BetaIT-Hub is in early access — your feedback helps us improve. Use the chat or email [email protected]

Latest
How AI is Rewriting the Zero-Day Playbook for Preemptive SecurityRapid7 · just nowAembit Joins Snowflake to Tackle AI’s Next Security Frontier: Trusted Agent InteroperabilityHackRead · 28m agoBugs in Hugging Face Diffusers Bypass Custom Code SafeguardInfosecurity Magazine · 29m agoTengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its ProcessThe Hacker News · 43m agoAI-Assisted Bug Hunt Uncovers Linux Kernel 0-Day in net/schedInfosecurity Magazine · 59m ago24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before LoginThe Hacker News · 1h agoIs Your SSO Protected Against Modern Credential Attacks?BleepingComputer · 1h agoJFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face BreachThe Hacker News · 2h agoFrom Payments to Portfolios: How Financial Super Apps Rewrite Economics of Global InvestingHackRead · 2h agoPhishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion TechniquesInfosecurity Magazine · 2h agoThe Next Evolution of MDR: Preemptive Defense and Agentic InvestigationRapid7 · 2h agoRapid7 Cyber GRC is now available: Turn security action into compliance proofRapid7 · 2h agoCritical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as RootThe Hacker News · 2h agoMicrosoft Launches Flurry of AI Security Initiatives to Combat AI-Enabled ThreatsInfosecurity Magazine · 2h agoOver 24,000 exposed server BMCs leak password hash via decades-old flawBleepingComputer · 3h agoHow AI is Rewriting the Zero-Day Playbook for Preemptive SecurityRapid7 · just nowAembit Joins Snowflake to Tackle AI’s Next Security Frontier: Trusted Agent InteroperabilityHackRead · 28m agoBugs in Hugging Face Diffusers Bypass Custom Code SafeguardInfosecurity Magazine · 29m agoTengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its ProcessThe Hacker News · 43m agoAI-Assisted Bug Hunt Uncovers Linux Kernel 0-Day in net/schedInfosecurity Magazine · 59m ago24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before LoginThe Hacker News · 1h agoIs Your SSO Protected Against Modern Credential Attacks?BleepingComputer · 1h agoJFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face BreachThe Hacker News · 2h agoFrom Payments to Portfolios: How Financial Super Apps Rewrite Economics of Global InvestingHackRead · 2h agoPhishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion TechniquesInfosecurity Magazine · 2h agoThe Next Evolution of MDR: Preemptive Defense and Agentic InvestigationRapid7 · 2h agoRapid7 Cyber GRC is now available: Turn security action into compliance proofRapid7 · 2h agoCritical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as RootThe Hacker News · 2h agoMicrosoft Launches Flurry of AI Security Initiatives to Combat AI-Enabled ThreatsInfosecurity Magazine · 2h agoOver 24,000 exposed server BMCs leak password hash via decades-old flawBleepingComputer · 3h ago

Security & IT News

Live

Real-time news from 13+ trusted sources — BleepingComputer, The Hacker News, Krebs on Security, Dark Reading & more.

1372 results in Vulnerability

VulnerabilityThe Hacker News·12d ago
New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password

ClickLock Stealer, a new macOS infostealer, answers a victim's refusal by killing their apps on a loop until they hand over the login password. It arrives as a command pasted into Terminal, asks for the password behind a fake system dialog, and when the victim cancels, installs two LaunchAgents and quietly exits. At the next login, Finder, the Dock, Spotlight, Terminal, Activity Monitor, and

VulnerabilityCISA·12d ago
Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix

p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-197-06.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition. /strong /p p The following versions of Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix are affected: /p ul li CompactLogix 5370 lt;=V35.015 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) /li li Compact GuardLogix 5370 lt;=V35.015 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) /li li ControlLogix 5570 lt;=V35.015 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) /li li GuardLogix 5570 lt;=V35.015 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) /li li CompactLogix 5380 lt;=V34.012 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) /li li CompactLogix 5380 lt;=V35.011 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) /li li Compact GuardLogix 5380 lt;=V34.012 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) /li li Compact GuardLogix 5380 lt;=V35.011 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) /li li CompactLogix 5480 lt;=V34.012 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) /li li CompactLogix 5480 lt;=V35.011 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) /li li ControlLogix 5580 lt;=V34.012 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) /li li ControlLogix 5580 lt;=V35.011 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) /li li GuardLogix 5580 lt;=V34.012 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) /li li GuardLogix 5580 lt;=V35.011 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) /li li CompactLogix 5380 Recovery Image lt;=1.072 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) /li li Compact GuardLogix 5380 Recovery Image lt;=1.072 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) /li li CompactLogix 5480 Recovery Image lt;=1.072 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) /li li ControlLogix 5580 Recovery Image lt;=1.072 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) /li li GuardLogix 5580 Recovery Image lt;=1.072 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 8.6 /td td Rockwell Automation /td td Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix /td td Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Critical Manufacturing /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong United States /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" hre

VulnerabilityCISA·12d ago
Rockwell Automation Flex 5000 Adapter

p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-197-08.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition on the affected product. /strong /p p The following versions of Rockwell Automation Flex 5000 Adapter are affected: /p ul li Flex 5000 Adapter 6.011 (CVE-2026-12659) /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 7.5 /td td Rockwell Automation /td td Rockwell Automation Flex 5000 Adapter /td td Double Free /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Critical Manufacturing, Information Technology /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong United States /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2026-12659 /a /h3 div class="csaf-accordion-content" p A denial-of-service security issue exists in the affected products. The security issue stems from improper handling of exceptional conditions when processing crafted CIP packets sent to the adapter. A power cycle is required to recover the module and associated I/O. /p p a href="https://www.cve.org/CVERecord?id=CVE-2026-12659" View CVE Details /a /p hr h4 Affected Products /h4 h5 Rockwell Automation Flex 5000 Adapter /h5 div class="ics-vendor-version-status" div class="ics-vendor" strong Vendor: /strong br Rockwell Automation /div div class="ics-version" strong Product Version: /strong br Rockwell Automation Flex 5000 Adapter: 6.011 /div div class="ics-status" strong Product Status: /strong br known_affected /div /div div class="ics-remediations" h6 Remediations /h6 p strong Vendor fix /strong br Rockwell Automation recommends users to upgrade to the following: Flex 5000 Adapter version 6.012. /p p strong Mitigation /strong br Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices (https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight). br a href="https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight" https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight /a /p p strong Mitigation /strong br For more information, see Rockwell Automation Security Advisory SD1789 (https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1789.ht

VulnerabilityCISA·12d ago
Siemens SICAM 8

p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-197-05.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong Multiple SICAM 8 products are affected by multiple vulnerabilities that could lead to denial of service, namely: - SICAM A8000 Device firmware - CPCI85 for CP-8031/CP-8050 - SICORE for CP-8010/CP-8012 - SICAM EGS Device firmware - CPCI85 - SICAM S8000 - SICORE Siemens has released new versions for the affected products and recommends to update to the latest versions. /strong /p p The following versions of Siemens SICAM 8 are affected: /p ul li CPCI85 Central Processing/Communication vers:intdot/ lt;26.20 (CVE-2026-54798, CVE-2026-54799, CVE-2026-54800, CVE-2026-54801) /li li SICORE Base system vers:intdot/ lt;26.20.0 (CVE-2026-54798, CVE-2026-54799, CVE-2026-54800, CVE-2026-54801) /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 7.2 /td td Siemens /td td Siemens SICAM 8 /td td Active Debug Code, Initialization of a Resource with an Insecure Default, Unverified Password Change /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Critical Manufacturing, Energy /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong Germany /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2026-54798 /a /h3 div class="csaf-accordion-content" p The affected application includes a debugging interface that is accessible through HTTP endpoints. This could allow an authenticated attacker to disrupt the system by crashing the web process causing denial of service conditions. /p p a href="https://www.cve.org/CVERecord?id=CVE-2026-54798" View CVE Details /a /p hr h4 Affected Products /h4 h5 Siemens SICAM 8 /h5 div class="ics-vendor-version-status" div class="ics-vendor" strong Vendor: /strong br Siemens /div div class="ics-version" strong Product Version: /strong br CPCI85 Central Processing/Communication lt; V26.20, SICORE Base system lt; V26.20.0 /div div class="ics-status" strong Product Status: /strong br known_affected /div /div div class="ics-remediations" h6 Remediations /h6 p strong Vendor fix /strong br Update to V26.20 or later version The firmware CPCI85 V26.20 is present within “CP-8031/CP-8050 Package” V26.20 https://support.industry.siemens.com/cs/ww/en/view/109804985/ and also within “SICAM EGS Package” V26.20 https://support.industry.siemens.com/cs/document/109972536/ /p p strong Vendor fix /strong br Update to V26.20.0 or later version The firmware SICORE V26.20.0 is presen

VulnerabilityCISA·12d ago
SALTO ProAccess Space

p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-197-07.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong Successful exploitation of this vulnerability allows an authenticated attacker to escalate privileges and access spaces outside their assigned partition, within the same Salto ProAccess Space installation or system. Exploitation requires valid authenticated operator credentials and the partition feature to be enabled; installations without partitioning are not affected. /strong /p p The following versions of SALTO ProAccess Space are affected: /p ul li ProAccess Space lt;6.13 (CVE-2026-11889) /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 6.5 /td td SALTO /td td SALTO ProAccess Space /td td Authorization Bypass Through User-Controlled Key /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Commercial Facilities, Critical Manufacturing /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong Spain /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2026-11889 /a /h3 div class="csaf-accordion-content" p SALTO ProAccess Space software using the tenancy feature / logical partition is vulnerable to a privilege escalation attack that could allow an authorized attacker to access any space managed by the affected product. /p p a href="https://www.cve.org/CVERecord?id=CVE-2026-11889" View CVE Details /a /p hr h4 Affected Products /h4 h5 SALTO ProAccess Space /h5 div class="ics-vendor-version-status" div class="ics-vendor" strong Vendor: /strong br SALTO /div div class="ics-version" strong Product Version: /strong br SALTO ProAccess Space: lt;6.13 /div div class="ics-status" strong Product Status: /strong br known_affected /div /div div class="ics-remediations" h6 Remediations /h6 p strong Mitigation /strong br Users of SALTO ProAccess using the tenancy feature should upgrade to version 6.13. /p p strong Vendor fix /strong br To further enhance security after applying the update: 1. Operate ProAccess Space on a protected internal network and avoid exposing it directly to the Internet. 2. Restrict operator-level accounts to the minimum required and apply least-privilege principles. 3. If feasible, disable the partitioning feature and operate under a single partition. 4. When strong tenant separation is required, consider running separate Space instances (isolated environments) rather than relying solely on logical partitioning. /p /div p strong Relevant CWE: /strong a href=

VulnerabilityCISA·12d ago
Rockwell Automation FactoryTalk DataMosaix

p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-197-09.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong Successful exploitation of this vulnerability could allow an authenticated attacker to inject malicious scripts on the server. /strong /p p The following versions of Rockwell Automation FactoryTalk DataMosaix are affected: /p ul li DataMosaix Private Cloud lt;=8.02 (CVE-2026-9292) /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 6.1 /td td Rockwell Automation /td td Rockwell Automation FactoryTalk DataMosaix /td td Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Critical Manufacturing, Information Technology /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong United States /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2026-9292 /a /h3 div class="csaf-accordion-content" p A Stored Cross-Site Scripting security issue exists within FactoryTalk DataMosaix Private Cloud. The vulnerability stems from improper neutralization of user-supplied input within the Workflows configuration. An authenticated attacker with high privileges can inject malicious scripts that are permanently stored on the server. This vulnerability can result in the execution of malicious JavaScript when other users access the affected page, potentially allowing for account takeover, credential theft, or redirection to a malicious website. /p p a href="https://www.cve.org/CVERecord?id=CVE-2026-9292" View CVE Details /a /p hr h4 Affected Products /h4 h5 Rockwell Automation FactoryTalk DataMosaix /h5 div class="ics-vendor-version-status" div class="ics-vendor" strong Vendor: /strong br Rockwell Automation /div div class="ics-version" strong Product Version: /strong br Rockwell Automation DataMosaix Private Cloud: lt;=8.02 /div div class="ics-status" strong Product Status: /strong br known_affected /div /div div class="ics-remediations" h6 Remediations /h6 p strong Vendor fix /strong br Rockwell Automation recommends users to upgrade to the following: DataMosaix Private Cloud versions 8.03 or later. /p p strong Mitigation /strong br Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices (https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight). br a href="https://s

VulnerabilityCISA·12d ago
NASA Core Flight System (cFS) Health & Safety (HS) Application

p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-197-03.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. /strong /p p The following versions of NASA Core Flight System (cFS) Health amp; Safety (HS) Application are affected: /p ul li Core Flight System (cFS) Health amp; Safety (HS) Application /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 7.5 /td td NASA /td td NASA Core Flight System (cFS) Health amp; Safety (HS) Application /td td NULL Pointer Dereference /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Transportation Systems /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong United States /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2026-15352 /a /h3 div class="csaf-accordion-content" p A vulnerability exists in the Health amp; Safety (HS) application of NASA's Core Flight System (cFS). The flaw allows the application to crash via segmentation fault when processing a routine Housekeeping Telemetry request, leading to denial of service. /p p a href="https://www.cve.org/CVERecord?id=CVE-2026-15352" View CVE Details /a /p hr h4 Affected Products /h4 h5 NASA Core Flight System (cFS) Health amp; Safety (HS) Application /h5 div class="ics-vendor-version-status" div class="ics-vendor" strong Vendor: /strong br NASA /div div class="ics-version" strong Product Version: /strong br NASA Core Flight System (cFS) Health amp; Safety (HS) Application: lt;v7.0.1 /div div class="ics-status" strong Product Status: /strong br known_affected /div /div div class="ics-remediations" h6 Remediations /h6 p strong Mitigation /strong br NASA recommends users update to v7.0.1 (https://github.com/nasa/HS/releases/tag/v7.0.1) br a href="https://github.com/nasa/HS/releases/tag/v7.0.1" https://github.com/nasa/HS/releases/tag/v7.0.1 /a /p /div p strong Relevant CWE: /strong a href="https://cwe.mitre.org/data/definitions/476.html" CWE-476 NULL Pointer Dereference /a /p hr h4 Metrics /h4 div class="csaf-table csaf-metrics-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS Version /th th role="columnheader" Base Score /th th role="columnheader" Base Severity /th th role="columnheader" Vector String /th /tr /thead tbody tr td 3.1 /td td 7.5 /td td HIGH /td td a hre

VulnerabilityCISA·12d ago
AutomationDirect Productivity Suite

p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-197-04.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong Successful exploitation of these vulnerabilities could allow an attacker with local or physical access to cause memory corruption, unintended information disclosure, application instability, or a denial-of-service condition in the affected product. /strong /p p The following versions of AutomationDirect Productivity Suite are affected: /p ul li Productivity Suite lt;=v4.6.2.2 (CVE-2026-60063, CVE-2026-61389, CVE-2026-60140, CVE-2026-57896, CVE-2026-60073, CVE-2026-61378) /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 7 /td td AutomationDirect /td td AutomationDirect Productivity Suite /td td Out-of-bounds Write, Out-of-bounds Read, Divide By Zero /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Critical Manufacturing /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong United States /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2026-60063 /a /h3 div class="csaf-accordion-content" p An out-of-bounds write vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption via a crafted IOCTL request, potentially resulting in privilege escalation or system instability. /p p a href="https://www.cve.org/CVERecord?id=CVE-2026-60063" View CVE Details /a /p hr h4 Affected Products /h4 h5 AutomationDirect Productivity Suite /h5 div class="ics-vendor-version-status" div class="ics-vendor" strong Vendor: /strong br AutomationDirect /div div class="ics-version" strong Product Version: /strong br AutomationDirect Productivity Suite: lt;=v4.6.2.2 /div div class="ics-status" strong Product Status: /strong br known_affected /div /div div class="ics-remediations" h6 Remediations /h6 p strong Mitigation /strong br AutomationDirect recommends that users update Productivity suite to v4.7.0.47 and above https://www.automationdirect.com/support/software-downloads. br a href="https://www.automationdirect.com/support/software-downloads" https://www.automationdirect.com/support/software-downloads /a /p p strong Mitigation /strong br If the update cannot be applied right away, the following compensating controls are recommended until the upgrade can be performed. /p p strong Mitigation /strong br Disconnect the engineering workstation from external networks (e.g., the internet or corporate LAN) to reduce exposure. /p p strong Mitigation /stron

VulnerabilityCISA·12d ago
Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT

p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-197-02.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. /strong /p p The following versions of Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT are affected: /p ul li 1756-EN3 lt;=V12.001 (CVE-2026-9653) /li li 1756-EN2 lt;=V12.001 (CVE-2026-9653) /li li 1756-ENBT V6.006 (CVE-2026-9653) /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 7.5 /td td Rockwell Automation /td td Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT /td td Improper Validation of Integrity Check Value /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Critical Manufacturing /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong United States /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2026-9653 /a /h3 div class="csaf-accordion-content" p A denial-of-service security issue exists across all the 1756-EN2, EN3, and ENBT communication module due to improper validation of CIP Implicit Connection packets. An attacker on the network can exploit this by sending crafted packets to continuously disrupt device connections, though device connections will recover immediately after. /p p a href="https://www.cve.org/CVERecord?id=CVE-2026-9653" View CVE Details /a /p hr h4 Affected Products /h4 h5 Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT /h5 div class="ics-vendor-version-status" div class="ics-vendor" strong Vendor: /strong br Rockwell Automation /div div class="ics-version" strong Product Version: /strong br Rockwell Automation 1756-EN3: lt;=V12.001, Rockwell Automation 1756-EN2: lt;=V12.001, Rockwell Automation 1756-ENBT: V6.006 /div div class="ics-status" strong Product Status: /strong br known_affected /div /div div class="ics-remediations" h6 Remediations /h6 p strong Vendor fix /strong br Rockwell Automation recommends users take the following actions: 1756-EN3: Update to V12.002 /p p strong Vendor fix /strong br 1756-EN2: Update to V12.002 /p p strong Vendor fix /strong br 1756-ENBT: Product is discontinued, fix is unavailable /p /div p strong Relevant CWE: /strong a href="https://cwe.mitre.org/data/definitions/354.html" CWE-354 Improper Validation of Integrity Check Value /a /p hr h4 Metrics /h4 div class="csaf-table csaf-metrics-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-mi

VulnerabilityCISA·12d ago
CISA Adds Three Known Exploited Vulnerabilities to Catalog

p CISA has added three new vulnerabilities to its a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" Known Exploited Vulnerabilities (KEV) Catalog /a , based on evidence of active exploitation. /p ul li a href="https://www.cve.org/CVERecord?id=CVE-2026-25089" target="_blank" CVE-2026-25089 /a Fortinet FortiSandbox OS Command Injection Vulnerability nbsp; /li li a href="https://www.cve.org/CVERecord?id=CVE-2026-39808" target="_blank" CVE-2026-39808 /a Fortinet FortiSandbox OS Command Injection Vulnerability nbsp; /li li a href="https://www.cve.org/CVERecord?id=CVE-2026-58644" target="_blank" CVE-2026-58644 /a Microsoft SharePoint Deserialization of Untrusted Data Vulnerability /li /ul p These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. /p p a href="https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk" Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk /a establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. /p p While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" KEV Catalog vulnerabilities /a . CISA will continue to add vulnerabilities to the catalog that meet the a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities" specified criteria /a . /p p Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s a href="https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w" target="_blank" KEV Nomination Form /a . Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance. nbsp; /p

VulnerabilityCISA·12d ago
Rockwell Automation Arena

p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-197-01.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong Successful exploitation these vulnerabilities could allow an attacker to execute arbitrary code in the context of the current process. /strong /p p The following versions of Rockwell Automation Arena are affected: /p ul li Arena lt;=V17.00.00 (CVE-2026-8085, CVE-2026-8312, CVE-2026-8313, CVE-2026-8314) /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 7.8 /td td Rockwell Automation /td td Rockwell Automation Arena /td td Out-of-bounds Write /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Critical Manufacturing /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong United States /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2026-8085 /a /h3 div class="csaf-accordion-content" p A security issue exists within Arena Simulation due to a memory corruption vulnerability in the model.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file. /p p a href="https://www.cve.org/CVERecord?id=CVE-2026-8085" View CVE Details /a /p hr h4 Affected Products /h4 h5 Rockwell Automation Arena /h5 div class="ics-vendor-version-status" div class="ics-vendor" strong Vendor: /strong br Rockwell Automation /div div class="ics-version" strong Product Version: /strong br Rockwell Automation Arena: lt;=V17.00.00 /div div class="ics-status" strong Product Status: /strong br known_affected /div /div div class="ics-remediations" h6 Remediations /h6 p strong Mitigation /strong br Rockwell Automation recommends users to update to V17.00.01 /p /div p strong Relevant CWE: /strong a href="https://cwe.mitre.org/data/definitions/787.html" CWE-787 Out-of-bounds Write /a /p hr h4 Metrics /h4 div class="csaf-table csaf-metrics-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS Version /th th role="columnheader" Base Score /th th role="columnheader" Base Severity /th th role="columnheader" Vector String /th /tr /thead tbody tr td 3.1 /td td 7.8 /td td HIGH /td td a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/

VulnerabilityThe Hacker News·12d ago
20+ Hijacked Government Websites Became
an Attack Channel

More than 20 Brazilian government websites were hijacked and turned into malware delivery channels in an active PhantomEnigma campaign uncovered by ANY.RUN, a leading provider of interactive malware analysis and threat intelligence solutions. The investigation revealed previously undocumented backdoor behavior, hidden infrastructure relationships, and multiple attack arms behind a campaign

VulnerabilityThe Hacker News·12d ago
New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands

Ask an AI agent to summarize the reviews on a product page, and a single planted review can make it click "Buy Now" instead. Ask a coding assistant to apply a maintainer's fix from a GitHub thread, and a fake comment can make it run a stranger's command on your computer. Neither trick hijacks the agent's task. Each one just corrupts the facts it trusts and lets it carry on with the job you

VulnerabilityThe Hacker News·12d ago
Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM Backdoor

An advanced malware previously attributed to a China-linked threat actor has resurfaced after more than four years within a Taiwan manufacturing firm, along with a previously unreported backdoor dubbed Stupig. Daxin ("srt64.sys"), as the kernel-mode rootkit is referred to, was first documented by Broadcom-owned Symantec in March 2022, with evidence indicating its use in targeted attacks aimed

VulnerabilityThe Hacker News·12d ago
AI Can Find Bugs, But Human Knowledge Still Proves Them

Artificial intelligence (AI) is changing offensive security, but it has not changed the standard that matters most: a finding has to be proven before it becomes useful. AI-assisted tools can read code quickly, generate payloads, summarize attack surfaces, explain unfamiliar APIs, and run repetitive testing workflows at impressive speed. That is a real advantage for security teams. It also

VulnerabilityThe Hacker News·12d ago
OpenAI’s GPT-Red Automates Prompt Injection Testing to Harden GPT-5.6 Sol

OpenAI has disclosed details of GPT-Red, an internal automated red-teaming model that scales prompt injection vulnerability discovery with an aim to fix issues before the tools are deployed widely. "GPT‑Red is a strong red-teamer, and our previous models are highly vulnerable to its prompt injection attacks," the artificial intelligence (AI) company said. "We use GPT‑Red to adversarially train