🚨 ACTIVE EXPLOITATION
- Check Point patches SmartConsole zero-day CVE-2026-16232 exploited in attacks — BleepingComputer
Check Point patched an authentication bypass zero-day in SmartConsole actively exploited in the wild.- Applies to Check Point Security Management and Multi-Domain Management products
- CVE-2026-16232 allows unauthenticated attackers to obtain admin login tokens
- Attackers can remotely access Management Server if exposed to the Internet without IP restrictions
- Exploitation enables modification of security policies and configurations via SmartConsole GUI
- CISA added CVE-2026-16232 to Known Exploited Vulnerabilities catalog, requiring urgent patching
💥 BREACHES & INCIDENTS
- StickerHub suffers security compromise, details remain scarce — cyberplace.social
StickerHub has been compromised.- Applies to StickerHub platform and its users
- Security breach confirmed without disclosed CVE identifiers
- No detailed information on attack vector or impact available
🕵️ RESEARCH & DEEP DIVES
-
Chaos ransomware group uses msaRAT malware to route C2 traffic via Chrome and Edge browsers — BleepingComputer
Chaos ransomware group deploys msaRAT malware that routes C2 traffic through Chrome and Edge browsers.- Targets Windows environments via phishing and remote management software installation
- msaRAT is a Rust-based backdoor using Chrome DevTools Protocol to control headless Chrome or Edge
- Routes command-and-control traffic through browser using Cloudflare Workers and Twilio TURN servers
- Communication encrypted with WebRTC DTLS and ChaCha20-Poly1305 + ECDH keys
- Avoids direct network connections to C2 infrastructure, evading detection and tracing
-
Researchers find three actors probing CVE exploit paths weeks before public disclosure — honeylabs.net
Three distinct IP actors probed exact CVE exploit paths weeks before public advisories appeared.- Applies to internet-exposed services including cPanel WHM and LMDeploy vision module
- Probes targeted specific vulnerable endpoints matching CVE exploit signatures before public disclosure
- Detection based on analysis of 30 million honeypot probes with four strict filters to remove false positives
- Earliest confirmed probe was 18 days before CVE-2026-41940 advisory for cPanel authentication bypass
- Other early probes include 56 days before CVE-2026-33626 (server-side request forgery) and 57 days before CVE-2026-8181
🔓 CVEs & KEV
- 21 CVEs reported without scores this cycle.