惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Google DeepMind News
Google DeepMind News
I
InfoQ
Engineering at Meta
Engineering at Meta
D
DataBreaches.Net
L
LangChain Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Recent Announcements
Recent Announcements
GbyAI
GbyAI
爱范儿
爱范儿
Microsoft Security Blog
Microsoft Security Blog
腾讯CDC
美团技术团队
罗磊的独立博客
Microsoft Azure Blog
Microsoft Azure Blog
WordPress大学
WordPress大学
T
The Blog of Author Tim Ferriss
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
雷峰网
雷峰网
M
MIT News - Artificial intelligence
D
Docker
MongoDB | Blog
MongoDB | Blog
F
Fortinet All Blogs
博客园 - 叶小钗

Cybersecurity Dive - Latest News

Dozens of Red Hat npm packages targeted in supply chain attack Turning tension into collaboration: How CIOs and CISOs can lead together Anthropic shares Mythos with 150 more organizations, including critical infrastructure operators Without strong governance, companies put credit ratings at risk in AI era CISA adds critical Palo Alto Networks firewall flaw to KEV as company, researchers warn of exploitation How Canva scaled to 260+M users while elevating security and productivity Top 4 data security best practices for the AI-enabled enterprise CISA urges security teams to check for software development compromises How CISOs can manage sovereign-cloud security risks IBM’s new $5B initiative will help enterprises rapidly patch open-source vulnerabilities Enterprise data is creeping its way into shadow AI tools Coordinated operation takes down Glassworm botnet Leading AI models are more vulnerable to malicious prompts than vendors claim Iranian government, not hacktivist group, breached LA Metro system, security firm says FBI warns about PhaaS platform used to access Microsoft 365 environments Iran-linked hackers target key US, allied sectors with sophisticated spear-phishing messages New York regulator calls for additional cyber mitigation amid heightened threat environment CISA asks cybersecurity community to alert it to vulnerability exploitation Grafana Labs links GitHub environment breach to TanStack npm supply chain attack 7-Eleven hit by data breach Microsoft disrupts cybercrime operation that hid behind legitimate software Compromised coding tool helped hackers breach thousands of GitHub repositories Telecom sector launches its own private ISAC Patch bypass allows hackers to exploit prior flaw in SonicWall SSL-VPN Grafana Labs says hacker gained access to codebase through leaked token How a government contest launched a revolution in AI-based bug hunting Attackers exploit critical flaw in Cisco Catalyst SD-WAN Controller MSPs need AI to fight AI-fueled cyberthreats: Guardz More money is going to physical security, but it’s often CISOs that oversee it: EY Frontier AI models reap rapid discovery of security vulnerabilities
Check Point warns of zero-day flaw targeted by ransomware...
David Jones · 2026-06-09 · via Cybersecurity Dive - Latest News

An article from site logo

A vulnerability in the company’s VPN deployments has faced exploitation since early May.

Published June 9, 2026

Hooded person types on computer in a dark room with multiple monitors and cables everywhere.

Getty Images

A critical authentication bypass flaw in Check Point Remote Access VPN and Mobile Access deployments has been under exploitation for more than a month, according to a blog post published Monday by Check Point Research. 

The vulnerability, tracked as CVE-2026-50751, is related to a logic flaw in certificate validation, according to the report. If successfully exploited, the flaw allows an attacker to establish a VPN session without the need for a password. 

Discovering suspicious activity, Check Point began investigating on Thursday.  It found threat activity dating back to May 4. Researchers urge security teams to prioritize forensic log audits and configuration reviews.

The VPN vulnerability is found in deployments that are configured for the deprecated Internet Key Exchange v1 protocol. 

Forensic evidence

So far, the investigation has identified a few dozen targeted organizations across the globe. In one specific case, post-compromise activity was linked to an affiliate of Qilin ransomware. The same infrastructure has been observed targeting VPN vulnerabilities in Palo Alto Networks, F5 and Fortinet, according to researchers.

The Cybersecurity and Infrastructure Security Agency on Monday added CVE-2026-50751 to its Known Exploited Vulnerabilities catalog. 

During the investigation, Check Point found a second vulnerability, tracked as CVE-2026-50752. The flaw affects certificate validation in deprecated IKEv1 key exchange. This could enable man-in-the-middle attacks that might impact site-to-site VPN communication if certain conditions are met. Check Point has not seen any exploitation of the second vulnerability.

CheckPoint is urging upgrades to a hotfix. In addition, the company released security guidance to address the vulnerabilities, along with mitigation steps. 

Researchers from Rapid7 confirmed they have observed at least one case involving CVE-2026-50751. 

Researchers noted that of the nine total version branches of products impacted by the zero-day flaw, four of those products have reached out-of-service status and are no longer under support by Check Point.