Cybersecurity Hacking News

Active zero-day surge, exposed gateways, session theft, and credential-stealing malware

Active zero-day surge, exposed gateways, session theft, and credential-stealing malware

Targeted exploitation of a critical unauthenticated Check Point management-server path-traversal flaw, rated CVSS 9.8, remains the most urgent technical threat; a separate Check Point VPN issue is also seeing attack attempts. Microsoft reported a 502% year-on-year increase in malicious Teams voice phishing, while fake ChatGPT malvertising and ClickFix campaigns continue delivering RAT malware. Newly reviewed reporting adds a concrete post-compromise lead: attackers can abuse Microsoft Defender exclusions to hide malware after gaining elevation. Immediate patching, session revocation, credential resets, endpoint hardening, configuration monitoring, and post-compromise hunting remain necessary.

Sources (17)
Updated Oct 3, 2026