VulnerabilityCISA Advisories·4 days ago

Defending Against an Active Threat to Siemens S7 Series PLCs

Federal agencies including CISA, NSA, and FBI have issued a joint advisory warning of active exploitation of Internet-exposed Siemens S7 Series PLCs across critical infrastructure sectors using AI-generated exploitation scripts that masquerade as legitimate monitoring tools. Threat actors are leveraging internet scanning services to identify vulnerable installations running outdated software and using open-source industrial automation libraries combined with AI assistance to develop custom exploitation tools that can read and write to PLC memory and configuration data via the S7comm protocol. Organizations are urged to immediately inventory their S7 Series PLCs, apply critical security patches, isolate PLCs from Internet access, strengthen access controls, and deploy ICS-aware monitoring to detect unauthorized S7comm activity and anomalous behavior patterns.

VulnerabilityCISA Advisories·4 days ago

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added CVE-2026-64849, an MLflow Server-Side Request Forgery vulnerability, to its Known Exploited Vulnerabilities Catalog based on active exploitation evidence. Federal agencies are required under Binding Operational Directive 26-04 to prioritize rapid remediation of vulnerabilities listed in the KEV Catalog, particularly those on publicly exposed assets, while CISA encourages all organizations to adopt similar risk-based vulnerability management practices. Organizations aware of other exploited vulnerabilities can submit them for KEV Catalog consideration if they include a CVE ID, exploitation evidence, and mitigation guidance.

VulnerabilityThe Hacker News·4 days ago

Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation

CISA has added four critical vulnerabilities to its Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild across macOS, SharePoint, vCenter, and Microsoft IKE implementations. One of the flaws affecting Apple macOS, CVE-2026-65400 with a CVSS score of 9.8, involves an improper authentication vulnerability that could enable unauthorized access. Security teams should prioritize patching these actively exploited vulnerabilities across their affected systems.

VulnerabilityMalwarebytes Labs·4 days ago

Update Chrome now: Two critical vulnerabilities fixed

Google has released a Chrome desktop update addressing 15 security vulnerabilities, two of which are critical buffer overflow flaws. Security professionals should prioritize updating to the latest version to mitigate these high-severity issues.

VulnerabilityThe Cyber Express·4 days ago

Critical GitLab Flaw Lets Hackers Alter or Delete Public Projects

GitLab has patched two critical vulnerabilities, including CVE-2026-19478, a code injection flaw with a CVSS score of 9.4 that allows unauthenticated attackers to modify or delete public projects and user data through GraphQL directive exploitation. The second vulnerability, CVE-2026-19650, is a high-severity CSRF flaw in GitLab's GraphQL multiplex query handler that could enable unauthorized mutations via GET requests. Organizations running self-managed GitLab CE/EE versions 18.2 through 19.2 are urged to upgrade immediately to the patched releases (18.11.11, 19.0.8, 19.1.6, or 19.2.4).

VulnerabilityThe Hacker News·4 days ago

Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data

A JSP web shell linked to the Clop threat actor has been discovered targeting PTC Windchill and FlexPLM servers following exploitation of a critical vulnerability, designed to decrypt credentials and exfiltrate engineering data from enterprise PLM environments. ReliaQuest researchers identified the malware as a sophisticated extortion platform with capabilities to map sensitive vault contents, indicating attackers are leveraging compromised PLM systems for targeted data theft operations.

VulnerabilityTenable·4 days ago

Oracle August 2026 Critical Security Patch Update Addresses 925 CVEs

Oracle released its August 2026 Critical Security Patch Update addressing 925 CVEs across 943 patches spanning 23 product families, with 154 patches (16.3%) rated as critical severity. Oracle Fusion Middleware and Oracle Hyperion received the largest share of fixes at 262 patches each, and notably 289 vulnerabilities across both product families can be exploited remotely without authentication. The August CSPU volume nearly quadrupled compared to June's release and represents approximately 65% of July's quarterly CPU volume, indicating a significant expansion in scope for what was intended as a targeted interim release cycle.

VulnerabilityCISA KEV·4 days ago

CVE-2026-64849: MLflow Server-Side Request Forgery Vulnerability

MLflow contains a server-side request forgery vulnerability that can allow attackers to reach internal or cloud metadata services and receive response_status and response_body. Added to CISA's Known Exploited Vulnerabilities catalog with a CVSS score of 9.3 (Critical). Affects MLflow MLflow.

VulnerabilityDark Reading·4 days ago

Critical GitLab Zero-Click Flaw Poses Mitigation Challenges

A critical zero-click vulnerability in GitLab affecting self-managed deployments has emerged with limited technical disclosure, creating detection challenges for affected organizations. The scarcity of technical details surrounding CVE-2026-19478 may hinder remediation efforts and make it difficult for security teams to identify signs of exploitation in their environments.

VulnerabilityDark Reading·5 days ago

'CoSnitch' Attack Tricked Copilot Into Mapping Out Architecture

Researchers have identified a "meta-hacking" technique dubbed CoSnitch that exploits AI services by tricking them into disclosing their own architectural details and security weaknesses. The attack demonstrates how adversaries can leverage AI assistants themselves as tools to uncover sensitive information about the systems they run on.

VulnerabilityQualys·5 days ago

CVE-2026-68820 is in KEV. Here Is What CISA BOD 26-04 Actually Requires Now

Executive Summary CVE-2026-68820 is an actively exploited Windows vulnerability listed in CISA’s Known Exploited Vulnerabilities (KEV) Catalog, with a remediation deadline as suggested by CISA BOD 26-04. CISA BOD 26-04 introduces risk-based remediation timelines ranging from 3 to 14 days, increasing the pressure on teams to move quickly from patch availability to verified remediation. Installing […]

VulnerabilityThe Hacker News·5 days ago

Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps

Varonis Threat Labs disclosed three vulnerabilities in Microsoft Copilot Personal, collectively termed CoSnitch, that exploit an undocumented URL parameter to enable single-click data exfiltration from connected apps and victim Copilot sessions. The flaws allow attackers to silently extract sensitive information through a crafted link, leveraging functionality that Copilot itself exposed through its undocumented parameters.

VulnerabilityThe Hacker News·5 days ago

Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets

Attackers are actively exploiting a server-side request forgery (SSRF) vulnerability in MLflow to steal cloud credentials and secrets from compromised systems. The flaw is among multiple critical vulnerabilities being targeted in both MLflow and FUXA, an open-source industrial automation platform, according to recent threat intelligence from watchTowr and VulnCheck.

VulnerabilityInfosecurity Magazine·5 days ago

Wiz AI Agent Finds Critical Snowflake GitHub Repo Flaw Advanced Security Missed

A Wiz AI agent identified a critical security flaw in Snowflake's GitHub Actions workflow that had previously gone undetected by GitHub Advanced Security scanning. The discovery highlights a potential gap in automated security tooling, where advanced vulnerability scanning failed to catch a vulnerability that required more sophisticated analysis to uncover.

VulnerabilityThe Register·5 days ago

CISA gives feds 3 days to fix actively exploited Ray RCE bug

CISA has issued a three-day deadline for federal agencies to patch an actively exploited remote code execution vulnerability in Ray. The vulnerability is being leveraged through phishing and malvertising campaigns targeting developers as an initial access vector to corporate networks.

VulnerabilityInfosecurity Magazine·5 days ago

Enterprise Applications Carry 4.31x More Critical and High Vulnerabilities

Enterprise applications contain significantly more critical and high-severity vulnerabilities compared to other software types, according to research from Sonatype. The findings highlight a growing security gap as organizations accelerate their enterprise software development efforts while vulnerability exposure increases in this critical application segment.

VulnerabilityMalwarebytes Labs·5 days ago

Apple fixes another image-processing flaw that could allow code execution

Apple has released updates addressing 27 vulnerabilities across iOS, iPadOS, and macOS Tahoe, with a notable image-processing flaw among them that could potentially lead to code execution. The severity and attack vector details for this flaw remain unclear from the available information.

Load more