SMA1000 Access Turned Into Ransomware Fuel

The risk has shifted from simple intrusion to direct extortion: a successful SonicWall SMA1000 chain can now give an attacker full control of the appliance, enough to steal data and deploy ransomware from the same foothold. Patch-and-move-on thinking misses that the gateway itself can become the monetization point, not just the entry door. CyberScoop reports that INC ransomware is now the most commonly named actor using CVE-2026-15409 and CVE-2026-15410 together, after the flaws were already being exploited before SonicWall disclosed and patched them on July 14. Rapid7 said early activity starting June 22 came from common hosted infrastructure and was mostly unsuccessful, but post-disclosure INC activity used different infrastructure and moved from access to ransomware deployment in short order; at least one case included ransomware, and the same chain has been used for both theft and encryption. That leaves government and national-sector teams with a dual-blast-radius problem on a remote-access appliance: exposed data can be leaked even if the box is repaired, and availability can be hit in the same run.

Part of the PlainSec briefing for 2026-08-04

Every edition of this story: SMA1000 Access Turned Into Ransomware Fuel

Sources