Security news.
Today's security landscape is marked by critical zero-day exploitation, new Linux vulnerabilities, and significant data breaches. Threat actors continue to innovate, weaponizing legitimate services and leveraging sophisticated malware, while AI models are being benchmarked for their cybersecurity investigation capabilities.
Check Point Zero-Day Actively Exploited in the Wild
A critical authentication bypass vulnerability (CVE-2026-16232) in Check Point SmartConsole, affecting Security Management and Multi-Domain Management products, is being actively exploited to gain full administrative access.
New RefluXFS Linux Flaw Grants Root Privileges
A nine-year-old race condition (CVE-2026-64600) in the Linux kernel's XFS filesystem allows local attackers to overwrite protected files and achieve root privileges, notably affecting default RHEL, Fedora, and Amazon Linux installations.
Attackers Weaponize GitHub Actions to Target cPanel and WHM
A large-scale campaign is leveraging compromised GitHub repositories as distributed attack infrastructure to target cPanel and WebHost Manager (WHM) instances, involving malicious Packagist development versions.
US Warns of Iranian Hackers Targeting ICS Devices
Federal agencies have issued an updated advisory highlighting Iranian state-sponsored actors targeting Siemens, Schneider, and Rockwell Industrial Control Systems (ICS) devices, providing insights into their techniques.
Upbound Group Reports $13 Million Fraudulent Losses from Data Breach
Fintech company Upbound Group disclosed that a data breach, which exposed non-sensitive customer information, led to $13 million in fraudulent Acima leases.
New msaRAT Malware Hides C2 Traffic in Browsers
The Chaos ransomware gang is deploying msaRAT, a new backdoor that conceals its command-and-control communication by routing it through legitimate Chrome or Edge browser processes.
AI Models Struggle with Nuclear-Sabotage Malware Benchmark
A new benchmark by SentinelOne, based on the Fast16 case, reveals that most frontier AI models struggle to effectively conduct malware investigations related to nuclear sabotage scenarios.
Microsoft Investigating Exchange Online Mailbox Quarantine Issue
Microsoft is actively working to resolve an ongoing issue in Exchange Online that has been mistakenly quarantining customer mailboxes since Sunday.