Check Point links VPN zero-day attacks to Qilin ransomware gang
2026-06-08T13:23:33Z•47422cf09639641a75741b5ed1586d3ea2df03ea4de21e31a1e33ee7c656ef11
APTC0XMOCVE-2026-20245CVE-2026-3300Check PointCisco SD-WANDD-WRTEverest Forms ProQilinSolarWinds Serv-UUNC5221WordPressaccount-takeoveractive-exploitationbotnetcredential-theftdata-breachlaw-firm-targetingransomwaresocial-engineeringsupply-chainzero-day
What happened
Multiple active threats and breaches were reported: Check Point disclosed a critical Remote Access/Mobile Access VPN zero-day exploited in attacks attributed to the Qilin ransomware gang; Cisco warned of an actively exploited SD‑WAN zero-day (CVE-2026-20245) enabling root escalation; a critical Everest Forms Pro WordPress flaw (CVE-2026-3300) is being exploited for full site takeover; and attackers are exploiting a recently patched SolarWinds Serv‑U flaw to crash servers. Separately, Meta confirmed abuse of its AI support system that led to 20,225 Instagram account takeovers, Oxford University
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 47422cf09639641a75741b5ed1586d3ea2df03ea4de21e31a1e33ee7c656ef11
- Enrichment time
- 2026-06-08T13:23:33Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.