Israeli cybersecurity firm Check Point has released security updates for a critical VPN vulnerability exploited in active zero-day attacks. The flaw affects Remote Access VPN and Mobile Access deployments and has been linked to the Qilin ransomware group.
Check Point identified the zero-day vulnerability in its VPN infrastructure and confirmed it was being actively exploited in the wild. The company attributed the attacks to Qilin, a ransomware-as-a-service operation known for targeting enterprise networks.
The vulnerability allowed attackers to gain unauthorized access to remote VPN sessions, potentially enabling lateral movement within compromised networks. Check Point released patches immediately upon discovery to address the flaw across affected product lines.
Qilin has emerged as a significant threat actor in recent months, conducting high-profile ransomware operations against organizations globally. The group typically exfiltrates data before encrypting systems, leveraging the stolen information for extortion purposes.
Check Point urged customers to apply patches immediately. The company did not disclose additional technical details about the vulnerability to prevent further exploitation before widespread patching could occur. Organizations using Check Point VPN solutions are advised to verify their systems have been updated.
A U.S. citizen is asking a court to dismiss government accusations that he used a 'duress' password to erase his phone during a border search, raising fresh constitutional questions about digital privacy rights.
A threat actor deployed the open-source Hermes AI agent in unattended mode to automate post-exploitation activities during an alleged breach of Thailand's Ministry of Finance.
OnTrac, a major parcel delivery company, has notified customers of a network breach that may have exposed personal information. The hack compromised the company's corporate systems.
Slopsquatting, phantom domains, and HalluSquatting exploit identical vulnerabilities in AI coding agents. Security researchers warn that these attacks leverage late-binding patterns where AI systems trust non-existent packages and repositories.