Overview
Description
Statistics
- 2 Posts
- 5 Interactions
Fediverse
Defend against the CVE-2026-51990 Sogou exploit. Discover how hackers use this one-click flaw to drop backdoors and how to secure your systems today.
#CVE202651990 #SogouInputMethod #CyberSecurity #UNC3569 #InfoSec #EndpointSecurity #ThreatIntel
Overview
- checkpoint
- Quantum Security Gateway
Description
Statistics
- 4 Posts
Fediverse
@cyberwald Bevor man hier einen Hersteller zu CVEs verurteilt, sollte man vielleicht tiefer recherchieren und dazu ein paar Fakten hinzufügen.
Beide Schwachstellen wurden intern entdeckt und bis zur Veröffentlichung gab es keine Hinweise darauf, dass sie in freier Wildbahn ausgenutzt wurden. Weiterhin gab es zu jedem CVE direkt entsprechende Anweisungen und Patches:
- CVE-2026-85102 - Authentication Bypass and Remote Code Execution in Remote Access and Site-to-Site VPN -> https://support.checkpoint.com/results/sk/sk1000117/
- CVE-2026-85103 - ASN.1 decoding heap overflow leading to a remote code execution -> https://support.checkpoint.com/results/sk/sk1000118/
Darüber hinaus gibt es mittlerweile die Funktion Check Point Live Patch (CPLP), welches ein im Betriebssystem Gaia enthaltener Dienst zur Bereitstellung von Abwehrmaßnahmen ist. Es schließt kritische Schwachstellen im laufenden Betrieb durch gezielte In-Memory-Korrekturen (Live-Patches). -> https://support.checkpoint.com/results/sk/sk185114
#CheckPoint #CheckpointsoftwareTechnologies
#CheckPointsw
#CVE #CVE202685102 #CVE202685103
Check Point patches two critical VPN gateway flaws scoring 9.8 on CVSS
Check Point patches two critical VPN vulnerabilities, CVE-2026-85102 and CVE-2026-85103, rated CVSS 9.8 and capable of unauthenticated remote code executionhttps://thecybersecguru.com/news/check-point-vpn-cve-2026-85102-cve-2026-85103/
📰 Check Point patches two critical 9.8 CVSS flaws in VPN products
Check Point patches two critical 9.8 CVSS vulnerabilities (CVE-2026-85102, CVE-2026-85103) in its VPN products. Flaws could allow unauthenticated RCE. Admins are urged to apply hotfixes immediately. #CyberSecurity #Vulnerability #VPN #PatchNow
⚠️ CRITICAL: Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent
Two critical remote code execution vulnerabilities in Check Point VPN (CVE-2026-85102 and CVE-2026-85103) are facing imminent exploitation. Any organization running affected Check Point VPN appliances is at immediate risk of full system compromise. Unpatched instances are likely to be targeted with…
🤖 AI generated summary
Overview
- irontec
- sngrep
Description
Statistics
- 2 Posts
Bluesky
Overview
- checkpoint
- Quantum Security Gateway
Description
Statistics
- 4 Posts
Fediverse
@cyberwald Bevor man hier einen Hersteller zu CVEs verurteilt, sollte man vielleicht tiefer recherchieren und dazu ein paar Fakten hinzufügen.
Beide Schwachstellen wurden intern entdeckt und bis zur Veröffentlichung gab es keine Hinweise darauf, dass sie in freier Wildbahn ausgenutzt wurden. Weiterhin gab es zu jedem CVE direkt entsprechende Anweisungen und Patches:
- CVE-2026-85102 - Authentication Bypass and Remote Code Execution in Remote Access and Site-to-Site VPN -> https://support.checkpoint.com/results/sk/sk1000117/
- CVE-2026-85103 - ASN.1 decoding heap overflow leading to a remote code execution -> https://support.checkpoint.com/results/sk/sk1000118/
Darüber hinaus gibt es mittlerweile die Funktion Check Point Live Patch (CPLP), welches ein im Betriebssystem Gaia enthaltener Dienst zur Bereitstellung von Abwehrmaßnahmen ist. Es schließt kritische Schwachstellen im laufenden Betrieb durch gezielte In-Memory-Korrekturen (Live-Patches). -> https://support.checkpoint.com/results/sk/sk185114
#CheckPoint #CheckpointsoftwareTechnologies
#CheckPointsw
#CVE #CVE202685102 #CVE202685103
Check Point patches two critical VPN gateway flaws scoring 9.8 on CVSS
Check Point patches two critical VPN vulnerabilities, CVE-2026-85102 and CVE-2026-85103, rated CVSS 9.8 and capable of unauthenticated remote code executionhttps://thecybersecguru.com/news/check-point-vpn-cve-2026-85102-cve-2026-85103/
📰 Check Point patches two critical 9.8 CVSS flaws in VPN products
Check Point patches two critical 9.8 CVSS vulnerabilities (CVE-2026-85102, CVE-2026-85103) in its VPN products. Flaws could allow unauthenticated RCE. Admins are urged to apply hotfixes immediately. #CyberSecurity #Vulnerability #VPN #PatchNow
⚠️ CRITICAL: Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent
Two critical remote code execution vulnerabilities in Check Point VPN (CVE-2026-85102 and CVE-2026-85103) are facing imminent exploitation. Any organization running affected Check Point VPN appliances is at immediate risk of full system compromise. Unpatched instances are likely to be targeted with…
🤖 AI generated summary
Overview
Description
Statistics
- 2 Posts
Bluesky
Overview
Description
Statistics
- 2 Posts
Fediverse
¿Seguimos confiando demasiado?
Anderson hablaba de confianza en seguridad informática a comienzos de los años 70.
Más de cincuenta años después tenemos Cloud, SaaS, Zero Trust, MFA, PAM, EDR y tecnologías que en aquella época hubieran parecido ciencia ficción.
Entonces me hice una pregunta:
¿El problema también cambió?
En lugar de buscar la respuesta en otro paper, decidí mirar algunas vulnerabilidades recientes:
CVE-2026-20079
CVE-2026-19490
CVE-2025-25249
CVE-2026-20212
Authentication bypass, problemas de memoria, componentes de infraestructura...
Vulnerabilidades técnicamente muy diferentes.
Pero hay una pregunta interesante que podemos hacerle a cada una:
¿Qué tuvo que asumir el sistema para que esa vulnerabilidad pudiera existir?
De eso hablaremos próximamente
¿Seguimos confiando demasiado? —
De Anderson a la Inteligencia Artificial
Overview
Description
Statistics
- 1 Post
- 2 Interactions
Fediverse
💡 Tabs & Accordions v3.1.0
Changes:
⚠️ [SECURITY FIX] Fixes crafted data-rlta-alias attributes allowing JavaScript execution when matching links are clicked (CVE-2026-85191)
👉 Adds an open-narrow attribute to set a different initial open state on narrow screens
👉 Adds the documented JavaScript function for closing a specific tab or accordion
👉 and 9 more
Overview
Description
Statistics
- 2 Posts
- 2 Interactions
Fediverse
💡 ReReplacer v16.2.0
With ReReplacer you can replace whatever you want in your entire site.
Changes:
⚠️ [SECURITY FIX] [PRO] Fixes Condition Set labels allowing access to unrelated database fields (CVE-2026-85188)
👉 [PRO] Adds settings to restrict who can save PHP Condition Rules
👉 [PRO] Removes the automatic Download Key popup (inline field remains available)
👉 and 17 more
Changelog: https://regularlabs.com/rereplacer/changelog
Overview
Description
Statistics
- 1 Post
- 2 Interactions
Fediverse
💡 Quick Index v5.0.5
With Quick Index you can easily add an index (or ToC) to your content.
Changes:
⚠️ [SECURITY FIX] Fixes crafted index class options allowing JavaScript injection (CVE-2026-85190)
👉 [PRO] Removes the automatic Download Key popup (inline field remains available)
👉 [PRO] Fixes "Only when ordered" heading numbers also appearing on unordered individual levels
👉 and 9 more
Changelog: https://regularlabs.com/quickindex/changelog
Overview
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
2026-W37 — Weekly Threat Roundup
🤖 AI is no longer just a defender's tool: state-sponsored groups and criminals weaponized Claude, ChatGPT, and OpenAI agents to automate exploitation, rebuild malware, and generate one million personalized phishing emails in three days.
🔓 GitLab's CVSS 10.0 path traversal flaw (CVE-2026-85706) wa…
https://threatnoir.com/weekly/2026-w37
#infosec #cybersecurity #threatintel
🤖 AI generated summary