vulnerability Delta Electronics DTM Soft A vulnerability has been identified in Delta Electronics’ DTM Soft software, allowing for potential arbitrary code execution via deserialization of untrusted data. This poses a risk to critical manufacturing operations g… CISA Advisories · Jun 25, 2026 High CVE-2026-12578WOdeserializationcwe-502critical manufacturing
vulnerability Yokogawa FAST/TOOLS and CI Server This advisory details a vulnerability in Yokogawa FAST/TOOLS and CI Server software, specifically versions R9.01 to R10.04, that allows an attacker to potentially retrieve CI Server setting information. The vulnerability… CISA Advisories · Jun 25, 2026 Medium CVE-2026-11833USweb servercwe-319vulnerability
ransomware Europe Evolves Into Ransomware's Favorite Region Ransomware attacks in Europe have dramatically increased, representing a significant shift from previous trends. Black Kite researchers report a 55% rise in ransomware attacks across the continent through the first four… Dark Reading · Jun 25, 2026 High UKGEFRransomwaresupply-chainai
threat-intel Exclusive: Meet AIVEX, a New Triage Model Built to Reduce Supply Chain Threat and Risk This article discusses the limitations of current vulnerability triage methods (SBOMs, VEX, and CVSS) in addressing supply chain attacks, particularly in the context of increasingly complex AI-driven systems. The author,… SecurityWeek · Jun 24, 2026 High supply chainaiautonomous robots
vulnerability ABB Freelance Security Lock This report details a critical vulnerability in ABB’s Freelance Security Lock software, allowing attackers to bypass security measures and potentially gain access to underlying operating system functions. The vulnerabili… CISA Advisories · Jun 23, 2026 Critical CVE-2025-7064WOkeyboardsecuritybypass
vulnerability Siemens Products using OpenSSL A stack-based buffer overflow vulnerability (CVE-2025-15467) has been identified in various Siemens products utilizing OpenSSL. This vulnerability allows a remote attacker to potentially cause a denial-of-service or exec… CISA Advisories · Jun 23, 2026 High CVE-2025-15467DEUSCNopensslbuffer overflowdenial of service
threat-intel INTERPOL Warns Phishing, Ransomware, and AI Scams Are Rising Across Asia-Pacific A new INTERPOL report highlights a significant surge in cybercrime across the Asia-Pacific region, driven by factors like digitalization and evolving criminal tactics. Phishing remains the most prevalent threat, alongsid… The Hacker News · Jun 22, 2026 High UKCALAphishingransomwareai
threat-intel CISA warns Fortinet users to secure devices after FortiBleed leak CISA has issued a warning to Fortinet customers regarding the "FortiBleed" data leak, which exposed nearly 74,000 firewall and VPN credentials. Threat actors are exploiting these compromised credentials to target interne… BleepingComputer · Jun 19, 2026 High USRUCNcredentialsvpnfirewall
ransomware INC Ransomware Emerges as Major RaaS Threat in 2026 with 830+ Victims Since 2023 INC ransomware has grown into a significant RaaS threat, impacting over 830 organizations since August 2023. The group leverages a combination of established techniques, including credential dumping from Veeam backups an… The Hacker News · Jun 18, 2026 High CVE-2023-3519CVE-2025-5777CVE-2023-48788USransomware-as-a-servicecredential dumpinglateral movement
vulnerability Rockwell Automation FactoryTalk Historian Site Edition This advisory from CISA details vulnerabilities in Rockwell Automation’s FactoryTalk Historian Site Edition software, specifically versions through 11.00. Exploitation could lead to denial-of-service attacks or authentic… CISA Advisories · Jun 18, 2026 Medium CVE-2025-13036CVE-2025-44019CVE-2025-36539USfactorytalkhistorianrockwellautomation
vulnerability Mitsubishi Electric MELSEC iQ-F Series This advisory from CISA details a vulnerability (CVE-2026-8805) in the Mitsubishi Electric MELSEC iQ-F Series FX5-EIP EtherNet/IP Module. The vulnerability, stemming from an integer overflow, allows a remote attacker to… CISA Advisories · Jun 18, 2026 High CVE-2026-8805JPethernet/ipdenial of serviceinteger overflow
vulnerability Schneider Electric EasyLogic T150 and Saitel DP This advisory details a vulnerability (CVE-2026-6865) affecting Schneider Electric’s EasyLogic T150 and Saitel DP Remote Terminal Units & Controllers. The vulnerability, a CWE-22 ‘Path Traversal’ flaw, allows an attacker… CISA Advisories · Jun 18, 2026 High CVE-2026-6865FRpath traversalfirmwareremote terminal unit
vulnerability Mitsubishi Electric Co.'s MELSEC iQ-F Series FX5-ENET/IP Ethernet Module This advisory from CISA details a denial-of-service (DoS) vulnerability in Mitsubishi Electric's MELSEC iQ-F Series FX5-ENET/IP Ethernet Module. The vulnerability, CVE-2026-8806, allows a remote attacker to overwhelm the… CISA Advisories · Jun 18, 2026 High CVE-2026-8806JPdenial-of-serviceethernetcve-2026-8806
threat-intel EU Gets a Head Start in Developing 6G Network Security The EU is launching the "Shield-6G" project, a collaborative initiative funded by the EU, to proactively develop cybersecurity measures for the upcoming 6G network. This project, involving 19 organizations, aims to addre… Dark Reading · Jun 18, 2026 Medium EU6gaicybersecurity
ransomware INC Ransomware Thrives by Mastering the Basics The INC ransomware group has emerged as a significant threat, particularly thriving through a focus on established ransomware-as-a-service (RaaS) tactics and targeting sectors with high pressure to pay, such as healthcar… Dark Reading · Jun 17, 2026 High CVE-2025-5777CVE-2024-57727CVE-2023-3519UKraasransomwareextortion
data-breach FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices. A significant data leak, dubbed "FortiBleed," has exposed approximately 73,932 Fortinet VPN credentials for firewall URLs across numerous organizations worldwide. The leak, discovered by Bob Diachenko, reveals a multi-op… BleepingComputer · Jun 17, 2026 High USGBJPvpncredentialsbreach
threat-intel Protecting legacy OT systems against modern cyberthreats The article highlights a growing and increasingly serious cybersecurity threat to manufacturing operations, particularly due to the convergence of IT and OT systems. Despite a long history of neglecting OT security, rans… WeLiveSecurity · Jun 17, 2026 High UKot securitylegacy systemsransomware
malware Fileless Phantom Stealer Targets Browser Credentials A new fileless malware, Phantom Stealer, is being deployed through targeted phishing campaigns against banks and high-value organizations. The malware focuses on stealing browser credentials and session cookies, utilizin… Dark Reading · Jun 16, 2026 High GBDEFRcredential theftbrowser securityfileless malware
threat-intel Can CISOs Trust Their Applications? TrustCloud Wants to Replace the Questionnaire This article discusses the challenges CISOs face when assessing the trust and security of their enterprise applications, highlighting the manual and time-consuming nature of traditional questionnaire-based approaches. Tr… SecurityWeek · Jun 16, 2026 Medium GBautomationaiapplication security
threat-intel Rockwell Automation Logix 5370 & 5570 Controllers Vulnerable To Denial of Service Via CIP Rockwell Automation has identified a denial-of-service vulnerability (CVE-2026-11317) affecting several versions of its Logix 5370 and 5570 controllers. The vulnerability stems from a fault triggered by crafted CIP messa… CISA Advisories · Jun 16, 2026 High CVE-2026-11317USdenial-of-serviceciprockwell automation