Skip to Content

Security News Update: How to fix the new Check Point zero-day flaw (CVE-2026-93616)? and more

Check Point Zero-Day Exploited Ahead of Fix

Check Point patched a zero-day in its Security Management software after finding attackers had already exploited the flaw in targeted attacks.

CVE-2026-93616 carries a 9.8 CVSS score and can allow unauthenticated attackers to execute arbitrary scripts on vulnerable management servers.

Treat affected Check Point servers as compromised and activate your IR plan until you can rule out unauthorized activity.

Patch affected systems, restrict TCP/19009 to trusted IPs, and hunt for suspicious activity going back to at least July 23.

F5 BIG-IP Vulnerability Under Active Attack

Threat actors are exploiting a F5 BIG-IP flaw that can enable unauthenticated remote code execution on certain APM configurations.

The 9.8 CVSS vulnerability specifically affects systems configured as OAuth Authorization Servers.

The OAuth server role makes this more than another internet-facing RCE. An attacker who gains control at the access layer could potentially use a single vulnerable system as a foothold into applications that trust it.

Confirm whether your APM configuration is affected, apply F5’s hotfix, and hunt for suspicious OAuth failures and audit-log activity.

ShinyHunters Says It Stole FBI Personnel Data

ShinyHunters claims it breached FBI systems and stole sensitive information on employees and applicants.

404 Media reviewed 5,000 purported records containing personal and family information, though the FBI has not confirmed the breach.

Threat actors can use the family details to impersonate relatives, fabricate emergencies for financial fraud, or build pretexts tailored to individual FBI personnel.

Limit access to personnel data, monitor bulk downloads, and alert employees whose information may have been exposed.

Stolen Credentials Put U.S. Water Utilities at Risk

SpyCloud found compromised OT or remote-access credentials at 258 U.S. water utilities, potentially opening another path into critical infrastructure.

Infostealers can also capture active session tokens, and a single compromised vendor device could potentially affect multiple utilities.

Utilities should treat vendor access as a shared attack surface, especially when the same third party can remotely connect to multiple operators.

Monitor remote-access accounts, revoke compromised sessions, and tightly restrict vendor access to OT environments.

Cyberattacks Push Healthcare Systems Into Downtime

Cyberattacks against healthcare organizations increased 14% in the first half of 2026.

For hospitals, outages affecting EHRs, imaging, scheduling, or communications can disrupt patient care, giving attackers leverage even without stealing data

As a former nurse, I know downtime isn’t just an IT problem. When clinicians lose access to patient histories, medication records, test results, or other critical information, they still have patients in front of them who need care.

Test downtime procedures under realistic conditions and measure how long critical clinical workflows can safely operate without their supporting systems.