Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Researchers have identified a sophisticated attack campaign involving the GoSerpent backdoor and other tools like Stowaway RAT, targeting government entities in Southeast Asia. These attacks occur in two phases, with the goal of stealing sensitive data. The use of advanced techniques for data collection and exfiltration indicates a high level of sophistication among the attackers. This is concerning for national security and could impact the integrity of government operations in the region. As these threats evolve, it's crucial for organizations to bolster their cybersecurity defenses to protect against such persistent intrusions.

Read Original

Rockwell Automation has identified several vulnerabilities in its CompactLogix, ControlLogix, Compact GuardLogix, and GuardLogix products that could allow attackers to cause a denial-of-service (DoS) condition. The affected versions include various models of CompactLogix and ControlLogix controllers, specifically those running versions V35.015 or lower for the 5370 and 5570 series, and V34.012 or V35.011 for the 5380, 5480, and 5580 series. If exploited, these vulnerabilities could lead to the devices entering a non-recoverable fault state, disrupting operations in critical manufacturing sectors. Users are urged to update their systems to the latest versions to mitigate these risks, as the vulnerabilities have a high severity rating (CVSS score of 8.6).

Read Original
Critical
Siemens SICAM 8

All CISA Advisories

Siemens has identified multiple vulnerabilities in its SICAM 8 product line, which could lead to denial of service and other security risks. The affected products include the CPCI85 Central Processing/Communication and SICORE Base system versions prior to 26.20.0. These vulnerabilities could allow attackers to disrupt services, install malicious firmware, or gain unauthorized access to critical system functions. Siemens has released updates for the affected products and strongly advises users to upgrade to the latest versions to mitigate these risks. This is particularly important for operators in critical infrastructure sectors like energy and manufacturing, where such vulnerabilities could have serious implications.

Read Original
Critical
Rockwell Automation Flex 5000 Adapter

All CISA Advisories

Rockwell Automation has reported a vulnerability in its Flex 5000 Adapter, specifically version 6.011, that could lead to a denial-of-service (DoS) condition. This issue arises from improper handling of specific CIP packets, which can cause the adapter to become unresponsive, necessitating a power cycle to restore functionality. The vulnerability is classified as CVE-2026-12659 and has a CVSS score of 7.5, indicating a high severity level. Users are advised to upgrade to version 6.012 to mitigate this risk. For those unable to update, Rockwell Automation recommends following its security best practices to safeguard their systems. This vulnerability is particularly concerning for sectors involved in critical manufacturing and information technology, affecting organizations globally.

Read Original
Critical
SALTO ProAccess Space

All CISA Advisories

A vulnerability in SALTO ProAccess Space has been identified, allowing authenticated attackers to escalate their privileges and access areas outside their designated partitions. This flaw affects versions below 6.13 and requires valid operator credentials and the partition feature to be enabled. Organizations using this system should urgently upgrade to version 6.13 to mitigate the risk. The vulnerability, designated as CVE-2026-11889, poses a significant threat as it could allow unauthorized access to spaces managed by the system, particularly in sectors such as commercial facilities and critical manufacturing. Users are advised to enhance their security by limiting operator account permissions and considering operational adjustments, such as disabling partitioning if possible.

Read Original

A serious vulnerability has been identified in Rockwell Automation's FactoryTalk DataMosaix Private Cloud software, affecting versions up to 8.02. This flaw, classified as CVE-2026-9292, allows authenticated attackers to inject malicious scripts into the server due to improper handling of user input. If exploited, this could lead to account takeovers, credential theft, or redirection to harmful websites when other users access the compromised pages. Rockwell Automation recommends that users upgrade to version 8.03 or later to mitigate the risk. For those unable to upgrade, following security best practices outlined by Rockwell is advised. Although there have been no reports of active exploitation of this vulnerability, organizations are urged to enhance their security measures to protect against potential threats.

Read Original

Rockwell Automation has reported a vulnerability affecting their 1756-EN2, 1756-EN3, and 1756-ENBT communication modules. Specifically, versions 1756-EN3 and 1756-EN2 up to V12.001, and 1756-ENBT V6.006 are susceptible to a denial-of-service attack due to improper validation of connection packets. An attacker on the same network could exploit this issue by sending malicious packets that disrupt device connections, although these connections can recover immediately. This vulnerability is particularly concerning for industries relying on critical manufacturing infrastructure, as it could lead to significant operational disruptions. Users are advised to update their devices to version 12.002 to mitigate this risk.

Read Original
Actively Exploited

The Cybersecurity and Infrastructure Security Agency (CISA) has added three vulnerabilities to its Known Exploited Vulnerabilities Catalog due to evidence that they are being actively exploited. The vulnerabilities include two related to Fortinet's FortiSandbox, identified as CVE-2026-25089 and CVE-2026-39808, both of which are OS command injection flaws. The third vulnerability, CVE-2026-58644, affects Microsoft SharePoint and involves the deserialization of untrusted data. These vulnerabilities present serious risks, especially to federal agencies, which are urged to prioritize their remediation as mandated by CISA’s Binding Operational Directive 26-04. While this directive applies specifically to federal civilian agencies, CISA encourages all organizations to adopt similar practices for managing vulnerabilities. Organizations are also invited to report any exploited vulnerabilities not currently listed in the KEV Catalog.

Read Original
Critical
Rockwell Automation Arena

All CISA Advisories

Rockwell Automation's Arena software has several critical vulnerabilities that could allow attackers to execute arbitrary code. These vulnerabilities affect versions up to V17.00.00 and include issues in components like model.exe, expmt.exe, linker.exe, and siman.exe. The problems arise from improper validation of user-supplied data, leading to out-of-bounds writes. Users are urged to update to version V17.00.01 to mitigate the risks. This situation is particularly concerning for sectors involved in critical manufacturing, as the software is used worldwide. No active exploitation of these vulnerabilities has been reported yet, but organizations should remain vigilant.

Read Original
Critical
AutomationDirect Productivity Suite

All CISA Advisories

AutomationDirect's Productivity Suite has several critical vulnerabilities that could be exploited by attackers with local or physical access. These vulnerabilities, affecting versions up to 4.6.2.2, include out-of-bounds writes and reads, which could lead to memory corruption, information disclosure, and system instability. Users are strongly advised to update to version 4.7.0.47 or later to mitigate these risks. In the meantime, AutomationDirect recommends several compensating controls, such as disconnecting affected workstations from external networks and restricting access to authorized personnel only. The vulnerabilities affect critical manufacturing sectors worldwide, emphasizing the need for immediate attention from users of the software.

Read Original

A vulnerability has been identified in NASA's Core Flight System (cFS) Health & Safety (HS) Application, specifically affecting versions prior to 7.0.1. This flaw allows attackers to cause the application to crash when processing certain telemetry requests, resulting in a denial-of-service condition. The vulnerability, categorized as CVE-2026-15352, poses a risk to critical infrastructure, particularly in the transportation sector, as the application is used globally. Users are urged to update to version 7.0.1 to mitigate this risk. While there have been no reports of the vulnerability being actively exploited in the wild, organizations are advised to take precautionary measures to secure their systems against potential attacks.

Read Original
Actively Exploited

Over 20 Brazilian government websites have been hijacked as part of a campaign by a group known as PhantomEnigma. These sites were repurposed to deliver malware, which poses a significant risk to users who visit them. Researchers from ANY.RUN discovered previously unknown backdoor tactics and complex relationships within the cybercriminal infrastructure involved. This incident not only affects the integrity of government websites but also puts the data and security of users at risk, highlighting the ongoing challenges in protecting public digital resources. It serves as a reminder for both users and government agencies to remain vigilant against such attacks.

Read Original

Two individuals have been sentenced to five and a half years in prison for their involvement in a cyber-attack against Transport for London (TfL) in 2024. The attackers pleaded guilty to offenses under the Computer Misuse Act, revealing a case of reckless bravado that led to significant disruptions in TfL's operations. The attack not only targeted essential transport infrastructure but also raised concerns about the security of public services. This incident serves as a stark reminder of the vulnerabilities faced by critical systems and the need for stringent cybersecurity measures. The jail time reflects the seriousness of such cyber crimes in today's digital landscape.

Read Original
Critical
OkoBot Malware Uses ClickFix, Hidden Browser Extensions to Steal Crypto Data

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

Kaspersky has reported a new malware called OkoBot that specifically targets cryptocurrency users. The malware masquerades as fake software, tricking users into downloading it. Once installed, OkoBot steals sensitive information such as wallet files, seed phrases, and passwords, while also recording user activity within wallet applications. This poses a significant risk to cryptocurrency holders, as their assets could be compromised. Users need to be cautious about the software they install and ensure they are using legitimate applications to protect their digital currencies.

Read Original

Daxin, an advanced malware linked to a Chinese threat actor, has been detected again after a four-year gap, this time within a manufacturing firm in Taiwan. This kernel-mode rootkit, identified as 'srt64.sys', was first reported by Symantec in March 2022. Alongside Daxin, researchers have also discovered a new backdoor called Stupig, which has not been previously documented. The resurgence of Daxin raises concerns about targeted attacks on critical infrastructure, particularly in sectors like manufacturing that are vital to the economy. Organizations in Taiwan and similar industries need to be vigilant and reassess their cybersecurity measures to protect against these sophisticated threats.

Read Original
PreviousPage 100 of 369Next