threat-intel Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials A threat actor is exploiting vulnerabilities in public Wi-Fi gateways, particularly at hotels and conference centers, to steal corporate credentials, including Microsoft 365 accounts, and is leveraging tactics similar to… SecurityWeek · Jul 27, 2026 High USINSAdnscaptive portalcredential theft
threat-intel Andy Burnham signals continuity on UK cyber policy, reappoints minister despite scrapping ministry Following a government reshuffle, UK cybersecurity minister Liz Lloyd has been reappointed to her role, maintaining continuity on the Cyber Security and Resilience Bill. The government has reorganized departments, splitt… The Record · Jul 24, 2026 Medium UKcybersecurityukcyber policy
data-breach Data Breach Confirmed After Australian Energy Giant Origin Is Hacked Origin Energy, a major Australian energy provider, suffered a data breach, with an attacker claiming to have stolen information from approximately 2 million customers. The attacker demanded a ransom, threatening to relea… SecurityWeek · Jul 24, 2026 High AUdata breachcybersecurityransomware
threat-intel ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories This week's "ThreatsDay" bulletin highlights a diverse range of security threats, from malware targeting PLCs with Iranian involvement to AI-generated vulnerabilities and deceptive apps. Key concerns include a GitHub sup… The Hacker News · Jul 23, 2026 High IRmalwarethreat intelligencesupply-chain
data-breach Major Australian energy supplier confirms customer data compromised Origin Energy, a major Australian energy provider, has confirmed a data breach impacting nearly 5 million customers. The breach exposed sensitive data including account details, credit card information, and personal iden… The Record · Jul 23, 2026 Medium AUdata breachcybersecurityaustralia
vulnerability MZ Automation lib60870 A vulnerability in MZ Automation lib60870, version 2.4.0 and earlier, allows for a denial-of-service attack through an out-of-bounds read. This affects critical infrastructure sectors like chemical, energy, and water/was… CISA Advisories · Jul 23, 2026 Medium CVE-2026-16002GEout-of-boundsdenial of servicecisa
threat-intel Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite A group of Russian state-supported cyber actors, known as LAUNDRY BEAR, has been aggressively targeting Western organizations using the Zimbra Collaboration Suite (ZCS) since July 2025, seeking to gather sensitive inform… CISA Advisories · Jul 23, 2026 High CVE-2025-66376MOPOSPphishingsupply-chainmalware
vulnerability Panduit IntraVUE Pronetiqs has identified and reported several vulnerabilities in Panduit IntraVUE software versions 3.2.1a14 and earlier, posing significant risks to industrial control systems. These vulnerabilities include plaintext st… CISA Advisories · Jul 23, 2026 High CVE-2026-40430CVE-2026-42933CVE-2026-44955industrial control systemsot securitypassword vulnerability
vulnerability MZ Automation libIEC61850 MZ Automation libIEC61850 versions 1.0.0 through 1.6.1 are vulnerable to several stack and heap-based buffer overflows, potentially allowing an unauthenticated attacker to crash critical IEC 61850 services or execute arb… CISA Advisories · Jul 23, 2026 High CVE-2026-50039CVE-2026-49035CVE-2026-50103iec61850buffer overflowindustrial control systems
threat-intel US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices The US government has issued an updated cybersecurity advisory warning of ongoing Iranian-linked attacks targeting industrial control systems (ICS) manufactured by Siemens, Schneider Electric, and Rockwell Automation. Ha… SecurityWeek · Jul 23, 2026 High IRicsindustrial control systemsplc
threat-intel Swiss train maker Stadler refuses Everest $12 million ransomware demand Swiss train manufacturer Stadler Rail refused a $12.3 million ransomware demand from the Russian-speaking group Everest after cybercriminals stole technical data from a supplier’s file-sharing platform. The incident did… The Record · Jul 22, 2026 High SWRUransomwaredata breachsupply chain
vulnerability Siemens IAM Client Siemens has identified a critical unquoted search path vulnerability in its IAM Client SDK, potentially allowing an authenticated local attacker to escalate privileges. Multiple Siemens products, including COMOS, Designc… CISA Advisories · Jul 21, 2026 Critical CVE-2025-40945cwe-426unquoted search pathiam client
vulnerability Rockwell Automation ThinManager Rockwell Automation has issued a security advisory regarding a path traversal vulnerability in its ThinManager software. This vulnerability allows an authenticated attacker to write arbitrary files to restricted system d… CISA Advisories · Jul 21, 2026 Critical CVE-2026-11917path traversalicsindustrial control systems
vulnerability Siemens CADRA Siemens CADRA is affected by multiple vulnerabilities within the zlib library, primarily stemming from improper input validation and integer overflows. These vulnerabilities could lead to denial-of-service crashes, heap… CISA Advisories · Jul 21, 2026 High CVE-2005-2096CVE-2016-9840CVE-2016-9841zlibvulnerabilitybuffer overflow
threat-intel New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit Researchers at Zhejiang University have discovered a method to potentially disrupt power grids using cloud GPUs. Dubbed ‘Bit2Watt,’ the technique involves manipulating a GPU’s power draw – switching between high-intensit… The Hacker News · Jul 21, 2026 High CHgpupower gridcybersecurity
threat-intel India says allegedly leaked nuclear plant files pose no safety risk A cybercrime group, World Leaks (formerly Hunters International ransomware), has allegedly leaked thousands of files related to India's Kudankulam Nuclear Power Plant, claiming they originated from a breach involving Rel… The Record · Jul 20, 2026 High INcybercrimedata breachnuclear
threat-intel ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More This week saw a flurry of vulnerabilities and attacks, including a WordPress core flaw leading to remote code execution, exploitation of zero-day vulnerabilities in SonicWall VPN appliances, and a new malware framework (… The Hacker News · Jul 20, 2026 High CVE-2026-63030CVE-2026-60137CVE-2026-15409INTÜBRvulnerabilityzero-dayransomware
threat-intel Ukrainians rally against dismissal of tech-minded defense minister Fedorov Ukrainian citizens have taken to the streets to protest the dismissal of Defense Minister Mykhailo Fedorov, who was a key figure in integrating drone technology and digital innovation into Ukraine’s military and combatin… The Record · Jul 16, 2026 Medium UAukrainedefensedigitalization
threat-intel Legacy Systems, Real-World Impacts: The Reality of OT Security This article highlights the unique challenges of securing Operational Technology (OT) systems compared to traditional IT environments. Unlike IT, OT vulnerabilities often lead to devastating real-world consequences – lik… SecurityWeek · Jul 16, 2026 High otcybersecurityvulnerability
threat-intel HelloNet campaign — new malicious modules launched through the ViPNet update system A Chinese-speaking Advanced Persistent Threat (APT) group, likely operating since May 2026, has been targeting Russian organizations using a sophisticated campaign centered around the ViPNet software suite. The campaign… Securelist · Jul 16, 2026 High CHaptdll hijackingprocess injection