Ransomware groups are actively exploiting unpatched flaws in security tools used across the U.S. federal government, prompting the U.S. cybersecurity agency CISA to order all civilian agencies to remediate the vulnerabilities by the end of Wednesday.
Cybersecurity firm Check Point Software said the bug affects several of its remote access tools, firewalls and VPNs, which act as digital gatekeepers protecting internal networks from unauthorized access.
In a separate blog post, the company said it has confirmed that the bug has been exploited by a known ransomware group called Qilin to hack “dozens of targeted organizations around the world” that rely on the affected security tools.
Check Point said the hacking began on May 7, but activity began to increase last week.
Given the risks to federal enterprise networks, CISA on Monday ordered all civilian federal agencies, including the Departments of Homeland Security, State, and Treasury, to remediate all instances using the affected products by the end of June 11th. The agency cited BOD 22-01, an operational guidance memo that directs government agencies to take security measures when there is an active cyber threat to government networks.

