Research.Checkpoint Ransomware and Vulnerabilities Targeting Ivanti and Check Point Systems
Article Content
Browse articles
On February 9, 2026, Check Point reported on active ransomware threats and vulnerabilities affecting Ivanti Endpoint Manager. Specifically, CVE-2026-1281 and CVE-2026-1340 were published on January 29, 2026, with CVE-2026-1281 being actively exploited as of the same day. Check Point Harmony Endpoint and Threat Emulation are providing protection against these threats.
Ask AI about this cluster
Answers cite the sources they use
Updated 183d ago How this analysis works
Timeline
2024-05-26
First public exploit for CVE-2025-8088 released
2025-11-03
CVE-2025-11953 published
2026-01-29
CVE-2026-1281 and CVE-2026-1340 published
2026-01-29
CVE-2026-1281 added to CISA KEV (active exploitation)
2026-02-01
First public PoC for CVE-2026-1281
2026-02-05
CVE-2025-11953 added to CISA KEV (active exploitation)
More articles in this cluster (1)
Following this threat?
Track Akira, APT41 and CVE-2025-11953 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Node.js Exploited in Ransomware Attacks Using EtherHiding Technique Since February 2026, threat actors have been exploiting the trusted Node.js runtime to deploy malicious payloads in targeted attacks against government departments, technology companies, and hotels. The technique leverages node.exe, a legitimate and signed developer tool, allowing attackers to run interpreted scripts…
Global Industrial Ransomware Incidents Surge 12% in Q2 2026 Ransomware attacks on industrial organizations increased by 12% globally in Q2 2026, with Dragos reporting 1,140 incidents, up from 1,020 in Q1. Manufacturing was the most affected sector, accounting for 65% of incidents. Australia and New Zealand reported 19 incidents, unchanged from Q1, highlighting significant…