Cybersecurity Daily: News & Threats · 21 Jul 2026 · 4 min

Root Access Before the Patch: SonicWall, INC Ransomware & 570 Microsoft Fixes

Two threat actors chained unpatched SonicWall zero-days for root access on enterprise VPNs before disclosure — then INC Ransomware weaponized the same flaws at scale. Plus Microsoft's record 570-fix Patch Tuesday, the Craneware healthcare supply chain breach, and 23M Paidwork records on cybercrime forums.

Cybersecurity Daily: News & Threats
Now Playing
Root Access Before the Patch: SonicWall, INC Ransomware & 570 Microsoft Fixes

Audio is available on Spreaker — see link below.

What's covered

SonicWall Zero-Day Chain

Two threat actors. Two unpatched flaws.

Listen now →

INC Ransomware Weaponizes SonicWall

What makes this more concerning is what came next. Rapid7 identified INC Ransomware as an active exploiter of the same vulnerability chain.

Listen now →

Microsoft's 570-Fix Patch Tuesday

Elsewhere, Microsoft shipped a record five hundred and seventy fixes in this month's Patch Tuesday update, KB5101650. Two of those are zero-days under active exploitation.

Listen now →

Craneware Healthcare Breach

The Craneware breach adds to what's becoming a clear pattern in 2026. The UK-based company provides billing software to thousands of US hospitals and pharmacies.

Listen now →

Paidwork Data Exposure and 7-Zip Patch

Two more items to track. Paidwork, a microtask platform, had twenty-three point three million user records exposed from a March intrusion.

Listen now →

What to Watch Next

The two watchpoints that matter most right now: whether additional SonicWall victims emerge as incident response investigations widen, and how quickly healthcare sector organizations assess their exposure through billing software providers like Craneware. Both situations are actively developing with significant gaps in confirmed information.

Listen now →

Chapter summary auto-generated from the verified script. Listen to the full episode for the complete content.

More episodes

From Cybersecurity Daily: News & Threats