TechCrunch Desktop Logo TechCrunch Mobile Logo LatestStartupsVentureAppleSecurityAIAppsDisrupt 2026 EventsPodcastsNewsletters SearchSubmit Site Search Toggle Mega Menu Toggle Topics Latest AI Amazon Apps Biotech & Health Climate Cloud Computing Commerce Crypto Enterprise EVs Fintech Fundraising Gadgets Gaming Google Government & Policy Hardware Instagram Layoffs Media & Entertainment Meta Microsoft Privacy Robotics Security Social Space Startups TikTok Transportation Venture More from TechCrunch Staff Events Startup Battlefield StrictlyVC Newsletters Podcasts Videos Partner Content TechCrunch Brand Studio Crunchboard Contact Us In Brief Posted: 10:40 AM PDT · June 9, 2026 Image Credits:Bryce Durbin / TechCrunch Zack Whittaker CISA gives US federal agencies three days to fix a VPN bug under attack by a ransomware gang A ransomware group is actively exploiting an unpatched flaw in security tools used across the U.S. federal government, prompting the U.S. cybersecurity agency CISA to order all civilian agencies to remediate the vulnerability by end of day Wednesday. Cybersecurity firm Check Point Software said the bug affects several of its remote access tools, firewalls, and VPNs, which act as digital gatekeepers to protect company networks from unauthorized access. The company said in a separate blog post that it had confirmed the bug was being exploited by a known ransomware group called Qilin to hack into “a few dozen targeted organizations globally” that rely on the affected security tools.
The hacks began on May 7 but activity began to rise last week, per Check Point. Given the risk to the federal government’s enterprise network, CISA on Monday ordered all civilian federal agencies — such as Homeland Security, the Department of State, and the Treasury — to fix any instances where agencies are using the affected products by end of day June 11. The agency cited BOD 22-01, its operational guidance memo that allows it to instruct agencies to take security action when there is an active cyber threat to government networks.
Topics CISA, cybersecurity, In Brief, Security, zero-day October 13 – 15 San Francisco Scale faster. Gain practical expertise. No matter your goal, Disrupt can empower you.Save up to $300 today!
REGISTER NOW Newsletters See More Subscribe for the industry’s biggest tech news TechCrunch Daily News Every weekday and Sunday, you can get the best of TechCrunch’s coverage. TechCrunch Mobility TechCrunch Mobility is your destination for transportation news and insight. Startups Weekly Startups are the core of TechCrunch, so get our best coverage delivered weekly.
StrictlyVC Provides movers and shakers with the info they need to start their day. Subscribe By submitting your email, you agree to our Terms and Privacy Notice. { "title": "Newsletters", "description": "Subscribe for the industry’s biggest tech news", "showBtn": "1", "newsletters": [,,,], "currentUserEmail": "", "urls": } Related AI The AI safety test is becoming a safety risk Rebecca Bellan 16 hours ago Security This ‘adversarial’ pattern can prevent surveillance cameras from detecting you Zack Whittaker 16 hours ago Security Google’s top hacker hunter explains why hacking groups get codenames Lorenzo Franceschi-Bicchierai 2 days ago Latest in Security AI The AI safety test is becoming a safety risk Rebecca Bellan 16 hours ago Security This ‘adversarial’ pattern can prevent surveillance cameras from detecting you Zack Whittaker 16 hours ago Security Google’s top hacker hunter explains why hacking groups get codenames Lorenzo Franceschi-Bicchierai 2 days ago X LinkedIn Facebook Instagram youTube Mastodon Threads Bluesky TechCrunchStaffContact UsAdvertiseCrunchboard JobsSite Map Terms of ServicePrivacy PolicyRSS Terms of UseCode of Conduct OpenAI vs AppleNous ResearchSpace Data CentersStaya NadellaSpaceX StarshipTech LayoffsChatGPT © 2026 TechCrunch Media LLC.
Extract — continue reading at the source.