The INC Ransomware group is actively exploiting two critical vulnerabilities in SonicWall SMA 1000 VPN appliances to break into corporate networks. Australian organisations are confirmed among the victims.
The flaws — CVE-2026-15409 (CVSS 10) and CVE-2026-15410 (CVSS 7.2) — let an unauthenticated attacker open a WebSocket tunnel to restricted services and escalate to root. Patches have been available since mid-July, but the vulnerabilities were exploited as zero-days from at least 22 June. INC Ransomware has claimed 885 victims to date and is accelerating, with new listings appearing daily through early August.
What makes this campaign especially dangerous is what the attackers steal on the way in. According to Resecurity’s analysis, they’re extracting stored credentials, active session databases, and — critically — TOTP multi-factor authentication seeds. That means MFA enabled on your VPN won’t help if the appliance storing those seeds is compromised. We regularly see businesses across Sydney and regional NSW assume MFA alone covers their VPN — it doesn’t, once the device itself is owned.
What to do now
If your business uses a SonicWall SMA 1000 series appliance, patch to the latest firmware immediately. If you haven’t patched since mid-July, treat it as a potential compromise: rotate all credentials, revoke active sessions, and re-seed your MFA tokens. Check your logs for unusual activity on the /wsproxy endpoint.
Not sure whether your VPN gateway is affected? Our cybersecurity team can check your environment and help lock things down — get in touch.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
