Cybersecurity News
Aggregated daily from 25 sources. Updated automatically every morning.
CISA
NCSC UK
SANS ISC
The Hacker News
Bleeping Computer
Krebs on Security
Dark Reading
SecurityWeek
Exploit-DB
CERT-In
Google Project Zero
PortSwigger Research
Check Point Research
Cisco Talos
CrowdStrike
Unit 42
Elastic Security Labs
SentinelOne
WithSecure Labs
Avast Threat Labs
ZDI
0days in the Wild
Lakera AI Security
Embrace the Red
Simon Willison
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
It is pretty obvious that hostnames can replace IP addresses. Pretty much any software accepting an IP address will also accept a hostname as an argument. Last week, I wrote about scans for the cloud metadata service listening at 169.254.169.254. These scans attempted to exploit Server Side Request Forgery (SSRF) vulnerability. One way to prevent these types of exploits is to filter requests that contain the string "169.254.169.254" or to add this IP to a blocklist of URLs that should not be accessed.
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized administrative access, disclose sensitive information, modify device configuration, hijack authenticated sessions, and disrupt device operation.
The following versions of Ebyte NE2-D11 are affected:
NE2-D11 Firmware FW-9167-0-11
CVSS
Vendor
Equipment
Vulnerabilities
v3 9.8
Ebyte
Ebyte NE2-D11
Missing Authentication for Critical Function, Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials, Use of Client-Side Authentication, Use of GET Request Method With Sensitive Query Strings, Cross-Site Request Forgery (CSRF), Improper Restriction of Excessive Authentication Attempts, Improper Restriction of Rendered UI Layers or Frames, Missing Authorization
Background
Critical Infrastructure Sectors: Critical Manufacturing, Energy
Countries/Areas Deployed: Worldwide
Company Headquarters Location: China
Vulnerabilities
Expand All +
CVE-
Advisory at a Glance
Title
A Tale of Two SOCs: Insights From Two Red Team Assessments
Original Publication
August 25, 2026
Executive Summary
The Cybersecurity and Infrastructure Security Agency (CISA) conducted simultaneous red team assessments at two organizations and observed different defensive outcomes. In both environments, the red team achieved full domain compromise and accessed sensitive business systems (SBSs) and cloud resources. Organization A failed to detect or contain the activity, but Organization B rapidly identified initial compromise attempts, isolated affected systems, and forced the red team into an assume breach model.
This advisory details the red team’s activity and organizations’ defensive actions, offering lessons learned and mitigations to help critical infrastructure organizations strengthen detection, response, and protections in IT, cloud, and operational technology (OT) environments.
Lessons Learned
Untuned detection tools lead to missed
View CSAF
Summary
Successful exploitation of this vulnerability could allow an attacker to access sensitive information and override user permissions.
The following versions of Rently Smart Home are affected:
Smart Home <=20.1.0
CVSS
Vendor
Equipment
Vulnerabilities
v3 8.1
Rently
Rently Smart Home
Insufficiently Protected Credentials
Background
Critical Infrastructure Sectors: Commercial Facilities, Communications, Information Technology
Countries/Areas Deployed: United States, India
Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2026-75960
Rently Smart Home versions 20.1.0 and prior are vulnerable to an Insufficiently Protected Credentials vulnerability. This could allow an attacker to retrieve pins including the Master Pin, overriding standard user permissions.
View CVE Details
Affected Products
Rently Smart Home
Vendor:Rently
Product Version:Rently Smart Home: <=20.1.0
Product Status:known_affected
Remediations
MitigationRently
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2026-60004 Gitea Code Injection Vulnerability
This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether thr
View CSAF
Summary
Successful exploitation of this vulnerability could allow a remote, authenticated or unauthenticated attacker to disclose sensitive information, arbitrarily modify the device to cause a denial of service, or alter a devices displayed image.
The following versions of PayRange API are affected:
PayRange API vers:all/*
CVSS
Vendor
Equipment
Vulnerabilities
v3 8.8
PayRange
PayRange API
Missing Authorization
Background
Critical Infrastructure Sectors: Commercial Facilities
Countries/Areas Deployed: United States, Canada
Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2026-18965
The affected product is missing proper authorization on management endpoints, which allows verbose details of every device on the PayRange network to be publicly accessible, with or without an account.
View CVE Details
Affected Products
PayRange API
Vendor:PayRange
Product Version:PayRange PayRange API: vers:all/*
Product Status:known_affected
Re
View CSAF
Summary
Successful exploitation of this vulnerability could result in full Remote Code Execution (RCE) as the web server user.
The following versions of Zoneminder are affected:
Zoneminder 1.37.48|1.38.3
CVSS
Vendor
Equipment
Vulnerabilities
v3 8.8
Zoneminder
Zoneminder
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Background
Critical Infrastructure Sectors: Information Technology
Countries/Areas Deployed: Worldwide
Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2026-76060
An authenticated OS Command Injection vulnerability exists in ZoneMinder's event export functionality. The exportFile HTTP request parameter is passed unsanitized into a shell command executed via PHP's exec(), allowing any authenticated user with View Events permission to execute arbitrary operating system commands on the server.
View CVE Details
Affected Products
Zoneminder
Vendor:Zoneminder
Product Version
View CSAF
Summary
SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed contain a missing authentication vulnerability in the Node-RED HTTP interface that could allow an unauthenticated remote attacker to create malicious flows and execute arbitrary code on the underlying server with maximum privileges. Siemens has released a new version for SIMATIC IoT2050 Advanced and strongly recommends to update to the latest version.
The following versions of Siemens SIMATIC IoT2050 Advanced are affected:
SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) vers:intdot/<4.3.4.1
CVSS
Vendor
Equipment
Vulnerabilities
v3 10
Siemens
Siemens SIMATIC IoT2050 Advanced
Missing Authentication for Critical Function
Background
Critical Infrastructure Sectors: Chemical, Critical Manufacturing, Energy, Transportation Systems
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Germany
Vulnerabilities
Expand All +
CVE-2026-58115
Affected devices do not enforce
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker to alter device settings.
The following versions of FURUNO FA-50 Class B AIS Transponder are affected:
FURUNO FA-50 Class B AIS Transponder vers:all/*
CVSS
Vendor
Equipment
Vulnerabilities
v3 9.1
FURUNO ELECTRIC CO.,LTD.
FURUNO FA-50 Class B AIS Transponder
Use of Hard-coded Credentials, Missing Authentication for Critical Function
Background
Critical Infrastructure Sectors: Transportation Systems
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Japan
Vulnerabilities
Expand All +
CVE-2026-59769
An attacker, who knows the credentials and has access to the in-vessel network to which the device is connected to, may operate the settings screen using that credentials to alter the settings of the device.
View CVE Details
Affected Products
FURUNO FA-50 Class B AIS Transponder
Vendor:FURUNO ELECTRIC CO.,LTD.
Product Version:FURUNO FA-50 Class B AIS Transponder: ver
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker to cause the loss of ABS functions, steering assist, speedometer, shifting capabilities, or disable automatic traction control.
The following versions of Bendix EC80 Brake ECU are affected:
EC80ESP+ J1708 Z228999
EC80ESP+ 6S/6M Z228999
EC80ESP+ PLC Z228999
EC80ESP+ 2nd CAN Z228999
EC80ESP+ Integrated TPMS Z228999
EC80ESP 6S/6M Z266494
EC80ESP PLC Z266494
EC80ESP 2nd CAN Z266494
EC80ESP CAN Gateway Z266494
EC80ESP 4S/4M Z286098
EC80ESP PLC Z286098
CVSS
Vendor
Equipment
Vulnerabilities
v3 7.5
Bendix
Bendix EC80 Brake ECU
Stack-based Buffer Overflow, Out-of-bounds Write, Use of Hard-coded Credentials
Background
Critical Infrastructure Sectors: Transportation Systems
Countries/Areas Deployed: United States, Canada
Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2026-67560
The affected product is vulnerable to a stack-based buffer overflow,
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2026-21962 Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability
This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establis
New malware that uses steganography always gets my attention, but I was disappointed when I looked at the latest DOUBLECUP write-up. It doesn&#x26;#39;t use real steganography:
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2026-73570 Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for whe
In every MFA rollout, there will come a time where you think you are closing in on "done", and some automation to list what&#x26;#39;s left would be handy. Something quicker than scrolling through the web interface through thousands of accounts ...
 This is that method.
 Also, remember when we discussed yesterday about the beta graph commands in the Microsoft.Graph.Beta library? We&#x26;#39;ll use one of those beta commands here!
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
One thing that folks never seem to do after "going to the CLOOOOUUUUD" is to look at their logs, logs that they would have checked daily when things were on premise.
 One log that really bears looking at is the log of successful and failed logins. the call for that is:
Building on the last diary on Using MS Graph and Powershell, let&#x26;#39;s look at "Risky" logins.
Microsoft Graph is a newer API that is meant to replace several others.&#x26;#xc2;&#x26;#xa0; OK, it&#x26;#39;s at version 2.3.9, so it&#x26;#39;s not all that new, but it&#x26;#39;s new enough that lots of folks (and commercial tools) aren&#x26;#39;t using it yet.&#x26;#xc2;&#x26;#xa0; &#x26;#xc2;&#x26;#xa0;It allows you to Get and Set info from/to M365, Entra Users and Entra managed machines for starters.&#x26;#xc2;&#x26;#xa0; Let&#x26;#39;s dig in!
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2026-72529 TrueConf Server Missing Authentication for Critical Function Vulnerability
CVE-2026-72530 TrueConf Server Code Injection Vulnerability
These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-ri
View CSAF
Summary
Successful exploitation of this vulnerability could allow a local attacker with low privileges to extract user credentials (passwords and authentication tokens) from system memory, potentially leading to unauthorized access to the application and connected systems.
The following versions of Johnson Controls Simplex Incident Manager are affected:
Simplex Incident Manager <=V2.01 (CVE-2026-27875)
CVSS
Vendor
Equipment
Vulnerabilities
v3 5.8
Johnson Controls Inc.
Johnson Controls Simplex Incident Manager
Cleartext Storage of Sensitive Information in Memory
Background
Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Ireland
Vulnerabilities
Expand All +
CVE-2026-27875
The Simplex Incident Manager application stores user credentials (such as passwords and authentication tokens) in an unencryp
Use safeguards, sandboxing and active oversight to realise the benefits of autonomous systems while limiting the unintended activity.
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Cloud providers typically expose a REST API at 169.254.169.254 that allows code running on virtual machines to retrieve machine-specific data. Some of the data is more or less harmless, such as the region the machine is running in or its MAC and IP addresses. However, the service may also be used to retrieve credentials for IAM roles and service account tokens.
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2026-64849 MLflow Server-Side Request Forgery Vulnerability
This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must che
Executive summary
Note: This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs). However, ongoing PLC targeting activity is broader than Siemens PLCs. All PLC owners and operators should apply relevant mitigations to reduce the risk to their devices and systems. The Siemens-specific content in this advisory should be understood and applied as one subset of the wider threat landscape.
Top Mitigations
Inventory all Siemens S7 Series programmable logic controllers (PLCs)
Apply critical security patches
Ensure PLCs are not accessible from the Internet
Strengthen access controls
Monitor for unauthorized activity
Harden PLC services, protocols, and ladder logic integrity
Hunt for anomalies that may indicate a compromise
The National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Department of Energy (DOE), and Environmental Protection Agency (EPA)—hereafter re
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View CSAF
Summary
Simcenter Nastran is affected by a stack overflow vulnerability that could be triggered when an application binary reads arbitrary string as a file argument. If a user is tricked to run one of the impacted application binary with a malicious string, an attacker could leverage the vulnerability to perform remote code execution in the context of the current process. Siemens has released new versions for the affected products and recommends to update to the latest versions.
The following versions of Siemens Simcenter Nastran are affected:
Simcenter Femap vers:intdot/<2606 (CVE-2026-59086)
Simcenter Nastran vers:intdot/<2606 (CVE-2026-59086)
CVSS
Vendor
Equipment
Vulnerabilities
v3 7.8
Siemens
Siemens Simcenter Nastran
Stack-based Buffer Overflow
Background
Critical Infrastructure Sectors: Critical Manufacturing, Defense Industrial Base, Energy, Healthcare and Public Health, Transportation Systems
Countries/Areas Deployed: Worldwide
Company Headquarters Loc