
Check Point patches SmartConsole zero-day under attack
Check Point has issued a hotfix for a zero-day vulnerability in its SmartConsole GUI that attackers were already exploiting in the wild.
Incidents, vulnerabilities, abuse and certificates.

Check Point has issued a hotfix for a zero-day vulnerability in its SmartConsole GUI that attackers were already exploiting in the wild.

Iran's Revolutionary Guard claims to have struck an Amazon Web Services data center in Bahrain with cruise missiles, marking a potential escalation in targeting commercial cloud infrastructure during Middle Eastern hostilities. AWS has not confirmed the attack or damage.

The US government has filed a civil forfeiture action to seize the domain Egypt.com, claiming it was purchased with cryptocurrency linked to the now-defunct Abacus Market darknet marketplace. The complaint alleges the domain was acquired through a US brokerage and registrar using funds traced to drug trafficking operations.

OVH deployed emergency fixes for the Januscape guest-host escape vulnerability across its infrastructure, rebooting tens of thousands of hosts to protect roughly one million virtual machines after testing the process in Australia.

Cloudflare has activated Web Application Firewall protections for two high-severity WordPress vulnerabilities—an unauthenticated remote code execution flaw and a SQL injection issue—affecting versions 6.8 and later. The rules block attack attempts while sites apply patches released in WordPress 7.0.2 and backported versions.

Arelion's 2026 report identifies the Aisuru botnet as the source of 33% of DDoS traffic on its AS1299 backbone, highlighting the growing scale and economic impact of compromised consumer devices on global network defense.

Three Russian nationals face US federal charges for allegedly running a bulletproof hosting service used by ransomware gangs, causing over $62 million in damages worldwide.

SonicWall has released emergency fixes for two zero-day vulnerabilities in its SMA1000 secure access gateways after observing active exploitation. No customer impact details have been disclosed.

Cybersecurity agencies from the United States and eight partner countries have released a coordinated advisory detailing Russian state-sponsored attacks on critical infrastructure via vulnerable network routers. The alert provides mitigation guidance for operators.

Progress Software has instructed customers running on-premises ShareFile Storage Zone Controllers to power down servers immediately after identifying a credible security threat.

A critical authentication bypass vulnerability in the official Gitea Docker image is being actively exploited, allowing attackers to gain unauthorized access to self-hosted Git services by impersonating users, including administrators.

Zimbra has released a security update for its Classic Web Client after discovering a critical cross-site scripting vulnerability that could allow attackers to hijack user sessions. The company advises all customers to apply the patch without delay.

A China-linked threat group has exploited a vulnerability in Roundcube webmail servers at U.S. and Canadian universities to steal credentials and deploy backdoor malware, according to security researchers.

BeyondTrust issued fixes for critical vulnerabilities in its Remote Support and Privileged Remote Access software that allowed authentication bypass, potentially exposing customer sessions to unauthorized access.

DigiCert has released a preview of Quantum Central, a tool designed to help enterprises identify cryptographic assets, assess quantum attack exposure, and manage migration to post-quantum algorithms without disrupting production systems.

Over 81 million login attempts were recorded in a two-week password-spraying campaign against Microsoft 365 environments, security researchers reported.

A campaign targeting Python developers has been distributing malicious PyPI packages that compromise Telegram bot servers, allowing attackers to read arbitrary files since November 2025.

AWS Certificate Manager (ACM) now supports the ACME protocol for automated public TLS certificate issuance, enabling centralized management, policy enforcement, and auditability across organizations.

The World Wide Web Consortium has released a draft policy outlining how security researchers can report suspected vulnerabilities in its standards and specifications, aiming to streamline triage and resolution through formal W3C processes.

A security researcher found that India’s .bank.in registry, operated by IDRBT, exposed bcrypt password hashes, contact details, and login metadata of 5,576 bank employees via unauthenticated API endpoints for over a year. The flaw was fixed after disclosure in early June 2026.