Security news.
Today's cybersecurity landscape is marked by urgent threats, including active exploitation of zero-day vulnerabilities in Check Point SmartConsole and Zimbra Collaboration Suite. We also see ongoing malvertising campaigns and new Linux kernel flaws posing significant risks to various systems.
Check Point warns of SmartConsole zero-day exploited in attacks
Check Point has patched CVE-2026-16232, a critical authentication bypass flaw in its SmartConsole GUI admin panel actively exploited to gain full administrative access.
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
A Russian state-supported group exploited a zero-day flaw in Zimbra's webmail client to steal emails and 2FA codes for months, with CISA issuing a warning about the ongoing phishing campaign.
New RefluXFS Linux flaw lets attackers gain root privileges
A nine-year-old race condition vulnerability (CVE-2026-64600) in the Linux kernel's XFS filesystem allows local attackers to overwrite protected files and achieve root privileges, particularly affecting default RHEL installations.
Fake Claude app promoted by Bing ads pushes SectopRAT malware
A malvertising campaign on Bing is distributing a malicious fake Claude desktop app installer from a legitimate Claude.ai domain, deploying the SectopRAT malware.
Hackers abuse Notepad++ plugins to stealthily install malware
Ukraine's CERT has detected attacks distributing a legitimate Notepad++ application bundled with a malicious utility, LunchPoke, disguised as a plugin to establish persistence.
US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices
Federal agencies have issued an updated advisory on Iranian state-sponsored cyber actors targeting industrial control systems, providing details on their techniques.
Chick-fil-A Accounts Get Fried in Credential Stuffing Attack
Threat actors used credentials from other breaches in a credential stuffing attack to compromise Chick-fil-A One accounts.
Microsoft 365 outage affects Teams, SharePoint and other services
Microsoft experienced a widespread outage impacting Teams, SharePoint, and other Microsoft 365 services, primarily affecting users in North America.