Check Point Warns of SmartConsole Zero-Day Exploited in Attacks
Check Point patched CVE-2026-16232, an authentication bypass vulnerability in its SmartConsole GUI admin panel that allows unauthenticated attackers to obtain an application login token usable to authenticate with administrator privileges on a vulnerable Security Management Server. Successful exploitation requires the Management Server IP to be exposed to internet access with no restrictions on Trusted Clients, after which an attacker can modify security policies and configurations across the affected deployment; Check Point says the flaw has affected “a very small number of customers” so far. CISA is urging all organizations, not just federal agencies, to prioritize patching given the vendor’s history — this is the second Check Point authentication bypass exploited as a zero-day this year, following a June flaw the Qilin ransomware gang used to breach VPN gateways.
Hackers Were Inside South Korea’s Diplomat Training System for 9 Months
South Korea’s Ministry of Foreign Affairs disclosed that an unidentified attacker compromised the Korea National Diplomatic Academy’s online e-learning platform from April 2025 through February 2026, exploiting a previously unknown vulnerability to maintain persistent access for nearly ten months before another government authority detected abnormal activity. The stolen data includes IDs, names, email addresses, and encrypted passwords belonging to roughly 10,000 current and former ministry employees, diplomats, and officials stationed at overseas missions, though the ministry says more sensitive information like phone numbers, home addresses, and photographs was not affected. Some analysts have noted the intrusion technique resembles tactics associated with North Korean state-backed hacking groups, and the breach has renewed scrutiny of South Korea’s fragmented incident-response structure, since the compromised server had been excluded from the ministry’s regular security inspections despite sitting inside its own headquarters.
Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities
Google DeepMind released Gemini 3.5 Flash Cyber, a lightweight AI model built specifically to discover, validate, and patch software vulnerabilities at high speed and low cost, initially available only to governments and trusted partners through DeepMind’s CodeMender vulnerability-patching agent. In internal testing, the model found 55 confirmed V8 issues compared to 47 for mainline Gemini 3.5 Flash and 36 for Claude Opus 4.6, and Google’s Cloud Vulnerability Research team used it to find remote code execution flaws in public APIs and a memory-corruption bug in a sensitive production service within two hours. DeepMind says the restricted rollout reflects the “dual-use nature” of the technology — the same capability that lets defenders find and fix bugs faster could just as easily be misused for offense — and the limited-access model lets the company enable only defensive functions while disabling other capabilities that could be exploited if the model were more broadly available.
Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs
Qualys disclosed CVE-2026-8933, a high-severity local privilege escalation vulnerability in Ubuntu’s snap-confine sandbox component that lets an unprivileged local user gain full root access on default installations of Ubuntu Desktop 24.04, 25.10, and 26.04. The flaw stems from a well-intentioned security hardening change made in July 2025 that shifted snap-confine from a set-uid-root binary to a set-capabilities model, inadvertently introducing a narrow race-condition window during sandbox initialization that an attacker can exploit by mounting a FUSE filesystem over a temporary directory and using a symlink to write to arbitrary files. This is the second snap-confine privilege escalation flaw Qualys has found in the same component in four months, and while the bug requires local access to exploit, researchers note that stolen credentials or a separate initial-access vulnerability could easily provide that starting foothold — administrators should apply the patched snapd packages immediately.
OT Environments Ever More in Hacktivist Crosshairs
Hacktivist groups aligned with Russia and Iran are increasingly turning their attention to Western operational technology environments and industrial control systems, with threat intelligence firm Kela reporting that geopolitical tensions in Eastern Europe and the Middle East have “catalyzed a surge in hacktivist collectives acting as state proxies or independent ideologues” willing to target critical civilian infrastructure. Recent claimed activity includes a pro-Russia group asserting it gained control over HMI functionality at a Dutch energy management firm and hackers claiming access to Taiwanese infrastructure used for remotely reading smart meters at rental properties, though Kela notes most of these claims go independently unverified beyond screenshots or videos posted to Telegram. Dragos CEO Rob Lee has separately warned that many attacks on OT systems are being misidentified as ordinary IT incidents, complicating efforts to distinguish genuine infrastructure-targeting operations from financially motivated ransomware activity or hacktivist theater designed mainly to generate headlines and project power.