threat-intel ISC Stormcast For Friday, May 15th, 2026 https://isc.sans.edu/podcastdetail/9934, (Fri, May 15th) The SANS Internet Storm Center's Stormcast for May 15th, 2026 highlighted a concerning increase in several active threats across the internet landscape. The report detailed a rise in phishing campaigns, malicious email a… SANS Internet Storm Center · May 15, 2026 Medium phishingvulnerabilitythreat intelligence
threat-intel Taiwan Bullet Train Hack Highlights Cybersecurity Gaps in Rail Systems A Taiwanese student exploited vulnerabilities in the Taiwan High Speed Rail (THSR)'s TETRA radio system, causing a 48-minute delay in service by spoofing an emergency alarm. This incident highlights broader cybersecurity… Dark Reading · May 15, 2026 Medium TAPOISrailcyberattacktetra
threat-intel Suspected Dream Market kingpin arrested after gold bars sent to his home address Owe Martin Andresen, suspected to be the administrator of the notorious Dream Market dark web drug marketplace, has been arrested on money laundering charges in the US and Germany. Authorities allege he moved millions of… Graham Cluley · May 14, 2026 High USDEdark webdrug traffickingmoney laundering
threat-intel The time of much patching is coming This article from Cisco Talos anticipates a significant increase in software patching due to advancements in AI-powered vulnerability detection and the uncovering of long-standing technical debt. The surge in discovered… Cisco Talos · May 14, 2026 High USvulnerabilitypatchingai
vulnerability Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities Cisco Talos has identified ongoing exploitation of vulnerabilities within Cisco Catalyst SD-WAN Controller and Manager, specifically CVE-2026-20182 and a set of related vulnerabilities (CVE-2026-20133, CVE-2026-20128, an… Cisco Talos · May 14, 2026 High CVE-2026-20182CVE-2026-20133CVE-2026-20128sd-wanciscoauthentication
Upcoming Speaking Engagements This is a current list of where and when I am scheduled to speak: I’m giving a virtual talk on “The Security of Trust in the Age of AI,” hosted by the Financial Women’s Association of New York , at 6:00 PM ET on May 21,… Schneier on Security · May 14, 2026
vulnerability Siemens Ruggedcom Rox A vulnerability has been identified in Siemens Ruggedcom Rox devices, specifically within the Scheduler functionality, allowing authenticated remote attackers to execute arbitrary commands with root privileges. This is d… CISA Advisories · May 14, 2026 Critical CVE-2025-40949DEinput validationroot privilegescheduler
vulnerability Siemens SIPROTEC 5 This CISA advisory details a critical vulnerability in Siemens SIPROTEC 5 devices due to the use of insufficiently random session identifiers. An unauthenticated remote attacker could potentially exploit this weakness to… CISA Advisories · May 14, 2026 Critical CVE-2024-54017session_hijackingauthenticationrandomness
vulnerability Siemens Simcenter Femap A heap-based buffer overflow vulnerability has been identified in Siemens Simcenter Femap, specifically within the Datakit library. The vulnerability, reported by TrendAI Zero Day Initiative, allows for remote code execu… CISA Advisories · May 14, 2026 High CVE-2025-12659GEheap-overflowremote-code-executionipt
threat-intel Siemens SIMATIC Siemens has released a security update for its SIMATIC CN 4100 system to address multiple vulnerabilities discovered within its Linux kernel components and libxml2. These vulnerabilities, including null pointer dereferen… CISA Advisories · May 14, 2026 High CVE-2024-47704CVE-2024-57924CVE-2024-58240DElinuxkernelvulnerability
vulnerability Siemens SIMATIC S7 PLC Web Server This CISA advisory details multiple vulnerabilities discovered within Siemens SIMATIC S7 PLCs, specifically within their web servers. These vulnerabilities, identified as CVE-2026-25786 through CVE-2026-25789, allow for… CISA Advisories · May 14, 2026 Medium CVE-2026-25786CVE-2026-25787CVE-2026-25789plcwebserverxss
vulnerability Siemens Ruggedcom Rox This CISA advisory details a vulnerability affecting Siemens Ruggedcom Rox devices. The devices, specifically versions prior to 2.17.1, contain multiple third-party vulnerabilities, including those listed in CVEs from 20… CISA Advisories · May 14, 2026 Medium CVE-2019-13103CVE-2019-13104CVE-2019-13106vulnerabilitypatchingcve
vulnerability CISA Adds One Known Exploited Vulnerability to Catalog CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-20182 Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability Th… CISA Advisories · May 14, 2026 Medium CVE-2026-20182
vulnerability Siemens Siemens ROS# This advisory details a critical vulnerability in Siemens ROS# (version 2.2.2 and earlier) due to a path traversal flaw. An attacker could potentially access and modify arbitrary files on a system hosting the ROS# file_s… CISA Advisories · May 14, 2026 Critical CVE-2026-41551DEpath traversalindustrial control systemscwe-23
vulnerability Siemens Teamcenter Siemens Teamcenter versions 2312, 2406, 2412, and 2506 are affected by multiple vulnerabilities, including a PDF.js flaw and hardcoded credentials. These vulnerabilities could allow for arbitrary code execution and unaut… CISA Advisories · May 14, 2026 High CVE-2026-33862CVE-2026-33893CVE-2024-4367DEpdfjscredentialscve-2024-4367
vulnerability Siemens Ruggedcom Rox A vulnerability has been identified in Siemens Ruggedcom Rox devices, specifically within the feature key installation process. This flaw allows authenticated remote attackers to execute arbitrary commands with root priv… CISA Advisories · May 14, 2026 Critical CVE-2025-40947DEinput validationremote code executionroot privilege
vulnerability Siemens SIMATIC A vulnerability (CVE-2026-27662) has been identified in Siemens SIMATIC HMI Unified Comfort Panels. The flaw allows an unauthenticated attacker to gain access to the web browser through the help link, potentially enablin… CISA Advisories · May 14, 2026 High CVE-2026-27662hmiindustrial controlweb browser
vulnerability Siemens SENTRON 7KT PAC1261 Data Manager A vulnerability has been identified in the Siemens SENTRON 7KT PAC1261 Data Manager software, specifically within the Go Project’s net/http package. This allows an attacker to potentially gain administrative control over… CISA Advisories · May 14, 2026 High CVE-2025-22871DEhttprequest smugglingindustrial control systems
vulnerability Siemens Ruggedcom Rox This advisory details a vulnerability in Siemens Ruggedcom Rox devices due to improper input validation within the JSON-RPC interface. An authenticated remote attacker could potentially read arbitrary files from the devi… CISA Advisories · May 14, 2026 High CVE-2025-40948DEjson-rpcroot accessfile disclosure
vulnerability Universal Robots Polyscope 5 A critical vulnerability has been identified in Universal Robots Polyscope 5 software versions prior to 5.25.1, allowing for unauthenticated code execution via OS command injection. This poses a significant risk to criti… CISA Advisories · May 14, 2026 Critical CVE-2026-8153WOcommand injectionroboticscve-2026-8153