Analysis by Black Kite warns that ransomware ecosystem is becoming bigger and more fragmented
Security & IT News
LiveReal-time news from 13+ trusted sources — BleepingComputer, The Hacker News, Krebs on Security, Dark Reading & more.
Fake FBI agents are using deepfake videos, spoofed IC3 websites and false recovery claims to steal money and personal information from people who were scammed before, the FBI warns.
p a href= https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-204-05.json strong View CSAF /strong /a /p h2 Summary /h2 p strong Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to restricted system directories outside of the application's intended directory. /strong /p p The following versions of Rockwell Automation ThinManager are affected: /p ul li ThinManager gt;=13.0.0| lt;13.0.7, gt;=13.1.0| lt;13.1.5, gt;=13.2.0| lt;13.2.4, gt;=14.0.0| lt;14.0.2 /li /ul div class= csaf-table table class= tablesaw tablesaw-stack data-tablesaw-mode= stack data-tablesaw-minimap thead tr th role= columnheader data-tablesaw-priority= persist CVSS /th th role= columnheader Vendor /th th role= columnheader Equipment /th th role= columnheader Vulnerabilities /th /tr /thead tbody tr td v3 8.1 /td td Rockwell Automation /td td Rockwell Automation ThinManager /td td Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Chemical, Critical Manufacturing, Energy, Food and Agriculture, Water and Wastewater /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong United States /li /ul hr h2 Vulnerabilities /h2 div class= csaf-accordion p a class= csaf-accordion-toggle-all href= # Expand All + /a /p div class= csaf-accordion-item h3 a class= csaf-accordion-toggle href= # CVE-2026-11917 /a /h3 div class= csaf-accordion-content p A path traversal security issue exists within Rockwell Automation ThinManager software due to improper limitation of file save operations within the API. An authenticated attacker could exploit this vulnerability to write arbitrary files to restricted system directories outside of the application's intended directory. /p p a href= https://www.cve.org/CVERecord?id=CVE-2026-11917 View CVE Details /a /p hr h4 Affected Products /h4 h5 Rockwell Automation ThinManager /h5 div class= ics-vendor-version-status div class= ics-vendor strong Vendor: /strong br Rockwell Automation /div div class= ics-version strong Product Version: /strong br Rockwell Automation ThinManager: gt;=13.0.0| lt;13.0.7, Rockwell Automation ThinManager: gt;=13.1.0| lt;13.1.5, Rockwell Automation ThinManager: gt;=13.2.0| lt;13.2.4, Rockwell Automation ThinManager: gt;=14.0.0| lt;14.0.2 /div div class= ics-status strong Product Status: /strong br known_affected /div /div div class= ics-remediations h6 Remediations /h6 p strong Mitigation /strong br Users using the affected software, should upgrade to one of the corrected versions as follows: /p p strong Vendor fix /strong br ThinManager Versions 13.0.0 - 13.0.7 -- gt; 13.0.8 /p p strong Vendor fix /strong br ThinManager Versions 13.1.0 - 13.1.5 -- gt; 13.1.6 /p p strong Vendor fix /strong br ThinManager Versions 13.2.0 - 13.2.4 -- gt; 13.2.5 /p p strong Vend
p a href= https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-08.json strong View CSAF /strong /a /p h2 Summary /h2 p strong Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product. /strong /p p The following versions of Rockwell Automation 1718-AENTR/1719-AENTR are affected: /p ul li 1718/ 1719 Ex I/O 3.011 nbsp; /li /ul div class= csaf-table table class= tablesaw tablesaw-stack data-tablesaw-mode= stack data-tablesaw-minimap thead tr th role= columnheader data-tablesaw-priority= persist CVSS /th th role= columnheader Vendor /th th role= columnheader Equipment /th th role= columnheader Vulnerabilities /th /tr /thead tbody tr td v3 7.5 /td td Rockwell Automation /td td Rockwell Automation 1718-AENTR/1719-AENTR /td td Allocation of Resources Without Limits or Throttling /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Critical Manufacturing /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong United States /li /ul hr h2 Vulnerabilities /h2 div class= csaf-accordion p a class= csaf-accordion-toggle-all href= # Expand All + /a /p div class= csaf-accordion-item h3 a class= csaf-accordion-toggle href= # CVE-2026-9140 /a /h3 div class= csaf-accordion-content p A denial-of-service security issue exists in the 1719-AENTR. The security issue stems from improper handling of a UDP unicast network storm, which causes the device to become overloaded and lose communication. A power cycle is required to recover. /p p a href= https://www.cve.org/CVERecord?id=CVE-2026-9140 View CVE Details /a /p hr h4 Affected Products /h4 h5 Rockwell Automation 1718-AENTR/1719-AENTR /h5 div class= ics-vendor-version-status div class= ics-vendor strong Vendor: /strong br Rockwell Automation /div div class= ics-version strong Product Version: /strong br Rockwell Automation 1718/ 1719 Ex I/O: 3.011 /div div class= ics-status strong Product Status: /strong br known_affected /div /div div class= ics-remediations h6 Remediations /h6 p strong Vendor fix /strong br Rockwell Automation recommends users to upgrade to 1718/ 1719 Ex I/O version 3.012 or later. /p p strong Mitigation /strong br Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices (https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight). br a href= https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight /a /p p strong Mitigation /strong br For more information, see Rockwell Automation Security Advisories: https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html. br a href= https://www.rockwellautomation.com/en-
p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-03.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong Opcenter X before V2604 contain an authentication bypass vulnerability that could allow an attacker to gain full unauthorized access to the application. Siemens has released a new version for Opcenter X and recommends to update to the latest version. /strong /p p The following versions of Siemens Opcenter X are affected: /p ul li Opcenter X vers:intdot/ lt;2604 /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 10 /td td Siemens /td td Siemens Opcenter X /td td Improper Verification of Cryptographic Signature /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Critical Manufacturing /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong Germany /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2026-56451 /a /h3 div class="csaf-accordion-content" p Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header. This could allow an unauthenticated remote attacker to forge arbitrary JWT, bypass authentication mechanisms and impersonate any user including administrative accounts, potentially gaining full unauthorized access to the application. /p p a href="https://www.cve.org/CVERecord?id=CVE-2026-56451" View CVE Details /a /p hr h4 Affected Products /h4 h5 Siemens Opcenter X /h5 div class="ics-vendor-version-status" div class="ics-vendor" strong Vendor: /strong br Siemens /div div class="ics-version" strong Product Version: /strong br Opcenter X lt; V2604 /div div class="ics-status" strong Product Status: /strong br known_affected /div /div div class="ics-remediations" h6 Remediations /h6 p strong Vendor fix /strong br Update to V2604 or later version br a href="https://support.sw.siemens.com/product/206159703/" https://support.sw.siemens.com/product/206159703/ /a /p /div p strong Relevant CWE: /strong a href="https://cwe.mitre.org/data/definitions/347.html" CWE-347 Improper Verification of Cryptographic Signature /a /p hr h4 Metrics /h4 div class="csaf-table csaf-metrics-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS Version /th th role="columnheader" Base Score /th th role="columnheader" Base Severity /th th role="columnheader" Vector String /th /tr /thead tbody tr td 3.1 /td td 10 /td td CRITICAL /td td a
p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-07.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong Successful exploitation of this vulnerability could allow an attacker to impersonate an authorized user on the FTSP server, resulting in unauthorized access to system configurations. /strong /p p The following versions of Rockwell Automation FactoryTalk Services Platform are affected: /p ul li FactoryTalk Directory (FTSP) 6.60 nbsp; /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 7.8 /td td Rockwell Automation /td td Rockwell Automation FactoryTalk Services Platform /td td Weak Authentication /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Critical Manufacturing /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong United States /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2026-10714 /a /h3 div class="csaf-accordion-content" p A security issue exists within FactoryTalk Services Platform (FTSP), allowing an attacker to bypass JWT signature validation during Okta Web Authentication. The vulnerability stems from the application not verifying that the JWT algorithm is configured for RSA, enabling an attacker to set the algorithm to "none" and craft forged tokens. This could allow an authenticated low-privilege user to impersonate any authorized user on the FTSP server, resulting in unauthorized access to system configuration and the ability to grant permissions to other systems protected by FTSP. /p p a href="https://www.cve.org/CVERecord?id=CVE-2026-10714" View CVE Details /a /p hr h4 Affected Products /h4 h5 Rockwell Automation FactoryTalk Services Platform /h5 div class="ics-vendor-version-status" div class="ics-vendor" strong Vendor: /strong br Rockwell Automation /div div class="ics-version" strong Product Version: /strong br Rockwell Automation FactoryTalk Directory (FTSP): 6.60 /div div class="ics-status" strong Product Status: /strong br known_affected /div /div div class="ics-remediations" h6 Remediations /h6 p strong Mitigation /strong br Users using FactoryTalk Services Platform v6.60 should apply either the individual patch (RAID 1158263) or the February 2026 Patch Roll-up, or later update. /p p strong Mitigation /strong br Users using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell's security best practices. br a href="https://support.rockwellautomation.com/app/answers/answer_view/a_id
p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-06.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong CADRA is affected by multiple zlib and Foxit vulnerabilities. Siemens has released a new version for CADRA and recommends to update to the latest version. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available. /strong /p p The following versions of Siemens CADRA are affected: /p ul li CADRA vers:intdot/ lt;2511, vers:all/* nbsp; /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 9.8 /td td Siemens /td td Siemens CADRA /td td Improper Input Validation, Incorrect Bitwise Shift of Integer, Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Integer Overflow or Wraparound, Access of Resource Using Incompatible Type ('Type Confusion') /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Chemical, Commercial Facilities, Communications, Energy /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong Germany /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2005-2096 /a /h3 div class="csaf-accordion-content" p zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete code description of a length greater than 1, which leads to a buffer overflow, as demonstrated using a crafted PNG file. /p p a href="https://www.cve.org/CVERecord?id=CVE-2005-2096" View CVE Details /a /p hr h4 Affected Products /h4 h5 Siemens CADRA /h5 div class="ics-vendor-version-status" div class="ics-vendor" strong Vendor: /strong br Siemens /div div class="ics-version" strong Product Version: /strong br CADRA lt; V2511 /div div class="ics-status" strong Product Status: /strong br known_affected /div /div div class="ics-remediations" h6 Remediations /h6 p strong Vendor fix /strong br Update to V2511 or later version /p /div p strong Relevant CWE: /strong a href="https://cwe.mitre.org/data/definitions/20.html" CWE-20 Improper Input Validation /a /p hr h4 Metrics /h4 div class="csaf-table csaf-metrics-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS Version /th th role="columnheader" Base Score /th th role="columnheader" Base Severity /th th role="columnheader" Vector String /th /tr /thead tbo
p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-10.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong Successful exploitation of these vulnerabilities could allow for a local attacker to execute arbitrary files, alter configurations, or execute arbitrary code. /strong /p p The following versions of Rockwell Automation Studio 5000 Logix Designer are affected: /p ul li Studio 5000 Logix Designer V36.00 (CVE-2026-9108) /li li Studio 5000 Logix Designer V35.00 (CVE-2026-9108, CVE-2026-9127, CVE-2026-9128) /li li Studio 5000 Logix Designer V35.01 (CVE-2026-9108) /li li Studio 5000 Logix Designer gt;=V34.00| lt;=V34.03 (CVE-2026-9108) /li li Studio 5000 Logix Designer gt;=V33.00| lt;=V33.03 (CVE-2026-9108) /li li Studio 5000 Logix Designer gt;=V32.00| lt;=V32.04 (CVE-2026-9108, CVE-2026-9127, CVE-2026-9128) /li li Studio 5000 Logix Designer V34.00 (CVE-2026-9127) /li li Studio 5000 Logix Designer V34.01 (CVE-2026-9127) /li li Studio 5000 Logix Designer V33.00 (CVE-2026-9127) /li li Studio 5000 Logix Designer V33.02 (CVE-2026-9127) /li li Studio 5000 Logix Designer gt;=V34.00| lt;=V34.02 (CVE-2026-9128) /li li Studio 5000 Logix Designer gt;=V33.00| lt;=V33.02 (CVE-2026-9128) /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 7.5 /td td Rockwell Automation /td td Rockwell Automation Studio 5000 Logix Designer /td td Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Incorrect Authorization, Unquoted Search Path or Element /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Critical Manufacturing /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong United States /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2026-9108 /a /h3 div class="csaf-accordion-content" p A path traversal security issue exists within Studio 5000 Logix Designer due to improper limitation of file paths within ACD project files. The software does not sanitize or validate file names embedded in the ACD file structure during the project opening procedure, allowing path traversal sequences to escape the intended extraction directory. If exploited, an attacker could craft a malicious ACD project file that results in arbitrary files being written to attacker-controlled locations on the file system, potentially leading to code execution. /p p a href="https://www.cve.org/CVERecord?id=CVE-2026-9108" View CVE Details /a /p hr h4 Affected Products /h4 h5 Rockwell Automation Stud
p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-09.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product. /strong /p p The following versions of Rockwell Automation 1734 POINT I/O are affected: /p ul li 1734 POINT I/O 3.023 nbsp; /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 7.5 /td td Rockwell Automation /td td Rockwell Automation 1734 POINT I/O /td td Allocation of Resources Without Limits or Throttling /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Critical Manufacturing /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong United States /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2026-10573 /a /h3 div class="csaf-accordion-content" p A denial-of-service security issue exists in 1734 POINT I/O module. The security issue stems from improper handling of crafted CIP messages, which can cause the module to enter a faulted state. A restart is required to recover. /p p a href="https://www.cve.org/CVERecord?id=CVE-2026-10573" View CVE Details /a /p hr h4 Affected Products /h4 h5 Rockwell Automation 1734 POINT I/O /h5 div class="ics-vendor-version-status" div class="ics-vendor" strong Vendor: /strong br Rockwell Automation /div div class="ics-version" strong Product Version: /strong br Rockwell Automation 1734 POINT I/O: 3.023 /div div class="ics-status" strong Product Status: /strong br known_affected /div /div div class="ics-remediations" h6 Remediations /h6 p strong Mitigation /strong br Rockwell Automation recommends users are to migrate to 5034-OB8. /p p strong Mitigation /strong br Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices (https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight). br a href="https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight" https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight /a /p p strong Mitigation /strong br For more information, see Rockwell Automation Security Advisories: https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html. br a href="https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html" https://www.r
p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-02.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong Palo Alto Networks has published [1] information on vulnerabilities in PAN-OS. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Customers are advised to consult and implement the workarounds provided in Palo Alto Networks' upstream security notifications. [1] https://security.paloaltonetworks.com/ /strong /p p The following versions of Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW are affected: /p ul li RUGGEDCOM APE1808 vers:all/* nbsp; /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 7.2 /td td Siemens /td td Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW /td td Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Missing Authorization, Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Critical Manufacturing /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong Germany /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2026-0266 /a /h3 div class="csaf-accordion-content" p A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface. This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma® Access are not affected by this vulnerability. /p p a href="https://www.cve.org/CVERecord?id=CVE-2026-0266" View CVE Details /a /p hr h4 Affected Products /h4 h5 Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW /h5 div class="ics-vendor-version-status" div class="ics-vendor" strong Vendor: /strong br Siemens /div div class="ics-version" strong Product Version: /strong br RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW /div div class="ics-status" strong Product Status: /strong br known_affected /div /div div class="ics-remediations" h6 Remediations /h6 p strong Vendor fix /strong br Contact customer support to receive patch and update information /p /div p strong Relevant CWE: /strong a href="https://cwe.mitre.org/data/definitions/79.html" CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') /a /p hr h4 Metric
p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-05.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong Multiple Siemens products are affected by unquoted search path vulnerability in IAM Client. This could allow an authenticated local attacker to perform privilege escalation. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available. /strong /p p The following versions of Siemens IAM Client are affected: /p ul li COMOS V10.4.5 vers:intdot/ lt;10.4.5.0.2 nbsp; /li li COMOS V10.6 vers:intdot/ lt;10.6.1 nbsp; /li li Designcenter NX vers:intdot/ lt;2512.7000 nbsp; /li li Simcenter 3D vers:intdot/ lt;2512.7000 nbsp; /li li Simcenter Femap V2506 vers:intdot/ lt;2506.0003 nbsp; /li li Simcenter Femap V2512 vers:intdot/ lt;2512.0002 nbsp; /li li Simcenter Nastran vers:intdot/ lt;2606 nbsp; /li li Simcenter STAR-CCM+ vers:intdot/ lt;2606 nbsp; /li li Solid Edge SE2025 vers:intdot/ lt;225.0.13.3 nbsp; /li li Solid Edge SE2026 vers:intdot/ lt;226.0.04.003 nbsp; /li li Teamcenter Visualization V2412 vers:intdot/ lt;2412.0012 nbsp; /li li Teamcenter Visualization V2506 vers:intdot/ lt;2506.0009 nbsp; /li li Teamcenter Visualization V2512 vers:intdot/ lt;2512.2605 nbsp; /li li Tecnomatix Plant Simulation V2404 vers:intdot/ lt;2404.0022 nbsp; /li li Tecnomatix Plant Simulation V2504 vers:intdot/ lt;2504.0010 nbsp; /li li Tecnomatix Process Simulate vers:intdot/ lt;2606 nbsp; /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 6.7 /td td Siemens /td td Siemens IAM Client /td td Untrusted Search Path /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Chemical, Critical Manufacturing, Energy /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong Germany /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2025-40945 /a /h3 div class="csaf-accordion-content" p Untrusted search path in IAM Client SDK may allow an authenticated user to potentially enable escalation of privilege via local access. /p p a href="https://www.cve.org/CVERecord?id=CVE-2025-40945" View CVE Details /a /p hr h4 Affected Products /h4 h5 Siemens IAM Client /h5 div class="ics-vendor-version-status" div class="ics-vendor" strong Vendor: /strong br Siemens /div div class="ics-version" strong Product Version: /strong br COMOS V10.4.5 lt; V1
p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-04.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong SIDIS Secured SmartPlug before V7.26.0310 is affected by multiple vulnerabilities in the components OpenSSL, OpenSSH, and several other packages as described below. Siemens has released a new version of SIDIS Secured SmartPlug and recommends to update to the latest version. /strong /p p The following versions of Siemens SIDIS Secured SmartPlug are affected: /p ul li SIDIS Secured SmartPlug vers:intdot/ lt;7.26.0310 nbsp; /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 9.8 /td td Siemens /td td Siemens SIDIS Secured SmartPlug /td td Improper Enforcement of Message Integrity During Transmission in a Communication Channel, Reusing a Nonce, Key Pair in Encryption, Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Integer Overflow or Wraparound, Out-of-bounds Read, Covert Timing Channel, Detection of Error Condition Without Action, Incorrect Authorization /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Critical Manufacturing /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong Germany /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2022-23303 /a /h3 div class="csaf-accordion-content" p The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9494. /p p a href="https://www.cve.org/CVERecord?id=CVE-2022-23303" View CVE Details /a /p hr h4 Affected Products /h4 h5 Siemens SIDIS Secured SmartPlug /h5 div class="ics-vendor-version-status" div class="ics-vendor" strong Vendor: /strong br Siemens /div div class="ics-version" strong Product Version: /strong br SIDIS Secured SmartPlug lt; V7.26.0310 /div div class="ics-status" strong Product Status: /strong br known_affected /div /div div class="ics-remediations" h6 Remediations /h6 p strong Vendor fix /strong br Update to V7.26.0310 or later version /p /div p strong Relevant CWE: /strong a href="https://cwe.mitre.org/data/definitions/924.html" CWE-924 Improper Enforcement of Message Integrity During Transmission in a Communication Channel /a /p hr h4 Metrics /h4 div class="csaf-table csaf-metrics-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="co
p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-01.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk. /strong /p p The following versions of Tycon Systems TPDIN-Monitor-WEB2 are affected: /p ul li TPDIN-Monitor-WEB2 2.3.9 nbsp; /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 9.8 /td td Tycon Systems /td td Tycon Systems TPDIN-Monitor-WEB2 /td td Authentication Bypass Using an Alternate Path or Channel, Cleartext Storage of Sensitive Information /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Critical Manufacturing /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong United States /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2026-61884 /a /h3 div class="csaf-accordion-content" p The web management interface of the affected device does not perform server-side validation of credentials during the login process. By submitting empty values for both credential fields, an unauthenticated remote attacker can bypass the authentication check and establish a valid administrative session. This grants full access to device controls including power relay management, device reboot, remote access service configuration, and network settings, which could allow an attacker to disrupt connected infrastructure or cause physical damage to equipment. /p p a href="https://www.cve.org/CVERecord?id=CVE-2026-61884" View CVE Details /a /p hr h4 Affected Products /h4 h5 Tycon Systems TPDIN-Monitor-WEB2 /h5 div class="ics-vendor-version-status" div class="ics-vendor" strong Vendor: /strong br Tycon Systems /div div class="ics-version" strong Product Version: /strong br Tycon Systems TPDIN-Monitor-WEB2: 2.3.9 /div div class="ics-status" strong Product Status: /strong br known_affected /div /div div class="ics-remediations" h6 Remediations /h6 p strong Vendor fix /strong br Tycon Systems did not respond to CISA's attempts at coordination. Users of Tycon Systems TPDIN-Monitor-WEB2 are encouraged to contact Tycon Systems and keep their systems up to date. br a href="https://www.tyconsystems.com/contact" https://www.tyconsystems.com/contact /a /p /div p strong Relevant CWE: /strong a href="https://cwe.mitre.org/data/definitions/288.html" CWE-288 Authentication
FBI warned of deepfake videos of IC3 leadership directing users to spoofed complaint sites
p CISA has added four new vulnerabilities to its a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" Known Exploited Vulnerabilities (KEV) Catalog /a , based on evidence of active exploitation. /p ul li a href="https://www.cve.org/CVERecord?id=CVE-2021-27137" target="_blank" CVE-2021-27137 /a DD-WRT Stack-Based Buffer Overflow Vulnerability /li li a href="https://www.cve.org/CVERecord?id=CVE-2026-0770" target="_blank" CVE-2026-0770 /a Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability nbsp; /li li a href="https://www.cve.org/CVERecord?id=CVE-2026-63030" target="_blank" CVE-2026-63030 /a WordPress Core Interpretation Conflict Vulnerability nbsp; /li li a href="https://www.cve.org/CVERecord?id=CVE-2026-60137" target="_blank" CVE-2026-60137 /a WordPress Core SQL Injection Vulnerability /li /ul p These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. /p p a href="https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk" Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk /a establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. /p p While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" KEV Catalog vulnerabilities /a . CISA will continue to add vulnerabilities to the catalog that meet the a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities" specified criteria /a . /p p Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s a href="https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w" target="_blank" KEV Nomination Form /a . Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance. nbsp; /p
An Android app that can draw over other windows and write to shared storage can slip instructions to the AI agent driving that phone, in text no human eye will ever see. Two more steps, and the same app is running commands on the PC driving the agent. Researchers demonstrated that chain, plus six other attacks, against five open-source mobile agent frameworks: AppAgent, AppAgentX,
Every patch is a confession. The moment a vendor ships a security fix, the diff between the old code and the new code tells anyone watching exactly what was broken and where. Turn that diff back into a working exploit, and you can hit every system that hasn't updated yet. This is N-day exploitation, and it's always been a race: the vendor patches, the clock starts, and defenders try to deploy
A cloud tenant using nothing but ordinary GPU access can push a data center's power draw up and down fast enough to threaten the grid it runs on, with no exploit and no break-in. That is the claim behind Bit2Watt, described by three Zhejiang University researchers in a paper accepted to CHES 2026, the IACR's hardware-security conference, and the evidence splits in two: they measured the power
It’s a lot : According to information obtained by The Tech , MIT is spending over $3 million on more than 500 AI surveillance cameras in academic buildings, residence halls, and outdoor areas along Memorial Drive. Installation of the new cameras, along with the wiring and infrastructure that will support them, began November 2025 and will likely continue until September 2026. Technical specifications for the cameras suggest that they will be capable of collecting real-time face and object classification data, including detection of motion, loitering, crowds, face masks, and camera tampering. Individuals can also be automatically classified on the basis of clothing color, gender, and age, up to a distance of 35 feet (11 meters) from the camera. According to a statement from MIT spokesperson Kimberly Allen, any collected data is “retained up to 30 days,” unless an exception is granted. […] Most of the new cameras, which are part of Hanwha’s Wisenet AI line , are marketed for their ability to identify and classify multiple objects with deep learning algorithms. They support resolutions ranging from 2MP to 4K while also recognizing faces, license plates, vehicles, and other objects in real time. Nearly all cameras will accommodate a wide range of pan, tilt, rotate, and zoom motion and will be monitored continually with Ai-RGUS , an AI camera software. Yikes.
The U.S. Justice Department has seized more than 1,000 websites and blocked 1,970 domains used to stream FIFA World Cup 2026 matches without authorization. [...]