
Unpatched AhsayCBS Flaws Exploited to Deploy Webshells, Mine Crypto
Threat actors are exploiting unpatched vulnerabilities in AhsayCBS to deploy webshells and cryptocurrency miners.
Stories tagged “Vulnerabilities.”
30 stories

Threat actors are exploiting unpatched vulnerabilities in AhsayCBS to deploy webshells and cryptocurrency miners.
mySCADA myPRO Manager
ICS Advisory for mySCADA myPRO Manager with CVE-2026-73807 and CVE-2026-82567 vulnerabilities.
Microsoft patches 972 vulnerabilities, setting a new record.

Cisco FMC vulnerabilities exploited by ransomware and state-sponsored hackers
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA updates its Known Exploited Vulnerabilities (KEV) Catalog with two new vulnerabilities.

Microsoft releases 966 security updates, including 2 zero-days, on September 2026 Patch Tuesday.
Schneier discusses a vulnerability that allows recovery of ballot order, exploited with AI tools. He analyzed voter behavior in Georgia using publicly available data.

Two zero-day vulnerabilities in PaperCut's print management software, recently patched, are now being exploited for data theft. Attackers are chaining the flaws to bypass authentication and steal data from vulnerable servers.

Security researcher Matt Burch found nine vulnerabilities in CryptoPro Secure Disk software used in ATMs and other industries. The flaws could have been exploited to bypass integrity checks and gain access to encrypted devices.

PaperCut has released a second emergency security update for two vulnerabilities in its print management software.
Linux kernel's CVEs per release are increasing, with recent releases averaging over 1,000 CVEs. Greg Kroah-Hartman shared a slide showing the trend from Linux 6.9 to Linux 7.2.

ServiceNow patched three critical vulnerabilities in its AI Platform, including code injection, SQL injection, and privilege escalation attacks.

Hackers exploit two Microsoft SharePoint vulnerabilities to execute code, using proof-of-concept exploits.

Ubiquiti releases security patches for three new maximum-severity vulnerabilities in its UniFi products.
Ebyte NE2-D11 Vulnerabilities Expose Industrial Control Systems to Unauthorised Access
CISA has identified several vulnerabilities in the Ebyte NE2-D11 industrial control system, which could allow an attacker to gain unauthorized administrative access, disclose sensitive information, modify device configuration, hijack authenticated sessions, and disrupt de…

Citrix has warned customers to immediately secure their systems against two vulnerabilities affecting NetScaler Gateway secure remote access solutions and NetScaler ADC networking appliances.

Microsoft is investigating reports that its August 2026 Windows updates, specifically KB5121003, are causing some games to freeze, crash, or fail to launch on Windows 11 systems.

This article lists various security updates for Wednesday, including updates for AlmaLinux, Debian, Fedora, Oracle, Red Hat, SUSE, and Ubuntu.
CISA Warns of Multiple Vulnerabilities in Malcolm Network Traffic Analysis Tool Suite
The Cybersecurity and Infrastructure Security Agency (CISA) has identified multiple vulnerabilities in the Malcolm network traffic analysis tool suite. These vulnerabilities could allow an attacker to cause a denial-of-service condition or execute arbitrary code. CISA rec…
CISA Adds Four Known Exploited Vulnerabilities to Catalog
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterpr…

This article lists various security updates for Monday, including updates for AlmaLinux, Debian, Fedora, Gentoo, Oracle, Slackware, and SUSE.
Siemens Parasolid Vulnerability Exposes Industrial Control Systems to Out-of-Bounds Read Attacks
Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Parasolid are affected: Parasolid V38.0 vers:intdot/<38.0.235 (CVE-2026-64629) Parasolid V38.1 vers:intdot/<38.1.230 (CVE-2026-64…
Siemens License Server (SLS) Vulnerabilities Allow Privilege Escalation and File Access
Siemens License Server (SLS) is affected by multiple vulnerabilities that could allow an attacker to elevate its privileges and read arbitrary files on the system. Siemens has released a new version for Siemens License Server (SLS) and recommends to update to the latest v…
Siemens Desigo DXR and PXC Controllers Vulnerable to Denial-of-Service Attacks
A vulnerability in Siemens Desigo DXR and PXC controllers has been identified that could allow an attacker to cause denial of service conditions by sending malformed BACnet packets. Recovery requires a device reset or reboot to restore normal functionality.
Johnson Controls Inc. Airwall Vulnerabilities Exposed
Johnson Controls Inc. has released a security advisory for its Airwall product, warning of two vulnerabilities that could allow attackers to decrypt sensitive data, bypass authentication controls, and gain unauthorized access to system resources. The affected versions are…

A volunteer security initiative, AnchorWatch, has used AI to scan 150 Bitcoin repositories and found over a dozen vulnerabilities. The effort aims to develop an open-source AI platform for auditing Bitcoin software.

Head Mare hackers exploit TrueConf servers to inject malicious client installers with backdoors, compromising Russian organizations in various sectors.

The Swiss government's federal IT office has been breached, with hackers exploiting vulnerabilities in Microsoft SharePoint servers to compromise approximately 200 accounts. The agency has blocked external internet access to SharePoint, patched the suspected vulnerabiliti…
ABB Ability Zenon Vulnerabilities Expose Industrial Control Systems to Attacks
CISA has issued an advisory warning of vulnerabilities in ABB Ability Zenon, a widely used industrial control system. The flaws, which affect IIoT services with MongoDB (4.2) installed on ABB Ability Zenon, could allow attackers to bypass security, crash systems, execute …

Security flaws in agent infrastructure from Amazon Web Services (AWS), Google, and Vercel let untrusted or forged instructions reach an agent's tools with no check that a model turn had authorized them.