Check Point warns of ransomware-linked attacks exploiting outdated VPN protocol

Chronological Source Flow
Back

AI Fusion Summary

Check Point issued emergency hotfixes for two vulnerabilities affecting VPN deployments using the deprecated IKEv1 protocol. One flaw allows attackers to establish VPN sessions without valid passwords, granting access to corporate networks. The Qilin ransomware group exploited this bug starting in early May, targeting dozens of organizations globally before the fix was released. Check Point noted that the attackers had a one-month head start, with exploitation activity accelerating in recent weeks before the vulnerabilities were addressed.
Community Comments
Loading updates...
0