Friday's Other Headlines: Check Point Proved Our Playbook, and North Korea Is Poisoning Packages to Fool Your AI Agent.
- Patrick Duggan
- 6 minutes ago
- 3 min read
Certighost was the flagship of a busy Friday and gets its own write-up. This is the rest — the headlines that moved around it, and where we already stood on each. No victory lap, just the ledger, our date next to theirs.
Check Point confirmed the exact exposure we told you to close
Yesterday we covered CVE-2026-16232, the Check Point SmartConsole authentication bypass, and the single loudest line in our playbook was: get the management plane off the public internet — a security-management console has no business being directly reachable. Today Check Point put a number on who actually got hit. Their statement: the exploited customers were the ones "whose Management environments were directly exposed to the Internet without IP restrictions."
That is our advice, verbatim, written as an incident finding instead of a recommendation. The bug was the same for everyone who patched late; the ones who got owned were the ones who left the console on a public IP. If you run Check Point and you did the two things we said — patch, and wall the management plane behind an allowlist — you were never in the exposed set. The vendor just confirmed the shape of the risk we described.
North Korea's newest trick: packages engineered to fool the AI agent, not the human
Famous Chollima — the DPRK actor also tracked as Shifty Corsair, the crew behind Contagious Interview — has a fresh supply-chain campaign, PromptMink, built on npm packages designed specifically to deceive AI coding agents. It's part of a larger push researchers tallied to the same cluster describe as 108 malicious packages and extensions across npm, Composer, Go modules, and a Chrome extension.
This is our beat twice over. We covered Famous Chollima in April, when they got Claude to co-author their crypto stealer, and we've spent this month on exactly this attack class — the FakeGit campaign of 7,600 fake repos where the trick was getting the AI agent to recommend the malware to you itself, and the free MCP tool we shipped so your agent refuses a poisoned dependency before it installs it. PromptMink is the same thesis with a state actor's name on it: the supply-chain target of 2026 is not the developer, it's the developer's agent. The defense is the same too — verify the package's reputation at install time, which is precisely what check-package does.
Two more on the actively-exploited list
Quick, because they're straightforward patch-now items: Adobe's ColdFusion [CVE-2026-48282](https://analytics.dugganusa.com/api/v1/dredd/kev-gap?cve=CVE-2026-48282) — one of seven CVSS-10 flaws Adobe patched July 1 — is now confirmed exploited in the wild. And Cisco Unified Communications Manager [CVE-2026-20230](https://analytics.dugganusa.com/api/v1/dredd/kev-gap?cve=CVE-2026-20230), a server-side request forgery flaw, is under active exploitation. Both are edge-adjacent, both are patched, both reward being current.
And a pattern-confirmation, not a new event: security press this week framed the Cisco Catalyst SD-WAN zero-day as "exploited months before patching." That is the exact shape we've written about five times since May — SD-WAN Manager is the brain of the network, its flaws get used long before they're fixed, and the number of them is the signal. Nothing here changes the advice: if you run it, you're on the most-actively-exploited list, and the deadline was yesterday.
The through-line
Check Point's exposure finding is a confirmation of something we'd already mapped, and PromptMink is a state actor validating an attack class we've been shipping defenses against all month. That is what the daily discipline buys: when the news breaks, the useful version is not "here's what happened," it's "here's where you already stood." Patch Certighost first. Then close the Check Point console and point check-package at whatever your agents are about to install this weekend.
Every indicator in this post is in the feed. Free.
1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.
