vulnerability AVEVA Enterprise SCADA A critical vulnerability (CVE-2025-7639) has been identified in AVEVA Enterprise SCADA, allowing an authenticated attacker with specific privileges to tamper with serialized data and potentially execute code. This vulnerability affects multiple versions of AVEVA Enterprise SCADA and related products, including HMI, and… CISA Advisories · Aug 13, 2026 High CVE-2025-7639cve-2025-7639deserializationcode execution
vulnerability Schneider Electric IGSS Schneider Electric has identified and issued a security advisory (SEVD-2026-195-01) regarding a critical out-of-bounds write vulnerability in its IGSS Definition module for the IGSS (Interactive Graphical SCADA System) p… CISA Advisories · Jul 30, 2026 High CVE-2026-12927scadaindustrial control systemscwe-787
threat-intel DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts The DevMan ransomware-as-a-service (RaaS) operation has significantly upgraded its affiliate portal, transitioning from a chat-based system to a centralized platform for managing victims, payouts, and team operations. PR… The Hacker News · Jul 25, 2026 High USCISEransomwareraasdevman
threat-intel Hacker Conversations: Jesse McGraw (GhostExodus), From Blackhat Hacker to Redemption Jesse McGraw, once a notorious blackhat hacker known as GhostExodus and leader of the Electronik Tribulation Army (ETA), has undergone a dramatic transformation. Driven by a complex mix of factors including neurodiversit… SecurityWeek · Jul 13, 2026 High neurodiversityred-hatosint
vulnerability Frangoteam FUXA SCADA/HMI This advisory details a critical vulnerability in Frangoteam FUXA SCADA/HMI software versions up to 1.3.1, allowing unauthenticated remote attackers to enumerate user accounts and role assignments. The vulnerability stem… CISA Advisories · Jun 30, 2026 Critical CVE-2026-13207WOauthentication bypassscadahmi
threat-intel ScadaBR CISA has issued an advisory regarding critical vulnerabilities in ScadaBR version 1.2.0, a SCADA system. The vulnerabilities include missing authentication, OS command injection, and CSRF, potentially allowing unauthenti… CISA Advisories · May 19, 2026 Critical CVE-2026-8602CVE-2026-8603CVE-2026-8604scadavulnerabilityremote code execution