Bitdefender’s August 2026 Threat Debrief puts 873 claimed ransomware victims in July, its third-highest monthly tally in a year, but the most immediate action item for administrators is narrower: SonicWall SMA 1000 appliances affected by CVE-2026-15409 and CVE-2026-15410 need patching and compromise review, not merely a routine firmware check.

The Bitdefender report, based partly on ransomware leak sites, also highlights the sudden emergence of CRPx0, continued volume from The Gentlemen and Qilin, activity attributed to Global Secret Group, and another purported LAPSUS$ exit. Those items are useful indicators of criminal-market activity. They are not equivalent to verified breach counts, victim impact, or even proof that a group named on a leak site conducted the initial intrusion.

That distinction becomes especially important in the report’s SonicWall section. Bitdefender says several reports identified INC Ransom exploiting the two SMA 1000 flaws and associates the campaign with KNUCKLEBALL and ORANGETAIL malware. SonicWall, CISA, NVD, Volexity, and independent reporting all confirm active exploitation and the technical attack chain. But Volexity attributes the observed pre-disclosure campaign to a cluster it calls UTA0533, not INC Ransom. As of August 12, no public primary-source record establishes that UTA0533 and INC Ransom are the same operator.

For defenders, that attribution gap does not reduce the urgency. It changes what should be reported internally: an exploited perimeter appliance is an incident requiring evidence preservation, credential response, and forensic review—not a ransomware event that can safely be summarized by a leak-site label.

A hacker monitors a network device amid servers, code, and red alerts for CVE-2026-15409 and CVE-2026-15410.CRPx0’s victim count is a marketing claim before it is a trend​

Bitdefender says CRPx0 moved from fewer than 10 reported victims in June to 46 claimed victims in July, with targets shifting from small dental practices to technology and financial-services organizations. The operation’s claimed activity also expanded from primarily U.S. victims to a cluster of Turkish organizations.

The vendor’s strongest observation is not that CRPx0 is a major new ransomware power, but that its reported growth has unusual characteristics. Bitdefender noted near-synchronous ransom countdowns and raised the possibility that the group could be republishing datasets obtained elsewhere rather than conducting every underlying breach. That is a material caveat: a leak site demonstrates that someone possesses—or claims to possess—data. It does not establish initial access, encryption, payment, or the authenticity and completeness of the stolen material.

Independent threat-tracking pages do show CRPx0 listings, including dental organizations, and Emerging Threats added detection rules for CRPx0-related domains and payload activity earlier this year. Those records support the conclusion that the name is attached to observed malicious infrastructure and extortion claims. They do not independently validate Bitdefender’s 46-victim July total or prove every named organization was compromised by the same actor.

CRPx0’s advertised business model is another reason to be skeptical of its apparent scale. Bitdefender reports a $10,000 one-time fee for a white-label ransomware service, paired with a promise that buyers retain 100% of ransom proceeds. A separate affiliate page reportedly advertises 70% profit sharing. Those incompatible pitches are not evidence of a mature ransomware-as-a-service operation. They are evidence of a sales operation trying to recruit criminals, and potentially to extract money from them.

The group’s apparent blending of ransomware, hacking as a service, clipboard hijacking, and cryptocurrency-wallet seed phrase theft is more consequential than the affiliate economics. A campaign that steals a wallet recovery phrase or swaps a copied cryptocurrency address can monetize quickly and quietly, while data theft and encryption create the larger extortion opportunity. Windows endpoint teams should therefore avoid treating ransomware prevention as a control set focused only on mass file changes.

Controls need to catch the earlier behaviors: fake CAPTCHA or ClickFix pages that persuade users to run commands, suspicious script execution, browser-to-command-shell handoffs, credential theft, clipboard monitoring, and anomalous access to cryptocurrency-wallet files or browser data. A clean backup remains essential for ransomware recovery, but it does nothing for stolen credentials, copied data, or drained wallets.


SonicWall SMA 1000 patches are only the first step​

SonicWall disclosed CVE-2026-15409 and CVE-2026-15410 on July 14, describing active exploitation of SMA 1000 Series appliances. The affected products include SMA 6210, SMA 7210, SMA 8200v, and Central Management Server deployments on specified 12.4.3 and 12.5.0 hotfix builds. The fixed releases are 12.4.3-03453 or later and 12.5.0-02835 or later.

CVE-2026-15409 is a critical server-side request forgery issue with a CVSS score of 10.0. CVE-2026-15410 is a high-severity code-injection vulnerability scored at 7.2. CISA added both to its Known Exploited Vulnerabilities catalog on July 14, giving U.S. federal civilian agencies a July 17 remediation deadline; private-sector organizations should read that as confirmation that exploitation was sufficiently credible and urgent to warrant immediate response.

Volexity’s investigation provides the operational context missing from a patch bulletin. The firm found that an attacker it tracks as UTA0533 used the flaws to reach services intended to be local-only, obtain elevated execution, and deploy KNUCKLEBALL. That loader injected an open-source proxy called Suo5 and a custom Java web shell that Volexity calls ORANGETAIL into a legitimate SonicWall process. Investigators also found evidence of persistence and packet capture aimed at unencrypted LDAP traffic.

This is why “install the hotfix” is incomplete advice for appliances that were exposed before patching. SonicWall explicitly tells customers to conduct a forensic analysis. Where indicators of compromise are found, the company recommends reimaging physical appliances or redeploying virtual ones, changing user and administrator passwords, and resetting TOTP tokens. It also warns that configuration backups should predate the vulnerable December hotfix releases, or else be closely audited for tampering.

Administrators should review the SonicWall notice’s indicators, including suspicious requests involving the appliance’s API-style routes, anomalous /wsproxy activity, hotfix-removal entries in the control-service log, and unexpected changes to the NGINX Unit configuration. Volexity’s findings add a practical reason to preserve logs and appliance state before a reboot: one examined system had rebooted, and the firm assessed that the event likely removed memory-resident backdoors and other volatile evidence.

Bitdefender’s association of this exploitation with INC Ransom may yet be corroborated by additional research. For now, the public record supports a tighter conclusion: the vulnerabilities were actively exploited before disclosure; UTA0533 was observed using KNUCKLEBALL and ORANGETAIL; and SonicWall SMA 1000 administrators must assume an unpatched or late-patched internet-facing appliance may have been compromised.

The Gentlemen’s rise is visible, but rankings are not incident data​

Bitdefender again puts The Gentlemen atop its July ranking, with Qilin and CRPx0 also in the top tier. That broad picture is consistent with other reporting. Infosecurity Magazine, citing ReliaQuest analysis released in July, reported that The Gentlemen had overtaken Qilin in a March-to-May count of published extortion incidents. Other threat-intelligence reporting has likewise tracked The Gentlemen as one of the most active operations of 2026.

The explanation deserves restraint. Bitdefender points to affiliate crossover with Qilin, playbook reuse, and AI-assisted tooling. These are plausible factors in the group’s growth, and public reporting on leaked internal material has described rapid development and recruitment activity. Yet a leak-site ranking measures postings, not confirmed intrusions, encrypted systems, paid ransoms, or the number of distinct victims after duplicates and recycled data are removed.

For IT leaders, the useful conclusion is that the major RaaS brands remain interchangeable from a preparedness standpoint. The same basic weaknesses—stolen credentials, exposed remote access, unpatched edge devices, weak admin segmentation, and inadequate monitoring of living-off-the-land activity—give affiliates opportunities regardless of which name claims the victim afterward.

Bitdefender’s sector observations fit that operational reality. Technology and healthcare rose to second and third place in its July data, while financial-services claims increased. These are risk signals, particularly for organizations that combine high-value identities with time-sensitive services, but they should not be read as a statistically complete census of ransomware harm.


Global Secret Group and LAPSUS$ claims need an evidence threshold​

Bitdefender reports that Global Secret Group, or GSG, updated its leak site, claimed 31 victims in July, and has posted datasets exceeding 100,000 records. Public trackers show the group name and some claimed victims, including organizations in the energy, utilities, and nonprofit sectors. That validates the existence of a leak-site operation; it does not establish that GSG is an “organized syndicate” with a durable capability to develop tooling beyond the LockBit Black codebase.

The report’s assertion that the group is more than a short-lived copycat is therefore an analytical judgment, not a fact independently demonstrated by the available public evidence. Ransomware groups routinely exaggerate datasets, recycle prior leaks, and borrow brands or leaked builders to gain attention. Organizations listed by GSG should verify the claim through internal telemetry, incident-response channels, and breach-notification procedures—not accept or dismiss it because of a criminal group’s reputation.

The same skepticism applies to LAPSUS$’s reported exit announcement. Bitdefender is right to note that such declarations have little predictive value. A threat actor can disappear, rebrand, join another operation, or simply return when a new access broker or identity-compromise opportunity appears. The defensive lesson is more durable than the announcement: protect identity systems and privileged access paths, because theft of credentials, session artifacts, enrollment data, and administrative control can produce damage long before ransomware is deployed.

Bitdefender’s July total shows a ransomware market still able to generate a high volume of public claims. The report’s most valuable contribution is not its leaderboard. It is the reminder that leak-site data is attacker-controlled intelligence, while the SonicWall advisory is a verified exploitation event with a defined remediation path. Patch affected SMA 1000 appliances, investigate them as potentially compromised, rotate exposed credentials and MFA material where evidence warrants it, and measure ransomware readiness from the first credential theft or edge-device intrusion—not from the day a criminal posts a logo on a leak site.