Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

The Cybersecurity and Infrastructure Security Agency (CISA), along with the NSA and FBI, has issued a warning to users of the Zimbra Collaboration Suite about an ongoing campaign linked to Russian state-sponsored actors. These attackers are using malicious tactics to exploit vulnerabilities in the software, which is widely used for email and collaboration. Organizations that rely on Zimbra should be particularly vigilant, as this threat could lead to unauthorized access and data breaches. The warning emphasizes the need for users to implement security measures and keep their systems updated to mitigate the risk of exploitation. This situation highlights the importance of staying aware of potential threats, especially for software that is integral to business communications.

Read Original
Critical
Weintek cMT3092X

All CISA Advisories

Weintek's cMT3092X human-machine interface (HMI) has several security vulnerabilities that could allow unauthorized users to escalate their privileges or access sensitive user credentials. The affected firmware versions include those below 20210218 and EasyWeb versions prior to 2.1.20. Notably, vulnerabilities include reliance on unvalidated cookies, incorrect permission assignments, and the storage of passwords in plaintext. Weintek has issued a patch, cmt_typeB_20260316_007, which upgrades EasyWeb to version 2.3.17 to address these issues. Users are urged to apply this patch immediately to protect their systems.

Read Original
Critical
Johnson Controls XAAP Android

All CISA Advisories

A vulnerability has been identified in the Johnson Controls XAAP Android application, specifically in versions prior to 1.53. This flaw allows sensitive data to be stored in cleartext on devices, making it accessible to attackers who have physical access or can exploit another vulnerability on the device. The issue does not require network access and poses risks to users worldwide, particularly in critical manufacturing sectors. Johnson Controls advises users to upgrade to version 1.53 or later to mitigate this risk, and recommends implementing additional security measures such as restricting physical access, enabling device encryption, and using Mobile Device Management solutions to enforce security policies. Currently, there have been no reports of this vulnerability being actively exploited in the wild.

Read Original
Critical
MZ Automation libIEC61850

All CISA Advisories

Recent vulnerabilities in MZ Automation's libIEC61850 could allow unauthorized attackers on the same network to crash vital IEC 61850 services or run arbitrary code. This affects all versions of libIEC61850 from 1.0.0 to 1.6.1. With these weaknesses, critical control and protection functions could be significantly disrupted, posing a serious risk to industrial control systems. MZ Automation recommends that users update to the latest version of the software to mitigate these vulnerabilities. Although no known exploitations have been reported, organizations should take immediate action to secure their systems by minimizing network exposure and using secure remote access methods like VPNs.

Read Original
High
Rockwell Automation ThinManager

All CISA Advisories

Rockwell Automation's ThinManager software has a significant vulnerability that allows authenticated attackers to write files to restricted directories outside the intended application area. This issue affects several versions, specifically ThinManager versions 13.0.0 through 14.0.2. Users who cannot upgrade to the patched versions—13.1.6, 13.2.5, and 14.0.3—are advised to follow security best practices provided by Rockwell. The vulnerability, classified as a path traversal issue, has a high severity score of 8.1. Although no known active exploitation of this vulnerability has been reported, organizations should remain vigilant and implement defensive measures to protect their control systems.

Read Original

Johnson Controls has reported significant vulnerabilities in its C-CURE 9000 and Victor application server software that could allow attackers to execute arbitrary code remotely. Specifically, versions of the C-CURE 9000 and Victor applications up to v2.90_v3.0 and Victor Web versions up to v7.1 are impacted. An attacker on an adjacent network could exploit these flaws to compromise physical security controls and access sensitive information. The vulnerabilities have been assigned high to critical severity scores, highlighting the urgency for affected users to take action. Johnson Controls recommends upgrading to the latest versions and implementing various security measures to mitigate risks.

Read Original
Critical
Panduit IntraVUE

All CISA Advisories

Recent vulnerabilities have been discovered in Panduit's IntraVUE software, affecting versions 3.2.1a14 and earlier. These security flaws could allow attackers to manipulate industrial control devices remotely without needing physical access or specialized tools. Notably, one vulnerability involves the storage of passwords in plaintext, which could expose sensitive credentials via the API. Users are urged to upgrade to version 3.2.1a16 or later to mitigate these risks. With potential impacts on critical infrastructure sectors including manufacturing, energy, and water systems, the urgency for organizations to update their software is high to prevent exploitation.

Read Original

Synthetic identity fraud is an emerging form of identity theft where attackers create fake identities by combining real data points with fabricated information. Unlike traditional identity theft, where a real person's information is stolen, synthetic identity fraud involves crafting identities that don't exist, making it difficult to detect. This type of fraud can lead to significant financial losses for businesses and financial institutions, as these synthetic identities can be used to open accounts, secure loans, and commit various types of fraud without raising red flags. The challenge lies in the fact that there are no real victims to report the misuse, which complicates detection and prevention efforts. As this fraud scheme evolves, it poses a growing risk to both consumers and organizations, highlighting the need for enhanced monitoring and verification processes.

Read Original

A recent report from Sophos warns that companies rapidly adopting artificial intelligence (AI) technology are exposing themselves to new cyber threats. As businesses integrate AI into their operations, they may overlook security measures, leaving them vulnerable to exploitation by cybercriminals. The report indicates that this new attack surface is growing quickly, and organizations may not be fully prepared to defend against the potential risks. This is particularly concerning as AI systems can be targeted in ways that traditional security measures might not anticipate. Companies are urged to reassess their cybersecurity strategies to address these emerging vulnerabilities and ensure that their AI implementations are secure.

Read Original

Cybersecurity researchers have uncovered a significant campaign that exploits compromised GitHub repositories to launch attacks against cPanel and WebHost Manager (WHM) servers. The attackers are using malicious versions of 10 different packages linked to a PHP and DevOps developer known as dinushchathurya. This activity took place between July 12 and 13, and it effectively turns these repositories into a distributed attack infrastructure. This incident is concerning because it puts many web hosting providers and their clients at risk, as cPanel and WHM are widely used for managing web hosting services. Companies need to be vigilant and ensure their systems are secure against these types of attacks, which could lead to unauthorized access or data breaches.

Read Original

The article discusses how advancements in technology are addressing previous challenges in adopting secure data vaults for confidential computing. However, it warns that the rise of artificial intelligence is introducing new obstacles that could hinder this progress. Experts in the field are exploring potential solutions to these emerging issues, emphasizing the need for ongoing adaptation in security practices. This situation is particularly relevant for companies handling sensitive data, as the balance between leveraging AI and maintaining confidentiality becomes increasingly complex. The implications for data security and privacy are significant, as organizations must navigate these evolving challenges to protect their information.

Read Original

South Korea's Foreign Ministry has reported a security breach affecting the Korea National Diplomatic Academy's online education platform. This breach has compromised personal data belonging to both current and former ministry employees, as well as diplomats stationed overseas. The online training system, initiated in 2022 for remote learning during the COVID-19 pandemic, has been utilized for job training and language courses. Details about the timeline of the breach have not been fully disclosed, but the ministry confirmed that the intrusion was ongoing for several months. This incident raises concerns about the security of sensitive personal information related to diplomatic personnel and the potential risks associated with such data exposure.

Read Original

A new paper updates the debate on end-to-end encryption (E2EE), marking what the authors call 'Round 3' of the Going Dark Debate. This discussion centers on the tension between privacy and law enforcement, as governments globally push for laws that restrict E2EE to enable access for security purposes. The paper outlines the history of encryption debates, starting with the Crypto Wars of the 1990s, followed by a phase where lawful access was feasible through cloud services. Currently, the rise of E2EE means that messages are secure from third-party access, complicating law enforcement efforts. The implications of this research are significant, as it challenges policymakers to balance privacy rights with national security needs, affecting users, tech companies, and governments alike.

Read Original

Upbound Group reported a data breach that resulted in a significant financial impact, totaling $13 million in fraudulent contract losses. The breach involved hackers accessing non-sensitive customer data and other documents, although the specifics of the data compromised were not disclosed. This incident raises concerns about how even non-sensitive information can be exploited by cybercriminals to commit fraud. Companies need to be vigilant about protecting all types of data and ensuring robust security measures are in place to mitigate potential risks. The breach serves as a reminder of the ongoing threats businesses face in the digital landscape.

Read Original

Attackers are exploiting a serious authentication bypass vulnerability, identified as CVE-2026-16232, in Check Point's Security Management and Multi-Domain Security Management servers. These servers are crucial as they manage policy updates for Check Point's firewall products. The flaw allows unauthenticated individuals to acquire a login token, which they can then use to access the system with full administrative rights. This could enable them to make unauthorized changes to security policies and configurations. Check Point has confirmed that this vulnerability is actively being exploited, posing significant risks to organizations using their security management products.

Read Original
PreviousPage 83 of 369Next