Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical VPN Vulnerability Exploited to Deploy Ransomware

Critical VPN Vulnerability Exploited to Deploy Ransomware

Posted on June 8, 2026 By CWS

Check Point Research has identified the active exploitation of a significant security flaw, CVE-2026-50751, affecting Check Point’s Remote Access VPN and Mobile Access products. This vulnerability, rated 9.3 on the CVSS scale, is being used by cybercriminals associated with the Qilin ransomware group to compromise systems.

Vulnerability Details and Impact

The vulnerability targets configurations using the outdated IKEv1 key exchange protocol. Exploiting a weakness in certificate validation, attackers can initiate a VPN session without a valid password, bypassing authentication entirely. The affected products include Mobile Access/SSL VPN, Remote Access VPN, and Spark Firewall, spanning versions from R80.20.X to R82.10.

While the initial breach occurs through this authentication bypass, further actions are necessary for attackers to access internal systems or elevate privileges. Check Point began investigating on June 4, 2026, following unusual activity, with exploitation efforts traced back to May 7, 2026.

Exploitation and Response

Exploitation incidents surged in early June 2026, impacting several dozen organizations worldwide. Security teams are advised to prioritize forensic audits of logs and review configurations from the earliest observed exploitation date. The attackers are believed to be financially motivated, deploying Qilin Linux ransomware binaries and attempting to download malicious ELF files from their controlled infrastructure.

The threat actors likely utilize the Tox protocol for command-and-control, a method frequently linked to ransomware operations. The same attackers are suspected of exploiting VPN vulnerabilities in products by Palo Alto, Fortinet, and F5. Their infrastructure was found across hosting services like Kaupo Cloud HK, Shock Hosting, and Vultr Holdings, with server locations often matching victim locations.

Related Vulnerability and Mitigation Measures

During the investigation of CVE-2026-50751, a related flaw, CVE-2026-50752, was discovered by Check Point’s AI code security platform, BLAST. This vulnerability affects IKEv1 certificate validation, potentially enabling man-in-the-middle attacks on site-to-site VPN communications. While not yet exploited, customers are strongly advised to apply updates promptly.

Check Point recommends immediate application of their hotfix for affected Security Gateways. Those unable to patch immediately should consider disabling support for legacy remote access clients, configuring authentication to IKEv2, enforcing machine certificate authentication, and enabling IPS with the latest signatures.

For further updates, follow Check Point on Google News, LinkedIn, and X.

Cyber Security News Tags:Check Point, CVE-2026-50751, Cybersecurity, Exploitation, IKEv1 protocol, network security, Qilin ransomware, Ransomware, security update, VPN vulnerability

Post navigation

Previous Post: Anthropic Calls for Unified AI Development Pause Amid Risks
Next Post: China-Linked Group OP-512 Exploits IIS Servers

Related Posts

Azure Data Breach Exposes Millions from Major Firms Azure Data Breach Exposes Millions from Major Firms Cyber Security News
Critical Cisco Vulnerability Exposes Networks to DoS Attacks Critical Cisco Vulnerability Exposes Networks to DoS Attacks Cyber Security News
HashiCorp Nomad Vulnerability Allows Privilege Escalation via ACL Policy Lookup Exploit HashiCorp Nomad Vulnerability Allows Privilege Escalation via ACL Policy Lookup Exploit Cyber Security News
Critical Vulnerability in Popular NPM Library Exposes AI and NLP Apps to Remote Code Execution Critical Vulnerability in Popular NPM Library Exposes AI and NLP Apps to Remote Code Execution Cyber Security News
Libraesva ESG Vulnerability Let Attackers Inject Malicious Commands Libraesva ESG Vulnerability Let Attackers Inject Malicious Commands Cyber Security News
131 Malicious Extensions Targeting WhatsApp Used Found in Chrome Web Store 131 Malicious Extensions Targeting WhatsApp Used Found in Chrome Web Store Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Innovative InjectEave Attack Eavesdrops on Headphones from 30 Meters
  • OpenAI Pledges $1 Billion for AI Cybersecurity Tools
  • New Linux Malware Tengu Hides as Kernel Process
  • ConnectWise Highlights ScreenConnect Security Issue
  • Microsoft Phasing Out Manifest V2 Extensions by 2027

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Innovative InjectEave Attack Eavesdrops on Headphones from 30 Meters
  • OpenAI Pledges $1 Billion for AI Cybersecurity Tools
  • New Linux Malware Tengu Hides as Kernel Process
  • ConnectWise Highlights ScreenConnect Security Issue
  • Microsoft Phasing Out Manifest V2 Extensions by 2027

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark