Search/bosch
Known CVEs
0
Highest CVSS
In KEV
0
Vendor
smart home
Connections
138 relationships
Ernst & Young Data Breach Affects Personal, Financial Information
Professional services giant Ernst & Young (EY) has started notifying its clients that their personal and financial information was compromised in a data breach. The incident was discovered on April 23 and involved a third-party service management platform that EY uses to support tax-related work it performs on behalf of its clients. “Support tickets submitted through the platform may include documents containing client tax information,” the company wrote in a notification letter sent to clients, a copy of which was filed (PDF) with the California Attorney General’s Office. After identifying anomalous activity on the platform, EY activated incident response and began remediation and recovery efforts. It also engaged an independent cybersecurity firm to investigate the nature and scope of the attack. The hackers, it says, had access to the compromised platform between March 28 and April 12, and downloaded documents of EY clients. Personal and financial information contained within those documents includes names, addresses, Social Security numbers, account numbers, credit/debit card numbers, and other types of information used to prepare tax filings, EY told the Texas AGO. The company says it is not aware of any misuse or further exposure of the affected clients’ personal information, but is providing them with two years of free credit monitoring, identity monitoring, and identity restoration services. EY has not shared details on how the attack occurred, nor on the threat actor responsible for it, and no known ransomware or extortion group appears to have claimed responsibility for the incident. SecurityWeek has emailed Ernst & Young for additional information on the data breach and will update this article if the company responds. Related: Hugging Face Hacked in Autonomous AI Attack Related: Synopsys Finds No Evidence of Data Breach Amid Bosch Hack Claims Related: Centers Laboratory Data Breach Affects 540,000 Individuals Related: 12 Million Impacted by Data Breach at Japanese Telco KDDI
securityweek.comJul 20, 2026extracted
Coca-Cola Suspends US Fairlife Production Due to Ransomware Attack
American soft drinks giant Coca-Cola announced Thursday that it has suspended production at its subsidiary Fairlife after detecting a ransomware attack. Based in Chicago, Fairlife is a Coca-Cola wholly owned dairy company that distributes ultra-filtered milk in five flavors: chocolate, fat-free, reduced fat, strawberry, and whole milk. In a July 16 filing with the US Securities and Exchange Commission (SEC), Coca-Cola said hackers had accessed a portion of Fairlife’s systems, including production-related systems. “After detecting the issue, the Company promptly activated its incident response and business continuity protocols. The Company’s investigation and assessment of the impact of the incident is ongoing, with the assistance of outside advisors and cybersecurity experts,” Coca-Cola said. The company told the SEC it has notified law enforcement of the attack and that it has yet to determine the full scope, nature, and impact of the incident. “Product quality and safety have not been impacted. However, as a result of the incident, production operations at Fairlife in the United States are temporarily suspended. Fairlife’s Canada production operations are not currently impacted,” the company said. Coca-Cola said it is scrambling to complete its investigation into the attack and to determine whether the incident will have any material impact. The company has not shared details on how the incident occurred, who was behind it, or whether it has received any extortion demands from the attackers. SecurityWeek has emailed Coca-Cola for additional information and will update this article if the company responds. SecurityWeek has not seen any known ransomware groups claim responsibility for the incident. Related: Synopsys Finds No Evidence of Data Breach Amid Bosch Hack Claims Related: Centers Laboratory Data Breach Affects 540,000 Individuals Related: 12 Million Impacted by Data Breach at Japanese Telco KDDI Related: Mount Royal University Confirms Data Stolen in Ransomware Attack
securityweek.comJul 17, 2026extracted
US Charges Russian Individuals and Firms for Running Cybercrime Services
The US Justice Department on Tuesday unsealed an indictment charging three Russian nationals and two companies for allegedly running cybercrime services. The individuals are Aleksandr Alexandrovich Volosovik, Kirill Andreevich Zatolokin, and Yulia Pankova, and the targeted companies are ML.Cloud and Media Land, whose infrastructure spanned countries such as China, the Netherlands, Finland, and even the United States. The three suspects are accused of running ML.Cloud and Media Land, which allegedly provided bulletproof hosting services to a wide range of threat actors, including profit-driven gangs and state-sponsored groups. [ Read: Synopsys Finds No Evidence of Data Breach Amid Bosch Hack Claims ] ML.Cloud and Media Land infrastructure was used for phishing, DDoS attacks, brute-force attacks, ransomware, and hosting cybercrime marketplaces and forums, according to the DOJ. Authorities said threat actors leveraged the two services to target at least 42 entities across 21 US states, overall causing tens of millions of dollars in losses. The indictment targeting Volosovik, Zatolokin, and Pankova was returned in December 2024, but it was only unsealed now. However, this is not the first time the names of the suspects and their companies have been made public. In late 2025, the United States and its allies announced sanctions against them, along with other individuals and companies tied to criminal activities. The US also announced on Tuesday that it’s offering a reward of up to $10 million and possible relocation for information on the ML.Cloud and Media Land operators. While it’s not common for Russian bulletproof hosting administrators to be sentenced to prison in the United States, it’s not unheard of either. Related: Russian Cybercrime Network Targeted for Sanctions Across US, UK and Australia Related: Third US Security Expert Sentenced to Prison for Helping Ransomware Gang
securityweek.comJul 15, 2026extracted
Synopsys Finds No Evidence of Data Breach Amid Bosch Hack Claims
Silicon-to-systems design firm Synopsys says it has found no evidence of a data breach after a cybercrime group claimed to have hacked its systems and gained access to valuable data belonging to one of its major customers, Bosch. A new ransomware group named D1R in recent days listed Synopsys and Bosch on its Tor-based leak website. The cybercriminals claimed to have exploited a vulnerability in Synopsys’ website to access a corporate client database containing 40,000 entries, and they are threatening to leak the stolen data unless a ransom is paid. Separately, D1R claimed to have hacked German engineering and technology giant Bosch using data obtained from Synopsys. The cybercriminals allegedly obtained valuable intellectual property belonging to Bosch. Synopsys specializes in electronic design automation software and pre-designed semiconductor blueprints used to build and test microchips. The company supplies the software tools and digital chip blueprints that Bosch’s engineering teams rely on to design electronic components for modern vehicles and industrial systems. However, Synopsys told SecurityWeek that it has found no evidence to support the hackers’ claims. “The security of data and systems is a priority for Synopsys,” the company said. “We are continuously monitoring our network and have found no evidence of Synopsys or customer technical data being subject to unauthorized access. We have not been contacted by this threat actor and, based on our investigation, claims of unauthorized access to customer confidential data are unfounded.” Indeed, a screenshot of a document the hackers posted to prove access to Bosch data appears to be from a user manual that is already in the public domain. It’s not uncommon for cybercriminals to leak fake data or exaggerate the scope of their hacks. When contacted by SecurityWeek, Bosch declined to answer specific questions about the incident, offering a standard boilerplate statement instead: Bosch places great importance on cybersecurity. As a globally networked industrial company, Bosch continuously strengthens the protection of its digital systems and expands its capabilities to respond quickly and in a coordinated manner to potential cyber incidents. The goal is to protect critical systems based on risk and limit the impact of potential attacks. In this way, cybersecurity makes a significant contribution to Bosch’s reliability, operational capability, and resilience. Related: Accenture Confirms Data Breach After Hacker Claims Source Code Theft Related: Centers Laboratory Data Breach Affects 540,000 Individuals Related: 12 Million Impacted by Data Breach at Japanese Telco KDDI
securityweek.comJul 14, 2026extracted
The hidden smart fridge risks that emerge years after purchase
The hidden smart fridge risks that emerge years after purchase Household refrigerators are built to last more than a decade. The software, cloud services, and mobile apps that control them are not. A new analysis from Erik Buchmann at Leipzig University maps what happens when those two timelines collide, and the findings reach further than the kitchen. The study examines three current models on the market: the Bosch KGN36HI32, the Samsung RF27T5501SG, and the LG GSX960NEAZ. Each adds network connectivity, mobile control, and in some cases cameras, voice assistants, and touchscreen apps to a core appliance whose mechanical components are expected to keep working for over ten years. IT architecture (Source: Research paper) Even basic cooling can depend on the cloud Even cooling can become a long-term risk when the appliance ships with a stripped-down control panel and routes temperature adjustments through a smartphone app and a vendor cloud account. The Samsung RF27T5501SG, for example, requires owners to install the SmartThings app and register for a Samsung cloud account to access many functions. If any link in that chain goes away, a working compressor and a working sensor array may still leave the owner with an appliance they can no longer configure as intended. A parallel case from earlier IoT history saw tens of thousands of internet radios stop working after a service provider shut down. Three families of long-term risk Buchmann groups the risks into compliance, economic, and operational categories. Compliance risks come from changes in law and regulation after purchase. Privacy rules can restrict where personal data flows, trade and sanctions regimes can cut off specific vendors or regions, and product categories can be reclassified entirely. Germany banned a children’s smart toy three years after launch once authorities determined it functioned as a covert listening device. Economic risks track the business decisions of the companies that keep the ecosystem running. Vendors can degrade older services to push customers toward newer products, switch to subscription pricing, discontinue a cloud platform, or go out of business and void existing warranties. Seven of the eight use cases identified in the study depend on services run by parties other than the owner. Operational risks accumulate through technical aging. Devices lose compatibility with newer phones and home networks, security updates stop arriving, and expertise and spare parts for older interfaces become hard to source. Protocols considered secure at purchase can be deprecated within a few years. The security cost of multimedia features Buchmann’s protection-needs analysis produces a finding that has practical consequences for anyone using a fridge as a smart-home hub. Because the appliance handles configuration data, credentials, and operating system updates, every other service it runs inherits the same elevated security requirement. Streaming music or browsing recipes on the door panel is therefore tied to the same protection level as the device’s most sensitive functions. A weakness in a casual feature can expose the rest. Thomas Uhlemann, Cybersecurity Evangelist at AV-Comparatives, told Help Net Security that the problem compounds once vendor updates stop. “As soon as a vendor stops shipping updates, the appliance freezes in time, but the threat landscape around it does not. Outdated TLS implementations, deprecated cipher suites, unpatched Wi-Fi stacks, hard-coded credentials in old firmware: all of these become permanent residents on the same LAN as everything else the household relies on.” In AV-Comparatives’ lab work, Uhlemann says two failure modes recur. “An appliance with a weak or unauthenticated local API, still common in older smart kitchen firmware, gives an attacker who has already gained a foothold elsewhere a stable pivot point. The fridge does not need to be the entry vector to be the problem; it only needs to be reachable.” The second is protocol decay, where a device keeps speaking to its cloud backend over TLS configurations that current browsers would reject, or advertising internal network topology through legacy services. The conclusion from the lab matches the conclusion from the paper. “The security posture of a home network is set by its weakest long-lived device,” Uhlemann says. A well-configured router and current endpoint protection raise the baseline, “but they cannot retroactively fix a device whose manufacturer has walked away from it.” It’s annoying, not catastrophic There’s some good news in here. For a regular household, none of the risks rise to the worst harm category in the analysis, things like serious illness from food poisoning or steep fines. The realistic worst cases are food that spoils, digital features that stop working for good, privacy exposure, and the appliance becoming an expensive paperweight. Buchmann adds that the math changes in higher-stakes settings, like a hospital using a connected fridge to store medication. The lesson extends beyond fridges Any consumer product that pairs long-lived hardware with software dependencies inherits the same structural problem. Smart televisions, connected ovens, networked thermostats, and home security panels all sit on the same fault line. The catalog of risks Buchmann assembles can be applied to any of them with minor adjustments to the asset inventory. Anyone shopping for a smart appliance has a new question to weigh at the store: what will it still do once its supporting ecosystem moves on? Bosch, LG and Samsung did not respond to a request for comment by the time of publication.
helpnetsecurity.comMay 12, 2026extracted
UE, meno limiti all’AI. Un successo per le industrie europee ma soprattutto per gli Usa
L’accordo, con il rinvio di oltre un anno di regole più stringenti per il digitale, rappresenta un importante successo diplomatico e geo-economico degli Usa. Niente restrizioni sugli usi ad alto rischio dell’AI in UE per almeno un altro anno, in base all’accordo che i legislatori comunitari hanno raggiunto giovedì mattina. Per la piena operatività dell’AI Act (Regolamento UE 2024/1689) bisognerà attendere. L’accordo, sottolinea POLITICO, “esenta inoltre in larga misura l’impiego dell’AI in ambito industriale dalla cornice normativa dello stesso Regolamento“. Fondamentali, in questo senso, sono state le forti pressioni delle Big Tech e di alcuni Governi nazionali, come quello tedesco che era stato il promotore della misura. Il Cancelliere tedesco Friedrich Merz che si è infatti battuto in prima persona per mantenere competitivi i colossi tecnologici Siemens e Bosch. Più che dei singoli Paesi europei, comunque, la decisione segna un importante successo diplomatico e geo-economico soprattutto degli Usa. Tra tutele per i cittadini e necessità di mercato L’AI Act (Regolamento UE 2024/1689) è entrato in vigore nell’agosto 2024 dopo anni di negoziati. In base all’introduzione graduale, “le norme che regolano gli usi ad alto rischio del’AI sarebbero dovute entrare in vigore il prossimo agosto“. Oltre a rinviare le restrizioni sull’AI ad alto rischio a dicembre 2027, l’accordo concede alle aziende un periodo di grazia “per soddisfare i nuovi requisiti relativi ai watermark dei contenuti generati dall’AI“. Tuttavia, “tale periodo sarà di tre mesi e non di sei, come si era originariamente proposto“. Divieti anche sull’AI in grado di generare deepfake a sfondo sessuale di persone “identificabili”, a seguito dell’indignazione globale per l’uso abusivo dello strumento dell’AI di Elon Musk, Grok. Saranno vietati anche i sistemi di intelligenza artificiale che generano pornografia infantile. Tuttavia, poiché solo un paio di Paesi in tutto il mondo hanno seguito l’esempio dell’UE, queste limitazioni hanno ricevuto grandi critiche. In primo luogo “per aver bloccato gli sviluppi dell’AI” e per non essere riuscite a diventare un punto di riferimento in materia di norme tecnologiche. L’importanza dell’accordo L’ultimo accordo, sotto l’egida della presidenza cipriota del Consiglio dell’UE, segna il primo significativo passo indietro delle norme nel settore digitale. Il tutto, mentre Bruxelles deve affrontare le pressioni degli Usa. Continuano, inoltre, gli avvertimenti provenienti dalle industrie e dagli stessi Governi europei secondo cui le rigide restrizioni avrebbero legittimato uno svantaggio nella corsa globale all’AI. Al contempo, la società civile e gli attivisti per la privacy, continuano a sostenere che delle regole simili siano necessarie per proteggere le persone dai potenziali danni della tecnologia emergente. Ursula von der Leyen: “Per una governance europea dell’AI sicura e semplice“ Anche il Presidente della Commissione Ursula von der Leyen ha accolto favorevolmente l’accordo, sottolineando gli sviluppi potenziali del mercato. Così von der Leyen sul suo profilo X: “Accolgo con favore l’accordo politico raggiunto sul nostro pacchetto normativo per l’AI. Garantisce un contesto semplice e favorevole all’innovazione, che consentirà al nostro ecosistema europeo di crescere. Allo stesso tempo, stiamo rafforzando le misure di tutela a favore dei nostri cittadini. Per una governance dell’AI sicura e semplice in Europa“. Per approfondire Leggi il Regolamento (UE) 2024/1689 in PDF.
cybersecitalia.itMay 7, 2026extracted
Pneumatici cyber di Pirelli, il Governo protegge ancora di più la tecnologia italiana e i dati che possono raccogliere. Gli azionisti cinesi contrari al nuovo Golden Power
Come funzionano i Cyber Tyres? Quali dati possono o non possono raccogliere gli Pneumatici cyber di Pirelli e dove sono custoditi? I limiti imposti dal nuovo decreto Golden Power, che ribadisce al Gruppo italiano il divieto di condivisione di questi dati al primo socio, che è cinese. Pirelli potrà continuare a vendere i suoi pneumatici cyber negli Stati Uniti, la cui commercializzazione era a rischio a causa della norma, voluta da Biden e poi applicata da Trump, sull’importazione e la vendita di veicoli connessi che utilizzano software e hardware di società con un “collegamento sufficiente” con la Cina o la Russia. Questo è uno dei primi effetti del nuovo Decreto del Presidente del Consiglio dei Ministri (DPCM) in ambito Golden Power. Questo DPCM ha, quindi, un impatto positivo a livello commerciale per Pirelli, ma ha anche una rilevanza nazionale perché il Governo rafforza la protezione sulla tecnologia, realizzata dal Gruppo italiano Pirelli, alla base di questi tipi di pneumatici, chiamati cyber tyres. Già nel 2023 l’esecutivo guidato da Meloni aveva fatto scattare il Golden Power su questi pneumatici smart per evitare che finissero in mano ai cinesi, in quanto il primo socio, con il 34,1% dell’azionariato del Gruppo Pirelli, è il Gruppo cinese Sinochem. Le nuove restrizioni Golden Power cambiano la Governance di Pirelli, il socio cinese valuta azioni legali Il DPCM ha soprattutto effetti societari, perché limita ancora di più i poteri del primo socio cinese, limitando a tre, di cui due indipendenti, il numero di consiglieri che Sinochem può nominare e questi 3 consiglieri non possono ricoprire la carica di Presidente, Vicepresidente e Amministratore Delegato. Ma questa prescrizione del Governo non varrà sempre, saranno revocate se il socio cinese scenderà sotto il 10%. A queste nuove restrizioni di governance il Gruppo cinese non ci sta “sono discriminatorie e avranno inevitabilmente un impatto negativo sul clima degli investimenti in Italia “e valuta azioni legali “a tutela dei propri legittimi diritti e interessi in qualità di azionista“. Pneumatici cyber di Pirelli, il focus di Cybersecurity Italia In attesa di conoscere le eventuali vicende legali, Cybersecurity Italia è in grado di descrivere le caratteristiche tecniche dei cyber tyres. Come già detto, il Governo italiano considerata strategica e utile la tecnologia a sensori che caratterizza questi pneumatici, unici sul mercato. Ma come funzionano? Il sistema hardware e software Pirelli Cyber Tyre si basa su un sensore di circa 12 grammi posto nella parte interna del battistrada dello pneumatico, capace di fornire informazioni uniche. A partire dalla “carta d’identità” dello pneumatico stesso, oltre a temperatura, pressione di gonfiaggio e anche i dati legati allo stato dell’asfalto e delle strade nonché sulle abitudini degli utenti e le condizioni di guida. Tramite una connessione Bluetooth i dati sono trasferiti in vettura, dove un software Pirelli li elabora in tempo reale, generando algoritmi che alimentano diverse funzionalità del veicolo. Grazie a un accordo di sviluppo congiunto firmato con Bosch, i dati vengono utilizzati per far funzionare in modo ottimale sistemi come controllo di trazione, ABS, ESP. Facciamo un esempio: in caso di aquaplaning, lo pneumatico può modificare il comportamento dell’autovettura, perché comunicando con la centralina dell’auto modica la velocità del veicolo. Quali dati non possono raccogliere gli Pneumatici cyber di Pirelli? I limiti imposti dal decreto Golden Power Oltre ai dati sullo stato delle gomme, dell’asfalto e delle strade, il super sensore di 12 grammi, posto nella parte interna del battistrada degli pneumatici, è in grado di raccogliere anche dati esterni al veicolo mentre è in transito, dati che possono essere sensibili e strategici. Su questi dati c’è lo stop del Governo. Questi dati non possono essere raccolti dai cyber tyres. Questo è un altro degli effetti chiave dei due DPCM su Pirelli e in particolare su questa tecnologia. Il Governo riconosce sia l’utilità di questa tecnologia, ma è consapevole anche dei rischi qualora dovesse finire nelle mani sbagliate, per questi motivi ha voluto maggiormente proteggerla con il Golden Power e in particolare con questo nuovo DPCM, resosi necessario dalla volontà dell’azionista Camfin, che fa capo al vicepresidente esecutivo di Pirelli, Marco Tronchetti Provera, di non rinnovare il patto parasociale con i soci cinesi. Chi gestisce i dati dei Cyber Tyres? Pirelli, con il divieto di condivisione con il socio cinese Tutti i dati raccolti dai cyber Tyres sono gestiti da Pirelli, che ha l’headquarter, nonché la R&D, a Milano. Resta tutto qui. Con il divieto, previsto proprio dai DPCM Golden Power, di condividere questi dati con i soci cinesi. Le collaborazioni con l’Autostrade per l’Italia per il monitoraggio del manto stradale e con Regione Puglia per creare una mappa dello “stato di salute” delle strade Infine, in relazione alla tecnologia Cyber Tyre, il DPCM Golden Power ha, altresì, considerato che la stessa si è evoluta nel tempo al punto di poter essere considerata una tecnologia abilitante per diversi scenari d’impiego all’avanguardia, tra cui il monitoraggio di infrastrutture critiche, la simulazione avanzata tramite realizzazione della versione digitale di elementi fisici (digital twin, elaborato mediante sistemi di super-calcolo), la guida autonoma. Per esempio, in Italia proseguono le collaborazioni con Movyon, società del gruppo Autostrade per l’Italia, per il monitoraggio del manto stradale, nonché quella con la Regione Puglia dove è stato attivato un sistema di monitoraggio della rete viaria nel territorio regionale con lo scopo di creare una mappa dello “stato di salute” delle strade. In quest’ultimo caso, peraltro, il sistema Cyber Tyre integra i dati provenienti dagli pneumatici con altri raccolti attraverso telecamere installate nei veicoli.
cybersecitalia.itApr 15, 2026extracted
Calcolo quantistico: caratteristiche, servizi cloud e applicazioni emergenti
Il calcolo quantistico non rappresenta una semplice evoluzione che incrementa la potenza di calcolo degli elaboratori, ma una vera e propria discontinuità paradigmatica rispetto al modello computazionale classico basato sulla logica binaria dei bit. Un computer quantistico sfrutta i principi controintuitivi della meccanica quantistica, in particolare i fenomeni di sovrapposizione e di intreccio quantistico, per eseguire calcoli che vanno oltre le capacità dei sistemi di calcolo ad alte prestazioni (HPC) più potenti. Attualmente, la tecnologia si trova nell’era del “Noisy Intermediate-Scale Quantum” (NISQ), un termine coniato per descrivere lo stato dell’arte dei sistemi caratterizzati da un numero limitato di qubit, rumore intrinseco, tassi di errore non trascurabili e una scalabilità ancora ridotta (Preskill, 2018). Ecco le caratteristiche fondamentali della tecnologia, il ruolo abilitante del modello Quantum Computing as a Service (QCaaS) e dei principali casi d’uso emergenti. Indice degli argomenti Per apprezzare appieno il potenziale e i limiti del calcolo quantistico, è necessario avere una conoscenza approfondita dei principi fisici e delle architetture hardware su cui si basa. In questa sezione verranno analizzati i concetti di base, verranno messe a confronto le diverse tecnologie impiegate per la realizzazione dei qubit, le unità fondamentali dell’informazione quantistica, e verranno illustrate le sfide tecnologiche dell’era attuale. Successivamente, verranno discussi i principi fondamentali su cui si basa questa rivoluzione computazionale. L’operatività di un computer quantistico si basa su tre concetti chiave derivati dalla meccanica quantistica, le cui definizioni sono state elaborate da Varsamis et al. (2025): Qubit: il qubit (quantum bit) è l’unità di base dell’informazione quantistica. A differenza del bit classico, che può assumere solo i valori 0 o 1, il qubit può esistere in una sovrapposizione coerente di entrambi gli stati, rappresentando un continuum infinito di valori intermedi. Sovrapposizione (Superposition): questo fenomeno quantistico consente a un qubit di esistere simultaneamente in più stati. Un registro di N qubit può quindi rappresentare contemporaneamente 2^N stati, una capacità che cresce esponenzialmente e che costituisce la base del potenziale parallelo del calcolo quantistico. Entanglement: è una forma di correlazione quantistica in cui gli stati di due o più qubit diventano intrinsecamente interdipendenti. Quando i qubit sono “entangled”, la misurazione di uno di essi influenza istantaneamente lo stato degli altri, a prescindere dalla loro distanza. Questa interconnessione non locale è una risorsa essenziale per l’esecuzione di complessi algoritmi quantistici. La realizzazione fisica di qubit stabili e controllabili rappresenta una delle sfide ingegneristiche più complesse. Sono in fase di sviluppo diverse tecnologie, ognuna con i propri vantaggi e svantaggi specifici. La tabella seguente mette a confronto le principali piattaforme hardware, basandosi sull’analisi condotta da Varsamis et al. (2025). Per superare i limiti di scalabilità dei singoli processori quantistici (QPU), sono stati proposti modelli di architettura distribuita. Basandosi sulle definizioni fornite da Gyongyosi e Imre (2025), è possibile distinguere tre approcci principali: Multichip: all’interno di una singola unità di elaborazione quantistica (QPU) sono contenuti più circuiti quantistici (QC) di piccole dimensioni. Questo modello favorisce la modularità e l’integrazione su piccola scala, ma la comunicazione quantistica tra i circuiti dipende dall’implementazione fisica, limitando la coesione del sistema. Distribuzione del circuito (Circuit Distribution): un grande circuito quantistico viene distribuito su più QPU. Ogni nodo esegue un sottocircuito e la comunicazione quantistica tra i nodi è disponibile. Questo è il paradigma più potente per l’esecuzione di algoritmi monolitici complessi, ma richiede una rete quantistica a bassa latenza e alta fedeltà, una sfida tecnologica ancora aperta. Scomposizione del circuito (Circuit Splitting): un grande circuito viene suddiviso tra più QPU, ma in questo modello non è disponibile la comunicazione quantistica tra di essi. L’interazione si basa esclusivamente su canali classici, il che limita questo approccio ai problemi la cui soluzione può essere ricostruita tramite post-elaborazione classica. L’era NISQ (Noisy Intermediate-Scale Quantum), in cui ci troviamo attualmente, è caratterizzata da una serie di sfide tecnologiche che limitano le prestazioni dei computer quantistici. I sistemi sono soggetti a elevati livelli di rumore e di errore che degradano la qualità dei calcoli. Nonostante i progressi nel controllo dei qubit siano stati rapidi, il tasso di errore dei gate (ε), ovvero la probabilità che un’operazione fallisca, si attesta oggi nell’ordine di ε ≈ 0,01, con un miglioramento di circa due ordini di grandezza negli ultimi anni (Gyongyosi e Imre, 2025). La coerenza, ovvero la capacità di un qubit di mantenere il proprio stato quantistico, è fragile e di breve durata, il che rende difficile l’esecuzione di algoritmi lunghi e complessi. La scalabilità rappresenta ancora un ostacolo significativo: aumentare il numero di qubit mantenendo bassi tassi di errore e un’elevata connettività rappresenta una sfida ingegneristica eccezionale. Infine, la mancanza di tecniche di correzione degli errori quantistici pienamente efficaci ostacola il raggiungimento della computazione fault-tolerant, requisito essenziale per sbloccare il pieno potenziale della tecnologia. Nonostante queste barriere, il modello di servizio cloud (QCaaS) sta contribuendo a superare alcune di queste sfide, rendendo la tecnologia più accessibile a ricercatori e sviluppatori. Il modello “as a service”, mutuato dal cloud computing tradizionale, sta diventando il veicolo fondamentale per democratizzare l’accesso alle risorse di calcolo quantistico. Considerata l’estrema complessità e il costo proibitivo della costruzione e della manutenzione di un computer quantistico, solo poche organizzazioni possono permettersi di possederne uno. Il QCaaS supera questa barriera, offrendo l’accesso remoto a hardware e simulatori all’avanguardia. In questa sezione, esamineremo la definizione di QCaaS, i suoi vantaggi strategici, le principali piattaforme e i principi di ingegneria del software che ne guidano lo sviluppo. Il Quantum Computing as a Service (QCaaS) è un modello che consente agli utenti di accedere a hardware e simulatori quantistici tramite il cloud, senza dover possedere o gestire l’infrastruttura fisica sottostante (Romero-Álvarez et al., 2023). Questo modello offre vantaggi strategici per l’adozione e lo sviluppo della tecnologia quantistica: Accessibilità e abbattimento dei costi: il QCaaS rende il calcolo quantistico accessibile a una vasta comunità di ricercatori, sviluppatori e aziende. Trasforma il costo iniziale elevato per la produzione e la manutenzione dell’hardware in un modello a costo operativo (OPEX), spesso basato su un modello di pagamento per singola esecuzione del circuito (pay-per-shot) (Ahmad et al., 2024). Astrazione della complessità hardware: le piattaforme QCaaS forniscono interfacce e kit di sviluppo software (SDK) che riducono la complessità dei diversi backend hardware. Ciò consente agli sviluppatori di concentrarsi sulla progettazione di algoritmi e applicazioni senza doversi occupare dei dettagli fisici a basso livello del dispositivo. Abilitazione di sistemi ibridi quantistico-classici: il QCaaS rappresenta il pilastro fondamentale per lo sviluppo di applicazioni ibride. In questi sistemi, i moduli classici si occupano del pre-processing e del post-processing dei dati e dell’orchestrazione del flusso di lavoro, mentre i moduli quantistici eseguono i calcoli computazionalmente intensivi per i quali offrono un potenziale vantaggio (Uphues et al., 2025). I principali giganti del cloud computing e le startup specializzate offrono piattaforme QCaaS che forniscono l’accesso a un’ampia gamma di tecnologie quantistiche: Amazon Web Services (AWS): la sua piattaforma, Amazon Braket, funge da aggregatore, fornendo l’accesso all’hardware di terze parti, come i processori a ioni intrappolati di IonQ, i sistemi superconduttori di Rigetti e OQC e i computer ad atomi neutri di QuEra (Golec et al., 2024). IBM: offre l’accesso ai propri processori quantistici basati su tecnologia superconduttrice tramite IBM Quantum e IBM Cloud. IBM è stata pioniera nell’offrire al pubblico l’accesso ai propri dispositivi, con una roadmap di sviluppo hardware in continua evoluzione (Gyongyosi & Imre, 2025). Microsoft: la piattaforma Azure Quantum offre un ecosistema aperto che integra hardware di vari partner, consentendo agli utenti di scegliere il processore più adatto al loro problema specifico. Google: attraverso Google Quantum AI, offre l’accesso ai suoi processori superconduttori all’avanguardia, come quelli utilizzati per dimostrare il “quantum advantage”. L’ingegneria del software quantistico (QSE) è definita come l’applicazione sistematica dei principi e delle pratiche dell’ingegneria del software allo sviluppo del software quantistico, adattandoli agli ambienti ibridi classico-quantistici (Ahmad et al., 2024). Nel contesto del QCaaS, la QSE è fondamentale per sviluppare applicazioni robuste, scalabili e manutenibili. Pattern architetturali: l’adozione di pattern come il Quantum-Classic Split non è una semplice scelta stilistica, ma una necessità strategica imposta dall’era NISQ. Questo modello consente di isolare le computazioni quantistiche, intrinsecamente rumorose e a bassa coerenza, delegando la logica di controllo, la gestione dei dati e la mitigazione degli errori a componenti classiche robuste e scalabili. Altri pattern, come API Gateway e Service Composition, sono essenziali per costruire sistemi modulari e interoperabili. Software Development Kit (SDK): gli SDK sono strumenti essenziali che permettono agli sviluppatori di interagire con le piattaforme QCaaS. I principali SDK, come Qiskit (IBM), Cirq (Google) e Amazon Braket SDK, forniscono librerie e interfacce di programmazione (solitamente in Python) che permettono di progettare circuiti quantistici, simulare il loro comportamento ed eseguirli su hardware reale. L’infrastruttura QCaaS, unita a solidi principi di QSE, sta abilitando lo sviluppo di applicazioni concrete in diversi ambiti, come verrà approfondito nella prossima sezione. A differenza dei computer classici, progettati come macchine universali, i computer quantistici offrono un vantaggio computazionale solo per determinate classi di problemi. Il loro potere risiede nella capacità di esplorare ampi e complessi spazi di soluzioni in modo efficiente. Questa sezione illustra quattro domini applicativi in cui il calcolo quantistico promette di avere un impatto significativo, basandosi su esempi concreti tratti dalla letteratura scientifica. Molti problemi di ottimizzazione in settori quali la logistica, la finanza e la pianificazione operativa (come il problema della programmazione dei turni del personale infermieristico) sono classificati come NP-hard, il che significa che la loro complessità computazionale cresce esponenzialmente con l’aumentare delle dimensioni del problema, rendendoli intrattabili per i computer tradizionali (Uphues et al., 2025). Algoritmi quantistici come il Quantum Approximate Optimization Algorithm (QAOA) e il quantum annealing sono progettati specificamente per esplorare lo spazio delle possibili soluzioni di questi problemi e trovare configurazioni ottimali in modo più efficiente (Varsamis et al., 2025). La simulazione di sistemi quantistici, come molecole o materiali complessi, è stata l’idea originale di Richard Feynman, che ha dato il via a questo campo di applicazione. I computer classici faticano a simulare la natura a livello quantistico a causa della crescita esponenziale delle risorse richieste. I computer quantistici, essendo essi stessi sistemi quantistici, sono intrinsecamente adatti a questo compito (Daley et al., 2022). Ciò ha implicazioni rivoluzionarie in vari campi, quali la chimica quantistica (per il calcolo della struttura elettronica e dell’energia dello stato fondamentale delle molecole), la scienza dei materiali (per la progettazione di nuovi materiali con proprietà desiderate) e la scoperta di farmaci. In questi ambiti, gli algoritmi quantistici possono accelerare processi quali lo studio del ripiegamento delle proteine (protein folding) e il legame molecolare (molecular docking) (ADAC Quantum Computing Working Group, 2025). In questo ambito, algoritmi come il Variational Quantum Eigensolver (VQE) rivestono un ruolo centrale (Varsamis et al., 2025). Il calcolo quantistico rappresenta una minaccia esistenziale per molti degli attuali standard di crittografia a chiave pubblica. Se venisse eseguito su un computer quantistico sufficientemente potente, l’algoritmo di Shor potrebbe fattorizzare grandi numeri interi in tempo polinomiale, un’impresa ritenuta intrattabile per i computer classici. Ciò renderebbe vulnerabili gli schemi crittografici ampiamente utilizzati, come RSA, la cui sicurezza si basa proprio sulla difficoltà di fattorizzazione (Varsamis et al., 2025). Per rispondere a questa minaccia, è nato il campo della crittografia post-quantistica (PQC), che si occupa dello sviluppo di nuovi algoritmi crittografici in grado di resistere agli attacchi sia dei computer classici sia di quelli quantistici (ADAC Quantum Computing Working Group, 2025). Il Quantum Machine Learning (QML) è un campo interdisciplinare che esplora il modo in cui i principi quantistici possano potenziare gli algoritmi di machine learning. I modelli QML, come le reti neurali quantistiche (QNN), operano in spazi di feature di elevatissima dimensionalità (spazi di Hilbert), offrendo il potenziale per identificare pattern nei dati inaccessibili ai modelli classici. Attualmente, le applicazioni si concentrano su flussi di lavoro ibridi in cui i computer quantistici vengono utilizzati come acceleratori per compiti specifici quali l’addestramento dei modelli, l’ottimizzazione degli iperparametri e l’inferenza (Chen et al., 2024). I classificatori quantistici variazionali, per esempio, sono un’area di ricerca che combina circuiti quantistici parametrici e tecniche di ottimizzazione classiche (Sharma et al., 2025). Il calcolo quantistico è una tecnologia dirompente che non mira a sostituire i computer tradizionali, ma a fungere da acceleratore specializzato per la risoluzione di problemi specifici che i sistemi convenzionali non sono in grado di affrontare in tempi ragionevoli. Il futuro della computazione ad alte prestazioni risiede nelle architetture ibride che integrano in modo sinergico le risorse di calcolo classico (HPC) e quantistico. In questo scenario, il paradigma del Quantum Computing as a Service (QCaaS) riveste un ruolo fondamentale, democratizzando l’accesso a hardware costosi e complessi e abbassando la soglia d’ingresso per l’innovazione e la ricerca. Tuttavia, il percorso verso il calcolo quantistico su larga scala è ancora costellato di sfide interconnesse che devono essere affrontate in modo sistematico. Il raggiungimento della tolleranza agli errori (fault-tolerance) è il Santo Graal della ricerca hardware ed è un requisito fondamentale per eseguire in modo affidabile algoritmi complessi. Parallelamente, è fondamentale colmare il divario di competenze sviluppando una forza lavoro qualificata in grado di operare all’intersezione tra fisica quantistica, informatica e ingegneria del software (ADAC Quantum Computing Working Group, 2025). Infine, per superare l’attuale frammentazione dell’ecosistema, sarà necessaria una maggiore standardizzazione delle API e dei protocolli. La standardizzazione non solo favorirà l’interoperabilità e la portabilità delle applicazioni su diverse piattaforme (Garcia-Alonso et al., 2025), ma sarà anche un prerequisito per semplificare lo sviluppo di materiali didattici e abbassare la soglia d’ingresso per i nuovi ricercatori. Solo affrontando congiuntamente questi tre pilastri – hardware, persone e standard – sarà possibile passare dall’era sperimentale del NISQ a quella del robusto vantaggio quantistico resistente agli errori. ADAC Quantum Computing Working Group. (2025). The Role of Quantum Computing in Advancing Scientific High-Performance Computing: A perspective from the ADAC Institute. arXiv preprint arXiv:2505.13284. Ahmad, A., Altamimi, A. B., & Aqib, J. (2024). Quantum Computing as a Service – a Software Engineering Perspective. arXiv preprint arXiv:2404.05318. Chen, K.-C., Li, X., Xu, X., Wang, Y.-Y., & Liu, C.-Y. (2024). Multi-gpu-enabled hybrid quantum-classical workflow in quantum-hpc middleware: Applications in quantum simulations. arXiv preprint arXiv:2403.05828. Daley, A. J., Bloch, I., Kokail, C., Flannigan, S., Pearson, N., Troyer, M., & Zoller, P. (2022). Practical quantum advantage in quantum simulation. Nature, 607(7920), 667–676. Garcia-Alonso, J., et al. (2025). Rethinking Services in the Quantum Age: The SOQ Paradigm. arXiv preprint arXiv:2510.03817. Golec, M., Hatay, E. S., Golec, M., Uyar, M., Golec, M., & Gill, S. S. (2024). Quantum cloud computing: Trends and challenges. Journal of Economy and Technology, 2, 190–199. Gyongyosi, L., & Imre, S. (2025). Networked Quantum Services. arXiv preprint arXiv:2505.23074. Preskill, J. (2018). Quantum Computing in the NISQ era and beyond. Quantum, 2, 79. Rietsche, R., Dremel, C., Bosch, S., Steinacker, L., Meckel, M., & Leimeister, J.-M. (2022). Quantum computing. Electronic Markets, 32(4), 2525–2536. Romero-Álvarez, J., et al. (2023). Quantum Microservices Development and Deployment. arXiv preprint arXiv:2309.11926. Sharma, H., et al. (2025). When Federated Learning Meets Quantum Computing: Survey and Research Opportunities. arXiv preprint arXiv:2411.08272. Uphues, M., Thöne, S., & Kuchen, H. (2025). A Reference Architecture for Embedding Quantum Software into Enterprise Systems. arXiv preprint arXiv:2505.07166. Varsamis, G. D., et al. (2025). Interfacing Quantum Computing Systems with High- Performance Computing Systems: An overview. arXiv preprint arXiv:2505.08051.
cybersecurity360.itApr 9, 2026extracted
Dozens of Vendors Patch Security Flaws Across Enterprise Software and Network Devices
SAP has released security updates to address two critical security flaws that could be exploited to achieve arbitrary code execution on affected systems. The vulnerabilities in question listed below - CVE-2019-17571 (CVSS score: 9.8) - A code injection vulnerability in SAP Quotation Management Insurance application (FS-QUO) CVE-2026-27685 (CVSS score: 9.1) - An insecure deserialization vulnerability in SAP NetWeaver Enterprise Portal Administration "The application uses an outdated artifact of Apache Log4j 1.2.17 that is vulnerable to CVE-2019-17571," SAP security company Onapsis said. "It allows an unprivileged attacker to execute arbitrary code remotely on the server, causing high impact on confidentiality, integrity, and availability of the application." CVE-2026-27685, on the other hand, stems from missing or insufficient validation during the deserialization of uploaded content, which could allow an attacker to upload untrusted or malicious content. "Only the fact that an attacker requires high privileges for a successful exploit prevents the vulnerability from being tagged with a CVSS score of 10," Onapsis added. The disclosure comes as Microsoft shipped patches for 84 vulnerabilities across products, including dozens of privilege escalation and remote code execution flaws. On Tuesday, Adobe also announced patches for 80 vulnerabilities, four of which are critical flaws impacting Adobe Commerce and Magento Open Source that could result in privilege escalation and security feature bypass. Separately, it fixed five critical vulnerabilities in Adobe Illustrator that could pave the way for arbitrary code execution. Elsewhere, Hewlett Packard Enterprise put out fixes for five shortcomings in Aruba Networking AOS-CX. The most severe of the flaws is CVE-2026-23813 (CVSS score: 9.8), an authentication bypass affecting the management interface. "A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls," HPE said. "In some cases, this could enable resetting the admin password." "Exploitation of this Aruba vulnerability potentially gives attackers full control of AOS-CX network devices and the ability to compromise an entire system undetected," Ross Filipek, CISO at Corsica Technologies, said in a statement. "A successful compromise could lead to the disruption of network communications or the erosion of the integrity of key business services. This flaw is a reminder that vulnerabilities in network devices are becoming more common in today's hyper-connected world. When attackers gain privileged access to these devices, it puts organizations at significant risk." Software Patches from Other Vendors Security updates have also been released by other vendors over the past few weeks to rectify several vulnerabilities, including — ABB Amazon Web Services AMD Arm Atlassian Bosch Broadcom (including VMware) Canon Cisco Commvault Dassault Systèmes Dell Devolutions Drupal Elastic F5 Fortinet Fortra Foxit Software GitLab Google Android and Pixel Google Chrome Google Cloud Google Pixel Watch Google Wear OS Grafana Hitachi Energy Honeywell HP HP Enterprise (including Aruba Networking and Juniper Networks) IBM Intel Ivanti Jenkins Lenovo Linux distributions AlmaLinux, Alpine Linux, Amazon Linux, Arch Linux, Debian, Gentoo, Oracle Linux, Mageia, Red Hat, Rocky Linux, SUSE, and Ubuntu MediaTek Mitsubishi Electric Moxa Mozilla Firefox, Firefox ESR, and Thunderbird n8n NVIDIA Palo Alto Networks QNAP Qualcomm Ricoh Samsung Schneider Electric ServiceNow Siemens SolarWinds Splunk Synology TP-Link Trend Micro WatchGuard Western Digital Zoom, and Zyxel
thehackernews.comMar 11, 2026extracted
Microsoft Issues Security Fixes for 56 Flaws, Including Active Exploit and Two Zero-Days
Microsoft closed out 2025 with patches for 56 security flaws in various products across the Windows platform, including one vulnerability that has been actively exploited in the wild. Of the 56 flaws, three are rated Critical, and 53 are rated Important in severity. Two other defects are listed as publicly known at the time of the release. These include 29 privilege escalation, 18 remote code execution, four information disclosure, three denial-of-service, and two spoofing vulnerabilities. In total, Microsoft has addressed a total of 1,275 CVEs in 2025, according to data compiled by Fortra. Tenable's Satnam Narang said 2025 also marks the second consecutive year where the Windows maker has patched over 1,000 CVEs. It's the third time it has done so since Patch Tuesday's inception. The update is in addition to 17 shortcomings the tech giant patched in its Chromium-based Edge browser since the release of the November 2025 Patch Tuesday update. This also consists of a spoofing vulnerability in Edge for iOS (CVE-2025-62223, CVSS score: 4.3). The vulnerability that has come under active exploitation is CVE-2025-62221 (CVSS score: 7.8), a use-after-free in Windows Cloud Files Mini Filter Driver that could allow an authorized attacker to elevate privileges locally and obtain SYSTEM permissions. "File system filter drivers, aka minifilters, attach to the system software stack, and intercept requests targeted at a file system, and extend or replace the functionality provided by the original target," Adam Barnett, lead software engineer at Rapid7, said in a statement. "Typical use cases include data encryption, automated backup, on-the-fly compression, and cloud storage." "The Cloud Files minifilter is used by OneDrive, Google Drive, iCloud, and others, although as a core Windows component, it would still be present on a system where none of those apps were installed." It's currently not known how the vulnerability is being abused in the wild and in what context, but successful exploitation requires an attacker to obtain access to a susceptible system through some other means. Microsoft Threat Intelligence Center (MSTIC) and Microsoft Security Response Center (MSRC) have been credited with discovering and reporting the flaw. According to Mike Walters, president and co-founder of Action1, a threat actor could gain low-privileged access through methods like phishing, web browser exploits, or another known remote code execution flaw, and then chain it with CVE-2025-62221 to seize control of the host. Armed with this access, the attacker could deploy kernel components or abuse signed drivers to evade defenses and maintain persistence, and can be weaponized to achieve a domain-wide compromise when coupled with credential theft scenarios. The exploitation of CVE-2025-62221 has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add it to the Known Exploited Vulnerabilities (KEV) catalog, mandating Federal Civilian Executive Branch (FCEB) agencies to apply the patch by December 30, 2025. The remaining two zero-days are listed below - CVE-2025-54100 (CVSS score: 7.8) - A command injection vulnerability in Windows PowerShell that allows an unauthorized attacker to execute code locally CVE-2025-64671 (CVSS score: 8.4) - A command injection vulnerability in GitHub Copilot for JetBrains that allows an unauthorized attacker to execute code locally "This is a command injection flaw in how Windows PowerShell processes web content," Action1's Alex Vovk said about CVE-2025-54100. "It lets an unauthenticated attacker execute arbitrary code in the security context of a user who runs a crafted PowerShell command, such as Invoke-WebRequest." "The threat becomes significant when this vulnerability is combined with common attack patterns. For example, an attacker can use social engineering to persuade a user or admin to run a PowerShell snippet using Invoke-WebRequest, allowing a remote server to return crafted content that triggers the parsing flaw and leads to code execution and implant deployment." It's worth noting that CVE-2025-64671 comes in the wake of a broader set of security vulnerabilities collectively named IDEsaster that was recently disclosed by security researcher Ari Marzouk. The issues arise as a result of adding agentic capabilities to an integrated development environment (IDE), exposing new security risks in the process. These attacks leverage prompt injections against the artificial intelligence (AI) agents embedded into IDEs and combine them with the base IDE layer to result in information disclosure or command execution. "This uses an 'old' attack chain of using a vulnerable tool, so not exactly part of the IDEsaster novel attack chain," Marzouk, who is credited with discovering and reporting the flaw, told The Hacker News. "Specifically, a vulnerable 'execute command' tool where you can bypass the user-configured allow list." Marzouk also said multiple IDEs were found vulnerable to the same attack, including Kiro.dev, Cursor (CVE-2025-54131), JetBrains Junie (CVE-2025-59458), Gemini CLI, Windsurf, and Roo Code (CVE-2025-54377, CVE-2025-57771, and CVE-2025-65946). Furthermore, GitHub Copilot for Visual Studio Code has been found to be susceptible to the vulnerability, although, in this case, Microsoft assigned it a "Medium" severity rating with no CVE. "The vulnerability states that it's possible to gain code execution on affected hosts by tricking the LLM into running commands that bypass the guardrails and appending instructions in the user's 'auto-approve' settings," Kev Breen, senior director of cyber threat research at Immersive, said. "This can be achieved through 'Cross Prompt Injection,' which is where the prompt is modified not by the user but by the LLM agents as they craft their own prompts based on the content of files or data retrieved from a Model Context Protocol (MCP) server that has risen in popularity with agent-based LLMs." Software Patches from Other Vendors In addition to Microsoft, security updates have also been released by other vendors over the past several weeks to rectify multiple vulnerabilities, including — Adobe Amazon Web Services AMD Arm ASUS Atlassian Bosch Broadcom (including VMware) Canon Cisco Citrix CODESYS Dell Devolutions Django Drupal F5 Fortinet Fortra GitLab Google Android and Pixel Google Chrome Google Cloud Google Pixel Watch Hitachi Energy HP HP Enterprise (including Aruba Networking and Juniper Networks) IBM Imagination Technologies Intel Ivanti Lenovo Linux distributions AlmaLinux, Alpine Linux, Amazon Linux, Arch Linux, Debian, Gentoo, Oracle Linux, Mageia, Red Hat, Rocky Linux, SUSE, and Ubuntu MediaTek Mitsubishi Electric MongoDB Moxa Mozilla Firefox and Firefox ESR NVIDIA OPPO Progress Software Qualcomm React Rockwell Automation Samsung SAP Schneider Electric Siemens SolarWinds Splunk Synology TP-Link WatchGuard Zoom, and Zyxel
thehackernews.comDec 10, 2025extracted
How to protect your car from hacking | Kaspersky official blog
It’s been ten years since two researchers — Charlie Miller and Chris Valasek — terrified a Wired journalist (and then the whole world) with their remote hack of a Jeep Cherokee speeding down the highway. It played out like something straight out of a Stephen King novel — a possessed car gone rogue. The wipers started moving on their own, buttons stopped responding, the radio blasted uncontrollably, and the brake pedal went dead. We’ve covered that case in detail plenty before: here, here, and here. Since then, cars have continued to evolve rapidly to integrate an ever-wider array of features. Digital electronics now control almost everything — from the engine and fuel systems to autopilot, passenger safety, and infotainment. That also means every interface or component can become a hacker’s entry point: MOST, LIN, and CAN buses, OBD ports, Ethernet, GPS, NFC, Wi-Fi, Bluetooth, LTE… But hey — on the bright side, the latest CarPlay lets you change your dashboard wallpaper! Jokes aside, the most serious attacks no longer target individual vehicles, but rather their manufacturers’ servers. In 2024, for example, Toyota lost 240GB of data, including customer information and internal network details. A single compromised server can expose millions of vehicles at once. Even the United Nations has taken note, and for once didn’t stop at “expressing concern”. Together with automakers, the UN has developed two key regulations — UN R155 and UN R156 — setting high-level cybersecurity and software update requirements for vehicle manufacturers. Also relevant is the ISO/SAE 21434:2021 standard, introduced in 2021, which details methods to mitigate cyber-risks throughout vehicle production. Though the above, technically, are recommendations, automakers have a strong incentive to comply: mass recalls can cost tens or even hundreds of millions of dollars. Case in point: following the incident mentioned earlier, Jeep had to recall 1.4 million vehicles in the U.S. alone — and faced a whopping $440 million in lawsuits. Surprisingly, the UN’s efforts have had real impact. In the last two years, the strict new rules have already led to the discontinuation of several older models, simply because they were designed before the regulations came into force. The discontinued models in 2024 include the Porsche 718 Boxster and Cayman (July), Porsche Macan ICE (April), Audi R8 and TT (June), VW Up! and Transporter 6.1 (June), and Mercedes-Benz Smart EQ Fortwo (April). What exactly can hackers do? There are plenty of ways cybercriminals can cause trouble for drivers: Creating dangerous situations. Disabling brakes, blasting loud music, or triggering other distractions (as in the Jeep case) can serve as psychological pressure or direct physical threats to anyone inside the vehicle. Stealing telematics data. This can be used to launch a targeted attack on specific individuals. In 2024, millions of Kia vehicles were found vulnerable to remote tracking via a dealer portal. With just a license plate number, attackers could locate the car in real time, lock or unlock the doors, start or stop the engine, and even honk the horn. Similar issues have affected BMW, Mercedes, Ferrari, and other manufacturers. Researchers also discovered that by compromising smart alarm systems they could listen to what’s going on in the interior of the car, access vehicle history, and steal owners’ personal data. Stealing the car itself. For example, by using devices such as CAN injectors, which connect to the vehicle’s CAN bus (through the headlight circuit, for example) and send commands that mimic signals from the real key. Stealing payment data. You might wonder why a car would hold the owner’s credit card info? Well, one was needed to pay for BMW’s heated seat subscription, for example. But while that particular scheme was scrapped after a public backlash, the “everything-as-a-service” trend continues. For example, in 2023, Mercedes-Benz offered electric car drivers the option to pay extra for faster acceleration. The feature would shave 0.9 seconds off the 0–100km/h time for an annual fee of US$600–900! How real is the threat to your car? First, let’s determine which category your vehicle falls into. Kaspersky ICS-CERT experts roughly divide all cars into three groups: Obsolete vehicles — no risk Vehicles in this group have no interaction with external information systems via digital channels. Their control units are minimal, and the only interface (if any) is the diagnostic OBD port. They can’t be hacked remotely, and there are no known cases of cyberattacks against them — the only real threat is traditional theft. Even if you install a modern multimedia head unit or an emergency response system, those modules remain isolated from the car’s internal components, preventing any attack on critical systems. Legacy vehicles — highest risk These models come in-between older cars with nothing to hack (“when cars were car”, etc.), and today’s “computers on wheels” packed with sensors and interfaces. Most of their systems and controls are digital. They typically include a telematics unit for wireless connectivity, a powerful infotainment system, and intelligent driver-assistance features. Together, these modules form a poorly protected information network where the ability to remotely adjust vehicle settings or control certain systems creates plenty of potential attack vectors. Owners often replace the outdated factory head units with new ones from third-party manufacturers — which rarely prioritize cybersecurity. Such models are the most vulnerable to serious cyberattacks — including those that can endanger the driver’s or passengers’ lives. But no one is planning serious security updates for them anymore. That ill-fated Jeep mentioned earlier falls squarely into this category. Modern vehicles — medium risk The latest models take into account lessons learned from past mistakes, as well as newly developed standards and regulations. Manufacturers now use segmented network architectures with a central gateway that filters traffic to isolate critical systems from the components most exposed to attack — the infotainment and telecom modules. Major automakers (General Motors was among the first, plus Tesla, Ford, Hyundai, BMW, Mercedes, Volkswagen, Toyota, Honda, and component makers like Bosch and Continental) now have dedicated cybersecurity teams and conduct penetration testing. However, this doesn’t mean these cars are completely secure. Researchers regularly find new vulnerabilities even in the most advanced models, because their attack surface is far larger than that of older vehicles. By the way, Kaspersky has developed its own car cybersecurity solution — Kaspersky Automotive Secure Gateway, so our top-tier protection will soon be available for vehicles too. What to look out for when buying a car? When buying a new vehicle these days, consider not only the technical specs but also its cybersecurity. Start by checking online for reports of cyberattacks on specific models or their manufacturers — such incidents rarely go unnoticed. If possible, find information about the following: The information network architecture of the car The presence of a central security gateway Separation of the car’s network into security domains Support of CAN-message encryption You should also ask the dealer the right questions: What cybersecurity systems are built into the car? How often are software updates released for this model, and how are they installed? How can unused smart functions be disabled? How do you set everything up correctly if you already have a car? Start with the manufacturer’s mobile app (if one exists). Set a strong, unique password that doesn’t contain any personal information. For help with this, see Creating an unforgettable password. Strengthen your account security with two-factor authentication or passkeys, if available. Regularly check the activity log and the list of devices connected to your account. Disable any unused features in both the app and the car. Next, tighten up the privacy settings in the car itself. Turn off telemetry collection where possible. Limit access to microphones and cameras. Clear your travel history and saved contacts before selling the car. And let’s not forget about managing connected devices. Regularly review paired Bluetooth devices. If possible, prohibit Bluetooth pairing without confirmation. Remove connections to the devices of previous owners or passengers. Disable automatic connection to unknown Wi-Fi networks. A few final tips: Keep your car’s software up to date: install firmware updates as soon as they’re released. Enable automatic notifications for available updates in the car settings. Monitor telemetry access: regularly check what data your car collects and who it’s shared with. Many of the latest cars let you limit personal data collection. What to do if you suspect your car is hacked? First, ask yourself: “What’s the evidence?” and check for the following signs of compromise: Vehicle features unexpectedly turning on and off Rapid battery drain with no obvious cause Strange notifications in the vehicle’s mobile app Inability to control the car normally If you suspect a hack, do the following: Disconnect the car from the internet. Remove the SIM card if possible, or contact your mobile operator to block data transfer for the number linked to the vehicle. Change passwords for the car’s mobile app. If possible, terminate all sessions tied to your account (often an option in the settings), or review all connections and remove any unknown devices. Take photos of any alerts the car displays. If you’ve entered payment card details in the car, block the card immediately. Contact an authorized dealer for diagnostics. Contact the vehicle manufacturer’s support. If you suspect data theft, report it to the police. Note that for private owners, the most likely threats are tracking and theft. However, for organizations that operate fleets (taxis, car-sharing, transportation or construction equipment companies), the risks are significantly higher. For a deeper dive into current automotive cybersecurity trends, check out our report on the Kaspersky ICS CERT site. Want to learn more about other threats to car owners? Browse our relevant posts:
kaspersky.comOct 9, 2025extracted
Red Hat Confirms GitLab Instance Hack, Data Theft
Red Hat on Thursday confirmed that one of its GitLab instances was hacked after a threat actor claimed to have stolen sensitive data belonging to the company and its customers. It was initially reported that the hackers had targeted a GitHub instance, but the enterprise software giant clarified that it was actually a GitLab instance, specifically one used by the Red Hat Consulting team. The hackers, calling themselves Crimson Collective, claimed to have stolen 570 Gb of compressed data from 28,000 private repositories. The obtained data allegedly includes source code, credentials, secrets, and configurations, as well as customer engagement reports (CERs). The attackers also claimed to have used the compromised information to gain access to Red Hat customers’ infrastructure. The hackers attempted to extort Red Hat, but based on information obtained by International Cyber Digest their attempt failed and the company had a very limited interaction with the attackers. SOCRadar reported that the data of as many as 800 Red Hat customers was obtained by the hackers, including major companies such as IBM, Siemens, Verizon, Bosch, and US government organizations such as the Energy Department, NIST, and the NSA. In a blog post published in response to the incident, Red Hat said the compromised GitLab instance has been used for “internal Red Hat Consulting collaboration in select engagements”. “Upon detection, we promptly launched a thorough investigation, removed the unauthorized party’s access, isolated the instance, and contacted the appropriate authorities,” Red Hat said, adding, “Our investigation, which is ongoing, found that an unauthorized third party had accessed and copied some data from this instance.” Red Hat has not addressed the claims about customers’ infrastructure being accessed by the hackers, but it’s not uncommon for extortion groups to make exaggerated claims in an effort to pressure victims into paying up. The software giant confirmed that the compromised GitLab instance stored data such as example code snippets, project specifications, and internal communications pertaining to consulting services. However, the instance does not typically store any sensitive personal information and to date Red Hat has found no evidence of such data being exposed. “At this time, we have no reason to believe the security issue impacts any of our other Red Hat services or products and are highly confident in the integrity of our software supply chain,” Red Hat told SecurityWeek in an emailed statement. Industry observers have questioned whether the incident was in any way related to a recently disclosed Red Hat Openshift AI service vulnerability that allows a low-privileged attacker to escalate privileges to full cluster administrator. Red Hat has clarified that the data breach is not related to the flaw. UPDATE: GitLab has provided the following statement to SecurityWeek: There has been no breach of GitLab’s managed systems or infrastructure. GitLab remains secure and unaffected. The incident refers to Red Hat’s self-managed instance of GitLab Community Edition, our free open-core offering. Customers who deploy free, self-managed instances on their own infrastructure are responsible for securing their instances, including applying security patches, configuring access controls, and maintenance. GitLab encourages all self-managed customers to update to the latest version of GitLab and follow all security recommendations and best practices to secure their instances. Users can find security resources and guidance in our Handbook: Related: Arch Linux Project Responding to Week-Long DDoS Attack Related: Salesloft GitHub Account Compromised Months Before Salesforce Attack Related: GitLab, Atlassian Patch High-Severity Vulnerabilities
securityweek.comOct 3, 2025extracted
Hackers claim to have plundered Red Hat’s GitHub repos
Hackers claim to have plundered Red Hat’s GitLab repos The Crimson Collective, an emerging extortion / hacker group, has made a bombshell claim on their Telegram channel: they have gained access to Red Hat’s GitLab and have exfiltrated data from over 28,000 internal repositories connected to the company’s consulting business. What data was allegedly compromised? Red Hat is the U.S.-based open-source enterprise software company known for providing Linux, cloud, container, and automation platforms for enterprises. Its professional services arm – Red Hat Consulting – help organizations plan, deploy, and optimize open-source-based IT solutions and teach customers’ internal teams how to maintain their IT infrastructure. Crimson Collective claims to have pilfered repositories related to Red Hat Consulting, which contain credentials, CI/CD secrets, pipeline and container registry configurations, VPN profiles, infrastructure blueprints, Ansible (automation) playbooks, OpenShift (cluster) install blueprints, and so on. “The file tree includes thousands of repositories referencing major banks, telecoms, airlines, and public-sector organizations, such as Citi, Verizon, Siemens, Bosch, JPMC, HSBC, Merrick Bank, Telstra, Telefonica, and even mentions the U.S. Senate…” the International Cyber Digest X account pointed out. “Over 28000 repositories were exported, it includes all their customer’s [engagement reports] and analysis of their [infrastructure] + their other [developers’] private repositories, this one will be fun,” Crimson Collective stated, and also claimed to have already gained access to some of Red Hat Consulting customers’ infrastructure: Screenshot of Crimson Collective’s claims on Telegram (Source: Kevin Beaumont) The list of the allegedly stolen customer engagement reports (CERs) also includes many high-profile organizations across the globe: Bank of America, Carrefour, Lumen, Samsung, Bank of Canada, Novonordisk, PepsiCo, Intelsat, Accenture, Boeing, and others, as well as government entities like the US Department of Homeland Security. What now? Crimson Collective says that they tried to contact Red Hat to present their ransom demand but that they received only an automatic reply from the Red Hat Information Security Team telling them to submit a vulnerability report. We’ve reached out to Red Hat with questions, but have yet to hear back from them. The company has told BleepingComputer that they are looking into the report of the security incident and have “initiated necessary remediation steps.” They also said that they currently have no reason to believe that this issue had an impact on other Red Hat services or products and that they are “highly confident” in the integrity of their software supply chain. UPDATE (October 3, 2025, 07:20 a.m. ET): While this article initially said that the attackers claimed to have accessed Red Hat Consulting’s GitHub repos, the company later confirmed that, in fact, one of the consulting arm’s GitLab instances has been breached. The headline and the text of the article were changed to reflect that. “Upon detection, we promptly launched a thorough investigation, removed the unauthorized party’s access, isolated the instance, and contacted the appropriate authorities,” the company said. “Our investigation, which is ongoing, found that an unauthorized third party had accessed and copied some data from this instance. The compromised GitLab instance housed consulting engagement data, which may include, for example, Red Hat’s project specifications, example code snippets, internal communications about consulting services, and limited forms of business contact information.” Red Hat said it would notify affected users directly. UPDATE (October 6, 2025, 04:50 a.m. ET): GitLab pointed out there has been no breach of GitLab’s managed systems or infrastructure, and that the incident refers to Red Hat’s self-managed instance of GitLab Community Edition. “Customers who deploy free, self-managed instances on their own infrastructure are responsible for securing their instances, including applying security patches, configuring access controls, and maintenance,” a GitLab spokesperson told Help Net Security. “GitLab encourages all self-managed customers to update to the latest version of GitLab and follow all security recommendations and best practices to secure their instances.” UPDATE (October 8, 2025, 08:10 a.m. ET): Hacker collective Scattered Lapsus$ Hunters has launched a data leak site for extorting a variety of organizations, including Red Hat. While the relationship between the Crimson Collective and Scattered Lapsus$ Hunters is difficult to ascertain, it seems that they have at least one member in common. The sample data provided by the collective to prove they’ve, indeed, made off with Red Hat Consulting data – including customer engagement reports for many large companies – is apparently legitimate. Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!
helpnetsecurity.comOct 2, 2025extracted
Cybersecurity jobs available right now: September 9, 2025
Cybersecurity jobs available right now: September 9, 2025 Analyst, Cybersecurity DFIR ICE | Singapore | On-site – No longer accepting applications As an Analyst, Cybersecurity DFIR, you will review and triage user-reported emails to identify phishing, malware, and other threats, taking containment actions and supporting eradication efforts. You will analyze DLP alerts for potential data exfiltration, monitor security tools for signs of compromise, and help tune detection rules to reduce false positives and improve alert accuracy. CISO SHVA | Israel | Hybrid – No longer accepting applications As a CISO, you will own the company’s information security strategy, protect corporate assets, and manage cyber risks. You will lead and develop the security team, oversee architects, GRC, and SOC functions, and continuously assess and manage risks. You will also create and maintain security policies and procedures, ensuring they remain effective and up to date. Cloud Security Engineer Coca Cola | Italy | Hybrid – No longer accepting applications As a Cloud Security Engineer, you will develop and enforce security architectures and practices across Azure environments. You will manage roles, permissions, and policies to ensure least privilege access, implement secure encryption for data at rest, in transit, and in use, and oversee encryption key management. You will also analyze threats and vulnerabilities in cloud systems and design countermeasures to mitigate risks. Get weekly updates on new cybersecurity job openings. Subscribe here! Consultant, Offensive Security, L2.2 Kroll | United Kingdom | Remote – No longer accepting applications As a Consultant, Offensive Security, L2.2, you will deliver projects for clients across Europe and North America, performing web application, API, mobile, and infrastructure penetration tests. You will draft reports based on assessment results, respond to client inquiries, and contribute to the refinement and improvement of security assessments. Cyber Security Engineer The Institute of Cancer Research | United Kingdom | On-site – No longer accepting applications As a Cyber Security Engineer, you will identify system and network weaknesses through vulnerability assessments and penetration testing, ensure systems are updated with the latest security patches, and monitor for suspicious activity. You will respond to security incidents by analyzing logs, investigating alerts, and containing breaches. Cyber Threat Intelligence Analyst Check Point Software | Israel | On-site – No longer accepting applications As a Cyber Threat Intelligence Analyst, you will assess customer needs and PIRs, configure tailored environments in the ERM intelligence platform, and provide ongoing tuning and training support. You will monitor and analyze threats or digital exposure issues to deliver actionable intelligence reports, while investigating sources, threat actors, tools, and techniques. Cyber Threat Intelligence Analyst Bosch | Germany | On-site – No longer accepting applications As a Cyber Threat Intelligence Analyst, you will identify, analyze, and track threat actor TTPs and IOCs using prioritization frameworks and continuous threat monitoring. You will investigate complex threat data to provide situational awareness, quantify trends, support investigations, and enhance detection and response. You will also perform in-depth technical analysis to support threat hunting and identify potential intrusions in Bosch networks and systems. Cybersecurity Engineer Central Transport | USA | On-site – No longer accepting applications As a Cybersecurity Engineer, you will onfigure, maintain, and manage security tools, including firewalls, SIEM, DLP, email, and endpoint protection. You will plan and implement network segmentation policies to enhance security and optimize performance, conduct regular vulnerability assessments with remediation recommendations, and develop and maintain security policies, procedures, and documentation. Cybersecurity Manager Inception | UAE | Hybrid – No longer accepting applications As a Cybersecurity Manager, you will will lead the development and improvement of the organization’s cybersecurity strategy, policies, and procedures. You will also manage Azure cloud security operations, leveraging native tools, automation, and scripting to strengthen security and efficiency. Deputy CISO United States Holocaust Memorial Museum | USA | Hybrid – No longer accepting applications As a Deputy CISO, you will design, implement, and manage the IT security program for the United States Holocaust Memorial Museum, protecting its systems and data. You will oversee the security incident response program, implement technical controls, and promote IT security throughout the system development life cycle by advising on security issues and new technologies. Industrial Cybersecurity Officer for Battery Storage Systems Siemens Energy | Germany | On-site – No longer accepting applications As an Industrial Cybersecurity Officer for Battery Storage Systems, you will advise and support global R&D and project teams in designing and implementing cost-effective cybersecurity architectures and technologies. You will also engage with leadership to understand regulatory requirements, market demands, and customer needs for products, solutions, services, and the Battery Storage factory. Lead OT Cyber Security Engineer Wood | UAE | On-site – No longer accepting applications As a Lead OT Cyber Security Engineer, you will advise clients on developing and implementing cybersecurity solutions for industrial control systems in the energy and materials industry. You will conduct gap assessments using NIST, ISO 27001, or ISA/IEC 62443 frameworks, guide clients on OT cybersecurity resilience roadmaps, and support growth and delivery of industrial cybersecurity and digital solutions projects. Linux Cryptography and Security Engineer Canonical | EMEA | Remote – View job details As a Linux Cryptography and Security Engineer, you will enhance cryptographic components such as OpenSSL, Libgcrypt, and GnuTLS to meet FIPS and CC certification requirements. You will collaborate with security consultants to validate kernel and crypto modules, work with partners to develop hardening benchmarks and automation for Ubuntu, and contribute to mainline and upstream projects to deliver solutions that benefit the community. Manager – Attack Surface Reduction Rockwell Automation | USA | Hybrid – No longer accepting applications As a Manager – Attack Surface Reduction, you will oversee the end-to-end vulnerability management lifecycle, including scanning, evaluation, remediation tracking, and reporting. Manage internal and external penetration testing engagements, ensuring scope, execution, and remediation are aligned with business risk. Design and maintain dashboards and indicators that communicate risk posture, remediation progress, and testing outcomes to both technical and executive audiences. NAS Cybersecurity Engineer Thales | Italy | Hybrid – No longer accepting applications As a NAS Cybersecurity Engineer, you will define security requirements for solution components, establish verification criteria, and support risk assessments to identify threats and vulnerabilities. You will assist in developing compliant technical solutions, ensure design and development processes meet security standards, and participate in solution integration, performing analyses and tests to verify security requirements are met. OT Cyber Security Specialist Orica | Philippines | Hybrid – No longer accepting applications As an OT Cyber Security Specialist, you will drive the OT Cyber Security Roadmap by identifying solutions tailored to manufacturing, supporting site-based OT engineers, and tracking key cyber risk indicators. You will monitor and report on site progress, assist in deploying security tools, investigate vulnerabilities, and support incident response efforts. Security Engineer AWS | Ireland | Remote – No longer accepting applications As a Security Engineer, you will lead incident triage and response, assess impacts on AWS systems and customers, and coordinate with service teams for rapid remediation. You will monitor alerts and logs for threats, conduct post-incident analyses, and contribute to lessons-learned documentation. Senior AI Security Engineer HelloFresh | Germany | On-site – No longer accepting applications As a Senior AI Security Engineer, you will threat model and secure data pipelines, training jobs, inference APIs, and RAG systems. You will mitigate risks such as prompt injection, data exfiltration, and model theft, implement content safety and access controls, and operationalize evaluations through red‑team tests, adversarial suites, and drift detection. Senior Cyber Security Engineer Contentsquare | France | Hybrid – No longer accepting applications As a Senior Cyber Security Engineer, you will respond to security incidents, proactively prevent future issues, and develop internal security tools. You will design and maintain alerts, automated actions, and escalation workflows for 24/7 incident response, and regularly audit platforms and applications to ensure security best practices are followed. Senior Director, Cyber Security Governance Risk & Compliance Rogers Communications | Canada | Hybrid – No longer accepting applications As a Senior Director, Cyber Security Governance Risk & Compliance, you will oversee the development and maintenance of information security policies, standards, and guidelines, ensuring they are regularly reviewed and updated. You will manage the genera
helpnetsecurity.comSep 9, 2025extracted
Chip Programming Firm Data I/O Hit by Ransomware
Chip programming solutions provider Data I/O was recently targeted in a ransomware attack that has caused significant disruption to the company’s operations. Data I/O offers electronic device programming systems for integrated circuits, such as flash memory and microcontrollers. According to its website, Data I/O customers include Bosch, Amazon, Apple, Google, HP, Microsoft, Siemens, Philips, Sony, and Foxconn. In an 8-K form filed with the SEC on August 21, the company revealed that it detected ransomware on some IT systems on August 16. It took some platforms offline in response to the intrusion, which led to communications, shipping, manufacturing, and other functions getting disrupted. Data I/O has called in outside experts to help with incident response and recovery. The investigation is ongoing, but the wording in the SEC report suggests the cybercriminals may have stolen some data from hacked systems. “Based on the findings, the Company will take additional actions as appropriate, including notifying affected individuals and regulatory authorities in compliance with applicable laws,” the firm said. The company has been working on restoring impacted systems, but on August 21 it could not provide a timeline for full restoration. “The expected costs related to the incident, including fees for our cybersecurity experts and other advisors, and costs to restore any impacted systems, are reasonably likely to have a material impact on the Company’s results of operations and financial condition,” the company said. No known ransomware group appears to have taken credit for the attack on Data I/O. Related: Telecom Firm Colt Confirms Data Breach as Ransomware Group Auctions Files Related: Pharmaceutical Company Inotiv Confirms Ransomware Attack Related: US Seizes $2.8 Million From Zeppelin Ransomware Operator Related: Manpower Says Data Breach Stemming From Ransomware Attack Impacts 140,000
securityweek.comAug 25, 2025extracted
Microsoft August 2025 Patch Tuesday Fixes Kerberos Zero-Day Among 111 Total New Flaws
Microsoft on Tuesday rolled out fixes for a massive set of 111 security flaws across its software portfolio, including one flaw that has been disclosed as publicly known at the time of the release. Of the 111 vulnerabilities, 16 are rated Critical, 92 are rated Important, two are rated Moderate, and one is rated Low in severity. Forty-four of the vulnerabilities relate to privilege escalation, followed by remote code execution (35), information disclosure (18), spoofing (8), and denial-of-service (4) defects. This is in addition to 16 vulnerabilities addressed in Microsoft's Chromium-based Edge browser since the release of last month's Patch Tuesday update, including two spoofing bugs affecting Edge for Android. Included among the vulnerabilities is a privilege escalation vulnerability impacting Microsoft Exchange Server hybrid deployments (CVE-2025-53786, CVSS score: 8.0) that Microsoft disclosed last week. The publicly disclosed zero-day is CVE-2025-53779 (CVSS score: 7.2), another privilege escalation flaw in Windows Kerberos that stems from a case of relative path traversal. Akamai researcher Yuval Gordon has been credited with discovering and reporting the bug. It's worth mentioning here that the issue was documented in detail back in May 2025 by the web infrastructure and security company, giving it the codename BadSuccessor. The novel technique essentially allows a threat actor with sufficient privileges to compromise an Active Directory (AD) domain by misusing delegated Managed Service Account (dMSA) objects. "The good news here is that successful exploitation of CVE-2025-53779 requires an attacker to have pre-existing control of two attributes of the hopefully well protected dMSA: msds-groupMSAMembership, which determines which users may use credentials for the managed service account, and msds-ManagedAccountPrecededByLink, which contains a list of users on whose behalf the dMSA can act," Adam Barnett, lead software engineer at Rapid7, told The Hacker News. "However, abuse of CVE-2025-53779 is certainly plausible as the final link of a multi-exploit chain which stretches from no access to total pwnage." Action1's Mike Walters noted that the path traversal flaw can be abused by an attacker to create improper delegation relationships, enabling them to impersonate privileged accounts, escalate to a domain administrator, and potentially gain full control of the Active Directory domain. "An attacker who already has a compromised privileged account can use it to move from limited administrative rights to full domain control," Walters added. "It can also be paired with methods such as Kerberoasting or Silver Ticket attacks to maintain persistence." "With domain administrator privileges, attackers can disable security monitoring, modify Group Policy, and tamper with audit logs to hide their activity. In multi-forest environments or organizations with partner connections, this flaw could even be leveraged to move from one compromised domain to others in a supply chain attack." Satnam Narang, senior staff research engineer at Tenable, said the immediate impact of BadSuccessor is limited, as only 0.7% of Active Directory domains had met the prerequisite at the time of disclosure. "To exploit BadSuccessor, an attacker must have at least one domain controller in a domain running Windows Server 2025 in order to achieve domain compromise," Narang pointed out. Some of the notable Critical-rated vulnerabilities patched by Redmond this month are below - CVE-2025-53767 (CVSS score: 10.0) - Azure OpenAI Elevation of Privilege Vulnerability CVE-2025-53766 (CVSS score: 9.8) - GDI+ Remote Code Execution Vulnerability CVE-2025-50165 (CVSS score: 9.8) - Windows Graphics Component Remote Code Execution Vulnerability CVE-2025-53792 (CVSS score: 9.1) - Azure Portal Elevation of Privilege Vulnerability CVE-2025-53787 (CVSS score: 8.2) - Microsoft 365 Copilot BizChat Information Disclosure Vulnerability CVE-2025-50177 (CVSS score: 8.1) - Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability CVE-2025-50176 (CVSS score: 7.8) - DirectX Graphics Kernel Remote Code Execution Vulnerability Microsoft noted that the three cloud service CVEs impacting Azure OpenAI, Azure Portal, and Microsoft 365 Copilot BizChat have already been remediated, and that they require no customer action. Check Point, which disclosed CVE-2025-53766 alongside CVE-2025-30388, said the vulnerabilities allow attackers to execute arbitrary code on the affected system, leading to a full system compromise. "The attack vector involves interacting with a specially crafted file. When a user opens or processes this file, the vulnerability is triggered, allowing the attacker to take control," the cybersecurity company said. The Israeli firm revealed that it also uncovered a vulnerability in a Rust-based component of the Windows kernel that can result in a system crash that, in turn, triggers a hard reboot. "For organizations with large or remote workforces, the risk is significant: attackers could exploit this flaw to simultaneously crash numerous computers across an enterprise, resulting in widespread disruption and costly downtime," Check Point said. "This discovery highlights that even with advanced security technologies like Rust, continuous vigilance and proactive patching are essential to maintaining system integrity in a complex software environment." Another vulnerability of importance is CVE-2025-50154 (CVSS score: 6.5), an NTLM hash disclosure spoofing vulnerability that's actually a bypass for a similar bug (CVE-2025-24054, CVSS score: 6.5) that was plugged by Microsoft in March 2025. "The original vulnerability demonstrated how specially crafted requests could trigger NTLM authentication and expose sensitive credentials," Cymulate researcher Ruben Enkaoua said. "This new vulnerability [...] allows an attacker to extract NTLM hashes without any user interaction, even on fully patched systems. By exploiting a subtle gap left in the mitigation, an attacker can trigger NTLM authentication requests automatically, enabling offline cracking or relay attacks to gain unauthorized access." Software Patches from Other Vendors In addition to Microsoft, security updates have also been released by other vendors over the past several weeks to rectify several vulnerabilities, including — 7-Zip Adobe Amazon Web Services AMD AMI Apple Arm ASUS Atlassian Autodesk Axis Communications Bosch Broadcom (including VMware) Check Point Cisco CODESYS D-Link Dell Drupal Elastic Emerson F5 Fortinet Fortra Foxit Software FUJIFILM Fujitsu Gigabyte GitLab Google Android and Pixel Google Chrome Google Cloud Google Wear OS HMS Networks HP HP Enterprise (including Aruba Networking) Huawei IBM Intel Ivanti Juniper Networks Lenovo Linux distributions AlmaLinux, Alpine Linux, Amazon Linux, Arch Linux, Debian, Gentoo, Oracle Linux, Mageia, Red Hat, Rocky Linux, SUSE, and Ubuntu MediaTek Mitel Mitsubishi Electric Moxa Mozilla Firefox, Firefox ESR, and Thunderbird NVIDIA Palo Alto Networks Qualcomm Rockwell Automation Salesforce Samsung SAP Schneider Electric ServiceNow Siemens SolarWinds SonicWall Sophos Splunk Spring Framework Supermicro Synology TP-Link Trend Micro WinRAR Xerox Zimbra Zoom, and Zyxel
thehackernews.comAug 13, 2025extracted
Critical Flaws in Niagara Framework Threaten Smart Buildings and Industrial Systems Worldwide
Cybersecurity researchers have discovered over a dozen security vulnerabilities impacting Tridium's Niagara Framework that could allow an attacker on the same network to compromise the system under certain circumstances. "These vulnerabilities are fully exploitable if a Niagara system is misconfigured, thereby disabling encryption on a specific network device," Nozomi Networks Labs said in a report published last week. "If chained together, they could allow an attacker with access to the same network — such as through a Man-in-the-Middle (MiTM) position — to compromise the Niagara system." Developed by Tridium, an independent business entity of Honeywell, the Niagara Framework is a vendor-neutral platform used to manage and control a wide range of devices from different manufacturers, such as HVAC, lighting, energy management, and security, making it a valuable solution in building management, industrial automation, and smart infrastructure environments. It consists of two key components: Station, which communicates with and controls connected devices and systems, and Platform, which is the underlying software environment that provides the necessary services to create, manage, and run Stations. The vulnerabilities identified by Nozomi Networks are exploitable should a Niagara system be misconfigured, causing encryption to be disabled on a network device and opening the door to lateral movement and broader operational disruptions, impacting safety, productivity, and service continuity. The most severe of the issues are listed below - CVE-2025-3936 (CVSS score: 9.8) - Incorrect Permission Assignment for Critical Resource CVE-2025-3937 (CVSS score: 9.8) - Use of Password Hash With Insufficient Computational Effort CVE-2025-3938 (CVSS score: 9.8) - Missing Cryptographic Step CVE-2025-3941 (CVSS score: 9.8) - Improper Handling of Windows: DATA Alternate Data Stream CVE-2025-3944 (CVSS score: 9.8) - Incorrect Permission Assignment for Critical Resource CVE-2025-3945 (CVSS score: 9.8) - Improper Neutralization of Argument Delimiters in a Command CVE-2025-3943 (CVSS score: 7.3) - Use of GET Request Method With Sensitive Query Strings Nozomi Networks said it was able to craft an exploit chain combining CVE-2025-3943 and CVE-2025-3944 that could enable an adjacent attacker with access to the network to breach a Niagara-based target device, ultimately facilitating root-level remote code execution. Specifically, the attacker could weaponize CVE-2025-3943 to intercept the anti-CSRF (cross-site request forgery) refresh token in scenarios where the Syslog service is enabled, causing the logs containing the token to be transmitted potentially over an unencrypted channel. Armed with the token, the threat actor can trigger a CSRF attack and lure an administrator into visiting a specially crafted link that causes the content of all incoming HTTP requests and responses to be fully logged. The attacker then proceeds to extract the administrator's JSESSIONID session token and use it to connect to the Niagara Station with full elevated permissions and creates a new backdoor administrator user for persistent access. In the next stage of the attack, the administrative access is abused to download the private key associated with the device's TLS certificate and conduct adversary-in-the-middle (AitM) attacks by taking advantage of the fact that both the Station and Platform share the same certificate and key infrastructure. With control of the Platform, the attacker could leverage CVE-2025-3944 to facilitate root-level remote code execution on the device, achieving complete takeover. Following responsible disclosure, the issues have been addressed in Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11. "Because Niagara often connects critical systems and sometimes bridges IoT technology and information technology (IT) networks, it could represent a high-value target," the company said. "Given the critical functions that can be controlled by Niagara-powered systems, these vulnerabilities may pose a high risk to operational resilience and security provided the instance has not been configured per Tridium's hardening guidelines and best practices." The disclosure comes as several memory corruption flaws have been discovered in the P-Net C library, an open-source implementation of the PROFINET protocol for IO devices, that, if successfully exploited, could allow unauthenticated attackers with network access to the targeted device to trigger denial-of-service (DoS) conditions. "Practically speaking, exploiting CVE-2025-32399, an attacker can force the CPU running the P-Net library into an infinite loop, consuming 100% CPU resources," Nozomi Networks said. "Another vulnerability, tracked as CVE-2025-32405, allows an attacker to write beyond the boundaries of a connection buffer, corrupting memory and making the device entirely unusable." The vulnerabilities have been resolved in version 1.0.2 of the library, which was released in late April 2025. In recent months, multiple security defects have also been unearthed in Rockwell Automation PowerMonitor 1000, Bosch Rexroth ctrlX CORE, and Inaba Denki Sangyo's IB-MCT001 cameras that could result in execution of arbitrary commands, device takeover, DoS, information theft, and even remote access of live footage for surveillance. "Successful exploitation of these vulnerabilities could allow an attacker to obtain the product's login password, gain unauthorized access, tamper with product's data, and/or modify product settings," the U.S. Cybersecurity and Infrastructure Security Agency (CISA) said in an advisory for IB-MCT001 flaws.
thehackernews.comJul 28, 2025extracted