Search/honeywell
Vendor

honeywell

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
h3w4gr1 firmware
Connections
185 relationships
Hacker Conversations: Vinnie Liu, Performer Turned Ringmaster
Vinnie Liu was recruited by the NSA when he was just 17 years old. He is now the CEO of Bishop Fox. He says little about his work at the NSA, only that “My first year was on the red team, and in the second year, it was more externally facing.” He had been recommended to the NSA by an Air Force guy he never met face-to-face and whose ‘handle’ he no longer remembers. But being recruited by such an organization in such a manner at such an early age would indicate a prodigious hacker. This is not the image he projects. “I hadn’t been engaged in hacking in anything like a grand scale, like some scattered spider. But I spent a lot of time learning how systems worked and figuring out how to set systems up and take them down. I’ve always been more on the white hat side. I think that’s probably what caught their attention – I wasn’t trying to break into things for the thrill of it; I was just trying to learn.” His earlier understanding of computers and programming came from an older sister who was away at college. “She would come home from college every now and then with books or materials, and I would just devour them. I found them fascinating. She’d come home with these various programming books, and I would just think ‘Oh, what’s that?’ So, I’d try to figure it out.” He was less than 10 years old and already displaying some of the key characteristics of a hacker: an intense curiosity and desire to understand. But he had no concept of hacking or hackers. His motivation was simply to do what he enjoyed and have fun doing it – a motivation that has stayed with him through life. Later, in high school, he started to learn about computers and computing. He clearly excelled since he was recruited by the NSA before even working toward a degree. He understood the concept of hacking, and obviously dabbled, but solely out of curiosity and the desire to have fun. “I had been spending a lot of time on IRC,” he explains, and it was here that he met the Air Force guy who recommended him to the NSA. Asked if he did anything ‘shady’ with his growing knowledge, he said ‘No’. Pressed on the subject (‘What – not even breaking into the school’s computer network?’), he simply replied, “I don’t think that’s shady – it’s just de rigueur if you’re into programming and at school.” He doesn’t say he did do this, but clearly implies he did this or similar. “My definition of a hacker is somebody who likes to find a way around a control or a security system to get things to behave in ways that were unintended.” Note that he doesn’t specify any motivating purpose for hacking. For Liu, the act of hacking stands alone. It is the purpose of the hacker that differentiates between black and white hat hacking. “I think intent is really important. There’s exploring, and then there’s exploring for the purpose of destroying or hurting or harming. There’s a distinction between those two things.” Liu liked to explore constantly, freely, for fun – but never harm. It is perhaps this total absence of any malicious intent from Liu that makes him reticent about his own hacking career. Asked if he had ever considered selling his discoveries on the dark web, he replied that he couldn’t because it didn’t exist at the time. “When I started, in the first half of the 1990s, there was no dark web.” Again, we have this minor evasion of the point of the question – he didn’t, not because he wouldn’t, but because he couldn’t. But his answer was accurate: the dark web didn’t really evolve until after the Tor project software was released in 2002 and the Tor browser arrived around 2008. Despite the apparent slight contradictions in his history (being involved in hacking within the NSA and considering breaking into school computer networks just par for the course), Liu clearly has a strong moral compass. He got into hacking solely for the purpose of having fun. He could do it, he enjoyed it, but he never had any malicious intent. This moral compass came, he believes, “From both my parents and early educators, who I think were very good role models.” This suggests he believes that morality is something learned, not something innate. Statistically, many hackers are neurodiverse. Neurodiversity simply indicates a brain and thought processes that are out of the norm. For hackers, it is often evident in ADHD and ASD (the latter was formerly called ‘Asperger’s syndrome’). It helps with what ‘normies’ (the majority of non-neurodiverse people) might consider to be thinking outside of the box, and engaging in long periods of sustained and deep concentration – both of which are clearly beneficial attributes for a hacker. Is Liu neurodiverse? “No. I don’t consider myself to be neurodiverse,” he says. “My wife would call me nuts, but I don’t think I’m neurodiverse in the traditional sense. I just really enjoy what I do.” Liu was only 17 when he took his first formal employment working for the NSA. This was in 1999. “I was a full-time employee,” he explains, “but they let me take classes.” It is difficult to classify what he did within the NSA, which he merely states as ‘externally facing’. Let’s assume he was a hacker for the NSA. Could that be considered black hat, since it would clearly intend some form of harm to the target? Or is any form of hacking for the good guys automatically white hat? Either way, his career after the NSA was clearly and increasingly white hat. During his two years at the NSA, the commercial ‘civilian’ security industry went through a rapid expansion, and “They started hiring a lot of my colleagues, especially the ones I really got along with.” @stake was founded in 1999, the same year he joined the NSA. A year later, @stake acquired Lopht Heavy Industries, an organization that had been a major magnet for serious and well-known hackers (including Weld Pond, Kingpin and Space Rogue). By 2001, he realized that everyone was leaving to join private industry. “I decided to do the same. I left the NSA but first wanted to complete my degree course. That took another couple of years.” By the time he was 21, he had two years’ experience working for the NSA, a recently acquired degree in Computer Science, and considerable knowledge of what we should politely call offensive security. “In a lot of cases,” he comments, “hackers [by which he means both internal red teamers and external attackers] wind up understanding a system better than the original developers; because they’ve thought so deeply about the system and how to subvert its behavior.” This is by no means a simple process – and hackers are as prone to burnout as any other security practitioner. “I’ve seen a lot of brilliant, brilliant hackers – I mean real next level folks – burn out and just lose it.” With his CV, he was never likely to have difficulty finding employment in the private sector. In 2003 he started work as a Security Consultant at the Advanced Security Center, Ernst & Young LLP, where he re-acquainted with Fran Brown. He and Brown had been in the same hall in college freshman year, and they took the same courses. Within 18 months they were both recruited by Honeywell. Together they led Honeywell’s global penetration testing team. This time, he, well they, stayed for just 16 months. They began to get additional sub-contracting work on the side, “from friends who needed help”. They were already thinking about what to do next, and decided, “Hey, yeah, why not?” Bishop Fox was the ultimate answer to this question, although the precise route is difficult to plot. Both Liu and Brown indicate they left Honeywell and moved immediately into Bishop Fox, which they co-founded. Liu’s LinkedIn profile suggests he did this the year before leaving Honeywell. Brown’s profile suggests it was concurrent with leaving Honeywell. But the name Bishop Fox is a rebranding of the firm Stach & Liu LLC, which happened in 2014. Stach and Liu was itself not founded, according to Dun & Bradstreet, until 2011. It was rebranded to Bishop Fox in 2013 – possibly because the former sounds more like a law firm while the latter symbolizes both the protective and aggressive aspects of penetration testing and red teaming. Nevertheless, regardless of the circuitous route to Bishop Fox, Liu and Brown founded a company that is now widely considered to be a top-tier authority in offensive security. Liu, as its CEO, has progressed from an offensive security performer to an offensive security ringmaster. Is he still a hacker? “I’d like to think so. And certainly I would have given you a very affirmative ‘Yes’ 10 years ago. These days, I think my team thinks I’m a little out of date, but I’ve spent a large part of my career hacking into things. More recently I spend time managing the firm, but, yeah, I would like to think I’m still a hacker.” Still this slight reticence in clearly stating he is a hacker. He clearly is a hacker – and since hacking is as much a state of mind as physical process, once a hacker, always a hacker. The clarity, however, is that he, Fran Brown, and the entire Bishop Fox organization are hackers for good. Related: Hacker Conversations: Isira Adithya, the Evolution of an Ethical Hacker Related: Hacker Conversations: Joey Melo on Hacking AI Related: Hacker Conversations: Tal Kollander’s Journey From Black Hat to Hack Blocker
securityweek.comSep 10, 2026extracted
ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact
Industrial giants Siemens, Schneider Electric, and Phoenix Contact have published August 2026 Patch Tuesday advisories to inform customers about vulnerabilities found in their ICS products. Siemens has published 10 new advisories. One covers a maximum-severity missing-authentication vulnerability in Simatic IoT2050 Advanced devices. A remote, unauthenticated attacker can exploit it to execute arbitrary code on the underlying server with elevated privileges. A critical code execution vulnerability has also been fixed by Siemens in the Siveillance Video Management Servers. High-severity flaws have been addressed in Solid Edge, Simcenter Nastran, Siemens License Server, Simcenter Femap, Parasolid, and Logo! Soft Comfort. They can be exploited to crash applications, execute arbitrary code, elevate privileges, read arbitrary files, or obtain sensitive information. Medium-severity issues have been resolved in Ruggedcom devices and Desigo controllers. Schneider Electric has published two new advisories describing vulnerabilities in NetBotz 5 and PowerChute Serial Shutdown products. In NetBotz, the company fixed two code/command execution issues, while in PowerChute it patched a flaw allowing excessive authentication attempts, which could lead to disruption or access to system data. Phoenix Contact has published one advisory for multiple vulnerabilities in PLCnext firmware. The flaws can be exploited by unauthenticated attackers to cause a DoS condition, trigger unexpected behavior, or execute malicious SQL queries. Honeywell has published several advisories for its building management system products. The cybersecurity agency CISA published three new advisories on Tuesday and several others earlier this month. The new advisories cover vulnerabilities in Pulsetto, Mira (Quanovate Tech), and Johnson Controls products. Related: ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Rockwell Related: ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact
securityweek.comAug 12, 2026extracted
Ivanti, Fortinet, SAP, VMware, n8n Patch RCE, SQL Injection, Privilege Escalation Flaws
Ivanti, Fortinet, n8n, SAP, and VMware have released security fixes for various vulnerabilities that could be exploited by bad actors to bypass authentication and execute arbitrary code. Topping the list is a critical flaw impacting Ivanti Xtraction (CVE-2026-8043, CVSS score: 9.6) that could be exploited to achieve information disclosure or client-side attacks. "External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files and write arbitrary HTML files to a web directory, leading to information disclosure and possible client-side attacks," Ivanti said in an advisory. Fortinet published advisories for two critical shortcomings affecting FortiAuthenticator and FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS that could result in code execution - CVE-2026-44277 (CVSS score: 9.1) - An improper access control vulnerability in FortiAuthenticator that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. (Fixed in FortiAuthenticator versions 6.5.7, 6.6.9, and 8.0.3) CVE-2026-26083 (CVSS score: 9.1) - A missing authorization vulnerability in FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS WEB UI that may allow an unauthenticated attacker to execute unauthorized code or commands via HTTP requests. (Fixed in FortiSandbox versions 4.4.9 and 5.0.2, FortiSandbox Cloud version 5.0.6, and FortiSandbox PaaS versions 4.4.9. and 5.0.2) SAP also shipped fixes for two critical vulnerabilities - CVE-2026-34260 (CVSS score: 9.6) - An SQL injection vulnerability in SAP S/4HANA CVE-2026-34263 (CVSS score: 9.6) - A missing authentication check in the SAP Commerce cloud configuration "The vulnerability is caused by an overly permissive security configuration with improper rule ordering, allowing an unauthenticated user to perform malicious configuration upload and code injection, resulting in arbitrary server-side code execution," Onapsis said about CVE-2026-34263. On the other hand, CVE-2026-34260 could be exploited by an attacker to inject malicious SQL statements and potentially impact the confidentiality and availability of the application. However, since the affected code only allows read access to data, the vulnerability does not compromise the integrity of the application. "It allows a low-privileged, authenticated attacker to inject malicious SQL code via user-controlled input, potentially exposing sensitive database information and crashing the application," Pathlock said. Patches have also been released by Broadcom for a high-severity flaw in VMware Fusion (CVE-2026-41702, CVSS score: 7.8) that could pave the way for local privilege escalation. The issue has been addressed in version 26H1. "VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a SETUID binary," Broadcom said. "A malicious actor with local non-administrative user privileges may exploit this vulnerability to escalate privileges to root on the system where Fusion is installed." Round off the list is a set of five critical vulnerabilities impacting n8n - CVE-2026-42231 (CVSS score: 9.4) - A vulnerability in the xml2js library used to parse XML request bodies in n8n's webhook handler that allows prototype pollution via a crafted XML payload, enabling an authenticated user with permission to create or modify workflows to achieve remote code execution on the n8n host. (Fixed in n8n versions 1.123.32, 2.17.4, and 2.18.1) CVE-2026-42232 (CVSS score: 9.4) - An authenticated user with permission to create or modify workflows could achieve global prototype pollution via the XML Node, leading to remote code execution when combined with other nodes exploiting the prototype pollution. (Fixed in n8n versions 1.123.32, 2.17.4, and 2.18.1) CVE-2026-44791 (CVSS score: 9.4) - A bypass for CVE-2026-42232 that could result in remote code execution on the n8n host. (Fixed in n8n versions 1.123.43, 2.20.7, and 2.22.1) CVE-2026-44789 (CVSS score: 9.4) - An authenticated user with permission to create or modify workflows could achieve global prototype pollution via an unvalidated pagination parameter in the HTTP Request node, leading to remote code execution on the n8n host. (Fixed in n8n versions 1.123.43, 2.20.7, and 2.22.1) CVE-2026-44790 (CVSS score: 9.4) - An authenticated user with permission to create or modify workflows could inject CLI flags on the Git node's Push operation, enabling an attacker to read arbitrary files from the n8n server and resulting in full compromise. (Fixed in n8n versions 1.123.43, 2.20.7, and 2.22.1) Software Patches from Other Vendors Security updates have also been released by other vendors over the past several weeks to rectify various vulnerabilities, including - ABB Adobe Amazon Web Services AMD Apple ASUS Atlassian Axis Communications AVEVA Canon Cisco CODESYS ConnectWise Dell Devolutions Drupal F5 Fortra Foxit Software Fujitsu GitLab GnuTLS Google Android and Pixel Google Chrome Google Cloud Grafana Hikvision Hitachi Energy Honeywell HP HP Enterprise (including Aruba Networking and Juniper Networks) Huawei IBM Intel Jenkins Lenovo Linux distributions AlmaLinux, Alpine Linux, Amazon Linux, Arch Linux, Debian, Gentoo, Oracle Linux, Mageia, Red Hat, Rocky Linux, SUSE, and Ubuntu MediaTek Meta WhatsApp Microsoft Mitel Mitsubishi Electric MongoDB Moxa Mozilla Firefox, Firefox ESR, and Thunderbird NVIDIA OPPO Palo Alto Networks Phoenix Contact Phoenix Technologies Progress Software QNAP Qualcomm React Ricoh Samsung Schneider Electric Siemens Sophos Spring Framework Supermicro Synology Tenable TP-Link WatchGuard Zoom, and Zyxel
thehackernews.comMay 18, 2026extracted
Cybersecurity jobs available right now: April 14, 2026
Cybersecurity jobs available right now: April 14, 2026 Cyber Security Engineer/Application Security Specialist Tecnots | India | On-site – No longer accepting applications As a Cyber Security Engineer/Application Security Specialist, you will integrate security into the SDLC, perform application security reviews, and support secure APIs, authentication, and data protection. You will embed security into CI/CD pipelines using SAST and DAST, enforce secure coding practices, and support remediation. You will secure cloud and on-prem environments, including Microsoft Azure, manage IAM and access controls, and handle vulnerabilities, compliance, and incident response. Cyber Security Engineer Netrolynx AI | United Kingdom | Remote – No longer accepting applications As a Cyber Security Engineer, you will monitor, detect, and respond to threats using SIEM, EDR, and threat intelligence tools, and analyze logs to identify risks and breaches. You will investigate incidents such as phishing, malware, and unauthorized access, and maintain the security risk register. Cyber Security GRC Consultant RINA | Italy | Hybrid – No longer accepting applications As a Cyber Security GRC Consultant, you will identify security risks in systems and architectures, design controls to improve security posture, and ensure compliance with regulations and standards. You will support clients, produce technical reports, and maintain cybersecurity guidelines and methodologies. Get weekly updates on new cybersecurity job openings. Subscribe here! Cyber Threat Intelligence Lead MANTECH | USA | On-site – No longer accepting applications As a Cyber Threat Intelligence Lead, you will stablish and enforce CTI standards, oversee monitoring activities, and lead advanced threat analysis. You will identify indicators of compromise, support attribution of advanced persistent threats, and analyze intelligence from diverse sources. Cybersecurity Analyst TENEX.AI | USA | On-site – No longer accepting applications As a Cybersecurity Analyst, you will monitor and analyze security events using traditional tools and AI/ML systems, leveraging Google Chronicle for threat detection and visibility. You will investigate and respond to incidents, perform root cause analysis, and use Google SecOps to streamline and accelerate response workflows. You will also collaborate across teams, optimize security operations, and automate routine SOC tasks using AI-driven solutions. Cybersecurity Engineer ReeVo Cloud & Cyber Security | Italy | On-site – No longer accepting applications As a Cybersecurity Engineer, you will manage and fine-tune advanced security tools such as SIEM, SOAR, NDR, and XDR, and design proactive measures to detect and mitigate cyber threats. You will ensure the protection of customer data and systems. Cybersecurity Manager, GRC SBS Transit | Singapore | Hybrid – No longer accepting applications As a Cybersecurity Manager, GRC, you will oversee cybersecurity controls across IT and OT environments, including critical infrastructure, and develop policies aligned with regulations such as Cybersecurity Code of Practice 2.0. You will conduct audits, risk assessments, and vulnerability checks to ensure controls are effective and compliant. Digital Forensics Analyst Cyber Centaurs | USA | Remote – No longer accepting applications As a Digital Forensics Analyst, you will collect and preserve digital evidence through forensic imaging of computers, drives, and mobile devices while maintaining strict chain of custody. You will analyze forensic data across Windows, macOS, and mobile systems to identify user activity, data access, and potential exfiltration, and support investigations into employee misconduct and trade secret theft. ICT/Cyber Security Engineer Honeywell | France | Hybrid – No longer accepting applications As an ICT/Cyber Security Engineer, you will design, implement, secure, and support ICT infrastructure and enterprise applications across client environments. You will contribute to technical risk reviews, maintain complex systems, and support platforms such as Honeywell solutions. Information Security Lead TeleClinic | Germany | Remote – No longer accepting applications As an Information Security Lead, you will design and maintain secure backend services and APIs using Python and Django, and lead compliance efforts including ISO 27001 certification. You will build and enforce the ISMS, define security policies, and lead risk assessments, threat modeling, and vulnerability management. InfoSec Engineer Oxford Nanopore Technologies | United Kingdom | Hybrid – No longer accepting applications As an InfoSec Engineer, you will build and enhance blue team and threat hunting capabilities across Oxford Nanopore Technologies IT systems. You will design, deploy, and harden configurations, monitor and respond to SIEM alerts, and improve detection through rule tuning. You will support incident response by triaging alerts and reducing false positives, work with third parties to secure tools such as EDR, SIEM/SOAR, SWG, DLP, and vulnerability management, and advise on security architecture, vendor selection, and service improvements. Insider Risk BI Developer SMBC Group | Ireland | On-site – No longer accepting applications As an Insider Risk BI Developer, you will deliver insider risk and cybersecurity metrics, KPIs, and dashboards, and identify gaps to improve reporting. You will analyze cyber intelligence and compliance data to support decision-making and strategic recommendations. OT Cybersecurity Risk & Compliance Engineer VINCI Energies | UAE | On-site – View job details As an OT Cybersecurity Risk & Compliance Engineer, you will develop and maintain security procedures for OT environments, ensure compliance with cybersecurity policies, and support the ISMS across industrial systems. You will assess risks, define mitigation actions, and track risk treatment plans. You will conduct audits, analyze OT security incidents, and communicate findings to stakeholders. Penetration Tester SECTERIOUS | Israel | On-site – No longer accepting applications As a Penetration Tester, you will conduct vulnerability assessments and penetration tests on applications, networks, and systems to identify and mitigate security risks. You will perform reverse engineering, malware analysis, and red team exercises to simulate attacks. Principal Cybersecurity Engineer Collins Aerospace | Australia | On-site – View job details As a Principal Cybersecurity Engineer, you will design and test ICT systems, identify vulnerabilities, and implement security controls. You will perform threat modeling, define mitigations, and evaluate new cybersecurity tools. You will lead initiatives to improve security and compliance through automation and policy updates, and maintain SOPs, security plans, and accreditation activities. (Senior) Cyber Detection & Response Engineer ZEAL Network | Germany | Hybrid – No longer accepting applications As a (Senior) Cyber Detection & Response Engineer, you will manage and optimize the CrowdStrike Falcon platform, improving detection quality, configurations, and workflows across endpoints, servers, and cloud. You will handle L2/L3 incident escalations, lead investigations, and refine alert triage and prioritization. You will build and tune detections, perform threat hunting, and use exposure insights to identify vulnerabilities and drive remediation, improving overall security posture. Security Engineer Application & Networking CYBERcom | Israel | On-site – No longer accepting applications As a Security Engineer Application & Networking, you will mplement and maintain application security solutions using Cloudflare. You will configure and optimize DNS, WAF, CDN, caching, and troubleshoot network, SSL, and performance issues. You will support advanced protections such as bot, API, and DDoS security, and implement ZTNA and SASE solutions including secure web gateway, CASB, DLP, and RBI. Senior Cyber Security Engineer II-Identity Governance Staples | USA | On-site – No longer accepting applications As a Senior Cyber Security Engineer II-Identity Governance, you will design, secure, and maintain Active Directory and hybrid identity environments, ensuring resilience and alignment with best practices. You will apply zero trust principles, enforce least-privilege access, and support privileged identity management to reduce risk across identity systems. Senior IAM Engineer Momentum Financial Services Group | Canada | On-site – View job details As a Senior IAM Engineer, you will manage user access lifecycles, enforce role-based and least-privilege access, and support governance, compliance, and audit readiness. You will also monitor IAM systems for security threats, respond to access-related incidents, integrate IAM with enterprise applications, and collaborate across teams. Additionally, you will automate IAM processes and drive continuous improvements to enhance efficiency and security posture. Senior Security Engineer Pigment | France | Hybrid – No longer accepting applications As a Senior Security Engineer, you will define a risk-driven security roadmap, design security features, and advise stakeholders on risks across product and infrastructure. You will conduct security reviews, support audits and testing, and manage vulnerability remediation end-to-end. You will also improve monitoring and detection, handle incident response, and develop automation to enhance security operations. Senior Security Engineer Analog | UAE | On-site – No longer accepting applications As a Senior Security Engineer, you will define security strategy and roadmap aligned with business goals, and design security architectures across cloud, on-premises, and hybrid environments. You will develop and enforce security policies and standards, and conduct risk assessments, threat modeling, and vulnerability management. Senior Security Operations Analyst Gong | Ireland | On-site – No longer accepting applications As a Senior Security Operations Analyst, you will lead incident response, manage security events, and conduct proactive threat hunting. You will build automation and SOAR workflows, secure AWS, GCP, and Azure environments, and monitor for threats. Software Engineer, Security Engineering Opendoor | Canada | On-site – No longer accepting applications As a Software Engineer, Security Engineering, you will build systems and AI agents that secure infrastructure, protect sensitive data, and enable safe real estate transactions. You will design secure workflows and CI/CD pipelines, apply threat modeling and risk management, and establish modern security patterns for AI-driven engineering. You will also mentor engineers and promote best practices across security, software development, and AI. Vehicle Cyber Security Systems Engineer Ford Motor Company | USA | Hybrid – No longer accepting applications As a Vehicle Cyber Security Systems Engineer, you will perform cybersecurity assessments across multiple Ford Motor Company product lines and ensure compliance with standards such as ISO 21434, UNECE R155, and UNECE WP.29. You will review technical documentation, manage cybersecurity requirements throughout the product lifecycle, and work closely with feature and ECU owners to ensure security by design. You will also apply engineering practices including threat analysis, risk assessment, and security validation across vehicle systems.
helpnetsecurity.comApr 14, 2026extracted
Dozens of Vendors Patch Security Flaws Across Enterprise Software and Network Devices
SAP has released security updates to address two critical security flaws that could be exploited to achieve arbitrary code execution on affected systems. The vulnerabilities in question listed below - CVE-2019-17571 (CVSS score: 9.8) - A code injection vulnerability in SAP Quotation Management Insurance application (FS-QUO) CVE-2026-27685 (CVSS score: 9.1) - An insecure deserialization vulnerability in SAP NetWeaver Enterprise Portal Administration "The application uses an outdated artifact of Apache Log4j 1.2.17 that is vulnerable to CVE-2019-17571," SAP security company Onapsis said. "It allows an unprivileged attacker to execute arbitrary code remotely on the server, causing high impact on confidentiality, integrity, and availability of the application." CVE-2026-27685, on the other hand, stems from missing or insufficient validation during the deserialization of uploaded content, which could allow an attacker to upload untrusted or malicious content. "Only the fact that an attacker requires high privileges for a successful exploit prevents the vulnerability from being tagged with a CVSS score of 10," Onapsis added. The disclosure comes as Microsoft shipped patches for 84 vulnerabilities across products, including dozens of privilege escalation and remote code execution flaws. On Tuesday, Adobe also announced patches for 80 vulnerabilities, four of which are critical flaws impacting Adobe Commerce and Magento Open Source that could result in privilege escalation and security feature bypass. Separately, it fixed five critical vulnerabilities in Adobe Illustrator that could pave the way for arbitrary code execution. Elsewhere, Hewlett Packard Enterprise put out fixes for five shortcomings in Aruba Networking AOS-CX. The most severe of the flaws is CVE-2026-23813 (CVSS score: 9.8), an authentication bypass affecting the management interface. "A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls," HPE said. "In some cases, this could enable resetting the admin password." "Exploitation of this Aruba vulnerability potentially gives attackers full control of AOS-CX network devices and the ability to compromise an entire system undetected," Ross Filipek, CISO at Corsica Technologies, said in a statement. "A successful compromise could lead to the disruption of network communications or the erosion of the integrity of key business services. This flaw is a reminder that vulnerabilities in network devices are becoming more common in today's hyper-connected world. When attackers gain privileged access to these devices, it puts organizations at significant risk." Software Patches from Other Vendors Security updates have also been released by other vendors over the past few weeks to rectify several vulnerabilities, including — ABB Amazon Web Services AMD Arm Atlassian Bosch Broadcom (including VMware) Canon Cisco Commvault Dassault Systèmes Dell Devolutions Drupal Elastic F5 Fortinet Fortra Foxit Software GitLab Google Android and Pixel Google Chrome Google Cloud Google Pixel Watch Google Wear OS Grafana Hitachi Energy Honeywell HP HP Enterprise (including Aruba Networking and Juniper Networks) IBM Intel Ivanti Jenkins Lenovo Linux distributions AlmaLinux, Alpine Linux, Amazon Linux, Arch Linux, Debian, Gentoo, Oracle Linux, Mageia, Red Hat, Rocky Linux, SUSE, and Ubuntu MediaTek Mitsubishi Electric Moxa Mozilla Firefox, Firefox ESR, and Thunderbird n8n NVIDIA Palo Alto Networks QNAP Qualcomm Ricoh Samsung Schneider Electric ServiceNow Siemens SolarWinds Splunk Synology TP-Link Trend Micro WatchGuard Western Digital Zoom, and Zyxel
thehackernews.comMar 11, 2026extracted
ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Moxa, Mitsubishi Electric
Industrial giants Siemens, Schneider Electric, Mitsubishi Electric, and Moxa have published new Patch Tuesday advisories for vulnerabilities found recently in their ICS products. Siemens and Schneider Electric have each published six new advisories. Each of Schneider’s new advisories addresses one vulnerability. The company has informed customers about high-severity issues in EcoStruxure IT Data Center Expert (hardcoded credentials), EcoStruxure Power Monitoring Expert and Power Operation (local arbitrary code execution), and EcoStruxure Automation Expert (command execution and full system compromise). Medium-severity flaws have been patched by the company in Modicon controllers (DoS, account takeover via XSS) and EcoStruxure Foxboro DCS (remote code execution). Siemens has addressed a critical stored XSS vulnerability in Simatic S7-1500 devices, and a potentially severe misconfiguration in Mendix applications. Siemens has also informed customers about vulnerabilities introduced by the use of Fortinet, OpenSSL, and other third-party components. High- and medium-severity issues have been patched by Siemens in the Sicam Siapp SDK, and a low-severity vulnerability has been fixed in Heliox EV chargers. Mitsubishi Electric has published one new advisory to describe a remotely exploitable DoS vulnerability in its Numerical Control Systems, including C80, M800, M800V and M700V series products. Earlier this month the company informed customers about multiple remotely exploitable DoS flaws in MELSEC iQ-F Series controllers. Moxa has published four new advisories, including three describing the impact of vulnerabilities discovered in Intel products. The fourth advisory informs customers that Moxa products are not affected by a recent GNU Inetutils vulnerability. The cybersecurity agency CISA has also published ICS advisories this Patch Tuesday. The advisories inform the public about vulnerabilities in Ceragon Siklu MultiHaul and EtherHaul, Lantronix EDS3000PS and EDS5000, and Apeman cameras. CISA has also published an advisory for a recently disclosed Honeywell building controller vulnerability. The vendor and the researcher who found the flaw have clashed over its impact. Germany’s VDE-CERT has published advisories for Codesys, Janitza, and Weidmueller product vulnerabilities. Some of the Janitza and Weidmueller flaws can be exploited by remote, unauthenticated attackers to fully compromise the targeted system.
securityweek.comMar 11, 2026extracted
Rockwell Vulnerability Allowing Remote ICS Hacking Exploited in Attacks
An old vulnerability affecting industrial control system (ICS) products from Rockwell Automation has been exploited in attacks, according to the vendor and the cybersecurity agency CISA. CISA added the flaw, tracked as CVE-2021-22681, to its Known Exploited Vulnerabilities (KEV) catalog on Thursday, instructing federal agencies to address it by March 26. The security hole affects the Studio 5000 Logix Designer software and several Logix programmable logic controllers (PLCs), including CompactLogix, ControlLogix, DriveLogix, FlexLogix, GuardLogix, and SoftLogix devices. CVE-2021-22681 was disclosed in February 2021, when the vendor announced mitigations and credited Soonchunhyang University in South Korea, Kaspersky, and Claroty for reporting it. Claroty said at the time that it had reported the issue to Rockwell in 2019. The vulnerability, related to an insufficiently protected cryptographic key, could allow a remote, unauthenticated attacker to bypass verification and connect to a targeted controller by mimicking an engineering workstation. In a real-world industrial environment, the vulnerability could allow remote attackers to manipulate PLC logic and disrupt manufacturing processes, or even cause physical damage to equipment. Rockwell updated its initial advisory on Thursday to mention in-the-wild exploitation of CVE-2021-22681, but the company has not shared any information about the attacks. SecurityWeek has reached out to Rockwell for comment and will update this article if the company responds. A Shodan search currently shows nearly 6,000 internet-exposed Rockwell devices, but it’s unclear how many may be affected by CVE-2021-22681. It’s worth noting that Rockwell issued a security notice in 2024, urging customers to ensure their ICS devices are not connected to the internet. One of the vulnerabilities highlighted in that alert was CVE-2021-22681, which indicates that the vendor did not rule out malicious exploitation. In 2023, Rockwell and CISA warned that an unnamed APT had developed an exploit for a different Rockwell controller vulnerability (CVE-2023-3595), which could be exploited to cause disruption or destruction, but there had been no evidence of actual attacks. Currently, CVE-2021-22681 is the only Rockwell product vulnerability in CISA’s KEV catalog. Related: 3 Threat Groups Started Targeting ICS/OT in 2025: Dragos Related: Honeywell, Researcher Clash Over Impact of Building Controller Vulnerability Related: Critical Flaws Exposed Gardyn Smart Gardens to Remote Hacking
securityweek.comMar 6, 2026extracted
Critical FreeScout Vulnerability Leads to Full Server Compromise
A critical-severity vulnerability in the open source help desk and shared mailbox solution FreeScout can be exploited in zero-click remote code execution (RCE) attacks, Ox Security warns. Tracked as CVE-2026-28289 (CVSS score of 10/10), the security defect is a patch bypass for CVE-2026-27636, a recently fixed high-severity authenticated RCE bug. The initial issue, described as a missing .htaccess in the file upload restriction list, could allow an authenticated attacker to upload a .htaccess file, tampering with file processing and achieving RCE. The patch for the initial CVE, Ox discovered, can be bypassed using a zero-width space character, which is invisible and passes the dot-check, resulting in a valid .htaccess filename being saved to disk. According to the FreeScout maintainers, CVE-2026-28289 is a Time-of-Check to Time-of-Use (TOCTOU) issue in the filename sanitization function, “where the dot-prefix check occurs before sanitization removes invisible characters”. The fix for CVE-2026-27636 attempted to block filenames that have restricted file extensions or that begin with a period (“.”) by appending an underscore to the file extension. To bypass the patch, an attacker prepends a zero-width space character (Unicode U+200B) to the filename. Because the character is not treated as visible content, the filename bypasses validation, the U+200B character is stripped, and the file is saved as a true dotfile. “The attack works by sending a malicious email from any address to a mailbox configured in FreeScout. Importantly, this requires no authentication and no user interaction. The malicious payload is written to disk on the FreeScout server and can then be leveraged to execute commands remotely,” Ox explains. An attacker, the cybersecurity firm notes, can predict where the file will be saved on the disk, which allows them to access the payload and execute commands on the server. Successful exploitation of the new vulnerability could allow attackers to take full control of vulnerable servers, exfiltrate helpdesk tickets, mailbox content, and other sensitive data from FreeScout, and potentially move laterally to other systems on the network. “All FreeScout 1.8.206 installations are affected when running on Apache with AllowOverride All enabled (a common configuration),” FreeScout’s maintainers explain. CVE-2026-28289 was resolved in FreeScout version 1.8.207. Users are advised to update their deployments as soon as possible. Related: VMware Aria Operations Vulnerability Exploited in the Wild Related: Honeywell, Researcher Clash Over Impact of Building Controller Vulnerability Related: Vulnerability in MS-Agent AI Framework Can Allow Full System Compromise Related: Vulnerability Allowed Hijacking Chrome’s Gemini Live AI Assistant
securityweek.comMar 4, 2026extracted
Honeywell, Researcher Clash Over Impact of Building Controller Vulnerability
A researcher claims to have identified a high-risk vulnerability in a Honeywell building management controller, but the vendor disputes the severity and impact of the findings. Cybersecurity researcher Gjoko Krstic, known in the industry for his analysis of building control systems and the discovery of high-impact vulnerabilities, recently investigated Honeywell’s IQ4 controller. According to Krstic, the product exposes its web-based human-machine interface (HMI) without authentication in its factory-default configuration. The researcher also found that if the product is not properly configured and a user module is not enabled during setup, a remote attacker who has access to the management interface can create an account with administrator permissions, before legitimate users set up their accounts. “This action can effectively lock legitimate operators out of local and web-based configuration and administration,” Krstic said in an advisory published this week. The researcher warned that the vulnerability could expose schools, commercial buildings, and other facilities that use the building control system. The findings were reported to Honeywell in December 2025, but the vendor is apparently not releasing any patches, arguing that the IQ4 product is designed for on-premises use and should not be exposed to the internet. “IQ4 devices are delivered unconfigured and are set up by trained technicians before they become operational,” Honeywell said in a statement to SecurityWeek. “The scenario described by the researcher could only occur during a brief installation phase, before the system is active, or if security settings were deliberately disabled against clear warnings.” “At that stage, the device cannot monitor or control any equipment, and there is no impact on operations. Any installation issue can be resolved through a standard reset, and when installed using normal processes, security is automatically enabled as part of a secure‑by‑default design,” Honeywell added. However, the researcher disagrees with this statement and Honeywell’s risk assessment. Krstic said he identified nearly 7,500 internet-exposed instances of the product, and an estimated 20% can be accessed without authentication. The researcher also disputes Honeywell’s claims that the device cannot monitor or control any equipment if it’s not fully set up. “I’ve seen installations where the user account has not been created and I was able to write changes to components like lighting and temperature, turn off the boiler or chiller, and other operations on control equipment,” Krstic told SecurityWeek. SecurityWeek can confirm that many IQ4 interface instances are exposed to the internet, but has not verified the other claims. Krstic said a CVE for the vulnerability is pending. The researcher recently also reached out to the CERT Coordination Center (CERT/CC) at Carnegie Mellon University, which often mediates vulnerability disclosures. Threat actors often target building automation systems in their attacks, according to cybersecurity firms. Related: Critical Flaws Exposed Gardyn Smart Gardens to Remote Hacking Related: 3 Threat Groups Started Targeting ICS/OT in 2025: Dragos Related: Cyber Insights 2026: The Ongoing Fight to Secure Industrial Control Systems
securityweek.comMar 3, 2026extracted
Critical infra Honeywell CCTVs vulnerable to auth bypass flaw
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a critical vulnerability in multiple Honeywell CCTV products that allows unauthorized access to feeds or account hijacking. Discovered by researcher Souvik Kanda and tracked as CVE-2026-1670, the security issue is classified as “missing authentication for critical function,” and received a crtical severity score of 9.8. The flaw allows an unauthenticated attacker to change the recovery email address associated with a device account, enabling account takeover and unauthorized access to camera feeds. “The affected product is vulnerable to an unauthenticated API endpoint exposure, which may allow an attacker to remotely change the "forgot password" recovery email address,” CISA says. According to the security advisory, CVE-2026-1670 impacts the following models: I-HIB2PI-UL 2MP IP 6.1.22.1216 SMB NDAA MVO-3 WDR_2MP_32M_PTZ_v2.0 PTZ WDR 2MP 32M WDR_2MP_32M_PTZ_v2.0 25M IPC WDR_2MP_32M_PTZ_v2.0 Honeywell is a major global supplier of security and video surveillance equipment with a broad range of CCTV camera models and related products deployed in commercial, industrial, and critical infrastructure settings worldwide. The company offers many NDAA-compliant cameras that are suitable for deployment in U.S. government agencies and federal contractors. The specific model families named in CISA’s advisory are mid-level video surveillance products used in small to medium business environments, offices, and warehouses, some of which may be part of critical facilities. CISA stated that as of February 17th there were no known reports of public exploitation specifically targeting this vulnerability. Nonetheless, the agency recommends minimizing network exposure of control system devices, isolating them behind firewalls, and using secure remote access methods such as updated VPN solutions when remote connectivity is necessary. Honeywell has not published an advisory on CVE-2026-1670, but users are advised to contact the company’s support team for patch guidance. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comFeb 18, 2026extracted
Bug critico nelle telecamere Honeywell: rischio di compromissione totale. Il CISA Avverte
Betti RHC, la prima graphic novel al mondo dedicata alla cybersecurity awareness, ha finalmente il suo sito ufficiale. Uno spazio tutto suo dove scoprire il progetto, sfogliare le copertine degli episodi e immergersi nel mondo di Betti: la giovane laureanda in informatica che, dopo la morte misteriosa del padre, si trasforma nell'hacker più potente del mondo. Una storia avvincente che, episodio dopo episodio, affronta una minaccia digitale diversa — dal phishing al ransomware, fino al cyberbullismo — e insegna a riconoscerla e a difendersi, senza che sembri mai una lezione. Sul sito trovate tutto ciò che rende Betti un progetto diverso dal solito: la sua filosofia, le anteprime delle tavole e il racconto di come nasce ogni volume. Perché dietro Betti RHC c'è solo lavoro umano: ogni tavola è disegnata interamente a mano dagli artisti del Gruppo Arte di Red Hot Cyber, senza alcun uso di intelligenza artificiale. E a garantire che ogni storia sia realistica e tecnicamente corretta c'è la supervisione degli hacker etici del gruppo HackerHood, che mantengono il racconto fedele al mondo reale della sicurezza informatica. C'è spazio anche per le aziende, che possono usare Betti come strumento di awareness diverso dai soliti corsi: acquistare i volumi, personalizzarli con il proprio brand o sponsorizzare nuovi episodi. E come primo regalo, l'episodio "Byte the Silence", dedicato al cyberbullismo, è scaricabile gratuitamente per uso personale. Perché la miglior difesa, in fondo, è una bella storia. 👉 Scopri tutto su https://betti.redhotcyber.com/
redhotcyber.comFeb 18, 2026extracted
ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Aveva, Phoenix Contact
Industrial giants Siemens, Schneider Electric, Phoenix Contact, and Aveva have published a dozen Patch Tuesday advisories to inform customers about vulnerabilities found in their ICS/OT products. Siemens has released five new advisories. Two of them describe the same critical authorization bypass flaw in Industrial Edge Devices that can be leveraged by an unauthenticated, remote attacker to bypass authentication and impersonate a user. One advisory covers Industrial Edge Devices, while the other is for the Industrial Edge Device Kit. The remaining advisories inform customers about the availability of fixes for high-severity vulnerabilities in Ruggedcom, ET 200SP, and TeleControl Server Basic products. Schneider Electric has published four new advisories. One of them describes a high-severity issue that can be leveraged for privilege escalation in EcoStruxure Process products. Another advisory describes one medium- and one high-severity flaw in EcoStruxure Power Build Rapsody. They can be exploited for arbitrary code execution using specially crafted files. The remaining advisories describe vulnerabilities in third-party components used by Schneider Electric products, specifically Zigbee and Redis. Phoenix Contact has released an advisory to inform customers about a high-severity command injection issue that can be exploited by an attacker against TC Router and Cloud Client industrial routers. Exploitation requires the attacker to have elevated privileges on the targeted system, or they need trick the victim into uploading a malicious payload. Germany’s VDE CERT has also published a version of Phoenix Contact’s advisory. Aveva has published an advisory describing seven types of vulnerabilities in Process Optimization (formerly ROMeo). The security holes, rated high and critical severity, can be exploited for remote code execution, privilege escalation, and to obtain sensitive data. Honeywell has released security advisories for its Pro-Watch and Maxpro building security and video management products. The advisories mostly focus on Windows patches released by Microsoft. The cybersecurity agency CISA has published ICS advisories for Rockwell Automation vulnerabilities disclosed by the vendor in December 2025, as well as for three flaws found in the YoSmart YoLink Smart Hub. A few days before Patch Tuesday, ABB published an advisory to inform customers about three flaws that can lead to authentication bypass and DoS in its WebPro SNMP Card PowerValue product. Related: ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Rockwell, Schneider
securityweek.comJan 15, 2026extracted
ownCloud urges users to enable MFA after credential theft reports
File-sharing platform ownCloud warned users today to enable multi-factor authentication (MFA) to block attackers using compromised credentials from stealing their data. ownCloud has over 200 million users worldwide, including hundreds of enterprise and public-sector organizations such as the European Organization for Nuclear Research, the European Commission, German tech company ZF Group, insurance firm Swiss Life, and the European Investment Bank. In a security advisory published today, the company urged users to enable MFA following a recent report from Israeli cybersecurity company Hudson Rock, which revealed that multiple organizations had their self-hosted file sharing platforms (including some ownCloud Community Edition instances) breached in credential theft attacks. "The ownCloud platform was not hacked or breached. The Hudson Rock report explicitly confirms that no zero-day exploits or platform vulnerabilities were involved," ownCloud said. "The incidents occurred through a different attack chain: threat actors obtained user credentials via infostealer malware (such as RedLine, Lumma, or Vidar) installed on employee devices. These credentials were then used to log in to ownCloud accounts that did not have Multi-Factor Authentication (MFA) enabled." ownCloud advised users to immediately enable MFA on their ownCloud instance to secure their data against future attacks and prevent unauthorized access even when their credentials are compromised. Additionally, ownCloud recommends resetting all user passwords, invalidating all active sessions to force re-authentication, and reviewing access logs for suspicious login activity. This warning comes after a threat actor (known as Zestix) has been offering to sell corporate data stolen from dozens of companies, likely obtained after breaching their ShareFile, Nextcloud, and ownCloud instances. In its January 5th report, Hudson Rock says the attackers may have obtained initial access to the companies' file-sharing servers using credentials stolen by infostealer malware such as RedLine, Lumma, and Vidar, which infected employee devices. The cybercrime intelligence firm identified thousands of infected computers, including some on the networks of high-profile organizations like Deloitte, KPMG, Samsung, Honeywell, Walmart, and the U.S. CDC (Centers for Disease Control and Prevention). Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJan 7, 2026extracted
Dozens of Major Data Breaches Linked to Single Threat Actor
Several major data breaches are linked to a threat actor who relies on stolen credentials to compromise enterprise networks, Hudson Rock reports. Operating under the moniker ‘Zestix’ but also linked to the online persona ‘Sentap’, the threat actor is an initial access broker (IAB) who was also seen exfiltrating victim data and selling it on hacker forums. According to Hudson Rock, Zestix emerged as a distinct entity in late 2024-early 2025, but its activities can be linked to Sentap operations that have been ongoing since 2021. Both personas can be linked to information-stealer infections resulting in the compromise of global enterprises operating in the aerospace, government infrastructure, legal, and robotics sectors. The credentials, Hudson Rock says, were harvested from the personal or work devices of employees at the victim organizations using information stealers such as RedLine, Lumma, and Vidar. “While some credentials were harvested from recently infected machines, others had been sitting in logs for years, waiting for an actor like Zestix to exploit them,” Hudson Rock notes. The lack of multi-factor authentication (MFA) protections on accounts with access to file-transfer instances such as ShareFile, OwnCloud, and Nextcloud has allowed Zestix/Sentap to use the compromised credentials successfully on roughly 50 occasions. The exfiltrated data is then offered for sale on closed Russian-language forums, but Zestix was also seen selling access to the compromised systems. Zestix/Sentap victims According to Hudson Rock, Zestix has established a reputation for reliability. This explains why they were asking $150,000 for the 77 GB of data allegedly stolen from Iberia, the Spanish flag carrier. Other victims include Pickett & Associates (an engineering firm serving energy organizations), Intecro Robotics (aerospace and defense equipment maker), Maida Health (serves the Brazilian military police), CRRC MA (rolling stock maker subsidiary), K3G (Brazilian ISP), NMCV Business LLC (manages data for US healthcare facilities), and over a dozen others. Under the Sentap moniker, the threat actor built a wider list of victims, but Hudson Rock says it could not link these breaches to file-sharing services or infostealer infections. “It is possible that they still stem from similar Infostealer credentials based on the high number of victims we did identify to have infostealer credentials to those services, but we do not rule out access via another initial access,” Hudson Rock says. The threat actor has claimed massive breaches at Pan-Pacific Mechanical (1.04 TB), Bradley R. Tyer & Associates (1.02 TB), The Providence Group (1 TB), Australian NBN (306 GB), UrbanX.io (275 GB), and dozens of others. The infostealer problem According to Hudson Rock, credentials pertaining to thousands of organizations that use ShareFile, OwnCloud, and Nextcloud are circulating in infostealer logs, including those of prominent names such as Deloitte, Honeywell, KPMG, Samsung, and Walmart. “These organizations have employees or partners who have been infected, leaving valid sessions or credentials to sensitive file repositories exposed to actors like Zestix,” the cybersecurity firm notes. The issue, however, has been around for a long time and is unlikely to be easily resolved. The information stealer industry is fueling modern cybercrime, acting as the starting point for data breaches, identity theft, and fraud. “Stealers are an example of the commodification of cybercrime delivered through malware-as-a-service (MaaS),” SpyCloud Labs SVP of security research Trevor Hilligoss said in a discussion with SecurityWeek. “You no longer need to be a skilled developer or hacker to gain access to tools that are incredibly effective when deployed at scale. Anyone can just buy or hire readymade malware from the MaaS marketplace,” Hilligoss added. The success of information stealers builds on speed and stealth. They exfiltrate sensitive information in minutes and are often removed from the infected devices immediately after, leaving minimal traces of wrongdoing. And for over a decade, stolen credentials have fueled massive attack campaigns, including credential stuffing attacks, which continue to be a problem. Related: NordVPN Denies Breach After Hacker Leaks Data Related: Brightspeed Investigating Cyberattack Related: Sedgwick Confirms Cyberattack on Government Subsidiary Related: Thousands of Secrets Leaked on Code Formatting Platforms
securityweek.comJan 6, 2026extracted
Cloud file-sharing sites targeted for corporate data theft attacks
A threat actor known as Zestix has been offering to sell corporate data stolen from dozens of companies likely after breaching their ShareFile, Nextcloud, and OwnCloud instances. According to cybercrime intelligence company Hudson Rock, initial access may have been obtained through credentials collected by info-stealing malware such as RedLine, Lumma, and Vidar deployed on employee devices. The three infostealers are usually distributed through malvertising campaigns or ClickFix attacks. This type of malware commonly targets data stored by web browsers (credentials, credit cards, personal info), messaging apps, and cryptocurrency wallets. A threat actor with valid credentials can gain unauthorized access to a service, such as a file-sharing platforms, when multi-factor authentication (MFA) protection is missing. In a report today, Hudson Rock notes that some of the analyzed stolen credentials have been present in criminal databases for years, indicating failure to rotate them or to invalidate active sessions even after extended periods. Multiple breaches advertised Hudson Rock says that Zestix operates as an initial access broker (IAB) on underground forums, selling access to high-value corporate cloud platforms. The cybersecurity company suggest that attackers breached ShareFile, Nextcloud, and ownCloud environments used by organizations across multiple sectors, including aviation, defense, healthcare, utilities, mass transit, telecommunications, legal, real estate, and government. After parsing infostealer logs "specifically looking for corporate cloud URLs (ShareFile, Nextcloud)," the threat actor logs into the file-sharing services using a valid username and password where MFA is not active. Hudson Rock says it pinpointed the likely breach points by correlating infostealer data from its platform with publicly available images, metadata, and open-source information. In at least 15 of the analyzed cases, the cybersecurity company found that employee credentials for the cloud file-sharing services had been collected by infostealers. It is important to note that this verification is unilateral, and there’s no public confirmation of a security breach from the listed companies. One exception could be Iberia, although its recent disclosure isn't necessarily linked to Hudson Rock's findings. Zestix offered to sell stolen data volumes that range from tens of gigabytes to several terabytes, claiming to include aircraft maintenance manuals and fleet data, defense and engineering files, customer databases, health records, mass-transit schematics, utility LiDAR maps, ISP network configs, satellite project data, ERP source code, government contracts, and legal documents. Many of the allegedly stolen files could expose organizations to security, privacy, and industrial espionage risks, while exposed government contracts may raise national security concerns. Hudson Rock has found an additional set of 30 victims that Zestix sells under the alias “Sentap,” but the researchers did not validate it in the same way. The researchers report that, in addition to the listed victims, their threat intelligence data indicates that cloud exposure is a broader, systemic problem stemming from organizations’ failure to follow good security practices. They report having identified thousands of infected computers, including some at Deloitte, KPMG, Samsung, Honeywell, and Walmart. Hudson Rock told BleepingComputer that it has notified ShareFile and will also alert Nextcloud and OwnCloud about the verified exposures so they can take the appropriate action. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJan 5, 2026extracted
ICS Patch Tuesday: Vulnerabilities Addressed by Siemens, Rockwell, Aveva, Schneider
Industrial giants Siemens, Schneider Electric, Rockwell Automation, and Aveva have released Patch Tuesday advisories informing customers about vulnerabilities in their ICS/OT products. Siemens published six new advisories. One of them covers two vulnerabilities in the Comos plant engineering software, including a critical code execution flaw, and a high-severity security bypass issue. Vulnerabilities have also been addressed in Siemens Solid Edge (remote MitM, code execution), Altair Grid Engine (code execution), Logo! 8 BM (code execution, DoS, settings tampering), and Sicam P850 (CSRF) products. Rockwell Automation published five new advisories on November 11, each covering high-severity vulnerabilities found in various products. The company informed customers of its Verve Asset Manager OT security platform that the product is affected by a high-severity access control issue that allows unauthorized read-only users to tamper with other user accounts via an API. In the Studio 5000 integrated design environment for Logix 5000 controllers, Rockwell fixed an SSRF flaw exposing NTLM hashes, as well as a local code execution bug. MFA bypass and persistent XSS vulnerabilities have been patched in FactoryTalk DataMosaix Private Cloud. In addition, flaws introduced by the use of third-party components have been fixed in SIS Workstation (code execution) and FactoryTalk Policy Manager (DoS). Aveva published two new advisories on Tuesday. One of them describes a high-severity persistent XSS flaw that can be exploited for privilege escalation. The second advisory covers an Aveva Edge vulnerability that allows an attacker with read access to project and cache files to obtain user passwords by brute-forcing weak hashes. This vulnerability also impacts Schneider Electric’s EcoStruxure Machine SCADA Expert & Pro-face BLUE Open Studio products. Schneider published two new advisories this Patch Tuesday and one of them covers the impact of this flaw. Schneider’s second advisory describes high-severity path traversal, authentication brute-forcing, and privilege escalation issues in the PowerChute Serial Shutdown UPS management software. Moxa, ABB, Honeywell, and Mitsubishi Electric did not publish any advisories on Patch Tuesday, but they all informed customers about fixed vulnerabilities in the preceding days. Germany’s VDE@CERT also published two advisories in recent days. Related: ICS Patch Tuesday: Rockwell Automation Leads With 8 Security Advisories
securityweek.comNov 12, 2025extracted
SecurityWeek to Host 2025 ICS Cybersecurity Conference October 27-30 in Atlanta
SecurityWeek will host the 2025 Industrial Control Systems (ICS) Cybersecurity Conference from October 27 – 30, 2025 at the InterContinental Atlanta Buckhead. With 75+ sessions over three days, the conference brings together hundreds of critical infrastructure stakeholders to explore cutting-edge strategies and solutions to fortify operational technology (OT) environments and enhance resilience against cyber threats. Now in its 24th year, the conference is known for its powerful community of cybersecurity experts, researchers, engineers, and OT asset owners who gather annually to share insights, network, and shape the future of industrial cybersecurity. The conference will also feature a capture the flag (CTF) competition in partnership with ICS Village. In addition to three full days of conference sessions, delegates can choose from five optional ICS cybersecurity training classes and cyber defense exercises, including: Cyber Attack Methods for Cyber-Physical Systems (3-Day Course) Applied ICS Security Training Lab (One Day) ICS/OT Cybersecurity Incident Preparedness & Response Workshop (One Day) Industrial Cybersecurity Launchpad (One Day) Cyber Attack Methods (CAM) Short Course (1/2 Day) The ICS Cybersecurity Conference focuses on safeguarding critical components, including SCADA systems, plant control systems, engineering workstations, substation equipment, programmable logic controllers (PLCs), and other essential field devices. Conference sessions will include both technical and strategy sessions, along with advanced ICS cybersecurity research from national labs, world-renowned researchers, and numerous OT asset owners from large organizations. Online registration is open for the conference and training sessions. Press registration is available for qualified journalists. Sponsors include Cisco (NASDAQ: CSCO), Fortinet (NASDAQ: FTNT), Honeywell (NASDAQ: HON), Rockwell Automation (NYSE: ROK), Nozomi Networks, TXONet Networks, Claroty, Keystrike, SSH, MorganFranklin Consulting, Corsha, Interstates, SUBNET Solutions, Tosi, OWL Cyber Defense, Xona, Dispel, Cyber Realm Solutions, Hillstrong Security, and Fortiphyd Logic. Learn More: Social Media: #ICSCC25, X: @SecurityWeek LinkedIn: https://www.linkedin.com/company/securityweek/ Web: https://www.icscybersecurityconference.com/
securityweek.comOct 15, 2025extracted
Two New Windows Zero-Days Exploited in the Wild — One Affects Every Version Ever Shipped
Microsoft on Tuesday released fixes for a whopping 183 security flaws spanning its products, including three vulnerabilities that have come under active exploitation in the wild, as the tech giant officially ended support for its Windows 10 operating system unless the PCs are enrolled in the Extended Security Updates (ESU) program. Of the 183 vulnerabilities, eight of them are non-Microsoft issued CVEs. As many as 165 flaws have been rated as Important in severity, followed by 17 as Critical and one as Moderate. The vast majority of them relate to elevation of privilege vulnerabilities (84), with remote code execution (33), information disclosure (28), spoofing (14), denial-of-service (11), and security feature bypass (11) issues accounting for the rest. The updates are in addition to the 25 vulnerabilities Microsoft addressed in its Chromium-based Edge browser since the release of September 2025's Patch Tuesday update. The two Windows zero-days that have come under active exploitation are as follows - CVE-2025-24990 (CVSS score: 7.8) - Windows Agere Modem Driver ("ltmdm64.sys") Elevation of Privilege Vulnerability CVE-2025-59230 (CVSS score: 7.8) - Windows Remote Access Connection Manager (RasMan) Elevation of Privilege Vulnerability Microsoft said both issues could allow attackers to execute code with elevated privileges, although there are currently no indications on how they are being exploited and how widespread these efforts may be. In the case of CVE-2025-24990, the company said it's planning to remove the driver entirely, rather than issue a patch for a legacy third-party component. The security defect has been described as "dangerous" by Alex Vovk, CEO and co-founder of Action1, as it's rooted within legacy code installed by default on all Windows systems, irrespective of whether the associated hardware is present or in use. "The vulnerable driver ships with every version of Windows, up to and including Server 2025," Adam Barnett, lead software engineer at Rapid7, said. "Maybe your fax modem uses a different chipset, and so you don't need the Agere driver? Perhaps you've simply discovered email? Tough luck. Your PC is still vulnerable, and a local attacker with a minimally privileged account can elevate to administrator." According to Satnam Narang, senior staff research engineer at Tenable, CVE-2025-59230 is the first vulnerability in RasMan to be exploited as a zero-day. Microsoft has patched more than 20 flaws in the component since January 2022. The third vulnerability that has been exploited in real-world attacks concerns a case of Secure Boot bypass in IGEL OS before 11 (CVE-2025-47827, CVSS score: 4.6). Details about the flaw were first publicly disclosed by security researcher Zack Didcott in June 2025. "The impacts of a Secure Boot bypass can be significant, as threat actors can deploy a kernel-level rootkit, gaining access to the IGEL OS itself and, by extension, then tamper with the Virtual Desktops, including capturing credentials," Kev Breen, senior director of threat research at Immersive, said. "It should be noted that this is not a remote attack, and physical access is typically required to exploit this type of vulnerability, meaning that 'evil-maid' style attacks are the most likely vector affecting employees who travel frequently." All three issues have since been added to the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to apply the patches by November 4, 2025. Some other critical vulnerabilities of note include a remote code execution (RCE) bug (CVE-2025-59287, CVSS score: 9.8) in Windows Server Update Service (WSUS), an out-of-bounds read vulnerability in the Trusted Computing Group (TCG) TPM2.0 reference implementation's CryptHmacSign helper function (CVE-2025-2884, CVSS score: 5.3), and an RCE in Windows URL Parsing (CVE-2025-59295, 8.8). "An attacker can leverage this by carefully constructing a malicious URL," Ben McCarthy, lead cybersecurity engineer at Immersive, said about CVE-2025-59295. "The overflowed data can be designed to overwrite critical program data, such as a function pointer or an object's virtual function table (vtable) pointer." "When the application later attempts to use this corrupted pointer, instead of calling a legitimate function, it redirects the program's execution flow to a memory address controlled by the attacker. This allows the attacker to execute arbitrary code (shellcode) on the target system." Two vulnerabilities with the highest CVSS score in this month's update relate to a privilege escalation flaw in Microsoft Graphics Component (CVE-2025-49708, CVSS score: 9.9) and a security feature bypass in ASP.NET (CVE-2025-55315, CVSS score: 9.9). While exploiting CVE-2025-55315 requires an attacker to be first authenticated, it can be abused to covertly get around security controls and carry out malicious actions by smuggling a second, malicious HTTP request within the body of their initial authenticated request. "An organization must prioritize patching this vulnerability because it invalidates the core security promise of virtualization," McCarthy explained regarding CVE-2025-49708, characterizing it as a high-impact flaw that leads to a full virtual machine (VM) escape. "A successful exploit means an attacker who gains even low-privilege access to a single, non-critical guest VM can break out and execute code with SYSTEM privileges directly on the underlying host server. This failure of isolation means the attacker can then access, manipulate, or destroy data on every other VM running on that same host, including mission-critical domain controllers, databases, or production applications." Software Patches from Other Vendors In addition to Microsoft, security updates have also been released by other vendors over the past several weeks to rectify several vulnerabilities, including — Adobe Amazon Web Services AMD AMI Apple ASUS Axis Communications Broadcom (including VMware) Canon Check Point Cisco D-Link Dell Drupal Elastic F5 Fortinet Foxit Software FUJIFILM Gigabyte GitLab Google Chrome Google Cloud Google Pixel Watch Grafana Hitachi Energy HMS Networks (including Red Lion) Honeywell HP HP Enterprise (including Aruba Networking and Juniper Networks) IBM Ivanti Jenkins Lenovo Linux distributions AlmaLinux, Alpine Linux, Amazon Linux, Arch Linux, Debian, Gentoo, Oracle Linux, Mageia, Red Hat, Rocky Linux, SUSE, and Ubuntu MediaTek Mitsubishi Electric MongoDB Moodle Moxa Mozilla Firefox, Firefox ESR, and Thunderbird NVIDIA Oracle Palo Alto Networks Progress Software QNAP Qualcomm Ricoh Rockwell Automation Salesforce Samsung SAP Schneider Electric ServiceNow Siemens SolarWinds SonicWall Splunk Spring Framework Supermicro Synology TP-Link Unity Veeam, and Zoom
thehackernews.comOct 15, 2025extracted
NIST Publishes Guide for Protecting ICS Against USB-Borne Threats
NIST has published a new guide designed to help organizations reduce cybersecurity risks associated with the use of removable media devices in operational technology (OT) environments. NIST Special Publication (SP) 1334 was authored by the National Cybersecurity Center of Excellence (NCCoE) and it focuses on the use of USB flash drives, but also mentions other types of removable media such as external hard drives and CD/DVD drives. USB flash drives are often used in OT environments to conduct firmware updates or to retrieve data for diagnostics purposes, but such devices are also often a source of malware infections. While the cybersecurity industry has long warned organizations about the security risks, the use of USB drives in OT environments still poses a significant threat to industrial control systems (ICS) and recent research has shown that while such drives typically carry commodity malware, threats are becoming increasingly sophisticated and targeted at OT. “If a USB device is infected with malware, it can spread to the industrial control system and cause problems, such as disrupting operations or compromising safety,” NIST warned. NIST SP 1334 condenses all relevant information on protecting ICS against USB-borne threats into a two-page document. The guide covers four aspects: procedural controls, physical controls, technical controls, and transportation and sanitization. In terms of procedural controls, the guide advises organizations to develop policies for purchasing, authorizing and managing devices they own, and to consider all other devices as untrusted. The acquired devices should adhere to modern security standards and their use should be limited to specific personnel and purposes. As for physical controls, devices should be stored in a physically secure location, and they should be inventoried and labeled. The section of NIST’s guide on technical controls recommends disabling unnecessary ports to prevent unauthorized use, scanning devices for malware before and after use, disabling autorun, encrypting data stored on portable storage media, and enabling write-protection when possible. The agency also recommends having procedures in place for transporting devices within and between organizations, and performing data sanitization prior to the disposal of the device. Companies such as Honeywell have been offering dedicated cybersecurity solutions designed to protect industrial facilities from USB-borne threats. Related: New Guidance Calls on OT Operators to Create Continually Updated System Inventory Related: No Patches for Vulnerabilities Allowing Cognex Industrial Camera Hacking Related: Unpatched Vulnerabilities Expose Novakon HMIs to Remote Hacking
securityweek.comOct 1, 2025extracted
Mitsubishi Electric acquisisce Nozomi Networks per 1 miliardo di dollari. La storia dell’azienda nata a Varese
Nozomi, fondata da Andrea Carcano e Moreno Carullo, diventerà una controllata interamente posseduta da Mitsubishi Electric, pur mantenendo la propria indipendenza operativa. Il colosso industriale giapponese Mitsubishi Electric ha annunciato l’acquisizione della società di cybersicurezza Nozomi Networks in un’operazione dal valore di circa 1 miliardo di dollari. Nozomi diventerà una controllata interamente posseduta da Mitsubishi Electric, pur mantenendo la propria indipendenza operativa. La transazione comprende 883 milioni di dollari in contanti oltre a precedenti partecipazioni azionarie. Nozomi aveva raccolto 100 milioni di dollari in un round di finanziamento Serie E nel 2024, a cui avevano partecipato attori di primo piano dell’Operational Technology (OT), tra cui Mitsubishi Electric e Schneider Electric. Tra gli investitori precedenti figuravano Honeywell, il fondo di venture capital della CIA In-Q-Tel e Johnson Controls. L’amministratore delegato Edgard Capdevielle ha dichiarato che la società continuerà a fornire servizi anche agli investitori preesistenti e ad altre aziende dopo il completamento dell’operazione, previsto per il quarto trimestre. Capdevielle ha sottolineato che Nozomi resterà “vendor-agnostic” nonostante la nuova proprietà. Mitsubishi Electric – Nozomi Networks: una delle operazioni più rilevanti nella cybersicurezza industriale Si tratta di una delle operazioni più rilevanti finora nel campo della cybersicurezza industriale, un settore in forte crescita che riguarda la protezione delle infrastrutture critiche come impianti idrici, centrali elettriche e gasdotti. L’aumento degli attacchi da parte di avversari stranieri ha accresciuto l’attenzione sulla vulnerabilità dei sistemi industriali. Secondo un rapporto pubblicato ad agosto da Dragos e Marsh McLennan, il rischio finanziario medio globale legato a cyberattacchi contro tecnologie operative potrebbe raggiungere i 31,1 miliardi di dollari nei prossimi 12 mesi. Le tensioni geopolitiche contribuiscono ad alimentare le preoccupazioni per la sicurezza delle infrastrutture industriali. Washington accusa da anni la Cina di infiltrazioni nelle reti di operatori critici e ha recentemente lanciato allarmi dopo attacchi a sistemi idrici statunitensi attribuiti a hacker legati all’Iran, in seguito al bombardamento di siti nucleari iraniani. La collaborazione tra Nozomi e Mitsubishi Electric si era già intensificata nel 2024 con il lancio di Arc, un sensore sviluppato congiuntamente per monitorare il traffico di rete nei sistemi Mitsubishi dedicati all’automazione industriale. Questi ambienti, basati su controllori logici programmabili, sono spesso incompatibili con i tradizionali software di cybersicurezza. “Abbiamo dimostrato di poter collaborare sia sul piano tecnico sia su quello commerciale, riuscendo anche a portare soluzioni congiunte sul mercato,” ha concluso Capdevielle. Nozomi Networks: l’azienda nata a Varese da due dottorandi Nozomi Networks nasce dieci anni fa a Varese dall’intuizione di Andrea Carcano e Moreno Carullo, due giovani ricercatori appassionati di cybersicurezza che hanno trasformato un’idea di dottorato in un’impresa globale. L’ispirazione arriva proprio dal percorso accademico di Carcano all’Università dell’Insubria, dove, studiando le vulnerabilità delle infrastrutture critiche, comprende che le tecnologie esistenti non erano sufficienti a difendere centrali elettriche, metropolitane e aeroporti da attacchi informatici. Da quel lavoro nasce il prototipo di un software che diventerà il cuore di Nozomi. Dopo un’esperienza professionale in Eni, Carcano decide di rischiare: lascia il posto sicuro, chiama Carullo e insieme avviano l’avventura imprenditoriale dalla casa dei genitori a Varese con un sogno preciso, portare la loro idea in Silicon Valley. È da lì che Nozomi cresce, fino a diventare un unicorno della cybersicurezza industriale, con 300 dipendenti, oltre 12 brevetti e clienti in tutto il mondo. Una “dual company” che conserva un’anima italiana, con ricerca e sviluppo realizzati soprattutto da ingegneri del nostro Paese, e un quartier generale a San Francisco. Una storia che dimostra come talento e visione possano trasformare una startup nata in provincia in un punto di riferimento mondiale.
cybersecitalia.itSep 11, 2025extracted
ICS Patch Tuesday: Rockwell Automation Leads With 8 Security Advisories
Several industrial control systems (ICS) giants have published new security advisories this Patch Tuesday, including Rockwell Automation, Siemens, Schneider Electric, and Phoenix Contact. Rockwell Automation published the highest number of new advisories this Patch Tuesday. The company released eight new advisories, all of them covering high-severity vulnerabilities found recently in the company’s products. Rockwell fixed a sensitive data exposure issue in FactoryTalk Analytics LogixAI, and DoS and code execution issues in ControlLogix controllers. It also addressed a remote code execution vulnerability in Stratix (Cisco) devices, a memory corruption in 1783-NATR, a SSRF issue in Automation ThinManager, a remote code execution flaw in FactoryTalk Optix, and a data exposure issue in FactoryTalk Activation Manager. Siemens has published seven new advisories. With a CVSS score of 9.3, one of the most serious issues impacts Simatic Virtualization as a Service and allows an attacker to access or alter sensitive data. Another vulnerability with a ‘critical’ severity rating impacts Siemens’ User Management Component (UMC) and it can be exploited for unauthenticated remote code execution or DoS attacks. Siemens also addressed high-severity issues in Simotion and Industrial Edge Management products. Advisories covering medium- and low-severity flaws have been published for Sinamics, Apogee PXC and Talon TC, and Sinec OS products. Schneider Electric published only two new advisories this Patch Tuesday. One of them covers two medium-severity OS command injection issues in Saitel DR & Saitel DP RTU products. The second advisory informs customers about an XSS flaw in Altivar products. Phoenix Contact has published two new advisories: one for two vulnerabilities in the Jq JSON processor used by FL Mguard, and one for a vulnerability introduced by the use of Wibu’s CodeMeter Runtime. Honeywell has published several advisories for building management products, including Maxpro and Pro-Watch NVR and VMS products. CISA has published nine new and five updated advisories. Of the new advisories, a vast majority cover the Rockwell Automation product vulnerabilities. One CISA advisory informs organizations about ABB product vulnerabilities. The vendor published its own advisory for the flaws, which impact its Aspect building management system, earlier this month. The issues were reported to ABB by researcher Gjoko Krstic, who in January claimed to have found over 1,000 vulnerabilities in ABB products. Germany’s CERT@VDE agency published seven new advisories this week, including for a critical Wago controller vulnerability that can be exploited without authentication for DoS attacks and to weaken credentials, resulting in default credentials being applied to the device. CERT@VDE’s advisories also cover two other Wago product vulnerabilities, two Bender Charge Controller issues, and the recently disclosed Phoenix Contact flaws. Related: ICS Patch Tuesday: Major Vendors Address Code Execution Vulnerabilities
securityweek.comSep 10, 2025extracted
ICS Patch Tuesday: Major Vendors Address Code Execution Vulnerabilities
August 2025 Patch Tuesday advisories have been published by several major companies offering industrial control system (ICS) and other operational technology (OT) solutions. Siemens has published 22 new advisories. One of them is for CVE-2025-40746, a critical Simatic RTLS Locating Manager issue that can be exploited by an authenticated attacker for code execution with System privileges. The company has also published advisories covering high-severity vulnerabilities in Comos (code execution), Siemens Engineering Platforms (code execution), Simcenter (crash or code execution), Sinumerik controllers (unauthorized remote access), Ruggedcom (authentication bypass with physical access), Simatic (code execution), Siprotect (DoS), and Opcenter Quality (unauthorized access). Siemens also addressed vulnerabilities introduced by the use of third-party components, including OpenSSL, Linux kernel, Wibu Systems, Nginx, Nozomi Networks, and SQLite. Medium- and low-severity issues have been resolved in Simotion Scout, Siprotec 5, Simatic RTLS Locating Manager, Ruggedcom ROX II, and Sicam Q products. As usual, Siemens has released patches for many of these vulnerabilities, but only mitigations or workarounds are available for some of the flaws. Schneider Electric has released five new advisories. One of them describes four high-severity vulnerabilities in EcoStruxure Power Monitoring Expert (PME), Power Operation (EPO), and Power SCADA Operation (PSO) products. Exploitation of the flaws can lead to arbitrary code execution or sensitive data exposure. In the Modicon M340 controller and its communication modules the industrial giant fixed a high-severity DoS vulnerability that can be triggered with specially crafted FTP commands, as well as a high-severity issue that can lead to sensitive information exposure or a DoS condition. In the Schneider Electric Software Update tool, the company patched a high-severity vulnerability that can allow an attacker to escalate privileges, corrupt files, obtain information, or cause a persistent DoS. Medium-severity issues that can lead to privilege escalation, DoS, or sensitive credential exposure have been patched in Saitel and EcoStruxure products. Honeywell has published six advisories focusing on building management products, including several advisories that inform customers about Windows patches for Maxpro and Pro-Watch NVR and VMS products. The company has also released advisories covering PW-series access controller patches and security enhancements. Aveva has published an advisory for two issues in its PI Integrator for Business Analytics. Two vulnerabilities have been patched: one arbitrary file upload issue that could lead to code execution, and a sensitive data exposure weakness. ABB told customers on Tuesday about several vulnerabilities affecting its Aspect, Nexus and Matrix products. Some of the flaws can be exploited without authentication for remote code execution, obtaining credentials, and to manipulate files and various components. Phoenix Contact has informed customers about a privilege escalation vulnerability in Device and Update Management. The company has described it as a misconfiguration that allows a low-privileged local user to execute arbitrary code with admin privileges. Germany’s CERT@VDE has also published a copy of the Phoenix Contact advisory. The US cybersecurity agency CISA has published three new advisories describing vulnerabilities in Santesoft Sante PACS Server, Johnson Controls iSTAR, and Ashlar-Vellum products. CISA has also distributed the Aveva advisory and one of the Schneider Electric advisories. A few days prior to Patch Tuesday, Rockwell Automation published an advisory informing customers about several high-severity code execution vulnerabilities affecting its Arena Simulation product. Also prior to Patch Tuesday, Mitsubishi Electric released an advisory describing an information tampering flaw in Genesis and MC Works64 products. Related: ICS Patch Tuesday: Vulnerabilities Addressed by Rockwell, ABB, Siemens, Schneider
securityweek.comAug 13, 2025extracted
OT Networks Targeted in Widespread Exploitation of Erlang/OTP Vulnerability
An Erlang/OTP vulnerability whose existence came to light in mid-April has been exploited in the wild, with many attacks apparently targeting operational technology (OT) networks. Erlang/OTP is a collection of libraries, middleware and other tools designed for creating real-time systems that require high availability, such as banking, e-commerce, and communications applications. Researchers discovered that Erlang/OTP’s SSH implementation is affected by a critical vulnerability that can allow arbitrary code execution in the context of the SSH daemon, which can potentially give an attacker full access to the host, enabling unauthorized access to and manipulation of sensitive data. Tracked as CVE-2025-32433, the flaw impacts all unpatched SSH servers that leverage the Erlang/OTP SSH library, and systems used for remote access are particularly at risk. The security hole has been patched with the release of OTP-27.3.3, OTP-26.2.5.11 and OTP-25.3.2.20. Earlier versions are affected. The cybersecurity agency CISA added CVE-2025-32433 to its Known Exploited Vulnerabilities catalog on June 9, but there did not appear to be any public reports describing exploitation of the flaw. On Monday, however, Palo Alto Networks published a blog post detailing exploitation attempts, which the cybersecurity giant has seen since May 1. According to Palo Alto Networks, exploitation activity surged in May 1-9, with 70% of attacks observed by the company aimed at OT networks. A majority of the detections were seen in the United States. “OT and 5G environments use Erlang/OTP due to its fault-tolerance and scalability for high availability systems with minimal downtime,” the security firm explained. “Due to compliance and safety requirements, OT and 5G administrators tend to use Erlang/OTP’s native SSH implementation to remotely manage hosts, which makes CVE-2025-32433 a particular concern in these types of networks.” Palo Alto Networks has seen Erlang/OTP SSH services exposed on the internet through various ports, including TCP port 2222, which is often used for older industrial automation products. Data collected by the company’s firewalls showed that 85% of the exploitation attempts were aimed at the healthcare, agriculture, media and entertainment, and high tech sectors. “Despite high OT reliance, utilities and energy, mining, and aerospace and defense showed no direct OT triggers for this specific threat,” Palo Alto said. “Sectors like professional and legal services primarily saw triggers on their IT networks. Industries such as manufacturing, wholesale and retail, and financial services experienced more balanced detection across both IT and OT, necessitating integrated defenses.” The company identified several malicious payloads that the attackers attempted to deliver through the exploitation of CVE-2025-32433, including reverse shells enabling unauthorized remote access. In some cases researchers spotted the use of a remote host with a port commonly associated with servers used for botnet communications. Scanning conducted by Palo Alto showed that hundreds of Erlang/OTP services present on industrial networks are exposed and vulnerable to attacks. Related: Cisco Confirms Some Products Impacted by Critical Erlang/OTP Flaw Related: Order Out of Chaos – Using Chaos Theory Encryption to Protect OT and IoT Related: Honeywell Experion PKS Flaws Allow Manipulation of Industrial Processes
securityweek.comAug 12, 2025extracted
⚡ Weekly Recap: VPN 0-Day, Encryption Backdoor, AI Malware, macOS Flaw, ATM Hack & More
Malware isn’t just trying to hide anymore—it’s trying to belong. We’re seeing code that talks like us, logs like us, even documents itself like a helpful teammate. Some threats now look more like developer tools than exploits. Others borrow trust from open-source platforms, or quietly build themselves out of AI-written snippets. It’s not just about being malicious—it’s about being believable. In this week’s cybersecurity recap, we explore how today’s threats are becoming more social, more automated, and far too sophisticated for yesterday’s instincts to catch. ⚡ Threat of the Week Secret Blizzard Conduct ISP-Level AitM Attacks to Deploy ApolloShadow — Russian cyberspies are abusing local internet service providers' networks to target foreign embassies in Moscow and likely collect intelligence from diplomats' devices. The activity has been attributed to the Russian advanced persistent threat (APT) known as Secret Blizzard (aka Turla). It likely involves using an adversary-in-the-middle (AiTM) position within domestic telecom companies and ISPs that diplomats are using for Internet access to push a piece of malware called ApolloShadow. This indicates that the ISP may be working with the threat actor to facilitate the attacks using the System for Operative Investigative activities (SORM) systems. Microsoft declined to say how many organizations were targeted, or successfully infected, in this campaign. Inside the 2025 Security Shift: What Every Cloud Leader Must Know Now Cloud security is shifting fast. Sysdig’s 2025 Cloud Defense Report shows how AI tools like Sysdig Sage™ cut response time by 76%, while runtime security and open source tools like Falco reshape defense. Get insights and strategies to stay ahead. Get the report ➝ 🔔 Top News Companies that Employed Hafnium Hackers Linked to Over a Dozen Patents — Threat actors linked to the notorious Hafnium hacking group have worked for companies that registered several patents for highly intrusive forensics and data collection technologies. The findings highlight China's diverse private sector offensive ecosystem and an underlying problem with mapping tradecraft to a specific cluster, which may not accurately reflect the true organizational structure of the attackers. The fact that the threat actors have been attributed to three different companies shows that multiple companies may be working in tandem to conduct the intrusions and those companies may be providing their tools to other actors, leading to incomplete or misleading attribution. It's currently not known how the threat actors came to possess the Microsoft Exchange Server flaws that were used to target various entities in a widespread campaign in early 2021. But their close relationship with the Shanghai State Security Bureau (SSSB) has raised the possibility that the bureau may have obtained access to information about the zero-days through some evidence collection method and passed it on to the attackers. The discovery also highlights another important aspect: China-based Advanced Persistent Threats (APTs) may actually consist of different companies that serve many clients owing to the contracting ecosystem, which forces these companies to collaborate on intrusions. In June 2025, Recorded Future revealed that a Chinese state-owned defense research institute filed a patent in late December 2024 that analyzes various kinds of intelligence, including OSINT, HUMINT, SIGINT, GEOINT, and TECHINT, to train a military-specific large language model in order to "support every phase of the intelligence cycle and improve decision-making during military operations." Likely 0-Day SonicWall SSL VPN Flaw Used in Akira Ransomware Attacks — SonicWall SSL VPN devices have become the target of Akira ransomware attacks as part of a newfound surge in activity observed in late July 2025. Arctic Wolf Labs said that the attacks could be exploiting an as-yet-undetermined security flaw in the appliances, meaning a zero-day vulnerability, given that some of the incidents affected fully-patched SonicWall devices. However, the possibility of credential-based attacks for initial access hasn't been ruled out. The development came as watchTowr Labs detailed multiple vulnerabilities in SonicWall SMA 100 Series appliances (CVE-2025-40596, CVE-2025-40597, and CVE-2025-40598) that an attacker could exploit to cause denial-of-service or code execution. "We stumbled across vulnerabilities that feel like they were preserved in amber from a more naïve era of C programming," security researcher Sina Kheirkhah said. "While we understand (and agree) that these vulnerabilities are ultimately difficult - or in some cases, currently not exploitable – the fact that they exist at all is, frankly, disappointing. Pre-auth stack and heap overflows triggered by malformed HTTP headers aren't supposed to happen anymore." UNC2891 Breaches ATM Network via 4G Raspberry Pi in Cyber-Physical Attack — The threat actor known as UNC2891 has been observed targeting Automatic Teller Machine (ATM) infrastructure using a 4G-equipped Raspberry Pi as part of a covert attack. The cyber-physical attack involved the adversary leveraging their physical access to install the Raspberry Pi device and have it connected directly to the same network switch as the ATM, effectively placing it within the target bank's network. The end goal of the infection was to deploy the CAKETAP rootkit on the ATM switching server and facilitate fraudulent ATM cash withdrawals. UNC2891 is assessed to share tactical overlaps with another threat actor called UNC1945 (aka LightBasin), which was previously identified compromising managed service providers and striking targets within the financial and professional consulting industries. UNC1945 is also known for its attacks aimed at the telecom sector. Active Exploitation of Alone WordPress Theme Flaw — Threat actors are actively exploiting a critical security flaw in "Alone – Charity Multipurpose Non-profit WordPress Theme" to take over susceptible sites. The vulnerability, tracked as CVE-2025-5394 (CVSS score: 9.8), is an arbitrary file upload affecting all versions of the plugin prior to and including 7.8.3. It has been fixed in version 7.8.5 released on June 16, 2025. In the observed attacks, the flaw is averaged to upload a ZIP archive containing a PHP-based backdoor to execute remote commands and upload additional files. Alternatively, the flaw has also been weaponized to deliver fully-featured file managers and backdoors capable of creating rogue administrator accounts. Multiple Flaws Patched in AI Code Editor Cursor — Several security vulnerabilities have been addressed in Cursor, including one high-severity bug (CVE-2025-54135 aka CurXecute) that could result in remote code execution (RCE) when processing external content from a third-party model context protocol (MCP) server. "If chained with a separate prompt injection vulnerability, this could allow the writing of sensitive MCP files on the host by the agent," Cursor said. "This can then be used to directly execute code by adding it as a new MCP server." Also addressed in Cursor version 1.3 is CVE-2025-54136 (CVSS score of 7.2), which could have allowed attackers to swap harmless MCP configuration files for a malicious command, without triggering a warning. "If an attacker has write permissions on a user's active branches of a source repository that contains existing MCP servers the user has previously approved, or an attacker has arbitrary file-write locally, the attacker can achieve arbitrary code execution," the company said. ️🔥 Trending CVEs Hackers are quick to jump on newly discovered software flaws – sometimes within hours. Whether it’s a missed update or a hidden bug, even one unpatched CVE can open the door to serious damage. Below are this week’s high-risk vulnerabilities making waves. Review the list, patch fast, and stay a step ahead. This week's list includes — CVE-2025-7340, CVE-2025-7341, CVE-2025-7360 (HT Contact Form plugin), CVE-2025-54782 (@nestjs/devtools-integration), CVE-2025-54418 (CodeIgniter4), CVE‑2025‑4421, CVE‑2025‑4422, CVE‑2025‑4423, CVE‑2025‑4424, CVE‑2025‑4425, CVE‑2025‑4426 (Lenovo), CVE-2025-6982 (TP-Link Archer C50), CVE-2025-2297 (BeyondTrust Privilege Management for Windows), CVE-2025-5394 (Alone theme), CVE-2025-2523 (Honeywell Experion PKS), CVE-2025-54576 (OAuth2-Proxy), CVE-2025-46811 (SUSE), CVE-2025-6076, CVE-2025-6077, and CVE-2025-6078 (Partner Software). 📰 Around the Cyber World Critical RCE in @nestjs/devtools-integration — A critical remote code execution flaw (CVE-2025-54782, CVSS score: 9.4) has been uncovered in @nestjs/devtools-integration, a NestJS npm package downloaded over 56,000 times per week. The package sets up a local development server with an endpoint that executes arbitrary code inside a JavaScript "sandbox" built with node:vm module and the now-abandoned safe-eval, ultimately allowing for execution of untrusted user code in a sandboxed environment, Socket said. Further analysis has found that the sandbox is trivially escapable and because the server is accessible on localhost, any malicious website can trigger code execution on a developer's machine via CSRF using the inspector/graph/interact endpoint. "Due to improper sandboxing and missing cross-origin protections, any malicious website visited by a developer can execute arbitrary code on their local machine," Nestjs maintainer Kamil Mysliwiec said in an advisory. "By chaining these issues, a malicious website can trigger the vulnerable endpoint and achieve arbitrary code execution on a developer's machine running the NestJS devtools integration." Attackers Exploit Compromised Email Accounts for Attacks — Threat actors are increasingly using compromised internal or trusted business partner email accounts to send malicious emails to obtain initial access. "Using a legitimate trusted account affords an attacker numerous advantages, such as potentially bypassing an organization's security controls as well as appearing more trustworthy to the recipient," Talos said. The disclosure comes as bad actors are also continuing to exploit Microsoft 365's Direct Send feature to deliver phishing emails that appear to originate from within the organization by using a spoofed internal From address and increases the likelihood of success of social engineering attacks. The messages are injected into Microsoft 365 tenants via unsecured third-party email security appliances used as SMTP relays. "This tactic allows attackers to send malicious payloads to Microsoft 365 users with increased credibility, often resulting in successful delivery despite failed authentication checks," Proofpoint said. Signal Warns it Will Exit Australia Over Encryption Backdoor Push — Signal Foundation president Meredith Whittaker said the secure messaging application will leave Australia if the government forces it to incorporate a backdoor into its encryption algorithm or demand access to encrypted user data. Earlier this year, the U.K. government issued a secret order demanding that Apple allow it access to encrypted user data to assist in investigations, resulting in Apple removing its Advanced Data Protection (ADP) feature for users in the region. While the U.K. government appears to be backing down from its earlier demand, Google told TechCrunch that, unlike Apple, it did not receive any request from the U.K. to build a secret backdoor. This is the first time Google has formally commented on the matter. Google Hardens Chrome Extension Supply Chain Against Account Compromise — Google has rolled out a new security feature called Verified CRX Upload for Chrome extension developers that enforces cryptographic signatures for all Chrome extension updates and prevents bad actors from compromising developer accounts and publishing malicious updates to the Chrome Web Store (CWS). The security protection is also designed to address scenarios where CWS code reviews may not always flag such malicious attacks. "When opting an extension into Verified CRX Upload, the developer gives Google a public key. After that, the developer can no longer upload unsigned ZIP files for that extension and must instead upload a CRX file signed with the corresponding private key," Google said [PDF]. "Verified upload acts as a second factor for the act of uploading to CWS. A malicious actor who compromises a developer's account password, session cookies, or even an OAuth token, would not be able to upload a malicious update unless they also gain access to the developer's private signing key." Kimsuky Targets South Korea with Stealer Malware — The North Korea-linked Kimsuky hacking group has been linked to a spear-phishing campaign that targets South Korean entities using Windows shortcut (LNK) files as an initial access vector to trigger a multi-stage infection chain to deploy a keylogger, information stealer, establish persistent control over compromised hosts, and deliver unknown next-stage payloads. In parallel, users are displayed with lure PDF documents related to tax notices and government alerts about alleged sex offenders in the area. "Once inside, the malware performs extensive system profiling, steals credentials and sensitive documents, monitors user activity through keylogging and clipboard capture, and exfiltrates data in discreet segments over standard web traffic—helping it blend into normal network operations," Aryaka said. Apple macOS Flaw Can Bypass TCC — Attackers could have used a recently patched macOS vulnerability to bypass Transparency, Consent, and Control (TCC) security checks and steal sensitive user information from locations such as the Downloads directory and Apple Intelligence caches. The flaw, dubbed Sploitlight by Microsoft and tracked as CVE-2025-31199, was addressed by Apple with the release of macOS Sequoia 15.4 in March 2025. The attack is so named because it exploits Spotlight plugins called importers, which are used to index data found on a device and surface it via its built-in search tool. Sploitlight turns these plugins into a TCC bypass, allowing valuable data to be leaked without a user's consent. Improved Version of XWorm Spotted — A new version of a remote access trojan called XWorm (version 6.0) has been discovered with new features such as process protection and enhanced anti-analysis capabilities, indicating continued attempts by the developers to iterate and refine their tactics. The starting point of the attack is a Visual Basic Script that's likely delivered to targets via social engineering, which then proceeds to set up persistence on the host via Windows Registry (as opposed to scheduled tasks in the previous version), although it's important to note that the builder offers three different methods, including the aforementioned techniques and the adding the payload to the Startup folder. It's also designed to run a PowerShell script that includes the ability to bypass Antimalware Scan Interface (AMSI) via in-memory modification of "clr.dll" to sidestep detection. Some of the new features observed in the latest version of XWorm are its ability to prevent process termination by marking itself as a critical process and killing itself if the compromised host is running Windows XP. Mozilla Warns Add-ons Devs Against Phishing Attack — Browser maker Mozilla is warning of a phishing campaign targeting its Firefox Add-ons infrastructure that aims to trick developers into parting with their account credentials as part of emails containing messages like "Your Mozilla Add-ons account requires an update to continue accessing developer features" that are designed to provoke engagement. The disclosure follows the emergence of bogus Firefox add-ons that masquerade as TronLink, Solflare, Rabby Wallet and are designed to steal cryptocurrency wallet secrets, security researcher Lukasz Olejnik said. New Stealer Malware Dissected — Cybersecurity researchers have detailed three new stealer malware families called Cyber Stealer, Raven Stealer, and SHUYAL Stealer that combine extensive credential theft capabilities with advanced system reconnaissance and evasion tactics. "Beyond credential theft, SHUYAL captures system screenshots and clipboard content, exfiltrating this data alongside stolen Discord tokens through a Telegram bot infrastructure," Hybrid Analysis said. "The malware maintains operational stealth through self-deletion mechanisms, removing traces of its activity using a batch file after completing its primary functions." Cyber Stealer, for its part, maintains communication with its command-and-control (C2) server through heartbeat checks, XMR miner configuration, task checks, and data exfiltration. It also comes with a clipper, remote shell, reverse proxy, DDoS, XMR mining, and DNS poisoning capabilities based on the subscription tier chosen by a customer. "The C2 URL can be dynamically updated through Pastebin, with a hardcoded backup URL if that fails," eSentire said. While there are a number of stealers on the cybercrime scene already, the emergence of new stealers demonstrates the lucrative nature of such tools to enable data theft at scale. The third new infostealer malware is Raven Stealer, which is actively distributed through GitHub repositories and promoted via a Telegram channel operated by the threat actors. The stealer is consistent with other stealers, facilitating credential theft, browser data harvesting, and real-time data exfiltration via Telegram bot integration. NOVABLIGHT Node.js Stealer Spotted in the Wild — Developed and sold by the Sordeal Group, a threat actor demonstrating French-language proficiency, NOVABLIGHT is marketed as an "educational tool" on platforms like Telegram and Discord from €25 for a month to €140 for six months ($28 to $162). However, this aspect masks its true intent: A modular, feature-rich NodeJS-based malware built on the Electron framework, designed to steal sensitive information, including login credentials and cryptocurrency wallet data. The malware is said to be distributed via fake websites advertising video game installers. "NOVABLIGHT is a modular and feature-rich information stealer built on Node.js with the Electron framework," Elastic Security Labs said. "Its capabilities go beyond simple credential theft, incorporating methods for data collection and exfiltration, sandbox detection, and heavy obfuscation." $3.5B LuBian Bitcoin Theft Goes Undetected for Nearly Five Years — A previously undisclosed theft of 127,426 Bitcoin, valued at $3.5 billion at the time (presently approximately $14.5 billion), has been traced back to a December 2020 attack on a little-known Chinese mining pool called LuBian, making it as the largest cryptocurrency theft to date, surpassing the $1.5 billion Bybit hack that occurred in February 2025. "They appear to have been first hacked on December 28th, 2020, for over 90% of their BTC," Arkham Intelligence said. "Subsequently, on December 29th, around $6M of additional BTC and USDT was stolen from a Lubian address active on the Bitcoin Omni layer. On the 31st, LuBian rotated their remaining funds to recovery wallets." It's believed that the unknown attackers may have exploited a flawed private key generation algorithm that left it susceptible to brute-force attacks. "LuBian preserved 11,886 BTC, currently worth $1.35B, which they still hold," Arkham said. "The hacker also still holds the stolen BTC, with their last known movement being a wallet consolidation in July 2024." Neither LuBian nor the suspected hacker has ever publicly acknowledged the breach. Russia Blocks Access to Speedtest — Russia blocked access to Speedtest, a popular internet speed testing tool developed by U.S. company Ookla, claiming the service poses a national security threat and could aid cyber attacks. The restriction is due to the "identified threats to the security of the public communication network and the Russian segment of the internet," Roskomnadzor, country's communications watchdog, said, adding it "collects data on the layout and capacity of Russian communications nodes" that could be used to "plan, conduct, and assess attacks on Russian networks and related systems." CISA Releases Thorium — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced the public availability of Thorium, an open-source platform for malware and forensic analysts across the government, public, and private sectors. "Thorium enhances cybersecurity teams' capabilities by automating analysis workflows through seamless integration of commercial, open-source, and custom tools," CISA said. "It supports various mission functions, including software analysis, digital forensics, and incident response, allowing analysts to efficiently assess complex malware threats." The agency has also released the Eviction Strategies Tool, which helps security teams during the incident response by providing the necessary actions to contain and evict adversaries from compromised networks and devices. Russian Entities Targeted to Deploy Cobalt Strike — The Russian information technology (IT) sector, and to a certain extent companies in China, Japan, Malaysia, and Peru, has been at the receiving end of a spear-phishing email campaign that delivers the Cobalt Strike Beacon by means of intermediate payloads that reach out to fake profiles on social media platforms to obtain the URL hosting the post-exploitation toolkit. The accounts, created on GitHub, Quora, and Russian-language social networks, are said to have been created specifically for the attacks and act as dead drop resolvers to facilitate operational resiliency. The activity was first recorded in the second half of 2024, reaching its peak in November and December. The campaign has not been attributed to any known threat actor or group. APT36 Targets Indian Railways, Oil & Gas Sectors — A suspected Pakistani threat actor known as APT36 (aka Transparent Tribe) has been attributed to attacks targeting Indian railway systems, oil and gas infrastructure, and the Ministry of External Affairs via spear-phishing attacks to deliver a known malware called Poseidon. "They use .desktop files disguised as PDF documents to execute scripts that download malware and establish persistence using cron jobs," Hunt.io said. "The Poseidon backdoor, built on the Mythic framework and written in Go, is used to maintain access and support lateral movement." Qilin Ransomware Attack Leverages BYOVD Technique — Threat actors associated with Qilin ransomware have been observed leveraging a previously unknown driver, TPwSav.sys, to stealthily disable security tools using a custom version of EDRSandblast as part of a Bring Your Own Vulnerable Driver (BYOVD) attack. "This driver, originally developed for power-saving features on Toshiba laptops, is a signed Windows kernel driver, making it an attractive choice for bypassing EDR protections through a BYOVD attack," Blackpoint Cyber said. Prior to this incident, there has been no evidence of in-the-wild exploitation of the driver. "Compiled in 2015 and holding a valid signature, this driver is an appealing candidate for BYOVD attacks aimed at disabling EDR. While interacting with the driver requires only low-level privileges, loading it and enumerating physical memory demand administrative privileges," the company added. Phishing Campaign Distributes 0bj3ctivity Stealer — Phishing emails bearing purchase order-lures are being used to distribute via JavaScript files a stealer called 0bj3ctivity Stealer, which has been propagated via Ande Loader in the past. "The further stages are uncommon, including custom PowerShell scripts to deploy the next stages and steganography to hide some of the payloads," Trellix said. "Once decoded, the PowerShell script will download from archive.org a JPG image, which contains the next stage hidden using steganography." The United States, Germany, and Montenegro exhibit a high volume of detections, although telemetry data has also revealed noticeable activity in Europe, North America, Southeast Asia, and Australia, indicating the global nature of the threat. Increasing Number of Flaws Leveraged as 0- or 1-Days — A third of flaws leveraged by attackers this year have been zero-day or 1-day flaws, indicating that threat actors are becoming faster at exploiting vulnerabilities. "We observed an 8.5% increase in the percentage of KEVs [Known Exploited Vulnerabilities] that had exploitation evidence disclosed on or before the day a CVE was published — 32.1% in H1-2025 as compared to the 23.6% we reported in 2024," VulnCheck said. In total, the company added 432 new vulnerabilities to its KEV list in the first half of 2025, with 92 unique threat actors linked to the exploitation efforts. Of these, 56 (60.8%) were attributed to specific countries, including China (20), Russia (11), North Korea (9), and Iran (6). In a related development, a GreyNoise report found that in 80% of reconnaissance spikes against enterprise gear, the increase in activity was followed by the publication of a new CVE within six weeks, suggesting threat actors or researchers are testing their exploits ahead of time. "These patterns were exclusive to enterprise edge technologies like VPNs, firewalls, and remote access tools – the same kinds of systems increasingly targeted by advanced threat actors," the threat intelligence firm said. BreachForums Comes Back Online — BreachForums appears to be back again after it went offline in April. The popular cybercrime forum was shut down and resurrected several times over the past year. According to DataBreaches.Net, the official site appears to be back online on its dark web address, while preserving the original user database, reputation, credits, and posts. What's more, the site seems to have returned under new leadership – a user with the online moniker "N/A." In an introductory post, N/A also claimed that none of its administrators have been arrested and that it's "business as usual." RedCurl's New Attacks Deliver RedLoader — The threat actor known as Gold Blade (aka Earth Kapre, RedCurl, and Red Wolf) has been linked to a new set of attacks in July 2025 that combine malicious LNK files and WebDAV to execute remotely hosted DLLs to ultimately launch RedLoader using DLL side-loading. The LNK files, disguised as cover letters in the PDF format, are distributed via phishing emails via third-party job search sites like Indeed. Mimo Exploits SharePoint Flaws to Deliver Ransomware — The threat actor known as Mimo is exploiting the recently disclosed Microsoft SharePoint flaws to deliver the Go-based 4L4MD4r ransomware. The hacking group was recently linked to the abuse of a critical Craft CMS flaw to drop miners. The development marks the first time the hacking group has deployed ransomware in the wild. Silver Fox APT Uses Fake Flash Plugin to Deliver Malware — The threat actor tracked as Silver Fox has been observed delivering the Winos trojan under the guise of popular tools like Adobe Flash, Google Translate, and WPS. Typical distribution vectors include email, phishing websites, and instant messaging software. "However, with the leakage of core remote control Trojan source code (such as Winos 4.0) in the cybercrime circle, Silver Fox has gradually transformed from a single organization into a malicious family widely redeveloped by cybercrime groups and even APT organizations," the Knownsec 404 team said. "Winos has a rich set of functional plug-ins that enable various remote control functions and data theft on the target host." Girona Hacker Arrested — Spanish authorities have apprehended a cybercriminal who allegedly stole sensitive data from major financial institutions, educational organizations, and private companies across the country. The accused, described as a man with advanced computer programming skills, stands accused of targeting Spanish banks, a driving school, and a public university, among others. The suspect is alleged to have stolen personal databases of employees and customers, as well as internal documents of companies and organizations, and then sold them for profit. ShadowSyndicate Infrastructure Analyzed — Cybersecurity researchers have found connections between ShadowSyndicate infrastructure and various malware families like AMOS Stealer, TrueBot, and a number of ransomware strains such as Cl0p, BlackCat, LockBit, Play, Royal, CACTUS, and RansomHub. Aside from having access to a network of bulletproof hosters (BPHs) in Europe, it's believed that ShadowSyndicate functions as an initial access broker (IAB) fueling Russian, North Korean, and Chinese APTs. "It remains unclear whether ShadowSyndicate has a structured business model with formal clients or partners in cybercrime, or whether it represents a more fluid, hybrid threat actor," Intrinsec said. Who is Lionishackers? — Threat hunters have ripped the cover off Lionishackers, a corporate database seller and a financially motivated threat actor focused on exfiltrating and selling corporate databases through Telegram and underground forums since July 2024. "Even though they seem to have an opportunistic approach when choosing their targets, there seems to be a certain preference for victims located in Asian countries," Outpost24 said. "They have shown a high level of collaboration with the 'Hunt3r Kill3rs' group and extensive participation in relevant underground communities' Telegram channels. Furthermore, they also worked on and offered other services such as pen testing, the commercialization of the Ghost botnet, and the launch of a forum project dubbed Stressed Forums." EdskManager RAT, Pulsar RAT, and Retro-C2 RAT Exposed — Three new remote access trojans called EdskManager RAT, Pulsar RAT, and Retro-C2 RAT have been flagged by cybersecurity researchers, flagging their ability to evade detection and maintain control over compromised systems. "The malware employs a downloader disguised as legitimate software, followed by in-memory decryption and stealth communication with command-and-control servers," CYFIRMA said about EdskManager RAT. "Its use of HVNC (Hidden Virtual Network Computing), advanced persistence techniques, and anti-analysis measures indicates a strong focus on long-term, covert access to infected systems." Pulsar RAT, on the other hand, is an Android trojan that exploits accessibility services to gain near-total control of the device, accessing messages, calls, GPS data, the camera, microphone, and other sensitive data. Developed by a Turkish-speaking threat actor known as ZeroTrace, Retro-C2 RAT employs reflective loading techniques to evade detection and siphon data from compromised machines. "The command-and-control infrastructure is fully web-based and provides threat actors with real-time client monitoring, action management such as CMD, PowerShell, Remote Desktop, keylogging, clipboard capture, file and process management, registry and network operations, audio recording, wallet scanning, persistence operations, and credential recovery," ThreatMon said. Apple to Enable Advanced Fingerprinting Protection for All Safari Browsing Sessions — Apple has revealed that it intends to make advanced fingerprinting protection the default for all browsing sessions in Safari with the release of iOS 26, iPadOS 26, and macOS 26 in September 2025. Currently, the option is limited to Private Browsing mode. The feature was first introduced in Safari 17.0. Security Flaw Uncovered in Catwatchful Spyware — An SQL injection vulnerability in an Android stalkerware operation called Catwatchful has exposed more than 62,000 of its customers, including its Uruguay-based administrator, Omar Soca Charcov. The bug, discovered by researcher Eric Daigle, could be exploited to leak the application's database, compromising customers' email addresses and plaintext passwords. Google has since added protections to flag such malicious apps and suspended the developer's Firebase account for abusing its infrastructure to operate the monitoring software. Ransomware Continues to be a Threat — DragonForce has claimed more than 250 victims on its dark web leak site, with 58 in the second quarter of 2025 alone, indicating that the ransomware cartel is gaining traction after purportedly absorbing RansomHub. Some of the groups that appear to have exited the scene include RansomHub, Babuk-Bjorka, FunkSec, BianLian, 8Base, Cactus, and Hunters International. "With major RaaS services shutting down, many affiliates are operating independently or seeking new partnerships," Check Point said. "The result is a growing number of smaller, often short-lived, ransomware entities. At the same time, established players are actively competing to recruit these 'orphaned' affiliates." Ransomware attacks have also been observed evolving beyond double extortion to coerce victims into paying up with threats of data leaks and DDoS attacks. "Double, triple, and quadruple extortion tactics add pressure by threatening to expose customer information, disrupting operations with distributed denial-of-service (DDoS) attacks, and sending harassing messages to business partners, customers, and others -- including informing media of the breach," Akamai said. Threat Actors Hide Malware in DNS Records — While it's known that threat actors have leveraged the Domain Name System (DNS) for command-and-control purposes using a technique called DNS tunneling, it has been observed that cybercriminals are evolving their tactics further by concealing malicious commands in DNS TXT records by converting them into their hexadecimal representation and storing them in chunks. The practice is both clever and sneaky as it allows malicious scripts and early-stage malware to fetch binary files without having to download them from attacker-controlled sites or attach them to emails, which have a higher chance of being detected by antivirus software. 🎥 Cybersecurity Webinars Malicious Python Packages Are Everywhere — Learn How to Spot and Stop Them: In 2025, attacks on the Python ecosystem are rising fast—from typosquatting to dangerous container image flaws. If you're still “pip installing and praying,” it’s time to level up. Join us for a hands-on webinar where we break down real supply chain threats and show you how to defend your code with practical tools, smarter workflows, and hardened images. No hype—just clear steps to secure your Python stack. Secure Your AI Stack: Learn How to Defend Identity Before It’s Too Late: AI is changing the way we work—and the way we get attacked. Join Okta’s Karl Henrik Smith to explore how identity is becoming the last, and most critical, line of defense against AI-powered threats. From deepfakes to autonomous agents, attackers are moving faster than traditional tools can handle. In this free webinar, you’ll learn why identity-first security is the key to staying ahead—and how to put it into action. 🔧 Cybersecurity Tools Thorium: Released by the U.S. CISA, this new open-source tool is a scalable platform for automating file analysis and aggregating results across diverse tools. It helps cybersecurity teams streamline malware triage, forensics, and tool testing by integrating with existing workflows through event-driven automation and a scalable infrastructure. LangExtract: It is an open-source Python library, developed by Google, that helps developers extract structured information from unstructured text using Gemini and other LLMs. It’s designed for tasks like parsing medical records, legal documents, or customer feedback by combining prompt-driven extraction, source-grounded outputs, and schema enforcement. LangExtract supports flexible backends, scales across long documents, and makes it easy to visualize and verify results—all without fine-tuning a model. Disclaimer: These newly released tools are for educational use only and haven’t been fully audited. Use at your own risk—review the code, test safely, and apply proper safeguards. 🔒 Tip of the Week Your Keyboard Could Be Spying on You — Here's How to Tell — Most people don’t realize it, but your smartphone keyboard can do more than just type. Some of them quietly connect to the internet, sending back what you type, when you type, and even what’s in your clipboard. Even trusted apps like Gboard and SwiftKey have cloud sync features that share your typing patterns. And in worse cases, rogue keyboards can log passwords or steal crypto wallet seeds without any visible signs. The fix isn't just “don’t use shady keyboards.” It’s knowing how to control what they can do. Start by using a firewall app like NetGuard or RethinkDNS to block your keyboard from sending data over the internet. Go into your keyboard’s settings and turn off “personalization” or sync features. Watch out for weird behavior like a keyboard asking for access to your mic, contacts, or location — those are red flags. On newer Android versions, clipboard alerts will warn you if a keyboard is snooping. If you want full peace of mind, switch to a keyboard that respects your privacy by design. Options like OpenBoard or Simple Keyboard have no internet access at all. They’re fast, clean, and open source — meaning their code can be audited for hidden behavior. In short: if your keyboard wants to "learn from you," make sure it’s not learning too much. Conclusion Every threat we covered this week tells the same story: attackers are evolving faster because they’re learning from us. From how we code to how we trust, they’re watching closely. But the flipside? So are we. The more we share, the faster we adapt. Keep pushing, keep questioning, and never let “normal” make you comfortable.
thehackernews.comAug 4, 2025extracted
Critical Flaws in Niagara Framework Threaten Smart Buildings and Industrial Systems Worldwide
Cybersecurity researchers have discovered over a dozen security vulnerabilities impacting Tridium's Niagara Framework that could allow an attacker on the same network to compromise the system under certain circumstances. "These vulnerabilities are fully exploitable if a Niagara system is misconfigured, thereby disabling encryption on a specific network device," Nozomi Networks Labs said in a report published last week. "If chained together, they could allow an attacker with access to the same network — such as through a Man-in-the-Middle (MiTM) position — to compromise the Niagara system." Developed by Tridium, an independent business entity of Honeywell, the Niagara Framework is a vendor-neutral platform used to manage and control a wide range of devices from different manufacturers, such as HVAC, lighting, energy management, and security, making it a valuable solution in building management, industrial automation, and smart infrastructure environments. It consists of two key components: Station, which communicates with and controls connected devices and systems, and Platform, which is the underlying software environment that provides the necessary services to create, manage, and run Stations. The vulnerabilities identified by Nozomi Networks are exploitable should a Niagara system be misconfigured, causing encryption to be disabled on a network device and opening the door to lateral movement and broader operational disruptions, impacting safety, productivity, and service continuity. The most severe of the issues are listed below - CVE-2025-3936 (CVSS score: 9.8) - Incorrect Permission Assignment for Critical Resource CVE-2025-3937 (CVSS score: 9.8) - Use of Password Hash With Insufficient Computational Effort CVE-2025-3938 (CVSS score: 9.8) - Missing Cryptographic Step CVE-2025-3941 (CVSS score: 9.8) - Improper Handling of Windows: DATA Alternate Data Stream CVE-2025-3944 (CVSS score: 9.8) - Incorrect Permission Assignment for Critical Resource CVE-2025-3945 (CVSS score: 9.8) - Improper Neutralization of Argument Delimiters in a Command CVE-2025-3943 (CVSS score: 7.3) - Use of GET Request Method With Sensitive Query Strings Nozomi Networks said it was able to craft an exploit chain combining CVE-2025-3943 and CVE-2025-3944 that could enable an adjacent attacker with access to the network to breach a Niagara-based target device, ultimately facilitating root-level remote code execution. Specifically, the attacker could weaponize CVE-2025-3943 to intercept the anti-CSRF (cross-site request forgery) refresh token in scenarios where the Syslog service is enabled, causing the logs containing the token to be transmitted potentially over an unencrypted channel. Armed with the token, the threat actor can trigger a CSRF attack and lure an administrator into visiting a specially crafted link that causes the content of all incoming HTTP requests and responses to be fully logged. The attacker then proceeds to extract the administrator's JSESSIONID session token and use it to connect to the Niagara Station with full elevated permissions and creates a new backdoor administrator user for persistent access. In the next stage of the attack, the administrative access is abused to download the private key associated with the device's TLS certificate and conduct adversary-in-the-middle (AitM) attacks by taking advantage of the fact that both the Station and Platform share the same certificate and key infrastructure. With control of the Platform, the attacker could leverage CVE-2025-3944 to facilitate root-level remote code execution on the device, achieving complete takeover. Following responsible disclosure, the issues have been addressed in Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11. "Because Niagara often connects critical systems and sometimes bridges IoT technology and information technology (IT) networks, it could represent a high-value target," the company said. "Given the critical functions that can be controlled by Niagara-powered systems, these vulnerabilities may pose a high risk to operational resilience and security provided the instance has not been configured per Tridium's hardening guidelines and best practices." The disclosure comes as several memory corruption flaws have been discovered in the P-Net C library, an open-source implementation of the PROFINET protocol for IO devices, that, if successfully exploited, could allow unauthenticated attackers with network access to the targeted device to trigger denial-of-service (DoS) conditions. "Practically speaking, exploiting CVE-2025-32399, an attacker can force the CPU running the P-Net library into an infinite loop, consuming 100% CPU resources," Nozomi Networks said. "Another vulnerability, tracked as CVE-2025-32405, allows an attacker to write beyond the boundaries of a connection buffer, corrupting memory and making the device entirely unusable." The vulnerabilities have been resolved in version 1.0.2 of the library, which was released in late April 2025. In recent months, multiple security defects have also been unearthed in Rockwell Automation PowerMonitor 1000, Bosch Rexroth ctrlX CORE, and Inaba Denki Sangyo's IB-MCT001 cameras that could result in execution of arbitrary commands, device takeover, DoS, information theft, and even remote access of live footage for surveillance. "Successful exploitation of these vulnerabilities could allow an attacker to obtain the product's login password, gain unauthorized access, tamper with product's data, and/or modify product settings," the U.S. Cybersecurity and Infrastructure Security Agency (CISA) said in an advisory for IB-MCT001 flaws.
thehackernews.comJul 28, 2025extracted