:

CHECK POINT PATCHES VPN ZERO-DAY TIED TO QILIN GANG

SECURITY DESK1 MIN READ
MON, JUN 8, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Israeli cybersecurity firm Check Point has released security updates for a critical VPN vulnerability exploited in active zero-day attacks. The flaw affects Remote Access VPN and Mobile Access deployments and has been linked to the Qilin ransomware group.

Check Point identified the zero-day vulnerability in its VPN infrastructure and confirmed it was being actively exploited in the wild. The company attributed the attacks to Qilin, a ransomware-as-a-service operation known for targeting enterprise networks. The vulnerability allowed attackers to gain unauthorized access to remote VPN sessions, potentially enabling lateral movement within compromised networks. Check Point released patches immediately upon discovery to address the flaw across affected product lines. Qilin has emerged as a significant threat actor in recent months, conducting high-profile ransomware operations against organizations globally. The group typically exfiltrates data before encrypting systems, leveraging the stolen information for extortion purposes. Check Point urged customers to apply patches immediately. The company did not disclose additional technical details about the vulnerability to prevent further exploitation before widespread patching could occur. Organizations using Check Point VPN solutions are advised to verify their systems have been updated.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Attackers can exploit three chained vulnerabilities in Ubiquiti's UniFi OS server to execute remote code with root privileges without authentication. The flaws have already been patched.

2H AGOAI Desk

Gogs has released a security patch for a critical zero-day vulnerability that enables remote code execution on exposed instances. The flaw allows attackers to compromise servers and access all repositories, including private ones.

2H AGOSecurity Desk

Meta's WhatsApp has detected new spyware attacks linked to NSO Group, the Israeli surveillance firm behind the notorious Pegasus malware. The company disrupted a phishing campaign targeting its users, marking another violation of existing court orders against NSO.

2H AGOIndustry Desk

Oxford University disclosed a data breach after its third-party careers services provider, Group GTI, notified the institution that its CareerConnect platform had been compromised.

6H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.