What Happened
Resecurity published research on August 4 identifying INC Ransomware as the dominant threat actor now exploiting CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 in SonicWall Secure Mobile Access 1000 series VPN appliances. The group’s activity has accelerated sharply since the start of August.
The two flaws work as a chain. CVE-2026-15409 allows an unauthenticated remote attacker to open a WebSocket tunnel to internal services that should require authentication, using a path-confusion flaw in the WSProxy endpoint. CVE-2026-15410 then provides a post-authentication command injection vector that achieves root privilege escalation on the appliance. Together they give an attacker unauthenticated root access to the SMA1000 device.
Resecurity observed attackers extracting active session tokens, stored user credentials, and TOTP seeds from compromised appliances. The theft of TOTP seeds is significant: it gives attackers the ability to generate time-based one-time codes independently, bypassing multi-factor authentication on internal applications protected by the SMA1000 gateway even after a victim organization rotates passwords. INC Ransomware has claimed 885 total victims, with new victims listed as recently as August 2.
Both vulnerabilities were patched by SonicWall on July 14 and added to the CISA Known Exploited Vulnerabilities catalog the same day. Evidence indicates exploitation as zero-days began in late June — at least two weeks before patches were available.
Why This Matters for Canadian Organizations
SonicWall SMA1000 appliances are widely deployed in Canadian enterprise, healthcare, and government environments as remote access VPN gateways. Organizations in the financial services, insurance, telecommunications, and public sector segments use these devices to provide secure remote access for staff and contractors.
The TOTP seed extraction capability is the most serious aspect of this campaign. When attackers extract TOTP seeds from a compromised SMA1000, they retain the ability to generate valid MFA codes for any account registered to that gateway — even after the victim organization has changed every password, rotated certificates, and believed the incident closed. This type of persistent post-compromise access is difficult to detect without dedicated investigation of the VPN gateway itself. Organizations operating under OSFI Guideline B-13 should treat a compromised SMA1000 as requiring full MFA re-enrollment for all affected users, not simply a password reset.
Canadian organizations that have not patched CVE-2026-15409 and CVE-2026-15410 face an elevated risk of INC Ransomware intrusion. Given the group’s demonstrated capability for lateral movement and double extortion, a compromised SMA1000 gateway is a credible initial access point for a network-wide ransomware deployment. PIPEDA breach notification obligations are triggered if personal data was exfiltrated during any period of unauthorized access.
What to Do
Verify that your SonicWall SMA1000 firmware is patched to the version released on July 14. Apply the patch immediately if you have not done so. After patching, review SMA1000 session logs for authentication events from unexpected IP addresses or geographic locations in the June 22 to August 4 window. If you identify unauthorized access, treat TOTP seeds registered to that gateway as compromised: re-enroll all affected users in MFA using a new authenticator seed rather than relying on existing app entries. Rotate all user credentials authenticated through the gateway during the exposure window. Report any confirmed unauthorized access to your incident response provider and, where applicable, to the CCCS and your OSFI-regulated entity’s supervisory relationship.
Source: The Hacker News | SecurityWeek | Resecurity






