Critical

One Packet Can Crash OT Servers in Industrial Sectors

darkreading
Actively Exploited

Overview

A recently discovered zero-day vulnerability in the TDengine time-series database poses a significant risk to various sectors, including industrial, IoT, energy, and automotive. This flaw allows attackers to crash operational technology (OT) servers with just a single packet, potentially disrupting critical systems. Organizations utilizing TDengine need to be aware of this issue, as it could lead to severe operational disruptions and safety concerns. The vulnerability underscores the importance of timely updates and monitoring in environments where downtime can have serious consequences. As of now, there is no specific patch or remediation mentioned, making it crucial for affected users to take immediate steps to secure their systems.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: TDengine time-series database
  • Timeline: Newly disclosed

Original Article Summary

A high-severity zero-day vulnerability affects the TDengine time-series database used across industrial, IoT, energy, and automotive environments.

Impact

TDengine time-series database

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Newly disclosed

Remediation

Not specified

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Zero-day, Vulnerability, Patch, and 1 more.

Related Coverage

Hackers exploit Citrix NetScaler zero-day to deploy web shells

BleepingComputer

Cybersecurity experts have reported that attackers are exploiting a zero-day vulnerability in Citrix NetScaler, identified as CVE-2026-88772. This vulnerability allows hackers to deploy custom web shells and tunneling malware, which can lead to root access on affected systems. Once inside, attackers can steal credentials and move laterally across internal networks, posing a significant risk to organizations that rely on Citrix products. This incident is particularly concerning given the potential for widespread credential theft and internal network compromise. Organizations using Citrix NetScaler should take immediate action to assess their security posture and apply any available patches or mitigations.

Sep 29, 2026

Former US Air Force members sent to prison over BEC attacks

BleepingComputer

Two former members of the U.S. Air Force have been sentenced to a total of 189 months in federal prison for their involvement in a series of business email compromise (BEC) scams and phishing campaigns that spanned several years. These scams tricked businesses into transferring large sums of money by impersonating company executives or trusted partners through compromised email accounts. The actions of these individuals not only caused financial harm to various businesses but also highlighted the vulnerabilities in email communication systems. This case serves as a warning to organizations about the importance of email security and the need for robust verification processes to prevent similar attacks in the future.

Sep 29, 2026

Dual NetScaler Zero-Days Trigger Chaos for Citrix Customers

darkreading

Citrix customers are facing significant security risks due to two newly discovered zero-day vulnerabilities affecting their NetScaler products. These vulnerabilities allow attackers to gain unauthorized access to customer networks, essentially acting as a 'skeleton key.' The flaws are present in the default configurations of these products, which means many users may be at risk without any action taken. Given the critical nature of these vulnerabilities, organizations using NetScaler should prioritize assessing their configurations and implementing security measures to protect their networks. The urgency of this situation is underscored by the potential for active exploitation by malicious actors.

Sep 29, 2026

Kiteworks Fixes Critical Flaw Found During Nine-Hour Precautionary Shutdown

The Hacker News

Kiteworks announced that it discovered a critical security vulnerability during a scheduled precautionary shutdown, which took place over the weekend. The company collaborated with federal intelligence authorities to address the issue, which was confined to a feature used by less than 1% of their customer base. This vulnerability's existence raises concerns about the security of the affected systems, even though it's limited in scope. Kiteworks has not disclosed specific details about the vulnerability or the exact systems impacted, but the incident emphasizes the importance of regular security checks and timely responses to potential threats. Users of Kiteworks products should stay vigilant and ensure their systems are up to date with any patches released following this discovery.

Sep 29, 2026

Vietnamese man charged in $16 million 'pig butchering' crypto scam

BleepingComputer

A Vietnamese man is facing charges related to a large-scale cryptocurrency scam known as 'pig butchering,' which resulted in a staggering loss of $16 million for a victim. This scheme involved manipulating victims into investing in fake cryptocurrency platforms, leading to significant financial devastation. The term 'pig butchering' refers to the tactic of fattening up victims with false promises before taking their money. The case underscores the growing risks associated with cryptocurrency investments and the need for awareness about such scams. Victims of these scams often find it challenging to recover their funds, making this incident a stark reminder of the dangers in the digital currency space.

Sep 29, 2026

Kiteworks patches critical flaw, brings customer systems online

BleepingComputer

Kiteworks, an American tech company, recently addressed a significant security vulnerability that prompted them to advise customers to temporarily shut down their systems. The company has now released a patch to fix the flaw, allowing affected customer systems to come back online safely. This vulnerability could have exposed sensitive information, making the patching process crucial for maintaining data security. Users of Kiteworks' services were directly impacted, and the swift action taken by the company is essential to protect their clients from potential exploitation. Companies should ensure they apply the update promptly to mitigate any risks associated with this vulnerability.

Sep 29, 2026