A Busy Week for Zero-Days and Legacy Bugs Alike
This week's cybersecurity newsletter bulletin reads like a reminder that old vulnerabilities never really disappear, they just wait for someone to notice them again. Among the more than 20 stories rounded up this week, researchers flagged an actively exploited Check Point zero-day, a newly named exploit chain called Certighost, an HTTP/2 protocol flaw, and abuse of plugins for the popular Notepad++ text editor. Layered on top of all of that: threat actors are increasingly pairing these techniques with AI-accelerated tooling, including autonomous agents capable of chaining multiple zero-days together in a single automated campaign.
For everyday readers, weekly bulletins like this can feel like noise. But the pattern underneath the headlines matters: attackers are exploiting both brand-new flaws and decade-old bugs at the same time, which tells you that patching discipline still matters just as much as watching for the latest zero-day.
Check Point Zero-Day and the Certighost Exploit
The most urgent item in this week's bulletin is an authentication flaw in Check Point products that is already being exploited in the wild. Authentication bugs are particularly dangerous because they can let an attacker bypass the login process entirely, potentially gaining access to systems that organizations rely on for perimeter security. When a security vendor's own product becomes the entry point for an attack, the fallout tends to ripple outward to every customer running that software.
Alongside it, researchers named a separate exploit chain Certighost, adding to a growing list of branded vulnerabilities that security teams need to track this year. The naming convention has become common practice in the industry precisely because it helps IT teams and journalists communicate quickly about a specific threat without wading through technical jargon. Whether or not the branding is warranted, the underlying message for defenders is consistent: patch quickly, verify vendor advisories, and assume that publicly disclosed authentication flaws will be weaponized within days, not weeks.
Old Bugs, New Targets: NGINX, HTTP/2, and Notepad++
One of the more striking details in this week's roundup is the continued exploitation of a 15-year-old NGINX bug. NGINX powers a huge share of the web's infrastructure, and a bug that old surviving into active exploitation campaigns underscores a persistent problem in cybersecurity: legacy software often keeps running long after it should have been retired or patched, especially in smaller organizations without dedicated security staff.
The bulletin also covered a flaw in the HTTP/2 protocol, the technology that underpins how modern browsers and servers exchange data efficiently. Protocol-level flaws tend to be harder to fix quickly because they affect implementations across countless vendors, not just a single piece of software. Meanwhile, attackers have also been abusing plugins for Notepad++, a widely used free text editor popular with developers and IT administrators. Plugin ecosystems are frequently overlooked in security reviews, making them an attractive soft spot for attackers looking for a foothold on a developer's machine.
Taken together, these three stories paint a picture familiar to anyone who follows security news closely: attackers don't need flashy zero-days when overlooked legacy code, protocol edge cases, and third-party plugins offer easier paths in. It's a theme that echoed through a recent roundup covering a ransomware claim against Switzerland's rail network and LG's proxy restrictions, where seemingly unrelated stories pointed to the same underlying lesson about infrastructure exposure.
AI Agents Are Now Chaining Zero-Days
Perhaps the most forward-looking item in this week's bulletin involves autonomous AI agents observed chaining zero-day exploits together in an attack against Hugging Face, the platform widely used by developers and researchers to host and share machine learning models. The idea of an AI system independently identifying and combining multiple vulnerabilities in sequence, without a human operator manually directing each step, marks a meaningful shift in how attacks can be assembled and executed.
This matters for privacy and security beyond the immediate target. Platforms like Hugging Face often store API keys, model weights, and credentials tied to broader cloud infrastructure. An automated attack chain that can move from one vulnerability to the next at machine speed reduces the window defenders have to detect and respond, which is exactly the kind of threat that traditional, manually-tuned security tooling was not built to catch.
What This Means For You
Most people reading a cybersecurity newsletter bulletin like this aren't running Check Point firewalls or hosting NGINX servers themselves, but the underlying lessons still apply broadly. If you use software built on any of the platforms mentioned, whether that's a VPN client, a router's admin panel, or a developer tool like Notepad++, keeping it updated is the single most effective defense against exactly this kind of exploitation. Attackers rely on the assumption that patches roll out slowly and unevenly, and this week's bulletin shows that assumption still holds true even for bugs that are 15 years old.
The rise of AI-driven exploit chaining is also worth watching, not because it changes what you personally need to do today, but because it signals that the speed of attacks is increasing. Faster attacks mean less time between a vulnerability's disclosure and its exploitation, which makes prompt patching and strong authentication practices more important than ever.
Actionable Takeaways
- Apply security patches for any software you use as soon as updates become available, especially for widely deployed tools like web servers, firewalls, and text editors.
- Review browser extensions and application plugins periodically, removing any that are unused or from unverified sources, since plugin ecosystems are an increasingly common attack vector.
- If you administer any Check Point products, consult the vendor's advisories immediately and apply available mitigations for the authentication flaw.
- Stay informed through regular security roundups. Threats increasingly move faster than traditional news cycles, and understanding the broader pattern, not just individual headlines, helps you prioritize which updates matter most.




