The US Cybersecurity and Infrastructure Security Agency (CISA) has ordered all federal civilian departments to urgently patch an actively exploited vulnerability in their VPN and security systems by 11 June, following targeted cyberattacks by the notorious Qilin ransomware syndicate.
Check Point security tools targeted globally
The critical vulnerability affects multiple remote access tools, firewalls, and VPNs developed by cybersecurity firm Check Point Software. These systems serve as essential digital gateways designed to protect sensitive corporate and government networks from unauthorised external access.
The rise of the Qilin ransomware threat
According to a technical blog post published by Check Point, security analysts confirmed that the security loophole is being actively weaponised by the Qilin ransomware gang. The cybercriminals have already breached “a few dozen targeted organisations globally” that utilise these vulnerable security products. The malicious activity originally commenced on 7 May, with a significant spike in exploitation detected last week.
CISA invokes emergency powers to secure networks
Recognising the immediate risk to federal enterprise infrastructure, CISA intervened on Monday. The agency issued a binding directive requiring civilian departments—including Homeland Security, the Department of State, and the Treasury—to secure all vulnerable installations by the close of business on 11 June.
The agency authorised this urgent mandate under BOD 22-01, its operational guidance memo that empowers CISA to compel federal agencies to mitigate known security risks in the face of active cyber threats to government networks.
