Critical Check Point Flaw Allows Root Privilege Code Execution
Check Point Software disclosed and patched a critical vulnerability enabling attackers to execute code as root on management systems, risking full enterprise system compromise.
Tag
11 results in the archive.
Check Point Software disclosed and patched a critical vulnerability enabling attackers to execute code as root on management systems, risking full enterprise system compromise.
An attacker used a MeshCentral backdoor to gain root access to internal systems at 3BB, a major Thai broadband provider, exposing subscriber credentials and internal tools.
A Russian-speaking threat actor used hundreds of AI agents to exploit vulnerabilities in PaperCut NG/MF servers, compromising 395 organizations worldwide and highlighting the operational risks of AI-driven cyberattacks.
Microsoft's September 2026 Patch Tuesday addresses 966 vulnerabilities including two actively exploited zero-day flaws.
PaperCut released a second emergency patch addressing two actively exploited vulnerabilities in its NG and MF print management software after initial mitigations were bypassed.
A critical zero-day vulnerability in all versions of PaperCut NG and MF print management software is actively exploited in attacks, affecting organizations using these products.
CVE-2026-54121 enables a standard domain user to escalate privileges by exploiting an Enterprise Certificate Authority to become a Domain Controller, exposing risks in PKI infrastructure trust models.
A threat actor is selling employee databases stolen from Microsoft Azure infrastructure of multiple Fortune 500 companies using compromised credentials, exposing sensitive account records and presenting an enterprise security risk.
A maximum-severity remote code execution vulnerability in SAP Commerce Cloud patched just three days ago is now actively exploited, posing a critical security risk.
Microsoft's August 2026 Patch Tuesday addresses 400 security flaws, including one actively exploited zero-day and two publicly disclosed zero-day vulnerabilities.
The ShinyHunters extortion gang claimed responsibility for a data breach at Ernst & Young obtained through a supply-chain attack involving stolen system credentials.