Daily brief — Saturday, 19 September 2026

ITsecurityNews · 2026-09-19

Unauthenticated root RCE in Check Point management servers leads a heavy Friday of critical fixes

The Hacker News reports an unauthenticated code-execution flaw in the Check Point server that controls firewall policy, while Google's advisory lists six Chrome bugs each scored 9.6.

The IT Security Desk


Elsewhere

Friday Squid Blogging: On Squid Egg Sacs
Schneier on Security

Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root
The Hacker News

CISA Adds One Known Exploited Vulnerability to Catalog
CISA

New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution
The Hacker News

Researchers used Claude to hack OpenAI employees' ChatGPT accounts
The Register

North Korea's fake job interviews infected 30,000 devices
The Register

FBI: Fake cop and government impersonation scams cost victims $1.6B
The Register

Gyazo server flaw exploited to steal 23.6 million user records
BleepingComputer

CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA

Nations take action on North Korean IT workers after UN report
The Record

In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw
SecurityWeek

All editions from ITsecurityNews