Everything threat intel needs, in one platform

Deltabridge reads and correlates the noise across 300+ sources and synthesises it into decision-ready intelligence, so your analysts spend their judgement where it counts.

How it works

Noise in. Intelligence out.

Every source is read, correlated to the threat it concerns, and routed into the right living Brief. A new Brief only appears when something is genuinely new, so the noise never reaches you.

300+
sources ingested
200K+
entities tracked
81K+
connections mapped
1
feed that matters

Core ecosystem

Briefs you act on. An analyst on call. A graph that ties it together.

One living dossier per threat: a campaign, CVE, actor or malware family. It stays current as new intelligence lands, so the story you cared about last month is still tracked today.

  • 300+ OSINT sources, one filtered feed
  • Living Briefs that re-synthesise
  • Sector-tuned to your stack
Try it free
app.deltabridge.ai/monitor/briefs
20 references·Updated August 13, 2026

Qilin Ransomware Expands Operations Exploiting VPN Zero-Days Globally

qilin
RansomwareRansomware-as-a-ServiceZero Day ExploitInitial AccessCybercrime

Threat assessment

79.2

A critical ransomware threat with severe exploitation capability exploiting zero-days globally, though limited immediate mitigation options reduce overall actionability.

Summary

Qilin has emerged as one of the most operationally active ransomware-as-a-service operations in 2026, chaining zero-day and high-severity authentication-bypass vulnerabilities in enterprise VPN products — CVE-2026-50751 (Check Point) and CVE-2026-0257 (Palo Alto PAN-OS GlobalProtect) — to achieve initial access without valid credentials.

Its reach is amplified by the access broker Woodgnat (KongTuke), whose Mistic backdoor and ModeloRAT toolkit seed footholds later sold to affiliates. By early July 2026 Qilin was assessed as the leading RaaS operation globally by victim volume.

Timeline

  1. 12 August 2026
    Qilin attacks South Korean motor and robotics manufacturer
    Confirmed targeting expands the group's focus on South Korean industrial and technology sectors.
  2. 27 July 2026
    Qilin and LockBit 5 dominate Italian ransomware incidents
    Together they account for a disproportionate share of 148 confirmed claims against Italian organisations in H1 2026.
  3. 21 July 2026
    Affiliates confirmed exploiting PAN-OS CVE-2026-0257
    Arctic Wolf Labs ties multiple June 2026 intrusions to the GlobalProtect authentication-bypass flaw.
  4. 08 June 2026
    Check Point discloses CVE-2026-50751, confirms exploitation
    A CVSS 9.3 improper-authentication flaw in Remote Access VPN, attributed to a Qilin affiliate.
  5. 01 May 2026
    CVE-2026-50751 exploitation begins ahead of disclosure
    Evidence indicates Qilin affiliates exploited the flaw weeks before the advisory.

Technical details

Qilin affiliates exploit CVE-2026-50751 (CVSS 9.3) by abusing a logic weakness in the IKEv1 certificate-validation flow to establish VPN sessions without valid credentials. The payload chain now incorporates a custom Rust-based loader and a kernel-level driver that terminates EDR before encryption commences.

CVEs

CVE-2026-50751, CVE-2026-50752, CVE-2026-0257, CVE-2024-24919

Affected systems

Check Point Remote Access VPN, Mobile Access, Spark Firewall; Palo Alto PAN-OS GlobalProtect; enterprise Windows environments.

References

SecurityWeek24/06/2026
New 'Mistic' RAT Opens Door to Several Ransomware Families

Mistic is used by Woodgnat, an initial access broker working with Qilin, Interlock, Rhysida, Akira, 8Base and Black Basta.

Rapid7 Blog08/06/2026
Critical Check Point VPN Zero-Day Exploited in the Wild (CVE-2026-50751)

On June 8 2026 Check Point published an advisory for a critical authentication-bypass vulnerability affecting Remote Access VPN, Mobile Access and Spark Firewall.

DarkReading08/06/2026
Check Point VPN Flaw Exploited Since Early May

A critical zero-day is under attack; a Qilin ransomware affiliate has been blamed for at least one incident.

See how all three work together, end to end.

Explore the live demo

Put it on your own threats

Start free and turn your noisy feeds into decision-ready briefs in minutes. No credit card required.