fuente: https://thehackernews.com/2026/07/check-point-patches-exploited.html
Check Point has released security updates to address multiple vulnerabilities impacting Security Management and Multi-Domain Management (MDSM) products, including a critical flaw that has come under active exploitation in the wild.
The security flaw, tracked as CVE-2026-16232 (CVSS score: 9.3), is an authentication bypass affecting the Check Point SmartConsole login process that allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.
Esta nueva vulnerabilidad, aún sin parchear, permite que un cliente remoto no autenticado colapse los servidores HTTP/3 basados en XQUIC de Alibaba con aproxima...
Leer artículo →La campaña de vishing roba credenciales y respuestas de autenticación multifactor (MFA), e intenta registrar claves de acceso controladas por el atacante, adapt...
Leer artículo →Durante tres semanas, este grupo dejó su servidor completamente expuesto, revelando toda la operación: WP-SHELLSTORM. En su interior se encontraron 27 vulnerabi...
Leer artículo →