organization · 5 records
Check Point

Apache Syncope vulnerability enables arbitrary SQL command execution
Rapid7 released a public proof-of-concept script for a critical authentication bypass vulnerability in Check Point SmartConsole that allows unauthenticated attackers to gain administrative privileges.

Linux kernel update addresses vulnerability in action lifecycle management
CVE-2026-53264 disclosed: In the Linux kernel, the following vulnerability has been resolved: net/sched: act_api: use RCU with deferred freeing for action lifecycle When NEWTFILTER and DELFILTER are run concurrently it is po

OpenWrt releases security patches to address critical DHCPv6 vulnerabilities
OpenWrt released version 24.10.8 and 25.12.5 to patch a critical DHCPv6 stack overflow flaw allowing arbitrary code execution as root, alongside other network service vulnerabilities.

Check Point releases security updates for critical vulnerabilities in management products
Check Point has released security updates to address multiple high-severity vulnerabilities in its management and SmartConsole products, including a flaw under active exploitation added to the CISA KEV catalog.

Researchers identify new malware using Microsoft 365 calendar for covert communications
Group-IB researchers identified a new HollowGraph malware module that abuses Microsoft 365 calendar features as a covert command-and-control channel, likely linked to an Iranian threat actor targeting Israeli organizations.