Qilin Ransomware is a ransomware_group tracked across 11 threat clusters and 11 intelligence report mentions on ThreatCluster. First observed October 27, 2025; most recent activity July 21, 2026.
Check Point Software Technologies disclosed a critical authentication bypass vulnerability (CVE-2026-50751) affecting its Remote Access VPN and Mobile Access products, with exploitation confirmed since May 7, 2026. The…
Qilin ransomware has attacked multiple organizations, including TaLachaim, Quasar, and Z-Tronix, leading to unauthorized access to databases and sensitive information leaks. The attacks also involved DDoS attacks and…
CISA has mandated federal agencies to patch a critical vulnerability in Check Point VPN products within 72 hours due to active exploitation by the Qilin ransomware group. The vulnerability, tracked as CVE-2026-42271,…
In early 2026, the Iranian APT group MuddyWater, affiliated with the Ministry of Intelligence and Security, executed a sophisticated cyber operation disguised as a Chaos ransomware attack. Utilizing social engineering…
On July 13, 2026, the U.S. Treasury's Office of Foreign Assets Control (OFAC) sanctioned First VPN Service (1VPNS), its administrator Dmytro Rashevskyi, and malware provider Yegeniy Vladimirovich Silayev for enabling…
The Qilin ransomware gang is actively exploiting a critical authentication bypass vulnerability (CVE-2026-0257) in Palo Alto Networks' PAN-OS GlobalProtect VPN software. This flaw allows attackers to bypass security…
On November 19, 2025, the United States, United Kingdom, and Australia announced coordinated sanctions against the Russian web company Media Land, accusing it of facilitating ransomware operations. The sanctions include…
Qilin ransomware has been identified using Windows Subsystem for Linux (WSL) to execute Linux encryptors on Windows systems. This method allows attackers to bypass traditional Windows defenses by running ELF binaries,…
A Qilin ransomware incident has prompted a detailed investigation by security analysts. The analysis focuses on understanding how attackers gained initial access and the subsequent actions taken, using various clues…
A Qilin ransomware attack has prompted an investigation by security analysts to determine how the attackers gained initial access and the subsequent actions taken. The analysis involves examining logs, antivirus…