CISA has ordered federal agencies to patch CVE-2026-50751 in Check Point VPN products by June 11 after it was exploited as a zero-day by Qilin ransomware affiliates. The critical authentication bypass flaw affects only IKEv1 configurations and has breached a few dozen organizations worldwide so far.

Although these attacks have only led to breaches at a few dozen organizations worldwide, Check Point has linked at least one incident to the Qilin Ransomware-as-a-Service operation.
Two years ago, CISA tagged another vulnerability in Check Point's Quantum Security Gateways as actively exploited by ransomware gangs.
Federal agencies face a tight three-day window to remediate an actively exploited VPN flaw, underscoring how quickly CISA moves on KEV catalog additions when ransomware post-exploitation is confirmed.
Tap a lens to see what this story means for you.
Reader-supported · Daily Brief
Daily brief at 7 AM ET. Top tech stories, every morning. Sourced and fact-checked.
Reader-supported
The Circuitry is a passion project I've always wanted to build, and I love the work behind it.
Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.
Any contribution is appreciated. If not, no pressure. Thanks for reading.
Apple is expanding App Store bundles to include subscriptions from different companies and introducing Suites that combine subscriptions unavailable on their own. The changes, announced at WWDC alongside iOS 27, will roll out later this year with more details expected this summer.
The European Commission ordered Meta to restore rival AI chatbots' access to the WhatsApp Business API under pre-ban terms within five days. The move escalates an antitrust investigation into whether Meta abused its dominance by reserving AI features for itself, with potential fines up to 10% of global revenue.
Anthropic has released Claude Fable 5 as its first publicly available Mythos-class model, which it describes as exceeding any prior generally available model on nearly all benchmarks. The release includes conservative safeguards that redirect some queries to Claude Opus 4.8, while a less-restricted Mythos 5 version stays limited to select cyberdefenders.