IntelliOS Threat Intel Operating System
Sign In
© 2026 IntelliOS
AboutBlogsInsightsNewsroomContactLegal

IntelliOS panda

INC Ransom Exploits SonicWall SMA1000 Zero Days

Executive bottom line: internet-facing SonicWall SMA1000 appliances running affected versions should be treated as emergency remediation and retrospective compromise-assessment priorities. CVE-2026-15410 normally requires administrator-level access, but CVE-2026-15409 can expose its privileged local workflow without a conventional administrator login; the completed chain can give an outside attacker root control of the appliance. Upgrade now: install 12.4.3-03453 or later, or 12.5.0-02835 or later across affected 6210, 7210, 8200v, and CMS deployments. SonicWall provides no workaround. Do not stop at patching: if the appliance was internet-facing before upgrade, determine whether the attacker reached local services, executed commands, changed configuration, installed persistence, or used stolen credentials. Preserve before rebuilding: capture logs, configuration, memory where practical, filesystem evidence, authentication records, network flows, and relevant downstream Windows/identity telemetry before reimage or redeployment. Use a trusted configuration: SonicWall says configuration backups should predate installation of the December hotfix baselines 12.4.3-03245 or 12.5.0-02283. If no earlier backup exists, closely audit the configuration for tampering before recovery. Reset exposed trust: invalidate sessions; change user, administrator, LDAP/service-account, and other reachable credentials; reset TOTP seeds after confirmed compromise; and review certificates or secrets stored on or accessible to the appliance. Use the current CISA ransomware field: catalog version 2026.08.03 marks known ransomware campaign use as Known for both CVEs. This is authoritative at the CVE level but does not identify INC, UTA0533, a victim, or the outcome of every intrusion. Continued INC weaponization is now better supported: Resecurity assesses that INC accelerated use of the chain, and The Hacker News published a direct Rapid7 statement describing INC as the dominant actor actively weaponizing it. Treat that as source-qualified campaign attribution, not proof that UTA0533 is INC or that every INC leak-site victim entered through SMA1000. Separate exposure from impact: a vulnerable version establishes risk. Local evidence establishes whether compromise, lateral movement, data access, or ransomware occurred. Keep attribution qualified: use INC Ransom as a reported association and UTA0533 as Volexity's separate activity-cluster label unless stronger evidence connects them.

Research Framing

User Topic

INC Ransom exploiting two KEV-listed SonicWall SMA1000 zero days

Field: User Topic Value: INC Ransom exploiting two KEV-listed SonicWall SMA1000 zero days

Decision Question

Should leaders treat an exposed or recently patched SMA1000 appliance as a potential incident requiring credential, session, persistence, and internal-access validation rather than as a patch-only event?

Field: Decision Question Value: Should leaders treat an exposed or recently patched SMA1000 appliance as a potential incident requiring credential, session, persistence, and internal-access validation rather than as a patch-only event?

Interpreted Questions

What is actually happening on affected SMA1000 appliances? How do CVE-2026-15409 and CVE-2026-15410 combine to move an unauthenticated internet attacker from the public edge to root? Which parts of the INC and ransomware reporting are established, which remain source-qualified, who is exposed, and what should leaders authorize first?

Field: Interpreted Questions Value: What is actually happening on affected SMA1000 appliances? How do CVE-2026-15409 and CVE-2026-15410 combine to move an unauthenticated internet attacker from the public edge to root? Which parts of the INC and ransomware reporting are established, which remain source-qualified, who is exposed, and what should leaders authorize first?

Initial Observations

Official and primary technical sources establish active zero-day exploitation of internet-facing SMA1000 appliances, a no-login-required SSRF/WebSocket tunnel to appliance-local services, a path-traversal route to root command execution, credential and session theft, persistence, and attempts to enter internal networks. CISA now marks both CVEs' known ransomware campaign use as Known. The specific INC association remains source-qualified: Dark Reading reported Rapid7's initial assessment; Resecurity later assessed continued INC weaponization; and The Hacker News published a direct Rapid7 statement that INC had emerged as the dominant actor actively weaponizing the chain. Rapid7's public technical article still does not name INC or ransomware, and Volexity's UTA0533 label remains separate.

Field: Initial Observations Value: Official and primary technical sources establish active zero-day exploitation of internet-facing SMA1000 appliances, a no-login-required SSRF/WebSocket tunnel to appliance-local services, a path-traversal route to root command execution, credential and session theft, persistence, and attempts to enter internal networks. CISA now marks both CVEs' known ransomware campaign use as Known. The specific INC association remains source-qualified: Dark Reading reported Rapid7's initial assessment; Resecurity later assessed continued INC weaponization; and The Hacker News published a direct Rapid7 statement that INC had emerged as the dominant actor actively weaponizing the chain. Rapid7's public technical article still does not name INC or ransomware, and Volexity's UTA0533 label remains separate.[1] [2] [3] [4] [5] [6] [7] [8] [9] [10]

Fact / Analysis / Unknown Boundaries

Official sources establish exploitation mechanics, affected scope, remediation, and known ransomware use. The INC association remains source-qualified; Rapid7's public technical article does not itself name INC, and Volexity's UTA0533 activity is retained as a separate attribution label.

Field: Fact / Analysis / Unknown Boundaries Value: Official sources establish exploitation mechanics, affected scope, remediation, and known ransomware use. The INC association remains source-qualified; Rapid7's public technical article does not itself name INC, and Volexity's UTA0533 activity is retained as a separate attribution label.

Source Coverage

Field: Source Coverage

Tier 0 - Most Trusted

4

Field: Tier 0 - Most Trusted Value: 4 4 3 1

Tier 1 - Authoritative

6

Field: Tier 1 - Authoritative Value: 6 6 5 1

Tier 2 - High-Value Research

4

Field: Tier 2 - High-Value Research Value: 4 4 0 4

Tier 3 - Corroborating News

8

Field: Tier 3 - Corroborating News Value: 8 6 2 6

Tier 4 - Community Signal

12

Field: Tier 4 - Community Signal Value: 12 12 0 12

Tier 5 - Custom Source

0

Field: Tier 5 - Custom Source Value: 0 0 0 0

Tier 6 - Custom Integrations with API/Keys

1

Field: Tier 6 - Custom Integrations with API/Keys Value: 1 1 0 1

Tier 7 - Inner Discovery

0

Field: Tier 7 - Inner Discovery Value: 0 0 0 0

Tier 8 - Expansion Research / AI Agent Delta

0

Field: Tier 8 - Expansion Research / AI Agent Delta Value: 0 0 0 0

Total

35

Field: Total Value: 35 33 10 25

SonicWall SMA1000 Exploitation Snapshot

2

KEV-listed CVEs

10.0

CVE-2026-15409 CVSS

7.2

CVE-2026-15410 CVSS

0

Available workarounds

Plain-English attack chain

Step 1

Reach

An internet attacker reaches the public SMA1000 WorkPlace service.

Step 2

Tunnel

The appliance is tricked into opening a WebSocket connection to services normally available only inside itself.

Step 3

Execute

The attacker reaches a weaker local service and obtains command execution under a limited appliance account.

Step 4

Become root

The second flaw normally requires administrator-level access to the hotfix-removal workflow. The first flaw reaches that privileged local workflow without a conventional administrator login, and a malicious path causes an attacker-controlled script to run as root.

Step 5

Pivot

Root access enables credential/session theft, persistent implants, traffic capture, and attempts to enter the internal network.

Not affected by this advisory: the SMA100 product line and SSL VPN functionality on SonicWall firewalls. SonicWall's product notice includes SMA1000 CMS across hypervisors alongside 6210, 7210, and 8200v. Validate actual product role and software version before making exposure statements.[1] [3] [4] [8]

Topic

This brief covers the active exploitation of two vulnerabilities in SonicWall SMA1000 secure remote-access appliances. These systems sit at a sensitive boundary: they accept connections from the internet, authenticate remote users, hold or process session and identity information, and connect approved users to internal business systems.

Attackers chained unauthenticated CVE-2026-15409 with CVE-2026-15410. The first vulnerability lets an outside attacker reach services that should be accessible only from the appliance itself. SonicWall classifies the second vulnerability as post-authentication because, exploited on its own, it requires administrator-level access to the appliance-management workflow. In the observed chain, however, the first flaw reaches the privileged localhost control service without a conventional administrator login; the second flaw then turns that access into commands running as root —the highest operating-system privilege.[1] [3] [4] [5] [6]

Rapid7 and Volexity independently document exploitation, credential access, appliance persistence, and attempts to move into internal networks. Dark Reading separately reports that Rapid7 connected the activity to INC Ransom and that at least one case progressed to ransomware. That ransomware and INC statement is therefore retained as reported attribution, not treated as a fact established in Rapid7's public technical article.[3] [4] [7]

Persona / Audience Lens

This product is written for executives, IT leaders, security managers, legal and privacy stakeholders, incident-response teams, network and identity administrators, MSPs, insurers, and other portfolio owners who need a practical scoping decision. Executives need to know which business services depend on the appliance and whether trust can be restored; counsel needs preserved facts rather than assumed impact; SOC/DFIR teams need appliance, identity, Windows, firewall, EDR, and network evidence; and network/IAM teams need to identify every session, credential, TOTP seed, service account, certificate, route, and downstream trust path that may require reset or review.

BLUF

Executive bottom line: internet-facing SonicWall SMA1000 appliances running affected versions should be treated as emergency remediation and retrospective compromise-assessment priorities. CVE-2026-15410 normally requires administrator-level access, but CVE-2026-15409 can expose its privileged local workflow without a conventional administrator login; the completed chain can give an outside attacker root control of the appliance.

Upgrade now: install 12.4.3-03453 or later, or 12.5.0-02835 or later across affected 6210, 7210, 8200v, and CMS deployments. SonicWall provides no workaround.[1] [3] [4] [8]

Do not stop at patching: if the appliance was internet-facing before upgrade, determine whether the attacker reached local services, executed commands, changed configuration, installed persistence, or used stolen credentials.

Preserve before rebuilding: capture logs, configuration, memory where practical, filesystem evidence, authentication records, network flows, and relevant downstream Windows/identity telemetry before reimage or redeployment.

Use a trusted configuration: SonicWall says configuration backups should predate installation of the December hotfix baselines 12.4.3-03245 or 12.5.0-02283. If no earlier backup exists, closely audit the configuration for tampering before recovery.[8]

Reset exposed trust: invalidate sessions; change user, administrator, LDAP/service-account, and other reachable credentials; reset TOTP seeds after confirmed compromise; and review certificates or secrets stored on or accessible to the appliance.[3]

Use the current CISA ransomware field: catalog version 2026.08.03 marks known ransomware campaign use as Known for both CVEs. This is authoritative at the CVE level but does not identify INC, UTA0533, a victim, or the outcome of every intrusion.[2]

Continued INC weaponization is now better supported: Resecurity assesses that INC accelerated use of the chain, and The Hacker News published a direct Rapid7 statement describing INC as the dominant actor actively weaponizing it. Treat that as source-qualified campaign attribution, not proof that UTA0533 is INC or that every INC leak-site victim entered through SMA1000.[9] [10]

Separate exposure from impact: a vulnerable version establishes risk. Local evidence establishes whether compromise, lateral movement, data access, or ransomware occurred.

Keep attribution qualified: use INC Ransom as a reported association and UTA0533 as Volexity's separate activity-cluster label unless stronger evidence connects them.

Executive Summary

Executive bottom line. These vulnerabilities can turn a security appliance that is supposed to control remote access into an attacker-controlled gateway. Because the chain begins without a valid account and ends with the appliance's highest level of privilege, leaders should authorize both emergency upgrades and a time-bounded compromise investigation for every appliance that was exposed before it was fixed.

What the first vulnerability does. CVE-2026-15409 is a server-side request forgery, or SSRF, vulnerability. In plain English, SSRF means an attacker can make a trusted server or appliance send a connection on the attacker's behalf. Imagine an outsider convincing a receptionist inside a locked building to open an internal door that the outsider could not reach directly. Here, the public SMA1000 service can be tricked into opening a WebSocket tunnel to "localhost" services—software listening only inside the appliance and normally hidden from the internet. The tunnel is bidirectional, so the attacker can send commands to and receive responses from those internal services without first presenting a valid SMA user session.[1] [3] [4] [5]

How the chain reaches root. SonicWall classifies CVE-2026-15410 as a post-authentication code-injection vulnerability because, when considered by itself, it requires administrator-level access to the SMA1000 Appliance Management Console workflow. That does not mean the observed attackers necessarily possessed or used a valid administrator password. CVE-2026-15409 gives an unauthenticated attacker a tunnel to the appliance's localhost control service on port 8188, effectively reaching the privileged hotfix-removal workflow without a conventional administrator login. A path-traversal sequence—characters such as../ that tell a system to move outside an intended folder—can then point the workflow at an attacker-created script. The appliance marks that script executable and runs it as root. Root is the Linux operating system's highest privilege: it can read or change nearly any file, alter services and startup behavior, capture traffic, install backdoors, and interfere with logs.[1] [3] [4] [6]

Why the tunnel and root access matter. A WebSocket is a persistent, two-way connection. Here it functions like a private pipe through the appliance, allowing an external attacker to converse with services designed to trust local traffic. Once the attacker controls the operating system as root, a clean-looking web interface or version number cannot prove the appliance is trustworthy; on-box logs may be incomplete, modified, or lost after a reboot.

Why identity and recovery matter. Rapid7 observed theft of credentials, active session databases, and TOTP seed configurations. Volexity observed credential capture and attempts to authenticate from the appliance into customer networks. The hotfix closes the vulnerabilities, but it does not revoke stolen sessions, rotate passwords, reset MFA seeds, remove an implant already installed, or determine whether internal systems were reached.[3] [4]

Why the recovery point matters. SonicWall's product notice includes SMA1000 CMS across hypervisors in the affected scope. It also says configuration backups should be used only when they predate installation of the December hotfix baselines 12.4.3-03245 or 12.5.0-02283. If an earlier backup is not available, responders should closely audit the configuration for tampering rather than assuming a later backup is trustworthy.[8]

What investigators observed. Rapid7 reports targeted zero-day exploitation of internet-facing SMA1000 appliances, followed by command execution, theft of credentials/session databases/TOTP seed configurations, and VPN-less Active Directory authentication attempts originating from the appliance's internal IP address. Volexity reports appliance-specific persistence and malware: KNUCKLEBALL loaded Suo5 proxy and ORANGETAIL web-shell components, while the actor captured traffic and attempted to pivot further into the customer network.[3] [4]

What is known about INC and ransomware. Dark Reading reports that Rapid7 tied the activity to INC Ransom and that at least one investigated case progressed to ransomware. Rapid7's public technical article confirms exploitation and downstream credential/lateral-movement activity but does not itself name INC or ransomware. Volexity uses the temporary label UTA0533 for the activity it observed and does not publicly equate that label with INC. The defensible position is therefore high confidence in active exploitation and the technical chain, moderate confidence in the reported INC association, and no basis to assign every SMA1000 intrusion to one operator.[3] [4] [7]

What the August reporting adds. Resecurity says it observed INC activity accelerating at the beginning of August and assessed that some SMA1000 devices remained unpatched or compromised. The Hacker News separately published a direct statement from Rapid7 that INC had emerged as the dominant actor actively weaponizing the chain. These sources strengthen the continued-weaponization assessment but do not close the identity gap with Volexity's UTA0533 cluster. Resecurity's broader list of new INC leak-site victims is also not a confirmed SMA1000 victim list because the report does not establish the appliance chain as the entry path for each listing.[9] [10]

What leaders should authorize now. Identify every affected 6210, 7210, 8200v, and CMS deployment and its internet-exposure window; upgrade immediately; preserve appliance and adjacent evidence; investigate published behavioral indicators; invalidate sessions; rotate exposed credentials and service accounts; reset TOTP seeds where compromise is confirmed; and reimage physical appliances or redeploy virtual appliances when evidence establishes compromise or trust cannot be restored. Recover configuration only from a trusted pre-December-hotfix backup or closely audit the available configuration for tampering. CISA's live KEV catalog version 2026.08.03 now marks known ransomware campaign use as "Known" for both CVEs. That authoritative CVE-level field increases ransomware-risk confidence, but it does not identify an actor, victim, incident count, or prove that every exploitation attempt led to ransomware.[1] [2] [3] [8]

AI Agent Delta Updates

23-Jul-2026

PANDA baseline publication

Update Time: 23-Jul-2026 Agent / Monitor: PANDA baseline publication Delta Type: Published Evidence / Change: Created the brief and connected CARDS campaign, CVE, actor, alert, PANDA, and FORGE records. Affected Cards: Full brief Action Required: Begin remediation and scoping

23-Jul-2026

Source-bound editorial QA

Update Time: 23-Jul-2026 Agent / Monitor: Source-bound editorial QA Delta Type: Revised · v1.1 Evidence / Change: Expanded executive and technical explanations, corrected the Rapid7/Dark Reading boundary, and removed false actor linking. Affected Cards: Executive, attribution, related products, citations Action Required: Use corrected attribution language

23-Jul-2026

Publication layout and accessibility QA

Update Time: 23-Jul-2026 Agent / Monitor: Publication layout and accessibility QA Delta Type: Revised · v1.2 Evidence / Change: Standardized section structure, table hierarchy, typography, spacing, related-product presentation, and expand/collapse interactions. Affected Cards: Full brief Action Required: No intelligence change

23-Jul-2026

Source coverage reconciliation

Update Time: 23-Jul-2026 Agent / Monitor: Source coverage reconciliation Delta Type: Revised · v1.3 Evidence / Change: Expanded the source-planning record through Tier 8, reconciled the reviewed, candidate, selected, and not-used totals, and retained seven source-bound citations. Affected Cards: Research framing, source coverage, change log Action Required: Use v1.3 as product of record

23-Jul-2026

CVE authentication-boundary QA

Update Time: 23-Jul-2026 Agent / Monitor: CVE authentication-boundary QA Delta Type: Revised · v1.4 Evidence / Change: Clarified CVE-2026-15410's standalone administrator-level prerequisite and the chained localhost-control path. Affected Cards: Executive, CVE details, CARDS Action Required: Use source-bound privilege language

24-Jul-2026 9:04 AM ET

INC / SonicWall SMA1000 daily monitor

Update Time: 24-Jul-2026 9:04 AM ET Agent / Monitor: INC / SonicWall SMA1000 daily monitor Delta Type: Material · v1.5 Evidence / Change: Added SonicWall's CMS/all-hypervisors scope and trusted configuration-backup recovery guidance; revalidated KEV, NVD, Rapid7, Volexity, attribution, victims, fixes, and IOCs. Affected Cards: Scope, BLUF, executive, response, CVE, sources Action Required: Inventory CMS and validate recovery configuration

04-Aug-2026 9:04 AM ET

INC / SonicWall SMA1000 daily monitor

Update Time: 04-Aug-2026 9:04 AM ET Agent / Monitor: INC / SonicWall SMA1000 daily monitor Delta Type: Material · v1.6 Evidence / Change: CISA KEV catalog version 2026.08.03 changed known ransomware campaign use from Unknown to Known for both CVEs; vendor, NVD, Rapid7, Volexity, victim, fix, and IOC checks were otherwise unchanged. Affected Cards: BLUF, executive, Q&A, KEV, sources, CARDS Action Required: Use CISA's Known value without merging actor labels

06-Aug-2026 9:06 AM ET

INC / SonicWall SMA1000 daily monitor

Update Time: 06-Aug-2026 9:06 AM ET Agent / Monitor: INC / SonicWall SMA1000 daily monitor Delta Type: Material · v1.7 Evidence / Change: Added Resecurity's continued INC weaponization assessment and The Hacker News' direct Rapid7 attribution statement; explicitly excluded the broader INC leak-site cohort from the confirmed SMA1000 victim count and kept UTA0533 separate. Affected Cards: BLUF, executive, timeline, actors, victims, sources, CARDS Action Required: Hunt historical exposure; retain source-bound attribution

07-Aug-2026 1:00 PM ET

FORGE public-source monitor

Update Time: 07-Aug-2026 1:00 PM ET Agent / Monitor: FORGE public-source monitor Delta Type: Scheduled Evidence / Change: Checks for material changes in vendor guidance, exploitation, attribution, IOCs, victims, and remediation. Affected Cards: Source-dependent cards Action Required: Version only material deltas

Brief ID

PANDA-FTIB-INC-SONICWALL-SMA1000-2026-001

Current Brief Version

v1.7

Initial Publish Date

23-Jul-2026

First AI Agent Update Run

23-Jul-2026

AI Monitoring Updates Applied

7

Next Scheduled Monitor

Daily at 1:00 PM ET through 23-Jan-2027

Why It Matters

A security control becomes an entry point

SMA1000 appliances are intentionally reachable from the internet and trusted to broker access into private systems. Compromise reverses that relationship and makes the gateway an attacker foothold.

Theme: A security control becomes an entry point Why It Matters: SMA1000 appliances are intentionally reachable from the internet and trusted to broker access into private systems. Compromise reverses that relationship and makes the gateway an attacker foothold. Defender Implication: Treat exposure as both emergency remediation and a retrospective compromise-assessment problem.

Identity material expands the blast radius

Stolen passwords, sessions, LDAP service-account access, and TOTP seeds can outlive a software patch and support internal access or later re-entry.

Theme: Identity material expands the blast radius Why It Matters: Stolen passwords, sessions, LDAP service-account access, and TOTP seeds can outlive a software patch and support internal access or later re-entry. Defender Implication: Invalidate sessions and scope credential, service-account, MFA-seed, and certificate resets.

Root weakens the evidence source

An attacker with root can change files, startup scripts, routes, services, and logs. Rebooting can remove volatile evidence.

Theme: Root weakens the evidence source Why It Matters: An attacker with root can change files, startup scripts, routes, services, and logs. Rebooting can remove volatile evidence. Defender Implication: Preserve off-box and volatile evidence early; do not use a normal-looking interface as proof of trust.

Ransomware is a downstream outcome

Ransomware, if it occurs, follows appliance compromise, credential theft, discovery, and lateral movement. Waiting for encryption loses the prevention window.

Theme: Ransomware is a downstream outcome Why It Matters: Ransomware, if it occurs, follows appliance compromise, credential theft, discovery, and lateral movement. Waiting for encryption loses the prevention window. Defender Implication: Contain at the appliance and identity stages before business-wide impact becomes visible.

Containment can affect operations

Emergency isolation, reimage, credential rotation, and authentication resets may disrupt remote work and partner access.

Theme: Containment can affect operations Why It Matters: Emergency isolation, reimage, credential rotation, and authentication resets may disrupt remote work and partner access. Defender Implication: Coordinate continuity plans while avoiding the greater risk of leaving an untrusted gateway online.

Third-party scope can expand quickly

MSPs, hosting providers, and shared operational teams may manage one appliance or identity path for several organizations.

Theme: Third-party scope can expand quickly Why It Matters: MSPs, hosting providers, and shared operational teams may manage one appliance or identity path for several organizations. Defender Implication: Map each appliance, tenant, customer, environment, and integrated identity trust during the exposure window.

Timeline

22-Jun-2026

Earliest exploitation observed by Volexity.

Date / Period: 22-Jun-2026 Event: Earliest exploitation observed by Volexity. Source-Backed Meaning: High · primary incident reporting

Before 14-Jul-2026

Zero-day exploitation occurred before public disclosure.

Date / Period: Before 14-Jul-2026 Event: Zero-day exploitation occurred before public disclosure. Source-Backed Meaning: High · multiple primary sources

14-Jul-2026

SonicWall disclosed fixes; CISA added both CVEs to KEV.

Date / Period: 14-Jul-2026 Event: SonicWall disclosed fixes; CISA added both CVEs to KEV. Source-Backed Meaning: High · official records

17-Jul-2026

CISA remediation due date; Volexity published its UTA0533 analysis.

Date / Period: 17-Jul-2026 Event: CISA remediation due date; Volexity published its UTA0533 analysis. Source-Backed Meaning: High · official and primary records

23-Jul-2026

IntelliOS baseline, connected CARDS records, page alerts, and the six-month daily monitor were enabled.

Date / Period: 23-Jul-2026 Event: IntelliOS baseline, connected CARDS records, page alerts, and the six-month daily monitor were enabled. Source-Backed Meaning: Internal product record

24-Jul-2026

The daily monitor promoted SonicWall's CMS/all-hypervisors scope and configuration-backup integrity guidance into the brief and CARDS records.

Date / Period: 24-Jul-2026 Event: The daily monitor promoted SonicWall's CMS/all-hypervisors scope and configuration-backup integrity guidance into the brief and CARDS records. Source-Backed Meaning: High · official vendor product notice

01-Aug-2026

Resecurity reported continued INC weaponization and warned that some appliances remained unpatched or compromised; its wider INC leak-site cohort was not established as an SMA1000 victim list.

Date / Period: 01-Aug-2026 Event: Resecurity reported continued INC weaponization and warned that some appliances remained unpatched or compromised; its wider INC leak-site cohort was not established as an SMA1000 victim list. Source-Backed Meaning: Moderate · primary CTI/DFIR assessment

03-Aug-2026

CISA KEV catalog version 2026.08.03 changed known ransomware campaign use to Known for both CVEs.

Date / Period: 03-Aug-2026 Event: CISA KEV catalog version 2026.08.03 changed known ransomware campaign use to Known for both CVEs. Source-Backed Meaning: High · official live KEV feed

03-Aug-2026

The Hacker News published a direct Rapid7 statement that INC had emerged as the dominant actor actively weaponizing the chain.

Date / Period: 03-Aug-2026 Event: The Hacker News published a direct Rapid7 statement that INC had emerged as the dominant actor actively weaponizing the chain. Source-Backed Meaning: Moderate · direct quote in secondary reporting

Incident Response Playbook Ideas

1 · Mobilize

Assign IR leadership and counsel; identify appliance owners, identity owners, network teams, business dependencies, and third-party contacts.

Phase: 1 · Mobilize Actions: Assign IR leadership and counsel; identify appliance owners, identity owners, network teams, business dependencies, and third-party contacts. Evidence / exit criterion: Named decision owner, documented scope, evidence-preservation instruction, and change freeze where practical.

2 · Inventory

Locate SMA1000 6210/7210/8200v appliances and CMS deployments across hypervisors; record versions, internet exposure, management paths, backups, tenants, and connected identity stores.

Phase: 2 · Inventory Actions: Locate SMA1000 6210/7210/8200v appliances and CMS deployments across hypervisors; record versions, internet exposure, management paths, backups, tenants, and connected identity stores. Evidence / exit criterion: One reconciled inventory with exposure start/end times and current fixed-version status.

3 · Preserve

Export extraweb_access.log, ctrl-service.log and other appliance logs; collect configuration, filesystem timestamps, memory/disk where appropriate, firewall flows, DNS/proxy, IdP, LDAP/AD, EDR, and Windows events.

Phase: 3 · Preserve Actions: Export extraweb_access.log, ctrl-service.log and other appliance logs; collect configuration, filesystem timestamps, memory/disk where appropriate, firewall flows, DNS/proxy, IdP, LDAP/AD, EDR, and Windows events. Evidence / exit criterion: Evidence copied to controlled storage with collection time, source, handler, and integrity record.

4 · Contain

Restrict public and management access, isolate confirmed-compromised appliances, block suspicious appliance-to-internal traffic, invalidate sessions, and prevent use of compromised service accounts.

Phase: 4 · Contain Actions: Restrict public and management access, isolate confirmed-compromised appliances, block suspicious appliance-to-internal traffic, invalidate sessions, and prevent use of compromised service accounts. Evidence / exit criterion: No unapproved public management path; suspicious internal authentication stopped; continuity workaround approved.

5 · Eradicate

Apply fixed releases. For confirmed compromise, follow SonicWall guidance to reimage physical appliances or redeploy virtual appliances; remove unauthorized routes/files/startup changes.

Phase: 5 · Eradicate Actions: Apply fixed releases. For confirmed compromise, follow SonicWall guidance to reimage physical appliances or redeploy virtual appliances; remove unauthorized routes/files/startup changes. Evidence / exit criterion: Trusted build/configuration established and validated against a known-good baseline.

6 · Restore configuration

Use a configuration backup only if it predates installation of 12.4.3-03245 or 12.5.0-02283. If no earlier backup exists, closely audit the configuration for tampering before use.

Phase: 6 · Restore configuration Actions: Use a configuration backup only if it predates installation of 12.4.3-03245 or 12.5.0-02283. If no earlier backup exists, closely audit the configuration for tampering before use. Evidence / exit criterion: Recovery-point provenance documented and restored configuration independently validated.

7 · Reset trust

Change user/admin and reachable service-account passwords; reset TOTP seeds after confirmed compromise; evaluate certificates, API keys, and secrets accessible from the appliance.

Phase: 7 · Reset trust Actions: Change user/admin and reachable service-account passwords; reset TOTP seeds after confirmed compromise; evaluate certificates, API keys, and secrets accessible from the appliance. Evidence / exit criterion: Rotation register complete, owners attest, stale sessions/tokens rejected.

8 · Scope downstream

Investigate appliance-origin logons, atypical workstation names, domain-controller access, credential use, endpoint activity, exfiltration, security-control changes, and ransomware staging.

Phase: 8 · Scope downstream Actions: Investigate appliance-origin logons, atypical workstation names, domain-controller access, credential use, endpoint activity, exfiltration, security-control changes, and ransomware staging. Evidence / exit criterion: Documented conclusion for each reached identity/system and any unresolved evidence gap.

9 · Recover / monitor

Restore remote access in stages, apply least privilege and management restrictions, and monitor appliance, identity, network, and endpoint signals for recurrence.

Phase: 9 · Recover / monitor Actions: Restore remote access in stages, apply least privilege and management restrictions, and monitor appliance, identity, network, and endpoint signals for recurrence. Evidence / exit criterion: Business owner accepts restoration; heightened monitoring and lessons-learned actions have owners/dates.

Term Glossary

SSRF

Server-side request forgery. An outside attacker makes a trusted server or appliance initiate a connection on the attacker's behalf, potentially reaching systems the attacker cannot contact directly.

Term: SSRF Meaning: Server-side request forgery. An outside attacker makes a trusted server or appliance initiate a connection on the attacker's behalf, potentially reaching systems the attacker cannot contact directly.

Localhost

The appliance talking to itself. Services bound to localhost are normally hidden from the internet and may be less hardened because designers expect only trusted local software to reach them.

Term: Localhost Meaning: The appliance talking to itself. Services bound to localhost are normally hidden from the internet and may be less hardened because designers expect only trusted local software to reach them.

WebSocket proxy

A persistent, bidirectional tunnel. Once established, both sides can continuously send data, which can turn one public request into an interactive channel to a hidden service.

Term: WebSocket proxy Meaning: A persistent, bidirectional tunnel. Once established, both sides can continuously send data, which can turn one public request into an interactive channel to a hidden service.

Path traversal

Use of path components such as../ to escape an intended folder and point a trusted workflow at a different file or location.

Term: Path traversal Meaning: Use of path components such as../ to escape an intended folder and point a trusted workflow at a different file or location.

Code injection / command execution

Causing a system to run attacker-controlled instructions rather than treating the input only as data.

Term: Code injection / command execution Meaning: Causing a system to run attacker-controlled instructions rather than treating the input only as data.

Root

The highest privilege on a Linux-based system. Root can generally read, change, create, or delete system files and control services.

Term: Root Meaning: The highest privilege on a Linux-based system. Root can generally read, change, create, or delete system files and control services.

TOTP seed

The secret value used to generate rotating authenticator-app codes. If stolen, an attacker may be able to generate the same MFA codes until the seed is reset.

Term: TOTP seed Meaning: The secret value used to generate rotating authenticator-app codes. If stolen, an attacker may be able to generate the same MFA codes until the seed is reset.

Lateral movement

Using an initial foothold to reach additional accounts, servers, domain controllers, applications, or data inside the organization.

Term: Lateral movement Meaning: Using an initial foothold to reach additional accounts, servers, domain controllers, applications, or data inside the organization.

KEV

CISA's Known Exploited Vulnerabilities catalog. Inclusion means exploitation is known to have occurred in the wild; it does not identify every actor or victim.

Term: KEV Meaning: CISA's Known Exploited Vulnerabilities catalog. Inclusion means exploitation is known to have occurred in the wild; it does not identify every actor or victim.

Zero day

A vulnerability exploited before defenders had a public fix or sufficient advance notice.

Term: Zero day Meaning: A vulnerability exploited before defenders had a public fix or sufficient advance notice.

Attribution boundary

A rule that keeps source-specific actor labels and confidence levels separate unless evidence supports equivalence.

Term: Attribution boundary Meaning: A rule that keeps source-specific actor labels and confidence levels separate unless evidence supports equivalence.

TTPs

Initial access

Exploit internet-facing SMA1000 via CVE-2026-15409.

Phase: Initial access Observed / reported behavior: Exploit internet-facing SMA1000 via CVE-2026-15409. Defender focus: WebSocket proxy and access-log anomalies

Privilege / execution

Reach the normally administrator-restricted hotfix workflow through the CVE-2026-15409 localhost tunnel, then use CVE-2026-15410 path traversal/code injection to execute as root.

Phase: Privilege / execution Observed / reported behavior: Reach the normally administrator-restricted hotfix workflow through the CVE-2026-15409 localhost tunnel, then use CVE-2026-15410 path traversal/code injection to execute as root. Defender focus: Hotfix-control activity and shell artifacts

Persistence

Modify appliance routes/configuration; deploy web-accessible or appliance-resident tooling.

Phase: Persistence Observed / reported behavior: Modify appliance routes/configuration; deploy web-accessible or appliance-resident tooling. Defender focus: Configuration diff and filesystem integrity

Credential access

Access authentication material, sessions, or TOTP-related data.

Phase: Credential access Observed / reported behavior: Access authentication material, sessions, or TOTP-related data. Defender focus: Session invalidation and targeted rotation

Lateral movement

Authenticate from the appliance into reachable internal systems.

Phase: Lateral movement Observed / reported behavior: Authenticate from the appliance into reachable internal systems. Defender focus: Appliance-sourced Windows/network logons

Command and control

Use Suo5/proxying and custom implants including KNUCKLEBALL/ORANGETAIL.

Phase: Command and control Observed / reported behavior: Use Suo5/proxying and custom implants including KNUCKLEBALL/ORANGETAIL. Defender focus: Egress, process, route, and file anomalies

Common Questions Q&A

Is patching enough?

Not for an appliance that was internet-facing before the fixed release. Patching prevents the same exploit path going forward; it does not remove an implant, revoke stolen sessions, rotate credentials, reset TOTP seeds, or determine whether internal systems were reached.

Question: Is patching enough? Answer: Not for an appliance that was internet-facing before the fixed release. Patching prevents the same exploit path going forward; it does not remove an implant, revoke stolen sessions, rotate credentials, reset TOTP seeds, or determine whether internal systems were reached.

What does 'unauthenticated' mean?

The attacker did not need a valid SMA username, password, or session to begin exploiting CVE-2026-15409.

Question: What does 'unauthenticated' mean? Answer: The attacker did not need a valid SMA username, password, or session to begin exploiting CVE-2026-15409.

Does CVE-2026-15410 require an administrator login?

On its own, SonicWall classifies CVE-2026-15410 as post-authentication and administrator-level. In the observed chain, CVE-2026-15409 exposes the localhost control service and lets the attacker reach the privileged workflow without completing a conventional administrator login. Do not interpret the chain as proof that a valid administrator password was used.

Question: Does CVE-2026-15410 require an administrator login? Answer: On its own, SonicWall classifies CVE-2026-15410 as post-authentication and administrator-level. In the observed chain, CVE-2026-15409 exposes the localhost control service and lets the attacker reach the privileged workflow without completing a conventional administrator login. Do not interpret the chain as proof that a valid administrator password was used.

Why can an SSRF be critical?

Because the appliance can reach services the internet cannot. The flaw borrows the appliance's trusted network position and, in this chain, exposes local services that enable command execution.

Question: Why can an SSRF be critical? Answer: Because the appliance can reach services the internet cannot. The flaw borrows the appliance's trusted network position and, in this chain, exposes local services that enable command execution.

What does root access mean for the investigation?

Assume the attacker could change appliance files, configuration, startup behavior, and potentially logs. Prefer off-appliance evidence and known-good comparisons, and consider reimage/redeployment when trust cannot be demonstrated.

Question: What does root access mean for the investigation? Answer: Assume the attacker could change appliance files, configuration, startup behavior, and potentially logs. Prefer off-appliance evidence and known-good comparisons, and consider reimage/redeployment when trust cannot be demonstrated.

Which SMA1000 systems are in scope?

SonicWall's product notice lists 6210, 7210, 8200v, and CMS across hypervisors. It excludes SonicWall firewall SSLVPN functionality and the SMA100 line.

Question: Which SMA1000 systems are in scope? Answer: SonicWall's product notice lists 6210, 7210, 8200v, and CMS across hypervisors. It excludes SonicWall firewall SSLVPN functionality and the SMA100 line.[1] [8]

Can we restore a recent configuration backup?

Not automatically. SonicWall says the backup should predate installation of 12.4.3-03245 or 12.5.0-02283; otherwise, closely audit the configuration for tampering before use.

Question: Can we restore a recent configuration backup? Answer: Not automatically. SonicWall says the backup should predate installation of 12.4.3-03245 or 12.5.0-02283; otherwise, closely audit the configuration for tampering before use.[8]

Did INC definitely conduct every observed intrusion?

No. Dark Reading, Resecurity, and a direct Rapid7 statement published by The Hacker News support continued INC weaponization, but Volexity uses UTA0533 and does not publicly equate it with INC. Do not use one label for all exploitation or assume every INC leak-site victim used this entry path.

Question: Did INC definitely conduct every observed intrusion? Answer: No. Dark Reading, Resecurity, and a direct Rapid7 statement published by The Hacker News support continued INC weaponization, but Volexity uses UTA0533 and does not publicly equate it with INC. Do not use one label for all exploitation or assume every INC leak-site victim used this entry path.[7] [9] [10]

Does KEV prove ransomware use?

KEV inclusion proves known exploitation. CISA's separate live ransomware-campaign field now says Known for both CVEs, which establishes CISA's CVE-level ransomware-use assessment. It does not identify an actor or victim, establish that INC and UTA0533 are the same, or prove that every intrusion led to ransomware.

Question: Does KEV prove ransomware use? Answer: KEV inclusion proves known exploitation. CISA's separate live ransomware-campaign field now says Known for both CVEs, which establishes CISA's CVE-level ransomware-use assessment. It does not identify an actor or victim, establish that INC and UTA0533 are the same, or prove that every intrusion led to ransomware.[2] [7]

Does a vulnerable version prove breach?

No. It proves exposure to a known exploited flaw. Logs, configuration, filesystem, memory, identity, network, and endpoint evidence determine compromise and impact.

Question: Does a vulnerable version prove breach? Answer: No. It proves exposure to a known exploited flaw. Logs, configuration, filesystem, memory, identity, network, and endpoint evidence determine compromise and impact.

Should we publish public IP indicators as a blocklist?

Use source IPs as time-bound investigative pivots, not universal attribution. VPN/proxy infrastructure is shared and can change; behavioral evidence and local correlation are stronger.

Question: Should we publish public IP indicators as a blocklist? Answer: Use source IPs as time-bound investigative pivots, not universal attribution. VPN/proxy infrastructure is shared and can change; behavioral evidence and local correlation are stronger.

CVE / Vulnerability References

CVE-2026-15409

Tricks the public appliance into creating a WebSocket tunnel to normally hidden local services.

CVE: CVE-2026-15409 Plain-English role: Tricks the public appliance into creating a WebSocket tunnel to normally hidden local services. Precondition / result: No valid login required; gives the attacker an interactive path to appliance-internal services. Severity: Critical · CVSS 10.0

CVE-2026-15410

Post-authentication code injection in an administrator-level hotfix-removal workflow; path traversal can select an attacker-controlled script for execution.

CVE: CVE-2026-15410 Plain-English role: Post-authentication code injection in an administrator-level hotfix-removal workflow; path traversal can select an attacker-controlled script for execution. Precondition / result: Independently requires administrator-level access. In the observed chain, CVE-2026-15409 reaches the localhost control service without a conventional administrator login; commands then run as root. Severity: High · CVSS 7.2

SMA1000 Series · 6210 / 7210 / 8200v / CMS across hypervisors

12.4.3-03245, 12.4.3-03387, 12.4.3-03434; 12.5.0-02283, 12.5.0-02624, 12.5.0-02800

Affected line: SMA1000 Series · 6210 / 7210 / 8200v / CMS across hypervisors Known affected releases: 12.4.3-03245, 12.4.3-03387, 12.4.3-03434; 12.5.0-02283, 12.5.0-02624, 12.5.0-02800 Fixed release: 12.4.3-03453+ or 12.5.0-02835+ Workaround: None; upgrade is required

SonicWall says the SMA100 product line and SSL VPN functionality on SonicWall firewalls are not affected by these vulnerabilities. Its product notice separately brings CMS across hypervisors into the SMA1000 scope.[1] [3] [4] [8]

IOCs / Observables

extraweb_access.log

GET + /wsproxy + =-3389 + HTTP 101

Evidence source: extraweb_access.log Observable: GET + /wsproxy + =-3389 + HTTP 101 Interpretation: Characteristic WebSocket tunnel interaction. Suspicious localhost-style host values increase confidence. Response: Identify source/time/session, requested host/port, preceding enumeration, and subsequent appliance/internal activity.

Web request parameters

host=localhost, 0.0.0.0, or::ffff:127.0.0.1; ports 1050 or 8188

Evidence source: Web request parameters Observable: host=localhost, 0.0.0.0, or::ffff:127.0.0.1; ports 1050 or 8188 Interpretation: Attempt to reach appliance-local Erlang or ctrl-service endpoints through the proxy. Response: Correlate with 101 Switching Protocols, command execution, reboots, and local-service logs.

ctrl-service.log / process evidence

remove_hotfix with../../ traversal into /tmp or /var/tmp shell scripts

Evidence source: ctrl-service.log / process evidence Observable: remove_hotfix with../../ traversal into /tmp or /var/tmp shell scripts Interpretation: High-confidence CVE-2026-15410 exploitation pattern when tied to an attacker-staged file. Response: Preserve the referenced script, owner/timestamps, process ancestry, execution result, and reboot timeline.

HTTP / appliance logs

/auth1.html, /.env, /api/sonicos/is-sslvpn-enabled, /__api__/logon/<session>/authenticate

Evidence source: HTTP / appliance logs Observable: /auth1.html, /.env, /api/sonicos/is-sslvpn-enabled, /__api__/logon/<session>/authenticate Interpretation: Enumeration and authentication-path activity reported during exploitation. Response: Use as supporting context; generic probes alone are lower confidence.

NGINX Unit configuration

/var/lib/unit/conf.json routes for /__api__/login or /__api__/logout to 127.0.0.1:8085

Evidence source: NGINX Unit configuration Observable: /var/lib/unit/conf.json routes for /__api__/login or /__api__/logout to 127.0.0.1:8085 Interpretation: Volexity-reported routes exposing Suo5/ORANGETAIL implant paths; not present in legitimate configuration. Response: Diff with a clean baseline and inspect referenced Java processes, routes, and external access.

Filesystem / persistence

/usr/bin/xzfind; deploy_new.py; hypdate.b64; workplace startup-script modification

Evidence source: Filesystem / persistence Observable: /usr/bin/xzfind; deploy_new.py; hypdate.b64; workplace startup-script modification Interpretation: Reported privilege, KNUCKLEBALL, exploit, and persistence artifacts. Response: Collect hashes and metadata, identify execution/persistence, and scope related files before eradication.

Sensitive appliance data

/tmp/temp.db* access or unexpected session-database/TOTP material handling

Evidence source: Sensitive appliance data Observable: /tmp/temp.db* access or unexpected session-database/TOTP material handling Interpretation: Possible theft of stored session or MFA-related data. Response: Invalidate sessions, identify affected users, rotate/reset relevant authentication material.

Windows / AD

Event ID 4624, logon type 3, sourced from the appliance IP with KALI or other non-inventory workstation names and no matching VPN session

Evidence source: Windows / AD Observable: Event ID 4624, logon type 3, sourced from the appliance IP with KALI or other non-inventory workstation names and no matching VPN session Interpretation: High-value lateral-movement signal described by Rapid7. Response: Scope accounts, domain controllers, targets, privileges, follow-on processes, and any service-account compromise.

Network / packet capture

Unexpected tcpdump processes or capture files focused on LDAP TCP/389

Evidence source: Network / packet capture Observable: Unexpected tcpdump processes or capture files focused on LDAP TCP/389 Interpretation: Volexity observed unencrypted LDAP traffic capture for username/password collection. Response: Stop exposure, preserve capture evidence securely, rotate exposed directory credentials, and evaluate encrypted LDAP.

Treat these as investigative pivots, not a checklist that proves or disproves compromise by itself. Search the full exposure window and correlate appliance, identity, network, endpoint, and Windows evidence. A root-level attacker may alter on-box evidence, while shared VPN/proxy infrastructure can create false positives.

Source detail and caveats: Rapid7 provides the characteristic web/logon/hotfix patterns and Windows logon behavior; Volexity provides the appliance files, startup persistence, NGINX Unit routes, malware, and packet-capture behavior.[3] [4]

Threat Actor Glossary

INC Ransom

Ransomware/extortion operation connected to this activity by Dark Reading, Resecurity, and a direct Rapid7 statement published by The Hacker News. Moderate confidence for continued INC weaponization; Rapid7's public technical post itself still does not name INC, and this does not establish that INC equals UTA0533.

Label: INC Ransom Source-bound assessment: Ransomware/extortion operation connected to this activity by Dark Reading, Resecurity, and a direct Rapid7 statement published by The Hacker News. Moderate confidence for continued INC weaponization; Rapid7's public technical post itself still does not name INC, and this does not establish that INC equals UTA0533.[7] [9] [10]

UTA0533

Volexity temporary activity-cluster label for the SMA1000 exploitation it investigated. High confidence as Volexity's label; relationship to INC is not publicly established.

Label: UTA0533 Source-bound assessment: Volexity temporary activity-cluster label for the SMA1000 exploitation it investigated. High confidence as Volexity's label; relationship to INC is not publicly established.

KNUCKLEBALL

Volexity's name for the Python loader/persistence script deploy_new.py, which injects two Java payloads into a legitimate SonicWall process.

Label: KNUCKLEBALL Source-bound assessment: Volexity's name for the Python loader/persistence script deploy_new.py, which injects two Java payloads into a legitimate SonicWall process.

Suo5

Open-source HTTP proxy-forwarding code embedded by KNUCKLEBALL and modified with access-gating logic. It supports tunneling/pivoting.

Label: Suo5 Source-bound assessment: Open-source HTTP proxy-forwarding code embedded by KNUCKLEBALL and modified with access-gating logic. It supports tunneling/pivoting.

ORANGETAIL

Volexity's name for a custom Behinder-like Java web shell embedded by KNUCKLEBALL. It provides an attacker-controlled command channel.

Label: ORANGETAIL Source-bound assessment: Volexity's name for a custom Behinder-like Java web shell embedded by KNUCKLEBALL. It provides an attacker-controlled command channel.

Attribution conclusion

Malware or an exploit pattern can connect incidents technically without proving the same actor conducted every intrusion. Preserve source-specific labels and confidence.

Label: Attribution conclusion Source-bound assessment: Malware or an exploit pattern can connect incidents technically without proving the same actor conducted every intrusion. Preserve source-specific labels and confidence.

Talking Points

Board / executive

“A remote-access security appliance could be compromised from the internet without a valid user account and then controlled at the operating-system level. We are patching and separately determining whether any appliance or connected identity was already compromised.”

Audience / situation: Board / executive Recommended language: “A remote-access security appliance could be compromised from the internet without a valid user account and then controlled at the operating-system level. We are patching and separately determining whether any appliance or connected identity was already compromised.”

Business continuity

“Containment or rebuild may temporarily affect remote access. That disruption must be weighed against the risk of leaving a potentially attacker-controlled gateway connected to the company.”

Audience / situation: Business continuity Recommended language: “Containment or rebuild may temporarily affect remote access. That disruption must be weighed against the risk of leaving a potentially attacker-controlled gateway connected to the company.”

Counsel / notification

“A vulnerable appliance is not proof of unauthorized data access. We are preserving evidence and distinguishing vulnerability, exploitation, credential exposure, internal access, and confirmed impact.”

Audience / situation: Counsel / notification Recommended language: “A vulnerable appliance is not proof of unauthorized data access. We are preserving evidence and distinguishing vulnerability, exploitation, credential exposure, internal access, and confirmed impact.”

Technical leadership

“The first CVE opens a tunnel to hidden local services; the second abuses a trusted hotfix workflow to run a malicious script as root. Patching blocks the chain but does not restore stolen trust.”

Audience / situation: Technical leadership Recommended language: “The first CVE opens a tunnel to hidden local services; the second abuses a trusted hotfix workflow to run a malicious script as root. Patching blocks the chain but does not restore stolen trust.”

Attribution

“Public reporting now supports continued INC Ransom weaponization of the chain, while Volexity tracks its observed activity as UTA0533. We are not treating those labels as proven equivalents or attributing every intrusion or INC victim listing to the SMA1000 path.”

Audience / situation: Attribution Recommended language: “Public reporting now supports continued INC Ransom weaponization of the chain, while Volexity tracks its observed activity as UTA0533. We are not treating those labels as proven equivalents or attributing every intrusion or INC victim listing to the SMA1000 path.”

CISA / KEV

“Both CVEs are in CISA KEV, and catalog version 2026.08.03 now marks known ransomware campaign use as Known. We retain that official CVE-level value while keeping actor attribution and victim conclusions source-bound.”

Audience / situation: CISA / KEV Recommended language: “Both CVEs are in CISA KEV, and catalog version 2026.08.03 now marks known ransomware campaign use as Known. We retain that official CVE-level value while keeping actor attribution and victim conclusions source-bound.”

Customers / partners

“We are validating affected models, versions, exposure windows, evidence of exploitation, and any downstream reach before making customer-specific impact statements.”

Audience / situation: Customers / partners Recommended language: “We are validating affected models, versions, exposure windows, evidence of exploitation, and any downstream reach before making customer-specific impact statements.”

Decision Ready Actions

P0

Upgrade or isolate all affected SMA1000 appliances; there is no workaround.

Priority: P0 Decision: Upgrade or isolate all affected SMA1000 appliances; there is no workaround. Owner: Network / infrastructure Evidence of completion: Reconciled model/version/exposure inventory and fixed-version evidence

P0

Open a compromise assessment for every internet-facing pre-fix appliance.

Priority: P0 Decision: Open a compromise assessment for every internet-facing pre-fix appliance. Owner: IR lead / counsel Evidence of completion: Approved scope, preserved evidence, and named investigation owner

P0

Preserve evidence before reboot, reimage, or redeploy when operational risk permits.

Priority: P0 Decision: Preserve evidence before reboot, reimage, or redeploy when operational risk permits. Owner: DFIR / appliance owner Evidence of completion: Collection manifest covering appliance, network, identity, Windows, and endpoint sources

P0

Validate recovery-point trust: use only a configuration backup predating installation of 12.4.3-03245 or 12.5.0-02283, or closely audit the configuration for tampering.

Priority: P0 Decision: Validate recovery-point trust: use only a configuration backup predating installation of 12.4.3-03245 or 12.5.0-02283, or closely audit the configuration for tampering. Owner: Infrastructure / DFIR Evidence of completion: Documented backup provenance and configuration-integrity review

P0

Invalidate active sessions and contain suspicious appliance-to-internal access.

Priority: P0 Decision: Invalidate active sessions and contain suspicious appliance-to-internal access. Owner: IAM / network / SOC Evidence of completion: Revocation record and verified blocking/segmentation

P1

Rotate user/admin, LDAP/service-account, and reachable secrets; reset TOTP seeds after confirmed compromise.

Priority: P1 Decision: Rotate user/admin, LDAP/service-account, and reachable secrets; reset TOTP seeds after confirmed compromise. Owner: IAM / application owners Evidence of completion: Credential and MFA reset register with owner attestations

P1

Hunt published behavioral observables across appliance, identity, firewall, EDR, and Windows logs.

Priority: P1 Decision: Hunt published behavioral observables across appliance, identity, firewall, EDR, and Windows logs. Owner: SOC / DFIR Evidence of completion: Time-bounded hunt results, gaps, and escalation criteria

P1

Decide reimage/redeployment threshold based on root-compromise evidence and evidence integrity.

Priority: P1 Decision: Decide reimage/redeployment threshold based on root-compromise evidence and evidence integrity. Owner: IR / infrastructure / counsel Evidence of completion: Documented recovery decision and trusted baseline

P2

Determine customer, regulatory, contractual, insurer, and law-enforcement communications from established facts.

Priority: P2 Decision: Determine customer, regulatory, contractual, insurer, and law-enforcement communications from established facts. Owner: Counsel / privacy / executive Evidence of completion: Decision record separating exposure, compromise, data access, and business impact

Exploitable Technology Risks

Internet-facing remote-access gateway

The appliance must accept untrusted internet traffic while maintaining trusted internal reach.

Risk: Internet-facing remote-access gateway How it becomes exploitable: The appliance must accept untrusted internet traffic while maintaining trusted internal reach. Control implication: Minimize exposure, restrict management, inventory continuously, and treat emergency edge-device fixes as high priority.

SSRF / trust-boundary bypass

A public feature can be coerced into contacting localhost services that assume local traffic is trusted.

Risk: SSRF / trust-boundary bypass How it becomes exploitable: A public feature can be coerced into contacting localhost services that assume local traffic is trusted. Control implication: Authenticate proxy features, restrict destinations/ports, segment appliance services, and monitor unusual internal-service access.

Administrative workflow abuse

A hotfix-removal mechanism accepts a traversed path and executes the referenced file as root.

Risk: Administrative workflow abuse How it becomes exploitable: A hotfix-removal mechanism accepts a traversed path and executes the referenced file as root. Control implication: Canonicalize paths, constrain execution to signed/trusted packages, enforce least privilege, and log immutable workflow events.

Concentrated identity material

Remote-access appliances process credentials, sessions, directory service accounts, and MFA-related secrets.

Risk: Concentrated identity material How it becomes exploitable: Remote-access appliances process credentials, sessions, directory service accounts, and MFA-related secrets. Control implication: Reduce stored secrets, use encrypted directory protocols, rotate machine credentials, shorten session lifetime, and protect TOTP seeds.

Root-level evidence risk

An attacker with root may alter files/configuration/logs or install startup persistence; reboot can remove volatile evidence.

Risk: Root-level evidence risk How it becomes exploitable: An attacker with root may alter files/configuration/logs or install startup persistence; reboot can remove volatile evidence. Control implication: Forward logs off-box, monitor configuration integrity, preserve memory/disk early, and keep trusted rebuild procedures.

Downstream trust / lateral movement

The appliance's internal IP and integrated service accounts may be trusted by internal systems.

Risk: Downstream trust / lateral movement How it becomes exploitable: The appliance's internal IP and integrated service accounts may be trusted by internal systems. Control implication: Constrain service-account rights, segment appliance reach, alert on appliance-origin authentication, and require a matching remote-access session.

Virtual appliance and backup contamination

Snapshots or backups taken after compromise can preserve malicious configuration or persistence.

Risk: Virtual appliance and backup contamination How it becomes exploitable: Snapshots or backups taken after compromise can preserve malicious configuration or persistence. Control implication: Follow SonicWall's recovery boundary: prefer configuration backups predating the December hotfix baselines; otherwise closely audit the configuration for tampering before use.

Social Media / Community Signals

Researcher/social post

Discovery lead for a technical artifact or exploitation claim.

Signal: Researcher/social post How PANDA uses it: Discovery lead for a technical artifact or exploitation claim. Promotion threshold: Promote only when the underlying evidence is accessible and technically reviewable or independently corroborated.

Exploit / PoC discussion

Increases urgency and helps identify expected request patterns.

Signal: Exploit / PoC discussion How PANDA uses it: Increases urgency and helps identify expected request patterns. Promotion threshold: Separate defensive understanding from exploit-operational details; require vendor/NVD/credible researcher confirmation.

Victim or actor claim

Creates a scoping question, not a confirmed fact.

Signal: Victim or actor claim How PANDA uses it: Creates a scoping question, not a confirmed fact. Promotion threshold: Require victim disclosure, incident-response source, regulatory filing, or multiple credible independent sources.

IP/domain list

Time-bound hunt pivot.

Signal: IP/domain list How PANDA uses it: Time-bound hunt pivot. Promotion threshold: Validate provenance, observation time, shared-infrastructure risk, and local telemetry before blocking or attributing.

Secondary article repetition

May improve awareness but not evidence weight.

Signal: Secondary article repetition How PANDA uses it: May improve awareness but not evidence weight. Promotion threshold: Do not count multiple rewrites of one primary source as independent corroboration.

Community and social reporting can surface scanning, proof-of-concept activity, suspected victims, or new infrastructure faster than formal advisories. It is useful for discovery and hypothesis generation, but it is not sufficient by itself to raise attribution confidence, confirm a victim, or establish local compromise.

Tier 0 Through Tier 8 Source Summary

Tier 0

SonicWall PSIRT; SonicWall product notice; CISA KEV

Tier: Tier 0 Coverage: SonicWall PSIRT; SonicWall product notice; CISA KEV Use: Affected products, CMS/hypervisor scope, trusted-backup recovery boundary, fixes, deadlines, and official status

Tier 1

Rapid7; Volexity; NVD; Resecurity

Tier: Tier 1 Coverage: Rapid7; Volexity; NVD; Resecurity Use: Incident evidence, chain mechanics, artifacts, source-specific actor labels, and source-qualified continued weaponization

Tier 2

No material source used in v1.7

Tier: Tier 2 Coverage: No material source used in v1.7 Use: Reserved for highly relevant specialist synthesis with additional evidence

Tier 3

Dark Reading; The Hacker News

Tier: Tier 3 Coverage: Dark Reading; The Hacker News Use: Attributed reporting for the Rapid7-to-INC association, ransomware outcome, and direct Rapid7 continued-weaponization statement; not used to merge UTA0533 or assign every victim

Tiers 4–8

Discovery-only / not relied upon

Tier: Tiers 4–8 Coverage: Discovery-only / not relied upon Use: No unsupported claim amplification, victim naming, or unvalidated IOC promotion

Source Reconciliation

INC vs. UTA0533

Keep separate. Dark Reading, Resecurity, and a direct Rapid7 statement published by The Hacker News support continued INC weaponization; UTA0533 remains Volexity's cluster label. No retained source proves the labels are equivalent.

Issue: INC vs. UTA0533 Reconciled position: Keep separate. Dark Reading, Resecurity, and a direct Rapid7 statement published by The Hacker News support continued INC weaponization; UTA0533 remains Volexity's cluster label. No retained source proves the labels are equivalent.

Rapid7 public post vs. attributed statements

Rapid7's public post establishes zero-day exploitation, technical mechanics, credential/session/TOTP theft, and lateral movement but does not name INC. Dark Reading reported the initial Rapid7-to-INC association and ransomware outcome; The Hacker News later published a direct Rapid7 continued-weaponization statement. Keep each claim attached to the source that published it.

Issue: Rapid7 public post vs. attributed statements Reconciled position: Rapid7's public post establishes zero-day exploitation, technical mechanics, credential/session/TOTP theft, and lateral movement but does not name INC. Dark Reading reported the initial Rapid7-to-INC association and ransomware outcome; The Hacker News later published a direct Rapid7 continued-weaponization statement. Keep each claim attached to the source that published it.

INC leak-site victims vs. SMA1000 victims

Resecurity describes a broader group of new INC leak-site listings, but does not establish that every listed organization was compromised through CVE-2026-15409/CVE-2026-15410. The brief therefore retains no named SMA1000 victim.

Issue: INC leak-site victims vs. SMA1000 victims Reconciled position: Resecurity describes a broader group of new INC leak-site listings, but does not establish that every listed organization was compromised through CVE-2026-15409/CVE-2026-15410. The brief therefore retains no named SMA1000 victim.

KEV ransomware field

Retain CISA’s current “Known” value for both CVEs. Treat it as a CVE-level ransomware-use assessment, not as actor attribution, victim identification, incident counting, or proof that every intrusion reached ransomware.

Issue: KEV ransomware field Reconciled position: Retain CISA’s current “Known” value for both CVEs. Treat it as a CVE-level ransomware-use assessment, not as actor attribution, victim identification, incident counting, or proof that every intrusion reached ransomware.

CVE roles

CVE-2026-15409 supplies the no-login-required tunnel to hidden local services. CVE-2026-15410 is independently a post-authentication, administrator-level code-injection flaw; in the observed chain, the tunnel reaches its privileged localhost workflow without a conventional administrator login, and path traversal executes an attacker script as root.

Issue: CVE roles Reconciled position: CVE-2026-15409 supplies the no-login-required tunnel to hidden local services. CVE-2026-15410 is independently a post-authentication, administrator-level code-injection flaw; in the observed chain, the tunnel reaches its privileged localhost workflow without a conventional administrator login, and path traversal executes an attacker script as root.

Product scope

The PSIRT advisory names SMA1000 6210/7210/8200v; SonicWall's product notice also includes CMS across hypervisors. Exclude SMA100 and SonicWall firewall SSLVPN.

Issue: Product scope Reconciled position: The PSIRT advisory names SMA1000 6210/7210/8200v; SonicWall's product notice also includes CMS across hypervisors. Exclude SMA100 and SonicWall firewall SSLVPN.

Exposure vs. compromise

A vulnerable/exposed appliance is an urgent investigation subject, not automatic proof that exploitation, data access, lateral movement, or ransomware occurred.

Issue: Exposure vs. compromise Reconciled position: A vulnerable/exposed appliance is an urgent investigation subject, not automatic proof that exploitation, data access, lateral movement, or ransomware occurred.

Recovery

No workaround; upgrade plus retrospective compromise assessment. Confirmed root compromise should trigger trusted reimage/redeployment and authentication-material reset decisions. Use configuration backups only when they predate installation of the December hotfix baselines; otherwise closely audit configuration integrity.

Issue: Recovery Reconciled position: No workaround; upgrade plus retrospective compromise assessment. Confirmed root compromise should trigger trusted reimage/redeployment and authentication-material reset decisions. Use configuration backups only when they predate installation of the December hotfix baselines; otherwise closely audit configuration integrity.

About the Contributors

IntelliOS PANDA AI

Source collection, plain-language synthesis, threat-brief production, citation mapping, and decision-oriented presentation.

Contributor / system: IntelliOS PANDA AI Role: Source collection, plain-language synthesis, threat-brief production, citation mapping, and decision-oriented presentation. Boundary: Does not replace incident-specific forensic, legal, or regulatory analysis.

SonicWall PSIRT / product notice / CISA / NVD

Official product, remediation, recovery, KEV, and vulnerability identity records.

Contributor / system: SonicWall PSIRT / product notice / CISA / NVD Role: Official product, remediation, recovery, KEV, and vulnerability identity records. Boundary: Official status does not establish the facts of a specific organization's incident.

Rapid7 / Volexity / Resecurity

Primary incident-response, technical exploitation, and continued-weaponization assessments.

Contributor / system: Rapid7 / Volexity / Resecurity Role: Primary incident-response, technical exploitation, and continued-weaponization assessments. Boundary: Each reports from its own visibility; their actor labels, victim cohorts, and outcomes are not automatically universal.

IntelliOS CARDS

Connected campaign, CVE/KEV, and actor records with explicit attribution boundaries.

Contributor / system: IntelliOS CARDS Role: Connected campaign, CVE/KEV, and actor records with explicit attribution boundaries. Boundary: Relationships express sourced confidence, not identity equivalence.

IntelliOS FORGE

Daily six-month public-source monitoring, page-alert routing, and material-delta workflow.

Contributor / system: IntelliOS FORGE Role: Daily six-month public-source monitoring, page-alert routing, and material-delta workflow. Boundary: No-change checks do not manufacture content updates or subscriber alerts.

Real World Examples

Rapid7 MDR investigation

Targeted zero-day exploitation of internet-facing SMA1000 appliances; command execution; theft of credentials, active session databases, and TOTP seed configurations; VPN-less Active Directory authentication attempts from the appliance IP.

Public example: Rapid7 MDR investigation What was observed: Targeted zero-day exploitation of internet-facing SMA1000 appliances; command execution; theft of credentials, active session databases, and TOTP seed configurations; VPN-less Active Directory authentication attempts from the appliance IP. What it proves / does not prove: Proves the chain was operational before disclosure and could expose identity trust and support internal access. Rapid7's public article does not name INC or ransomware.[3]

Dark Reading reporting

Reports that Rapid7 attributed the activity to INC Ransom and that one observed case progressed to ransomware deployment.

Public example: Dark Reading reporting What was observed: Reports that Rapid7 attributed the activity to INC Ransom and that one observed case progressed to ransomware deployment. What it proves / does not prove: Supports the public INC/ransomware framing at secondary-source confidence. It does not establish that every SMA1000 intrusion is INC activity.[7]

August continued-weaponization reporting

Resecurity assesses continued INC use of the chain, while The Hacker News publishes a direct Rapid7 statement describing INC as the dominant actor actively weaponizing it.

Public example: August continued-weaponization reporting What was observed: Resecurity assesses continued INC use of the chain, while The Hacker News publishes a direct Rapid7 statement describing INC as the dominant actor actively weaponizing it. What it proves / does not prove: Strengthens the source-qualified INC association. It does not merge INC with UTA0533 or establish that every new INC leak-site listing was an SMA1000 victim.[9] [10]

Volexity investigation

Two compromised appliances, earliest observed activity June 22, UTA0533 tracking, root-level artifacts, KNUCKLEBALL persistence, Suo5/ORANGETAIL, LDAP traffic capture, and attempts to pivot into customer systems.

Public example: Volexity investigation What was observed: Two compromised appliances, earliest observed activity June 22, UTA0533 tracking, root-level artifacts, KNUCKLEBALL persistence, Suo5/ORANGETAIL, LDAP traffic capture, and attempts to pivot into customer systems. What it proves / does not prove: Independently validates zero-day exploitation, appliance-specific persistence, credential capture, and lateral-movement attempts. It does not publicly connect UTA0533 to INC.[4]

Local organization

No conclusion can be imported from another victim's case.

Public example: Local organization What was observed: No conclusion can be imported from another victim's case. What it proves / does not prove: Local model/version/exposure and forensic evidence determine whether compromise and downstream impact occurred.

Public Victims / Disclosure Matrix

Named ransomware victim

No authoritative victim name identified through the 06-Aug-2026 check

Category: Named ransomware victim Public status: No authoritative victim name identified through the 06-Aug-2026 check Brief treatment: Do not infer or publish victim identity.

Rapid7 client activity

Rapid7 publicly describes exploitation and downstream identity/lateral-movement behavior; the affected organization is unnamed.

Category: Rapid7 client activity Public status: Rapid7 publicly describes exploitation and downstream identity/lateral-movement behavior; the affected organization is unnamed. Brief treatment: Use for technical outcome validation; do not add ransomware or actor identity to Rapid7's public account.

Dark Reading account

Reports one Rapid7-observed case progressed to ransomware and names INC; victim remains unnamed.

Category: Dark Reading account Public status: Reports one Rapid7-observed case progressed to ransomware and names INC; victim remains unnamed. Brief treatment: Use as reported campaign/outcome context, not a victim disclosure.

Resecurity INC leak-site cohort

Reports new INC listings across several countries and says it assisted multiple victims, but does not establish the SMA1000 chain as the entry path for each listed organization.

Category: Resecurity INC leak-site cohort Public status: Reports new INC listings across several countries and says it assisted multiple victims, but does not establish the SMA1000 chain as the entry path for each listed organization. Brief treatment: Do not import the wider INC cohort into the confirmed SMA1000 victim count or publish unvalidated victim details.

Volexity cases

Two impacted appliances and activity are described without a public victim list.

Category: Volexity cases Public status: Two impacted appliances and activity are described without a public victim list. Brief treatment: Use for tradecraft, malware, and detection; do not infer organization identity.

Local environment

Unknown until validated

Category: Local environment Public status: Unknown until validated Brief treatment: Asset inventory and compromise assessment required.

KEV and CVE Details

KEV added / due

14-Jul-2026 / 17-Jul-2026

Field: KEV added / due CVE-2026-15409: 14-Jul-2026 / 17-Jul-2026 CVE-2026-15410: 14-Jul-2026 / 17-Jul-2026

Known ransomware campaign use

Known in catalog version 2026.08.03

Field: Known ransomware campaign use CVE-2026-15409: Known in catalog version 2026.08.03 CVE-2026-15410: Known in catalog version 2026.08.03

Authentication / privilege

Unauthenticated; no valid SMA login required

Field: Authentication / privilege CVE-2026-15409: Unauthenticated; no valid SMA login required CVE-2026-15410: Post-authentication / administrator-level when exploited independently (CVSS PR:H). The observed chain uses CVE-2026-15409 to reach the privileged localhost workflow without a conventional administrator login.

Impact

SSRF / WebSocket proxy pivot

Field: Impact CVE-2026-15409: SSRF / WebSocket proxy pivot CVE-2026-15410: Code injection / path traversal to root

Fixed releases

12.4.3-03453+ or 12.5.0-02835+

Field: Fixed releases CVE-2026-15409: 12.4.3-03453+ or 12.5.0-02835+ CVE-2026-15410: 12.4.3-03453+ or 12.5.0-02835+

Workaround

None

Field: Workaround CVE-2026-15409: None CVE-2026-15410: None

Required action

Apply vendor mitigation/fix or discontinue if unavailable

Field: Required action CVE-2026-15409: Apply vendor mitigation/fix or discontinue if unavailable CVE-2026-15410: Apply vendor mitigation/fix or discontinue if unavailable

Post-remediation duty

Review exploitation evidence and exposed trust

Field: Post-remediation duty CVE-2026-15409: Review exploitation evidence and exposed trust CVE-2026-15410: Review root execution/persistence; reimage/redeploy if compromised

Affected product scope also includes SMA1000 CMS across hypervisors. For recovery, use a configuration backup only if it predates installation of 12.4.3-03245 or 12.5.0-02283; otherwise closely audit the configuration for tampering.[8]

MITRE ATT&CK Lifecycle Mapping

T1190 · Exploit Public-Facing Application

Internet-facing SMA1000 exploitation through the WebSocket proxy flaw.

Technique: T1190 · Exploit Public-Facing Application Observed / reported behavior: Internet-facing SMA1000 exploitation through the WebSocket proxy flaw. Defensive breakpoint: Upgrade, reduce exposure, restrict management, and alert on characteristic /wsproxy requests. Confidence: High

Open source

T1059.004 · Unix Shell

Attacker-controlled shell scripts executed through the hotfix-removal path as root.

Technique: T1059.004 · Unix Shell Observed / reported behavior: Attacker-controlled shell scripts executed through the hotfix-removal path as root. Defensive breakpoint: Monitor remove_hotfix, traversed paths, staged scripts, shell execution, and unexpected reboots. Confidence: High

Open source

T1505.003 · Web Shell

ORANGETAIL was injected into a legitimate Java process and exposed through modified routes.

Technique: T1505.003 · Web Shell Observed / reported behavior: ORANGETAIL was injected into a legitimate Java process and exposed through modified routes. Defensive breakpoint: Diff NGINX Unit configuration, inspect Java instrumentation/processes, and validate external 404/gated paths. Confidence: High for Volexity-observed activity

Open source

T1557 · Adversary-in-the-Middle

Volexity observed tcpdump capture of unencrypted LDAP traffic to collect usernames/passwords.

Technique: T1557 · Adversary-in-the-Middle Observed / reported behavior: Volexity observed tcpdump capture of unencrypted LDAP traffic to collect usernames/passwords. Defensive breakpoint: Use encrypted LDAP, monitor packet-capture tools, and rotate exposed credentials. Confidence: High for Volexity-observed activity

Open source

T1003 · OS Credential Dumping / credential access context

Rapid7 reports theft of credentials, session databases, and TOTP seed configurations; exact sub-technique varies by artifact.

Technique: T1003 · OS Credential Dumping / credential access context Observed / reported behavior: Rapid7 reports theft of credentials, session databases, and TOTP seed configurations; exact sub-technique varies by artifact. Defensive breakpoint: Protect/rotate authentication material and alert on sensitive database/path access. Confidence: Medium; behavior is confirmed, exact ATT&CK sub-technique is context-dependent

Open source

T1021 · Remote Services

Appliance-origin authentication attempts into internal systems and domain controllers.

Technique: T1021 · Remote Services Observed / reported behavior: Appliance-origin authentication attempts into internal systems and domain controllers. Defensive breakpoint: Alert on appliance-sourced logons without a matching VPN session and constrain service-account privileges. Confidence: High

Open source

T1572 · Protocol Tunneling

WebSocket tunneling and Suo5 proxy functionality supported access to hidden services and pivoting.

Technique: T1572 · Protocol Tunneling Observed / reported behavior: WebSocket tunneling and Suo5 proxy functionality supported access to hidden services and pivoting. Defensive breakpoint: Inspect unusual bidirectional tunnels, egress, and proxy behavior from the appliance. Confidence: High

Open source

ATT&CK mappings translate observed behavior into a common defensive vocabulary. They do not attribute the activity or prove that every technique occurred in every incident.

Source Weighting / Relevance

SonicWall PSIRT

Tier 0

Source: SonicWall PSIRT Weight: Tier 0 What it supports: Authoritative affected-product, fixed-version, severity, no-workaround, and product-boundary guidance. Limit: Source-bound to its own visibility and publication date.

CISA

Tier 0

Source: CISA Weight: Tier 0 What it supports: Authoritative KEV status. Both CVEs were added July 14 with a July 17 due date; catalog version 2026.08.03 changed known ransomware campaign use to Known for both CVEs. This CVE-level field does not identify an actor or victim. Limit: Source-bound to its own visibility and publication date.

Rapid7

Tier 1

Source: Rapid7 Weight: Tier 1 What it supports: Primary incident-response analysis confirming zero-day exploitation, the two-stage chain, credential/session/TOTP theft, VPN-less lateral movement, and high-value appliance observables. Rapid7's public article does not name INC or ransomware. Limit: Source-bound to its own visibility and publication date.

Volexity

Tier 1

Source: Volexity Weight: Tier 1 What it supports: Primary incident analysis tracking the observed operator as UTA0533, with earliest observed exploitation on June 22 and KNUCKLEBALL, ORANGETAIL, and Suo5 tradecraft. Limit: Source-bound to its own visibility and publication date.

NVD

Tier 1

Source: NVD Weight: Tier 1 What it supports: National vulnerability record for the unauthenticated SSRF/WebSocket proxy flaw. Limit: Source-bound to its own visibility and publication date.

NVD

Tier 1

Source: NVD Weight: Tier 1 What it supports: National vulnerability record for the authenticated code-injection/path-traversal flaw. Limit: Source-bound to its own visibility and publication date.

Dark Reading

Tier 3

Source: Dark Reading Weight: Tier 3 What it supports: Secondary reporting that says Rapid7 tied the observed activity to INC Ransom and that at least one case progressed to ransomware. This is the explicit public source for that linkage. Limit: Secondary reporting; use for the explicit INC linkage, not chain mechanics.

SonicWall

Tier 0

Source: SonicWall Weight: Tier 0 What it supports: Authoritative product notice expanding the affected scope to SMA1000 CMS across hypervisors and directing responders to use only configuration backups that predate the December hotfix baselines, or closely audit the configuration for tampering. Limit: Source-bound to its own visibility and publication date.

Resecurity

Tier 1

Source: Resecurity Weight: Tier 1 What it supports: Primary threat-intelligence and DFIR reporting that assesses continued INC weaponization of the SMA1000 chain and says some devices remained unpatched or compromised. Its INC leak-site victim cohort is not treated as a list of confirmed SMA1000 victims, and its UTA0533-to-INC language is not used to merge the labels. Limit: Source-bound to its own visibility and publication date.

The Hacker News

Tier 3

Source: The Hacker News Weight: Tier 3 What it supports: Secondary reporting carrying a direct Rapid7 statement that INC had emerged as the dominant actor actively weaponizing the chain. Used only for that attributed statement and not to assign UTA0533 or every INC leak-site victim to this campaign. Limit: Source-bound to its own visibility and publication date.

Additional IntelliOS Threat Intel Products on This Topic

CARDS CVE / KEV Library

Open the connected vulnerability records for KEV dates, severity, affected products, campaign relationships, sources, and current official status.

CARDS Campaign Card

Campaign-level view connecting the two CVEs, observed tradecraft, INC reporting, UTA0533, malware, targets, and attribution boundaries.

CARDS Actor Card

Canonical INC Ransom record with the SMA1000 relationship retained at moderate confidence and explicitly sourced to public reporting.

CARDS Actor Card

Volexity-specific activity-cluster record kept deliberately separate from INC unless new corroborating evidence establishes a relationship.

Notes

Create an account and sign-in to use this card.

Record your personal notes and comments in this card related to this brief.

Version Change Log

v1.7

06-Aug-2026 09:06 AM ET

Version: v1.7 Date: 06-Aug-2026 09:06 AM ET Change: Added Resecurity's continued INC weaponization assessment and The Hacker News' direct Rapid7 attribution statement. Kept UTA0533 separate, excluded the wider INC leak-site cohort from the confirmed SMA1000 victim count, preserved CISA's live Known ransomware-use value, and promoted no unvalidated IOCs. Monitoring: Daily through 23-Jan-2027

v1.6

04-Aug-2026 09:04 AM ET

Version: v1.6 Date: 04-Aug-2026 09:04 AM ET Change: CISA KEV catalog version 2026.08.03 changed known ransomware campaign use from Unknown to Known for both CVEs. Revalidated SonicWall, NVD, Rapid7, Volexity, victims, fixes, and IOCs; preserved the boundary between INC Ransom and UTA0533. Monitoring: Superseded by v1.7

v1.5

24-Jul-2026 09:04 AM ET

Version: v1.5 Date: 24-Jul-2026 09:04 AM ET Change: Daily monitor added SonicWall's CMS/all-hypervisors affected scope and configuration-backup trust boundary, revalidated fixed versions and detection/response guidance, preserved CISA's live Unknown ransomware-use value, and found no new named victim or evidence merging INC with UTA0533. Monitoring: Superseded by v1.6

v1.4

23-Jul-2026

Version: v1.4 Date: 23-Jul-2026 Change: Clarified that CVE-2026-15410 is independently a post-authentication, administrator-level code-injection flaw while the observed CVE-2026-15409 chain reaches its privileged localhost workflow without requiring a conventional administrator login. Monitoring: Superseded by v1.5

v1.3

23-Jul-2026

Version: v1.3 Date: 23-Jul-2026 Change: Expanded the Research Framing source-planning ledger through Tier 8, reconciled 33 reviewed sources, and clarified the candidate, selected, and not-used totals while retaining seven cited sources. Monitoring: Superseded by v1.5

v1.2

23-Jul-2026

Version: v1.2 Date: 23-Jul-2026 Change: Standardized the brief's section structure, tables, typography, spacing, related-product presentation, and reader controls; strengthened the Research Framing, BLUF, Executive Summary, timeline, response, and citation sections. Monitoring: Superseded by v1.5

v1.1

23-Jul-2026

Version: v1.1 Date: 23-Jul-2026 Change: Expanded executive and technical explanations of SSRF, WebSocket tunneling, path traversal, and root access; strengthened response guidance and corrected the Rapid7 and Dark Reading attribution boundary. Monitoring: Superseded by v1.5

v1.0

23-Jul-2026

Version: v1.0 Date: 23-Jul-2026 Change: Initial publication with connected CARDS campaign, actor, CVE, alert, PANDA, and FORGE records, including explicit attribution boundaries and remediation guidance. Monitoring: Superseded by v1.5

Citations

1

Tier 0

#: 1 Tier: Tier 0 Publisher: SonicWall PSIRT Published: July 14, 2026 Why Used: Authoritative affected-product, fixed-version, severity, no-workaround, and product-boundary guidance. Source: SNWLID-2026-0008: SMA1000 Multiple Vulnerabilities https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008

https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008

2

Tier 0

#: 2 Tier: Tier 0 Publisher: CISA Published: Live catalog; checked August 6, 2026 Why Used: Authoritative KEV status. Both CVEs were added July 14 with a July 17 due date; catalog version 2026.08.03 changed known ransomware campaign use to Known for both CVEs. This CVE-level field does not identify an actor or victim. Source: Known Exploited Vulnerabilities Catalog https://www.cisa.gov/known-exploited-vulnerabilities-catalog

https://www.cisa.gov/known-exploited-vulnerabilities-catalog

3

Tier 1

#: 3 Tier: Tier 1 Publisher: Rapid7 Published: July 2026 Why Used: Primary incident-response analysis confirming zero-day exploitation, the two-stage chain, credential/session/TOTP theft, VPN-less lateral movement, and high-value appliance observables. Rapid7's public article does not name INC or ransomware. Source: Rapid7 MDR Discovers SonicWall SMA1000 Zero-Days Being Actively Exploited https://www.rapid7.com/blog/post/etr-rapid7-mdr-team-discovers-new-sonicwall-sma1000-zero-days-being-actively-exploited-cve-2026-15409-cve-2026-15410/

https://www.rapid7.com/blog/post/etr-rapid7-mdr-team-discovers-new-sonicwall-sma1000-zero-days-being-actively-exploited-cve-2026-15409-cve-2026-15410/

4

Tier 1

#: 4 Tier: Tier 1 Publisher: Volexity Published: July 17, 2026 Why Used: Primary incident analysis tracking the observed operator as UTA0533, with earliest observed exploitation on June 22 and KNUCKLEBALL, ORANGETAIL, and Suo5 tradecraft. Source: Proxying to Compromise: SonicWall Secure Mobile Access 0-Day Exploitation https://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/

https://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/

5

Tier 1

#: 5 Tier: Tier 1 Publisher: NVD Published: July 2026 Why Used: National vulnerability record for the unauthenticated SSRF/WebSocket proxy flaw. Source: CVE-2026-15409 Detail https://nvd.nist.gov/vuln/detail/CVE-2026-15409

https://nvd.nist.gov/vuln/detail/CVE-2026-15409

6

Tier 1

#: 6 Tier: Tier 1 Publisher: NVD Published: July 2026 Why Used: National vulnerability record for the authenticated code-injection/path-traversal flaw. Source: CVE-2026-15410 Detail https://nvd.nist.gov/vuln/detail/CVE-2026-15410

https://nvd.nist.gov/vuln/detail/CVE-2026-15410

7

Tier 3

#: 7 Tier: Tier 3 Publisher: Dark Reading Published: July 2026 Why Used: Secondary reporting that says Rapid7 tied the observed activity to INC Ransom and that at least one case progressed to ransomware. This is the explicit public source for that linkage. Source: INC Ransomware Exploits SonicWall SMA Zero-Days https://www.darkreading.com/vulnerabilities-threats/inc-ransomware-exploits-sonicwall-sma-zero-days

https://www.darkreading.com/vulnerabilities-threats/inc-ransomware-exploits-sonicwall-sma-zero-days

8

Tier 0

#: 8 Tier: Tier 0 Publisher: SonicWall Published: July 14, 2026; updated July 15, 2026 Why Used: Authoritative product notice expanding the affected scope to SMA1000 CMS across hypervisors and directing responders to use only configuration backups that predate the December hotfix baselines, or closely audit the configuration for tampering. Source: Product Notice: SMA 1000 Series affected by Multiple Vulnerabilities https://www.sonicwall.com/support/notices/product-notice-sma-1000-series-affected-by-multiple-vulnerabilities/kA1VN000001nv6D0AQ

https://www.sonicwall.com/support/notices/product-notice-sma-1000-series-affected-by-multiple-vulnerabilities/kA1VN000001nv6D0AQ

9

Tier 1

#: 9 Tier: Tier 1 Publisher: Resecurity Published: August 1, 2026 Why Used: Primary threat-intelligence and DFIR reporting that assesses continued INC weaponization of the SMA1000 chain and says some devices remained unpatched or compromised. Its INC leak-site victim cohort is not treated as a list of confirmed SMA1000 victims, and its UTA0533-to-INC language is not used to merge the labels. Source: From WSProxy to Root: INC Ransomware and SonicWall SMA Exploit Chain https://www.resecurity.com/blog/article/from-wsproxy-to-root-inc-ransomware-and-sonicwall-sma-exploit-chain

https://www.resecurity.com/blog/article/from-wsproxy-to-root-inc-ransomware-and-sonicwall-sma-exploit-chain

10

Tier 3

#: 10 Tier: Tier 3 Publisher: The Hacker News Published: August 3, 2026 Why Used: Secondary reporting carrying a direct Rapid7 statement that INC had emerged as the dominant actor actively weaponizing the chain. Used only for that attributed statement and not to assign UTA0533 or every INC leak-site victim to this campaign. Source: INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws https://thehackernews.com/2026/08/inc-ransomware-emerges-as-dominant.html

https://thehackernews.com/2026/08/inc-ransomware-emerges-as-dominant.html

Retained Sources · Revalidated 06-Aug-2026

Related published intelligence

Catalog navigation. A relationship does not establish common actors or incidents.

  • INC Ransom

    Exact related IntelliOS product link retained from /vault/inc-ransom-sonicwall-sma1000-zero-day-exploitation.

  • SonicWall Credential Attacks: Successful Firewall Logins and Cloud-Backup Risk

    Exact related IntelliOS product link retained from /vault/sonicwall-credential-stuffing-cloud-backup-risk.

  • SonicWall SMA1000 Zero-Day Exploitation Campaign

    Exact related IntelliOS product link retained from /vault/inc-ransom-sonicwall-sma1000-zero-day-exploitation.

  • UTA0533

    Exact related IntelliOS product link retained from /vault/inc-ransom-sonicwall-sma1000-zero-day-exploitation.