View CSAF Summary Successful exploitation of these vulnerabilities could allow an unauthenticated network-adjacent attacker to crash critical IEC 61850 services or execute arbitrary code, disrupting or compromising protection, visibility, and control functions. The following versions of MZ Automation libIEC61850 are…
Johnson Controls XAAP Android
View CSAF Summary Successful exploitation of this vulnerability could result in an attacker obtaining confidential information from the device. The following versions of Johnson Controls XAAP Android are affected: XAAP Android
Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite Executive summary A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS)…
Rockwell Automation ThinManager
View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to restricted system directories outside of the application’s intended directory. The following versions of Rockwell Automation ThinManager are affected: ThinManager >=13.0.0|=13.1.0|=13.2.0|=14.0.0|
Weintek cMT3092X
View CSAF Summary Successful exploitation of these vulnerabilities could allow a non-privileged user to escalate privileges or view the credentials of other users. The following versions of Weintek cMT3092X are affected: cMT3092X firmware
Bing Images Vulnerability Lets Attackers Execute Remote Code on Microsoft Servers
Three critical remote code execution (RCE) vulnerabilities in Microsoft’s infrastructure, with two flaws in Bing Images allowing attackers to hijack backend image-processing servers using nothing more than a crafted SVG file. The findings, disclosed responsibly by XBOW and now patched,…
Certighost Active Directory CS Exploit Allows Low-Privileged Users to Compromise Domain
A newly disclosed Active Directory Certificate Services (AD CS) vulnerability, dubbed Certighost, allowed a low-privilege domain user to impersonate a Domain Controller and take over an entire Active Directory domain. Tracked as CVE-2026-54121, the flaw was patched in Microsoft’s July…
Special Edition: What Cyber Experts Say About the Chick-Fil-a Breach
Incident Overview and Compromised Data On July 13, 2026, security teams verified that unauthorized actors had compromised Chick-fil-A One profiles using an automated credential stuffing attack utilizing email addresses and… The post Special Edition: What Cyber Experts Say About the…
By The Time You See The Ransom Note, Your Backups Are Already Gone
According to Mandiant’s M-Trends 2025 report, when organizations discover a ransomware intrusion on their own (without being tipped off by law enforcement or, ironically, by the attacker’s ransom note), the median… The post By The Time You See The Ransom Note,…
OpenAI scored an own goal with Hugging Face attack, showing how open Chinese models are winning
Closed models with guardrails can still cause harm, but may also not be able to fix problems they caused This article has been indexed from www.theregister.com – Articles Read the original article: OpenAI scored an own goal with Hugging Face…
DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts
The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to build payloads, oversee earnings, and manage various aspects related to victims. Swiss cybersecurity company PRODAFT is tracking the centrally administered…
Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments as part of a new data extortion campaign. “Attackers chain a pre-authentication information…
CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking
For years, phishing campaigns targeting financial institutions followed the same playbook. Victims were tricked into entering usernames and passwords, attackers collected the credentials, and accounts were compromised later when an opportunity arose. That model is changing. Recent investigations into insurance-focused…
Microsoft ends Exchange 2016/2019 ESU support
Microsoft has announced it will terminate Extended Security Update support for Exchange Server 2016 and 2019 in October 2025, marking the final end of security patches for these widely deployed email server versions. This article has been indexed from CyberMaterial…
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba’s JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the privileges of the Java process.…
IT Security News Hourly Summary 2026-07-25 15h : 1 posts
1 posts were published in the last hour 12:31 : AI, Cybersecurity, and Public Policy: Export Controls, Arms Races, and the “New Radium”
AI, Cybersecurity, and Public Policy: Export Controls, Arms Races, and the “New Radium”
AI, Cybersecurity, and Public Policy: Export Controls, Arms Races, and the “New Radium” On Cyber Security Today (Weekend), the host interviews Pratim Datta, a Kent State University professor and former global consultant, about the past six months of AI and…
The OpenAI Models That Hacked Hugging Face Were ‘Active on the Internet’ for Days
Plus: Russian hackers are trying to steal US nuclear scientists’ emails, the State Department bans known scammers from entering the United States, and more. This article has been indexed from Security Latest Read the original article: The OpenAI Models That…
Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git
Security researcher Yuhang Wu at depthfirst has published a working proof-of-concept (PoC) exploit that executes commands as git on an unpatched self-managed GitLab 18.11.3 server. An ordinary authenticated user triggers it by committing two crafted Jupyter notebooks and requesting their…
Hackers Use Stealer Logs to Bypass MFA and Launch Ransomware Attacks
Infostealer malware has now become the invisible thread linking petty credential theft to full-blown ransomware campaigns. Attackers no longer bother forcing their way through firewalls when infostealers have already unlocked the front door for them. Documented by DarkOwl, a stealer log…
Rockwell Patches Code Execution Flaws in Arena Simulation Software
A researcher has explained how an attacker could exploit these vulnerabilities to target industrial organizations. The post Rockwell Patches Code Execution Flaws in Arena Simulation Software appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read the original…
Google Launches Unified Cryptonym-Based Naming System for Threat Actors
Google Threat Intelligence Group (GTIG) has introduced a unified cryptonym-based naming system for cyber threat actors, aiming to simplify attribution, improve analyst workflows, and eliminate inconsistencies between legacy tracking conventions used across Google’s security teams. The initiative follows the integration…
Phantom Stealer Campaign Uses JavaScript and PowerShell to Steal Browser Credentials
A sophisticated phishing campaign that disguises malware delivery inside routine business communications, ultimately deploying Phantom Stealer v3.5.0 to harvest browser credentials, cookies, payment data, and cryptocurrency wallet information from victims. Documented by Seqrite, the campaign uses two distinct phishing themes that…
IT Security News Hourly Summary 2026-07-25 09h : 1 posts
1 posts were published in the last hour 6:31 : Hackers Exploit Industrial PLCs and Manipulate HMI Displays to Hide Attacks