Cập nhật nhanh các tin an ninh mạng đáng chú ý trong ngày 24/07/2026, được biên tập tự động cho độc giả gocdulieu.com từ các nguồn bảo mật công khai. Bài viết tập trung vào rủi ro có thể ảnh hưởng tới quản trị viên hệ thống, đội vận hành bảo mật và doanh nghiệp.
Điểm nóng bảo mật
- New Check Point Zero-Day Vulnerability Exploited in the Wild — The vulnerability tracked as CVE-2026-16232 has been exploited against customers with certain configurations. The post New Check Point Zero-Day Vulnerability Exploited in the Wild appeared first on SecurityWeek . Nguồn: SecurityWeek (23/07 16:06).
- Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge — The Chaos ransomware group ran its command-and-control through the victim's own browser. Cisco Talos on Thursday detailed msaRAT, the Rust implant behind it, found on a compromised Windows machine ahead of the encryptor. The implant never o Nguồn: The Hacker News (23/07 20:11).
- Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process — Cisco Talos has identified a Rust-based remote access trojan it attributes to the Chaos ransomware group, named msaRAT after four of the binding names left in the binary. The tool starts its own instance of Chrome or Edge on the victim mach Nguồn: Help Net Security (23/07 17:38).
- Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes — A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra's webmail client. The payload goes after the last 90 days of email, the organization's entire email directory, the passwo Nguồn: The Hacker News (24/07 01:36).
- Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access — Check Point has released security updates to address multiple vulnerabilities impacting Security Management and Multi-Domain Management (MDSM) products, including a critical flaw that has come under active exploitation in the wild. The secu Nguồn: The Hacker News (23/07 13:34).
- Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data — Cybersecurity researchers have disclosed details of a now-patched vulnerability chain in the Adobe Acrobat Chrome extension that has over 314 million users, which, if exploited, could facilitate a silent hijack of a user's WhatsApp data. Th Nguồn: The Hacker News (22/07 22:01).
Ưu tiên xử lý trong 24–48 giờ
- Kiểm kê các dịch vụ public-facing: VPN, gateway, IAM/NAC, remote support, dashboard quản trị và hệ thống có quyền cao.
- Đối chiếu phiên bản với advisory chính thức; ưu tiên vá lỗ hổng đang bị khai thác, có PoC công khai hoặc ảnh hưởng thiết bị biên.
- Rà soát log đăng nhập, thay đổi cấu hình, session/token bất thường và dấu hiệu truy cập từ hạ tầng lạ.
- Với AI agent/plugin/extension, áp dụng quyền tối thiểu, bật logging cho tool-call/API call và tách dữ liệu nhạy cảm khỏi môi trường thử nghiệm.
CISA KEV / lỗ hổng cần theo dõi
- CISA KEV chưa truy cập được từ môi trường tự động (HTTPError: HTTP Error 403: Forbidden); cần đối chiếu thủ công nếu đang xử lý hệ thống trọng yếu.
Nguồn tham khảo
- SecurityWeek — New Check Point Zero-Day Vulnerability Exploited in the Wild
- The Hacker News — Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge
- Help Net Security — Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process
- The Hacker News — Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
- The Hacker News — Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access
- The Hacker News — Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data
Lưu ý: Bản tin được biên tập theo hướng thực hành; trước khi áp dụng thay đổi trên hệ thống production, anh/chị nên đối chiếu với advisory chính thức của nhà cung cấp và quy trình change management nội bộ.
