Cybersecurity News
Aggregated daily from 25 sources. Updated automatically every morning.
CISA
NCSC UK
SANS ISC
The Hacker News
Bleeping Computer
Krebs on Security
Dark Reading
SecurityWeek
Exploit-DB
CERT-In
Google Project Zero
PortSwigger Research
Check Point Research
Cisco Talos
CrowdStrike
Unit 42
Elastic Security Labs
SentinelOne
WithSecure Labs
Avast Threat Labs
ZDI
0days in the Wild
Lakera AI Security
Embrace the Red
Simon Willison
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]
Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]
Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers.
The post Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow? appeared first on SecurityWeek.
Three feds spoke about future plans for the Continuous Diagnostics and Mitigation program, and lessons they’ve learned.
The post What’s next for CISA’s CDM program that gives cybersecurity tools to federal agencies appeared first on CyberScoop.
Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today.
The post “We Think the Security Control Is Working” Is No Longer Good Enough appeared first on SecurityWeek.
CenterPoint Energy disclosed a breach compromising some customers' personal information after an attacker leaked data allegedly stolen from the utility company. [...]
AI-assisted researchers flooded Vercel with reports, forcing the company to automate vulnerability triage.
The post $1 Million Sandbox Challenge Uncovers Linux Kernel Flaws appeared first on SecurityWeek.
The cybersecurity startup is building a proprietary foundation model and plans to accelerate global expansion.
The post Exein Secures $270M at $1.7B Valuation for Physical AI Security appeared first on SecurityWeek.
The company confirmed the defect was exploited before it was disclosed and patched, but it did not describe the nature of the attacks or the scope of impact across its customer base.
The post Cisco warns customers of actively exploited zero-day in email gateways appeared first on CyberScoop.
ChatGPT contractors are reviewing real users' conversations. Here’s how to stop AI companies using your chats for model training.
A hacker claims to have stolen 7.5 million customer records after breaching the company’s systems.
The post Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks Data appeared first on SecurityWeek.
I have not done this type of diary in a while: What traffic will you see from a system on boot, before a user logs in? I just took a quick look at macOS 27 "Golden Gate" to see what traffic you should expect. Here are some of the highlights:
A new report highlights the vast growth in fraudulent candidates, presenting significant insider threat challenges to organizations
A previously unknown malware framework called BambooToken, active since at least 2023, is now using the Message Queuing Telemetry Transport (MQTT) protocol to communicate with Windows and Linux systems. [...]
Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor. [...]
Fenix24 found only four of more than 800 clients came close to stated ransomware recovery targets of 24-48 hours
AI is shrinking the time between vulnerability disclosure and exploitation, leaving defenders less time to wait for patches or public exploits. Picus Security explains how exploitability validation, security control testing, and autonomous pentesting can help teams close exposure gaps before attackers arrive. [...]
Alleged Black Axe leaders extradited to the US over romance scams, BEC and money laundering claims
The hackers staged numerous scripts for reconnaissance and CVE probing, along with brute-force utilities and privilege escalation tools.
The post Thai Broadband Provider Hacked via Fortinet Vulnerability appeared first on SecurityWeek.
IANS finds AI is dominating net-new budgets even as overall funding for the function is flat
The incident occurred in May, when RubyGems maintainers suspended new account registrations due to what appeared like malicious activity.
The post OpenAI Investigates Report Linking AI Agents to RubyGems Attack appeared first on SecurityWeek.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned security teams that ransomware gangs have now joined ongoing attacks exploiting a critical VMware vCenter vulnerability patched in July. [...]
UK and allies provide advice to help organisations and individuals at risk detect and counter the threat from CHOSEN BRICK malware.
Advisory on CHOSEN BRICK malware, including technical analysis and advice to help individuals and organisations protect themselves.
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker to access live video and sensitive device information, enable unauthorized services, execute arbitrary code, modify device operation, and recover stored credentials.
The following versions of CareCam CM2507 are affected:
HMT.CM2507 Firmware v251211.1507 (CVE-2026-88259, CVE-2026-84398, CVE-2026-84400, CVE-2026-81305, CVE-2026-85478, CVE-2026-85497, CVE-2026-81321)
CVSS
Vendor
Equipment
Vulnerabilities
v3 7.5
CareCam
CareCam CM2507
Missing Authentication for Critical Function, Empty Password in Configuration File, Inclusion of Functionality from Untrusted Control Sphere, Use of Password Hash With Insufficient Computational Effort, Cleartext Storage of Sensitive Information
Background
Critical Infrastructure Sectors: Commercial Facilities
Countries/Areas Deployed: Worldwide
Company Headquarters Location: China
Vulnerabilities
Expand All +
CVE-2026-88259
CareCam CM2507 IP cameras
View CSAF
Summary
Siemens Reyrolle 7SR5 Before V2.70 is affected by multiple vulnerabilities. Siemens has released a new version for Reyrolle 7SR5 and recommends to update to the latest version.
The following versions of Siemens Reyrolle 7SR5 are affected:
Reyrolle 7SR5 vers:intdot/<2.70 (CVE-2024-42384, CVE-2024-42385, CVE-2024-42386, CVE-2024-42391, CVE-2024-42392, CVE-2026-62645, CVE-2026-62646, CVE-2026-62647, CVE-2026-62648, CVE-2026-62649, CVE-2026-62650, CVE-2026-62652, CVE-2026-62653, CVE-2026-62654)
CVSS
Vendor
Equipment
Vulnerabilities
v3 9.8
Siemens
Siemens Reyrolle 7SR5
Integer Overflow or Wraparound, Improper Neutralization of Delimiters, Use of Out-of-range Pointer Offset, Missing Authentication for Critical Function, Insufficient Entropy, Improper Input Validation, Out-of-bounds Write, Allocation of Resources Without Limits or Throttling, Authentication Bypass Using an Alternate Path or Channel, Insertion of Sensitive Information Into Debugging Code, Download o
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker to deliver an unauthorized update, execute code, or extract credentials to allow the attacker to impersonate a privileged client.
The following versions of Wärtsilä FOS-Onboard are affected:
FOS-Onboard 5.07.0923.01 (CVE-2026-78225, CVE-2026-81855)
CVSS
Vendor
Equipment
Vulnerabilities
v3 9.1
Wärtsilä
Wärtsilä FOS-Onboard
Use of Hard-coded Cryptographic Key
Background
Critical Infrastructure Sectors: Transportation Systems
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Finland
Vulnerabilities
Expand All +
CVE-2026-78225
A hardcoded cryptographic server key vulnerability exists in the deployer-ng Update Controller component of Wärtsilä FOS-Onboard.
View CVE Details
Affected Products
Wärtsilä FOS-Onboard
Vendor:Wärtsilä
Product Version:Wärtsilä FOS-Onboard: 5.07.0923.01
Product Status:known_affected
Remediations
MitigationWärtsilä states t
View CSAF
Summary
Mendix SAML module contains a vulnerability that could allow unauthenticated remote attackers to hijack an account in specific SSO configurations. Mendix has provided fix releases for the Mendix SAML module and recommends to update to the latest version.
The following versions of Siemens Mendix SAML are affected:
Mendix SAML (Mendix 10 compatible) vers:intdot/<4.2.3 (CVE-2026-80465)
Mendix SAML (Mendix 11 compatible) vers:intdot/<4.2.3 (CVE-2026-80465)
Mendix SAML (Mendix 9.24 compatible) vers:intdot/<3.6.27 (CVE-2026-80465)
CVSS
Vendor
Equipment
Vulnerabilities
v3 8.7
Siemens
Siemens Mendix SAML
Improper Verification of Cryptographic Signature
Background
Critical Infrastructure Sectors: Critical Manufacturing, Information Technology
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Germany
Vulnerabilities
Expand All +
CVE-2026-80465
Affected versions of the module do not properly validate the SAML response signature. This could al
View CSAF
Summary
A reflected cross site scripting vulnerability in the authentication redirect flow (/auth/) of Teamcenter allows an unauthenticated remote attacker to inject JavaScript into an authenticated user's session by crafting a malicious URL. Successful exploitation may enable the attacker to read data or perform actions within the victim's Teamcenter session. Siemens has released new versions for the affected products and recommends to update to the latest versions.
The following versions of Siemens Teamcenter are affected:
Teamcenter V2412 vers:intdot/<2412.0013 (CVE-2026-58113)
Teamcenter V2506 vers:intdot/<2506.0010 (CVE-2026-58113)
Teamcenter V2512 vers:intdot/<2512.2607 (CVE-2026-58113)
Teamcenter V2606 vers:intdot/<2606.2607 (CVE-2026-58113)
CVSS
Vendor
Equipment
Vulnerabilities
v3 6.1
Siemens
Siemens Teamcenter
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Background
Critical Infrastructure Sectors: Critical Manufa