BetaIT-Hub is in early access — your feedback helps us improve. Use the chat or email [email protected]

Latest
How AI is Rewriting the Zero-Day Playbook for Preemptive SecurityRapid7 · just nowCheck Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)Rapid7 · 32m agovBulletin fixes critical pre-auth RCE flaw with public exploitBleepingComputer · 55m agoPhantomEnigma Infects Organizations with Malware via Hijacked Government WebsitesHackRead · 1h agoShinyHunters Claims Ernst & Young (EY) Data Breach, Threatens July 31 LeakHackRead · 2h agoAembit Joins Snowflake to Tackle AI’s Next Security Frontier: Trusted Agent InteroperabilityHackRead · 3h agoBugs in Hugging Face Diffusers Bypass Custom Code SafeguardInfosecurity Magazine · 3h agoTengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its ProcessThe Hacker News · 4h agoAI-Assisted Bug Hunt Uncovers Linux Kernel 0-Day in net/schedInfosecurity Magazine · 4h ago24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before LoginThe Hacker News · 4h agoIs Your SSO Protected Against Modern Credential Attacks?BleepingComputer · 5h agoJFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face BreachThe Hacker News · 5h agoFrom Payments to Portfolios: How Financial Super Apps Rewrite Economics of Global InvestingHackRead · 5h agoPhishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion TechniquesInfosecurity Magazine · 6h agoThe Next Evolution of MDR: Preemptive Defense and Agentic InvestigationRapid7 · 6h agoHow AI is Rewriting the Zero-Day Playbook for Preemptive SecurityRapid7 · just nowCheck Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)Rapid7 · 32m agovBulletin fixes critical pre-auth RCE flaw with public exploitBleepingComputer · 55m agoPhantomEnigma Infects Organizations with Malware via Hijacked Government WebsitesHackRead · 1h agoShinyHunters Claims Ernst & Young (EY) Data Breach, Threatens July 31 LeakHackRead · 2h agoAembit Joins Snowflake to Tackle AI’s Next Security Frontier: Trusted Agent InteroperabilityHackRead · 3h agoBugs in Hugging Face Diffusers Bypass Custom Code SafeguardInfosecurity Magazine · 3h agoTengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its ProcessThe Hacker News · 4h agoAI-Assisted Bug Hunt Uncovers Linux Kernel 0-Day in net/schedInfosecurity Magazine · 4h ago24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before LoginThe Hacker News · 4h agoIs Your SSO Protected Against Modern Credential Attacks?BleepingComputer · 5h agoJFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face BreachThe Hacker News · 5h agoFrom Payments to Portfolios: How Financial Super Apps Rewrite Economics of Global InvestingHackRead · 5h agoPhishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion TechniquesInfosecurity Magazine · 6h agoThe Next Evolution of MDR: Preemptive Defense and Agentic InvestigationRapid7 · 6h ago

Security & IT News

Live

Real-time news from 13+ trusted sources — BleepingComputer, The Hacker News, Krebs on Security, Dark Reading & more.

1372 results in Vulnerability

VulnerabilityThe Hacker News·21d ago
RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service

A new Android malware operation called RedWing is being rented out on Telegram as a ready-made bank-fraud service. It lets even low-skill criminals take over a victim's phone, steal their banking logins, and capture the one-time codes that protect their accounts. Zimperium's zLabs, which found the operation, says it looks like a new variant of Oblivion, a $300-a-month rent-a-malware tool

VulnerabilityThe Hacker News·21d ago
Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots

A critical flaw in Google's Dialogflow CX could have let an attacker with edit rights on one Code Block-enabled agent compromise other Code Block-enabled agents in the same Google Cloud project. From there, they could read live conversations, steal the data users shared, and make the bots send attacker-written messages, including requests to re-enter a password. Security firm Varonis found it

VulnerabilityThe Hacker News·21d ago
DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts

A Microsoft 365 device code phishing campaign has been observed leveraging collaboration-themed lures to take control of victim accounts between the last week of June 2026 and into early July, per findings from ZeroBEC. "The campaign did not depend on a fake Microsoft password page. It used a malicious collaboration-style lure to push users into the legitimate Microsoft device login experience,

VulnerabilityCISA·21d ago
CISA Adds One Known Exploited Vulnerability to Catalog

p CISA has added one new vulnerability to its a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" Known Exploited Vulnerabilities (KEV) Catalog /a , based on evidence of active exploitation. /p ul li a href="https://www.cve.org/CVERecord?id=CVE-2026-48282" target="_blank" CVE-2026-48282 /a Adobe ColdFusion Path Traversal Vulnerability /li /ul p This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. /p p a href="https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk" Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk /a establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. /p p While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" KEV Catalog vulnerabilities /a . CISA will continue to add vulnerabilities to the catalog that meet the a href="https://www.cisa.gov/known-exploited-vulnerabilities" specified criteria /a . /p p Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s a href="https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w" target="_blank" KEV Nomination Form /a . Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance. nbsp; /p

VulnerabilityCISA·21d ago
Hitachi Energy PROMOD V

p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-188-02.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong Hitachi Energy is aware of insecure HTTP transmission vulnerability in PROMOD V product versions listed in this document. This vulnerability could allow attackers to intercept or manipulate sensitive data in transit, potentially leading to credential theft, session hijacking, or unauthorized access. /strong /p p The following versions of Hitachi Energy PROMOD V are affected: /p ul li PROMOD V vers:PROMOD_V/ lt;=1.0.10 /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 7.1 /td td Hitachi Energy /td td Hitachi Energy PROMOD V /td td Reliance on HTTP instead of HTTPS /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Energy /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong Switzerland /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2026-10763 /a /h3 div class="csaf-accordion-content" p PROMOD V is using insecure HTTP communication instead of HTTPS. The vulnerability is due to the lack of HTTPS support from 3rd party Digipede server. /p p a href="https://www.cve.org/CVERecord?id=CVE-2026-10763" View CVE Details /a /p hr h4 Affected Products /h4 h5 Hitachi Energy PROMOD V /h5 div class="ics-vendor-version-status" div class="ics-vendor" strong Vendor: /strong br Hitachi Energy /div div class="ics-version" strong Product Version: /strong br PROMOD V versions 1.0.10 and prior /div div class="ics-status" strong Product Status: /strong br known_affected /div /div div class="ics-remediations" h6 Remediations /h6 p strong Vendor fix /strong br Upgrade to version 1.0.11 and enable HTTPS on Digipede server. [2] Refer to “1.0.11 PROMOD V User Guide”, Section 2 Essential Skills- gt;Running PROMOD V- gt;Digipede Grid. Alternatively, refer to the same section in the online help contained in the application. /p p strong Mitigation /strong br Apply general mitigation factors /p /div p strong Relevant CWE: /strong a href="https://cwe.mitre.org/data/definitions/1428.html" CWE-1428 Reliance on HTTP instead of HTTPS /a /p hr h4 Metrics /h4 div class="csaf-table csaf-metrics-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS Version /th th role="columnheader" Base Score /th th role="columnheader" Base Severity /th th role="columnheader" Vector String /th /tr /thead tbo

VulnerabilityCISA·21d ago
Hydro-Québec Le Circuit Electrique charging station backend

p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-188-01.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong Successful exploitation of these vulnerabilities could lead to privilege escalation, or result in a denial-of-service attack. /strong /p p The following versions of Hydro-Québec Le Circuit Electrique charging station backend are affected: /p ul li Le Circuit Electrique charging station backend /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 9.8 /td td Hydro-Québec /td td Hydro-Québec Le Circuit Electrique charging station backend /td td Improper Access Control, Improper Restriction of Excessive Authentication Attempts, Insufficient Session Expiration /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Transportation Systems /li li strong Countries/Areas Deployed: /strong Canada /li li strong Company Headquarters Location: /strong Canada /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2026-20744 /a /h3 div class="csaf-accordion-content" p The charging station websocket endpoint accepts connections without proper authentication, which could lead to privilege escalation. /p p a href="https://www.cve.org/CVERecord?id=CVE-2026-20744" View CVE Details /a /p hr h4 Affected Products /h4 h5 Hydro-Québec Le Circuit Electrique charging station backend /h5 div class="ics-vendor-version-status" div class="ics-vendor" strong Vendor: /strong br Hydro-Québec /div div class="ics-version" strong Product Version: /strong br Hydro-Québec Le Circuit Electrique charging station backend: lt;June_2026 /div div class="ics-status" strong Product Status: /strong br known_affected /div /div div class="ics-remediations" h6 Remediations /h6 p strong Mitigation /strong br Hydro-Québec has updated the majority of charging stations to disable OCPP, mitigating the risk of exploitation. Hydro-Québec has also implemented authentication systems to mitigate the issue for certain charging stations which are still reliant on OCPP. Contact Hydro-Québec with any additional questions. /p /div p strong Relevant CWE: /strong a href="https://cwe.mitre.org/data/definitions/284.html" CWE-284 Improper Access Control /a /p hr h4 Metrics /h4 div class="csaf-table csaf-metrics-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS Version /th th role="columnheader" Base Score /th th role="columnheader" Base Severity /th th role="columnheader" Vector String

VulnerabilityCISA·21d ago
Siemens Mendix Studio Pro

p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-188-04.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong Mendix Studio Pro versions before V11.12 are affected by a file parsing vulnerability that could be triggered when the application reads specially crafted malicious project during the build pipeline. This could allow an attacker to execute arbitrary code in the context of that user. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available. /strong /p p The following versions of Siemens Mendix Studio Pro are affected: /p ul li Mendix Studio Pro 10.11 vers:all/* /li li Mendix Studio Pro 10.12 vers:all/* nbsp; /li li Mendix Studio Pro 10.13 vers:all/* /li li Mendix Studio Pro 10.14 vers:all/* nbsp; /li li Mendix Studio Pro 10.15 vers:all/* nbsp; /li li Mendix Studio Pro 10.16 vers:all/* nbsp; /li li Mendix Studio Pro 10.17 vers:all/* nbsp; /li li Mendix Studio Pro 10.18 vers:all/* nbsp; /li li Mendix Studio Pro 10.19 vers:all/* nbsp; /li li Mendix Studio Pro 10.20 vers:all/* nbsp; /li li Mendix Studio Pro 10.21 vers:all/* nbsp; /li li Mendix Studio Pro 10.22 vers:all/* nbsp; /li li Mendix Studio Pro 10.23 vers:all/* nbsp; /li li Mendix Studio Pro 10.24 vers:intdot/ lt;10.24.21 /li li Mendix Studio Pro 11.0 vers:all/* nbsp; /li li Mendix Studio Pro 11.1 vers:all/* nbsp; /li li Mendix Studio Pro 11.10 vers:all/* nbsp; /li li Mendix Studio Pro 11.11 vers:all/* nbsp; /li li Mendix Studio Pro 11.2 vers:all/* nbsp; /li li Mendix Studio Pro 11.3 vers:all/* nbsp; /li li Mendix Studio Pro 11.4 vers:all/* nbsp; /li li Mendix Studio Pro 11.5 vers:all/* nbsp; /li li Mendix Studio Pro 11.6 vers:intdot/ lt;11.6.7 nbsp; /li li Mendix Studio Pro 11.7 vers:all/* nbsp; /li li Mendix Studio Pro 11.8 vers:all/* /li li Mendix Studio Pro 11.9 vers:all/* nbsp; /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 5.4 /td td Siemens /td td Siemens Mendix Studio Pro /td td Improper Control of Generation of Code ('Code Injection') /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Critical Manufacturing, Energy /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong Germany /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2026-48192 /a /h3 div class="csaf-accordion-content" p Affected versions of Mendix Studio Pr

VulnerabilityCISA·21d ago
Digi International PortServer TS, Digi One SP IA

p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-188-07.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong Successful exploitation of these vulnerabilities could allow an attacker to bypass authentication and gain access to restricted resources, obtain credentials, and inject malicious scripts. /strong /p p The following versions of Digi International PortServer TS, Digi One SP IA are affected: /p ul li PortServer TS /li li Digi One SP /li li Digi One SP IA /li li Digi One IA /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 5.9 /td td Digi International /td td Digi International PortServer TS, Digi One SP IA /td td Incorrect Authorization, Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Critical Manufacturing, Communications, Information Technology, Transportation Systems /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong United States /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2026-12352 /a /h3 div class="csaf-accordion-content" p The vulnerability allows an unauthenticated actor to bypass authentication and gain access to restricted resources on the device. /p p a href="https://www.cve.org/CVERecord?id=CVE-2026-12352" View CVE Details /a /p hr h4 Affected Products /h4 h5 Digi International PortServer TS, Digi One SP IA /h5 div class="ics-vendor-version-status" div class="ics-vendor" strong Vendor: /strong br Digi International /div div class="ics-version" strong Product Version: /strong br Digi International PortServer TS: lt;Firmware_2025, Digi International Digi One SP: lt;Firmware_2025, Digi International Digi One SP IA: lt;Firmware_2025, Digi International Digi One IA: lt;Firmware_2025 /div div class="ics-status" strong Product Status: /strong br known_affected /div /div div class="ics-remediations" h6 Remediations /h6 p strong Mitigation /strong br Digi International recommends users upgrade to Digi Connect EZ or Digi Connect EZ TS as a long term solution. If users are not able to upgrade at this time, the following actions should be taken: /p p strong Vendor fix /strong br For Digi PortServer TS: Enable HTTPS on the web server. /p p strong Mitigation /strong br Alternatively, disable the web server when it is not actively being used for configuration. /p p strong Mitigation /strong br Compensating control: If you cannot apply the HTTPS configuration, restrict

VulnerabilityCISA·21d ago
Hitachi Energy e-mesh EMS

p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-188-03.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong Hitachi Energy is aware of a buffer overflow vulnerability that affects e-mesh EMS product versions listed in this document. Successful exploitation of this vulnerability could lead to a buffer overflow condition, potentially resulting in application outages (denial of service) and possible arbitrary code execution. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation. /strong /p p The following versions of Hitachi Energy e-mesh EMS are affected: /p ul li Hitachi Energy e-mesh EMS 4.1.6, 4.4.2, 4.7.0 /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 8.1 /td td Hitachi Energy /td td Hitachi Energy e-mesh EMS /td td Heap-based Buffer Overflow /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Energy /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong Switzerland /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2026-42945 /a /h3 div class="csaf-accordion-content" p NGINX Plus and NGINX Open Source used in e-mesh EMS have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. e-mesh EMS versions using NGINX v1.30.0 and below are affected. /p p a href="https://www.cve.org/CVERecord?id=CVE-2026-42945" View CVE Details /a /p hr h4 Affected Products /h4 h5 Hitachi Energy e-mesh EMS /h5 div class="ics-vendor-version-status" div class="ics-vendor" strong Vendor: /strong br Hitachi Energy /div div class="ics-version" strong Product Version: /strong br e-mesh EMS versions 4.1.6, e-mesh EMS versions 4.4.2, e-mesh EMS versions 4.7.0 /div div class="ics-status" strong Product Status: /strong br known_affected /div /div div class="ics-remediations" h6 Remediations /h6 p strong Vendor fix /strong br Apply hotfix for respecti

VulnerabilityCISA·21d ago
Labcenter Proteus 9

p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-188-06.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong Successful exploitation of these vulnerabilities could disclose information and allow a malicious user to execute arbitrary code on affected installations. /strong /p p The following versions of Labcenter Proteus 9 are affected: /p ul li Proteus 9.1_SP4_Build_42914 /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 7.8 /td td Labcenter Electronics /td td Labcenter Proteus 9 /td td Out-of-bounds Write, Stack-based Buffer Overflow, Use After Free /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Communications, Critical Manufacturing, Defense Industrial Base, Energy, Healthcare and Public Health, Transportation Systems, Water and Wastewater /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong United Kingdom /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2026-42953 /a /h3 div class="csaf-accordion-content" p The application contains an out-of-bounds write vulnerability that can be exploited by an attacker to cause the program to write data past the end of an allocated memory buffer. This can lead to arbitrary code execution. /p p a href="https://www.cve.org/CVERecord?id=CVE-2026-42953" View CVE Details /a /p hr h4 Affected Products /h4 h5 Labcenter Proteus 9 /h5 div class="ics-vendor-version-status" div class="ics-vendor" strong Vendor: /strong br Labcenter Electronics /div div class="ics-version" strong Product Version: /strong br Labcenter Electronics Proteus: 9.1_SP4_Build_42914 /div div class="ics-status" strong Product Status: /strong br known_affected /div /div div class="ics-remediations" h6 Remediations /h6 p strong Vendor fix /strong br Labcenter recommends ensuring you are using the latest version (9.2 SPO) of the software. Version can be found by looking at the bottom left of the Proteus home page (Version 8 or higher) or by selecting the About ISIS or About ARES option from the Help menu. Update notifications appear in the new and information section of the home page where you can activate the download and installation directly. /p p strong Mitigation /strong br If you have questions or need help please contact Labcenter or your local distributor. /p /div p strong Relevant CWE: /strong a href="https://cwe.mitre.org/data/definitions/787.html" CWE-787 Out-of-bounds Write /a /p hr h4 Metrics /h4 div class="csaf-table csaf-metrics-table" table class="

VulnerabilityCISA·21d ago
Siemens SINEC OS

p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-188-05.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong SINEC OS before V4.0 contains multiple vulnerabilities. Siemens has released a new version for RUGGEDCOM RST2428P and recommends to update to the latest version. /strong /p p The following versions of Siemens SINEC OS are affected: /p ul li RUGGEDCOM RST2428P (6GK6242-6PA00) vers:intdot/ lt;4.0 nbsp; /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 9.8 /td td Siemens /td td Siemens SINEC OS /td td Improper Restriction of Operations within the Bounds of a Memory Buffer, Improper Resource Shutdown or Release, Integer Overflow or Wraparound, Stack-based Buffer Overflow, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Uncontrolled Recursion, Out-of-bounds Read, Covert Timing Channel, Improper Input Validation, Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'), Improper Update of Reference Count, Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition'), Multiple Releases of Same Resource or Handle, Permissive Regular Expression, Expired Pointer Dereference, Incorrect Bitwise Shift of Integer, Out-of-bounds Write, User Interface (UI) Misrepresentation of Critical Information, Improper Access Control, Insertion of Sensitive Information Into Sent Data, Inefficient Algorithmic Complexity, Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Authentication Bypass by Primary Weakness, NULL Pointer Dereference, Active Debug Code, Loop with Unreachable Exit Condition ('Infinite Loop'), Missing Synchronization, External Control of File Name or Path, Privilege Dropping / Lowering Errors, Use of Web Browser Cache Containing Sensitive Information /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Critical Manufacturing, Transportation Systems, Energy, Healthcare and Public Health, Financial Services, Government Services and Facilities /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong Germany /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2025-1352 /a /h3 div class="csaf-accordion-content" p A vulnerability has been found in GNU elfutils 0.192 and classified as critical. This vulnerability affects the function __libdw_thread_tail in the library libdw_alloc.c of the component eu-readelf. The manipulation of the argument w leads to me

VulnerabilityCISA·21d ago
CISA Adds Three Known Exploited Vulnerabilities to Catalog

p CISA has added three new vulnerabilities to its a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" Known Exploited Vulnerabilities (KEV) Catalog /a , based on evidence of active exploitation. /p ul li a href="https://www.cve.org/CVERecord?id=CVE-2026-48908" target="_blank" CVE-2026-48908 /a JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability /li li a href="https://www.cve.org/CVERecord?id=CVE-2026-55255" target="_blank" CVE-2026-55255 /a Langflow Authorization Bypass Through User-Controlled Key Vulnerability nbsp; /li li a href="https://www.cve.org/CVERecord?id=CVE-2026-56290" target="_blank" CVE-2026-56290 /a Joomlack Page Builder Improper Access Control Vulnerability /li /ul p These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. /p p a href="https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk" Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk /a establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. /p p While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" KEV Catalog vulnerabilities /a . CISA will continue to add vulnerabilities to the catalog that meet the a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities" specified criteria /a . /p p Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s a href="https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w" target="_blank" KEV Nomination Form /a . Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance. nbsp; /p

VulnerabilityThe Hacker News·21d ago
What Changes When Your Software Supply Chain Includes AI Writing Your Code?

Software supply chain security was hard enough. Then AI joined the build pipeline. For five years, "software supply chain security" meant one question: what's in your code? Which open-source packages, which versions, which transitive dependencies three layers deep that nobody chose on purpose? SolarWinds, Log4Shell, and XZ Utils all taught the same lesson: the risk lives less in the code a