discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

Check Point links VPN zero-day attacks to Qilin ransomware gang

Check Point patched two VPN flaws, including one used in zero-day attacks tied to Qilin ransomware activity. The exploitation hit only a few dozen organizations, but was active worldwide.

By Sergiu Gatlan·Jun 8·bleepingcomputer.com·2 min read

Intelligence analysis by GPT-5.4 Mini

Check Point links VPN zero-day attacks to Qilin ransomware gang
Image: bleepingcomputer.com

Check Point says attackers abused a critical authentication-bypass bug in older VPN setups that use deprecated IKEv1. The company also found a second certificate-validation flaw and urged customers to patch or lock down legacy access paths immediately.

Why it matters

This is another reminder that VPN appliances remain high-value targets because they sit at the edge of corporate networks. The link to Qilin raises the stakes: a perimeter bug can turn into ransomware entry, not just a technical incident.

Check Point found a hole in some older VPN setups, which are like the locked front doors of a company’s network. Thieves used it to sneak in without a key, and in one case that trail led to ransomware crooks called Qilin.

Analysis

What happened

Check Point says it released security updates for a critical flaw, tracked as CVE-2026-50751, affecting Remote Access VPN and Mobile Access deployments. The bug can let unauthenticated remote attackers bypass authentication on certain VPN and firewall setups and establish a remote access VPN connection.

The company says the issue only affects systems configured to use the deprecated IKEv1 key exchange protocol, specifically gateways that accept legacy Remote Access clients and do not require a machine certificate. Check Point says exploitation began on May 7, increased in early June, and affected only “a few dozen” organizations worldwide.

Why the incident stands out

Check Point says at least one case involved post-compromise activity associated with a Qilin ransomware affiliate. That does not mean every attack was Qilin, but it does show the flaw was being used in real intrusion activity rather than just tested by researchers.

While investigating the first issue, Check Point also found CVE-2026-50752, a second flaw in certificate validation for deprecated IKEv1 use. The company says that bug could support man-in-the-middle attacks on site-to-site VPN connections, though it has not seen exploitation in the wild.

What defenders should do

Check Point urges customers to apply updates immediately. For organizations that cannot patch right away, it recommends removing support for the legacy remote access client, forcing Remote Access VPN authentication to IKEv2 only, making machine certificate authentication mandatory, and enabling IPS with the provided signatures.

The practical message is straightforward: older VPN settings are not just technical debt. In this case, they were the attack path.

Key points

  • Check Point patched CVE-2026-50751, a critical authentication-bypass flaw in certain VPN and Mobile Access deployments.
  • The company says attackers used the flaw in zero-day attacks starting on May 7 and intensifying in early June.
  • At least one incident was linked to post-compromise activity associated with a Qilin ransomware affiliate.
  • A second issue, CVE-2026-50752, affects certificate validation in deprecated IKEv1 use and may enable man-in-the-middle attacks.
  • Check Point says only a few dozen organizations were affected, but urges immediate updates and legacy VPN hardening.
The Upside

If organizations patch quickly and retire the older VPN setup, the attack path can be closed before wider abuse spreads. The extra mitigations Check Point lists could also reduce exposure for systems that cannot be updated immediately.

The Downside

If companies keep legacy IKEv1 settings enabled, attackers may continue to use the same bypass to get inside network perimeters. Because VPN access can lead straight into internal systems, even a small number of successful intrusions can still become serious ransomware incidents.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecurityransomwarevulnerabilityvpnenterprise-security

Author

Sergiu Gatlan

Intelligence analysis by

GPT-5.4 Mini

Published

Jun 8, 2026

Source

bleepingcomputer.com

Share

Topics

securityransomwarevulnerabilityvpnenterprise-security

Related

More from this desk

Jul 29·thehackernews.com

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

A maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, allows unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726, impacts all versions of the project before version 3.16.3.

Jul 29·thehackernews.com

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Broadcom patched three critical VMware vulnerabilities including two CVSS 9.8 flaws in vCenter for auth bypass and arbitrary code execution, plus a VMXNET3 flaw enabling VM escape.

Jul 29·bleepingcomputer.com

Hackers target over 30 Minnesota water utilities in coordinated OT attack

Hackers targeted over 30 Minnesota water utilities in a coordinated cyberattack, disrupting operational technology systems. The Minnesota IT Services agency is working with federal and state partners to investigate and fortify the security of the state's critical infrastr…

Jul 29·bleepingcomputer.com

Your AI Agents Are Guessing at Scale: Permissions Decide the Damage

AI agents are designed to improvise, but this can lead to security risks when paired with broad access. Teams struggle to apply least privilege to agents, and traditional security models break down. Token Security offers a solution to discover and map risky access, and au…