VulnerabilityCISA Advisories·1 week ago

Hitachi Energy APM Edge Product

Hitachi Energy APM Edge product versions 6.10 and prior contain two critical Linux kernel vulnerabilities (CVE-2026-43284 and CVE-2026-43500) affecting the IPsec ESP and RxRPC subsystems that allow local unprivileged users to escalate privileges to root by exploiting write-what-where and out-of-bounds write conditions. Both vulnerabilities carry CVSS scores of 8.8 and 7.8 respectively, with mitigation available through disabling the vulnerable kernel modules (esp4, esp6, and rxrpc). The flaws affect critical infrastructure worldwide and are exploitable by any local user with the ability to load these kernel modules.

VulnerabilityCISA Advisories·1 week ago

AVEVA Enterprise SCADA

CISA has published an advisory for CVE-2025-7639 affecting AVEVA Enterprise SCADA versions 2022 through 2025, a deserialization vulnerability in the Binary Formatter that could allow authenticated attackers to execute code. AVEVA recommends disabling Binary Formatter serialization, migrating to JSON-based serialization, and implementing defensive measures including permission audits and network perimeter hardening, with detailed mitigation steps available in KB117814.

VulnerabilityCISA Advisories·1 week ago

Siemens Siveillance Video

Siemens Siveillance Video Management Servers contain a critical OS command injection vulnerability (CVE-2026-3014, CVSS 9.1) affecting versions V2023 R3, V2024 R1, and V2025, which could allow users with edit permissions to execute arbitrary code. Siemens has released patched versions and recommends immediate updates to V23.3.27, V24.1.16, or V25.1.15 respectively. CISA advises protecting network access to affected systems and implementing defense-in-depth strategies to minimize exploitation risk.

VulnerabilityCISA Advisories·1 week ago

Siemens License Server (SLS)

Siemens License Server (SLS) contains two critical vulnerabilities: CVE-2026-69108, a local privilege escalation flaw in versions before 5.1 that could allow root-level command execution, and CVE-2026-69109, a path traversal vulnerability in versions before 5.3 that permits remote arbitrary file access. Siemens recommends immediate patching to the latest versions and advises restricting network access to the affected systems as a precautionary measure.

VulnerabilityCISA Advisories·1 week ago

Flow Neuroscience FL-100

CISA has issued an advisory for CVE-2026-18164 affecting Flow Neuroscience FL-100 brain stimulation devices, which contain hard-coded credentials that allow attackers within Bluetooth range to manipulate stimulation parameters and override safety limits. The vulnerability, with a CVSS score of 8.1, impacts devices manufactured before July 2026 and requires physical proximity to exploit. Users are advised to install the latest firmware updates via the Flow app to remediate the issue.

VulnerabilityCISA Advisories·1 week ago

Siemens Solid Edge

Siemens Solid Edge versions SE2025 (before V225.0.15) and SE2026 (before V226.0.7) are vulnerable to seven high-severity file parsing flaws affecting PAR, PSM, and DFT file formats, each with a CVSS score of 7.8. These vulnerabilities—including out-of-bounds read/write and use-after-free conditions—can be exploited by local attackers to execute arbitrary code or crash the application through specially crafted files. Siemens has released patched versions and strongly recommends immediate updates to mitigate risk in critical manufacturing environments.

VulnerabilityCISA Advisories·1 week ago

Johnson Controls Metasys

A persistent cross-site scripting vulnerability in Johnson Controls Metasys building automation systems (CVE-2026-34491) allows low-privilege users to inject malicious payloads via crafted URLs that execute in other users' sessions, including administrators, with a CVSS score of 8. Affected versions include Metasys 12 and 13 (end of support), Metasys 14 prior to v14.1.5, and Metasys 15 prior to v15.0.1, while patches or fixes are available for later versions. CISA recommends restricting network access to the Metasys UI, implementing network segmentation, enforcing least-privilege access, and deploying web application firewalls to mitigate exploitation risk.

VulnerabilityCISA Advisories·1 week ago

Siemens Simcenter Femap

Siemens Simcenter Femap versions prior to V2606.0001 contain two out-of-bounds read vulnerabilities in BMP file parsing that could allow arbitrary code execution if a user opens a malicious file. With a CVSS score of 7.8, the vulnerabilities affect critical manufacturing infrastructure worldwide, and Siemens has released version V2606.0001 as the fix. Organizations should update immediately and restrict network access to affected systems pending remediation.

Nation-StateDark Reading·1 week ago

'Jewelbug' APT Balances State Espionage & Cryptocurrency Theft

Researchers have identified a threat actor group operating under the moniker 'Jewelbug' that manages both state-sponsored espionage campaigns and financially motivated cryptocurrency theft operations from a single command infrastructure. This dual operational model suggests a flexible mercenary approach where the same attackers pivot between geopolitical intelligence gathering and direct financial gain depending on client objectives. The consolidated nature of their operations indicates sophisticated operational security practices that allow them to compartmentalize distinct mission types while maintaining unified command and control.

Policy & LegalWired Security·1 week ago

CBP Workers Allegedly Used Government Databases to Spy on Exes, Crushes, and Colleagues

U.S. Customs and Border Protection workers have allegedly exploited government databases to conduct unauthorized surveillance of personal contacts, including romantic interests and colleagues, according to records reviewed by WIRED. The documented cases reveal a pattern of internal tool misuse affecting hundreds of individuals, highlighting significant insider threat vulnerabilities within the agency's data access controls.

Data BreachInfosecurity Magazine·1 week ago

ICO Reprimands Criminal Records Office After 2023 Breach

The Information Commissioner's Office has formally reprimanded ACRO (the criminal records office) following a 2023 breach that exposed inadequate security practices. The agency found that failures in both patching and security monitoring directly contributed to the incident. This enforcement action underscores the regulatory consequences of neglecting fundamental cybersecurity hygiene for organizations handling sensitive data.

OtherKaspersky Securelist·1 week ago

Armored Likho expands its cyber-espionage toolkit

Kaspersky researchers have identified a new campaign by Armored Likho that masquerades as fundraising efforts to deliver an updated Still Toolkit designed to extract Telegram data and conduct surveillance on infected systems. The expanded toolkit represents an evolution in the threat actor's cyber-espionage capabilities, enabling more sophisticated data theft and eavesdropping operations against targeted victims.

VulnerabilityDark Reading·1 week ago

Belgium's eID Authentication Opens Citizen Accounts to RCE

Belgium's electronic ID system suffered a critical compromise when severe vulnerabilities in a key browser extension undermined the trust framework protecting citizen authentication, enabling remote code execution attacks. The incident highlights systemic weaknesses in how browser extensions are secured and managed within critical authentication infrastructure.

VulnerabilityThe Register·1 week ago

Chinese Loongson processors have leaky caches, researchers find

Researchers have discovered cache side-channel vulnerabilities in Chinese Loongson processors that could allow attackers to extract sensitive data. The vulnerability is particularly concerning because it can be exploited even from within a guest virtual machine, expanding the potential attack surface for threat actors.

MalwareRecorded Future·1 week ago

Malware Crypting Services and the Threat Actors Who Sell Them

Recorded Future's Insikt Group has analyzed 24 threat actors operating in the malware crypting services market, revealing how these services enable evasion of security tools through obfuscation. The research examines the market dynamics of these offerings and highlights the evasion techniques employed, while recommending that defenders shift focus toward behavioral detection methods rather than relying solely on static analysis. This analysis provides threat intelligence professionals with insights into a key enabler of malware distribution and guidance for more effective detection strategies.

Load more