Ransomware affiliates mounted a coordinated wave of attacks against internet-facing VPN and firewall appliances from Palo Alto Networks, Fortinet, Check Point, and Citrix, turning edge remote-access systems into a primary entry point for corporate intrusions. Reported campaigns included FortiBleed credential exposure on FortiGate devices, exploitation of Palo Alto GlobalProtect authentication bypass CVE-2026-0257, abuse of Check Point VPN authentication bypass CVE-2026-50751, and rapid exploitation of Citrix NetScaler memory-disclosure flaw CVE-2026-8451. Security reporting linked Qilin affiliates to at least the Palo Alto and Check Point activity, with exploitation beginning within days—and in some cases less than 24 hours—after disclosure or proof-of-concept release.
After gaining access, attackers were reported using lateral movement and credential-theft techniques including Impacket, NTLM relay, Mimikatz, PsExec, RDP, WMI, Chrome credential theft via GPO, and WSL-based EDR evasion, followed by data theft and double-extortion ransomware deployment. Victims were concentrated in the United States, United Kingdom, Australia, and Western Europe across healthcare, education, manufacturing, local government, media, professional services, and critical infrastructure. The surge prompted Sen. Ron Wyden to call for a federal purge of legacy, public-facing VPNs, urging OMB, CISA, and NIST to push agencies toward zero-trust remote access and away from perimeter-based systems repeatedly exposed by incidents involving Fortinet, Check Point, Ivanti, and Cisco platforms.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
A coordinated mid-2026 wave of ransomware initial-access activity targeted internet-facing VPN and firewall appliances from Fortinet, Palo Alto Networks, Check Point, and Citrix. Victims were reported across the United States, United Kingdom, Australia, and Western Europe in sectors including healthcare, education, manufacturing, government, media, professional services, and critical infrastructure.
Attackers rapidly began exploiting the Citrix NetScaler memory-disclosure flaw CVE-2026-8451, with reporting emphasizing very short weaponization timelines after disclosure or proof-of-concept release. The flaw was one of four campaigns highlighted in the mid-2026 ransomware access surge.
Qilin-linked ransomware affiliates exploited the Check Point VPN authentication bypass vulnerability CVE-2026-50751 as part of edge-device intrusion activity. The access was used for follow-on actions such as lateral movement, credential theft, exfiltration, and eventual double-extortion deployment.
Ransomware operators exploited the Palo Alto Networks GlobalProtect authentication bypass flaw CVE-2026-0257 to gain initial access through internet-facing VPN infrastructure. Reporting linked Qilin affiliates to at least some of the post-compromise activity following this access.
A ransomware-linked campaign dubbed FortiBleed targeted Fortinet FortiGate gateways by exposing credentials from internet-facing appliances. The activity was cited as part of a broader mid-2026 surge in attacks against legacy VPN and firewall infrastructure.
Sen. Ron Wyden called on OMB, CISA, and NIST to lead a government-wide effort to eliminate older internet-facing VPN and remote-access systems from federal agencies. He cited ArcaneDoor, FortiBleed, and exploited Ivanti and Check Point VPN flaws as evidence and asked for a binding directive, implementation standards, and funding priorities aligned to zero-trust adoption.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cyberscoop.com
Open sourcecybersecuritynews.com
Open sourcecyberveille.ch
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.