July 23, 2026 by sig9

Hacker Wars - July 23, 2026

bulletin-feature-image

Your daily dose of infosec chaos


Today’s theme: everything is on fire, and some of it is literally frozen food. We’ve got a Check Point zero-day being exploited in the wild, Iranian hackers going after industrial control systems, a ten-month espionage campaign against South Korean diplomats, and ransomware that managed to freeze an entire supply chain. Just another day in infosec.

Check Point SmartConsole Zero-Day Gives Attackers the Keys to the Kingdom

A critical zero-day in Check Point’s SmartConsole GUI (CVE-2026-16232, CVSS 9.3) has been actively exploited to gain full administrator access to Security Management and Multi-Domain Management products. The flaw lets unauthenticated attackers hijack the admin panel, which is basically handing them the master key to your entire security infrastructure.

What to do: Patch SmartConsole and Security Management immediately. Audit access logs for any unauthorized admin sessions. If you can’t patch yet, restrict SmartConsole network access to trusted IPs only.


Iranian Hackers Are Coming for Your PLCs

US federal agencies issued an updated advisory warning that Iranian threat actors are actively targeting programmable logic controllers from Siemens, Schneider Electric, and Rockwell Automation. These aren’t script kiddies - they’re going after the actual hardware that runs critical infrastructure like power grids and manufacturing lines.

What to do: Segment OT networks from IT and internet-facing systems. Apply vendor patches for affected PLCs. Monitor for anomalous connections to ICS devices and review the CISA advisory for specific TTPs.


South Korea’s Diplomatic Secrets Exposed in Ten-Month Breach

Hackers quietly maintained access to South Korea’s National Diplomatic Academy online education system for ten months, siphoning personal information from current and former Ministry of Foreign Affairs employees worldwide. Ten months of dwell time means they had plenty of time to exfiltrate everything they wanted.

What to do: If you work in government or adjacent sectors, assume your training platforms are targets too. Enforce MFA everywhere, segment sensitive systems, and implement behavioral anomaly detection to catch long-dwell intrusions.


Ransomware Freezes Japanese Food Supply Chain

A ransomware attack on a Japanese food and logistics company has disrupted frozen food deliveries to thousands of clients, including KFC franchises across the country. Attackers hit the company’s logistics systems, effectively freezing (pun intended) the entire cold supply chain.

What to do: Test your disaster recovery plans for supply chain disruption scenarios. Ensure backups are immutable and stored offline. If you’re in logistics or food distribution, segment OT and IT networks and have a manual fallback process ready.


That’s it for today. Remember: the best incident is the one you prevented.


Brought to you by sig9 - sig9.ch | Protecting the unseen, securing the unknown

This bulletin is provided for informational purposes. Contact us for tailored security analysis.