Hidden API Estate And AI-speed Recon Are Reshaping Modern Application Risk Key Takeaways Unknown APIs create unattributed exposure, and such exposure rarely gets tested. Attackers build their own inventory through live reconnaissance; they do not wait for your spreadsheet. API discovery must pull from gateways, cloud, specs, traffic paths, scanners, and external exposure signals. OWASP […]
A compromised AWS access key has been identified as the likely cause of a data breach affecting over 1500 UK charities using CRM provider Beacon's services. The exposure resulted in unauthorized access to sensitive charity data, highlighting the critical importance of securing cloud credentials and access keys across third-party platforms.
Google Cloud has established 2027 as a key milestone to address store-now-decrypt-later threats through its post-quantum cryptography initiative, reflecting the industry's growing concern about adversaries harvesting encrypted data today for future decryption. The company's broader migration to post-quantum cryptographic standards is expected to extend through 2028, indicating a multi-year commitment to transitioning its infrastructure ahead of quantum computing threats.
Four recent university breaches share a common root cause: misconfiguration, revealing a critical vulnerability pattern affecting the higher education sector in 2026. The article examines the specific misconfigurations enabling these attacks and outlines remediation strategies to address this widespread security gap.
Attackers wasted little time in exploiting a critical-severity vCenter vulnerability, with active exploitation occurring just five days after Broadcom's disclosure. The rapid weaponization underscores the heightened risk window organizations face when critical flaws are publicly revealed, emphasizing the urgency of patch deployment for vCenter deployments.
Shopify Shop app users are being targeted by a fake refund scam that has been active for several months, with fraudsters operating directly within the application itself. Security professionals should be aware of this threat vector targeting a widely-used mobile commerce platform and the social engineering tactics being leveraged against its user base.
For the past year, the ransomware conversation has centered on concentration: a handful of dominant RaaS operations controlling most of the damage, and a shrinking pool of active groups fighting over the same territory. The State of Ransomware Q2 2026 report from Check Point Research shows that picture starting to shift. The leaders are still winning, but […] The post The State of Ransomware Q2 2026 appeared first on Check Point Research.
The White House has authorized private sector participation in government-directed offensive cyber operations targeting transnational groups, marking a significant shift in cyber warfare approach. Security experts have raised concerns about potential escalation and the difficulty of attributing attacks when private companies are involved in such operations.
Johnson Controls Airwall versions 4.0.4 and earlier contain two critical vulnerabilities: CVE-2026-64887, a hardcoded cryptographic key affecting all installations identically, and CVE-2026-34492, an arbitrary file read flaw allowing attackers to access sensitive configuration and credential files. Organizations should upgrade to version 4.1.0 or later and implement secure key management practices, input validation, and file access restrictions to mitigate exploitation risk in critical infrastructure environments.
Siemens LOGO! Soft Comfort versions prior to V9 contain critical cryptographic weaknesses, including a hardcoded AES master key that allows local attackers to decrypt project files and remove passwords, and unsalted SHA-256 password hashes vulnerable to offline brute-force attacks. Both vulnerabilities carry a CVSS score of 6.8 and could enable unauthorized access to or modification of sensitive project logic and configurations in this industrial control software used worldwide. Siemens recommends immediate updates to V9 or later, with a required hardware upgrade to LOGO! V9 BM or later to fully remediate the issues.
CISA has disclosed four vulnerabilities in ANDRITZ HIPASE-250 and 250 SCALA devices (version ≤7.20) affecting critical infrastructure worldwide, including reversible password storage, unauthenticated access to data endpoints, suppression of audit logging, and hard-coded VNC credentials on engineering workstations. Exploitation could allow attackers to read sensitive data, access affected systems, and conceal malicious activity; ANDRITZ has released fixes in versions V8.00.00 and V8.15.00.
Siemens Parasolid versions V38.0 (before 38.0.235) and V38.1 (before 38.1.230) contain an out-of-bounds read vulnerability (CVE-2026-64629) triggered when parsing specially crafted X_T format files, which could allow attackers to crash the application or execute arbitrary code with a CVSS score of 7.8. Siemens has released patched versions and recommends immediate updates to mitigate the risk to critical manufacturing infrastructure worldwide.
A denial-of-service vulnerability in Siemens Desigo DXR and PXC Controllers allows attackers to send malformed BACnet packets that stop affected devices from responding, requiring a device reset or reboot to restore functionality. Multiple versions across the DXR2, PXC3, PXC4, PXC5, and PXC7 product lines are affected, with CVSS score 4.3 (Medium severity). Siemens has released patched versions and recommends immediate updates, along with implementing network segmentation and access controls for these critical infrastructure control devices.
View CSAF Summary Successful exploitation of this vulnerability may allow an attacker to inject and execute arbitrary OS commands with root privileges. The following versions of Haiwell IoT Cloud HMI Gateway are affected: Haiwell IoT Cloud HMI Gateway 3.40.1.12 (CVE-2026-19188) CVSS Vendor Equipment Vulnerabilities v3 10 Haiwell Haiwell IoT Cloud HMI Gateway Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Background Critical Infrastructure Sectors: Energy, Critical Manufacturing, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: China Vulnerabilities Expand All + CVE-2026-19188 A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the Net Check feature accessible via the /setting endpoint. The cmdPing Socket.io event fails to properly sanitize user-supplied input before passing it to the underlying operating system, allowing an attacker to inject and execute arbitrary OS commands with root privileges View CVE Details Affected Products Haiwell IoT Cloud HMI Gateway Vendor: Haiwell Product Version: Haiwell Haiwell IoT Cloud HMI Gateway: 3.40.1.12 Product Status: known_affected Remediations Mitigation Haiwell has addressed the issue in patch version number Scada-v3.50.1.19, which is available for download on their website: https://en.haiwell.com/app/system/entrance.php?m=include&c=access&a=dodown&lang=en&id=361 https://en.haiwell.com/app/system/entrance.php?m=include&c=access&a=dodown&lang=en&id=361 Relevant CWE: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Metrics CVSS Version Base Score Base Severity Vector String 3.1 10 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H 4.0 10 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H Acknowledgments Fiqram Akmal reported this vulnerability to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. Revision History Initial Release Date: 2026-08-13 Date Revision Summary 2026-08-13 1 Initial Publication Legal Notice and Terms of Use