Rockwell Automation's Studio 5000 Logix Designer has several vulnerabilities that could allow local attackers to execute arbitrary files and alter configurations. Versions affected include Studio 5000 Logix Designer V36.00 and various iterations of V35.00, V35.01, and earlier versions down to V32.00. The vulnerabilities, identified as CVE-2026-9108, CVE-2026-9127, and CVE-2026-9128, have been assigned high severity scores, indicating they could pose significant risks to users. Rockwell Automation has released updates to address these issues, and users unable to upgrade should follow the company's security best practices to mitigate risks. The potential for exploitation of these vulnerabilities highlights the need for organizations to maintain robust cybersecurity defenses.
Latest Cybersecurity Threats
Real-time threat intelligence from trusted sources
Siemens has identified multiple vulnerabilities affecting its CADRA software, primarily linked to zlib and Foxit libraries. These vulnerabilities include issues like improper input validation and buffer overflows, which could allow attackers to disrupt service or exploit systems. Siemens is urging users to update to CADRA version V2511 or later to mitigate these risks. For systems that cannot be immediately updated, the company recommends specific countermeasures to reduce exposure until fixes are available. This situation is particularly critical for sectors such as chemical and energy, where security vulnerabilities can have serious implications.
Rockwell Automation has disclosed a significant vulnerability in its FactoryTalk Services Platform (FTSP) version 6.60, which could allow attackers to impersonate authorized users. This flaw arises from weak authentication practices, specifically the inability of the application to properly validate JSON Web Tokens (JWT). As a result, low-privilege users could exploit this vulnerability to gain unauthorized access to critical system configurations and permissions. Organizations using FTSP are urged to apply a specific patch (RAID 1158263) or the February 2026 Patch Roll-up to mitigate this risk. As of now, there have been no reports of active exploitation in the wild, but users are advised to follow best security practices to protect their systems.
Siemens has identified a significant security vulnerability in its Opcenter X software, specifically in versions prior to V2604. This flaw allows attackers to bypass authentication, enabling unauthorized access to the application and the ability to impersonate any user, including administrators. The vulnerability stems from improper validation of the algorithm in the JSON Web Token (JWT) header, which could lead to severe security breaches. Siemens has urged all users to upgrade to version V2604 or later to mitigate this risk. This incident is particularly alarming as it affects critical manufacturing infrastructures worldwide, emphasizing the need for timely software updates and robust cybersecurity practices.
The article discusses the challenges of patching software vulnerabilities in a timely manner. When vendors release a security patch, they reveal information about what was fixed, which can be exploited by attackers against systems that haven't been updated yet. This practice, known as N-day exploitation, creates a race between the vendors issuing patches and defenders trying to apply these updates before they are targeted. The piece emphasizes that simply patching faster may not be enough to protect systems, as the window of opportunity for attackers can be dangerously short. This issue affects all companies relying on software, particularly those with critical infrastructure that may be slow to implement updates.
Researchers from Zhejiang University have identified a new attack method, dubbed Bit2Watt, that allows cloud tenants to manipulate a data center's power consumption. By simply using standard GPU access, these tenants can quickly increase or decrease the power draw of the facility, potentially destabilizing the power grid that the data center relies on. This vulnerability raises concerns about the security of cloud services and the broader implications for infrastructure resilience. The research indicates that no hacking or exploitation is necessary to carry out this attack, making it particularly alarming. As data centers become more integral to our digital infrastructure, understanding and mitigating such vulnerabilities is crucial.
Schneier on Security
MIT is investing over $3 million to install more than 500 AI surveillance cameras across its campus, including academic buildings and outdoor areas. This project, which began in November 2025 and is expected to finish by September 2026, will enhance the university's ability to monitor activities through advanced features like real-time facial recognition, object classification, and motion detection. The cameras can identify individuals based on clothing color, gender, and age from up to 35 feet away. Data collected from the cameras will be stored for up to 30 days, unless specific exceptions are made. The implications of this extensive surveillance initiative raise concerns about privacy and data security on campus, as it affects students, faculty, and visitors who may be monitored without their explicit consent.
BleepingComputer
The U.S. Justice Department has taken significant action against unauthorized streaming of FIFA World Cup 2026 matches by seizing over 1,000 websites and blocking nearly 2,000 domains linked to piracy. This crackdown aims to protect the rights of broadcasters and uphold copyright laws, especially as the World Cup draws near. The seized sites were used to stream matches without permission, which undermines legitimate services and can lead to financial losses for content creators. This operation illustrates the ongoing battle against online piracy and the measures authorities are willing to take to enforce copyright protections. As major sporting events attract large audiences, illegal streaming becomes a greater concern for stakeholders in the sports and entertainment industries.
A security researcher uncovered a broken access control vulnerability in Meta's support infrastructure, which could have potentially exposed customer support data. The flaw was serious enough that Meta awarded the researcher a bounty of $78,000 for their findings. This incident raises concerns about the security of user data handled by Meta, particularly as it relates to customer support interactions. While the exact impact on users remains unclear, the discovery serves as a reminder of the importance of robust security measures in protecting sensitive information. Companies like Meta need to continuously monitor and improve their security practices to safeguard user data from similar vulnerabilities.
The Qilin ransomware group is taking advantage of a serious flaw in PAN-OS GlobalProtect, which allows attackers to bypass authentication and access victims' networks. This vulnerability has raised alarms among cybersecurity experts, particularly Arctic Wolf, who reported on the ongoing exploitation. Organizations using Palo Alto Networks' GlobalProtect VPN are at risk, as the attackers can infiltrate systems without proper credentials. This situation emphasizes the urgency for affected companies to address the vulnerability and safeguard their networks to prevent ransomware attacks, which can result in data loss and significant downtime. Users are advised to stay vigilant and apply any available security updates promptly.
Infosecurity Magazine
Craneware, a financial software provider for healthcare organizations in the US, has reported a cyber incident involving unauthorized access and data theft. The breach poses a significant risk to the sensitive financial and operational data of the healthcare entities that rely on Craneware's services. While details about the specific data compromised have not been disclosed, such incidents can lead to serious repercussions including identity theft and financial fraud. This incident underscores the growing vulnerability of the healthcare sector to cyberattacks, which can disrupt services and compromise patient care. Organizations using Craneware's software should remain vigilant and implement security measures to protect their data.
SecurityWeek
Clover Health Investments recently reported a data breach that was caused by social engineering tactics employed by hackers. These attackers managed to gain access to employee accounts, which contained sensitive personal and health information. As a result, individuals whose data was compromised could face risks such as identity theft or unauthorized medical access. The company has not disclosed the exact number of affected individuals, but the nature of the data involved raises significant privacy and security concerns. This incident serves as a reminder for organizations to bolster their security measures and educate employees on recognizing and preventing social engineering attacks.
Amazon has introduced a new feature in GuardDuty called the investigation agent, which is currently in public preview. This tool uses artificial intelligence to streamline the initial steps of threat investigations within AWS accounts and organizations, aiming to help security teams save time. During the preview phase, users can access the investigation agent at no additional cost in 10 different AWS Regions, but there are limitations on usage: each account can only run 10 investigations daily and a total of 100 during the preview. It's important to note that failed investigations do not count against these limits. This development could significantly enhance the efficiency of security operations for AWS users by automating routine investigation tasks.
Zimbra has released an important update that addresses several serious security vulnerabilities, including command injection, cross-site scripting (XSS), restriction bypass, and server-side request forgery (SSRF) issues. These vulnerabilities could allow attackers to execute arbitrary commands, manipulate web pages, bypass security controls, or make unauthorized requests to other services. Users of Zimbra's email and collaboration software should apply this update promptly to protect their systems from potential exploitation. The vulnerabilities are significant as they could lead to unauthorized access to sensitive information or compromise the integrity of the systems involved. Regular updates are essential for maintaining security and preventing breaches.
A serious vulnerability in ServiceNow's AI Platform, identified as CVE-2026-6875, is being actively exploited by attackers. This flaw allows for unauthenticated remote code execution on self-hosted instances of the platform. Researchers from Searchlight Cyber disclosed the vulnerability on July 14, 2023, and ServiceNow promptly released patches for affected systems on the same day. However, reports indicate that attacks exploiting this flaw began shortly after, on July 17. Organizations using self-hosted ServiceNow instances need to apply the patches immediately to protect against potential breaches, as the vulnerability poses a significant risk to their data and operations.