Vpn
Cisco ASA and FTD Under Active Attack: Unauthenticated VPN Flaw Reloads Firewalls On Demand (CVE-2026-20349)
CVE-2026-20349, an unauthenticated heap inspection flaw in Cisco ASA and FTD's Remote Access SSL VPN service, is being actively exploited to remotely crash firewalls — CISA gave federal agencies until August 14 to patch, and no workaround exists.
QuickFox VPN Installer Trojanized for a Year to Deliver Mustang Panda's FDMTP Backdoor
A trojanized QuickFox VPN Windows installer quietly delivered the FDMTP backdoor for roughly a year, with Fortinet linking the campaign to Chinese state-sponsored actor Mustang Panda.
CVE-2026-20316: Static Credentials in Cisco Secure FMC Under Active Exploitation, Added to CISA KEV
Cisco disclosed CVE-2026-20316, a hardcoded low-privilege account baked into Secure Firewall Management Center's web interface that lets unauthenticated attackers log in and pull sensitive data — CISA added it to the KEV catalog on July 29 after confirming in-the-wild exploitation.
CVE-2026-15409 & CVE-2026-15410: SonicWall SMA1000 Zero-Days Chained for Unauthenticated RCE, CISA Deadline July 17
Two SonicWall SMA1000 zero-days — a CVSS 10.0 SSRF and a post-auth code injection flaw — are being chained in the wild for unauthenticated remote code execution. CISA KEV deadline is July 17, 2026.
CVE-2026-8451: A New CitrixBleed-Pattern Memory Overread Is Already Under Active Exploitation
Citrix patched CVE-2026-8451, a pre-auth memory overread in NetScaler's SAML IdP parser that leaks session tokens — and attackers were already exploiting it within 24 hours of disclosure.
CVE-2026-50751: Check Point VPN Auth Bypass Exploited by Qilin — IKEv1 Sessions Without a Password
Check Point confirmed active exploitation of CVE-2026-50751, a CVSS 9.3 authentication bypass in Remote Access VPN and Mobile Access deployments running deprecated IKEv1. Attackers establish VPN sessions without a valid password; one case is tied to a Qilin ransomware affiliate. Earliest exploitation traces to May 7.
CVE-2026-0257: Palo Alto GlobalProtect Auth Bypass Now Exploited — Unauthorized VPN Access Into Your Network
Palo Alto confirmed active exploitation of CVE-2026-0257, a CVSS 7.8 GlobalProtect authentication bypass that lets attackers establish unauthorized VPN sessions into the internal network. Rapid7 traced exploitation back to May 17. CISA KEV deadline is June 1.
The Edge Device Audit: Turn CISA's BOD 26-02 Into a Playbook You Can Actually Run
CISA's BOD 26-02 just handed every infrastructure team a free edge-device audit checklist. Here is how to run it on your own network — inventory, version, exposure, and end-of-support triage — before an attacker runs theirs.
The Ransomware Dwell Time Collapse: When the Entire Kill Chain Fits Inside an Hour
Akira is encrypting domains 60 minutes after a VPN login. Storm-1175 is going from zero-day to domain-wide Medusa deployment in under 24 hours. The industry's average detection time is still measured in days. The math no longer works.
Akira Ransomware Now Encrypts in Under an Hour: SonicWall VPNs Are the Front Door
Akira ransomware operators are completing full attack chains from initial VPN access to encryption in under 60 minutes, targeting SonicWall SSL VPNs even on patched devices.
15-Year-Old strongSwan Integer Underflow Lets Unauthenticated Attackers Crash VPN Gateways
CVE-2026-25075 is an integer underflow in strongSwan's EAP-TTLS AVP parser that lets remote, unauthenticated attackers crash the charon IKE daemon — affecting every version since 4.5.0.