Kaspersky’s Q2 2026 IT threat evolution report highlights a surge in critical exploits, notably the Microsoft Defender BlueHammer vulnerability and Check Point VPN zero-days. These incidents have driven sophisticated ransomware attacks, with Qilin identified among the most active groups. Organisations must understand the details of these threats to effectively defend their systems.
Key Findings from Kaspersky’s Q2 2026 Report
The Q2 2026 reporting period saw a continuation of high-profile attacks and the emergence of new malware variants targeting non-mobile systems. The report, based on millions of detection events, offers a statistical view of the evolving threat landscape:
- Nearly 400 million online attacks were blocked by Kaspersky products.
- Over 16 million malicious or unwanted objects were stopped by File Anti-Virus.
- 2,538 new ransomware variants identified.
- More than 71,000 users globally experienced ransomware attacks.
- Qilin accounted for 15 percent of ransomware victims whose data was published on leak sites.
- Over 213,000 users targeted by cryptomining malware.
The persistence and evolution of ransomware, as well as the exploitation of high-impact vulnerabilities, stand out as defining elements of this quarter.
Active Exploitation: Microsoft Defender BlueHammer (CVE-2026-33825)
One of the most significant findings in Q2 2026 is the active exploitation of the BlueHammer vulnerability in Microsoft Defender. Tracked as CVE-2026-33825, this local privilege escalation flaw enables attackers to elevate their access rights on compromised Windows systems, a crucial step for ransomware deployment and lateral movement.
Vulnerability Details and Timeline
- Vulnerability: BlueHammer (CVE-2026-33825)
- Affected Product: Microsoft Defender on Windows platforms
- Type: Local privilege escalation (LPE)
- Disclosure: Early April 2026
- Patch Released: 14 April 2026 by Microsoft
- Active Exploitation Confirmed by CISA: 22 April 2026
According to CISA’s Known Exploited Vulnerabilities (KEV) catalog, attackers have exploited this vulnerability in ransomware campaigns. While Microsoft rapidly issued a fix, unpatched systems remain at risk. No specific threat group attribution has been made public, but the exploitation aligns with a surge in ransomware attacks observed during the quarter.
Check Point VPN Zero-Day (CVE-2026-50751) and Related Flaws
A second major security event identified in Kaspersky’s report is the zero-day exploitation of Check Point Remote Access VPN and Mobile Access. The core flaw, CVE-2026-50751, allows unauthorised access and possible network compromise. Attackers began exploiting this vulnerability as a zero-day on 7 May 2026, with a notable increase in activity in early June.
Attack Details and Scope
- Vulnerability: CVE-2026-50751 (critical)
- Affected Products: Check Point Remote Access VPN, Mobile Access
- Attack Timeline: Zero-day exploitation began 7 May 2026, spiking in June
- Threat Actor: Qilin ransomware group linked to at least one confirmed incident
- Victim Count: Several dozen organisations targeted, with ongoing investigations
Check Point also identified a related vulnerability, CVE-2026-50752, impacting site-to-site VPN connections using the legacy IKEv1 protocol. This flaw undermines certificate validation, potentially allowing attackers to intercept or manipulate VPN traffic between sites.
Both vulnerabilities highlight the risks of exposed remote access services and legacy protocols, especially for organisations relying on VPNs for secure connectivity.
Ransomware Trends and Qilin Activity
The quarter saw ransomware continue to dominate the threat landscape. Kaspersky detected over 2,500 new ransomware variants, and the number of users impacted remains high. Qilin, in particular, was responsible for 15 percent of victims whose data was posted to data leak sites, indicating coordinated and targeted operations.
Malware-signing services were also disrupted this quarter. Microsoft’s Digital Crimes Unit took down a malware-signing-as-a-service (MSaaS) operation, known as Fox Tempest, that provided digital signatures for ransomware groups including Qilin. This action involved seizing the MSaaS domain, revoking certificates, and legal action against operators, disrupting a critical enabler for ransomware campaigns.
Why These Vulnerabilities Matter
Both the BlueHammer and Check Point VPN vulnerabilities present significant risks to organisations of all sizes. Attackers are actively targeting unpatched systems and exposed remote access services to gain initial access, escalate privileges, and deploy ransomware. The confirmed involvement of the Qilin group and the rapid exploitation timelines underscore the need for urgent response.
Recommendations for Organisations
- Immediately apply the latest security patches for Microsoft Defender (CVE-2026-33825) and all affected Check Point VPN products (CVE-2026-50751, CVE-2026-50752).
- Review VPN access policies: limit exposure, disable legacy protocols like IKEv1 where possible, and enforce strong authentication.
- Monitor for signs of Qilin-linked activity and review logs for suspicious VPN access or privilege escalation attempts.
Organisations, especially UK SMBs, should prioritise patch management and review their VPN configurations in light of these active threats.
Originally reported by securelist.com.






