Automatically translated.View original post

Hackers exploit Zero-Day vulnerability on Check Point VPN

Many hackers have been found using the Zero-Day vulnerability on Check Point VPN, releasing Qilin ransomware.

According to a report by the website, Security Week mentioned the detection of a security vulnerability on the VPN application of Check Point, a well-known cybersecurity development company, using its own research team. The vulnerability is coded CVE-2026-50751 with a CVSS Score danger rating of 9.3, or a very high critical danger, because it is a vulnerability that occurs between the Validation of the Certificate for Remote Access and Mobile Access. Key) IKEv1 rejected by the system during the key exchange, allowing hackers to create a password-free VPN implementation session.

That vulnerability was found to have been used by several hacker groups during the past 7 May, finding more use during June, where one of the hackers that implemented it was a group of hackers that used malware for ransom, or Ransomware named Qilin, to be used to release such ransomware for financial purposes, such as extortion through ransomware, etc.

But the good news is that Check Point has already released a Hot Fix update to plug the loophole, so any reader who is already using Check Point's VPN, please update it now.

# Trending # lemon 8 diary # vpn # checkpoint # freedomhack

7/5 Edited to

... Read moreจากประสบการณ์การใช้งาน VPN ติดต่อกับระบบงานภายในองค์กร รวมถึงในช่วงที่เกิดเหตุการณ์ช่องโหว่ Zero-Day ที่เกิดขึ้นกับ Check Point VPN ผมพบว่าความเสี่ยงจากช่องโหว่แบบนี้ไม่ได้หยุดอยู่แค่ที่การเข้าถึงระบบที่ไม่ได้รับอนุญาตเท่านั้น แต่ยังส่งผลกระทบต่อความเชื่อมั่นในการรักษาความปลอดภัยขององค์กรด้วย ช่องโหว่ CVE-2026-50751 ที่เกิดที่ IKEv1 Key Exchange ทำให้แฮกเกอร์สามารถแทรกแซงและสร้าง VPN Session โดยไม่ต้องใช้รหัสผ่านนั้น ถือว่าอันตรายมาก เพราะช่องโหว่นี้ใช้กลไกยืนยันตัวตนของ Certificate และการแลกเปลี่ยนกุญแจที่ผิดพลาดเป็นจุดอ่อน ทำให้แฮกเกอร์สามารถเลี่ยงมาตรการยืนยันตัวตน ส่งผลให้เข้าถึงระบบได้เสมือนเป็นผู้ใช้งานจริง ผมขอแนะนำให้ทุกองค์กรและผู้ใช้ VPN ของ Check Point ต้องรีบอัปเดตแพตช์ Hot Fix โดยทันที เพราะถึงแม้ Check Point จะออกอัปเดตมาแก้ไขช่องโหว่นี้แล้ว แต่ถ้าไม่อัปเดตระบบก็ยังเปิดโอกาสให้แรนซัมแวร์ Qilin เข้ามาคุกคามและเข้าถึงข้อมูลสำคัญภายในองค์กร หากถูกโจมตีสำเร็จอาจต้องใช้ต้นทุนเวลามากในการกู้คืนข้อมูล นอกจากนี้ การตั้งระบบแจ้งเตือนและเปิดใช้งานมาตรการรักษาความปลอดภัยเสริม เช่น การยืนยันตัวตนแบบหลายปัจจัย (MFA) รวมถึงเฝ้าระวังการเคลื่อนไหวผิดปกติบนระบบ VPN ด้วยจะเป็นการเพิ่มเกราะป้องกันอีกชั้นหนึ่ง สุดท้ายนี้เรื่องนี้เป็นกรณีศึกษาให้เห็นว่าการอัปเดตแพตช์ความปลอดภัยอย่างสม่ำเสมอเป็นสิ่งที่ทุกองค์กรไม่ควรมองข้าม โดยเฉพาะกับช่องโหว่ความปลอดภัยระดับวิกฤติที่มีผลกระทบต่อการทำงานและความปลอดภัยของข้อมูลอย่างมาก