The flaw, CVE-2026-93616, allows an attacker who can access the server’s web service to run scripts on it without logging in. Check Point released a fix on September 22 for the server that controls firewall policies for the Check Point
Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root
Kernel maintainers have fixed all four over the past few weeks, so a system running an up-to-date kernel is not affected. But the exploit code is now public, and any machine still running an older kernel should be updated.
The flaws
Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
The vulnerability in question is CVE-2026-89026 (CVSS v3.1 score: 9.8/CVSS v4.0 score: 9.3), which can allow an unauthenticated remote attacker to execute arbitrary operating system (OS) commands by taking advantage of a hard-coded
Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs
“The Fairwind Program gives high-priority defenders (like governments, healthcare providers, and telecommunications services) early access to advanced models that help them
Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure
The vulnerability in question is CVE-2026-82329 (CVSS score: 9.8), a case of authentication bypass that could lead to administrative access in Artifactory.
“JFrog Artifactory contains an authentication weakness that, under default
OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face
The incident, the company said, took place during cybersecurity evaluations of several OpenAI models, and that it was mainly fueled by what it described as a “highly capable
U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches
“We are launching an economic onslaught against Iran’s financial connections around the globe. Our objective is to sever every economic lifeline that sustains this tyrannical regime
Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
The vulnerability in question is CVE-2026-55040 (CVSS score: 9.1), which refers to a critical security feature bypass that stems from weak authentication. It was patched by Microsoft as part of its July 2026 Patch Tuesday updates.
“The authentication
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
The activity, per Check Point Research, is part of Operation Dream Job, a long-running cyber espionage and
Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
“Greatness supports AiTM [adversary-in-the-middle] credential and
