Check Point links VPN zero-day attacks to Qilin ransomware gang

2026-06-08T13:23:33Z47422cf09639641a75741b5ed1586d3ea2df03ea4de21e31a1e33ee7c656ef11
APTC0XMOCVE-2026-20245CVE-2026-3300Check PointCisco SD-WANDD-WRTEverest Forms ProQilinSolarWinds Serv-UUNC5221WordPressaccount-takeoveractive-exploitationbotnetcredential-theftdata-breachlaw-firm-targetingransomwaresocial-engineeringsupply-chainzero-day

What happened

Multiple active threats and breaches were reported: Check Point disclosed a critical Remote Access/Mobile Access VPN zero-day exploited in attacks attributed to the Qilin ransomware gang; Cisco warned of an actively exploited SD‑WAN zero-day (CVE-2026-20245) enabling root escalation; a critical Everest Forms Pro WordPress flaw (CVE-2026-3300) is being exploited for full site takeover; and attackers are exploiting a recently patched SolarWinds Serv‑U flaw to crash servers. Separately, Meta confirmed abuse of its AI support system that led to 20,225 Instagram account takeovers, Oxford University

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
47422cf09639641a75741b5ed1586d3ea2df03ea4de21e31a1e33ee7c656ef11
Enrichment time
2026-06-08T13:23:33Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.