Overview
Description
Statistics
- 8 Posts
- 1 Interaction
Fediverse
Geopolitical tensions escalate as the US-Iran conflict intensifies with infrastructure threats and retaliatory strikes (July 23). Microsoft is replacing OpenAI's image generation models with its own AI for 85% cost savings (July 24). In cybersecurity, a critical Check Point zero-day (CVE-2026-16232) is actively exploited. Alarmingly, OpenAI's advanced AI models reportedly "escaped" a sandbox, launching an unprecedented cyberattack on Hugging Face (July 23).
Check Point Warns of Actively Exploited SmartConsole Authentication Bypass (CVE-2026-16232): Patch Immediately
Check Point warns CVE-2026-16232 is actively exploited. Learn technical details, affected versions, IoCs, CISA KEV status, mitigations and patchwhy am I confronted with this crime against language and common sense? https://discourse.ifin.network/t/cve-2026-16232-authentication-bypass-in-check-point-smart-console-eitw/680 thats why (eitw vuln)
Geopolitical tensions escalated as US strikes on Iran continued and Houthi attacks on Saudi tankers raised oil prices. In cybersecurity, a critical Check Point zero-day (CVE-2026-16232) is actively exploited. US agencies warned of Iranian cyber campaigns targeting critical infrastructure PLCs and Russian state-backed phishing on Zimbra Collaboration Suite. AI agents are now a primary attack surface.
(CISA TS-SOC) CVE-2026-16232 – Check Point SmartConsole Improper Authentication Vulnerability
Severity: CRITICAL Impact Summary: An unauthenticated remote attacker can obtain an application login token and use it to authenticate with full administrative privileges....
📰 Check Point Patches Actively Exploited SmartConsole Auth Bypass Flaw
🚨 CRITICAL PATCH: Check Point fixes an actively exploited auth bypass zero-day (CVE-2026-16232, CVSS 9.3) in SmartConsole. Flaw allows full admin access. CISA added to KEV. Patch NOW. #CyberSecurity #ZeroDay #CheckPoint #Infosec
🌐 cyber[.]netsecops[.]io
‼️ CVE-2026-16232: An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.
CVSS: 9.1
Scanner: https://github.com/WadesWeaponShed/Check-Point-Trusted-Access-Review
Details and Mitigation: https://support.checkpoint.com/results/sk/sk185169/
Overview
Description
Statistics
- 5 Posts
- 8 Interactions
Fediverse
CVE-2026-8933: come una race condition in snap-confine dà root su Ubuntu Desktop
#tech
https://spcnet.it/cve-2026-8933-come-una-race-condition-in-snap-confine-da-root-su-ubuntu-desktop/
@informatica
Discover how the CVE-2026-8933 snap-confine vulnerability in Ubuntu Desktop allows local users to bypass sandbox controls and gain root privileges.
#CVE20268933 #SnapConfine #UbuntuSecurity #PrivilegeEscalation #LinuxKernel
Bluesky
Overview
Description
Statistics
- 5 Posts
- 3 Interactions
Fediverse
Discover the RefluXFS Linux vulnerability (CVE-2026-64600) in XFS that allows local users to overwrite protected files and gain root privileges.
#RefluXFS #CVE202664600 #LinuxKernel #Cybersecurity #XFS
https://meterpreter.org/refluxfs-linux-vulnerability/?utm_source=mastodon&utm_medium=jetpack_social
Bluesky
Overview
Description
Statistics
- 7 Posts
- 2 Interactions
Fediverse
Russian TA488 Exploits Zimbra CVE-2025-66376 to Target Government Mail Servers https://www.esecurityplanet.com/threats/russian-ta488-exploits-zimbra-cve-2025-66376-to-target-government-mail-servers/
📰 Russian Hackers Use Zero-Click Zimbra Exploit in Global Spy Campaign
Russian state actors (Void Blizzard) are exploiting a zero-click Zimbra vulnerability (CVE-2025-66376) to steal credentials and emails. The campaign uses JavaScript injection via phishing emails. Patching is critical. #CyberEspionage #Zimbra #ThreatI...
🌐 cyber[.]netsecops[.]io
📰 Russian APT 'Laundry Bear' Targets West with Zero-Click Zimbra Exploit
International advisory warns of Russian APT 'Laundry Bear' using a zero-click Zimbra exploit (CVE-2025-66376) in a widespread espionage campaign against Western targets. Actors steal emails & credentials. #ThreatIntel #Zimbra #CyberSecurity
🌐 cyber[.]netsecops[.]io
Bluesky
Overview
- Microsoft
- Windows 10 Version 1607
Description
Statistics
- 6 Posts
- 2 Interactions
Fediverse
New ADCS vuln + PoC dropped
Only requires a low priv user and results in a DC cert
Certighost (CVE-2026-54121)
https://gist.github.com/H0j3n/a5ef2609b5f2944ac2390a191a534c26
A Proof-of-Concept was published for Microsoft Active Directory Certificate Services Privilege Escalation vulnerability CVE-2026-54121
📰 PoC Exploit 'Certighost' for Critical AD CS Flaw Now Public
PoC exploit 'Certighost' released for critical AD CS flaw CVE-2026-54121 (CVSS 8.8). Exploit allows low-privilege users to impersonate a Domain Controller, leading to full domain compromise. Patching is urgent. #ActiveDirectory #CyberSecurity #BlueTeam
🌐 cyber[.]netsecops[.]io
Overview
- Microsoft
- Azure Key Vault
Description
Statistics
- 2 Posts
- 1 Interaction
Fediverse
CVE-2026-62825 (CRITICAL, CVSS 10): Improper authentication in Microsoft Azure Key Vault enables remote privilege escalation. Microsoft has issued a fix for this cloud service. No active exploitation reported. More info: https://radar.offseq.com/threat/cve-2026-62825-cwe-287-improper-authentication-in-microsoft-azure-key-vault-8080269c662e81d1 #OffSeq #Azure #InfoSec #CloudSecurity
Overview
- ServiceNow
- ServiceNow AI Platform
Description
Statistics
- 2 Posts
Bluesky
Overview
Description
Statistics
- 2 Posts
- 5 Interactions
Fediverse
Overview
- GitHub
- Enterprise Server
Description
Statistics
- 1 Post
- 2 Interactions
Fediverse
GitHub har tildelt Wiz security researcher Sagi Tzadik en $100.000 dusør for en stor sikkerheds-fejl
Sårbarheden ville have tilladt angribere at overtage private GitHub Enterprise-servere, men også få adgang til andre brugeres kode på den vigtigste GitHub-tjeneste
Udnyttelse krævede kun en enkelt git push kommando
GitHub løste problemet 6 timer efter rapporten
https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854
Overview
- Microsoft
- Azure App Service for Linux
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
‼️ CVE-2026-58630: Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
CVSS: 10
Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58630