Latest Briefings
North Korean PolinRider Campaign Spreads 108 Malicious Packages Across npm, Go, and Chrome
Threat actors behind the Contagious Interview campaign have published 108 malicious packages and browser extensions across multiple ecosystems, with researchers warning the…
JadePuffer: First Ransomware Campaign Run Entirely by an AI Agent
Cloud security firm Sysdig has documented what it believes is the first ransomware operation conducted end-to-end by a large language model agent,…
Siemens Patches OpenSSL Stack Overflow Across Dozens of Industrial Products
A stack-based buffer overflow in OpenSSL tracked as CVE-2025-15467 affects a broad range of Siemens networking, routing, and industrial products, with fixes…
Siemens SIPROTEC 5 Flaw Allows Malicious File Uploads via DIGSI 5
A newly disclosed vulnerability in Siemens SIPROTEC 5 protective relays permits authenticated users to upload arbitrary files through the DIGSI 5 protocol,…
B&R Products Affected by Linux Kernel Privilege Escalation Flaws
CISA has published an advisory detailing Linux kernel vulnerabilities affecting multiple B&R Industrial Automation products, with public proof-of-concept exploits already available for…
CISA Warns of Critical Auth Flaws in EVoke EV Charging Management System
CISA has published an advisory detailing multiple vulnerabilities in EVoke Systems' Charging Station Management System, with the most severe carrying a CVSS…
Schneider Electric PowerLogic P7 Hit by Three ICS Vulnerabilities
CISA has published an advisory detailing three security flaws in Schneider Electric's PowerLogic P7 protection and control platform, including an OS command…
Yokogawa FAST/TOOLS and CI Server Expose Settings via Cleartext Flaw
A high-severity vulnerability in Yokogawa's FAST/TOOLS and Collaborative Information Server allows unauthenticated network attackers to retrieve sensitive configuration data through unencrypted web…
OHIF DICOM Viewer SSRF Flaw Exposes Clinician Auth Tokens
A server-side request forgery vulnerability in OHIF Viewers DICOM versions up to 3.12.0 can leak authenticated OIDC Bearer tokens to attacker-controlled servers…
CISA Warns of Critical Flaws in Daktronics Controller Firmware
Three vulnerabilities in Daktronics DMP and VFC-DMP controller firmware, including hard-coded credentials and unrestricted file upload, could give unauthenticated attackers full root-level…
Bad Epoll Linux Kernel Flaw Grants Root to Unprivileged Users, Affects Android
A newly disclosed Linux kernel vulnerability tracked as CVE-2026-46242 allows an ordinary unprivileged user to gain full root control. The flaw affects…
Seven Unpatched Flaws Found in FatFs Library Used Across Millions of Embedded Devices
Security firm runZero has disclosed seven vulnerabilities in FatFs, a widely embedded FAT/exFAT filesystem library present in firmware for cameras, drones, industrial…