Other Conventional Threats

Other conventional threat types

Showing 261–280 of 390 threats, newest first

ICSOTindustrial-control-systemsCISAplaintext-passwordconfused-deputypass-the-hashweak-encryptioncritical-infrastructure

Panduit IntraVUE versions 3.2.1a14 and earlier contain five vulnerabilities, including a critical confused-deputy proxy flaw (CVSS 10) that allows attackers with IT network access to bypass OT segmentation and manipulate industrial control devices without authentication. Additional flaws expose plaintext credentials via the API, leak host/share filesystem and asset information to unauthenticated users, and use weak encryption enabling pass-the-hash admin credential theft. CISA advises upgrading to version 3.2.1a16 or later; no known public exploitation has been reported to date.

Updated Jul 27, 2026 · CVSS 10

ICSSCADAphysical-securitySSRFdeserializationremote-code-executioncritical-infrastructureCISA-advisory

Johnson Controls C-CURE 9000 and victor application server products contain three vulnerabilities, including a critical SSRF flaw (CVSS 9.6) in victor Web and a .NET deserialization-related SSRF issue enabling unauthenticated remote code execution on the application server. Successful exploitation could allow attackers with adjacent network access to compromise physical access control and video security systems, including connected client workstations used by security personnel.

Updated Jul 26, 2026 · CVSS 9.6

ICSOTIEC-60870-5-104denial-of-serviceout-of-bounds-readCISA-advisorycritical-infrastructureprotocol-library

MZ Automation's lib60870 library, versions 2.4.0 and earlier, contains an out-of-bounds read vulnerability (CVE-2026-16002) in its IEC 60870-5-104 protocol parsing code. Remote, unauthenticated attackers can crash the parsing process, causing a denial of service in energy, water/wastewater, and chemical sector control systems that rely on this library for SCADA/ICS communications.

Updated Jul 26, 2026 · CVSS 8.2

data-breachlogisticspii-exposurecorporate-network-intrusion

OnTrac, a parcel delivery company, disclosed that attackers breached its corporate network and potentially accessed customer personal information. Details on the intrusion vector, threat actor, and full scope of compromised data remain limited based on available reporting.

Updated Jul 25, 2026

icsotiec61850buffer-overflowrcedenial-of-servicecritical-infrastructureenergy-sector

MZ Automation's libIEC61850 library, widely used for IEC 61850 substation automation and protection communications, contains four vulnerabilities including stack- and heap-based buffer overflows and NULL pointer dereferences. An unauthenticated, network-adjacent attacker could exploit these flaws to crash critical protection and control services or achieve remote code execution, directly threatening energy, manufacturing, and transportation ICS environments.

Updated Jul 25, 2026 · CVSS 9.2

ICSOTmobile-securitycleartext-storageAndroidCWE-312Johnson-Controlscritical-manufacturing

Johnson Controls XAAP Android application versions prior to 1.53 store application data locally in cleartext, allowing an attacker with physical device access and a separate compromise vector to read sensitive data in plaintext. Exploitation requires local device access and cannot be performed remotely over a network.

Updated Jul 25, 2026 · CVSS 3.3

dnscache-poisoningunbounddns-resolverso_reuseportnetwork-securityagent-relevant

A vulnerability in NLnet Labs Unbound (versions 1.4.22 through 1.25.1) weakens DNS transaction security when SO_REUSEPORT load balancing is enabled, which is the default configuration. Attackers can infer the mapping between client source ports and internal worker threads, effectively reducing the entropy of outgoing query source ports and making DNS cache poisoning attacks significantly more feasible.

Updated Jul 25, 2026 · CVSS 9.3

data-breachpii-exposureenergy-sectoraustraliacustomer-data-leak

Origin Energy, a major Australian energy provider, confirmed that an unauthorized party accessed customer data and subsequently leaked it online. The breach exposed sensitive personally identifiable information (PII), raising concerns about downstream fraud, phishing, and identity theft targeting affected customers.

Updated Jul 24, 2026

ICSOTpath-traversalrockwell-automationthinmanagerindustrial-control-systemsCWE-22

A high-severity path traversal vulnerability (CVE-2026-11917) affects multiple versions of Rockwell Automation ThinManager, allowing an authenticated attacker to write arbitrary files to restricted system directories outside the application's intended scope. No public exploitation has been reported at this time, but organizations in critical infrastructure sectors using affected versions should prioritize patching.

Updated Jul 24, 2026 · CVSS 8.1

ICSHMIvulnerabilityprivilege-escalationplaintext-passwordCWE-784CWE-732CWE-256CWE-286critical-manufacturingCISA-advisory

CISA disclosed four vulnerabilities in Weintek cMT3092X HMI devices and their EasyWeb web interface, allowing non-privileged users to escalate privileges via cookie/token manipulation, view plaintext-stored user credentials, and modify data that should be read-only. The highest-severity flaws (CVSS v3.1 8.8) enable full compromise of confidentiality, integrity, and availability on affected industrial control devices. No public exploitation has been reported, but a vendor patch is available.

Updated Jul 24, 2026 · CVSS 8.8

residential-proxyiotsmart-tvwebosproxywareprivacyconsumer-device-abuse

Researchers found that over 42% of apps on LG's webOS smart TV store secretly embed residential proxy SDKs, allowing unknown third parties to route their internet traffic through consumers' TVs without clear consent. LG has announced it will ban apps that turn smart TVs into always-on residential proxy nodes. This practice exposes users' home IP addresses and bandwidth to potentially malicious or anonymized traffic routed by unknown actors.

Updated Jul 23, 2026

bug-bountypolicy-changegithubvulnerability-disclosureindustry-news

GitHub announced it will cut public bug bounty payouts by at least half across all severity levels starting July 27, 2026, while introducing a permanent invite-only VIP tier that retains higher payouts of $30,000 or more. Reports already submitted or in GitHub's triage queue before that date will honor the previous payout structure.

Updated Jul 23, 2026

data-breachgovernmentespionagesouth-koreacredential-theftdiplomatic-targeting

South Korea's Ministry of Foreign Affairs disclosed that attackers breached the National Diplomatic Academy's online education system, maintaining unauthorized access for approximately ten months. The compromise resulted in theft of personal information belonging to current and former MFA employees, including overseas diplomats, raising concerns about follow-on espionage and social engineering targeting diplomatic personnel.

Updated Jul 23, 2026

data-breachfraudfintechidentity-theftPII-exposure

Upbound Group, the parent company of fintech lease-to-own provider Acima, disclosed that attackers who stole customer data from its systems used that information to fraudulently generate $13 million in Acima lease agreements. The incident highlights how stolen PII and account data can be weaponized for downstream financial fraud beyond the initial breach.

Updated Jul 23, 2026

ICSOTPAN-OSSiemensRUGGEDCOMcommand-injectionprivilege-escalationXSScritical-infrastructure

Siemens RUGGEDCOM APE1808 devices running Palo Alto Networks Virtual NGFW are affected by three vulnerabilities disclosed upstream in PAN-OS, including stored XSS, missing authorization leading to privilege escalation, and OS command injection allowing root-level code execution. Exploitation requires authenticated administrative access, which limits attack surface but still poses significant risk in industrial control system environments if management interfaces are exposed or misconfigured. Siemens recommends contacting customer support for patches and following standard ICS network isolation best practices.

Updated Jul 23, 2026 · CVSS 7.2

icsscadasiemensprivilege-escalationunquoted-search-pathvulnerability-disclosure

Multiple Siemens industrial and engineering software products bundling the IAM Client SDK are affected by an untrusted/unquoted search path vulnerability that could allow an authenticated local attacker to escalate privileges. Siemens has released patched versions for most affected products and recommends updating as soon as possible, with fixes pending for remaining products.

Updated Jul 23, 2026 · CVSS 6.7

oracleunauthenticated-rcenetwork-exploitablecvss-9.8testing-infrastructure

A critical unauthenticated remote code execution vulnerability affects Oracle Application Testing Suite version 13.3.0.1, allowing attackers with mere network access to fully compromise the system without any credentials or user interaction. The flaw carries a maximum-impact CVSS score of 9.8, threatening confidentiality, integrity, and availability, and is trivially exploitable, making it a high-priority patching target.

Updated Jul 23, 2026 · CVSS 9.8

xrdprdpinteger-overflowout-of-bounds-readvncremote-accessdosinformation-disclosure

A vulnerability in xrdp versions 0.10.6 and earlier allows a malicious remote VNC server to trigger an integer overflow when processing crafted screen update image dimensions in vnc-any connection mode. This results in an undersized buffer allocation followed by an out-of-bounds heap read, enabling unauthenticated information disclosure or denial of service via process crash. The issue is fixed in xrdp 0.10.6.1.

Updated Jul 23, 2026 · CVSS 8.2

ai-security-toolvulnerability-researchdefensive-aiproduct-announcement

Google DeepMind announced Gemini 3.5 Flash Cyber, a specialized AI model designed to discover, validate, and patch software vulnerabilities, released via the CodeMender pilot program to governments and trusted partners. This is a defensive security tool announcement rather than an active threat, though it reflects the growing role of AI in both offensive and defensive security tooling.

Updated Jul 22, 2026

appleprivacyemail-privacydisclosureiosicloud

A privacy flaw in Apple's Hide My Email feature allowed users' real email addresses to be exposed in mail logs, undermining the service's core privacy promise. Apple deployed a fix on July 3, 2026, over a year after the issue was reported by researcher Tyler Murphy of EasyOptOuts.

Updated Jul 22, 2026