threat-intel Legacy Systems, Real-World Impacts: The Reality of OT Security This article highlights the unique challenges of securing Operational Technology (OT) systems compared to traditional IT environments. Unlike IT, OT vulnerabilities often lead to devastating real-world consequences – lik… SecurityWeek · Jul 16, 2026 High otcybersecurityvulnerability
vulnerability n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer A vulnerability in n8n’s Enterprise token exchange feature allows attackers to log in as users from another issuer if the platform trusts more than one external token issuer. The flaw stems from a mismatch between the is… The Hacker News · Jul 16, 2026 High CVE-2026-59208CVE-2026-54305jwttokenidentity-binding
vulnerability NASA Core Flight System (cFS) Health & Safety (HS) Application NASA has issued an advisory regarding a vulnerability in its Core Flight System (cFS) Health & Safety (HS) Application, potentially leading to denial-of-service conditions. The vulnerability, identified as a segmentation… CISA Advisories · Jul 16, 2026 Medium CVE-2026-15352vulnerabilitysegmentation faultcisa
threat-intel Siemens SICAM 8 Siemens has released security advisories detailing multiple vulnerabilities in its SICAM 8 industrial control system firmware and related components. These vulnerabilities could allow an attacker to cause denial of servi… CISA Advisories · Jul 16, 2026 High CVE-2026-54798CVE-2026-54799CVE-2026-54800vulnerabilityfirmwareindustrial control systems
vulnerability Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT Rockwell Automation has released a vulnerability in its 1756-EN2, 1756-EN3, and 1756-ENBT communication modules. Exploitation could lead to a denial-of-service condition. Users are advised to update to the latest version… CISA Advisories · Jul 16, 2026 High CVE-2026-9653vulnerabilitycontrol systemscisa
vulnerability Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix Several vulnerabilities exist in Rockwell Automation's CompactLogix, ControlLogix, Compact GuardLogix, and GuardLogix controllers. Successful exploitation could lead to a denial-of-service condition due to an invalid pro… CISA Advisories · Jul 16, 2026 High CVE-2025-12011CVE-2025-12012CVE-2025-11698firmwarecontrol-systemdenial-of-service
vulnerability AutomationDirect Productivity Suite AutomationDirect Productivity Suite versions 4.6.2.2 and earlier are vulnerable to multiple out-of-bounds read and write vulnerabilities, potentially leading to kernel memory corruption, privilege escalation, system inst… CISA Advisories · Jul 16, 2026 High CVE-2026-60063CVE-2026-61389CVE-2026-60140cvevulnerabilityioctl
vulnerability Rockwell Automation Arena Rockwell Automation has released an advisory regarding critical vulnerabilities in its Arena simulation software. Specifically, versions up to V17.00.00 are affected by memory corruption flaws that could allow an attacke… CISA Advisories · Jul 16, 2026 High CVE-2026-8085CVE-2026-8312CVE-2026-8313vulnerabilitycontrol-systemmemory-corruption
vulnerability SALTO ProAccess Space A critical vulnerability (CVE-2026-11889) exists in SALTO ProAccess Space versions prior to 6.13, allowing an authenticated attacker to escalate privileges and gain unauthorized access to spaces beyond their assigned par… CISA Advisories · Jul 16, 2026 Critical CVE-2026-11889WOvulnerabilityprivilege escalationcve-2026-11889
vulnerability Rockwell Automation Flex 5000 Adapter Rockwell Automation has released a security advisory regarding a denial-of-service vulnerability in its Flex 5000 Adapter software. Exploitation could lead to a denial-of-service condition, and Rockwell recommends upgrad… CISA Advisories · Jul 16, 2026 High CVE-2026-12659vulnerabilitydenial-of-servicecontrol systems
threat-intel New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands Researchers at Seoul National University, the University of Illinois Urbana-Champaign, and Largosoft have discovered a new attack method called Agent Data Injection (ADI) that can manipulate AI agents by subtly corruptin… The Hacker News · Jul 16, 2026 High CVE-2025-32711prompt-injectiondata-exfiltrationai-security
vulnerability Splunk, Zoom Patch Critical Vulnerabilities Splunk and Zoom have released patches to address several critical and high-severity vulnerabilities in their respective products. These flaws could allow attackers to steal credentials, access sensitive data, and potenti… SecurityWeek · Jul 16, 2026 High CVE-2026-20296CVE-2026-20297CVE-2026-20298vulnerabilitypatchsecurity
threat-intel AI Can Find Bugs, But Human Knowledge Still Proves Them AI tools are increasingly being used in security testing, offering benefits like rapid code analysis and payload generation. However, the key challenge remains that AI-generated findings often lack sufficient validation… The Hacker News · Jul 16, 2026 High aivulnerabilitysecurity
vulnerability Unpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-Wide A researcher discovered a critical vulnerability in Shark robot vacuums due to a flawed certificate policy on Amazon's AWS cloud platform. Attackers can exploit this to gain remote control of vacuums across an entire AWS… The Hacker News · Jul 16, 2026 Critical awsiotcertificate
vulnerability F5 Patches Multiple NGINX, BIG-IP Vulnerabilities F5 has released out-of-band security patches to address eight critical vulnerabilities affecting NGINX and BIG-IP. These flaws could lead to denial-of-service attacks, memory leaks, and potentially allow remote code exec… SecurityWeek · Jul 16, 2026 High CVE-2026-42533nginxbig-ipvulnerability
threat-intel Old UEFI Shims Expose Systems to Secure Boot Bypass A vulnerability in older Microsoft-signed UEFI shim bootloaders has been discovered, allowing attackers to bypass Secure Boot protections and potentially deploy bootkits on UEFI-based systems. These shims, some dating ba… SecurityWeek · Jul 16, 2026 High CVE-2026-8863CVE-2026-10797uefisecure bootvulnerability
vulnerability Zoom Patches Critical Windows Flaw That Could Enable Account Takeover Zoom has released critical security patches to address a series of vulnerabilities in its Windows-based products, including Zoom Workplace, Zoom VDI Client, and Zoom Rooms. These flaws could allow attackers to gain unaut… The Hacker News · Jul 16, 2026 High CVE-2026-53412CVE-2026-53411CVE-2026-53410windowsvulnerabilityaccount_takeover
vulnerability Nightmare Eclipse Drops ‘LegacyHive’ Windows Zero-Day Nightmare Eclipse, a security researcher, has released another unpatched Windows zero-day vulnerability, LegacyHive, which allows local privilege escalation. This exploit targets the Windows User Profile Service and requ… SecurityWeek · Jul 16, 2026 High zero-dayprivilege-escalationwindows
vulnerability Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities Several cybersecurity firms, including Trend Micro, Tenable, ESET, and Palo Alto Networks, have released patches to address critical vulnerabilities in their products. These vulnerabilities range from local privilege esc… SecurityWeek · Jul 16, 2026 High CVE-2026-15265vulnerabilitypatchsecurity
vulnerability Vulnérabilité dans Traefik (16 juillet 2026) A security vulnerability has been identified in Traefik versions 3.7.x, allowing attackers to bypass security policies. Users are advised to apply the latest security patch released by Traefik to mitigate this risk. CERT-FR · Jul 16, 2026 Medium traefikvulnerabilitysecurity