Latest Intelligence
CISA Releases Thirteen Industrial Control Systems Advisories
CISA has released thirteen advisories addressing vulnerabilities in various Industrial Control Systems (ICS) as of May 20, 2025. These advisories are crucial for enhancing security measures in critical infrastructure, as they inform users of potential exploits and necessary mitigations.
Schneider Electric Galaxy VS, Galaxy VL, Galaxy VXL
Schneider Electric's Galaxy VS, Galaxy VL, and Galaxy VXL products are affected by a critical vulnerability that allows for unauthenticated remote code execution due to missing authentication in the SSH server. This vulnerability poses significant risks to critical infrastructure sectors and requires immediate attention to mitigate potential exploits.
Siemens Siveillance Video
Siemens Siveillance Video has a vulnerability related to missing encryption of sensitive data, which could allow unauthorized access to system configuration files and affect backup data. The vulnerability, identified as CVE-2025-1688, poses a significant risk as it can be exploited remotely, necessitating immediate attention from users to mitigate potential security breaches.
National Instruments Circuit Design Suite
The National Instruments Circuit Design Suite has multiple vulnerabilities, including out-of-bounds writes and reads, as well as a stack-based buffer overflow, which could allow attackers to execute arbitrary code or disclose information. Users are advised to update to version 14.3.1 or later to mitigate these risks.
The Crowded Battle: Key Insights from the 2025 State of Pentesting Report
The 2025 State of Pentesting Report highlights the challenges faced by CISOs in managing security alerts and cyber risks, revealing a complex landscape of progress and shifting strategies in the cybersecurity realm. The insights from 500 surveyed CISOs underscore the importance of adapting to evolving threats and improving response mechanisms.
CloudSEK Raises $19 Million for Threat Intelligence Platform
CloudSEK, a threat protection and intelligence firm, has successfully raised $19 million in funding from a combination of new and existing investors. This funding is significant as it will enhance their threat intelligence platform, potentially improving cybersecurity measures for organizations.
O2 Service Vulnerability Exposed User Location
A vulnerability in O2's implementation of the IMS standard has led to the exposure of user location data in network responses. This issue raises significant privacy concerns for users, as their location information can be accessed through the network.
Madhu Gottumukkala Officially Announced as CISA Deputy Director
Madhu Gottumukkala has been officially appointed as the Deputy Director of the Cybersecurity and Infrastructure Security Agency (CISA). He joins CISA from the Bureau of Information and Technology in South Dakota, marking a significant leadership change within the agency.
Chinese Hackers Deploy MarsSnake Backdoor in Multi-Year Attack on Saudi Organization
Chinese hackers, identified as UnsolicitedBooker, have been targeting an international organization in Saudi Arabia using a new backdoor called MarsSnake. This multi-year attack highlights the ongoing cybersecurity threats posed by state-aligned actors, emphasizing the need for robust security measures.
Go-Based Malware Deploys XMRig Miner on Linux Hosts via Redis Configuration Abuse
A new cryptojacking campaign named RedisRaider is targeting publicly accessible Redis servers to deploy the XMRig miner on Linux hosts. This campaign highlights the risks associated with misconfigured Redis instances and the exploitation of legitimate commands for malicious purposes.
Malicious PyPI Packages Exploit Instagram and TikTok APIs to Validate User Accounts
Researchers have identified malicious packages on the Python Package Index (PyPI) that exploit TikTok and Instagram APIs to validate stolen email addresses. These packages, which have since been removed, highlight a significant security threat to users of these social media platforms.
'Operation RoundPress' Targets Ukraine in XSS Webmail Attacks
Operation RoundPress is a cyber-espionage campaign targeting Ukrainian government entities through sophisticated spear-phishing attacks that exploit XSS vulnerabilities. This highlights the ongoing threat to national security and the importance of cybersecurity measures in protecting sensitive information.
BreachRx Lands $15 Million as Investors Bet on Breach-Workflow Software
BreachRx, a San Francisco-based startup specializing in incident response coordination, has successfully secured $15 million in a Series A funding round led by Ballistic Ventures. This investment highlights the growing interest in breach-workflow software as organizations increasingly prioritize effective incident response solutions.
S. Dakota CIO Gottumukkala Signs on as CISA Deputy Director
S. Dakota CIO Gottumukkala has been appointed as the Deputy Director of the Cybersecurity and Infrastructure Security Agency (CISA), a significant role as the agency seeks to fill its leadership gap following the departure of its previous director, Easterly. Bridget Bean is currently serving in an acting capacity until a permanent director is appointed.
Legal Aid Agency Warns Lawyers, Defendants on Data Breach
The Legal Aid Agency has shut down its online service following a cyberattack, raising concerns about the security of sensitive legal data. The agency assures that individuals in need of legal assistance will still have access to necessary support despite the breach.