MikroTik RouterOS has a critical vulnerability (CVE-2026-14227) that allows attackers to extract the router's WireGuard private key using low-privilege API access. This could enable them to impersonate the VPN and decrypt all associated traffic. The flaw affects all versions of MikroTik RouterOS where the API is enabled, posing a significant risk to users globally. The issue arises from an insufficient session expiration, which means users may retain access even after their permissions have been downgraded. MikroTik advises that administrators log out affected users to enforce new permission policies effectively.
Latest Cybersecurity Threats
Real-time threat intelligence from trusted sources
Toptech Systems has reported a serious vulnerability in its RCU II+ and Multiload II+ products, which could allow attackers to gain unauthorized control over these devices. The flaw, identified as CVE-2026-12562, affects all versions of RCU II+ and Multiload II+ released before November 24, 2025. This vulnerability stems from a debug interface that lacks authentication, enabling attackers to access the system's Linux environment directly. If exploited, this could lead to significant manipulation of connected networks and resources. Users are urged to take defensive measures, including isolating the devices from untrusted networks and applying available vulnerability removal tools or firmware updates to protect against potential exploitation.
A vulnerability has been identified in Watchfire Controller Software that could allow attackers to deliver malicious firmware and gain full control of affected devices. The flaw, designated as CVE-2026-5846, impacts several versions of the software, including BC550 12.30, BC750 11.33 and 12.35, BC760 12.38 and 13.00, and BC760DC 12.39. This issue arises from the use of hard-coded cryptographic keys within the firmware, which are stored in plaintext, posing a significant security risk. Users of the affected software, primarily in sectors such as healthcare and financial services, are urged to apply security patches provided by Watchfire to mitigate the risk. While no public exploitation of this vulnerability has been reported yet, organizations are advised to take proactive measures to secure their systems against potential attacks.
Johnson Controls has identified multiple vulnerabilities in their OpenBlue Employee software, specifically versions up to V2025.3.1. These flaws could allow attackers to upload malicious files, execute cross-site scripting (XSS) attacks, or inject harmful HTML content, posing significant risks to users. The vulnerabilities are particularly concerning as they affect critical infrastructure sectors, including manufacturing, transportation, and energy. Johnson Controls advises users to apply the latest updates and implement strong access controls to mitigate potential risks. The company has outlined specific defensive measures to help secure the application and protect users from exploitation.
MZ Automation GmbH's libiec61850 library, used in critical infrastructure like energy systems, has several vulnerabilities that could lead to denial-of-service attacks. Versions prior to 1.6.2 are affected by multiple issues, including improper validation of timestamps and flaws in the GOOSE and MMS message processing. Attackers could exploit these weaknesses by sending specially crafted messages, causing the affected services to crash. This poses a significant risk to operational reliability in systems relying on this library. Users are urged to update to version 1.6.2 to mitigate these risks.
MZ Automation's lib60870 version 2.4.0 has been found to have serious vulnerabilities that could lead to device crashes. Specifically, two CVEs (CVE-2026-61893 and CVE-2026-63033) involve out-of-bounds read issues triggered by maliciously crafted IEC 60870-5-104 I-frames. These vulnerabilities affect systems in critical infrastructure sectors, including energy and water management, and have been reported globally. Users are advised to update to version 2.4.1 as a mitigation step to protect against potential exploits. Currently, there have been no reports of these vulnerabilities being actively exploited in the wild.
Rockwell Automation has identified a vulnerability in several of its communications modules, including the CompactLogix 5380 and ControlLogix 5580 models. This flaw could allow attackers to trigger a denial-of-service condition, disrupting the operation of affected devices. The vulnerable versions include ControlLogix 5580 from V36 to V37 and the 1756-EN4TR communications module versions V6.001 and V7.001. To mitigate this risk, users are advised to update to ControlLogix 5580, CompactLogix 5380, GuardLogix 5580, Compact GuardLogix 5380, and 1756-EN4TR versions V38.011 and V8.001, respectively. While no public exploitation has been reported yet, organizations are encouraged to take proactive measures to secure their systems, including minimizing network exposure and utilizing VPNs for remote access.
All CISA Advisories
CISA has issued a warning about a rise in cyberattacks targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems sector. Attackers are exploiting publicly exposed PLCs, leading to disruptions like boil water notices and forcing operators to revert to manual processes. This threat affects water organizations of all sizes, emphasizing that even those with established cybersecurity measures must review their systems for vulnerabilities, including hidden connections. CISA recommends immediate actions such as disconnecting PLCs from the internet, using VPNs for remote access, and implementing strict password protections. The agency also highlights the need for a clean backup of PLC images in case of unauthorized access.
Securelist
Researchers have identified two new backdoors, named OctLurk and SilkLurk, that are primarily operating in memory and targeting systems in Central Asia. These malicious tools are capable of injecting plugins to perform various harmful actions, including launching shells, scanning networks, dumping credentials, and logging keystrokes. The discovery raises concerns about the potential for espionage and data theft in the region. Organizations that operate within Central Asia should be aware of these threats and take precautions to protect their systems. Given the nature of these backdoors, they could pose significant risks to sensitive information and operational security.
Help Net Security
Cisco's Secure Firewall Management Center (FMC) is facing a significant security issue due to a vulnerability identified as CVE-2026-20316. This flaw allows attackers to exploit static credentials associated with a low-privileged user account within the FMC's web interface. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning, indicating that this vulnerability is being actively exploited by malicious actors. Organizations using Cisco FMC should take immediate action to secure their systems, as the exploitation of these credentials could lead to unauthorized access and potential control over network security settings. The report of this vulnerability was made by Jimi Sebree from Horizon3.ai, highlighting the urgency for affected users to address this issue promptly.
The Hacker News
The Chinese cybercrime group Silver Fox has targeted a Japanese manufacturing company using a sophisticated attack method that involves exploiting vulnerable drivers. This approach, known as bring your own vulnerable driver (BYOVD), allows attackers to bypass security measures and install a remote access tool called ValleyRAT, which enables persistent access to the compromised systems. The campaign marks a notable shift in tactics, as the group is utilizing newly identified vulnerable drivers alongside legitimate software abuse. This incident raises concerns for the industrial sector, highlighting the need for stronger security protocols to protect against such advanced threats. Organizations in manufacturing and similar industries should be particularly vigilant and assess their defenses against these types of attacks.
The FCC has expanded its Covered List to include foreign-made advanced robotic devices and power inverters, effectively prohibiting new models from being authorized for use in the U.S. This decision aims to mitigate potential security risks posed by these foreign products, which may be vulnerable to cyber threats. Existing devices that have already been authorized can still receive security updates until 2029, allowing for continued support while the agency assesses the risks of new entries. This move is significant as it reflects growing concerns over national security and the integrity of critical infrastructure. The restriction could impact companies and consumers looking to adopt the latest technology in automation and energy management.
A recent analysis by Claroty found that 20% of cyber-physical systems in major data centers are vulnerable to attacks. The study examined 750,000 assets across some of the largest facilities worldwide, revealing that many critical systems are easily accessible to potential attackers. This situation raises concerns for data security, as these systems often manage sensitive information and infrastructure. Companies operating data centers should take immediate action to assess and secure their assets to prevent possible breaches. The findings indicate a pressing need for improved security measures in environments where physical and cyber systems intersect.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a vulnerability affecting the Cisco Secure Firewall Management Center (FMC) to its Known Exploited Vulnerabilities catalog. This flaw, identified as CVE-2026-20316, has a CVSS score of 5.3, indicating a moderate level of severity. Organizations using Cisco FMC should take this seriously as the vulnerability could potentially be exploited by attackers. CISA's inclusion of this flaw in their catalog signals a heightened risk, urging companies to assess their security measures. It's crucial for users to stay updated and implement necessary patches to protect their systems from potential exploitation.
A cyberattack struck over 30 community water utilities in Minnesota on July 26 and 27, affecting their operational technology systems. Minnesota IT Services (MNIT) confirmed the incident on July 28, stating they promptly activated their cybersecurity response capabilities to manage the situation. The agency is collaborating with various partners to contain the intrusion and assess the damage. This attack raises significant concerns about the security of critical infrastructure, as water utilities play a vital role in public health and safety. The incident underscores the ongoing risks posed by cyber threats to essential services and highlights the need for robust cybersecurity measures in public utilities.