View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Zero-day vulnerability in Check Point SmartConsole actively exploited

🚨 ACTIVE EXPLOITATION

  • Zero-day vulnerability in Check Point SmartConsole actively exploited — Cybersecurity Dive
    A zero-day flaw in Check Point SmartConsole is being actively exploited.
    • Applies to Check Point SmartConsole users managing security configurations
    • Vulnerability allows attackers to bypass authentication controls
    • Exploitation enables unauthorized changes to security settings
    • Attackers leverage the flaw to gain elevated privileges within the console

🕵️ RESEARCH & DEEP DIVES

  • Default Azure Automation Setting Enables Cross-Tenant Identity Takeover — Dark Reading
    A default Azure Automation configuration flaw allows cross-tenant identity takeover.

    • Affects Microsoft Azure Automation customers using default public settings
    • Vulnerability allows attackers to seize identities across Azure tenants
    • Attackers could access other tenants' data, credentials, and cloud workloads
    • Exploit involves a chain of code flaws combined with public-by-default configuration
  • North Korean BlueNoroff uses Zoom, Teams phishing kit to profile crypto wallets before malware — The Hacker News
    BlueNoroff operates a phishing kit impersonating Zoom and Teams to profile crypto wallets and deliver malware.

    • Targets cryptocurrency sector employees via typosquatted Zoom and Microsoft Teams domains
    • Uses compromised trusted Telegram contacts to distribute phishing Calendly links
    • Phishing pages request webcam access, stream video to operators, and fingerprint crypto wallets
    • Delivers ClickFix malware payloads via fake Zoom SDK update messages on Windows and macOS
    • Windows payload disables Defender, steals Telegram sessions, and probes browser wallet extensions
  • Certighost Exploit Lets Low-Privileged AD Users Impersonate Domain Controllers — The Hacker News
    Researchers disclosed a Certighost exploit allowing low-privileged AD users to impersonate Domain Controllers.

    • Applies to Active Directory environments with Enterprise CA and default Machine certificate template
    • Vulnerability in AD CS enrollment fallback (chase) lets low-privileged users obtain Domain Controller certificates
    • Exploit abuses SMB and LDAP to relay CA authentication and sign DC identity into certificate
    • Allows Kerberos PKINIT authentication as Domain Controller and DCSync attacks to retrieve krbtgt secret
    • Affected versions include Windows Server 2012 through 2025 and Windows 10 versions 1607 and 1809
  • Microsoft Azure Kubernetes Service Elevation of Privilege VulnerabilityMissin... CVE-2026-56163 — CVE ThreatInt
    Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

  • Azure App Service on Azure Stack Hub Elevation of Privilege VulnerabilityImpr... CVE-2026-58630 — CVE ThreatInt
    Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.

🔓 CVEs & KEV

  • Other: 18 CVEs (worst 6.5)

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check