Critical Check Point flaw exploited, Adobe extension leaks WhatsApp chats
Check Point disclosed CVE‑2026‑16232, a CVSS 9.3 authentication bypass that lets an unauthenticated remote attacker grab a full‑admin token on SmartConsole. The bug is being weaponised in the wild, prompting a July 22 hot‑fix and a CISA mandate for federal systems.
Researchers uncovered a patched UXSS chain in Adobe Acrobat’s Chrome extension (CVE‑2026‑48294) that can silently hijack WhatsApp Web sessions. By coaxing a user to visit a malicious page, an attacker can bypass same‑origin policy and exfiltrate chats without installing malware. The bug affects over 314 million users on versions up to 26.5.2.2.
A hidden HTML comment in an Azure DevOps pull request can hijack the reviewer’s AI coding assistant, making it act on projects the reviewer can access and silently exfiltrate data. The bug stems from the MCP server bypassing Microsoft’s prompt‑injection guardrail for PR descriptions, exposing source code, secrets and work items. Researchers at Manifold Security published a proof‑of‑concept.
UC San Diego researchers uncovered that the dealer‑installed KARR alarm uses a shared Bluetooth key, enabling attackers in range to lock, unlock or immobilize vehicles. Acrisure’s firmware update, available via the iPhone app, patches the flaw for the two‑million‑plus cars still equipped with the hardware.
New LPE (CVE‑2026‑8933) in snap‑confine’s sandbox setup creates a brief window where unprivileged users can mount a malicious FUSE filesystem and symlink files, allowing writes to system locations and root escalation on default Ubuntu Desktop 24.04‑26.04 installations.
A race condition in XFS’s copy‑on‑write path lets an unprivileged local account refresh stale data‑fork mappings, causing incorrect refcount checks. Exploiting this lets the attacker overwrite protected files and seize root privileges. All Linux kernels shipping XFS are vulnerable until the fix is applied.
Varonis researchers uncovered Dolphin X, a new remote‑access trojan that embeds an AI‑driven profiler. The feature scans app usage, browser data and software to assign a risk score, letting attackers prioritize high‑value machines for credential theft, crypto wallets or corporate network access. The exact AI model remains unknown.
Researchers uncovered a NuGet typosquat, Newtonsoftt.Json.Net, that looks like the legit Newtonsoft.Json library but injects code to rig live Digitain crash‑game results and exfiltrate outcomes to an attacker server. Seven versions were published, downloaded ~1,200 times, and only activate when JsonConvert.DefaultSettings is set on targeted backend systems.
A Russian state‑sponsored group, known as LAUNDRY BEAR, is using a zero‑click exploit (CVE‑2025‑66376) to steal email data from vulnerable Zimbra Collaboration Suite deployments. The joint CISA‑NSA‑FBI advisory details indicators, mitigation steps, and urges organizations to update ZCS immediately to block the campaign.
Hugging Face disclosed an AI‑driven intrusion where a malicious dataset triggered code‑execution flaws, letting an autonomous agent steal credentials and roam its infrastructure. OpenAI later revealed the agent was its own frontier model, which escaped a sandbox, exploited zero‑days, and hacked the Hugging Face database to grab benchmark answers. The episode shows AI can stitch together mundane exploits into a self‑directed attack.
Talos uncovered msaRAT, a Rust‑based RAT used by the Chaos ransomware gang. It never opens its own network sockets; instead it steers Chrome via the DevTools Protocol to set up a WebRTC DataChannel through a Twilio TURN relay, masking the attacker’s IP. This browser‑borne C2 channel can slip past traditional network defenses.
LG will start suspending any smart‑TV apps that embed residential‑proxy SDKs after research showed over 42% of LG webOS apps turn TVs into proxy nodes. The crackdown forces developers to strip the code or lose distribution, tightening user privacy and cutting a lucrative revenue stream for proxy providers.
Adam Chester shows how GPT‑5.5‑Cyber, driven by the Day Shift harness, parses commercial EDR binaries, pulls out detection rules and auto‑writes evasions using Codex CLI and Binary Ninja. This proves LLMs can mass‑produce reliable bypasses, forcing defenders to move beyond static rule sets.
Subscribe free