vulnerability Schneider Electric IGSS Schneider Electric has identified and issued a security advisory (SEVD-2026-195-01) regarding a critical out-of-bounds write vulnerability in its IGSS Definition module for the IGSS (Interactive Graphical SCADA System) p… CISA Advisories · Jul 30, 2026 High CVE-2026-12927scadaindustrial control systemscwe-787
threat-intel CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs The CISA is warning the Water and Wastewater Systems sector about a significant increase in cyberattacks targeting Programmable Logic Controllers (PLCs). Threat actors are modifying passwords to lock out operators and di… CISA Advisories · Jul 30, 2026 High plccybersecurityoperational technology
vulnerability MZ Automation GmbH libiec61850 CISA has issued an advisory regarding multiple vulnerabilities in MZ Automation GmbH’s libiec61850 software, specifically version <1.6.2. These vulnerabilities, all related to out-of-bounds reads, can lead to denial-of-s… CISA Advisories · Jul 30, 2026 High CVE-2026-66720CVE-2026-66369CVE-2026-63550vulnerabilityout-of-bounds readdenial-of-service
vulnerability Toptech Systems RCU II+ and Multiload II+ Toptech Systems has issued a vulnerability notice regarding RCU II+ and Multiload II+ devices, exposing a critical unauthenticated service that allows for full system control. Exploitation is not currently possible remot… CISA Advisories · Jul 30, 2026 High CVE-2026-12562vulnerabilitycontrol systemsauthentication
threat-intel Cyber extortionists steal data from UK Department for Education Cybercriminals, identifying as ExfilSquad, have stolen data from the UK Department for Education and the Police National Legal Database, potentially exposing names, email addresses, and contact details of over 600,000 in… The Record · Jul 30, 2026 High UKransomwaredata breachcybercrime
vulnerability Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module A vulnerability exists in Rockwell Automation's CompactLogix, ControlLogix, and GuardLogix communication modules (specifically the 1756-EN4TR module) due to improper certificate revocation handling. An attacker could exp… CISA Advisories · Jul 30, 2026 High CVE-2026-9636certificate revocationcip securityindustrial control systems
vulnerability Johnson Controls OpenBlue Employee Johnson Controls has released a security advisory (JCI-PSA-2026-09) addressing critical vulnerabilities in its OpenBlue Employee system. These vulnerabilities – including stored XSS, HTML injection, and file upload flaws… CISA Advisories · Jul 30, 2026 High CVE-2026-21662CVE-2026-34495CVE-2026-34497vulnerabilityxsshtml injection
threat-intel Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents Microsoft Copilot for Word has a vulnerability that allows hidden instructions within a Word document to be copied into new documents and then re-introduced during subsequent Copilot drafting sessions. This allows an att… The Hacker News · Jul 30, 2026 High prompt injectionai securitycopilot
threat-intel The Network Has Become the Control Plane for AI Security As AI adoption explodes and fundamentally changes how network traffic flows, traditional firewalls are struggling to keep pace. Check Point has introduced an AI Network Firewall, designed to move beyond simple traffic in… The Hacker News · Jul 30, 2026 High aifirewallnetwork security
data-breach OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia A Chinese-speaking threat actor has been deploying two backdoors, OctLurk and SilkLurk, targeting government organizations and critical infrastructure in Central Asia since January 2025. These backdoors, along with assoc… Securelist · Jul 30, 2026 High
threat-intel Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts A state-sponsored threat group, potentially linked to Lazarus and operating between 2025 and 2026, exploited vulnerabilities in AnySign4PC, a certificate-based electronic signature software, to install backdoors on targe… The Hacker News · Jul 30, 2026 High CVE-2020-7882SOwatering holebuffer overflowremote code execution
threat-intel SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT The Chinese cybercrime group Silver Fox is targeting Japanese manufacturers using a sophisticated Bring Your Own Vulnerable Driver (BYOVD) attack chain to deploy ValleyRAT, a Gh0st RAT variant. They utilize a layered app… The Hacker News · Jul 30, 2026 High SOCHbyovddll side-loadingntdll unhooking
threat-intel Russian spies take their half-click email attack from Zimbra to Outlook Russian intelligence operatives are leveraging a phishing campaign mimicking Signal support to trick users into revealing sensitive information. This tactic has expanded beyond Zimbra to now target Outlook users, highlig… The Register · Jul 30, 2026 High CVE-2026-42897RUCHphishingsocial engineeringrussian threat actor
threat-intel ExfilSquad expose des données CRM municipales A new extortion group, ExfilSquad, claims to possess a significant amount of sensitive data from municipal services and CRM platforms, including data from Houston, Atlanta, and Microsoft. They’ve released sample data, pr… ZATAZ · Jul 30, 2026 High UNcrmdata breachexfiltration
threat-intel Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks A Chinese-speaking threat actor, operating under the aliases knaithe and KnYuan, is leveraging AI to conduct autonomous cyberattacks. Using the Hermes Agent framework and DeepSeek, they autonomously identified and exploi… Palo Alto Unit 42 · Jul 30, 2026 High CVE-2026-33017CVE-2026-21858CVE-2025-68613CNaiautonomousvulnerability
threat-intel 240 bases françaises diffusées par des pirates A massive leak of 240 French databases, totaling approximately 90% of which are already known, has been released by multiple pirates. The data spans incidents since 2022 and includes organizations like Gustave Auto, Wina… ZATAZ · Jul 30, 2026 High FRdata leakcybercrimedata breach
threat-intel 1 in 5 Data Center Assets Are Within Easy Reach of Attackers A Claroty report reveals that nearly one in five data center assets are within easy reach of attackers, with a significant portion (18%) just one network hop away from internet exposure. This exposes critical infrastruct… SecurityWeek · Jul 30, 2026 High cyber-physical systemsot securitydata center
threat-intel Mercor face aux affirmations d’un pirate A hacker claiming to be linked to Lapsus$ is alleging a major data breach at Mercor, a US startup specializing in AI data and intelligence. The hacker claims to possess 1.150GB of user data, including biometric informati… ZATAZ · Jul 30, 2026 High N/data breachbiometricslapsus$
threat-intel North Korea’s elite hackers turned on their own government – and got caught North Korea's elite hackers, trained by the Reconnaissance and Intelligence General Bureau (the same agency behind the Lazarus Group), turned their skills inward and attempted to steal funds from the country's two larges… Graham Cluley · Jul 30, 2026 High KPnorth koreahackingcybercrime
threat-intel Le rôle de l’IA dans les opérations de cybercriminalité sur le dark web The article highlights a growing trend in cybercrime – the use of artificial intelligence by criminals on the dark web. AI is being used to create more convincing phishing attacks, automate various stages of attacks, and… ZATAZ · Jul 30, 2026 High aicybercrimedark web