threat-intel ISC Stormcast For Tuesday, July 7th, 2026 https://isc.sans.edu/podcastdetail/9996, (Tue, Jul 7th) The SANS Internet Storm Center’s latest Stormcast highlighted a significant increase in malicious activity targeting industrial control systems (ICS) and operational technology (OT) environments. The report indicated a s… SANS Internet Storm Center · Jul 7, 2026 High icsotvulnerability
threat-intel 'BusySnake' Infostealer Slithers into Critical Infrastructure Networks The threat group Armored Likho, operating under the name 'BusySnake,' has infiltrated critical infrastructure networks across Russia, Brazil, and Kazakhstan. This group is leveraging a sophisticated infostealer to steal… Dark Reading · Jul 6, 2026 High RUBRKZinfostealercritical infrastructurenation-state
threat-intel ISC Stormcast For Monday, July 6th, 2026 https://isc.sans.edu/podcastdetail/9994, (Mon, Jul 6th) The SANS Internet Storm Center’s latest Stormcast highlighted a significant increase in malicious activity targeting industrial control systems (ICS) and operational technology (OT) environments. Specifically, the report… SANS Internet Storm Center · Jul 6, 2026 High icsotindustrial control systems
vulnerability ST Engineering iDirect iQ-Series Terminals ST Engineering iDirect has issued a security advisory regarding vulnerabilities in its iQ-Series Terminals, specifically versions through 4.5.2.1. These vulnerabilities allow unauthorized access to device information, in… CISA Advisories · Jul 2, 2026 High CVE-2026-38059CVE-2026-38057USapiauthenticationcsrf
threat-intel FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations A large-scale credential theft campaign, dubbed FortiBleed, has been linked to both the INC and Lynx ransomware groups, utilizing stolen Fortinet credentials for follow-on intrusions. The operation involved extensive sca… The Hacker News · Jul 2, 2026 High CVE-2026-35616USLAAScredential theftransomwarefortinet
vulnerability Schneider Electric EcoStruxure IT Data Center Expert This report details a vulnerability discovered in Schneider Electric’s EcoStruxure IT Data Center Expert software, specifically versions up to 9.1.1. The vulnerability, classified as CWE-611, is an Improper Restriction o… CISA Advisories · Jun 30, 2026 Medium CVE-2026-8045FRxmlcwe-611data center
vulnerability StoneFly Storage Concentrator This report details a critical vulnerability affecting StoneFly Storage Concentrator versions prior to 8.0.4.29, exposing the system to significant risks including unauthorized access, command execution, and data theft.… CISA Advisories · Jun 30, 2026 Critical CVE-2026-56415CVE-2026-55721CVE-2026-50040UScredentialcommand injectionsql injection
vulnerability Schneider Electric EasyLogic T150 and Saitel DP RTU This advisory details vulnerabilities in Schneider Electric's EasyLogic T150 and Saitel DP RTU devices, specifically versions through 11.06.37. These vulnerabilities, classified as CWE-522 and CWE-732, allow for unauthor… CISA Advisories · Jun 30, 2026 Medium CVE-2026-9650CVE-2026-9651FRcredentialsfirmwareiot
vulnerability Frangoteam FUXA SCADA/HMI This advisory details a critical vulnerability in Frangoteam FUXA SCADA/HMI software versions up to 1.3.1, allowing unauthenticated remote attackers to enumerate user accounts and role assignments. The vulnerability stem… CISA Advisories · Jun 30, 2026 Critical CVE-2026-13207WOauthentication bypassscadahmi
threat-intel Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign A Chinese-speaking Advanced Persistent Threat (APT) group, CL-STA-1062, has been actively targeting government entities and critical infrastructure in Southeast Asia since 2022, utilizing a new custom backdoor called Tin… The Hacker News · Jun 26, 2026 High VNaptbackdoorsoutheast asia
threat-intel FCC votes to toughen rules in bid to better protect undersea cables The FCC has voted to implement stricter regulations for undersea cables, aiming to bolster national security and protect internet traffic. This includes mandating licensing for submarine line terminal equipment (SLTE) an… The Record · Jun 26, 2026 High CHUKUSundersea cablescybersecuritynational security
threat-intel CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure Palo Alto Unit 42 has identified a sustained cyber threat campaign, CL-STA-1062, targeting government and critical infrastructure entities in Southeast Asia since at least March 2022. The group, linked to UAT-7237, utili… Palo Alto Unit 42 · Jun 25, 2026 High VNeast asiasoutheast asiabackdoor
threat-intel EVoke Systems Charging Station Management System This advisory details a vulnerability in the EVoke Systems Charging Station Management System (CSMS) due to a lack of proper authentication mechanisms in its WebSocket endpoints. Attackers could exploit this to gain unau… CISA Advisories · Jun 25, 2026 High CVE-2026-40702CVE-2026-50176CVE-2026-54479USwebsocketocppauthentication
vulnerability Schneider Electric PowerLogic P7 Schneider Electric has identified and addressed vulnerabilities within its PowerLogic™ P7 protection and control platform. Specifically, the product is susceptible to CWE-476 (NULL Pointer Dereference), CWE-78 (Improper… CISA Advisories · Jun 25, 2026 High CVE-2026-9716CVE-2026-9717CVE-2026-9718FRcwefirmwareindustrial control
vulnerability Yokogawa FAST/TOOLS and CI Server This advisory details a vulnerability in Yokogawa FAST/TOOLS and CI Server software, specifically versions R9.01 to R10.04, that allows an attacker to potentially retrieve CI Server setting information. The vulnerability… CISA Advisories · Jun 25, 2026 Medium CVE-2026-11833USweb servercwe-319vulnerability
vulnerability Siemens WinCC Certificate Manager A vulnerability has been identified in Siemens WinCC Certificate Manager, specifically versions V16 through V21, that allows an attacker to potentially extract sensitive information due to insufficient protection of key… CISA Advisories · Jun 23, 2026 High CVE-2026-24349GEcertificatekey managementindustrial control systems
vulnerability Hubbell Aclara Metrum Cellular Web Interface This CISA advisory details a vulnerability in Hubbell Aclara Metrum Cellular Web Interface software, specifically versions prior to 2.1.0.105. The flaw allows unauthorized access to critical device settings, potentially… CISA Advisories · Jun 23, 2026 High CVE-2026-1840USfirmwareauthenticationcritical infrastructure
threat-intel Siemens SINEC INS This CISA advisory details a critical vulnerability affecting Siemens SINEC INS versions prior to V1.0 SP2 Update 6. The vulnerability stems from improper input sanitization, allowing for command injection, path traversa… CISA Advisories · Jun 23, 2026 Critical CVE-2026-46746CVE-2026-46747CVE-2026-46748DEcommand injectionpath traversalpassword cracking
vulnerability Siemens SIPROTEC 5 Using DIGSI5 Protocol This CISA advisory details a vulnerability in Siemens SIPROTEC 5 devices, specifically utilizing the DIGSI5 protocol, that allows authenticated users to upload arbitrary files. This could lead to denial-of-service condit… CISA Advisories · Jun 23, 2026 High CVE-2025-40808relayprotocoldenial of service
threat-intel Canada’s Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices Canadian spy agency, CSIS, utilized a novel court-ordered warrant to neutralize two foreign-run botnets operating within Canada. The operation targeted infected servers, SOHO routers, and IoT devices like Ring doorbells… The Hacker News · Jun 22, 2026 High CAUSbotnetiotcybersecurity