SonicWall SMA1000: INC Ransomware extracting MFA seeds and session tokens then deploying ransomware via 22-day zero-day chain      N-able N-central CVE-2026-18577: patch bypass exploited to reach managed customer endpoints via built-in Take Control feature      UK Police National Legal Database: 100,000-plus officer home addresses, personal numbers, and roles exposed in breach      SonicWall SMA1000: INC Ransomware extracting MFA seeds and session tokens then deploying ransomware via 22-day zero-day chain      N-able N-central CVE-2026-18577: patch bypass exploited to reach managed customer endpoints via built-in Take Control feature      UK Police National Legal Database: 100,000-plus officer home addresses, personal numbers, and roles exposed in breach     
CyberSipTM
Intelligence without the noise
Issue No. 100
August 4, 2026
3 items · past 24h
<5 min read
Today's picture

INC Ransomware has emerged as the dominant actor exploiting SonicWall SMA1000 CVE-2026-15409 and CVE-2026-15410, a CVSS 10.0 WebSocket bypass chained with a root escalation that ran as a zero-day for 22 days before the July 14 patch, with Resecurity confirming the group is extracting VPN credentials, active session databases, and MFA seed configurations before deploying ransomware. N-able disclosed that attackers bypassed the patch for a prior N-central authentication bypass within days of its release, exploiting CVE-2026-18577 to gain admin access to the RMM console, pivot into managed customer endpoints using the built-in Take Control feature, and install Cloudflare tunnels that persist after N-central access is revoked. And attackers breached the UK Police National Legal Database, exposing contact data for more than 100,000 police officers and criminal justice professionals including home addresses, personal phone numbers, and current postings.

Today's intelligence
3 items
01 CriticalSonicWall SMA1000INC Ransomware
INC Ransomware is the dominant actor using the SonicWall SMA1000 zero-day chain to steal MFA seeds and session tokens before deploying ransomware
The chain was exploited for 22 days before SonicWall even knew about it. Attackers do not just use the foothold for ransomware — they extract the MFA seed database first, giving them the ability to generate valid one-time codes for every VPN user going forward. Patching closes the entry. It does not invalidate those seeds.
CVEsCVE-2026-15409
CVSS 10.0
CVE-2026-15410
CVSS 7.2
Exploited sinceJune 22, 2026
(zero-day)
PatchedJuly 14, 2026
Active actorINC Ransomware
885 victims to date
AffectsSMA1000 6210
7210, 8200v
Resecurity published a report on August 3 identifying INC Ransomware as the dominant threat actor exploiting CVE-2026-15409 and CVE-2026-15410 in SonicWall SMA1000 series appliances. INC Ransomware has claimed 885 victims across its operational history and added multiple new victims to its data leak site in the first days of August. The vulnerability pair was discovered by Rapid7's Managed Detection and Response team, which observed active zero-day exploitation beginning June 22, 2026, 22 days before SonicWall published its advisory and patch on July 14. CVE-2026-15409, rated CVSS 10.0, is a pre-authentication server-side request forgery in the SMA1000 WorkPlace WebSocket proxy that allows an unauthenticated remote attacker to open a tunnel to arbitrary internal services on the appliance. CVE-2026-15410, rated CVSS 7.2, is a path traversal and code injection flaw that allows an attacker with access to an internal localhost service to execute arbitrary commands as root through the appliance's hotfix management workflow. Chained together, the two vulnerabilities provide unauthenticated root-level remote code execution on internet-facing VPN gateways used by enterprises, government agencies, and managed security providers. Rapid7 documented that the attacks went significantly beyond initial access: attackers extracted high-value credentials stored on the appliance, active VPN session databases, and crucially, Time-Based One-Time Password MFA seed configurations. TOTP seeds are the shared secrets from which every future one-time code for enrolled users can be generated. An attacker in possession of those seeds can produce valid MFA codes for every enrolled VPN user indefinitely, independently of the appliance. CISA added both CVEs to its Known Exploited Vulnerabilities catalog on July 14 with a 72-hour patch deadline for federal agencies. Volexity separately attributed early zero-day exploitation to a previously untracked cluster designated UTA0533 that installed custom malware on compromised appliances before INC Ransomware became the dominant follow-on actor.
MFA seed theft is the critical detail in this attack chain and the one most likely to be missed in standard remediation. Patching CVE-2026-15409 and CVE-2026-15410 closes the remote code execution path through which the seeds were stolen. It does not invalidate the seeds themselves. An organization that patches and considers the incident closed has closed the door through which the attacker entered, but the attacker now holds the ability to generate valid MFA codes for every VPN user indefinitely. That capability persists until the TOTP seeds are rotated and every enrolled user re-registers their authenticator application.
SonicWall SMA1000 appliances are the third VPN or secure access gateway product to drive a major ransomware campaign this year following Ivanti Connect Secure and Palo Alto PAN-OS in earlier months. The pattern is structural: internet-facing gateways that aggregate credentials, session data, and access controls are the highest-value initial access targets available to ransomware operators because a single compromise provides the foothold and the lateral movement path simultaneously. The 22-day zero-day window before disclosure is also consistent with the broader trend this brief has tracked all year: exploitation begins substantially before the patch exists. Organizations with SMA1000 appliances should treat any device that was internet-accessible between June 22 and the patch date as potentially compromised and initiate forensic review accordingly.
  • Apply the July 14 SonicWall patches immediately if not already done. Fixed versions are firmware 12.4.3-03453 or later on the 12.4 branch and 12.5.0-02835 or later on the 12.5 branch. Any SMA1000 6210, 7210, or 8200v still on an earlier version should be treated as actively compromised and patched or taken offline today.
  • Rotate all TOTP MFA seeds for VPN users enrolled through the compromised SMA1000 appliances. Patching does not invalidate stolen seeds. Every user whose seed was stored on the appliance during the June 22 to July 14 window should re-register their authenticator application against a freshly generated seed.
  • Review SonicWall's published indicators of compromise against appliance logs covering June 22 onward. If UTA0533 custom malware artifacts or INC Ransomware staging activity are found, treat the investigation as a full incident response, not a patch-and-close exercise. Rotate VPN credentials and session tokens and hunt for lateral movement that originated from the appliance after June 22.
They took the MFA seeds. Patch the appliance and the door closes. The seeds still work. Every future one-time code for every enrolled user can still be generated by whoever extracted that database. Patch first. Then rotate every seed. Then check the logs from June 22 forward.
02 HighN-able N-centralRMM / MSP
Attackers broke through N-central's own patch within days and are now using admin access to reach every endpoint the RMM platform manages
N-able patched CVE-2026-18556 and attackers found an alternate path before customers had finished applying the first fix. CVE-2026-18577 gives an unauthenticated attacker admin access to the N-central console, and from there the built-in Take Control feature is the pivot to every managed endpoint. They are also installing Cloudflare tunnels that survive N-central access revocation.
CVECVE-2026-18577
CVSS 8.2
TypePatch bypass of
CVE-2026-18556
KEV addedAugust 3, 2026
Fixed inN-central 2026.3
Hotfix 1 (2026.3.1.7)
On-prem updateManual required
N-able first noticed unusual licensing errors from on-premises N-central customers on July 31, 2026. Investigation confirmed that attackers had exploited CVE-2026-18556, an authentication bypass rated CVSS 8.2, to gain unauthenticated administrative access to N-central servers running version 2026.1 and earlier. N-able released a first hotfix on August 2, which addressed the known exploit path. By August 3, N-able had identified that attackers found a second route to the same authentication bypass that the first hotfix did not close. That alternate path was assigned CVE-2026-18577, also rated CVSS 8.2, and a second hotfix was released as N-central 2026.3 Hotfix 1, build 2026.3.1.7. CISA added CVE-2026-18577 to its Known Exploited Vulnerabilities catalog on August 3. Both hosted and on-premises deployments are affected. Hosted instances received the update automatically. On-premises customers must install the hotfix manually. Huntress, which confirmed seeing attacks exploiting CVE-2026-18577, documented the post-exploitation pattern: attackers log in to the N-central console with administrative rights, use the built-in Take Control feature to open remote-control sessions on managed endpoints, and install a Windows service named Cloudflared that establishes an encrypted outbound Cloudflare tunnel. That tunnel provides persistent command-and-control access to the managed endpoint that survives N-central access revocation, firewall rule changes, and system reboots. N-able published six IP addresses observed in attacks, which Huntress identified as Mullvad and NordVPN exit nodes used to anonymize attacker traffic. N-able has not disclosed the number of customers affected.
N-central is a remote monitoring and management platform used by managed service providers and enterprise IT teams to monitor, patch, and remotely access hundreds to thousands of endpoints from a single console. An attacker with administrative access to N-central does not have access to one compromised server. They have remote-control access to every endpoint under management, including domain controllers, security appliances, and customer environments managed by MSPs on behalf of their clients. The Cloudflare tunnel persistence mechanism compounds this: revoking the attacker's N-central access does not remove the tunnels already installed on managed endpoints. Each tunnel must be identified and removed individually on each affected device.
The patch bypass timeline here is operationally significant. N-able patched CVE-2026-18556 on August 2. Attackers had identified and exploited the alternate path by August 3, the same day CISA added the new CVE to KEV. Organizations that applied the August 2 hotfix and considered themselves remediated were exposed for less than 24 hours before the bypass was confirmed. This is an unusually short gap between patch and bypass confirmation and reflects active attacker analysis of the fix rather than opportunistic scanning. MSPs running N-central should assume the alternate path was being tested from the moment the first hotfix was published and treat any N-central server that was accessible on August 2 as potentially exposed to CVE-2026-18577 even if CVE-2026-18556 was patched.
  • Update N-central to 2026.3 Hotfix 1 build 2026.3.1.7 immediately. This is the only version that closes both CVE-2026-18556 and CVE-2026-18577. The August 2 hotfix for CVE-2026-18556 alone is not sufficient. On-premises deployments require a manual update.
  • Hunt for Cloudflare tunnel persistence on all endpoints managed through N-central, not just those where Take Control sessions are visible in N-central logs. Check for a Windows service named Cloudflared or a svchost.exe binary located in a user's Documents folder. These are N-able's documented indicators of compromise for post-exploitation persistence.
  • Correlate N-central access logs against the six IP addresses N-able published and the Mullvad and NordVPN exit node ranges Huntress identified. Any administrative session originating from VPN exit nodes in those ranges should be treated as potentially attacker-controlled and trigger endpoint investigation for the Cloudflare tunnel indicators.
N-able patched the authentication bypass on August 2. Attackers had the alternate path working by August 3. The Cloudflare tunnels they installed on managed endpoints are still there after N-central access is revoked. Update to 2026.3.1.7, then go find the tunnels on the endpoints. The N-central server is not the only thing that needs cleaning.
03 HighUK PoliceData Breach
A breach of the UK Police National Legal Database exposed home addresses, personal phone numbers, and postings for more than 100,000 police officers
The PNLD is a reference system used by UK police and criminal justice professionals. The data exposed is the specific combination that creates personal safety risk: home addresses and personal contact details for officers whose identities are known to individuals with criminal histories.
OrganizationUK Police National
Legal Database
Exposed100,000+ police
officers and criminal
justice professionals
Data typesHome addresses
Personal phones
Current postings
Roles
DisclosedAugust 3, 2026
A cyberattack on the UK Police National Legal Database was confirmed on August 3, 2026, compromising the contact data of more than 100,000 police officers and criminal justice professionals. The PNLD is a reference system providing access to legal resources, case law, and procedural guidance for law enforcement and related professionals across the UK. Exposed data includes home addresses, personal mobile and phone numbers, and current posting locations and roles. The combination of home address, personal contact details, and role information for individuals in the law enforcement and criminal justice system represents a category of data breach with distinct personal safety implications beyond the typical financial fraud risk of consumer data breaches. The responsible authorities have not yet publicly confirmed the attack vector or threat actor responsible. The Information Commissioner's Office has been notified. No operational police systems or investigative databases are reported to have been accessed in connection with this breach.
This is the third significant UK law enforcement data exposure in 2026, following the Metropolitan Police contractor breach in February and the South Yorkshire Police supply chain incident in May. The PNLD breach is the largest by officer count and the most sensitive by data type. Home addresses and personal phone numbers for law enforcement officers are the data that organized crime networks, stalkers, and foreign adversaries specifically seek. The UK's National Police Chiefs' Council has previously described police officer data as a target of sustained interest by serious organized crime groups seeking to identify and locate officers. The PNLD breach puts that data in front of any actor who obtained it.
The breach notification as of August 3 has not confirmed the attack vector or the threat actor. The PNLD provides access to legal reference material rather than operational policing databases, meaning the primary value of the breach to a criminal or state actor is likely the officer contact data itself rather than the legal content the system holds. The distinction matters for response: this breach requires personal security reviews for affected officers, not operational investigation database audits. UK law enforcement personnel whose data was held in PNLD should expect direct notification from their force and should review their personal security arrangements, particularly home address visibility on any public-facing systems or directories.
  • UK law enforcement and criminal justice professionals who receive notification should review their personal security posture: check whether home address information appears in any public directories, electoral roll lookups, or social media profiles, and consider whether to take steps to suppress it through available mechanisms including the Electoral Register opt-out for public inspection purposes.
  • Criminal justice and law enforcement organizations should audit their supply chain and third-party access to personnel data systems following three significant data exposures affecting UK policing in 2026. Supply chain compromise and third-party access were the vectors in two of the three prior incidents.
Home addresses and personal phone numbers for 100,000 police officers and criminal justice professionals. The PNLD holds legal reference material, not case files. What makes this breach significant is not what the system contained about cases. It is what it contained about the people who work them.
Cross-source standouts
01
SonicWall and N-central together: two stories where patching is necessary but specifically not sufficient
Both stories today carry the same structural lesson about remediation completeness. In the SonicWall case, applying the July 14 patch closes the remote code execution path but leaves stolen TOTP seeds fully operational. In the N-central case, applying the August 2 hotfix closed the known authentication bypass path but left the alternate path open, and the Cloudflare tunnels installed before or during that window remain active on managed endpoints after N-central access is revoked. This brief has returned to the post-patch investigation problem repeatedly in July: CitrixBleed 2 session tokens surviving patching, SharePoint IIS machine keys surviving patching, OWAReaper surviving credential rotation and re-imaging. Both stories today extend the same argument specifically to MFA and persistence mechanisms. Patching closes the entry. It does not undo what was done before the entry was closed, and it does not remove the persistence mechanisms that were installed while it was open. The remediation checklist for both incidents today has two phases: apply the patch, and then separately identify and remove everything the attacker put in place before the patch arrived.
02
The N-central patch bypass confirms what the FortiOS bypass in Issue 95 showed: attackers are actively analyzing fixes to find alternate paths
Issue 95 covered CVE-2025-68686, a Fortinet FortiOS SSL-VPN patch bypass that restored the attack surface of three prior CVEs exploited continuously since 2022. The N-central situation is a faster and more compressed version of the same dynamic. N-able patched CVE-2026-18556. Attackers identified and exploited an alternate authentication bypass path within approximately 24 hours of the patch release, producing CVE-2026-18577. The rapid turnaround between patch publication and bypass exploitation suggests the attackers had already reverse-engineered the authentication implementation before the fix was released, likely during the window of exploitation, and were prepared to pivot to the alternate path the moment the primary one was closed. This is the attacker behavior that makes incomplete patches particularly dangerous for high-value platforms: once a platform has demonstrated exploitability and the attacker has already reverse-engineered its authentication layer, follow-on bypasses can arrive faster than the organization's patch cycle. For RMM platforms with the reach of N-central, the response to any authentication vulnerability should include a broader review of the authentication implementation rather than a targeted fix for the specific observed exploitation path.
Still watching
Days 2–5
Anthropic Claude evaluation incidents (Issue 99 · three organizations breached) — Anthropic suspended all cybersecurity evaluations July 23. Two victims were unaware until July 27. Investigation ongoing. Organizations that participated in evaluations with Irregular between April and July 2026 should confirm status with Anthropic directly.
Day 2
Laundry Bear OWAReaper CVE-2026-42897 (Issue 98 · active exploitation) — half-click OWA XSS delivers server-side backdoor surviving credential rotation and re-imaging. Patch May 2026 Exchange updates. Cleanup requires Exchange server inspection. Use Proofpoint IoCs to confirm whether cleanup is complete.
Day 4
Cisco FMC CVE-2026-20316 (Issue 99 · hardcoded credential, federal deadline passed) — static credential actively exploited. Apply the hotfix immediately. Check logs for authentication from unexpected IPs since July. Also verify CVE-2026-20079 is patched to close the root escalation chain.
Day 5
LegacyHive (Issue 88 · Nightmare Eclipse, no patch) — Windows User Profile Service privilege escalation. Working proof of concept on fully patched systems. No CVE, no fix. Now at Day 18. Three prior disclosures in this series were exploited before patches arrived.
Day 7+