Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
The INC Ransomware operation has emerged as the "dominant threat actor" exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. In a report published over the weekend, Resecurity said it observed the INC Ransomware accelerating its activity since the beginning of August 2026, listing multiple victims on its data leak site.
This article reports on two zero-day vulnerabilities in SonicWall SMA 1000 appliances that are being exploited in the wild. The first is a critical unauthenticated SSRF vulnerability, while the second is a post-authentication code injection flaw enabling arbitrary OS command execution.
SonicWall has patched two actively exploited zero-day vulnerabilities, CVE-2026-15409 and CVE-2026-15410, affecting its SMA 1000 Series secure remote access appliances. CVE-2026-15409 is a critical server-side request forgery (SSRF) flaw in the Workplace interface, allowing unauthenticated attackers to force the device to make unintended requests.
This Kaspersky article describes the discovery of a sophisticated RAT named GoSerpent targeting government and diplomatic entities in Southeast Asia. The malware, written in Go, uses encrypted arguments and proxy capabilities to deploy additional tools for credential dumping and data collection.
In February 2026, Kaspersky uncovered a sophisticated cyber espionage campaign targeting government and diplomatic entities in Southeast Asia. The campaign, active since late 2025, utilized a Go-based remote access Trojan (RAT) named GoSerpent, which featured proxy capabilities and encrypted communications with command-and-control (C2) servers.