Man-in-the-middle vulnerability in Check Point IKEv1 code path affecting site-to-site VPN tunnels. CVSS 7.4. Identified during investigation of CVE-2026-50751. No exploitation observed to date. Affects legacy IKEv1 configurations.
Apply hotfixes from Check Point sk185033 for affected versions. Migrate from IKEv1 to IKEv2-only configuration where operationally feasible, as IKEv1 has been deprecated since RFC 8247. Audit site-to-site VPN configurations for IKEv1 usage.
Source: NVD • Published: 2026-06-08
Supply chain attack compromised 32 npm packages under @redhat-cloud-services namespace with Miasma credential-stealing worm. Attacker used compromised Red Hat employee GitHub account to push malicious orphan commits in 72-second window. Packages have nearly 10 million collective downloads, averaging 80,000 weekly downloads. Attack bypassed code review entirely.
Immediately audit dependency trees for affected @redhat-cloud-services packages and downgrade to clean versions. Rotate all credentials accessible to development environments. Review GitHub Actions workflows for unauthorized modifications. Implement package manager controls like minimumReleaseAge.
Source: BleepingComputer • Published: 2026-06-01
Qilin ransomware group claimed 18 victims across manufacturing and energy sectors in 24 hours, part of 39 total new ransomware leaks. Actively exploiting CVE-2026-50751 Check Point VPN vulnerability and other zero-days. Manufacturing sector alone may have suffered over $18 billion in losses in first three quarters of 2026. Employs advanced social engineering including vishing.
Apply all Check Point VPN patches immediately, particularly CVE-2026-50751 fix. Implement multi-factor authentication on all VPN access. Deploy EDR solutions with anti-tampering protections. Conduct tabletop exercises for ransomware response. Maintain offline, immutable backups with regular testing.
Source: BleepingComputer • Published: 2026-06-15
REDHAT-NPM-2026-06-01: Supply chain attack compromised 32 npm packages under @redhat-cloud-services namespace with Miasma credential-stealing worm. Attacker used compromised Red Hat employee GitHub account to push malicious orphan commits in 72-second window. Packages have nearly 10 million collective downloads, averaging 80,000 weekly downloads. Attack bypassed code review entirely.