Bangalore, India
2021
  |  By Foresiet
CVE-2026-16232 is a critical authentication bypass in the Check Point SmartConsole login process. An unauthenticated attacker who can reach the Management Server IP, and who faces no Trusted Clients restriction, can obtain an application login token and sign in with full administrative rights. That access is enough to change security policy and configuration.
  |  By Foresiet
The U.S. Cybersecurity and Infrastructure Security Agency has warned that ransomware groups are now exploiting a critical VMware vCenter Server bug that Broadcom patched on 29 July 2026. The issue is CVE-2026-59310. It is a directory traversal flaw in the vCenter Syslog server. An attacker who can reach the server on the network does not need a password. Successful use can lead to remote code execution. The published severity score is 9.8.
  |  By Foresiet
On 6 September 2026, researchers publicly described a Telegram zero-day crash. A group owner said a chat they own became unreachable: opening it crashed official clients on iOS, Android, Desktop and Web. A second researcher posted a short recording of a script sending one specially prepared sticker into a test chat. The harm is availability, not account takeover. If the sticker stays in chat history, the crash can happen again every time someone opens that conversation.
  |  By Foresiet
On 4 September 2026, attackers began exploiting an unpatched remote code execution flaw in Magento Open Source and Adobe Commerce. Dutch e-commerce security firm Sansec disclosed the issue on 5 September and named it StyleSmuggler. The company said it published early because stores were being compromised in real time.
  |  By Foresiet
What security teams need to know about an unverified local elevation-of-privilege proof of concept published against Falcon Sensor, and how to respond without overreacting. On 3 September 2026, an independent researcher publishing as MSNightmare / Chaotic Eclipse / Nightmare Eclipse released a public GitHub repository named FalconFlank. The project is described as a local privilege-escalation proof of concept against CrowdStrike Falcon Sensor on Windows.
  |  By Foresiet
Foresiet reviewed a batch of 42 masked victim listings associated with the Cl0p extortion operation. The listings describe alleged exposure of project repositories, databases, CAD files, engineering drawings, backups, software and Windchill-related files. Those references recur with unusual consistency across the batch. The pattern resembles the type of information commonly managed within product lifecycle management (PLM) environments more than the contents of a general file share.
  |  By Foresiet
In June, the Texas Parks and Wildlife Department (TPWD) disclosed that a vendor running its hunting and fishing license system had been compromised, potentially exposing personal data belonging to more than three million people. Weeks earlier, Carnival Corporation confirmed that an attacker had socially engineered an employee into granting access to part of its IT environment, affecting close to six million individuals. Different sectors. Different attack paths.
  |  By Foresiet
In Part I of this series — “Behind the Fake Tax Notice” — the Foresiet Threat Intelligence Team mapped a multi-country, tax- and invoice-themed phishing network built around hxxps://adresesvip/. That infrastructure, hosted on Alibaba Cloud in Hong Kong, was used to target taxpayers across India, Germany, Malaysia and Japan. The first report documented the lure, the sender and the hosting, but left one question open: what does the campaign actually deliver?
  |  By Foresiet
Foresiet identified adreses[.]vip as part of a localized phishing infrastructure cluster using tax, invoice, payroll, and document-download themes. The strongest evidence supports malicious phishing infrastructure and campaign-level clustering; named-actor elevation remains evidence-weighted and under active validation.
  |  By Foresiet
If your phone has not stopped buzzing for twenty minutes, you may be facing a synchronized disruption tactic called a “bombing” attack. In the 2026 cybersecurity landscape, flooding an endpoint with many requests is not just a nuisance. A weaponized operational strategy. Whether an SMS bomber script targets a person or bot networks drive up a business’s API bills, the exploit works the same way.
  |  By Foresiet
Imagine, the system can think exactly like human brain, sense the risk, Forecast, react, Protect and correlate the past incident and recover with Self immunity

One Click Digital Risk Protection platform to protect from digital external threats, detect and prevent breach epidemic from surface, deep and Dark web.

Foresiet Digiview uses AI powered engine to identify and forecast the risk based on 100+ unique vectors across on-prem and cloud deployment assess your cyber security posture with Industry benchmarking.

  • Digital Risk: Measure your third party / supply chain digital Risk and good cyber hygiene.
  • Brand Monitoring and self-healing: Protect from Impersonation, Rogue websites, Fake social pages, mobile applications etc.
  • Anti-Phishing Shield: Protect employee from targeted Phishing / Impersonation attack using ML/AI engine.
  • Attack surface visibility: Discover / monitor external assets including infrastructure, vulnerable asset.
  • Threat Intelligence: Stay updated with latest threat advisory from Social, Deep and Dark web.
  • Compliance: Automated way to assess third party / vendor compliance and maturity.

Foresiet DigiRisk is the first platform to cover all of your digital risks, allowing enterprise to focus on the core business.