vulnerability Hitachi Energy e-mesh EMS Hitachi Energy has identified a buffer overflow vulnerability within its e-mesh EMS product versions 4.1.6, 4.4.2, and 4.7.0, stemming from a flaw in the NGINX Plus and NGINX Open Source modules. Exploitation could lead… CISA Advisories · Jul 7, 2026 High CVE-2026-42945buffer overflownginxubuntu
vulnerability Digi International PortServer TS, Digi One SP IA Digi International has issued a security advisory regarding critical vulnerabilities (CVE-2026-12948) in its PortServer TS, Digi One SP, Digi One SP IA, and Digi One IA devices. These vulnerabilities allow an unauthentic… CISA Advisories · Jul 7, 2026 High CVE-2026-12352CVE-2026-12948xsscveweb-management
vulnerability Hitachi Energy PROMOD V Hitachi Energy has identified an insecure HTTP transmission vulnerability in its PROMOD V product versions. This vulnerability, stemming from a lack of HTTPS support on the Digipede server, could allow attackers to inter… CISA Advisories · Jul 7, 2026 High CVE-2026-10763WOhttpvulnerabilitycybersecurity
threat-intel Siemens SINEC OS Siemens has released a security advisory regarding multiple vulnerabilities within its SINEC OS and related products, including the RUGGEDCOM RST2428P. These vulnerabilities, ranging from stack-based buffer overflows to… CISA Advisories · Jul 7, 2026 High CVE-2025-1352CVE-2025-1376CVE-2025-6052vulnerabilitybuffer overflowpath traversal
threat-intel Labcenter Proteus 9 CISA has issued an advisory regarding critical vulnerabilities in Labcenter Proteus 9, a software used in critical infrastructure sectors such as communications, defense industrial base, and energy. These vulnerabilities… CISA Advisories · Jul 7, 2026 High CVE-2026-42953CVE-2026-49033CVE-2026-42958vulnerabilityremote code executioncritical infrastructure
threat-intel UAT-7810 continues building ORB networks using new malware Cisco Talos Intelligence has identified UAT-7810, a China-nexus APT group, continuing to develop and deploy malware as part of its Operational Relay Box (ORB) network. The group is actively creating new malware variants,… Cisco Talos · Jul 7, 2026 High CVE-2020-22653CVE-2020-22658CVE-2023-25717CHaptmalwarechina
threat-intel Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities A China-aligned threat actor cluster, tracked as UNC5174 and linked to ShadowPad, has been exploiting vulnerabilities in Roundcube webmail software at U.S. and Canadian universities. The campaign leverages CVE-2024-42009… The Hacker News · Jul 7, 2026 High CVE-2024-42009CVE-2025-49113CHUSCAroundcubexsscve-2024-42009
vulnerability CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware The CERT Coordination Center has issued a warning about a hidden backdoor embedded in Tenda router firmware. This vulnerability, tracked as CVE-2026-11405, allows attackers to bypass password verification and gain full a… The Hacker News · Jul 7, 2026 High CVE-2026-11405routerbackdoorfirmware
threat-intel ISC Stormcast For Tuesday, July 7th, 2026 https://isc.sans.edu/podcastdetail/9996, (Tue, Jul 7th) The SANS Internet Storm Center’s latest Stormcast highlighted a significant increase in malicious activity targeting industrial control systems (ICS) and operational technology (OT) environments. The report indicated a s… SANS Internet Storm Center · Jul 7, 2026 High icsotvulnerability
threat-intel 'BusySnake' Infostealer Slithers into Critical Infrastructure Networks The threat group Armored Likho, operating under the name 'BusySnake,' has infiltrated critical infrastructure networks across Russia, Brazil, and Kazakhstan. This group is leveraging a sophisticated infostealer to steal… Dark Reading · Jul 6, 2026 High RUBRKZinfostealercritical infrastructurenation-state
vulnerability CitrixBleed-ing Again? NetScaler Vulnerability Under Attack A vulnerability in Citrix's NetScaler products has quickly been exploited by attackers following the release of a proof-of-concept exploit. The flaw allows attackers to potentially gain unauthorized access to systems, hi… Dark Reading · Jul 6, 2026 High memory-disclosurecitrixvulnerability
threat-intel Attackers vote themselves $20 million in BONK cryptocurrency Attackers exploited a governance mechanism within the decentralized finance project overseeing BONK cryptocurrency, draining $20 million worth of the token. This was achieved through a malicious governance proposal, leve… The Record · Jul 6, 2026 High KRdaogovernancecryptocurrency
threat-intel Blogspot-Hosted Payloads Delivered in ‘Veil#Drop’ Attacks Securonix researchers identified a complex malware delivery framework called ‘Veil#Drop’ that utilizes compromised websites, specifically Blogspot, to deploy information-stealing malware. The framework employs multiple l… SecurityWeek · Jul 6, 2026 High malwareinformation stealerevasion
threat-intel Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations Iranian hackers, linked to Iran's Ministry of Intelligence and Security (MOIS) and operating under the moniker Cavern Manticore, are utilizing a new, modular command-and-control (C2) framework called ‘Cavern’ to target I… The Hacker News · Jul 6, 2026 High CVE-2025-52691CVE-2025-68613CVE-2025-9316ISIRc2command and controldotnet
data-breach Major medical device manufacturer notifies nearly 4 million of breach Medtronic, a leading medical device manufacturer, has notified nearly 4 million individuals that their data may have been compromised in a cyberattack. The breach was linked to the ShinyHunters cybercrime group and resul… The Record · Jul 6, 2026 High data breachcybersecuritymedical devices
threat-intel 16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems A 16-year-old use-after-free vulnerability in Linux's KVM hypervisor, dubbed ‘Januscape’ (CVE-2026-53359), allows guest virtual machines to corrupt the host kernel's shadow-page state. Researcher Hyunwoo Kim discovered t… The Hacker News · Jul 6, 2026 High CVE-2026-53359CVE-2026-43284CVE-2026-43500use-after-freeshadow pagenested virtualization
threat-intel JadePuffer: The First Complete LLM-Driven Ransomware Attack Sysdig researchers have identified ‘JadePuffer,’ the first documented case of a fully autonomous ransomware operation driven by a large language model (LLM). The attack leveraged a Langflow vulnerability to gain initial… Dark Reading · Jul 6, 2026 High CVE-2025-3248airansomwarellm
apt Armored Likho APT Targeting Government, Electric Power Entities The Armored Likho APT group is actively targeting government and electric power entities across multiple countries, including Russia, Brazil, and Kazakhstan. The group utilizes a diverse toolkit of malware, including RAT… SecurityWeek · Jul 6, 2026 High RUBRKZaptspear-phishingrat
threat-intel Ukrainian media outlets now among 'priority targets' for Russian hackers Ukrainian media outlets are increasingly becoming priority targets for Russian hackers as part of a broader campaign to undermine public trust and spread propaganda amid Russia’s ongoing invasion of Ukraine. Recent attac… The Record · Jul 6, 2026 High UKRUcyberattacksukrainerussia
supply-chain North Korean Hackers Target Open Source Developers in Supply Chain Attacks North Korean hackers, linked to the Contagious Interview operation, are engaging in a sophisticated supply chain attack targeting open-source developers. They are leveraging compromised GitHub repositories and malicious… SecurityWeek · Jul 6, 2026 High KRsupply-chaingithubopen-source