vulnerability Horner Automation Cscape This advisory details a critical vulnerability in Horner Automation’s Cscape software, specifically versions prior to 10.2_SP3. The vulnerability allows for out-of-bounds reads, potentially leading to information disclos… CISA Advisories · Jun 25, 2026 Critical CVE-2026-12897UScscapeout-of-boundsvulnerability
vulnerability Daktronics Controller Firmware This CISA advisory details a vulnerability in Daktronics Controller Firmware versions up to v10.34.x.x, allowing unauthenticated users to gain root-level access and potentially execute arbitrary code due to a lack of pro… CISA Advisories · Jun 25, 2026 Critical CVE-2026-28701CVE-2026-33560CVE-2026-31928USfirmwareroot accessfile upload
vulnerability Yokogawa FAST/TOOLS and CI Server This advisory details a vulnerability in Yokogawa FAST/TOOLS and CI Server software, specifically versions R9.01 to R10.04, that allows an attacker to potentially retrieve CI Server setting information. The vulnerability… CISA Advisories · Jun 25, 2026 Medium CVE-2026-11833USweb servercwe-319vulnerability
vulnerability pydicom pynetdicom Library View CSAF Summary Successful exploitation of this vulnerability could allow an unauthenticated attacker to write to arbitrary file paths. The following versions of pydicom pynetdicom Library are affected: pynetdicom >=v1… CISA Advisories · Jun 25, 2026 Medium CVE-2026-56445
vulnerability OHIF Viewers DICOM This advisory details a vulnerability in the OHIF Viewers DICOM framework, specifically versions up to v3.12.0, that allows attackers to steal authenticated user tokens via crafted links. The vulnerability stems from unc… CISA Advisories · Jun 25, 2026 High CVE-2026-12473USssrfdicomweboidc
vulnerability Delta Electronics DTM Soft A vulnerability has been identified in Delta Electronics’ DTM Soft software, allowing for potential arbitrary code execution via deserialization of untrusted data. This poses a risk to critical manufacturing operations g… CISA Advisories · Jun 25, 2026 High CVE-2026-12578WOdeserializationcwe-502critical manufacturing
vulnerability Schneider Electric PowerLogic P7 Schneider Electric has identified and addressed vulnerabilities within its PowerLogic™ P7 protection and control platform. Specifically, the product is susceptible to CWE-476 (NULL Pointer Dereference), CWE-78 (Improper… CISA Advisories · Jun 25, 2026 High CVE-2026-9716CVE-2026-9717CVE-2026-9718FRcwefirmwareindustrial control
threat-intel EVoke Systems Charging Station Management System This advisory details a vulnerability in the EVoke Systems Charging Station Management System (CSMS) due to a lack of proper authentication mechanisms in its WebSocket endpoints. Attackers could exploit this to gain unau… CISA Advisories · Jun 25, 2026 High CVE-2026-40702CVE-2026-50176CVE-2026-54479USwebsocketocppauthentication
Interesting Paper Exploring Prompt Injection This is a fascinating explotation of how LLMs fall for prompt injection attacks. It turns out that they learn to recognize the style of text in different role/instruction blocks, and not just the tags. Their conclusion:… Schneier on Security · Jun 25, 2026 High
vulnerability Lantronix Serial-to-IP Converter Flaw Exploited in Attacks After OT Threat Warning The exploited flaw, CVE-2025-67038, is one of the vulnerabilities disclosed in April as part of the BRIDGE:BREAK research project. The post Lantronix Serial-to-IP Converter Flaw Exploited in Attacks After OT Threat Warni… SecurityWeek · Jun 25, 2026 CVE-2025-67038
threat-intel Surviving the Mythos Era: Richard Bejtlich on the Case for NDR This article discusses the challenges security teams face in investigating incidents due to the increasing volume of telemetry data and the accelerating pace of vulnerability discovery – often referred to as the ‘Mythos… The Hacker News · Jun 25, 2026 Medium UKnetwork detectionthreat huntingai
vulnerability GitLab Patches Code Execution, Information Disclosure Vulnerabilities The latest GitLab CE/EE updates address 13 vulnerabilities, including three high-severity defects. The post GitLab Patches Code Execution, Information Disclosure Vulnerabilities appeared first on SecurityWeek . SecurityWeek · Jun 25, 2026 High CVE-2026-10086CVE-2026-10712CVE-2026-12053
threat-intel Inside the 2026 SMB threat landscape: From phishing and scams to fake AI tools This Securelist article details Kaspersky's 2026 threat analysis for small and medium-sized businesses (SMBs), highlighting a significant increase in cyberattacks disguised as artificial intelligence (AI) tools, particul… Securelist · Jun 25, 2026 High USaismbmalware
threat-intel Introduction to COM usage by Windows threats This Cisco Talos report details the increasing use of the Component Object Model (COM) by malware actors for malicious activities within Windows environments. COM's capabilities for inter-process communication, automatio… Cisco Talos · Jun 25, 2026 Medium comwindowslateral movement
ransomware Europe Evolves Into Ransomware's Favorite Region Ransomware attacks in Europe have dramatically increased, representing a significant shift from previous trends. Black Kite researchers report a 55% rise in ransomware attacks across the continent through the first four… Dark Reading · Jun 25, 2026 High UKGEFRransomwaresupply-chainai
vulnerability 25-Year-Old Vulnerability Patched in Curl The latest version of the open source data transfer tool resolves 18 medium and low-severity vulnerabilities. The post 25-Year-Old Vulnerability Patched in Curl appeared first on SecurityWeek . SecurityWeek · Jun 25, 2026 High CVE-2026-8932CVE-2026-8926CVE-2026-8925
threat-intel New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis A new macOS malware, dubbed Gaslight, has been discovered using prompt injection techniques to deceive AI-powered analysis tools. Developed by North Korea-aligned threat actors, the malware steals information and attempt… The Hacker News · Jun 25, 2026 High KPmacosprompt injectionai evasion
SecurityWeek ICS Cybersecurity Conference Heads to Nashville for Special 25-Year Anniversary Edition The 2026 Industrial Control Systems (ICS) Cybersecurity Conference takes place October 6-8, 2026, at the W Nashville. The post SecurityWeek ICS Cybersecurity Conference Heads to Nashville for Special 25-Year Anniversary… SecurityWeek · Jun 25, 2026
threat-intel New Mistic Backdoor Linked to KongTuke in ClickFix and ModeloRAT Campaigns A new stealthy backdoor, Mistic (MLTBackdoor), linked to the KongTuke IAB has been used in financially motivated attacks targeting organizations across insurance, education, IT, and professional services since April 2026… The Hacker News · Jun 25, 2026 High USbackdoorremote access trojanclickfix
threat-intel Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances In 2025, the Russian-aligned threat actor Gamaredon significantly ramped up its cyberespionage operations targeting Ukraine, utilizing a sophisticated and evolving toolkit. The group, linked to the FSB, employed a combin… WeLiveSecurity · Jun 25, 2026 HighCVSS 8.8 CVE-2025-8088RUcyberespionagerussiaspearphishing