Cybersecurity News
Aggregated daily from 10 sources. Updated automatically every morning.
CISA
NCSC UK
SANS ISC
The Hacker News
Bleeping Computer
Krebs on Security
Dark Reading
SecurityWeek
Exploit-DB
CERT-In
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker with network access to achieve remote code execution.
The following versions of Johnson Controls C-CURE 9000 and Victor application server are affected:
C-CURE 9000 and victor <=v2.90_v3.0
victor Web <=v7.1
CVSS
Vendor
Equipment
Vulnerabilities
v3 9.6
Johnson Controls
Johnson Controls C-CURE 9000 and Victor application server
Server-Side Request Forgery (SSRF), Execution with Unnecessary Privileges
Background
Critical Infrastructure Sectors: Critical Manufacturing
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Ireland
Vulnerabilities
Expand All +
CVE-2026-21655
Under certain circumstances, successful exploitation of this vulnerability could allow an unauthenticated attacker on the adjacent network to achieve arbitrary code execution on the C-CURE 9000 or victor application server, as well as connected clients (e.g., workstations of physica
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker with access to the IT network to manipulate industrial control devices without requiring physical access, specialized insider knowledge, or advanced tooling.
The following versions of Panduit IntraVUE are affected:
IntraVUE <=3.2.1a14
CVSS
Vendor
Equipment
Vulnerabilities
v3 10
Pronetiqs
Panduit IntraVUE
Plaintext Storage of a Password, Unintended Proxy or Intermediary ('Confused Deputy'), Exposure of Sensitive System Information to an Unauthorized Control Sphere, Inadequate Encryption Strength
Background
Critical Infrastructure Sectors: Critical Manufacturing, Energy, Information Technology, Water and Wastewater
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Netherlands
Vulnerabilities
Expand All +
CVE-2026-40430
Pronetiqs IntraVUE Versions 3.2.1a14 and prior have a plaintext storage of a password vulnerability that could expose cleartext credenti
GCHQ’s National Cyber Security Centre and international partners issue warning as ‘LAUNDRY BEAR’ cyber threat group exposed for targeted phishing campaign
No organisation can navigate the migration alone; key takeaways from our first PQC migration workshop.
Cyber Advisors are offering free 30-minute consultations to help small businesses get started with cyber security.
New advisory highlights Russian state cyber actors’ global exploitation of poorly configured routers
An alternative path to Cyber Essentials Plus certification, without compromising the integrity of the scheme.
Why the UK is pioneering an initiative to develop a national scale, sovereign defence capability
Pen testers suggest what organisations can do to make their job more difficult.
Five Eyes cyber security agencies urge organisations to act on rapidly transforming cyber risk.
Organisations using Fortinet services are being urged to take action following a campaign affecting firewalls and VPN gateways.
Different code deserves different levels of oversight, so calibrate your approach to ‘vibe coding’ accordingly.
Dr Richard Horne highlighted the scale of cyber threats against the UK’s critical infrastructure at RUSI’s Annual Security Lecture.
Attackers are compromising open-source packages to spread malware. Cyber defenders are asked to review dependencies to reduce risks
New guidance explains how to design Zero Trust Network Access architectures aligned with zero trust principles and not built on old trust assumptions.
When it comes to using agentic AI, make sure you can walk before you run.
Using Artificial Intelligence to find vulnerabilities can bring added security considerations.
Organisations must act now to prepare for a wave of patches that will address decades of technical debt.
Poor metrics can render a well-intentioned security operation centre entirely ineffective.
Explaining the widespread shift in tactics, techniques and procedures (TTPs) towards networks of compromised infrastructure, and how to defend against it