ZeroHour
Organization

Check Point

4 mentions in 7 days · 9 in 30 days · 12 total · first seen · last

Timeline

12 Best Endpoint Encryption Software Compared (2026): Features & Pricing

2026 buying guide compares 12 endpoint encryption tools, framing paid products as management layers over free BitLocker and VeraCrypt engines.

An editorial comparison evaluates twelve endpoint encryption offerings, arguing that full-disk encryption itself is largely solved with free options like Microsoft BitLocker and open-source VeraCrypt. Paid products such as Sophos Central Device Encryption, Broadcom Symantec Endpoint Encryption, and Check Point Full Disk Encryption are positioned around management: central enforcement, recovery-key escrow, pre-boot authentication, and compliance evidence. The guide also warns against unmaintained tools like Rohos for business use and stresses operational concerns over cipher selection.

GBHackers · 4d agoIndustry 4 sources

New AI Attack Hides Malicious Instructions in Normal-Looking Text to Evade Safety Filters

Check Point researchers show crafted prose hides policy-violating instructions that bypass all tested LLM gatekeepers, including GPT-4o mini and Llama Guard 3.

A new prompt-crafting technique embeds malicious payloads inside grammatical, natural-looking text without Base64, invisible Unicode, or obvious encodings, defeating lightweight pre-screening gatekeepers. In testing, all four evaluated gatekeeper models—gpt-4o-mini-2024-07-18, gpt-oss-safeguard:20b, claude-3-haiku-20240307, and llama-guard3:8b—classified the crafted wrappers as safe at a 100% bypass rate across 23 obfuscated prompts. GPT-5 Thinking in high-reasoning mode recovered and acted on the hidden instruction in 17 of 18 tests (~94.4%), often spending over a minute and multiple Python executions. Researchers recommend paraphrasing untrusted input, hardening gatekeeper policies, and applying defense-in-depth controls for agentic deployments.

GBHackers · 4d agoAI safety & security 2 sources

Critical Check Point VPN Vulnerabilities Enable Remote Code Execution Attacks

Check Point patched two critical VPN flaws, CVE-2026-85102 and CVE-2026-85103 (CVSS 9.8), allowing unauthenticated RCE on Security Gateways.

Check Point disclosed and patched two critical VPN vulnerabilities, CVE-2026-85102 (improper certificate trust validation, CWE-295) and CVE-2026-85103 (heap-based buffer overflow in ASN.1 certificate parsing, CWE-122), both rated CVSS 9.8 and exploitable for unauthenticated remote code execution under specific conditions. The flaws affect Security Gateway, Security Management Server, and Spark Firewall deployments on R81.20, R82, and R82.10 branches plus end-of-support versions such as R80.40 and R81, while R82.20 is not affected. Check Point reports no evidence of active exploitation or public PoC; Live Patch rollout began September 9, 2026, and administrators without it must install Jumbo Hotfix Accumulator builds (R82.10 Take 44+, R82 Take 126+, R81.20 Take 166+). For Site-to-Site VPN, restricting UDP ports 500 and 4500 to known peers serves as an interim workaround, but no mitigation exists for Remote Access VPN or Spark Firewalls.

Cyber Security Newsupdated · 1d agofirst · 5d agoVulnerability 9 sourcesCVE-2026-85102CVE-2026-85103CVE-2026-50751

Veradigm warns of patient data breach after ransomware gang claims attack

Healthcare vendor Veradigm disclosed a patient data breach via a third-party vendor's credentials, which the Gentlemen ransomware gang claims involved 3.5 million records.

Veradigm, formerly Allscripts, told the SEC that an attacker used compromised credentials from a third-party vendor to access a customer-service API and copy patient data, including personal details and Social Security numbers, without touching clinical data or the broader network. The Gentlemen ransomware group listed Veradigm on its leak site claiming 3.5 million patient records and threatened to publish the data by September 11 unless ransom negotiations start. The gang, active since mid-2025, runs double extortion across Windows, Linux, NAS, BSD and ESXi, lists 800+ victims in 86 countries, and has been linked to a SystemBC proxy botnet and the GentleKiller EDR killer. Veradigm is notifying affected individuals, offering credit monitoring, and says it does not expect a material business impact.

BleepingComputerupdated · 5d agofirst · 6d agoData breach 4 sources

JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies

Check Point details JSCeal, a V8-compiled JavaScript stealer that replays stolen cookies to bypass Google authentication, spread via crypto malvertising.

Check Point Research's new report analyzes JSCeal, a compiled V8 JavaScript malware obfuscated with javascript-obfuscator using RC4-protected strings, control-flow flattening, and proxy functions. Delivered through fake TradingView installers on malvertising sites overlapping the WEEVILPROXY/MeadowLocust and SourTrade campaigns, it harvests cookies, passwords and OAuth tokens from Chromium browsers, records keystrokes and screenshots, and can replay stolen Google session cookies to bypass authentication. It also installs a local proxy with service-specific handlers for Binance, Bybit, and Ledger to intercept and modify cryptocurrency-related traffic.

The Hacker News · 8d agoMalware in the wild1

24th August – Threat Intelligence Report

Latvia's Road Traffic Safety Directorate (CSDD) confirmed a breach exposing payment records of 1.2 million people and 200,000 organizations.

Latvia's Road Traffic Safety Directorate (CSDD) has confirmed a data breach affecting payment records of more than 1.2 million people, roughly two-thirds of the country's population, as well as 200,000 organizations. The disclosure was highlighted in Check Point Research's weekly threat intelligence bulletin for the week of August 24, 2026. The scale of exposure makes this one of the largest confirmed breaches reported in Latvia.

Check Point Research · 22d agoData breach

TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore

Head Mare exploits TrueConf server flaws to install web shells and deliver PhantomCore and PhantomGraph backdoors at Russian organizations.

Kaspersky detected July 2026 attacks by the threat actor Head Mare exploiting a vulnerability chain (KLCERT-26-057 and KLCERT-26-058) in unpatched TrueConf videoconferencing servers. The chain enables arbitrary code execution with SYSTEM privileges, deployment of a web shell at locale.php, and replacement of client installers with versions delivering the PhantomCore backdoor and PhantomGraph, which uses Microsoft OneDrive as C2. Targets span Russian instrumentation, electronics, transport, energy, IT, and software firms. Patches shipped in TrueConf Server 5.3.9, 5.4.9, and 5.5.5 on June 18, 2026.

The Hacker News · 25d agoThreat actor in the wild1

StopAndProtect Turns 2,000 Hacked WordPress Sites Into a Criminal Network

Check Point uncovered StopAndProtect, a cybercrime operation using ~2,000 hacked WordPress sites for ClickFix-driven malware delivery, data theft, surveillance, and ransomware.

Check Point Research identified the StopAndProtect operation in May 2026; it abuses close to 2,000 compromised WordPress sites, many running outdated software, to host malware stages, act as C2, and store stolen data. Infection starts with fake CAPTCHA ClickFix prompts that trick visitors into running a PowerShell command, followed by .NET downloaders deploying ransomware, SMB/USB worm, lockscreen, chat, and credential-stealing components. Rather than always encrypting, operators selectively exfiltrate file lists and specific files; researchers found 700+ stolen-data archives, roughly 31,000 screenshots, and 6,000+ unique victim IP addresses, including WhatsApp activity monitoring.

Security Affairs · 26d agoThreat actor in the wild

StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data

Check Point details StopAndProtect: ~2,000 compromised WordPress sites deliver ClickFix fake-CAPTCHA malware toolkit combining ransomware, credential theft, screenshots, and WhatsApp surveillance.

Check Point researcher Jaromír Hořejší reports the campaign begins with ClickFix fake-CAPTCHA prompts that trigger a PowerShell command, then two .NET downloader stages that launch six components: SilentEncryptor, NetworkShareScanner, a VBS spreader, LockScreen, SimpleChatProxy, and SilentDataCollector. Hacked WordPress sites host malware stages, serve C2 commands, and receive exfiltrated logs; the actors installed a self-deleting WordPress plugin enabling arbitrary PHP upload anywhere under the WordPress root. From mid-May to late July 2026 the operators exfiltrated more than 700 archives including screenshots every 30 seconds, keylogger output, and WhatsApp contact data, and opsec failures exposed their Visual Basic automation tooling and lists of nearly 2,000 compromised domains.

The Hacker News · 26d agoThreat actor in the wild

China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud

China-linked Jewelbug runs government espionage and crypto fraud from a single XG-Web browser-based control framework.

Broadcom's Symantec and Carbon Black detail Jewelbug, a China-based hackers-for-hire group conducting espionage against governments and militaries in the Middle East, Southeast Asia, and South Asia, plus crypto fraud against Chinese-speaking victims. Operations center on XG-Web, a browser-centric remote-access and infostealing framework, with implants spanning browsers, Windows, Linux, and network devices. The group overlaps with CL-STA-0049, Ink Dragon, Earth Alux, and REF7707, and compromised a Middle Eastern government's webmail across 15 tenants.

The Hacker News · Aug 15, 2026Threat actor in the wild

Lazarus hackers pair fake job offers with Windows zero-day exploit

Lazarus' Operation Dream Job targets the defense sector with fake job offers, a Windows LPE zero-day (CVE-2026-68820), and new Troy and RelayShell backdoors.

Check Point documented two parallel infection chains in Lazarus' Operation Dream Job: a digitally signed PDF viewer with DLL sideloading delivering the MISTPEN in-memory downloader, and a trojanized SecurityPDF viewer, distributed via fake Enveil websites, installing the newly documented Troy backdoor. A component exploits CVE-2026-68820, a local privilege escalation zero-day in the Windows AFD.sys driver used since at least early July, which Microsoft patched on August 11, 2026, enabling deployment of the FudModule kernel-mode rootkit. Lazarus also compromised Roundcube webmail servers vulnerable to CVE-2025-49113 to deploy the RelayShell PHP web shell and relay C2 traffic, targeting defense-sector organizations primarily in Western Europe and India. Separately, CERT-UA documented Sandworm's UAC-0145 using fake job offers against IT professionals since May 2026.

Help Net Security · Aug 12, 2026Threat actor in the wildCVE-2026-68820CVE-2025-49113

Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820)

Microsoft's August 2026 Patch Tuesday fixes 400+ vulnerabilities, including an actively exploited Windows zero-day (CVE-2026-68820) used by North Korean attackers.

Microsoft's August 2026 Patch Tuesday fixes over 400 vulnerabilities, including CVE-2026-68820, a use-after-free in the Windows Ancillary Function Driver exploited in the wild by North Korean actors deploying a kernel-mode rootkit in Operation Dream Job. Critical unauthenticated remote code execution flaws in Microsoft QUIC (CVE-2026-62815) and Windows DNS (CVE-2026-62878) were also patched, alongside a SharePoint RCE chain combining CVE-2026-63520 with CVE-2026-55040. Researcher Nightmare-Eclipse released ShieldBreak, a PoC bypassing the July RoguePlanet Microsoft Defender patch (CVE-2026-50656), confirmed working by Will Dormann on Windows 11.

Help Net Security · Aug 12, 2026Exploit / PoC in the wildCVE-2026-68820CVE-2026-62832CVE-2026-72971+6 CVEs

Related CVEs

  • Use-After-Free Local Privilege Escalation in Microsoft Windows WinSock AFD Driver
    CVE-2026-68820 is a use-after-free (CWE-416) in the Windows Ancillary Function Driver for WinSock (afd.sys), the kernel component that handles Winsock socket operations. A local, authenticated attacker can trigger the memory corruption through crafted socket activity, and the high attack-complexity score (AV:L/AC:H/PR:L) indicates exploitation requires a specific, likely race-sensitive sequence of operations. Successful exploitation elevates privileges to SYSTEM, giving the attacker full control of the host, and public reporting describes deployment of a backdoor after privilege escalation. Virtually every Windows 10, Windows 11, and Windows Server (2012-2022) installation ships this driver, so the affected population is essentially the entire supported Windows installed base. The flaw is being exploited in the wild: CISA added it to the KEV on 2026-08-11, Microsoft fixed it in the August 2026 Patch Tuesday release, and reporting ties active exploitation to North Korea's Lazarus group, who paired the zero-day with fake job-offer lures.
    · Microsoft Windows Ancillary Function Driver for WinSock (afd.sys) as shipped with the Windows versions listed below · Microsoft Windows 10 1607, 1809, 21H2, 22H2 KEVmass
  • Unauthenticated IKEv1 VPN Auth Bypass in Check Point Security Gateways
    Check Point has disclosed CVE-2026-50751, a critical (CVSS 9.3) improper authentication flaw (CWE-287) in the certificate validation logic for Remote Access and Mobile Access VPN when the deprecated IKEv1 key exchange is used. An unauthenticated remote attacker can exploit this logic flow weakness during IKEv1 negotiation to bypass user authentication entirely. Successful exploitation lets the attacker establish a remote access VPN connection without a valid user password, gaining access to the organization's internal network resources (high confidentiality impact per the CVSS score). Any organization running a Check Point Security Gateway on Gaia OS or Gaia Embedded with IKEv1-based Remote Access/Mobile Access configured is affected; specific affected and fixed versions are in Check Point's advisory. The flaw is being exploited in the wild — it was added to CISA's Known Exploited Vulnerabilities catalog on 2026-06-08 with known ransomware use and an EPSS of 83.8% — and it was disclosed alongside other critical Check Point VPN certificate flaws per recent headlines.
    · Check Point Security Gateway (Gaia OS) · Check Point Security Gateway (Gaia Embedded) KEV ransomware PoC mass
  • Authentication Bypass in Microsoft SharePoint Server
    Microsoft SharePoint Server is affected by a weak authentication vulnerability (CWE-1390) that allows an unauthorized attacker to bypass a security feature over a network. Per the CVSS vector, exploitation requires no privileges and no user interaction with low attack complexity, so any unauthenticated attacker with network access to a vulnerable server can trigger it remotely. Impact to confidentiality and integrity is rated high (CVSS 9.1, critical), meaning the bypass effectively grants the attacker access that authentication should have prevented, with no direct availability impact. All organizations running on-premises Microsoft SharePoint Server are potentially affected; the source data does not specify affected version ranges or fixed builds, so defenders should consult Microsoft's advisory for those details. The flaw is under active exploitation: a public proof-of-concept is available on GitHub, attackers began exploiting it after the PoC went public, and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-08-18 (EPSS ~40%, 99th percentile; ransomware association unknown).
    · Microsoft SharePoint Server KEV PoC ×2mass
  • Authenticated PHP Object Deserialization RCE in Roundcube Webmail
    Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 contains a PHP object deserialization flaw (CWE-502) that allows remote code execution by authenticated users. The bug is in program/actions/settings/upload.php, where the _from URL parameter is not validated before deserialization, so any logged-in user can trigger it with a crafted URL to the settings upload action, with no user interaction required. Successful exploitation gives the attacker code execution on the web server with high confidentiality, integrity, and availability impact (CVSS 3.1 8.8). All deployments running affected versions are exposed, including Roundcube packages shipped with Debian Linux. The flaw reportedly existed for roughly a decade before disclosure, carries a 98.9% EPSS score (top percentile), and was added to CISA's KEV catalog on 2026-02-20, confirming exploitation in the wild.
    · Roundcube Webmail all versions before 1.5.10, and 1.6.x before 1.6.11 · Debian Linux (Roundcube Webmail package) Debian releases shipping affected Roundcube versions; fixes delivered via Debian security updates KEV PoC ×2mass
  • Use-after-free RCE in Microsoft MsQuic via crafted network packets
    A use-after-free (CWE-416) in Microsoft's QUIC implementation (MsQuic) allows an unauthenticated remote attacker to execute code on an affected host. The flaw arises because creating and removing new network paths in response to incoming packets can invalidate a pointer that is subsequently used. An attacker needs only to send a specially crafted packet to a service speaking QUIC, with no authentication or user interaction required; the maximum CVSS 4.0 score of 10 (critical) reflects full system-compromise potential. Any deployment of the MsQuic library is affected, including services built on Microsoft's in-box QUIC support (e.g., HTTP/3 and SMB over QUIC) and applications consuming the public NuGet package, though exact affected version ranges are not specified in the available data. Exploitation has not been observed: there is no public proof-of-concept, the issue is not in CISA's KEV, and EPSS puts the 30-day exploitation probability at about 1 percent, but a fix ('Guard path promotion', commit e0f55b5) is already available.
    · Microsoft MsQuic (Microsoft QUIC library; distributed via NuGet) · Microsoft Services and applications using MsQuic (e.g., HTTP/3, SMB over QUIC, .NET System.Net.Quic)mass
  • Unauthenticated Stack Buffer Overflow RCE in Windows DNS (CVE-2026-62878)
    Windows DNS contains a stack-based buffer overflow (CWE-121) that an unauthenticated, network-adjacent or internet-reachable attacker can trigger by sending crafted input to the DNS service. Successful exploitation yields remote code execution on the target host, with high impact on confidentiality, integrity and availability (CVSS 3.1: 9.8). The flaw affects the DNS component shipped with Windows 10 1607 and 1809 and with Windows Server 2012, 2016, 2019, 2022 and 2025; systems running the DNS Server role, especially internet-facing DNS servers and domain controllers, are the primary targets. Microsoft, which assigned the CVE, has issued a fix, and the flaw appeared amid a record-sized run of Patch Tuesday releases. No in-the-wild exploitation is currently known: it is not in CISA's KEV, no public proof-of-concept is available, and EPSS estimates only a 1.3% probability of exploitation within 30 days.
    · microsoft Windows 10 1607 · microsoft Windows 10 1809mass
  • Unauthenticated RCE in Microsoft SharePoint Server
    CVE-2026-63520 is an improper input validation flaw (CWE-20) in Microsoft Office SharePoint, affecting on-premises SharePoint Server deployments. A remote, unauthenticated attacker can trigger the flaw by sending improperly validated input to the SharePoint service over the network; the high attack complexity (AC:H) indicates exploitation depends on specific conditions, but no privileges or user interaction are required. Successful exploitation results in arbitrary code execution on the server, with high impact to confidentiality, integrity, and availability — effectively full compromise of the SharePoint host. Organizations running self-hosted SharePoint Server are in scope; SharePoint Online/Microsoft 365 is not listed in the affected products. The issue is patched as of Microsoft's Patch Tuesday (headlines mark it FIXED), with Rapid7 analysis and a researcher-disclosed exploit chain available, but there is no public PoC, no CISA KEV listing, and no confirmed in-the-wild exploitation; EPSS puts exploitation probability at 2.9% (86th percentile).
    · Microsoft SharePoint Server (Office SharePoint, on-premises)mass
  • Local Privilege Escalation via Link Following in Windows User Profile Service
    CVE-2026-62832 is a local privilege escalation flaw (CWE-59, improper link resolution, or 'link following') in the Windows User Profile Service. An attacker who already holds a limited local account on an affected machine can cause the service to follow a symbolic link or junction before it validates file access, so the service performs file operations with elevated rights. Successful exploitation grants elevated privileges on the local system — typically up to administrator/SYSTEM level — with no user interaction required. Affected platforms include Windows 10 21H2 and 22H2, Windows 11 23H2 through 26H1, and Windows Server 2022 and 2025, which together span essentially the entire supported Windows estate. As of this analysis there is no public proof-of-concept, no CISA KEV listing, and no confirmed in-the-wild exploitation of this specific flaw; EPSS estimates a 3.3% (88th percentile) chance of exploitation within 30 days, although Microsoft's August 2026 Patch Tuesday fixed 400+ vulnerabilities and a separate zero-day (CVE-2026-68820) is under active attack.
    · microsoft Windows 10 21H2 · microsoft Windows 10 22H2mass
  • Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ".
    Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ".
    · microsoft malware protection engine PoC
  • Local Tampering via Link-Following Flaw in Windows 11 26H1 Container Isolation Driver
    CVE-2026-72971 is a link-following flaw (CWE-59) in the Windows Container Isolation FS Filter Driver (unionfs.sys) on Windows 11 26H1: the driver performs file access without fully verifying that the path is not redirected through a symbolic link or junction. A local attacker who already holds low-privilege access (CVSS AV:L/PR:L, no user interaction required) can plant a malicious link at a location the driver processes, causing it to follow the link and act on an attacker-chosen target. The attacker gains tampering capability, which the CVSS scores as High integrity impact with no confidentiality or availability impact, meaning they can modify or overwrite files their account could not normally change. Any Windows 11 26H1 system is in scope per the CVE data, with the highest practical risk on shared or multi-user hosts and machines using container isolation features where unionfs.sys is active. No active exploitation is known: the CVE is not in CISA KEV, no public proof-of-concept exists, and EPSS puts 30-day exploitation probability at about 0.5%; the related news shows Microsoft's August 2026 Patch Tuesday shipped 400+ fixes, and defenders should confirm their devices received the unionfs.sys patch.
    · microsoft Windows 11 26H1 (Container Isolation FS Filter Driver, unionfs.sys)mass

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.