Cybersecurity teams are being challenged to move faster across every layer of defence—from patching actively exploited infrastructure and protecting connected energy systems to educating employees and using artificial intelligence to remediate vulnerable code.
Rapid7 has published technical details and proof-of-concept code for a critical Check Point vulnerability already exploited in the wild. Mate Security has secured $35 million to develop autonomous security-operations agents, while the International Energy Agency is drawing attention to the cyber risks hidden inside inverter supply chains. Reseda Group is investing in credit-union security education, and Leidos has introduced an AI platform designed to find and repair software vulnerabilities.
Rapid7 publishes PoC for exploited Check Point vulnerability
Rapid7 has released a technical analysis and proof-of-concept exploit for CVE-2026-16232, a critical authentication-bypass vulnerability affecting Check Point security-management products.
The flaw affects the SmartConsole authentication process used with Check Point Security Management and Multi-Domain Management environments. According to The Hacker News, an unauthenticated remote attacker could exploit the weakness to obtain a valid login token and access a management server with full administrative privileges.
Compromise at the management layer is particularly serious. An attacker with administrative control could modify firewall policies, create or remove administrators, alter VPN configurations and interfere with security logs. Rather than breaching one protected endpoint, the attacker could potentially manipulate the infrastructure responsible for enforcing security across an organisation.
Check Point has reported exploitation affecting a limited number of customers. The US Cybersecurity and Infrastructure Security Agency added the vulnerability to its Known Exploited Vulnerabilities catalogue, signalling that remediation should be treated as an immediate operational priority.
Rapid7’s public proof of concept is likely to increase that urgency. Technical disclosure helps defenders understand the vulnerability, validate patches and improve detection, but it can also lower the barrier for additional attackers once working exploitation details are publicly available.
Affected organisations should therefore:
- Install the relevant Check Point Jumbo Hotfix without delay.
- Restrict management access to trusted administrative addresses.
- Review SmartConsole and management-server authentication activity.
- Look for unexpected policy, administrator and VPN configuration changes.
- Preserve and independently examine logs for signs of earlier compromise.
- Rotate exposed administrative credentials and tokens where appropriate.
Patching closes the vulnerability, but it does not establish whether an attacker entered before the fix was applied. Organisations operating exposed management servers should conduct retrospective threat hunting rather than assuming that installing the update completes the response.
The incident reinforces a wider security principle: administrative consoles and orchestration systems require stronger isolation than ordinary applications because compromising them can undermine every control they manage. HIPTHER previously examined similarly high-impact infrastructure threats in its Cybersecurity Roundup covering operational technology, AI-agent security and emerging attack techniques.
Mate Security raises $35 million for autonomous security operations
Israeli cybersecurity company Mate Security has raised $35 million in Series A funding as it works to build what it describes as an operating system for AI security agents.
The round was led by Canaan Partners, with participation from Microsoft’s M12 venture fund, Insight Partners and Team8. It follows a $15.5 million seed round and brings the company’s total funding to more than $50 million.
According to Calcalist, Mate Security was founded in 2025 by Asaf Wiener, Oren Saban and Guy Pergal, whose previous experience includes roles at Wiz, Microsoft and Meta. The company currently employs approximately 50 people and plans to roughly double its workforce by the end of the year.
Mate’s platform uses autonomous agents to support security-operations tasks including threat detection, investigation, response and proactive hunting. Its central proposition is that an AI agent needs more than access to alerts: it also needs an understanding of the organisation in which those alerts occur.
A login from an unfamiliar location, for example, could indicate account compromise—or it could be expected activity associated with an authorised test or business trip. Mate says its context layer creates an organisational knowledge base that helps agents interpret technical signals alongside business and security information.
This contextual approach addresses a major obstacle to security automation. Traditional tools often generate large numbers of alerts because they evaluate individual events without understanding intent. If AI agents inherit the same fragmented information, they risk automating false positives or taking disruptive action against legitimate activity.
For autonomous SecOps to succeed, organisations will need clear limits around what agents can do without approval. Low-risk enrichment and investigation can be heavily automated, while actions such as disabling accounts, isolating production systems or changing firewall rules may still require human authorisation.
Detailed audit trails will also be essential. Security teams need to know which evidence an agent considered, which decision it made, what systems it changed and how that action can be reversed.
The investment reflects continued demand for tools that reduce the operational burden on overstretched security teams. It also demonstrates how the market is moving from AI assistants that summarise alerts toward agents expected to participate directly in investigations and response.
IEA highlights cybersecurity risks inside inverter supply chains
The rapid expansion of solar power, battery storage and other distributed-energy systems is turning inverters into strategically important digital infrastructure.
Inverters convert and manage electricity flowing between generation equipment, batteries and the grid. Modern devices increasingly include internet connectivity, remote monitoring, software updates and centralised fleet-management functions. Those capabilities improve efficiency and maintenance, but they also create potential paths for cyber intrusion and remote disruption.
The International Energy Agency argues that inverter supply-chain security and cybersecurity should be considered together. Manufacturing capacity for several clean-energy technologies remains highly concentrated, while utilities and energy providers may have limited visibility into the software, components and remote-access mechanisms embedded in the equipment they purchase.
The concern is not limited to a single manufacturer or country. Systemic risk emerges when large numbers of grid-connected devices depend on similar components, cloud platforms, update mechanisms or privileged remote services. A vulnerability or compromised supplier could then affect many installations simultaneously.
Energy companies and public authorities should incorporate cyber requirements throughout the inverter lifecycle, including:
- Secure-by-design procurement standards.
- Software bills of materials and component transparency.
- Cryptographically signed firmware and software updates.
- Clearly defined vulnerability-disclosure processes.
- Guaranteed security updates throughout the equipment’s service life.
- Strong authentication for local and remote administration.
- Network segmentation between inverter fleets and critical grid systems.
- Independent testing of cloud-management and remote-access functions.
- Contingency plans for operating equipment if a supplier service becomes unavailable.
Diversification also matters. Substituting one concentrated supplier base with another will not eliminate risk unless buyers also improve technical assurance, contractual safeguards and visibility into the software supply chain.
Because energy equipment can remain operational for decades, procurement decisions made today may determine the grid’s cyber exposure well into the future. HIPTHER has previously explored the physical consequences of attacks against energy infrastructure in its analysis of evolving cybersecurity threats to hydropower dams.
Reseda Group backs cybersecurity education for credit unions
Reseda Group is investing in Stickley on Security to make cybersecurity and fraud-prevention education more accessible to credit unions and their communities.
Reseda is a credit union service organisation wholly owned by Michigan State University Federal Credit Union. Stickley on Security, founded by cybersecurity specialist Jim Stickley in 2007, provides training courses, educational material, newsletters and security services designed for financial institutions.
The partnership will bring cybersecurity education directly to credit unions, according to the companies’ announcement.
Credit unions face many of the same threats as larger banks, including phishing, credential theft, business-email compromise, payment fraud and ransomware. However, smaller institutions may have fewer specialist staff and more limited budgets with which to manage those risks.
Education can reduce exposure by helping employees and members identify social-engineering attempts before credentials or funds are lost. Its effectiveness, however, depends on whether training reflects the real techniques being used against the institution.
Annual compliance modules alone are unlikely to change behaviour. Strong programmes use short, recurring lessons, realistic simulations and role-specific material for employees handling payments, customer support, privileged systems and sensitive member information.
Training should also be connected to incident reporting. Employees need a simple way to flag suspicious messages and transactions, while security teams should use those reports to update controls and future educational content.
Stickley on Security recently combined with information-security credit union service organisation VYFI, expanding its work across security awareness, assessments, penetration testing, vulnerability management, incident planning and regulatory readiness.
The initiative illustrates why cybersecurity resilience depends on people as well as products. HIPTHER has also examined the leadership dimension through the Cybersecurity for Leaders programme focused on AI-integrated security decisions.
Leidos introduces Parcata for AI-powered vulnerability remediation
Leidos has introduced Parcata, a proprietary AI platform designed to autonomously identify and repair vulnerabilities in first-party and third-party software.
Developed by the company’s Kudu Dynamics team, Parcata is model-agnostic and can use multiple large language models rather than depending on a single provider. Leidos says the platform can accelerate vulnerability discovery and patch zero-day flaws in real time.
The technology was validated through the US Defense Advanced Research Projects Agency’s AI Cyber Challenge and has been evaluated in internal technical exercises. According to the Leidos announcement, the company is now running Parcata against its own code before deploying it into customer and mission environments.
Automating both discovery and remediation could substantially reduce the period between a vulnerability entering software and an effective patch being deployed. This is increasingly important as adversaries use automation to scan for weaknesses and exploit newly disclosed vulnerabilities at greater speed.
Model diversity may also offer resilience. Different models can be used to analyse code, test exploitability, propose repairs and review one another’s output. An organisation is therefore less dependent on the performance or availability of one frontier model.
Nevertheless, AI-generated patches require rigorous validation. A repair that stops a specific exploit could introduce a functional regression, weaken another control or create a less obvious vulnerability elsewhere.
A safe deployment process should include:
- Reproducible testing that confirms the original vulnerability.
- Static and dynamic analysis of the proposed patch.
- Regression and performance testing.
- Independent review for high-impact or mission-critical software.
- Staged deployment with monitoring and rollback capability.
- Full records of the models, prompts, evidence and code changes involved.
The strongest use of AI may initially be to compress the time required for human experts to understand and repair a vulnerability. Fully autonomous production patching will require organisations to establish confidence not only in detection accuracy, but also in software correctness and operational recoverability.
The bigger picture: cybersecurity is becoming a continuous control system
The five developments show cybersecurity moving away from isolated alerts and periodic compliance exercises toward continuous control.
Rapid7’s Check Point research demonstrates how quickly defenders must react when a vulnerability reaches active exploitation. Mate Security and Leidos are using AI to shorten investigation and remediation cycles. The IEA is extending cyber risk management into equipment procurement and energy supply chains, while Reseda Group and Stickley on Security are addressing the human decisions that determine whether technical controls succeed.
Automation will play an increasingly important role, but speed cannot be its only measure of value. Security tools must also understand organisational context, operate within defined permissions, preserve evidence and allow consequential actions to be reviewed or reversed.
The future security stack will consequently need to combine four capabilities: rapid technical response, trustworthy automation, resilient supply chains and informed people. Organisations that treat these as one connected system will be better positioned to contain threats before individual weaknesses develop into operational crises.












Got a Questions?
Find us on Socials or Contact us and we’ll get back to you as soon as possible.