Check Point VPN Flaw Exploited Since Early May
2026-06-08T20:51:42Z•15427dad9dd53a3092d19f2816ac5258a30525fdc6a84c07ca31de88a1d4f3a4
AI threatsAI-assisted exploit developmentCheck PointClickFixDriveSurgeEDR evasionFakeUpdateGlobalProtectHadesIronWormKali365NPMPAN-OSPalo AltoPyPIQilin ransomwareShai-HuludVPNXeno RATactive exploitationagentic AIfuel-tank gaugesphishingsupply chainzero-day
What happened
Collection of DarkReading stories highlighting multiple active and emerging threats: a critical Check Point VPN zero‑day has been actively exploited since early May (attributed to a Qilin ransomware affiliate), and a PAN‑OS GlobalProtect authentication‑bypass has seen active exploitation in two waves. Significant software‑supply chain campaigns (PyPI/NPM infections such as Shai‑Hulud/Hades and IronWorm) and widespread phishing/TDS operations (Kali365, DriveSurge delivering ClickFix/FakeUpdate) threaten developer and consumer ecosystems. Other notable items: exposed Internet‑connected fuel tank
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- 15427dad9dd53a3092d19f2816ac5258a30525fdc6a84c07ca31de88a1d4f3a4
- Enrichment time
- 2026-06-08T20:51:42Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.