ABB has patched a search-path flaw in Advant Master Online Builder that could let someone with the required access load untrusted code on an affected node.
A Linux kernel weakness mapped to ABB Ability Edgenius shows how a local-only bug can matter just as much as a remote one when the affected system sits near operational data.
A critical authentication failure in Rockwell Automation’s 1715-AENTR EtherNet/IP adapter shows how an exposed service path can turn an OT maintenance feature into a high-risk control surface.
A security advisory for ABB T-MAC Plus shows how one industrial platform can expose web files, role boundaries, browser sessions, and field-device communications at the same time.
Two disclosed authorization flaws could let a low-privilege view into OAuth material and cross-tenant broker metadata, underscoring how messaging systems depend on disciplined boundary enforcement.
A ransomware label tied to Graphic-International-Centre and graphicint.com is enough to merit attention, but not enough to confirm an intrusion.
A named ransomware group has claimed an attack tied to SITAV-SpA and a listed website, but the allegation remains unverified and the operational impact is not established.
A post in which Dragonforce claims a ransomware attack names Edison-Global-Networks-Limited, but the public evidence stops short of confirming a breach.
Dutch intelligence has tied a Russian-linked surveillance campaign to internet-connected cameras used to watch military logistics and Ukrainian personnel across Europe.
A vendor-described chaining method tests whether an attack path can work in production by checking the steps an exploit needs, not by launching the exploit itself.
A small shortcut in UDP discovery code can turn IPv4 subnetting into a reliability problem, and sometimes a security one, once real networks stop looking like a neat /24.
ZEGO GmbH’s case shows how a single intrusion can turn a production pause into a severe financial crisis for an industrial business.
A July supervisory letter gives banks until 31 October 2026 to file an action plan on AI-enabled cyber threats, tying the request to DORA-style operational resilience.
A new healthcare warning puts supply-chain security, identity management, and staff readiness in the same frame: cyber risk becomes operational risk when hospitals cannot trust who connects, who updates, or who responds.
A 60-day review of the CMMC rollout may ease near-term pressure, but it also leaves defense suppliers navigating an uncertain compliance timetable.
A SANS Institute report points to rising AI use in cyber defense and a widening split between leadership enthusiasm and the controls frontline teams actually need.
A June ranking placed Brazil 3rd in ransomware activity, with 23 cases recorded by Ransomware.live.
An allegation involving Italian politicians, journalists, and managers on Signal is a reminder that secure messaging is only as strong as the phone, account, and linked sessions behind it.
A new cluster of Zoom flaws shows how collaboration software can become an access-control problem on Windows, with exposure reaching clients, rooms, VDI plugins, and embedded SDK deployments.
A ransomware post names aphenapharma.com, a hash, and a related company page, yet none of that by itself proves a confirmed intrusion.