Vendor
Cross-Telemetry Correlation of Endpoint and Network Security Alerts
3 TTPsDetection engineering logic that correlates Elastic Defend endpoint alerts with network security events from PAN-OS, FortiGate, and Suricata to identify potentially compromised hosts based on multi-source telemetry.
Remote Code Execution Vulnerability in Check Point Management Products
1 CVEA critical remote code execution vulnerability (CVE-2026-91843) affects multiple Check Point security management servers, allowing unauthenticated attackers to execute arbitrary code.
Critical Vulnerabilities in Check Point Security Appliances
2 TTPs 2 CVEsCheck Point has disclosed critical vulnerabilities, including CVE-2026-85102 and CVE-2026-85103, affecting various Security Gateway, Management Server, and Spark Firewall deployments.
Critical Remote Code Execution in Check Point Security Management
2 TTPs 1 CVECheck Point security management products are vulnerable to remote code execution and security policy bypass via CVE-2026-18574, affecting multiple current and legacy versions.
Check Point SmartConsole Authentication Bypass (CVE-2026-16232) Actively Exploited
1 TTP 4 CVEs 6 IOCsCheck Point released a critical security advisory to address CVE-2026-16232, an authentication bypass vulnerability in SmartConsole, which is actively being exploited in the wild and affects Security Management, Multi-Domain Management, Firewall, and Multi-Domain Log Server products.
Qilin Ransomware Claims New Victim in Agriculture and Food Production Sector
2 rules 13 TTPs 5 CVEs 178 IOCsThe Qilin ransomware group, active since July 2022 and utilizing Golang, has claimed a new victim, Danone (International Delights) in the US Agriculture and Food Production sector, employing double extortion tactics involving data encryption and threatened data release.
Multiple Vulnerabilities in Check Point Security Gateway
2 rules 3 TTPsMultiple vulnerabilities exist in Check Point Security Gateway that could be exploited by an attacker to perform a denial of service attack, disclose information, and perform a SQL injection attack.
Multiple Vulnerabilities in Check Point Products
2 rules 3 TTPs 4 CVEsMultiple vulnerabilities in Check Point Security Gateways and Spark Firewalls allow for remote denial of service, data confidentiality breaches, and data integrity compromise.
VECT Ransomware Destroys Files Due to Encryption Flaw
2 rules 1 TTPVECT 2.0 ransomware, a RaaS offering, permanently destroys large files due to an encryption flaw, discarding decryption nonces for files above 128 KB, rendering them unrecoverable and effectively acting as a wiper; it uses raw ChaCha20-IETF with no authentication.
Elastic Defend and Email Alerts Correlation
2 rules 1 TTPThis rule correlates Elastic Defend alerts with email security alerts by target username, potentially indicating a successful phishing attack and subsequent endpoint compromise.