Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
Check Point VPN and Google Chrome Vulnerabilities Under Active Exploitation
Check Point has disclosed a critical authentication bypass vulnerability (CVE-2026-50751, CVSS 9.3) in its VPN products that has been actively exploited since May 7, 2026, with attacks linked to Qilin ransomware affiliates. The flaw affects deployments using the deprecated IKEv1 protocol, allowing unauthenticated attackers to establish VPN connections without valid credentials. Separately, Google
DarkSword Malware
DarkSword is a sophisticated, likely government-designed iOS malware exploiting six zero-day vulnerabilities across iOS versions 18.4-18.7, deployed by multiple commercial surveillance vendors and state-sponsored actors since November 2025. The exploit chain has been used in targeted campaigns across Saudi Arabia, Turkey, Malaysia, and Ukraine, deploying three distinct malware families post-compro