Inc Ransomware Hits SonicWall Zero-Days & an 11-Byte OpenSSL Flaw (07/17/2026)
- › Inc ransomware is chaining two SonicWall SMA zero-days to gain root-level control of the mobile access appliance sitting at the network edge.
- › An 11-byte TLS request makes an unpatched OpenSSL server reserve up to 131 KB it never gets back, enough to freeze memory on a small box.
- › CISA ordered agencies to patch critical FortiSandbox command injection flaws after researchers spotted exploitation attempts.
- › OpenAI's GPT-5.6 wiped users' home directories in Full Access Mode, doing destructive work on its own without being asked.
- › A Go botnet called NadMesh is scanning for exposed AI services, and its own dashboard claims 3,811 stolen AWS keys.
Three of today’s stories share one address: the edge of your network, where the appliance you trust to let people in becomes the way the adversary gets root. Inc ransomware is chaining two SonicWall zero-days, CISA is ordering agencies to patch FortiSandbox under active attack, and an 11-byte OpenSSL request can freeze a server’s memory. The theme is the same one it always is: the box guarding the door is a target, not a shield.
Top 5 Critical Security Alerts
1. Inc Ransomware Chains Two SonicWall SMA Zero-Days for Root
Inc ransomware is exploiting two zero-days in SonicWall Secure Mobile Access (SMA) 1000 appliances, chaining an unauthenticated SSRF (CVE-2026-15409, rated 10.0) to reach internal services and a code injection flaw (CVE-2026-15410) to run commands as root (Dark Reading, Rapid7). The SMA appliance is the remote-access front door, which means the crew starts its intrusion already sitting on the box that terminates your VPN and trusts nobody by design, except now it trusts them. CISA set a federal patch deadline of today, July 17.
Operator Note: An edge appliance under active zero-day exploitation is the one asset you cannot afford to leave until the next maintenance window. If you run SonicWall SMA, hunt it before you patch it, because a foothold may already be there.
2. Eleven Bytes Freeze an OpenSSL Server’s Memory
Okta’s Red Team disclosed HollowByte, a flaw where an 11-byte TLS request makes an unpatched OpenSSL server reserve up to 131 KB for a message that never arrives, and the memory is not returned until the process restarts (The Hacker News, BleepingComputer). Okta measured 547 MB frozen on a 1 GB NGINX server and 25% of memory locked on a 16 GB box, all while the attack bandwidth stayed under the threshold that would trip an alert. OpenSSL shipped the fix on June 9 across the 3.0 through 4.0 branches, though it rated it a hardening bug rather than a CVE.
Operator Note: The asymmetry is the whole story. Eleven bytes in, 131 KB tied up, below your alerting floor. Patch OpenSSL and stop reading raw bandwidth as the only sign of a denial-of-service attempt.
3. CISA Orders Agencies to Patch Exploited FortiSandbox Flaws
CISA added critical command injection vulnerabilities in Fortinet’s FortiSandbox to its Known Exploited Vulnerabilities catalog and issued a patch order after researchers spotted abuse attempts (The Register). Command injection on a security appliance is a bitter twist, because the box you bought to detonate malware safely becomes the thing running the attacker’s commands for real.
4. GPT-5.6 Deleted Users’ Home Directories on Its Own
OpenAI’s GPT-5.6 wiped users’ entire home directories in several cases, mostly in the unprotected Full Access Mode, by overwriting a temporary directory variable and then carrying out destructive actions without being told to (The Decoder). Give an agent the keys and it does not need to be malicious to be catastrophic, it just needs to be wrong while holding root, which is the same blast-radius math we apply to any account that can delete everything.
Operator Note: An AI agent with full filesystem access is a privileged account. Scope it like one, or the next incident report will say a model did what no attacker bothered to.
5. NadMesh Botnet Hunts Exposed AI Services for Cloud Keys
A Go botnet called NadMesh surfaced in early July scanning for exposed AI services such as ComfyUI, Ollama, and Open WebUI, and its operator’s own dashboard claims 3,811 unique AWS keys harvested (The Hacker News). Everyone stood up an AI service this year, most of them fast, and NadMesh is proof the adversary already built the scanner to find the ones nobody locked down.
Additional Security Alerts
Security Breaches & Incidents
- Abbott Investigates Two Cyber Incidents: Abbott Laboratories confirmed unauthorized access to legacy Exact Sciences systems in its Cancer Diagnostics business, while separately probing an extortion claim. BleepingComputer
- Government Agencies Hit by Ransomware Daily: A new study warns that public-sector organizations are being targeted every day by attackers who know agencies cannot tolerate service disruption and are more likely to pay. Infosecurity Magazine
Threat Intelligence
- GoldenEyeDog Linked to the DigiCert Breach: Researchers attributed the April 2026 DigiCert incident to a GoldenEyeDog subgroup and tied it to code-signing certificate theft, the kind of supply chain trust theft that lets malware sign itself as legitimate. The Hacker News
- North Korea Hides Malware in SVG Flag Images: The Contagious Interview crew is using steganography in SVG files to smuggle OtterCookie-aligned malware through fake coding challenges aimed at job seekers. The Hacker News
- ACR Stealer Rides ClickFix Into Microsoft 365: Microsoft Defender Experts tracked increased ACR Stealer activity using ClickFix lures to lift browser tokens, session cookies, and files synced from OneDrive and SharePoint. Microsoft Security
Cloud & Network Security
- Seven Malicious npm Packages Target Vite: Checkmarx flagged a supply chain campaign it calls ViteVenom, seven malicious npm packages using blockchain-based command and control to deliver a remote access trojan through the Vite tooling ecosystem. The Hacker News
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.