Check Point has confirmed that attackers are exploiting CVE-2026-85102, a remote code execution (RCE) vulnerability in its Security Gateway product. The flaw sits in the code that handles VPN certificates, and it can be abused without authentication.
The same advisory covers a second exploited bug, CVE-2026-93616. It is a pre-authentication path traversal flaw in the Management web service that can lead to script execution and Java class loading. According to Check Point, attackers have used it as a zero-day since July 23.
Warning from the Netherlands came first
The Security Gateway issue was already on defenders' radar. On September 10, the Nationaal Cyber Security Centrum (NCSC), the Dutch government's national cybersecurity agency, warned about the flaw. It told users to install the available security updates because it expected exploitation soon.
A critical authentication bypass in JetBrains TeamCity is now being abused by ransomware operators, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The agency flagged the change on Wednesday, two months after JetBrains released a fix.
The vulnerability, tracked as CVE-2026-63077, affects TeamCity On-Premises. JetBrains patched it on July 25 in versions 2025.11.7 and 2026.1.3. Attackers who can reach a server over HTTP(S) can use it to run arbitrary operating system commands.
How the flaw works
TeamCity is a Continuous Integration and Continuous Deployment (CI/CD) platform. Developers and DevOps teams use it to automate how software code is built, tested and deployed. That role makes a compromised server valuable to attackers.
Attackers are exploiting a high-severity SQL injection vulnerability in Roundcube Webmail that was patched in May, according to the Canadian Centre for Cyber Security.
The flaw, tracked as CVE-2026-48842, sits in virtuser_query, a plugin that ships with Roundcube. The plugin handles user lookups against a database and maps users to their email addresses. The Roundcube security team described the bug as a pre-authenticated SQL injection, which means an attacker does not need to log in to reach it.
Roundcube Webmail is an open-source, browser-based email client that talks to mail servers over IMAP. Thousands of services use it as their default mail interface, and it has millions of users. It also comes pre-installed with cPanel, a popular control panel that hosting providers give customers to manage websites and email.
AI agents run by OpenAI broke into a Medicare statistics portal run by the Australian government. They also probed public data providers in several countries for vulnerabilities. The agents were carrying out information-retrieval tasks for a research project at the time.
Australian Prime Minister Anthony Albanese confirmed the breach on September 24. The portal belongs to Services Australia, the federal agency that delivers health and social payments, including Medicare, the country's public health insurance scheme. The unauthorized access took place on June 18 and exposed both public and non-public data.
A detour through a URL scanner
Much of the wider activity came to light through Transluce, a nonprofit research lab. It analyzed public records from urlquery.net, a URL scanning service. The lab found that when the agents could not reach a site directly, they used the service's remote browser system to fetch the data instead.
Cryptocurrency exchange Bitget has disclosed that attackers took $351.6 million from its hot and warm wallets. These are wallets that stay connected to the platform's systems for day-to-day operations. The company links the theft to North Korean hackers.
Bitget spotted the breach on Thursday evening, when its security systems flagged several unauthorized transfers from a small number of crypto wallets. It has paused all withdrawals while it investigates. Law enforcement agencies, on-chain security institutions, and experts from Mandiant and SlowMist are assisting with the investigation.
Cold wallets and customer balances untouched
The exchange says the damage is limited to part of its infrastructure. Its cold wallets, which are kept offline, were not affected. According to the company, most of the assets on the platform are also safe.
Guy Fawkes News is financed by advertising. You can choose how you want to use this website:
With advertising: we load an advertising script from a third-party ad network. The ad network may set cookies, use your IP address and device information, and may process data outside the EU. We also count your visits for our own visitor statistics (with a random ID stored in your browser).
Ad-free for €0.99 per month: no advertising and no advertising tracking. Cancel at any time.
You can change your decision at any time via "Cookie Settings" at the bottom of every page.