threat-intel Uncle Sam needs you to fight for 6G leadership and security, lest Beijing get there first The United States is actively working to maintain leadership in 6G technology and security, particularly in response to China's advancements. Recent security incidents highlight ongoing threats, including phishing attack… The Register · Jul 28, 2026 Medium IRCHphishingvulnerabilitiescybersecurity
threat-intel Former Citigroup CISO Blauner on What Makes A Great Security Leader This article focuses on the evolving role of the Chief Information Security Officer (CISO) and the increasing importance of operational resilience in cybersecurity. It highlights how AI is reshaping the field and emphasi… Dark Reading · Jul 28, 2026 Info cisocybersecurityleadership
vulnerability ABB KNX Update Tool ABB has identified a vulnerability in its KNX Update Tool, affecting legacy KNX devices due to a lack of security features. The vulnerability allows an attacker with physical access to the KNX bus to render the device un… CISA Advisories · Jul 28, 2026 High CVE-2026-12705
vulnerability MikroTik RouterOS and Cloud Hosted Router A critical vulnerability (CVE-2026-16347) exists in MikroTik RouterOS and Cloud Hosted Router, allowing attackers to rapidly guess passwords and gain unauthorized access by repeatedly attempting logins. No fix is current… CISA Advisories · Jul 28, 2026 Critical CVE-2026-16347vulnerabilitypassword-crackingapi
vulnerability Siemens Mendix Runtime A gap in Siemens Mendix Runtime documentation regarding access rules for the System.User entity has been identified, potentially leading developers to apply overly permissive access rules, exposing sensitive user data an… CISA Advisories · Jul 28, 2026 Critical CVE-2026-7891mendixaccess-controlindustrial-control-systems
vulnerability igloohome Smart Lock Mobile Application A vulnerability in the igloohome Smart Lock Mobile Application (Android 3.2.3) allows an unauthorized actor to access backend services. This could enable access to sensitive functionality and potentially compromise the s… CISA Advisories · Jul 28, 2026 Medium CVE-2026-16581vulnerabilitycwe-540smart lock
vulnerability Siemens SIMATIC S7-PLCSIM Advanced A vulnerability in Siemens SIMATIC S7-PLCSIM Advanced could allow an unauthenticated attacker to cause a denial-of-service condition by overwhelming the application with high-volume multicast network traffic. Siemens is… CISA Advisories · Jul 28, 2026 High CVE-2026-54429DEindustrial control systemscve-2026-54429denial of service
threat-intel CI Fortify – Advice for isolating vital systems The U.S. government, through CISA and ASD’s ACSC, has released guidance for critical infrastructure organizations to isolate vital operational technology and enabling systems from other networks. This proactive measure i… CISA Advisories · Jul 28, 2026 Medium critical infrastructurecybersecurityisolation
data-breach Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant). Siemens is preparing fix versions… CISA Advisories · Jul 28, 2026 High CVE-2021-41617CVE-2023-28531CVE-2023-51384
vulnerability Siemens Desigo CC A stack-based buffer overflow vulnerability in Siemens Desigo CC versions V7, V8, and V9 (prior to V9.0.1) has been identified, potentially allowing remote code execution. Siemens has released patches and recommends upda… CISA Advisories · Jul 28, 2026 High CVE-2025-15467DEstack-buffer-overflowcwe-787open ssl
threat-intel Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays The Iranian state-backed hacking group Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) is deploying a new campaign targeting entities across the Middle East, Africa, and South… The Hacker News · Jul 28, 2026 High IREGJOwindowsbackdoortunneling
threat-intel Microsoft Unveils MAI-Cyber-1-Flash, Its First Cybersecurity AI Model Microsoft has released MAI-Cyber-1-Flash, its first cybersecurity AI model, designed to significantly improve vulnerability detection compared to competitors. This new model is integrated into Microsoft’s Project Percept… SecurityWeek · Jul 28, 2026 Medium aicybersecurityvulnerability detection
threat-intel Axon Is Another License Plate Surveillance Company Municipalities are increasingly adopting license plate reader (LPR) technology, but switching from one vendor like Flock to another like Axon doesn't fundamentally improve privacy. Both systems collect extensive personal… Schneier on Security · Jul 28, 2026 Medium surveillanceprivacylpr
threat-intel Hacker Conversations: Tal Kollander’s Journey From Black Hat to Hack Blocker Tal Kollander, a former black hat hacker from Israel, has undergone a remarkable transformation, transitioning from exploiting systems to defending them. Growing up, she was a prolific hacker, motivated by curiosity and… SecurityWeek · Jul 28, 2026 High IShackingcybersecurityethical hacking
threat-intel Act Security Emerges from Stealth to Fight the Patch Problem Act Security, a Tel-Aviv-based cybersecurity firm founded by the team behind Medigate, has emerged from stealth with $60 million in funding to address the growing problem of excessive cloud access sprawl and the difficul… SecurityWeek · Jul 28, 2026 Medium IScloud securityaccess controlvulnerability management
threat-intel Hush Security Raises $30 Million for AI Agent Governance Hush Security, a cybersecurity startup, secured $30 million in Series A funding to bolster its AI agent governance platform. This platform aims to provide centralized control and security for AI agents within organizatio… SecurityWeek · Jul 28, 2026 Info aigovernancemachine access
threat-intel IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains This quarter, phishing, particularly QR code phishing leveraging trusted infrastructure, dominated initial access methods for attackers, with a significant increase in authentication abuse. The threat actor UAT-11764 con… Cisco Talos · Jul 28, 2026 High phishingauthenticationransomware
threat-intel Suitable AI : 15 176 comptes exposés via GraphQL A hacker claims to have breached Suitable AI, a recruitment platform utilizing AI, exposing data of 15,176 candidates and potentially compromising administrator accounts. The breach stemmed from vulnerabilities in Suitab… ZATAZ · Jul 28, 2026 Medium INUSgraphqlvulnerabilitydata breach
vulnerability Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock Arista Networks has patched a vulnerability in its VeloCloud software that was being actively exploited. The CISA (Cybersecurity and Infrastructure Security Agency) issued an advisory urging administrators to address the… The Register · Jul 28, 2026 High CVE-2026-16812patchvulnerabilitynetwork
threat-intel KomikoAI : une fuite relie courriels et prompts A leaked database attributed to KomikoAI, a Japanese AI-powered comic creation platform, is circulating online. The database allegedly contains over a million unique email addresses, user IDs, pseudonyms, profile picture… ZATAZ · Jul 28, 2026 High aipromptleak