Vpn
Curated coverage and analysis in this editorial area.

SonicWall SMA 1000 Under Attack: CVE-2026-15409 CVSS 10.0 and TOTP Seed Theft
CVE-2026-15409 and CVE-2026-15410 exposed SonicWall SMA 1000 appliances to unauthenticated root compromise. The theft of MFA seeds ren…

Trend Micro VPN: Local Privilege Escalation Flaw Allows SYSTEM Takeover
A local privilege escalation vulnerability in Trend Micro VPN, tracked as ZDI-26-577 and CVE-2026-67212, lets an attacker with low-pri…

INC Ransomware Chains Two SonicWall Zero-Days for Root Access via VPN Appliance
Two zero-days in SonicWall SMA 1000 let INC Ransomware gain remote root access. Pre-disclosure exploitation began June 22, three weeks…

Hotel DNS Attacks: Corporate VPNs Aren't Enough to Protect Microsoft 365
ReliaQuest has documented an active campaign since June 2026 that compromises hotel Wi-Fi gateways to redirect Microsoft 365 logins to…

Hotel Wi-Fi DNS Attacks Steal Microsoft 365 Accounts, Bypass MFA
Threat actors compromise hotel and conference center Wi-Fi captive portals to manipulate DNS and steal Microsoft 365 credentials, sess…

WatchGuard FireWare OS: IKEv2 Bug Enables Remote DoS with a Single Packet
A null pointer dereference in WatchGuard FireWare OS exposes firewalls with active IKEv2 VPN to remote denial-of-service. CVE-2026-130…

From VPN Bypass to Encrypted Domain: How CVE-2026-0257 Fuels Qilin Ransomware
Arctic Wolf Labs confirms active exploitation of CVE-2026-0257 to deploy Qilin ransomware. Specific TTPs reveal shared infrastructure…

US Sanctions First VPN Provider: Anonymity as Criminal Infrastructure
The Treasury Department sanctions First VPN Service and its Ukrainian administrator for supporting ransomware groups. It marks the fir…

FortiBleed: 75,000 Firewalls at Risk from Stolen Credentials, Not a Zero-Day
FortiBleed hits already-patched FortiGate devices: credentials stolen in prior incidents enable administrative access without exploiti…

FortiBleed Fuels INC and Lynx: One Operator Serving Two Ransomware Clients
SOCRadar has documented the link between FortiBleed and the INC and Lynx ransomware groups. A single operator accessed the negotiation…

FortiBleed: 74,000 Fortinet Credentials Exposed, CISA Orders Immediate Action
CISA mandates immediate hardening for roughly 74,000 Fortinet devices after the FortiBleed credential leak. Valid credentials are circ…

CVE-2026-50751: Check Point VPN Zero-Day Exploited by Qilin Affiliate; Patch Released June 8
A Qilin ransomware affiliate exploited a critical zero-day in Check Point VPN’s IKEv1 protocol for over a month. The flaw (CVSS 9.3) a…