Rebuild and Reissue: SMA 1000 Remediation After INC Ransomware
The SonicWall SMA 1000 exploit chain gets from unauthenticated HTTP to root through a loopback service and a control-service password derived from the appliance’s DMI product_uuid. Rapid7 and Resecurity assess INC Ransomware as the dominant actor now weaponizing it, and the loot — session databases and TOTP seeds — is why patching alone does not end the incident.