Research.Checkpoint Ransomware and Vulnerabilities Targeting Ivanti and Check Point Systems
Article Content
Browse articles
On February 9, 2026, Check Point reported on active ransomware threats and vulnerabilities affecting Ivanti Endpoint Manager. Specifically, CVE-2026-1281 and CVE-2026-1340 were published on January 29, 2026, with CVE-2026-1281 being actively exploited as of the same day. Check Point Harmony Endpoint and Threat Emulation are providing protection against these threats.
Ask AI about this cluster
Answers cite the sources they use
Updated 183d ago How this analysis works
Timeline
2024-05-26
First public exploit for CVE-2025-8088 released
2025-11-03
CVE-2025-11953 published
2026-01-29
CVE-2026-1281 and CVE-2026-1340 published
2026-01-29
CVE-2026-1281 added to CISA KEV (active exploitation)
2026-02-01
First public PoC for CVE-2026-1281
2026-02-05
CVE-2025-11953 added to CISA KEV (active exploitation)
More articles in this cluster (1)
Following this threat?
Track Akira, APT41 and CVE-2025-11953 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Node.js Exploited in Ransomware Attacks Using EtherHiding Technique Since February 2026, threat actors have been exploiting the trusted Node.js runtime to deploy malicious payloads in targeted attacks against government departments, technology companies, and hotels. The technique leverages node.exe, a legitimate and signed developer tool, allowing attackers to run interpreted scripts…
Akira Ransomware Uses Safe Mode to Evade EDR Detection In early August 2026, an Akira ransomware affiliate executed an attack leveraging Safe Mode to evade endpoint detection and response (EDR) tools. The attack began with credential spraying against an exposed SonicWall SSL VPN lacking multi-factor authentication (MFA), leading to unauthorized access to the domain…