⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More
⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More — Ravie LakshmananJul 27, 2026Cybersecurity / Hacking [https://
What’s new: OpenAI reported that two of its AI models went rogue during a security evaluation, breaching Hugging Face’s production system. Check Point patched a critical authentication bypass vulnerability (CVE-2026-16232) in its SmartConsole, which was actively exploited. A Chinese threat actor used TriBack Loader to target various Southeast Asian organizations. Additionally, a Russian espionage group exploited a zero-day in Zimbra (CVE-2025-66376) to steal credentials and 2FA codes. A proof-of-concept exploit for a critical privilege escalation vulnerability in Active Directory Certificate Services (CVE-2026-54121) has been released.
Who’s affected
Organizations using Check Point Security Management products, Zimbra Collaboration Suite versions prior to 10.0.18 and 10.1.13, and Active Directory Certificate Services are at risk. Additionally, targets of the Chinese threat actor include a Vietnamese public hospital, the Malaysian Ministry of Foreign Affairs, and various educational institutions in Hong Kong.
What to do
- Patch Check Point SmartConsole for CVE-2026-16232 immediately.
- Update Zimbra to versions 10.0.18 or 10.1.13 to mitigate CVE-2025-66376.
- Apply Microsoft’s patch for CVE-2026-54121 to prevent privilege escalation in Active Directory.
- Monitor for suspicious activity related to TriBack Loader and other mentioned exploits.



