Other Conventional Threats

Other conventional threat types

Showing 301–320 of 390 threats, newest first

ICSSCADACISA-advisoryXSSweb-vulnerabilitycritical-manufacturingrockwell-automation

A stored cross-site scripting (XSS) vulnerability affects Rockwell Automation FactoryTalk DataMosaix Private Cloud versions 8.02 and earlier, allowing an authenticated high-privilege attacker to inject persistent malicious scripts via the Workflows configuration. Successful exploitation could lead to account takeover, credential theft, or redirection of other users to malicious sites when they access the affected page. No public exploitation has been reported to date.

Updated Jul 18, 2026 · CVSS 6.1

ICSOTdenial-of-servicebuffer-overflowrockwell-automationcritical-manufacturingfirmwarePLC

Three vulnerabilities (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) affect multiple Rockwell Automation Logix controller families, allowing an unauthenticated remote attacker to send an invalid project or malformed file data that triggers a classic buffer overflow, causing the device to enter a major non-recoverable fault (MNRF). Exploitation results in denial-of-service impacting industrial control processes rather than data confidentiality or integrity loss. No known public exploitation has been reported to CISA at this time.

Updated Jul 18, 2026 · CVSS 8.6

wordpressplugin-vulnerabilityprivilege-escalationunauthenticatedcmsweb-application

The Bricksforge WordPress plugin (versions up to 3.1.8.6) contains a critical privilege escalation flaw in its Pro Forms registration action. Improper validation of the fieldIds parameter allows unauthenticated attackers to whitelist arbitrary form fields, including the administrator role field, enabling full site takeover via crafted registration requests.

Updated Jul 18, 2026 · CVSS 9.8

yamcsauthentication-bypassbrute-forcemissing-rate-limitingmission-control-softwarecve-2026-44596

Yamcs, an open-source mission control framework, contains a vulnerability in its authentication endpoint that allows unlimited password-guessing attempts due to missing rate limiting and account lockout mechanisms. An unauthenticated remote attacker could exploit this to brute-force credentials for any user account. The issue is patched in versions 5.12.7 and 5.13.0.

Updated Jul 18, 2026 · CVSS 6.5

account-takeoverresponse-manipulationauthentication-bypassHCLweb-application

CVE-2026-56453 affects HCL DFXAnalytics, allowing a remote attacker to intercept and manipulate HTTP responses to bypass authentication or authorization controls. This can result in unauthorized access to targeted user accounts without requiring credential theft.

Updated Jul 18, 2026 · CVSS 5.5

open-webuicors-misconfigurationrcellm-toolingadmin-takeoveragent-relevant

Open WebUI versions prior to 0.3.14 contain a CORS misconfiguration (allow_origins=*) combined with authenticated cookie-based requests to the /api/v1/functions endpoint, enabling attacker-controlled websites to trigger arbitrary code execution on the server. Exploitation requires an authenticated admin to visit a malicious webpage, after which the attacker can silently deploy or modify server-side functions to achieve RCE. This poses a serious risk to any organization self-hosting Open WebUI as an interface for LLMs or agentic workflows.

Updated Jul 18, 2026 · CVSS 8.3

xssopen-webuioauthaccount-takeoverllm-uiagent-relevantsupply-chain-component

Open WebUI versions prior to 0.9.5 contain a stored cross-site scripting vulnerability in the OAuth 'picture' claim handling, where MIME type validation relies on file extension instead of Content-Type headers. This allows attackers to smuggle malicious SVG files that execute script content when rendered, enabling authentication token theft and account takeover of Open WebUI users.

Updated Jul 18, 2026 · CVSS 7.3

roundupransomwarespywareinfostealerbrowser-securitysupply-chainweekly-digest

This is a weekly aggregated security news digest from The Hacker News covering multiple unrelated stories, including spyware disguised as game cheats, ransomware attacks that reach full encryption within 24 hours, and abuse of Chrome sync settings for tracking or session hijacking. The source material lacks technical depth on any single incident, functioning as a curated list of headlines rather than a detailed incident report.

Updated Jul 17, 2026

scattered-spidersocial-engineeringcritical-infrastructuretransportationlaw-enforcementhelp-desk-attack

Two members of the Scattered Spider hacking collective, Owen Flowers (18) and Thalha Jubair (20), were sentenced to five and a half years each for a 2024 cyberattack on Transport for London (TfL) that caused an estimated £29 million in losses. The attack rendered 148 TfL systems inoperable and required in-person password resets for all 27,000 employees, highlighting the operational disruption capability of social-engineering-driven threat actors against critical transit infrastructure.

Updated Jul 17, 2026

ICSphysical-securityaccess-controlprivilege-escalationauthorization-bypassCISA-advisory

A privilege escalation vulnerability exists in SALTO ProAccess Space access control software versions prior to 6.13, affecting installations using the tenancy/logical partition feature. An authenticated attacker with valid operator credentials can bypass partition boundaries to access spaces outside their assigned tenancy, potentially compromising physical access control across an organization's facilities.

Updated Jul 17, 2026 · CVSS 6.5

ICSOTSCADASiemenscritical-infrastructureenergy-sectorvulnerabilityfirmwareprivilege-escalationdenial-of-service

Siemens has disclosed four vulnerabilities affecting SICAM 8 product firmware (CPCI85 and SICORE base systems) used in energy and critical manufacturing environments. The flaws include an exposed debugging interface, insufficient firmware update signature validation, insecure default OPC UA security settings, and unverified password changes, which combined could lead to denial of service, unauthorized access, or persistent code execution on affected devices. Siemens has released firmware updates (V26.20/V26.20.0) to remediate all four issues.

Updated Jul 17, 2026 · CVSS 7.2

adobe-commercemagentoe-commerceauthorization-bypassweb-applicationunauthenticated-exploit

A high-severity Incorrect Authorization vulnerability affects Adobe Commerce, allowing attackers to bypass security controls and gain unauthorized read and write access without requiring user interaction. This flaw poses significant risk to e-commerce platforms storing sensitive customer, payment, and order data.

Updated Jul 17, 2026 · CVSS 8.2

microsoft-365-copilotiosprivilege-escalationaccess-controlagent-relevantai-agent-security

A high-severity access control flaw in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network. Exploitation could grant attackers elevated access to Copilot functionality and connected data without proper authorization, posing risk to enterprise mobile deployments.

Updated Jul 17, 2026 · CVSS 8.1

agent-relevantAI-agent-abuseLLM-toolingbotnetthreat-actorgemini-cliagentic-malware

A Russian-speaking threat actor known as 'bandcampro' has been observed repurposing Google's open-source Gemini CLI AI tool as an autonomous hacking agent to conduct offensive operations and manage a small-scale botnet. This represents a real-world case of adversaries weaponizing legitimate agentic AI tooling to automate reconnaissance, exploitation, and malware/botnet management tasks.

Updated Jul 16, 2026

investment-fraudlaw-enforcementtakedownsocial-engineeringfinancial-crime

Dutch Police arrested multiple suspects linked to a large-scale international investment fraud scheme that defrauded tens of thousands of victims out of over €100 million. The operation reportedly used deceptive online investment platforms and social engineering tactics to lure victims into fraudulent schemes.

Updated Jul 16, 2026

kevcisaactive-exploitationptc-windchillflexplmcisco-ucmssrfimproper-input-validationfederal-agencies

CISA has added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities Catalog: an improper input validation flaw in PTC Windchill and FlexPLM, and an SSRF vulnerability in Cisco Unified Communications Manager. Both are confirmed under active exploitation and pose significant risk, particularly to federal enterprise systems subject to BOD 26-04 remediation timelines.

Updated Jul 16, 2026

ICSOTABBT-MAC Plusfile-disclosureaccess-control-bypassXSSdenial-of-servicecritical-infrastructurecritical-manufacturing

ABB disclosed four vulnerabilities in T-MAC Plus 4.0-24, a Terminal Management System used in chemical, petroleum, and bulk terminal operations. The most severe issue (CVSS 9.9) allows authenticated users to exfiltrate sensitive files via crafted HTTP GET requests due to IIS misconfiguration, while other flaws enable privilege escalation, stored XSS, and physical-access-based denial of service against Card Reader services. ABB has released version 4.0-25 to remediate all four issues.

Updated Jul 16, 2026 · CVSS 9.9

kev-catalogknown-exploited-vulnerabilityoracle-ebsknx-protocolprivilege-escalationactive-exploitationfederal-agenciespatch-management

CISA added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: a KNX Protocol account lockout flaw (CVE-2023-4346) and an Oracle E-Business Suite improper privilege management vulnerability (CVE-2026-46817). Under BOD 26-04, FCEB agencies must prioritize remediation of these vulnerabilities on publicly exposed assets due to evidence of active in-the-wild exploitation.

Updated Jul 16, 2026

advisorybest-practicesvulnerability-disclosurepolicycisansa

This is not a threat but a joint CISA/NSA and international partner guidance document outlining best practices for establishing a Coordinated Vulnerability Disclosure (CVD) program. It advises software manufacturers and online service providers on creating vulnerability disclosure policies, triage processes, CVE assignment, and use of third-party intermediaries. The goal is to help organizations build collaborative relationships with security researchers and improve overall vulnerability management maturity.

Updated Jul 16, 2026

symfonyphpauthentication-bypassmtlsclient-certificateweb-frameworkagent-relevant

A critical authentication bypass vulnerability affects Symfony's X509Authenticator component, where an unanchored regex used to parse client certificate distinguished names (DN) can be exploited by an attacker holding any trusted certificate. By embedding 'emailAddress=victim' within an unexpected RDN field like CN, an attacker can impersonate any user identified by email in a mutual TLS authentication scheme.

Updated Jul 16, 2026 · CVSS 9.1