Check Point VPN Flaws Let Remote Attackers Run Code on Gateways and Servers
Two certificate-processing flaws reach gateways and management servers. Fixed takes and LivePatch output give operators a direct protection check.
Read article →Reader view
Choose the default article length.
Network activity, protocols, infrastructure, and detection.
Two certificate-processing flaws reach gateways and management servers. Fixed takes and LivePatch output give operators a direct protection check.
Read article →Attackers used Cisco Secure FMC flaws to reach root, steal credentials, tunnel into networks, deploy Cyclops Blink, and encrypt selected endpoints with Qilin.
Read article →CISA confirmed exploitation of CVE-2025-25249 across FortiOS, FortiSwitchManager and FortiSASE, with federal remediation due September 12.
Read article →CISA now links CVE-2025-14733 to ransomware. Patch exposed Fireboxes, check WatchGuard's indicators, and rotate locally stored secrets after confirmed activity.
Read article →Customer-managed VPN and AAA appliances need branch-specific fixed builds; configuration determines exposure on later NetScaler releases.
Read article →Every on-premises build before 2026.3.1.14 needs Hotfix 4. N-able's records conflict on exploitation, so MSPs should patch and review RMM activity.
Read article →Forescout ported a pre-auth PLC exploit with Claude, then bricked the device during an implant attempt. Restrict FTP and monitor crashes and outbound traffic.
Read article →Two factory firmware implants expose white-label ZBT routers through an open WAN service and an unauthenticated phone-home channel.
Read article →CERT Polska confirms attacks through internet-exposed SSH. Install a fixed build, restrict management access, and investigate the published log and account indicators.
Read article →D-Link fixed a DIR-X1860Z flaw that lets a local-network user set a new admin password; the similar DIR-X1860 has no update path.
Read article →SonicWall confirmed active attacks against two SMA1000 flaws and told customers to hotfix, seek an IoC review, and rebuild systems when compromise is found.
Read article →Fire Ant hid tunnels on Cisco routers, injected TACACS servers, and planted Linux backdoors. Sygnia's artifacts support checks of routers, authentication servers, and Linux hosts.
Read article →PaperCut confirms active exploitation of NG and MF servers. Release 3 patches the two-flaw chain; new log and service indicators help defenders investigate exposed hosts.
Read article →