to exploit the flaws, which were actively exploited for three weeks before the vendor disclosed and patched the defects July 14, but it has been the most assertive and concerning group to target and chain both vulnerabilities together for full access.
“Since public disclosure, INC ransomware has emerged as the most commonly named threat actor actively weaponizing this vulnerability chain,” Brett Deroche, director of incident response at Rapid7, told CyberScoop. “While Inc is the name driving the post-disclosure wave, we can’t attribute the full body of exploitation to INC specifically.”
SonicWall did not respond to a request for comment.
The SonicWall vulnerabilities — CVE-2026-15409 and CVE-2026-15410 — are the latest in a series of security issues confronting the vendor’s customers, including actively exploited zero-days, previously disclosed defects, and an attack last year that allowed a state-sponsored threat group to steal the firewall configurations of every SonicWall customer.
Just last week, Huntress researchers spotted an attack spree that compromised 30 SonicWall customers in less than two days.
Ransomware groups have taken a special interest in SonicWall. Ten of the 17 SonicWall defects added to the Cybersecurity and Infrastructure Security Agency’s known exploited vulnerabilities (KEV) catalog since late 2021 are known to be used in ransomware campaigns.
INC ransomware, which has claimed nearly 900 victims across 71 countries since it was first discovered three years ago, is just the latest financially-motivated group to target SonicWall customers.
Researchers haven’t determined how many organizations have been impacted by the latest SonicWall zero-days, including attacks linked to INC ransomware.
“Attribution here isn’t a single clean answer. The earliest exploitation we observed, beginning June 22, traced back to common hosted infrastructure, though those attacks were largely unsuccessful,” Deroche said.
“INC’s confirmed activity that we’ve observed came after public disclosure, using different infrastructure and moving from initial access to ransomware deployment in short order. That’s a meaningfully different operational tempo and skill level than what we saw pre-disclosure,” he added.
Deroche said Rapid7 has successfully prevented data theft and encryption in the majority of recent cases, yet noted ransomware was deployed in at least one case the security vendor observed.
Yet, there could be other attacks outside the purview of Rapid7’s telemetry. INC ransomware has listed multiple new alleged victims on its data leak site, including organizations and government agencies in Australia, the United States, the United Arab Emirates, Colombia and Switzerland, Resecurity said in a blog post Saturday.
The company said it has aided several victims with incident response, and learned multiple victims received emails and phone calls from alleged hackers who pressured them to engage in negotiations.
The post Prolific ransomware group behind SonicWall zero-day attacks appeared first on CyberScoop.
Huntress researchers spotted an active and ongoing series of attacks targeting SonicWall VPN and firewall accounts, which compromised 30 organizations in less than two days, the company said in a threat advisory Tuesday.
The credential stuffing campaign started Saturday and grew rapidly, ultimately compromising 92 unique user accounts during the next 41 hours, according to Huntress. Researchers said the attacks were broad and opportunistic, hitting various SonicWall devices, rather than targeting specific types of organizations.
SonicWall hasn’t released a security advisory about the malicious activity as of press time. A spokesperson told CyberScoop the company is still investigating and hopes to have more information soon.
The attacks ended — at least for now — as abruptly as they began. The last compromise occurred Monday, according to Michael Tigges, principal tactical response analyst at Huntress.
“This fits campaign trends,” he said. “A rash of compromise will break out, followed by silence until the adversary rotates infrastructure.”
Attackers, which haven’t been identified, have also refrained from initiating any post-compromise activity, indicating the intrusions could be pre-positioning for future attacks.
“With local network access, the sky is essentially the limit for most networks that do not have proper topology controls in place,” Tigges said.
Huntress’ observations are limited to telemetry it collects from its customers, meaning all of the identified victims were Huntress customers using SonicWall devices, so the number of organizations impacted could be greater.
Researchers haven’t identified a root cause for the attacks, noting that they begin with authorized logins. Attackers are validating credentials against remote access portals to compromise as many vulnerable accounts as possible, the cybersecurity vendor and threat intelligence firm said.
“This could be an aggregation of stealer malware logs, previously compromised SonicWall configuration files, or historic CVE compromise that resulted in more credentials than the adversary could use at the time,” Tigges said.
In 2025, an undisclosed state-sponsored threat actor intruded SonicWalls’s cloud environment and stole firewall configurations of every customer.
SonicWall customers have also been hit by a barrage of actively exploited zero-days, including a pair of zero-days that were exploited for three weeks before the vendor disclosed and patched the defects earlier this month, and previously disclosed defects in SonicWall devices for years.
Seventeen defects affecting the vendor’s products have been added to CISA’s known exploited vulnerabilities catalog since late 2021. Ten of those defects are known to be used in ransomware campaigns, according to CISA, including a wave of about 40 Akira ransomware attacks between mid-July and early August 2025.
“Edge devices are one of the most targeted interfaces, comprising over 70% of active intrusions triaged by Huntress, including the overwhelming majority of ransomware deployments,” Tigges said. “Organizations that do not spend significant time architecting secure remote access solutions and networks that are resilient to edge-device compromise will likely continue to feel the burn in the coming months and years.”
The post Huntress warns about attack spree that hit 30 SonicWall customers in 2 days appeared first on CyberScoop.
![]()
Kent Ickler & Jordan Drysdale // BHIS Webcast and Podcast This post accompanies BHIS’s webcast recorded on August 7, 2018, Active Directory Best Practices to Frustrate Attackers, which you can view below. […]
The post Active Directory Best Practices to Frustrate Attackers: Webcast & Write-up appeared first on Black Hills Information Security, Inc..