Cybersecurity Weekly Briefing, 25-31 July

July 31, 2026

Check Point patches critical actively exploited SmartConsole authentication bypass

Check Point has released urgent security updates for CVE-2026-16232, a critical authentication flaw in the SmartConsole login process rated CVSS 9.3 by the vendor.

The vulnerability allows an unauthenticated remote attacker to obtain an application token and access Security Management and Multi-Domain Management servers with full administrative privileges. Check Point confirmed active exploitation affecting a small number of customers whose management infrastructure was directly reachable and did not restrict Trusted Clients. CISA added the vulnerability to its Known Exploited Vulnerabilities catalogue on July 22, setting a remediation deadline of July 25.

Organisations should immediately install the latest Jumbo Hotfix, restrict management clients to trusted IP addresses, protect management access with firewall rules and review historical connections for the indicators published by Check Point.

More info

RefluXFS enables root privilege escalation on default Linux installations

Qualys has disclosed CVE-2026-64600, dubbed RefluXFS, a race condition in the Linux kernel’s XFS copy-on-write path. An ordinary local user can exploit the flaw to overwrite the contents of protected root-owned files, including /etc/passwd and SUID binaries, without visibly changing their permissions or metadata and without generating kernel logs.

The vulnerability has been present since Linux 4.11 and affects systems using XFS with reflink enabled, including default installations of RHEL, Oracle Linux, Amazon Linux, Fedora and several derivative distributions. Qualys estimates that more than 16.4 million systems could be exposed. SELinux, seccomp, kernel lockdown and common container isolation mechanisms do not prevent exploitation, leaving no practical workaround.

Organisations should install the corrected kernel supplied by their distribution and reboot the system to ensure that the patched version is running.

More info

TA488 exploited a Zimbra zero-day through “half-click” emails

Proofpoint, in coordination with the NSA and FBI, has documented that Russian-aligned threat actor TA488, also known as Void Blizzard or Laundry Bear, exploited a previously unknown Zimbra Collaboration Suite vulnerability for at least five months during 2025. The issue was later patched as CVE-2025-66376.

The XSS exploit triggers when a message is opened or previewed in a vulnerable Zimbra webmail client, requiring no link click or attachment download. The malicious JavaScript, tracked as ZimReaper, can steal autofilled passwords, tokens, two-factor recovery codes and contacts, create a ZimbraWeb application password that bypasses two-factor authentication and exfiltrate up to 90 days of email. Campaigns targeted Ukrainian organisations and US government, advanced-science and defence-industrial-base entities.

Administrators should upgrade to Zimbra 10.0.18, 10.1.13 or later and investigate unauthorised ZimbraWeb application passwords.

More info

JadeProx compromises healthcare, government and education organisations

Group-IB has identified a China-nexus operation tracked as JadeProx after discovering an exposed directory on an Alibaba Cloud server containing command histories, offensive tools, webshell paths and staged phishing packages.

The infrastructure revealed simultaneous intrusions involving a Vietnamese public hospital, Malaysia’s Ministry of Foreign Affairs and several educational institutions in Hong Kong, alongside targeting in Honduras and phishing campaigns impersonating Claude software. The operation centres on TriBack Loader, which uses DLL sideloading through signed binaries and Windows callback APIs to decrypt and execute shellcode while evading EDR monitoring. Two variants delivered AdaptixC2, while another deployed the Beagle backdoor.

Although its tooling and techniques overlap with Mustang Panda, Earth Lusca, APT27 and Tropic Trooper, Group-IB tracks JadeProx as a separate cluster because tools are routinely shared among China-nexus operators and the available evidence does not support attribution to a single documented group.

More info

Golden Chickens expands its MaaS platform with four new malware families

Recorded Future’s Insikt Group has identified four new malware families associated with TAG-195, also known as Golden Chickens or Venom Spider: TinyEgg, ChonkyChicken, a modular ChonkyChicken variant and ChromEggscalator. TinyEgg operates as a lightweight initial-access backdoor, while ChonkyChicken adds browser credential theft, network reconnaissance, remote execution and sustained surveillance.

The modular variant employs a controller-and-plugin architecture capable of retrieving at least fourteen modules on demand, allowing operators to deploy only the functions required for each intrusion and reducing the implant’s static detection footprint. ChromEggscalator adapts a publicly available tool to bypass Chrome encryption protections. The platform has been delivered through ClickFix campaigns that instruct victims to execute commands copied from fake security-verification pages.

Defenders should monitor suspicious use of regsvr32.exe, Run-key persistence, browsers launched with remote debugging enabled and unusual WebSocket communications.

More info