REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
181 reports · page 5 of 5
cisa_alerts · tlp:amber · 5/5/2026, 12:00:00 PM
Hitachi Energy PCM600 View CSAF Summary Hitachi Energy is aware of a vulnerability that affects the Hitachi Energy PCM600 product versions listed in this document. An attacker successfully exploiting this vulnerability can impact integrity of the product. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation. The following versions of Hitachi Energy PCM600 are affected: PCM600 Legacy vers:PCM600_Legacy/<=2.11 (CVE-2018-1002208)…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-125-01cisa_alerts · tlp:amber · 5/5/2026, 12:00:00 PM
ABB B&R Automation Runtime View CSAF Summary ABB became aware of vulnerability in the product versions listed as affected in the advisory. An update is available that resolves a vulnerability. An attacker who successfully exploited this vulnerability could cause the product to stop. The following versions of ABB B&R Automation Runtime are affected: Automation Runtime <6.5, >=6.5, =R4.93 (CVE-2025-11044, CVE-2025-11044) CVSS Vendor Equipment Vulnerabilities v3 6.8 A…
cisa_alerts · tlp:amber · 5/5/2026, 12:00:00 PM
Johnson Controls CEM AC2000 View CSAF Summary Successful exploitation of this vulnerability could allow a standard user to escalate privileges on the host machine. The following versions of Johnson Controls CEM AC2000 are affected: CEM AC2000 12.0 (CVE-2026-21661) CEM AC2000 11.0 (CVE-2026-21661) CEM AC2000 10.6 (CVE-2026-21661) CVSS Vendor Equipment Vulnerabilities v3 8.7 Johnson Controls Inc. Johnson Controls CEM AC2000 Uncontrolled Search Path Element Background Critical …
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-125-05cisa_alerts · tlp:amber · 5/5/2026, 12:00:00 PM
ABB B&R PVI View CSAF Summary ABB became aware of vulnerability in the product versions listed as affected in the advisory. An update is now available that addresses and remediates the vulnerability. An attacker who successfully exploited this vulnerability could read sensitive information in the logging data of the PVI client application. Logging is deactivated by default in all PVI client versions. The following versions of ABB B&R PVI are affected: PVI <6.5.0, 6.5.…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-125-02cisa_alerts · tlp:amber · 5/5/2026, 12:00:00 PM
ABB B&R Automation Studio View CSAF Summary ABB became aware of vulnerability in the product versions listed as affected in the advisory. An update is available that resolves a vulnerability. Successful exploitation of this vulnerability may enable an attacker to masquerade as a trusted party when B&R Automation Studio establishes a connection with a server via the ANSL over TLS or OPC-UA protocol. The following versions of ABB B&R Automation Studio are affected: Aut…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-125-04cisa_alerts · tlp:amber · 5/1/2026, 12:00:00 PM
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-31431 Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant…
Read original ↗https://www.cisa.gov/news-events/alerts/2026/05/01/cisa-adds-one-known-exploited-vulnerability-catalogcisa_alerts · tlp:amber · 5/1/2026, 12:00:00 PM
Careful Adoption of Agentic AI Services CISA, in collaboration with the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) and other international and U.S. partners, released guidance for organizations on adopting agentic artificial intelligence (AI) systems. This guide outlines key security challenges and risks associated with agentic AI, and provides actionable steps for designing, deploying, and operating these systems safely. It helps organiza…
Read original ↗https://www.cisa.gov/resources-tools/resources/careful-adoption-agentic-ai-servicescisa_alerts · tlp:amber · 4/30/2026, 12:00:00 PM
ABB AWIN Gateways View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to remotely reboot the device or complete an unauthenticated query to reveal system configuration, including sensitive details. The following versions of ABB AWIN Gateways are affected: ABB AWIN Firmware (2.0-0) installed on ABB AWIN GW100 rev.2 2.0-0 ABB AWIN Firmware (2.0-1) installed on ABB AWIN GW100 rev.2 2.0-1 ABB AWIN Firmware (1.2-0) installed on A…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-120-05cisa_alerts · tlp:amber · 4/30/2026, 12:00:00 PM
ABB Ability OPTIMAX View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to bypass user authentication on OPTIMAX installations that make use of the Azure Active Directory Single-Sign On integration. The following versions of ABB Ability OPTIMAX are affected: ABB Ability OPTIMAX 6.1 vers:all/* ABB Ability OPTIMAX 6.2 vers:all/* ABB Ability OPTIMAX 6.3 <6.3.1-251120 ABB Ability OPTIMAX 6.4 <6.4.1-251120 CVSS Ven…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-120-04cisa_alerts · tlp:amber · 4/30/2026, 12:00:00 PM
ABB Edgenius Management Portal View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to send a specially crafted message to the system node allowing the attacker to install and run arbitrary code, uninstall applications, and modify the configuration of installed applications. The following versions of ABB Edgenius Management Portal are affected: Edgenius Management Portal 3.2.0.0|3.2.1.1 CVSS Vendor Equipment Vulnerabilities v3 9.6 ABB ABB E…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-120-03cisa_alerts · tlp:amber · 4/30/2026, 12:00:00 PM
ABB System 800xA, Symphony Plus IEC 61850 View CSAF Summary This vulnerability was privately reported relating to ABB’s implementation of the IEC 61850 communication stack for MMS client applications used in some Automation control system products. Note: IEC 61850 communication typically supports MMS and GOOSE protocols. Some ABB products support both, others only MMS (e.g. S+ Operations and PM 877). In any case, GOOSE communication is not impacted by this reported vulnerabi…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-120-01cisa_alerts · tlp:amber · 4/30/2026, 12:00:00 PM
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-41940 WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant r…
Read original ↗https://www.cisa.gov/news-events/alerts/2026/04/30/cisa-adds-one-known-exploited-vulnerability-catalogcisa_alerts · tlp:amber · 4/30/2026, 12:00:00 PM
ABB Ability Symphony Plus Engineering View CSAF Summary ABB became aware of vulnerability in the products versions listed as affected in the advisory. The ABB S+ Engineering product versions are affected by vulnerabilities in PostgreSQL version 13.11 and earlier versions. If an attacker gains access to a site’s S+ Client Server network, they could exploit such vulnerabilities by executing arbitrary code and potentially compromising the entire system. The following versions o…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-120-06cisa_alerts · tlp:amber · 4/30/2026, 12:00:00 PM
ABB PCM600 View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to send specially crafted messages to the system node resulting in execution of arbitrary code. The following versions of ABB PCM600 are affected: PCM600 >=1.5|<=2.13 CVSS Vendor Equipment Vulnerabilities v3 4.4 ABB ABB PCM600 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Background Critical Infrastructure Sectors: Critical Manufactu…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-120-02cisa_alerts · tlp:amber · 4/29/2026, 12:00:00 PM
Adapting Zero Trust Principles to Operational Technology Adapting Zero Trust Principles to Operational Technology CISA, in coordination with the Department of War, Department of Energy, Federal Bureau of Investigation, and Department of State, released Adapting Zero Trust Principles to Operational Technology , joint guidance for organizations applying zero trust (ZT) principles to operational technology (OT). Zero trust is a modern, adaptive approach to cybersecurity that el…
Read original ↗https://www.cisa.gov/resources-tools/resources/adapting-zero-trust-principles-operational-technologycisa_alerts · tlp:amber · 4/28/2026, 12:00:00 PM
NSA GRASSMARLIN View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to disclose sensitive information. The following versions of NSA GRASSMARLIN are affected: GRASSMARLIN vers:all/* CVSS Vendor Equipment Vulnerabilities v3 5.5 NSA NSA GRASSMARLIN Improper Restriction of XML External Entity Reference Background Critical Infrastructure Sectors: Information Technology Countries/Areas Deployed: Worldwide Company Headquarters Location: United S…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-118-01cisa_alerts · tlp:amber · 4/28/2026, 12:00:00 PM
CISA Adds Two Known Exploited Vulnerabilities to Catalog CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2024-1708 ConnectWise ScreenConnect Path Traversal Vulnerability CVE-2026-32202 Microsoft Windows Protection Mechanism Failure Vulnerability These types of vulnerabilities are frequent attack vectors for malic…
Read original ↗https://www.cisa.gov/news-events/alerts/2026/04/28/cisa-adds-two-known-exploited-vulnerabilities-catalogcisa_alerts · tlp:amber · 4/24/2026, 12:00:00 PM
CISA Adds Four Known Exploited Vulnerabilities to Catalog CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2024-7399 Samsung MagicINFO 9 Server Path Traversal Vulnerability CVE-2024-57726 SimpleHelp Missing Authorization Vulnerability CVE-2024-57728 SimpleHelp Path Traversal Vulnerability CVE-2025-29635 D-Link DIR-823X Command Injection Vuln…
Read original ↗https://www.cisa.gov/news-events/alerts/2026/04/24/cisa-adds-four-known-exploited-vulnerabilities-catalogcisa_alerts · tlp:amber · 4/23/2026, 12:00:00 PM
Defending Against China-Nexus Covert Networks of Compromised Devices Defending against china-nexus covert networks of compromised devices executive summary Defending against China-nexus covert networks of compromised devices Explaining the widespread shift in tactics, techniques and procedures (TTPs) towards networks of compromised infrastructure, and how to defend against it Summary With support from the UK Cyber League , this advisory has been jointly released …
Read original ↗https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-113acisa_alerts · tlp:amber · 4/23/2026, 12:00:00 PM
Intrado 911 Emergency Gateway (EGW) (Update A) View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to read, modify, or delete files. The following versions of Intrado 911 Emergency Gateway (EGW) are affected: Emergency Gateway 7.x (CVE-2026-6074) Emergency Gateway 6.x (CVE-2026-6074) Emergency Gateway 5.x (CVE-2026-6074) CVSS Vendor Equipment Vulnerabilities v3 9.8 Intrado Intrado 911 Emergency Gateway (EGW) Path Traversal: '.../...//' Bac…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-113-06cisa_alerts · tlp:amber · 4/23/2026, 12:00:00 PM
Milesight Cameras View CSAF Summary Successful exploitation of these vulnerabilities could crash the device being accessed or allow remote code execution. The following versions of Milesight Cameras are affected: MS-Cxx63-PD <=51.7.0.77-r12 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766) MS-Cxx64-xPD <=51.7.0.77-r12 (CVE-2026-28747, CVE-2026-27785, CVE-2026-32644, CVE-2026-32649, CVE-2026-20766) MS-Cxx73-xPD <=51.7.0.77-r12 (CVE-2026…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-113-03