ABB Ability Zenon is facing significant vulnerabilities that could allow attackers to bypass security measures, crash systems, and compromise data. The issues primarily affect the IIoT services bundled with MongoDB version 4.2 across all versions of ABB Ability Zenon. Notably, vulnerabilities such as improper handling of length parameters and exploitation of uninitialized memory could lead to unauthorized actions. ABB has recommended urgent remediation steps, including replacing the bundled MongoDB with a supported version and uninstalling IIoT services if they are not needed. Given that these vulnerabilities impact critical infrastructure sectors like energy and healthcare, organizations using ABB Ability Zenon must act quickly to secure their systems.
Articles tagged "Windows"
Found 80 articles
The Hacker News
Cybersecurity researchers have identified a supply chain attack targeting QuickFox, a VPN tool favored by overseas Chinese users. The attack has reportedly been active since at least August 2025, involving a compromised version of the application that delivers the FDMTP backdoor. This backdoor allows attackers to gain unauthorized access to affected systems, posing significant risks to user privacy and data security. This incident raises concerns about the security of software supply chains, particularly for tools that are essential for users in sensitive environments. Users of QuickFox should be vigilant and consider alternative solutions while the situation is investigated further.
Security Affairs
The latest Malware newsletter from Security Affairs covers several significant developments in malware tactics. Notably, the DPRK's BlueNoroff group has upgraded its MaaS (Malware as a Service) ecosystem, introducing modular tools that enhance its capabilities. Additionally, a new threat called SourTrade has emerged, leveraging malvertising to deliver browser-assembled malware. Another concerning development is MedusaHVNC, which functions as a hidden desktop tool designed to capture live Windows sessions, potentially exposing sensitive information. The newsletter also includes an analysis of a malware strain named 'Cruciferra', though details on its specific impact are not provided. These findings underscore the evolving nature of cyber threats and the need for users and companies to stay informed and vigilant against such attacks.
A vulnerability has been identified in the Mitsubishi Electric CC-Link IE TSN Communication Protocol that could allow attackers on the same network segment to manipulate communication data. This vulnerability, tracked as CVE-2026-13584, can lead to denial-of-service (DoS) conditions by disrupting the control functions of affected products. A wide range of Mitsubishi Electric MELSEC MX controllers, motion modules, and various remote and safety modules are affected, including models MX-R300, MX-R500, and several others. Users of these devices should be aware of the potential risks, as the exploitation of this flaw could significantly impair operational capabilities. Addressing this vulnerability is crucial for maintaining the integrity and reliability of systems relying on this communication protocol.
Kaspersky researchers have identified a new strain of ransomware called GenieLocker, which targets Windows, Linux, and ESXi systems. This ransomware is associated with a group known as Toy Ghouls, which is primarily focused on financial extortion. The emergence of GenieLocker is concerning because it indicates a growing trend of customized ransomware that can impact multiple operating systems, making it a versatile threat for various organizations. Companies using affected systems should be vigilant and implement strong security measures to protect their data. With ransomware incidents on the rise, understanding the capabilities of threats like GenieLocker is crucial for effective defense strategies.
Help Net Security
Researchers have identified a significant vulnerability in Active Directory Certificate Services (AD CS), designated as CVE-2026-54121, also known as 'Certighost.' This flaw allows attackers to elevate privileges, potentially leading to a complete domain takeover. AD CS is a critical component of Microsoft Windows Server that organizations use to manage their Public Key Infrastructure (PKI). The release of a proof-of-concept exploit means that attackers may quickly learn how to exploit this vulnerability. Organizations using AD CS should be particularly vigilant as the risk of exploitation increases with the availability of this exploit.
A cybercrime group linked to China has been using a sophisticated crypter service named Cruciferra to hide malware in attacks targeting Indian taxpayers, tax professionals, and corporate finance teams. Recent analysis from Proofpoint reveals that this service allows various cybercriminals to deliver different forms of remote access malware while evading detection. Cruciferra employs techniques such as Bring Your Own Vulnerable Driver (BYOVD) and process ghosting, which help the malware operate stealthily on victim systems. The implications of these tactics are significant, as they enable attackers to compromise sensitive financial data and potentially cause substantial financial harm to individuals and organizations. This development is a reminder for users and companies to remain vigilant against evolving cyber threats and to implement strong security measures.
The Hacker News
A recent security flaw in Bing's image processing system allowed crafted SVG files to execute commands with elevated privileges, specifically as NT AUTHORITY\SYSTEM on Windows servers and as root on Linux machines. This vulnerability was identified through testing by security researchers at XBOW, who found that the issue was not isolated to a single machine but was present across multiple hosts and network ranges within Bing’s infrastructure. Microsoft responded by issuing two critical CVEs, CVE-2026-32194 and another unnamed one, to address the vulnerabilities. This incident raises significant concerns about the security of cloud-based services and the potential for attackers to exploit similar flaws to gain unauthorized access to sensitive systems. Companies relying on these services should prioritize patching and review their security protocols to mitigate risks from this kind of vulnerability.
The Hacker News
A China-based cyber operation known as JadeProx has been identified targeting government, healthcare, and education sectors in Asia and Latin America. Researchers from Group-IB discovered an exposed server on Alibaba Cloud in Singapore that was linked to these attacks. The operation utilizes a new Windows loader called TriBack Loader, which had not been documented before. Although the server was offline by the time of the report in mid-April 2026, the implications of these attacks are significant, as they threaten sensitive information and operations within critical public services. Organizations in the affected regions need to bolster their security measures to defend against such sophisticated threats.
BleepingComputer
Microsoft has issued an out-of-band update, KB5121767, to address a shutdown issue affecting certain Dell PCs that arose after the installation of July 2026 Windows 11 security updates. Users reported that their devices were unexpectedly shutting down, which raised concerns about system stability and user productivity. This fix specifically targets Dell systems, indicating that the problem may be linked to specific hardware configurations. Users of affected Dell PCs are encouraged to install this update to prevent further shutdowns and ensure their systems operate correctly. This incident serves as a reminder of the complexities involved in software updates, especially when they interact with various hardware.
Zoom has identified and patched a serious vulnerability in its Windows applications, labeled CVE-2026-53412, which carries a CVSS score of 9.8. This flaw allows attackers to take control of user accounts without needing any authentication, posing a significant risk to users of older versions of the Workplace and Windows VDI Client. The vulnerability primarily affects organizations using these outdated versions, making it essential for them to update promptly. The potential for account takeover could lead to unauthorized access to sensitive information, making this a critical security issue for affected users. Zoom's quick response to fix this vulnerability is crucial to protect its user base from potential exploitation.
Zoom has addressed a serious security flaw in its Windows applications that could allow attackers to take over user accounts. This vulnerability, identified as CVE-2026-53412, has a high severity score of 9.8, indicating its potential impact. The flaw affects several Zoom products, including the Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows. Users of these applications are at risk, making it crucial for them to apply the necessary updates. By patching this vulnerability, Zoom aims to protect its users from unauthorized access and potential misuse of their accounts.
A new zero-day vulnerability in Windows, dubbed 'LegacyHive', has been disclosed by a researcher known as Nightmare Eclipse. To mitigate the risk of immediate exploitation, the researcher has stripped the proof-of-concept exploit from public access. This vulnerability could potentially allow attackers to execute arbitrary code on affected systems, putting users and organizations at risk. Windows users and administrators should be particularly vigilant as they await further details and patches. The situation is evolving, and users are advised to stay updated on any security advisories related to this vulnerability.
Hackread – Cybersecurity News, Data Breaches, AI and More
Researchers from Dr.Web have identified a new backdoor named Siggen that targets Windows developers. This malware spreads through infected Visual Studio projects and utilizes Steam for command and control (C2) operations. Once installed, it can steal sensitive information, including user credentials and cryptocurrency data. The incident poses a significant risk to developers who may unknowingly incorporate these malicious projects into their work, potentially compromising their systems and data. The use of a popular platform like Steam for C2 makes it a notable concern for the developer community and highlights the need for vigilance against such threats.
Progress Software has advised ShareFile customers to shut down their Windows servers that run Storage Zone Controllers due to a credible external security threat. The company has temporarily restricted access to affected accounts as a precautionary measure while they investigate the situation. This warning raises concerns for businesses relying on ShareFile for secure file storage and collaboration, highlighting the potential risks associated with third-party services. Users are encouraged to take immediate action to protect their data until the issue is resolved. Progress is working closely with both internal and external security teams to address the threat effectively.