OTHER

CISA Gives Federal Agencies Three Days to Resolve VPN Vulnerability Exploited by Ransomware Gang

A ransomware group is exploiting an unaddressed vulnerability in security software used by U.S. federal agencies, prompting the U.S. cybersecurity agency CISA to require all civilian departments to resolve the issue by the end of the day Wednesday.

As reported by cybersecurity firm Check Point Software, the problem affects various remote access tools, firewalls, and VPNs, which function as digital barriers to protect corporate networks from unauthorized access.

Check Point has confirmed in another blog post that the flaw is being exploited by a notorious ransomware group named Qilin, which has been targeting “several dozen organizations globally” that are utilizing the affected security solutions.

The cyberattacks reportedly began on May 7 and saw a notable surge in activity last week, according to Check Point.

In response to the threat to federal government enterprise networks, CISA issued a directive on Monday, instructing all civilian federal agencies—including the Department of Homeland Security, State Department, and Treasury—to resolve any instances of the compromised software by the end of the day June 11. The agency cited BOD 22-01, its operational guidance memo, which equips it with the authority to direct agencies to implement security measures in response to an ongoing cyber threat to government networks.