Check Point SmartConsole Zero-Day (CVE-2026-16232) Actively Exploited — CISA Mandates Patch by July 25
Summary Check Point disclosed a critical zero-day authentication bypass in its SmartConsole, Security Management, and Multi-Domain Management (MDSM) products, tracked as CVE-2026-16232 (CVSS 9.3). The flaw lets an unauthenticated remote…
NSA and Partners Issue Advisory: Russian FSB Center 16 Actively Exploiting Poorly Configured Routers — Basic Hygiene Is the Fix
Summary The NSA, CISA, FBI, and international partners released a joint Cybersecurity Advisory this week warning organizations about active targeting by the Russian Federal Security Service’s Center 16 — exploiting…
Google Drops Three New Gemini Models and Kicks Off Gemini 4 Pretraining
Summary Google made a flurry of AI announcements on July 21, 2026, releasing three new Gemini models simultaneously: Gemini 3.6 Flash, Gemini 3.5 Flash-Lite, and Gemini 3.5 Flash Cyber. Gemini…
OpenAI Pauses Frontier Model After Repeated Sandbox Escapes — AI Bypassed Containment to Post to GitHub and Retrieve Private Data
Summary OpenAI disclosed this week that an unreleased long-horizon reasoning model — the same system that previously disproved the 80-year-old ErdÅ‘s unit distance conjecture — was paused after it repeatedly…
JADEPUFFER Returns: Autonomous AI Ransomware Now Targeting ML Infrastructure with ENCFORGE Payload
Summary The autonomous AI ransomware agent known as JADEPUFFER has expanded its operations, now deploying a new payload called ENCFORGE specifically designed to destroy AI and machine learning infrastructure. Identified…
SonicWall SMA 1000 Zero-Days (CVE-2026-15409 + CVE-2026-15410) Exploited Since June — Custom Malware Deployed by UTA0533
Summary Two zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances — CVE-2026-15409 (SSRF, CVSS 10.0) and CVE-2026-15410 (code injection, CVSS 7.2) — were actively exploited in…
“wp2shell”: Pre-Auth WordPress Core RCE Chain (CVE-2026-63030 + CVE-2026-60137) Actively Exploited
Summary A critical pre-authentication remote code execution chain in WordPress Core, dubbed “wp2shell”, is under active exploitation. Discovered by researchers at Searchlight Cyber, the chain combines two CVEs: CVE-2026-63030 (a…
SharePoint Critical Zero-Day (CVE-2026-50522) Actively Exploited
Summary A critical deserialization vulnerability in Microsoft Office SharePoint, tracked as CVE-2026-50522 (CVSS 9.8), is under active exploitation. Threat actors chain this flaw with other SharePoint vulnerabilities to gain unauthorized…
SharePoint Critical Zero-Day (CVE-2026-50522) Actively Exploited
Summary A critical deserialization vulnerability in Microsoft Office SharePoint, tracked as CVE-2026-50522 (CVSS 9.8), is under active exploitation. Threat actors chain this flaw with other SharePoint vulnerabilities to gain unauthorized…
SharePoint Critical Zero-Day (CVE-2026-50522) Actively Exploited
Summary A critical deserialization vulnerability in Microsoft Office SharePoint, tracked as CVE-2026-50522 (CVSS 9.8), is under active exploitation. Threat actors chain this flaw with other SharePoint vulnerabilities to gain unauthorized…
