← Back to feed
TechJun 9100% confidenceConfidence 100% — the share of independent, credible sources corroborating the core facts.

CISA Orders Federal Agencies to Patch Critical VPN Vulnerability Exploited by Ransomware Gang

Left 14%Center 86%
7 sources

The U.S. Cybersecurity and Infrastructure Security Agency issued a new binding directive requiring federal civilian agencies to remediate the most critical software vulnerabilities within three calendar days, with timelines varying based on exposure, exploitability, and impact. The directive, BOD 26-04, supersedes older 2019 and 2021 patching mandates and was partly prompted by AI tools enabling faster vulnerability discovery and exploitation. It arrives alongside an active ransomware campaign exploiting a Check Point VPN zero-day that gave attackers a month-long head start before a patch was available.

CISA's new Binding Operational Directive 26-04, announced Wednesday, establishes a tiered remediation framework for Federal Civilian Executive Branch agencies based on four criteria: whether a system is publicly exposed, whether the vulnerability appears in CISA's Known Exploited Vulnerabilities catalog, whether exploitation can be automated, and the degree of access an attacker would gain. As illustrated in CISA's decision-tree diagram, vulnerabilities meeting all four criteria must be fixed within three days and require a forensic triage to check for prior compromise; less severe flaws carry two-week or two-month deadlines. CISA Acting Executive Assistant Director Chris Butera cited advances in AI models — specifically their ability to autonomously find and exploit vulnerabilities at scale — as a key driver, noting that 'defenders cannot afford to take weeks to patch systems that can be autonomously exploited en masse.' The directive supersedes BOD 19-02 and BOD 22-01, which had set 15- and 30-day windows for the most critical bugs. Separately, CISA also invoked the older BOD 22-01 to order agencies to patch CVE-2026-50751, a critical authentication bypass in Check Point Remote Access VPN and Mobile Access products being actively exploited by a Qilin ransomware affiliate since at least May 7, with a remediation deadline of June 11. Check Point released an emergency hotfix on June 8 and disclosed a second related vulnerability, CVE-2026-50752, affecting IKEv1 key exchange configurations, though no in-the-wild exploitation of the second flaw has been reported. Some security experts welcomed the new directive but cautioned that faster patching alone is insufficient without architectural changes to limit attacker access after a breach.

What's missing

The sources do not clarify how compliance with the new three-day deadline will be enforced or what consequences agencies face for missing it, nor do they detail what resources or funding CISA is providing to help under-resourced agencies meet the accelerated timelines.

How coverage differed

Wired framed the directive primarily through the lens of AI's transformative threat to cybersecurity and included critical expert voices questioning whether patching alone is sufficient, while Channel NewsAsia and BleepingComputer focused more narrowly on the operational mechanics and timelines of the new directive without the broader systemic critique.

What different sources said

  • CISA gives US federal agencies three days to fix a VPN bug under attack by a ransomware gang

  • Ransomware crims got a month-long head start on Check Point VPN 0-day that now has a fix

  • '24 hours to fix ...': US cybersecurity agency CISA to several other government agencies

  • CISA tells govt agencies to patch critical exploited flaws in 3 days

  • US shortens cyber fix window to three days as AI threats rise

  • WiredLeft

    CISA Tells US Agencies to Fix Security Bugs in as Little as 3 Days Thanks to AI Threats

  • Cybersecurity stocks in spotlight as U.S. vulnerability takes center stage

Related

TechConfidence 69% — the share of independent, credible sources corroborating the core facts.

Samsung Galaxy S25 and S25 FE See Significant Price Cuts

Samsung's Galaxy S25 and Galaxy S25 FE smartphones are currently available at notably reduced prices, with the S25 FE dropping $201 (33%) to $449 on Woot for a limited time. The price reductions come amid a competitive smartphone market and ahead of anticipated future Samsung releases. The discounts make previously premium-priced devices more accessible to budget-conscious consumers.

2 sourcesJun 16
TechConfidence 100% — the share of independent, credible sources corroborating the core facts.

Anthropic Disables Fable 5 and Mythos 5 AI Models Globally After US Government Export Control Order

Anthropic has suspended all public access to its two most advanced AI models, Fable 5 and Mythos 5, after the US Commerce Department issued an export control directive ordering the company to block foreign nationals from accessing them on national security grounds. The order came just three days after Fable 5's public launch and reportedly stems from government concerns about a potential jailbreak that could enable the models to assist with cyberattacks, though Anthropic says it received only verbal evidence of a narrow, non-universal vulnerability. The shutdown affects all customers globally — including enterprise users and Anthropic employees — and marks a significant escalation of US efforts to restrict foreign access to advanced AI models themselves, rather than just the chips that power them.

4 sourcesJun 16
TechConfidence 89% — the share of independent, credible sources corroborating the core facts.

Xbox Free Play Days Offers Three Games Free to Play June 11–14

Microsoft's Xbox Free Play Days program is offering Hell Let Loose, State of Decay 2: Juggernaut Edition, and Blasphemous 2 at no cost from June 11 to June 14. Hell Let Loose requires an Xbox Game Pass Ultimate, Premium, or Essential membership, while State of Decay 2 and Blasphemous 2 (via a five-hour timed trial) are accessible to all Xbox console owners. Players who wish to keep any of the games can purchase them at a limited-time discount and retain any achievements earned during the free period.

2 sourcesJun 13