A denial of service vulnerability (CVE-2021-42260) affecting multiple Rockwell Automation industrial controllers including ControlLogix, CompactLogix, GuardLogix, and their variants can be triggered by crafted data, causing major nonrecoverable faults that require firmware updates or controller resets to recover. Affected versions across firmware branches 34.x, 35.x, 36.x, and 37.x should be updated to the latest patched versions (34.015, 35.014, 36.013, or 37.011 respectively), with CISA recommending network segmentation and isolation of control systems as additional protective measures.
Threat actors are exploiting a newly patched critical security flaw impacting JFrog Artifactory merely days after public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-82329 (CVSS score: 9.8), a case of authentication bypass that could lead to administrative access in Artifactory. "JFrog Artifactory contains an authentication weakness that, under default
CISA argues that the security industry's traditional approach of treating vulnerabilities as individual fixes is ineffective against attackers, and advocates instead for eliminating entire vulnerability classes at their root during software development. Rather than pursuing endless patching cycles, the agency contends that developers can prevent the weaknesses most likely to be exploited by threat actors by addressing fundamental causes in the development process.
Frontier artificial intelligence models like Claude are now being leveraged to identify and exploit vulnerabilities in programmable logic controllers (PLCs) that control critical infrastructure such as water utilities. This development demonstrates how advanced AI systems can be weaponized to streamline the reconnaissance and attack planning phases against operational technology environments.
Security researcher Chaotic Eclipse has released PrettyPrague, a proof-of-concept exploit for a previously unknown privilege escalation vulnerability in GenDigital Avast Antivirus. The zero-day flaw allows attackers to elevate privileges on affected systems running the antivirus software.