Ransomware Gangs Attack Palo Alto, Fortinet, Citrix, and Check Point VPNs to Target Corporate Networks
ID: fb07535f-4e70-5808-ab67-1af7ac68ac2a
STIX ID: report--fb07535f-4e70-5808-ab67-1af7ac68ac2a
Feed Name: cybersecurityNews.com
A coordinated mid‑2026 wave of exploitation targeting internet‑facing VPN and firewall appliances from Palo Alto, Fortinet, Check Point, and Citrix has become a dominant initial‑access vector for ransomware operators (including Qilin affiliates), leveraging Fortibleed credential harvesting, GlobalProtect cookie forgery (CVE‑2026‑0257), Check Point IKEv1 auth bypass (CVE‑2026‑50751), and Citrix NetScaler memory disclosures (CVE‑2026‑8451); the report provides IOCs, affected products, MITRE mappings, targeted sectors, and prioritized mitigation and detection recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
