AI Stories on SHORT INFO are generated & curated with AI
unverified 23 Jun, 10:42

Check Point VPN zero-day actively exploited by Qilin ransomware affiliates

Check Point $CHKP has confirmed a critical authentication-bypass flaw in its Remote Access VPN that lets attackers open a session without valid credentials. The company linked the active exploitation to an affiliate of the Qilin ransomware group, and U.S. authorities ordered fede

Check Point $CHKP confirmed a critical security flaw, rated 9.3 out of 10, in its Remote Access VPN, Mobile Access, and Spark Firewall products. The weakness lets an unauthenticated attacker open a VPN session without valid credentials, but only affects gateways still running a deprecated IKEv1 key exchange protocol with older remote access clients. Check Point first detected suspicious activity on June 4, while forensics traced exploitation back to early May, leaving a roughly month-long window of quiet access. The company linked at least one incident, with medium confidence, to an affiliate of the Qilin ransomware group, with activity so far limited to a few dozen targeted organizations worldwide. CISA added the flaw to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch within days. Check Point has released a hotfix and urges affected customers to apply it without delay. Sources: Check Point, Rapid7, BleepingComputer, Help Net Security, The Hacker News, CISA KEV.

#cyber
Published on
TikTokYouTubeThreadsFacebookInstagramBlueskyX