Siemens SINEC NMS Authentication Bypass Vulnerability (CVE-2026-24032)
Siemens SINEC NMS is vulnerable to an authentication bypass flaw (CVE-2026-24032, CVSS 7.3) that allows remote unauthenticated attackers to bypass authentication.
Stories cluster related articles into a single narrative, linked to the underlying CVEs and affected products. 6,172 stories synthesized.
Siemens SINEC NMS is vulnerable to an authentication bypass flaw (CVE-2026-24032, CVSS 7.3) that allows remote unauthenticated attackers to bypass authentication.
A critical stack-based buffer overflow vulnerability in Delta Electronics ASDA-Soft (CVE-2026-5726) allows remote code execution via malicious PAR files, with a CVSS score of 7.8 and a fix now available.
A high-severity local privilege escalation vulnerability in Docker Desktop's Enhanced Container Isolation feature, tracked as CVE-2026-6406, allows attackers with low-privileged code execution inside a container to break out and access host resources.
A high-severity privilege escalation vulnerability in Siemens SINEC NMS, tracked as CVE-2026-25654, allows authenticated remote attackers to access restricted resources.
Mandiant has identified a new threat group, UNC6692, that combines social engineering via Microsoft Teams with a custom modular malware suite to achieve deep network penetration.
The Gentlemen ransomware-as-a-service group has rapidly risen to prominence since mid-2025, claiming 202 attacks in Q1 2026 and deploying sophisticated tools like SystemBC and Cobalt Strike to compromise corporate environments at scale.
SentinelOne reveals three distinct zero-day supply chain attacks targeting LiteLLM, Axios, and CPU-Z in spring 2026, all blocked by its platform without prior signatures.
Cisco Talos research reveals that attackers are increasingly repurposing native macOS tools like Remote Application Scripting and Spotlight metadata for living-off-the-land attacks, exploiting the platform's growing enterprise presence.
An exposed server reveals a large-scale credential harvesting operation using the Bissa scanner platform, with AI tools embedded in the operator's workflow.
North Korean threat actor Void Dokkaebi has weaponized fake job interviews to turn compromised developer repositories into worm-like infection vectors, infecting over 750 repos in March 2026 alone.
A surge in phishing emails with empty subject lines is targeting high-value users, exploiting blind spots in email defenses and leveraging legitimate remote monitoring tools for persistence.
A malicious website posing as an AI-powered trading assistant called TradingClaw is distributing Needle Stealer, a modular Golang infostealer that can hijack browser sessions, steal cryptocurrency wallets, and install malicious browser extensions.
The UK National Cyber Security Centre has developed SilentGlass, a plug-and-play hardware device that protects HDMI and DisplayPort connections from malicious data injection, now licensed to Goldilock Labs for global commercial sale.
Cisco Talos Incident Response Q1 2026 trends show phishing surged to over a third of engagements, with public administration and healthcare tied as most targeted verticals.
Unit 42 researchers have unveiled AirSnitch, a set of novel attack techniques that bypass WPA2 and WPA3-Enterprise encryption by exploiting low-level protocol-infrastructure interactions, affecting devices from multiple major vendors.
Apple released iOS 26.4.2 on April 22, 2026, with security patches that the company has not detailed in its public release notes, urging users to update promptly.
Apple released iPadOS 26.4.2 (build 23E261) on April 22, 2026, addressing undisclosed security vulnerabilities in the operating system.
Infrawatch researchers have identified ProxySmart, a Belarus-based software platform that provides a turnkey 'SIM Farm as a Service' solution, powering over 90 phone farms across 17 countries and 19 US states.
This week's Risky Business podcast covers a Vercel security incident tied to an infostealer infection, Mozilla's use of Anthropic's Mythos to fix 271 Firefox bugs, and NIST's decision to limit vulnerability analysis amid a swelling CVE backlog.
GitLab released versions 18.11.1, 18.10.4, and 18.9.6 on April 22, 2026, fixing multiple high-severity vulnerabilities including a CSRF in the GraphQL API and a path-equivalence issue in the Web IDE.
Oracle's second quarterly security update of 2026 fixes 241 unique CVEs with 481 patches, including 34 critical-severity fixes, with Oracle Communications receiving the most patches.
Threat actors are using three publicly available proof-of-concept exploits—BlueHammer, RedSun, and UnDefend—to turn Microsoft Defender's cleanup functions into attack vectors, granting SYSTEM-level access and degrading threat detection.
ESET has uncovered a new NGate malware variant that uses a trojanized version of the legitimate HandyPay NFC relay app to steal payment app to steal card data and PINs from Android users, primarily in Brazil.
Attackers are actively exploiting a critical unauthenticated RCE vulnerability in BeyondTrust Remote Support (Bomgar) to deploy LockBit ransomware and compromise downstream clients via MSP supply chains.