Seite wählen

24.07.2026

Check Point hole grants unauthenticated attackers full SmartConsole admin privileges

CSO Online 23.07.2026 20:14
Check Point has confirmed that a critical security hole in its SmartConsole management tool, one that allows unauthenticated attackers to assume full admin privileges, is now being exploited in the wild. The vulnerability, CVE-2026-16232, was given a CVSS score of 9.3.
In its security alert, Check Point described the bug as one allowing an unauthenticated attacker to “obtain an application login token and use it to login via SmartConsole with full admin privileges and apply changes to the security policy and security configuration.”

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

The Hacker News 23.07.2026 18:36
A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra's webmail client.

The payload goes after the last 90 days of email, the organization's entire email directory, the password saved in the browser and the codes kept for two-factor recovery. Opening the message was enough to start it.

The NSA, CISA and partner agencies published

Linux XFS has a decade-old race condition allowing full root access

CSO Online 23.07.2026 15:45
Linux systems using the XFS filesystem suffer from a race condition that could enable an unprivileged local user to gain full root access.
The flaw affects systems with Linux kernel 4.11 or later that have enabled the XFS feature reflink, which permits the creation of copies of a file without actually copying its data.

Atlassian: Bamboo und Bitbucket für Schadcode-Attacken anfällig

Heise Security 23.07.2026 09:43
Wichtige Sicherheitsupdates schließen mehrere Schwachstellen in verschiedenen Anwendungen von Atlassian.

Über Add-on von Adobe: Forscher zeigen Whatsapp-Datenklau mit nur einem Klick

Golem 23.07.2026 09:24
Über 300 Millionen Nutzer vertrauen einer Chrome-Erweiterung von Adobe. Angreifer konnten darüber jedoch leicht Whatsapp-Chats ausleiten. (Sicherheitslücke, Browser)

Microsoft SharePoint: Angriffe auf weitere Sicherheitslücke

Heise Security 23.07.2026 07:13
Weitere Sicherheitslücken in SharePoint stehen unter Beschuss. Auch Check Point SmartConsole wird derzeit attackiert.

Cyberattacken auf Landesverwaltung nehmen weiter zu

Heise Security 23.07.2026 04:45
Cyberangriffe nehmen in Sachsen-Anhalt deutlich zu: Im ersten Halbjahr meldet die Landesverwaltung mehr als doppelt so viele Vorfälle wie zuvor.