1
0
1
0
1
0
1
0
0
1
1
0
1
0
VulnHub

AI-Powered Cybersecurity Intelligence

Latest Intelligence

All CISA Advisories
Siemens SINEC NMS

Siemens SINEC NMS has a vulnerability related to SQL injection that could allow authenticated low privileged attackers to escalate privileges. The vulnerability affects versions prior to V4.0 SP1 and has a CVSS v4 score of 8.7, indicating a significant risk. Read Original »


Impact: Siemens SINEC NMS: Versions prior to V4.0 SP1

Remediation: Update to V4.0 SP1 or later version; protect network access with appropriate mechanisms.

CVEExploitVulnerabilityUpdate

Added:

All CISA Advisories
Rockwell Automation FactoryTalk ViewPoint

Rockwell Automation's FactoryTalk ViewPoint has a vulnerability that allows unauthenticated attackers to perform XML external entity injection, potentially causing a temporary denial-of-service. The issue affects certain versions of the PanelView Plus terminals and has been assigned CVE-2025-9066. Read Original »


Impact: PanelView Plus 7 Terminal: Version 14 and prior

Remediation: Upgrade to Panel View Plus 7 Standard and Performance Series A v12, v13, v14 patch AID BF30506 or Performance Series B V14.103; follow security best practices.

CVEVulnerabilityPatchUpdate

Added:

All CISA Advisories
CISA Releases Thirteen Industrial Control Systems Advisories

CISA has released thirteen advisories addressing security vulnerabilities in various Industrial Control Systems (ICS) on October 16, 2025. These advisories aim to inform users and administrators about current security issues and provide guidance on mitigations. Read Original »


Impact: Rockwell Automation, Siemens, Hitachi Energy, Schneider Electric, Delta Electronics

Remediation: CISA encourages users and administrators to review newly released ICS advisories for technical details and mitigations.

Update

Added:

All CISA Advisories
Rockwell Automation ArmorStart AOP

Rockwell Automation's ArmorStart AOP has a vulnerability that can lead to a denial-of-service condition due to uncaught exceptions when invalid values are input into COM methods. This issue affects versions V2.05.07 and prior, with no fix currently available. Read Original »


Impact: Rockwell Automation ArmorStart AOP

Remediation: Follow security best practices and minimize network exposure for control system devices.

CVEVulnerabilityUpdate

Added:

All CISA Advisories
Siemens SiPass Integrated

Siemens SiPass Integrated has several vulnerabilities that could allow unauthorized access and manipulation of user accounts, including buffer overflow and cross-site scripting issues. Users are advised to update to the latest version and implement security measures to mitigate risks. Read Original »


Impact: Siemens SiPass integrated

Remediation: Update to V3.0 or a later version; restrict access to authorized personnel; avoid uploading untrusted image files.

PhishingCVEVulnerabilityUpdate

Added:

All CISA Advisories
Siemens TeleControl Server Basic

Siemens TeleControl Server Basic has a critical vulnerability that allows unauthenticated remote attackers to obtain user password hashes and perform authenticated operations on the database service. The vulnerability, identified as CVE-2025-40765, has a high CVSS score indicating significant risk. Read Original »


Impact: Siemens TeleControl Server Basic V3.1: Version V3.1.2.2 and up to but not including V3.1.2.3

Remediation: Restrict access to port 8000 to trusted IP addresses and update to V3.1.2.3 or later version.

CVEVulnerabilityUpdate

Added:

All CISA Advisories
Rockwell Automation FactoryTalk Linx

Rockwell Automation's FactoryTalk Linx has critical vulnerabilities related to privilege chaining that allow authenticated attackers to gain SYSTEM-level access, potentially compromising all files and system resources. Two specific CVEs, CVE-2025-9067 and CVE-2025-9068, have been identified, both with a CVSS v4 score of 8.5. Read Original »


Impact: Rockwell Automation FactoryTalk Linx: Versions 6.40 and prior

Remediation: Install the Microsoft patch for the MSI issue and upgrade to version 6.50 or later.

WindowsPhishingCVEMicrosoftVulnerabilityPatchUpdate

Added:

SecurityWeek
Fuji Electric HMI Configurator Flaws Expose Industrial Organizations to Hacking

Fuji Electric has identified vulnerabilities in its HMI Configurator that could expose industrial organizations to hacking risks. In response, the company has released patches, and Japan's JPCERT has alerted organizations about these security issues. Read Original »


Impact: Fuji Electric HMI Configurator

Remediation: Patches released

Added:

The Hacker News
Architectures, Risks, and Adoption: How to Assess and Choose the Right AI-SOC Platform

Security Operations Centers (SOCs) are facing immense challenges due to the overwhelming volume of alerts, with organizations averaging 960 alerts daily and larger enterprises exceeding 3,000. A significant portion of these alerts remains uninvestigated, indicating a critical need for enhanced solutions such as AI-driven platforms. Read Original »


Impact: Not specified

Remediation: Not specified

Added:

The Hacker News
Hackers Deploy Linux Rootkits via Cisco SNMP Flaw in "Zero Disco' Attacks

Cybersecurity researchers have revealed a campaign named Operation Zero Disco, which exploits a vulnerability in Cisco IOS Software and IOS XE Software to deploy Linux rootkits on older systems. The vulnerability, identified as CVE-2025-20352, has a CVSS score of 7.7, indicating a significant security risk. Read Original »


Impact: Cisco IOS Software, Cisco IOS XE Software

Remediation: Not specified

LinuxiOSCVECiscoVulnerability

Added:

SecurityWeek
Cisco Routers Hacked for Rootkit Deployment

Threat actors are exploiting a recent Cisco zero-day vulnerability, CVE-2025-20352, to deploy a rootkit on older networking devices. This highlights a significant security risk for users of affected Cisco routers. Read Original »


Impact: Cisco routers

Remediation: Not specified

CVEZero-dayCiscoVulnerability

Added:

SecurityWeek
US Charges Cambodian Executive in Massive Crypto Scam and Seizes More Than $14 Billion in Bitcoin

The U.S. government has charged a Cambodian executive for his role in a large-scale cryptocurrency scam that involved exploiting forced labor to defraud investors. Over $14 billion in bitcoin has been seized as part of the investigation, with funds allegedly used to purchase luxury items. Read Original »


Impact: Not specified

Remediation: Not specified

Added:

The Hacker News
Beware the Hidden Costs of Pen Testing

The article emphasizes the importance of a tailored approach to penetration testing, warning against traditional methods that can be inflexible and costly. It highlights that while pen testing is beneficial for securing IT systems, a one-size-fits-all strategy may lead to suboptimal outcomes. Read Original »


Impact: Not specified

Remediation: Not specified

Added:

SecurityWeek
Four-Year Prison Sentence for PowerSchool Hacker

Matthew Lane was sentenced to four years in prison after pleading guilty to extorting two companies by hacking into their networks and stealing information. This case highlights the ongoing issues of cybersecurity threats and the legal consequences for such criminal activities. Read Original »


Impact: Not specified

Remediation: Not specified

Added:

The Hacker News
ThreatsDay Bulletin: $15B Crypto Bust, Satellite Spying, Billion-Dollar Smishing, Android RATs & More

The article highlights the rapid evolution of online threats where everyday technology is misused for malicious purposes. Hackers are increasingly leveraging trusted tools and platforms to deceive users and gain unauthorized access. Read Original »


Impact: Not specified

Remediation: Not specified

Android

Added: