ownCloud contains an improper authentication vulnerability that allows an attacker to access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. Added to CISA's Known Exploited Vulnerabilities catalog with a CVSS score of 9.8 (Critical). Affects ownCloud ownCloud.
Academic researchers from the University of Toronto have disclosed GPUThor, a Rowhammer attack that exploits GDDR6 memory in NVIDIA RTX A6000 workstation GPUs to bypass ECC protections and achieve privilege escalation to root access. The attack defeats the error correction mechanism that NVIDIA recommends as the primary mitigation against GPU Rowhammer vulnerabilities, enabling both denial-of-service and root-level system compromise. The findings highlight a critical vulnerability in GPU memory security that affects professional-grade NVIDIA accelerators.
CISA has warned water utilities to identify and secure internet-exposed programmable logic controllers (PLCs) following July attacks that compromised over 100 systems in the US water and wastewater sector. The incidents demonstrated the vulnerability of industrial control systems when directly accessible from the internet, prompting CISA to release guidance beyond standard incident reporting. The agency is emphasizing proactive discovery and remediation of exposed PLCs as a critical defensive measure for critical infrastructure operators.
CISA has added six vulnerabilities to its Known Exploited Vulnerabilities catalog, including a high-severity flaw affecting Citrix NetScaler ADC and NetScaler Gateway that shows evidence of active exploitation in the wild. The addition signals that these flaws, spanning NetScaler, Linux, and SQL Server products, are actively being leveraged by threat actors and should be prioritized for patching by affected organizations.
Ubiquiti has patched three critical security vulnerabilities rated 10.0 across its UniFi product line as part of a larger disclosure addressing 22 total flaws. Nearly all of the disclosed vulnerabilities were rated critical, with severity scores of 9.0 or higher.