Digi International Devices Vulnerable to Authentication Bypass and Cross-Site Scripting
CISA has issued an advisory for multiple Digi International devices, including PortServer TS, Digi One SP, and Digi One IA, due to two critical vulnerabilities.
Stories cluster related articles into a single narrative, linked to the underlying CVEs and affected products. 3,727 stories synthesized.
CISA has issued an advisory for multiple Digi International devices, including PortServer TS, Digi One SP, and Digi One IA, due to two critical vulnerabilities.
Siemens Mendix Studio Pro versions prior to V11.12 contain a file parsing vulnerability (CVE-2026-48192) that allows for code injection, potentially leading to arbitrary code execution.
CISA has issued an advisory detailing three critical vulnerabilities in Hydro-Québec's Le Circuit Electrique charging station backend, potentially allowing for privilege escalation and denial-of-service attacks.
A critical vulnerability dubbed 'Rogue Agent' in Google Cloud Dialogflow CX allowed attackers to inject persistent malicious Python code into AI chatbots, potentially exfiltrating conversations and enabling phishing attacks.
A Trend Micro audit uncovered nearly 5,000 security issues across over 2,200 public Model Context Protocol (MCP) servers, highlighting critical vulnerabilities that endanger the burgeoning AI agent landscape.
Eight victims of the 'Predatorgate' spyware scandal have filed a lawsuit seeking €8 million in damages from Intellexa SA and associated individuals, alleging the company developed and distributed the Predator spyware used to hack their devices.
Outdated Service Level Agreements for Security Operations Centers (SOCs) are failing to keep pace with AI-driven security, leading to increased incident costs and vendor protection, according to a new analysis.
A new phishing campaign targets Russian aerospace and aviation organizations with fake invoices to deploy AnyDesk for unattended remote access, employing scheduled tasks for persistence and artifact deletion to evade detection.
Ubiquiti has addressed 25 security vulnerabilities across its UniFi ecosystem, with several critical flaws rated 9.9 and 10.0 CVSS allowing for unauthenticated command injection and SQL injection.
Japanese telecommunications giant NTT has disclosed a cyberattack impacting an email system used by five internet service providers, potentially exposing 12 million customer email addresses.
A new vulnerability named 'GitLost' allows attackers to trick GitHub's AI Agentic Workflows into leaking private repository contents through prompt injection in GitHub Issues.
A new attack pattern, dubbed Cordyceps, exploits GitHub Actions workflows, bypassing standard security scanners and enabling attackers to compromise high-impact repositories.
Two critical vulnerabilities in PHP's PDO drivers, CVE-2026-25289 and CVE-2026-25290, allow SQL injection and denial of service, respectively. Both have been patched.
A critical session isolation flaw, dubbed WriteOut, in the enterprise AI platform Writer has been patched, preventing attackers from hijacking user accounts and accessing sensitive data across different tenants.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is reportedly using Anthropic's advanced AI model, Mythos, to scan federal government code repositories for vulnerabilities.
A DigiCert survey reveals that 78% of enterprises have experienced AI-related security incidents or vulnerabilities, largely due to poor governance and misconfigured AI agents.
Commvault introduces a novel AI-powered simulation tool, 'Commvault Minutes to Recovery,' enabling organizations to test their cyber resilience by acting as attackers and defending against AI-driven threats.
Key findings • Forty malicious RubyGems packages were disclosed on July 7, 2026. • All 40 advisories were published within a 25-minute window, indicating a coordinated campaign. • Many pa…
A widespread phishing campaign impersonates major brands, using fake recruiter emails and career pages hosted on legitimate services to steal Gmail credentials via a deceptive Browser-in-Browser attack.
Attackers are actively exploiting CVE-2026-48282, a critical path traversal vulnerability in Adobe ColdFusion, just days after patches were released.
Key findings • 16 malicious packages were disclosed on PyPI within a minute on July 7, 2026. • The packages included two distinct naming campaigns: 'pygremlinbox-malware-' (6 packages) and 'c…
Google has filed a lawsuit against a Chinese scam operation, Outsider Enterprise, for leveraging its Gemini AI to create sophisticated phishing websites and campaigns.
Spanish police, acting on an FBI tip, have arrested a man suspected of coordinating cyberattacks for pro-Russia hacktivist groups like CARR and NoName057(16), which target critical national infrastructure.
Attackers are exploiting Microsoft Teams calls and social engineering to trick victims into installing EtherRAT, a sophisticated cross-platform trojan.