Abstract server racks depicting zero-day, code execution, and Linux appliance flaws.

Daily Cybersecurity News - June 8, 2026

Check Point VPN Zero-Day Tied to Qilin

Check Point pushed patches for a Remote Access VPN and Mobile Access flaw hit by zero-day attacks.

The flaw lets attackers bypass authentication and reach internal networks. One observed case was tied, with medium confidence, to a Qilin ransomware affiliate.

Affects only deployments using the deprecated IKEv1 key exchange protocol (Remote Access VPN, Mobile Access, Spark). Tracked as CVE-2026-50751, CVSS 9.3.

Check Point released updates across multiple gateway models and versions in a single coordinated push.

Everest Forms Flaw Hands Code Execution

WordPress sites running Everest Forms Pro just got hit with a remote code execution flaw (CVE-2026-3300) that attackers have already used for two months.

The bug lets unauthenticated users upload and run arbitrary PHP files through the plugin's form handling. CVSS 9.8, actively exploited in the wild.

Affects Everest Forms Pro up to and including 1.9.12, patched in 1.9.13. Commercial add-on, around 4,000 active installs.

Wordfence has blocked over 29,300 exploit attempts so far, with payloads dropping rogue admin accounts and web shells.

Source: SecurityWeek

SolarWinds Serv U Vulnerability Exploited in the Wild

SolarWinds Serv-U has a flaw that unauthenticated attackers are already exploiting in the wild.

Specially crafted POST requests crash the service. The issue affects the file transfer server component.

Any organization running Serv-U faces exposure, especially those with internet-facing deployments.

Patch available from SolarWinds now.

Source: SecurityWeek

VerdantBamboo Deploys BSD Variant of BRICKSTORM on Linux Appliances

A China nexus group tracked as VerdantBamboo is hitting Linux appliances with a BSD variant of the BRICKSTORM backdoor.

They drop the backdoor plus two other families on compromised systems. Volexity ties the activity to this specific cluster.

The fresh angle is a BSD variant landing on a pfSense firewall, with persistence customized per device.

Cluster overlaps with Clay Typhoon, UNC5221, and Warp Panda. Dwell time at least 18 months.