Ransomware Gangs Attack Palo Alto, Fortinet, Citrix, and Check Point VPNs to Target Corporate Networks
Article excerpt
Highlighted: the sentence this signal was extracted from
A coordinated wave of exploitation targeting edge VPN and firewall appliances from four major vendors Palo Alto Networks, Fortinet, Citrix, and Check Point has emerged as the dominant initial-access vector for ransomware operators in mid-2026. Threat actors, including affiliates of the Qilin ransomware-as-a-service (RaaS) operation, are chaining authentication-bypass flaws, credential-harvesting campaigns, and legacy-protocol weaknesses to obtain unauthenticated or credential-free access to corporate perimeters. Once inside, these actors move rapidly toward lateral movement, data exfiltration, and double-extortion ransomware deployment, often within days of a CVE's public disclosure. The campaigns analyzed here span four separate but converging incidents: the "Fortibleed" mass credential-compromise campaign against roughly 75,000 internet-facing FortiGate firewalls; active exploitation of the Palo Alto GlobalProtect authentication-bypass flaw CVE-2026-0257 ; Qilin-linked exploitation of the Check Point VPN authentication-bypass flaw CVE-2026-50751 tied to the deprecated IKEv1 protocol; and rapid in-the-wild abuse of a new CitrixBleed-style NetScaler memory-disclosure bug, CVE-2026-8451 . Each incident underscores the same operational reality: internet-facing remote access infrastructure has become the ransomware ecosystem's preferred front door. Enterprise VPN and firewall...
Keep reading with a free account
The rest of this article, and every signal for Fortinet, is in your free account.
