Check Point VPN Flaw Exploited Since Early May

2026-06-08T20:51:42Z15427dad9dd53a3092d19f2816ac5258a30525fdc6a84c07ca31de88a1d4f3a4
AI threatsAI-assisted exploit developmentCheck PointClickFixDriveSurgeEDR evasionFakeUpdateGlobalProtectHadesIronWormKali365NPMPAN-OSPalo AltoPyPIQilin ransomwareShai-HuludVPNXeno RATactive exploitationagentic AIfuel-tank gaugesphishingsupply chainzero-day

What happened

Collection of DarkReading stories highlighting multiple active and emerging threats: a critical Check Point VPN zero‑day has been actively exploited since early May (attributed to a Qilin ransomware affiliate), and a PAN‑OS GlobalProtect authentication‑bypass has seen active exploitation in two waves. Significant software‑supply chain campaigns (PyPI/NPM infections such as Shai‑Hulud/Hades and IronWorm) and widespread phishing/TDS operations (Kali365, DriveSurge delivering ClickFix/FakeUpdate) threaten developer and consumer ecosystems. Other notable items: exposed Internet‑connected fuel tank

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
15427dad9dd53a3092d19f2816ac5258a30525fdc6a84c07ca31de88a1d4f3a4
Enrichment time
2026-06-08T20:51:42Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.