Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

On August 12, President Trump signed a National Security Presidential Memorandum that permits vetted private companies in the U.S. to conduct offensive cyber operations against foreign criminal networks. This initiative aims to empower these companies to confront international cyber threats under the oversight of the U.S. government. By allowing private entities to engage in hacking operations, the administration seeks to bolster national security and tackle issues such as ransomware and other cyber crimes originating from abroad. This move could change how the U.S. approaches cybersecurity, potentially leading to more aggressive stances against foreign adversaries. However, it raises questions about the accountability and ethical considerations of allowing private firms to engage in such activities.

Read Original

Researchers from the CISPA Helmholtz Center for Information Security and KU Leuven have found that certain RISC-V processors are vulnerable to all major Spectre variants. This includes the commercially available SiFive P550 and T-Head Xuantie C910/C920 chips. Spectre vulnerabilities can allow attackers to exploit speculative execution features in processors, potentially accessing sensitive information. This discovery is significant as it affects a new architecture that is gaining traction in various applications, including cloud computing and embedded systems. Companies using these processors need to be aware of these vulnerabilities and take necessary precautions to safeguard their data.

Read Original
Actively Exploited

Just five days after Broadcom disclosed a serious vulnerability in its vCenter product, attackers began to exploit it. This flaw, which has been classified as critical-severity, poses significant risks to organizations using affected versions of vCenter. The rapid exploitation indicates that cybercriminals are quick to act on newly revealed vulnerabilities, which can lead to unauthorized access and potential data breaches. Companies using vCenter should prioritize applying the necessary patches to protect their systems from these attacks. The situation serves as a reminder of the importance of timely updates and vigilance in cybersecurity practices.

Read Original

Researchers have identified a new information-stealing malware targeting macOS users, named AmnesiaStealer. This Rust-based malware can hijack Chromium web browsers, allowing attackers to access and steal session data. AmnesiaStealer is distributed through a fake GitHub download page that pretends to offer legitimate software, misleading users into downloading it. This poses a significant risk to users who might unknowingly provide sensitive information, as attackers gain live control of their browsing sessions. It’s crucial for users to be vigilant about where they download software and to ensure they are using official sources to avoid falling victim to such scams.

Read Original

A significant vulnerability in Microsoft SharePoint, tracked as CVE-2026-55040, is being actively exploited by attackers. This flaw, which allows for the bypassing of authentication and the impersonation of users, can lead to unauthorized access to files and the ability to alter data. Microsoft issued a patch for this vulnerability during its July 2026 Patch Tuesday updates, but the release of proof-of-concept exploit code by Rapid7 has prompted immediate exploitation in the wild. Organizations using SharePoint should prioritize applying the provided security updates to protect against potential data breaches and unauthorized modifications. The situation highlights the ongoing risks associated with unpatched vulnerabilities, especially when exploit tools become publicly available.

Read Original

A recently discovered vulnerability in WordPress version 7.0.4 allows attackers with Author-level permissions or higher to execute remote code by uploading malicious Postscript files. This flaw poses a significant risk, as it could enable unauthorized access and control over affected WordPress sites. Users with outdated versions of WordPress should update immediately to prevent potential exploitation. The vulnerability emphasizes the need for regular software updates and security practices among WordPress site administrators to safeguard their platforms against such attacks. Keeping software up-to-date is crucial in the ongoing battle against cyber threats.

Read Original

The White House has given the green light for government-directed offensive cyber operations aimed at tackling transnational groups. This decision raises concerns about potential escalation in cyber conflicts and the challenges associated with attributing cyberattacks to specific perpetrators. The involvement of the private sector in these operations could lead to a more dynamic but risky cyber environment. Experts warn that without clear guidelines, the risk of unintended consequences increases, which could further complicate international relations and cybersecurity protocols. This move signals a shift in how the U.S. approaches cyber warfare and defense, emphasizing a more aggressive stance against threats from organized groups operating across borders.

Read Original

On August 12, 2026, President Donald J. Trump authorized a new National Security Presidential Memorandum that expands the ability of federal agencies to conduct offensive cyber operations against foreign criminal syndicates. This move aims to strengthen the U.S. response to cyber threats originating from outside the country, particularly those targeting American infrastructure and businesses. By giving agencies more flexibility, the administration hopes to deter attacks and protect national security. The directive signals a more aggressive stance in the ongoing battle against cybercrime, which has seen a rise in sophisticated attacks from various international groups. This development is significant as it could lead to more proactive measures in the cyber realm, impacting how foreign entities operate online.

Read Original
Critical
Siemens Parasolid

All CISA Advisories

Siemens has identified a serious vulnerability in its Parasolid software, specifically an out-of-bounds read issue affecting versions 38.0 and 38.1. This vulnerability arises when the application processes specially crafted X_T files, which could allow attackers to crash the software or run arbitrary code. Siemens has responded by releasing updated versions, urging users to upgrade to Parasolid V38.0.235 or later for version 38.0 and V38.1.230 or later for version 38.1. This is particularly important for organizations in the critical manufacturing sector, as the flaw can potentially impact operational stability. Siemens also recommends enhancing network security measures to protect devices from unauthorized access.

Read Original
Critical
Siemens License Server (SLS)

All CISA Advisories

Siemens License Server (SLS) has been found to contain multiple vulnerabilities that could allow attackers to gain elevated privileges and access arbitrary files on affected systems. Specifically, versions prior to 5.1 and 5.3 are vulnerable to local privilege escalation and path traversal, respectively. The first vulnerability, CVE-2026-69108, stems from an insecure sudoers policy, while CVE-2026-69109 results from inadequate input sanitization. Siemens recommends that users update to version 5.1 or later for the privilege escalation issue and to version 5.3 or later for the path traversal vulnerability. This is crucial as the vulnerabilities could lead to significant security breaches, including complete system compromise.

Read Original
Critical
Siemens Desigo DXR and PXC Controllers

All CISA Advisories

Siemens has identified a vulnerability affecting its Desigo DXR and PXC controllers that could enable attackers to initiate denial of service (DoS) conditions by sending malformed BACnet packets. This issue can cause the devices to stop responding to BACnet queries, requiring a reset or reboot for recovery. The affected versions include Desigo DXR2, PXC3, PXC4, PXC5.E003, PXC5.E24, and PXC7, all of which are used across various sectors such as healthcare, energy, and transportation. Siemens has released updated versions to address this vulnerability and strongly urges users to apply these updates to maintain device functionality and security.

Read Original
Critical
Johnson Controls Inc. Airwall

All CISA Advisories

Johnson Controls Inc. has identified serious vulnerabilities in its Airwall software, specifically affecting versions 4.0.4 and earlier. These flaws could let attackers decrypt sensitive data, bypass authentication, and access unauthorized files on the system. One vulnerability involves a hardcoded cryptographic key that is the same across all installations, making it easier for attackers to exploit. Another allows for arbitrary file read through inadequate validation of user input, potentially exposing sensitive configuration files or credentials. Companies using affected versions are urged to upgrade to version 4.1.0 or later and implement security best practices to mitigate risks.

Read Original
Critical
Johnson Controls Metasys

All CISA Advisories

A serious vulnerability has been identified in Johnson Controls' Metasys building automation system, affecting versions 12, 13, 14, and 15. This flaw allows a low-privilege user to inject malicious code into the Metasys user interface via a specially crafted URL. This can enable session hijacking, where attackers could gain unauthorized access to the system as other users, including administrators. Organizations using these affected versions should take immediate action to apply the latest patches or upgrade to version 16.0, which is not impacted by this vulnerability. Without prompt remediation, the risk of exploitation could pose significant security threats to critical infrastructure sectors worldwide, including manufacturing and transportation.

+1 more
Read Original
Critical
Siemens Siveillance Video

All CISA Advisories

Siemens has identified a serious vulnerability in its Siveillance Video Management Servers that could allow attackers to execute arbitrary code remotely. This flaw, classified as CVE-2026-3014, affects several versions of the software, specifically Siveillance Video V2023 R3 versions prior to 23.3.27, V2024 R1 versions before 24.1.16, and V2025 versions below 25.1.15. Siemens urges users to update their systems to the latest versions to mitigate the risk. The vulnerability poses a significant threat to critical infrastructure sectors, including manufacturing and communications, making it crucial for organizations using these systems to act promptly. Users are also advised to enhance their network security measures to protect against potential exploitation.

Read Original
Critical
Flow Neuroscience FL-100

All CISA Advisories

A serious vulnerability has been found in the Flow Neuroscience FL-100 devices, which could allow attackers within Bluetooth range to manipulate brain stimulation settings. This issue arises from a hard-coded credential that is shared across all affected units, enabling unauthorized access to bypass authentication. The vulnerability impacts both the Flow Neuroscience FL-100 and Halo Neuroscience FL-100, versions released before July 2026. Users are urged to install the latest firmware updates via the Flow app to mitigate this risk. Given the nature of these devices, which are used in healthcare, the implications for patient safety are significant, making immediate action essential to prevent potential exploitation.

Read Original
PreviousPage 24 of 362Next