ZDI-26-564: NVIDIA Transformers4Rec load_model_trainer_states_from_checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability
ZDI discloses CVE-2026-24232, a CVSS 7.8 deserialization RCE in NVIDIA Transformers4Rec's load_model_trainer_states_from_checkpoint function.
The Zero Day Initiative published ZDI-26-564, a deserialization of untrusted data vulnerability in NVIDIA Transformers4Rec. Remote code execution is possible, but exploitation requires user interaction such as visiting a malicious page or opening a malicious file. The flaw is tracked as CVE-2026-24232 with a CVSS score of 7.8.
CVE-2026-16232: Checkpoint Quantum Security Management auth bypass ...
Attackers exploit Check Point SmartConsole authentication bypass CVE-2026-16232 to take over Quantum Security Management firewall servers; CISA added it to KEV.
CVE-2026-16232 is an authentication bypass (CWE-287) in the SmartConsole login process of Check Point Quantum Security Management, exploitable via an application token. Disclosed July 22, 2026, it was added to CISA's Known Exploited Vulnerabilities catalog the same day with remediation due July 25. Rapid7, Check Point Research and other vendors confirmed exploitation in the wild, and a public PoC was released. A workaround is available, and federal agencies must comply with BOD 26-04 patching guidance.
Ransomware group hijacks hospital system’s Facebook page amid ongoing cyberattack fallout
'The Gentlemen' ransomware group hijacked AnMed's Facebook page, claiming theft of 6TB of sensitive patient data during an ongoing cyberattack on the hospital system.
AnMed, a nonprofit medical system with four hospitals in Georgia and South Carolina, is still responding to a July 26 cyberattack involving malware, with 10 facilities remaining closed as of Monday. On Tuesday its Facebook page displayed unauthorized posts claiming 'The Gentlemen' ransomware group exfiltrated 6 terabytes of data, including records on sexual assault, mental health, abortions and harassment; AnMed said the claims are unverified and patient data impact has not been confirmed. The Gentlemen, believed founded by a former Qilin affiliate using the moniker 'hastalamuerte,' extorted 332 victims in the first five months of 2026 per CheckPoint and claimed 125 industrial attacks in Q2 2026 per Dragos. The group typically breaches networks through edge devices, credential brute-forcing and known vulnerabilities, and offers affiliates tools to disable EDR.