vulnerability Siemens SIMATIC A vulnerability (CVE-2026-27662) has been identified in Siemens SIMATIC HMI Unified Comfort Panels. The flaw allows an unauthenticated attacker to gain access to the web browser through the help link, potentially enablin… CISA Advisories · May 14, 2026 High CVE-2026-27662hmiindustrial controlweb browser
threat-intel Siemens SIMATIC Siemens has released a security update for its SIMATIC CN 4100 system to address multiple vulnerabilities discovered within its Linux kernel components and libxml2. These vulnerabilities, including null pointer dereferen… CISA Advisories · May 14, 2026 High CVE-2024-47704CVE-2024-57924CVE-2024-58240DElinuxkernelvulnerability
vulnerability Siemens Teamcenter Siemens Teamcenter versions 2312, 2406, 2412, and 2506 are affected by multiple vulnerabilities, including a PDF.js flaw and hardcoded credentials. These vulnerabilities could allow for arbitrary code execution and unaut… CISA Advisories · May 14, 2026 High CVE-2026-33862CVE-2026-33893CVE-2024-4367DEpdfjscredentialscve-2024-4367
vulnerability Siemens Ruggedcom Rox This advisory details a vulnerability in Siemens Ruggedcom Rox devices due to improper input validation within the JSON-RPC interface. An authenticated remote attacker could potentially read arbitrary files from the devi… CISA Advisories · May 14, 2026 High CVE-2025-40948DEjson-rpcroot accessfile disclosure
vulnerability Siemens Solid Edge Siemens Solid Edge SE2026 is affected by two file parsing vulnerabilities that could allow an attacker to crash the application or execute arbitrary code when processing specially crafted PAR files. Siemens has released… CISA Advisories · May 14, 2026 High CVE-2026-44411CVE-2026-44412DEbuffer overflowfile parsingstack overflow
vulnerability Siemens Industrial Devices This article details a vulnerability (CVE-2025-40833) affecting multiple Siemens industrial devices, including IE/PB LINK HA, SCALANCE M series routers, and RuggedCom RM1224 LTE devices. The vulnerability allows an attac… CISA Advisories · May 14, 2026 High CVE-2025-40833industrial controldenial of servicefirmware update
threat-intel How Dangerous Is Anthropic’s Mythos AI? Anthropic’s Claude Mythos AI model demonstrates a significant capability in identifying software vulnerabilities, prompting concerns about its potential misuse by attackers. While the company initially restricted access… Schneier on Security · May 14, 2026 High UKaivulnerabilitycybersecurity
threat-intel Kimsuky targets organizations with PebbleDash-based tools This report details the ongoing activity of the Kimsuky threat actor group, also known as APT43, who have been utilizing a PebbleDash-based malware platform to conduct targeted attacks. The group has significantly evolve… Securelist · May 14, 2026 High KRBRDEspear phishingremote access trojansouth korea
ransomware When ransomware gets physical: cybercriminals turn to threats of violence Pay up, or we'll pay someone to pay you a visit. Cybercrime gangs are increasingly turning to real-world threats - and even hiring local muscle to deliver the message. Read more in my article on the Hot for Security blog… Graham Cluley · May 14, 2026 High
threat-intel FrostyNeighbor: Fresh mischief and digital shenanigans FrostyNeighbor, a long-running cyberespionage group allegedly linked to Belarus, is continuing its operations targeting governmental organizations in Ukraine and other Eastern European countries. The latest activity invo… WeLiveSecurity · May 14, 2026 High BYPLLTcyberespionagecobalt strikepicassoloader
threat-intel Smashing Security podcast #467: How ShinyHunters hacked the world’s biggest universities This episode of Smashing Security discusses a recent incident where ShinyHunters, a known threat actor, compromised the networks of several major universities. The attackers leveraged a vulnerability to gain access, targ… Graham Cluley · May 13, 2026 High universityvulnerabilitythreat-actor
threat-intel [GUEST DIARY] Tearing apart website fraud to see how it works., (Wed, May 13th) This article, a guest diary by an ISC intern, details an investigation into a fraudulent marketplace operation. The author discovered a website using SEO poisoning to lure victims into purchasing goods from a fake market… SANS Internet Storm Center · May 13, 2026 High INseo poisoningfraudmarketplace
vulnerability Microsoft Patch Tuesday for May 2026 — Snort rules and prominent vulnerabilities Microsoft released its May 2026 Patch Tuesday update, addressing 137 vulnerabilities across its product suite. The update includes a significant number of critical vulnerabilities, primarily remote code execution (RCE) f… Cisco Talos · May 12, 2026 High CVE-2026-32161CVE-2026-33109CVE-2026-33844rcebuffer overflowuse after free
threat-intel 20 Leaders Who Built the CISO Era: 2 Decades of Change This Dark Reading article reflects on the 20th anniversary of the publication, highlighting key figures who shaped the evolution of cybersecurity over the past two decades. The piece focuses on the rise of the CISO role,… Dark Reading · May 12, 2026 High UNEAcybercrimecisossecurity
vulnerability Copy.Fail Linux Vulnerability This is the worst Linux vulnerability in years. TL;DR copy.fail is a Linux kernel local privilege escalation, not a browser or clipboard attack. Disclosed by Theori on 29 April 2026 with a working PoC. It abuses the kern… Schneier on Security · May 12, 2026 High
threat-intel State-sponsored actors, better known as the friends you don’t want This Cisco Talos report highlights the significant differences in responding to state-sponsored cyber threats compared to conventional attacks like ransomware. It emphasizes that these actors operate within an organizati… Cisco Talos · May 12, 2026 High USUKstate-sponsoredzero trustosint
ransomware State of ransomware in 2026 Kaspersky’s 2026 ransomware threat report highlights a shift in the landscape, with ransomware attacks declining overall but becoming more sophisticated. Key trends include the emergence of post-quantum cryptography rans… Securelist · May 12, 2026 High USransomwarequantum cryptographyedr
threat-intel Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools This report from Palo Alto Unit 42 details how Active Directory Certificate Services (AD CS) is frequently exploited by both financially motivated ransomware groups and state-sponsored actors due to misconfigured templat… Palo Alto Unit 42 · May 11, 2026 High CVE-2022-26923NOad cscertificate issuanceprivilege escalation
threat-intel Eyes wide open: How to mitigate the security and privacy risks of smart glasses This article discusses the growing security and privacy risks associated with smart glasses, particularly due to their advanced tracking and recording capabilities combined with AI integration. The proliferation of these… WeLiveSecurity · May 11, 2026 High GEUKsurveillanceprivacyai
phishing One in eight UK workers has sold their company passwords, and bosses think it’s fine A recent survey revealed that approximately one in eight UK workers has disclosed their company login credentials, either directly or through a connection. This practice is compounded by a concerning lack of concern from… Graham Cluley · May 8, 2026 High GBpasswordssecurityuk