threat-intel All-Line Equipment Company Fuel-Boss A vulnerability exists in All-Line Equipment Company's Fuel-Boss industrial control system software, specifically versions up to and including PHP 7.1.5. Exploitation could allow remote code execution by injecting a malicious argument into the IMAP server name. While fixes are available for the Fuel-Boss V1 Standard an… CISA Advisories · 3d ago High CVE-2018-19518CVE-2019-11043industrial control systemscve-2018-19518cve-2019-11043
vulnerability Mitsubishi Electric CNC Series (Update A) A vulnerability (CWE-1285) exists in Mitsubishi Electric CNC Series (Update A) products, allowing a remote attacker to cause a denial-of-service by sending crafted packets to TCP port 683. This affects a wide range of CN… CISA Advisories · 3d ago Critical CVE-2025-2399cwe-1285cncindustrial control systems
threat-intel Threat landscape for industrial automation systems. Q2 2026 In Q2 2026, the percentage of ICS computers blocked by malicious objects continued to decline, hitting a low of 19.15%, the lowest since 2022. East Asia and Africa saw significant increases in threat percentages across… Securelist · 3d ago High RUCHAFicsindustrial automationcybersecurity
threat-intel Is Cyber Facing an Affordability Crisis? The cybersecurity industry is facing an ‘affordability crisis’ driven by rapidly rising breach costs and defense spending, disproportionately impacting small and medium-sized businesses (SMBs) who often lack the resource… Dark Reading · 5d ago High cybersecurityaffordabilitysmb
vulnerability Bendix EC80 Brake ECU A critical vulnerability exists in Bendix EC80 Brake ECU firmware, potentially allowing an attacker to disable ABS, steering assist, speedometer, and shifting capabilities, or inject malicious CAN bus traffic. Multiple f… CISA Advisories · 5d ago Critical CVE-2026-67560CVE-2026-68967CVE-2026-71396UNCAfirmwarebuffer overflowcan bus
threat-intel Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows The Mirage2FA campaign, a commercial phishing-as-a-service toolkit, has impacted approximately 4,532 organizations, primarily in the US, by exploiting legitimate Microsoft 365 login flows and bypassing two-factor authent… The Hacker News · 5d ago High USINSGphishingmicrosoftmfa
threat-intel ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More This week saw a surge in high-impact cyberattacks and vulnerabilities, highlighting the increasing sophistication and speed of threat actors. AI is now being weaponized to craft exploit scripts targeting Siemens PLCs, wh… The Hacker News · 6d ago High CVE-2026-19478CVE-2021-27101CVE-2023-34362UNRUvulnerabilitysupply-chainransomware
ransomware Gunra ransomware: what you need to know The Gunra ransomware gang is aggressively targeting organizations across multiple sectors, leveraging unpatched VPNs and firewalls to gain access and deploy their ransomware. They are demanding payments to decrypt stolen… Graham Cluley · 6d ago High vpnfirewallransomware
threat-intel Shipping More AI Code Than You Can Secure? Watch How to Control Remediation Debt AI coding tools are accelerating the influx of open-source packages into organizations’ software stacks, leading to a growing backlog of security vulnerabilities and remediation debt. A recent study of 300 enterprise le… The Hacker News · 6d ago Medium aiopen-sourcevulnerability
threat-intel How an Emerging Industrial Protocol Family Could Put OT at Risk A new research report from Nozomi Networks (acquired by Mitsubishi Electric) highlights a significant vulnerability within Time-Sensitive Networking (TSN) protocols, specifically CC-Link IE TSN, a widely deployed industr… Dark Reading · Aug 21, 2026 High tsnindustrial controlcybersecurity
threat-intel Identity Abuse Through Trusted Communication Channels Threat actors are increasingly leveraging trusted collaboration platforms – like Microsoft Teams and Slack – to conduct sophisticated identity phishing attacks. Instead of relying solely on traditional email phishing, at… Palo Alto Unit 42 · Aug 20, 2026 High PONOidentity phishingcollaboration platformssocial engineering
threat-intel NSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technology The NSA and FBI have issued an urgent warning about a growing threat where hackers are utilizing AI-generated exploit scripts to target critical infrastructure organizations, specifically focusing on Siemens S7 Series PL… The Record · Aug 19, 2026 High IRplccybersecurityai
threat-intel Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign The Cl0p ransomware group has publicly named over 40 organizations allegedly targeted in a campaign exploiting a vulnerability in PTC’s Windchill PLM platform. The group gained unauthorized access to sensitive data, incl… SecurityWeek · Aug 19, 2026 High CVE-2026-12569DEvulnerabilityransomwaredata breach
threat-intel 943 Patches Rolled Out With Oracle’s August 2026 Security Update Oracle released a massive update – 943 security patches – as part of its August 2026 Critical Security Patch Update, addressing over 1,000 unique vulnerabilities across numerous products. Many of these flaws, particularl… SecurityWeek · Aug 19, 2026 High patchingvulnerabilitiessecurity
threat-intel Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data A sophisticated, custom-built web shell, specifically designed for PTC Windchill and FlexPLM, has been deployed by the Clop ransomware gang. This web shell is capable of decrypting credentials, mapping sensitive data, an… The Hacker News · Aug 19, 2026 High CVE-2026-12569CVE-2021-27101CVE-2023-34362web shellcredential theftransomware
vulnerability Multiples vulnérabilités dans les produits Axis (19 août 2026) Multiple vulnerabilities have been discovered in Axis products, including remote code execution, privilege escalation, and denial-of-service attacks. These vulnerabilities affect various Axis products, requiring immediat… CERT-FR · Aug 19, 2026 High CVE-2026-4757CVE-2026-5303CVE-2026-5304vulnerabilityremote code executionprivilege escalation
vulnerability Multiples vulnérabilités dans Oracle Systems (19 août 2026) Multiple vulnerabilities have been discovered within Oracle Systems, potentially allowing attackers to compromise data confidentiality and integrity. These vulnerabilities affect several Oracle products and require immed… CERT-FR · Aug 19, 2026 High CVE-2026-60822CVE-2026-70737CVE-2026-70829oraclevulnerabilitypatch
threat-intel CISOs Break Their Silence in 'Declassified' Docuseries Red Mirror Studios, led by Danielle Lewan and Clint Howard II, is releasing an 11-episode docuseries titled "Declassified" featuring 11 cybersecurity CISOs sharing their real-world breach-response stories and personal st… Dark Reading · Aug 18, 2026 High cybersecuritycisosburnout
threat-intel AI-Driven Vulnerability Surge Breaks the Traditional Patching Model Rapid7’s analysis reveals a significant shift in the cybersecurity landscape driven by AI, leading to a dramatic increase in disclosed and exploited vulnerabilities. The traditional patching model is becoming obsolete du… SecurityWeek · Aug 18, 2026 High CHRUIRaivulnerabilitiespatching
threat-intel Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS Evooo1Bot, a Linux botnet derived from Mirai, has significantly expanded its capabilities beyond simple DDoS attacks. It now incorporates advanced features like encrypted C2 communications, SSH brute-force scanning, a re… Dark Reading · Aug 17, 2026 High CVE-2007-3010CVE-2016-6277CVE-2018-14558miraiddosbotnet