🚨 ACTIVE EXPLOITATION
- Zero-day vulnerability in Check Point SmartConsole actively exploited — Cybersecurity Dive
A zero-day flaw in Check Point SmartConsole is being actively exploited.- Applies to Check Point SmartConsole users managing security configurations
- Vulnerability allows attackers to bypass authentication controls
- Exploitation enables unauthorized changes to security settings
- Attackers leverage the flaw to gain elevated privileges within the console
🕵️ RESEARCH & DEEP DIVES
-
Default Azure Automation Setting Enables Cross-Tenant Identity Takeover — Dark Reading
A default Azure Automation configuration flaw allows cross-tenant identity takeover.- Affects Microsoft Azure Automation customers using default public settings
- Vulnerability allows attackers to seize identities across Azure tenants
- Attackers could access other tenants' data, credentials, and cloud workloads
- Exploit involves a chain of code flaws combined with public-by-default configuration
-
North Korean BlueNoroff uses Zoom, Teams phishing kit to profile crypto wallets before malware — The Hacker News
BlueNoroff operates a phishing kit impersonating Zoom and Teams to profile crypto wallets and deliver malware.- Targets cryptocurrency sector employees via typosquatted Zoom and Microsoft Teams domains
- Uses compromised trusted Telegram contacts to distribute phishing Calendly links
- Phishing pages request webcam access, stream video to operators, and fingerprint crypto wallets
- Delivers ClickFix malware payloads via fake Zoom SDK update messages on Windows and macOS
- Windows payload disables Defender, steals Telegram sessions, and probes browser wallet extensions
-
Certighost Exploit Lets Low-Privileged AD Users Impersonate Domain Controllers — The Hacker News
Researchers disclosed a Certighost exploit allowing low-privileged AD users to impersonate Domain Controllers.- Applies to Active Directory environments with Enterprise CA and default Machine certificate template
- Vulnerability in AD CS enrollment fallback (chase) lets low-privileged users obtain Domain Controller certificates
- Exploit abuses SMB and LDAP to relay CA authentication and sign DC identity into certificate
- Allows Kerberos PKINIT authentication as Domain Controller and DCSync attacks to retrieve krbtgt secret
- Affected versions include Windows Server 2012 through 2025 and Windows 10 versions 1607 and 1809
-
Microsoft Azure Kubernetes Service Elevation of Privilege VulnerabilityMissin...
CVE-2026-56163— CVE ThreatInt
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. -
Azure App Service on Azure Stack Hub Elevation of Privilege VulnerabilityImpr...
CVE-2026-58630— CVE ThreatInt
Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
🔓 CVEs & KEV
- Other: 18 CVEs (worst 6.5)