vulnerability MZ Automation libIEC61850 MZ Automation libIEC61850 versions 1.0.0 through 1.6.1 are vulnerable to several stack and heap-based buffer overflows, potentially allowing an unauthenticated attacker to crash critical IEC 61850 services or execute arb… CISA Advisories · Jul 23, 2026 High CVE-2026-50039CVE-2026-49035CVE-2026-50103iec61850buffer overflowindustrial control systems
vulnerability Multiples vulnérabilités dans Oracle Systems (23 juillet 2026) Multiple vulnerabilities have been discovered within Oracle Systems, potentially allowing attackers to compromise data confidentiality, integrity, and cause denial of service. These vulnerabilities affect various Oracle… CERT-FR · Jul 23, 2026 High CVE-2026-60659CVE-2026-60661CVE-2026-60833oraclevulnerabilitypatch
threat-intel Federal agencies broaden alert on Iran-linked OT attacks The U.S. government is widening its alert about ongoing cyberattacks targeting operational technology (OT) systems by Iranian-linked hackers. The initial warning focused on Rockwell Automation and Allen-Bradley PLCs, and… The Record · Jul 22, 2026 Medium IRotcyberattackplc
threat-intel Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA German and US law enforcement dismantled Kratos, a widely used criminal phishing kit, after arresting the developer and taking down over 200 servers. The kit, used by approximately 1,800 customers, was designed to steal… The Hacker News · Jul 22, 2026 High DEUSIDphishingcredential theftmfa bypass
threat-intel Ransomware Is Accelerating, But It's Not Because of AI Ransomware activity is surging, with a 25% increase in incidents between April 2025 and March 2026, driven by a fragmented ecosystem and the emergence of numerous new groups. Black Kite researchers found that many victim… Dark Reading · Jul 21, 2026 High USEUransomwarevulnerabilitysupply-chain
threat-intel CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG Andreas Gaetje, CISO at Korber AG, shares his career journey and insights on the evolving role of cybersecurity leadership. He emphasizes the importance of continuous learning and adaptability in a rapidly changing techn… SecurityWeek · Jul 21, 2026 High GEaicybersecurityleadership
threat-intel Coinbase Cartel menace Caterpillar Coinbase Cartel, a ransomware group, is attempting to intimidate Caterpillar with a threat to leak information to the press if the company doesn't respond. They are using a tactic of creating a countdown and threatening… ZATAZ · Jul 21, 2026 Medium ransomwareextortioncybercrime
threat-intel In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint This week’s cybersecurity news highlights a range of concerning events, including a Dutch telecom breach potentially linked to local cybercriminals, a Lidl data breach impacting customers in Belgium and the Netherlands,… SecurityWeek · Jul 17, 2026 High NEBEGEcyberattackransomwaredata breach
threat-intel Multiples vulnérabilités dans le noyau Linux de SUSE (17 juillet 2026) Multiple vulnerabilities have been discovered in the SUSE Linux kernel. These vulnerabilities can lead to privilege escalation, denial of service, and data confidentiality breaches. The affected products range from deskt… CERT-FR · Jul 17, 2026 High CVE-2023-53995CVE-2025-68324CVE-2025-71089vulnerabilitylinuxsecurity
threat-intel Legacy Systems, Real-World Impacts: The Reality of OT Security This article highlights the unique challenges of securing Operational Technology (OT) systems compared to traditional IT environments. Unlike IT, OT vulnerabilities often lead to devastating real-world consequences – lik… SecurityWeek · Jul 16, 2026 High otcybersecurityvulnerability
vulnerability Rockwell Automation Arena Rockwell Automation has released an advisory regarding critical vulnerabilities in its Arena simulation software. Specifically, versions up to V17.00.00 are affected by memory corruption flaws that could allow an attacke… CISA Advisories · Jul 16, 2026 High CVE-2026-8085CVE-2026-8312CVE-2026-8313vulnerabilitycontrol-systemmemory-corruption
threat-intel Siemens SICAM 8 Siemens has released security advisories detailing multiple vulnerabilities in its SICAM 8 industrial control system firmware and related components. These vulnerabilities could allow an attacker to cause denial of servi… CISA Advisories · Jul 16, 2026 High CVE-2026-54798CVE-2026-54799CVE-2026-54800vulnerabilityfirmwareindustrial control systems
vulnerability AutomationDirect Productivity Suite AutomationDirect Productivity Suite versions 4.6.2.2 and earlier are vulnerable to multiple out-of-bounds read and write vulnerabilities, potentially leading to kernel memory corruption, privilege escalation, system inst… CISA Advisories · Jul 16, 2026 High CVE-2026-60063CVE-2026-61389CVE-2026-60140cvevulnerabilityioctl
threat-intel ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Rockwell This Patch Tuesday saw significant security updates released by Siemens, Schneider Electric, Rockwell Automation, ABB, and Mitsubishi Electric to address a range of vulnerabilities in their industrial control systems (IC… SecurityWeek · Jul 15, 2026 High GEicspatch tuesdayvulnerability
vulnerability SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud SAP released 19 security patches on July 26th, 2026, addressing critical vulnerabilities across several of its flagship products, including NetWeaver, Approuter, and Commerce Cloud. The most severe vulnerability, CVE-202… SecurityWeek · Jul 14, 2026 Critical CVE-2026-44747CVE-2026-27690CVE-2026-44761sapvulnerabilitypatch
threat-intel Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths For a year, attackers leveraging the ShinyHunters group gained access to Salesforce environments not through exploiting vulnerabilities, but by exploiting trust placed in connected apps and vendors. They achieved this th… The Hacker News · Jul 14, 2026 High USoathconnected appsvendor compromise
vulnerability ISC Stormcast For Monday, July 13th, 2026 https://isc.sans.edu/podcastdetail/10004, (Mon, Jul 13th) The ISC Stormcast highlighted a significant vulnerability in Apache ActiveMQ, potentially allowing attackers to execute arbitrary code. This could lead to widespread disruption and data compromise across various industri… SANS Internet Storm Center · Jul 13, 2026 High activemqvulnerabilitydeserialization
ransomware No Manners Here: The Ruthless Rise of The Gentlemen Ransomware The Gentlemen, a rapidly growing Ransomware-as-a-Service (RaaS) program, has significantly increased its victim count in 2026, becoming the second most active RaaS program globally. Leveraging a 90% affiliate payout stru… Palo Alto Unit 42 · Jul 10, 2026 High CVE-2024-55591CVE-2025-32433CVE-2025-33073USCAGBransomware-as-a-serviceracksedge-device-attack
threat-intel Schneider Electric Easergy MiCOM Px40 Series Schneider Electric has issued a security advisory (SEVD-2026-104-03) regarding a critical vulnerability in its Easergy MiCOM Px40 Series protection relays. This vulnerability, a Use of Hard-coded Credentials (CWE-798), c… CISA Advisories · Jul 9, 2026 High CVE-2026-4832cwe-798snmpindustrial control systems
threat-intel 'GodDamn' Ransomware Uses BYOVD to Smite US Companies The ransomware group Hyadina, operating under the name "GodDamn," is leveraging a Microsoft-approved, malicious kernel driver – dubbed "PoisonX" – to infiltrate US organizations and deploy its ransomware. They utilize a… Dark Reading · Jul 9, 2026 High RUransomwaredriverbyovd