threat-intel Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility Polish CERT has revealed a second, parallel cyberattack targeting a smaller CHP plant supplying heat to 50,000 residents, utilizing a novel private APN attack vector. The attack, attributed to Russian APT group Sandworm,… SecurityWeek · Aug 10, 2026 High PLicsindustrial control systemsprivate apn
vulnerability ABB Ability Zenon ABB has issued a security advisory regarding multiple vulnerabilities in its Ability Zenon industrial automation platform. These vulnerabilities, primarily related to MongoDB, could allow attackers to bypass security, cr… CISA Advisories · Aug 6, 2026 High CVE-2025-14847CVE-2020-7928CVE-2020-7921WOvulnerabilitydata-breachmalware
vulnerability Johnson Controls Inc. TL280 A critical vulnerability (CWE-327) exists in Johnson Controls Inc.'s TL280 firmware, allowing attackers to access sensitive information on the device. The vulnerability stems from hardcoded credentials embedded directly… CISA Advisories · Aug 6, 2026 Critical CVE-2026-27871cwe-327firmwareics
threat-intel Device Code Phishing Up 1,500% in 2026; Vishing Doubles Device code phishing and vishing are experiencing a dramatic surge, driven by state-sponsored and cybercriminal groups, and are proving highly effective at bypassing traditional security measures. CrowdStrike reports a 1… Dark Reading · Aug 4, 2026 High USRUEUphishingvishingdevice-code-phishing
threat-intel Russian hackers hijack hotel Wi-Fi networks to spy on travelers, Microsoft says Russian state-sponsored hackers, linked to the Midnight Blizzard group (part of APT29), are compromising hotel Wi-Fi networks worldwide to steal traveler login credentials and install espionage malware. The campaign uses… The Record · Aug 3, 2026 High RUUKSAhotel wifiespionagecaptive portal
threat-intel CISA warns of spike in attacks on water systems as Minnesota incidents probed The CISA is warning of a significant increase in cyberattacks targeting water systems, particularly in Minnesota, with potential links to Iran. Attacks involve modifying passwords, disconnecting PLCs, and causing boil wa… The Record · Jul 31, 2026 High IRUScritical infrastructurecyberattackiran
threat-intel Finland to disconnect fiber-optic link to Russia as lease expires Finland is disconnecting a fiber-optic telecommunications link to Russia as its lease expires, following the end of electricity trade between the two countries due to the invasion of Ukraine. This action is part of a bro… The Record · Jul 31, 2026 Medium FIRUtelecominfrastructurerussia
threat-intel ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories This week’s ‘ThreatsDay’ bulletin highlights a diverse range of security threats, including AI-powered hacking campaigns, ransomware attacks targeting Russia, and vulnerabilities in various software systems. Notably, a C… The Hacker News · Jul 30, 2026 High CVE-2026-33017CVE-2026-21858CVE-2025-68613RUCCHransomwaresupply chainphishing
vulnerability Schneider Electric IGSS Schneider Electric has identified and issued a security advisory (SEVD-2026-195-01) regarding a critical out-of-bounds write vulnerability in its IGSS Definition module for the IGSS (Interactive Graphical SCADA System) p… CISA Advisories · Jul 30, 2026 High CVE-2026-12927scadaindustrial control systemscwe-787
vulnerability MZ Automation GmbH libiec61850 CISA has issued an advisory regarding multiple vulnerabilities in MZ Automation GmbH’s libiec61850 software, specifically version <1.6.2. These vulnerabilities, all related to out-of-bounds reads, can lead to denial-of-s… CISA Advisories · Jul 30, 2026 High CVE-2026-66720CVE-2026-66369CVE-2026-63550vulnerabilityout-of-bounds readdenial-of-service
vulnerability Toptech Systems RCU II+ and Multiload II+ Toptech Systems has issued a vulnerability notice regarding RCU II+ and Multiload II+ devices, exposing a critical unauthenticated service that allows for full system control. Exploitation is not currently possible remot… CISA Advisories · Jul 30, 2026 High CVE-2026-12562vulnerabilitycontrol systemsauthentication
vulnerability Johnson Controls OpenBlue Employee Johnson Controls has released a security advisory (JCI-PSA-2026-09) addressing critical vulnerabilities in its OpenBlue Employee system. These vulnerabilities – including stored XSS, HTML injection, and file upload flaws… CISA Advisories · Jul 30, 2026 High CVE-2026-21662CVE-2026-34495CVE-2026-34497vulnerabilityxsshtml injection
threat-intel o6 Automation open62541 Multiple vulnerabilities have been identified in o6 Automation open62541, a control system software, potentially allowing for denial of service, arbitrary code execution, and information disclosure. These vulnerabilities… CISA Advisories · Jul 30, 2026 Critical CVE-2026-63362CVE-2026-65423CVE-2026-63035vulnerabilitycontrol-systemcisa
threat-intel FCC Blocks New Foreign-Produced Robots and Power Inverters Over Cyber Risks The FCC has added foreign-produced mobile robots and networked power inverters to its Covered List, aiming to mitigate cybersecurity risks associated with these devices. This action prevents new models from receiving equ… The Hacker News · Jul 30, 2026 High CVE-2025-35027CVE-2025-2894UNcybersecuritynational securitysupply chain
threat-intel Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline A coordinated cyberattack targeted over 30 community water systems in Minnesota, leading to operational disruptions and communications failures. While the exact number of compromised systems remains unclear, the attacks… The Hacker News · Jul 29, 2026 High UNcritical infrastructureindustrial control systemscyberattack
threat-intel Cyberattack hits Angola’s largest telco hours before landmark stock debut Angola’s largest telecommunications operator, Unitel, experienced a significant cyberattack that disrupted services nationwide, occurring just hours before its landmark stock market debut. The attack appears to have been… The Record · Jul 29, 2026 High AOcyberattacktelecomipo
threat-intel 73% of Organizations Say They Are Not Fully Ready for a Major Cyberattack A recent study reveals that 73% of organizations aren't fully prepared to withstand a major cyberattack, despite having incident response plans and security tools. The core issue isn't simply having these capabilities, b… The Hacker News · Jul 29, 2026 High incident responsecybersecurityvulnerability
threat-intel Russia Charges Telegram Founder Pavel Durov With Aiding Terrorist Activity Russia has charged Telegram founder Pavel Durov with aiding terrorist activity, alleging that the platform was used by Ukrainian special services and terrorist organizations to plan attacks and facilitate cybercrime with… The Hacker News · Jul 29, 2026 High RUUArussiaukraineintelligence
threat-intel US, Australia Release OT Isolation Guidance for Critical Infrastructure The US cybersecurity agency CISA and Australia’s ACSC have jointly released guidance, ‘CI Fortify,’ to help critical infrastructure organizations isolate vital Operational Technology (OT) systems and supporting networks.… SecurityWeek · Jul 29, 2026 Medium USAUcritical infrastructureot securitycyber resilience
data-breach Origin Energy Data Breach Affects 900,000 Australians Origin Energy, a major Australian power company, suffered a data breach affecting approximately 900,000 customers. The attackers gained access to sensitive data, including personal details and financial information, and… SecurityWeek · Jul 28, 2026 High AUdata breachaustraliacybersecurity