1553 results found

  • high · nvd.nist.gov

    PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that allows local users to modify hardware configuration by exploiting exposed IOCTLs with no validation on device selection, register offset, or value. Attackers can obtain a device handle and issue arbitrary PCI configuration space read/write operations to enable Bus Master DMA on any PCI device, halt storage controller I/O by clearing command registers, or remap Base Address Registers to redirect DMA to an attacker-chosen physical address.

    A privilege escalation vulnerability exists in DirectIo64.sys, a kernel driver used by PassMark PerformanceTest (before 11.1 build 1012), BurnInTest (before 11.1 build 1000), and OSForensics (before 11.1 build 1016). The driver exposes IOCTLs with no validation on device selection, register offset, or value, allowing local users to gain elevated privileges. Attackers can obtain a device handle and issue arbitrary PCI configuration space read/write operations. Exploitation can enable Bus Master DMA on any PCI device, halt storage controller I/O by clearing command registers, or remap Base Address Registers to redirect DMA to attacker-controlled physical memory. The vulnerability is rooted in insufficient input validation within the exposed kernel-level IOCTL interface. Patches are available in the respective updated builds of each affected product.

    View original advisory →
  • critical · nvd.nist.gov

    A missing authorization vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows a lower-privileged Admin user to escalate privileges to SuperAdmin.

    A missing authorization vulnerability has been identified in the SonicWall Network Security Manager (NSM) On-Prem Management interface. The flaw allows a lower-privileged Admin user to escalate their privileges to SuperAdmin level. This represents a significant security risk as it can lead to unauthorized control over network security management functions. The vulnerability is tracked as CVE-2026-78328 and has been assigned a high criticality rating. SonicWall has published an advisory via their PSIRT portal under identifier SNWLID-2026-0015. Organizations running SonicWall NSM On-Prem deployments are advised to review the advisory and apply mitigations promptly. Privilege escalation vulnerabilities of this type can allow attackers with limited access to gain full administrative control over critical network security infrastructure.

    View original advisory →
  • medium · bleepingcomputer.com

    Coder's registry infrastructure compromised to push malicious modules

    Attackers compromised Coder's Cloudflare infrastructure to inject unauthorized registry servers into the platform. These rogue servers were used to deliver malicious Terraform modules containing credential-stealing code. The attack represents a supply chain compromise targeting developers using Coder's registry. By hijacking the infrastructure layer rather than the codebase directly, attackers could silently distribute malware to unsuspecting users. The credential-stealing payloads embedded in the Terraform modules pose a significant risk to affected organizations. This incident highlights the growing trend of supply chain attacks targeting developer tooling and infrastructure registries.

    View original advisory →
  • medium · bleepingcomputer.com

    HPE patches critical ArubaOS-CX remote code execution flaw

    Hewlett Packard Enterprise (HPE) has released patches addressing a critical vulnerability in the ArubaOS-CX network operating system. The flaw could allow remote attackers to execute arbitrary code on affected devices. ArubaOS-CX is a widely deployed network operating system used in enterprise switching environments. The vulnerability poses significant risk to organizations relying on HPE Aruba networking infrastructure. HPE has urged customers to apply the patches promptly to mitigate potential exploitation. No specific CVE identifier was mentioned in the article excerpt provided.

    View original advisory →
  • medium · thehackernews.com

    Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

    Cisco has released patches for a critical vulnerability (CVE-2026-20212, CVSS 9.8) affecting 10 Silicon One-based Nexus 9000 switches. The flaw allows unauthenticated remote attackers to execute arbitrary code as root. Additionally, Cisco released an IOS XR hardening update bundling 7 umbrella CVEs, two of which are rated 9.8. No workarounds exist for any IOS XR version, making patching the only remediation. The severity and unauthenticated nature of the exploit make this a high-priority issue for network administrators running affected Cisco hardware.

    View original advisory →
  • medium · thehackernews.com

    BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory

    Cybersecurity researchers have uncovered a sophisticated Python-based Windows malware framework called BraZetsu that supports an underground criminal marketplace. Unlike traditional infostealers, BraZetsu functions as a comprehensive master toolkit specifically designed to empower Initial Access Brokers (IABs). The malware turns compromised Windows systems into commercial inventory that can be sold or traded on underground markets. BraZetsu represents an evolution in the IAB ecosystem by automating and streamlining the process of monetizing access to compromised hosts. The framework's design suggests a highly organized criminal operation aimed at commercializing unauthorized system access at scale.

    View original advisory →
  • medium · bleepingcomputer.com

    Critical Elementor Pro flaw exploited to take over WordPress sites

    A critical vulnerability CVE-2026-32475 in the Elementor Pro WordPress plugin is being actively exploited in the wild. Attackers are leveraging the flaw to deliver webshell payloads onto compromised servers, enabling arbitrary command execution. The vulnerability has been patched, but exploitation is ongoing against unpatched installations. WordPress site owners using Elementor Pro are urged to apply the patch immediately. The attacks represent a significant risk as Elementor Pro is widely used across millions of WordPress sites, making the attack surface extremely large. Successful exploitation could lead to full site takeover and server compromise.

    View original advisory →
  • medium · thehackernews.com

    Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data

    Thomson Reuters disclosed that an unauthorized party gained access to files from C-Track, a court case management platform operated by its West Publishing Corporation subsidiary. The breach occurred in March 2026 and was discovered on June 30, 2026. The incident affected courts across 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada. Exposed data may include sensitive personal information such as Social Security Numbers (SSNs) and sealed court records. The breach raises serious concerns about the exposure of confidential legal data and the privacy of individuals involved in court proceedings. West Publishing is notifying affected courts and individuals. The scale of the breach and the sensitivity of the data involved make this a high-impact incident for both the legal system and affected individuals.

    View original advisory →
  • medium · cisa.gov

    Pyramid Solutions NetStaX EtherNet/IP Stack

    A critical stack-based buffer overflow vulnerability (CVE-2026-78012) has been identified in Pyramid Solutions NetStaX EtherNet/IP Stack versions prior to v5.6.1. The flaw allows a large Class 3 explicit-message request to exceed the application-side receive buffer without generating an error or warning. Successful exploitation could result in memory corruption, device crash, or a potential remote attack vector. All eight product variants of the NetStaX stack are affected, including adapter and scanner kits with and without CIP Security. The vulnerability carries a CVSS v3.1 score of 9.8 (CRITICAL) and a CVSS v4.0 score of 9.3 (CRITICAL). It impacts critical infrastructure sectors including Critical Manufacturing, Energy, Water and Wastewater, and Chemical industries worldwide. The fix is available in NetStaX v5.6.1, which implements compile-time assertions, runtime payload-size checks, and improved documentation. No known public exploitation has been reported to CISA at this time.

    View original advisory →
  • medium · cisa.gov

    Rockwell Automation 1756-ENBT Module

    A denial-of-service vulnerability (CVE-2025-10478) exists in the Rockwell Automation 1756-ENBT module, a ControlLogix EtherNet/IP bridge used to connect Logix 5000 controllers with Ethernet devices. An unauthenticated remote attacker can exploit this vulnerability by sending a crafted CIP packet, causing the module to crash and requiring a manual restart to recover. The vulnerability is classified as CWE-754 (Improper Check for Unusual or Exceptional Conditions) and carries a CVSS v3.1 score of 7.5 (HIGH) and a CVSS v4.0 score of 8.7 (HIGH). All versions of the 1756-ENBT module are affected. Rockwell Automation recommends upgrading to 1756-EN2T or 1756-EN4TR as the primary mitigation. The vulnerability affects critical infrastructure sectors including Critical Manufacturing, Food and Agriculture, Transportation Systems, and Water and Wastewater. No known public exploitation has been reported at the time of publication. The advisory was initially released on September 3, 2026, and was reported to CISA by Rockwell Automation.

    View original advisory →
  • medium · cisa.gov

    IXON VPN Client

    A critical vulnerability (CVE-2026-75925) has been identified in IXON VPN Client versions prior to 1.4.7, involving Improper Neutralization of CRLF Sequences (CWE-93). Successful exploitation allows an attacker to perform remote code execution with elevated privileges (root or SYSTEM) on the affected machine. The vulnerability stems from configuration values being written to a file consumed by a privileged subprocess without sanitizing line-ending sequences, and the configuration interface accepts changes without authentication (CWE-306). The injected configuration persists across restarts, making it stealthy as no behavioral changes are visible to users. CVSS v3.1 score is 9.6 (CRITICAL) and CVSS v4.0 score is 9.4 (CRITICAL). Affected sectors include Commercial Facilities, Critical Manufacturing, Energy, IT, and Water/Wastewater globally. IXON has mitigated the issue server-side by rejecting connections from clients below v1.4.7 as of August 5, 2026, and recommends updating to v1.4.7 or later. No known public exploitation has been reported to CISA at this time.

    View original advisory →
  • medium · cisa.gov

    Rockwell Automation ArmorStart LT

    CISA has published an advisory for Rockwell Automation ArmorStart LT versions up to and including v2.001, which are affected by two vulnerabilities. CVE-2026-19471 is a stored cross-site scripting (XSS) vulnerability (CWE-79) that allows attackers to inject malicious scripts executed when other users access the affected page. CVE-2026-19472 is a denial-of-service vulnerability (CWE-770) caused by improper handling of crafted HTTP PUT requests to the embedded web server, resulting in loss of web server availability. Both vulnerabilities are remotely exploitable with no authentication required. The highest CVSS v3.1 score is 7.5 (HIGH) for the DoS vulnerability. Rockwell Automation has addressed both issues in firmware version v2.002 and encourages users to update. No known public exploitation has been reported. The affected product is deployed worldwide in Critical Manufacturing sectors.

    View original advisory →
  • medium · cisa.gov

    Rockwell Automation ControlFLASH

    A vulnerability (CVE-2026-12663) exists in Rockwell Automation ControlFLASH versions up to and including V15.07. The installer incorrectly grants write permissions to the 'Everyone' group on the product installation directory, enabling arbitrary code execution at the logged-in user's permission level. The vulnerability is classified as Missing Authentication for Critical Function (CWE-306) with a CVSS v3.1 score of 7.3 (HIGH). Affected critical infrastructure sectors include Critical Manufacturing, Energy, and Water and Wastewater. Rockwell Automation has released version 15.08 to address the issue. Users unable to upgrade can manually remove the 'Everyone' group from the ControlFLASH installation directory permissions. The vulnerability is not remotely exploitable and no known public exploitation has been reported. Rockwell Automation self-reported the vulnerability to CISA.

    View original advisory →
  • medium · cisa.gov

    Tycon Systems TPDIN-Monitor-WEB3

    CISA has published an advisory for Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior, identifying three vulnerabilities: Use of Hard-coded Credentials (CVE-2026-77847), Cross-Site Request Forgery (CVE-2026-82712), and Missing Authorization (CVE-2026-82684). Successful exploitation could allow attackers to perform man-in-the-middle attacks, cause factory resets, wipe credentials, or retrieve sensitive information. The highest CVSS v3.1 score is 8.8 (HIGH) for the CSRF vulnerability. Affected devices are deployed worldwide in Critical Manufacturing and Energy sectors. Tycon Systems has released firmware v2.4.2 as a fix, with separate update artifacts for legacy (Intel HEX) and newer (signed .tfw container) units. The vulnerabilities were reported by Abdiwelli Guled to CISA. No known public exploitation has been reported at this time.

    View original advisory →
  • medium · cisa.gov

    Inductive Automation Ignition

    CISA published an ICS advisory for Inductive Automation Ignition versions 8.1.53 and earlier, affected by CVE-2026-77393, a high-severity vulnerability with a CVSS v3.1 score of 8.8. The vulnerability stems from the 'Create Project Role(s)' gateway setting shipping blank by default, allowing any authenticated user with gateway script execution capability to create projects. This is classified as CWE-276 (Incorrect Default Permissions). Affected sectors include Critical Manufacturing, Energy, and Information Technology. Remediation includes upgrading to Ignition 8.1.54 or later, or populating the 'Create Project Role(s)' setting to restrict project creation to authorized roles. The 8.3 series is not affected. No known public exploitation has been reported. The vulnerability was reported by Christopher Lusk of North Echo Security Research and independently confirmed by Elhussain Fathy (0xSphinx).

    View original advisory →
  • medium · thehackernews.com

    US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries

    A large-scale phishing campaign initially believed to target Canadian users via Canada Revenue Agency (CRA) tax form lures has been revealed as a much broader operation spanning 46 countries. The United States has emerged as the top target, accounting for approximately 45% of observed activity. ANY.RUN researchers linked 601 cases to the wider operation. The campaign leverages Remote Monitoring and Management (RMM) tools as part of its attack chain, likely to gain persistent access to victim systems. The use of legitimate tax-related lures adds a layer of social engineering credibility to the attacks. The geographic breadth and volume of cases indicate a well-organized and ongoing threat actor operation.

    View original advisory →
  • medium · thehackernews.com

    Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks

    Threat actors are exploiting the trusted Node.js JavaScript runtime (node.exe) to deploy malicious payloads in targeted cyberattacks. The campaign, identified by the Symantec Threat Hunter Team, has been active since February 2026. Targets include government departments, technology companies, and hotels. The technique leverages the legitimacy of node.exe to bypass security controls and deliver malware. The abuse of trusted runtimes makes detection more challenging for defenders. This represents a living-off-the-land style attack leveraging legitimate software. The campaign appears targeted rather than opportunistic, focusing on specific sectors. The method's appeal lies in the trusted nature of the Node.js binary, which may evade endpoint security tools.

    View original advisory →
  • medium · thehackernews.com

    Shai-Hulud's Reach Just Grew to 469 Credential Locations. Here's What That Means

    A new variant of the Shai-Hulud infostealer worm has significantly expanded its credential-harvesting capabilities, now scanning 469 locations compared to only 189 in earlier variants. The malware targets developer environments, CI/CD pipelines, cloud configurations, and AI tool configurations. This evolution was discovered by GitGuardian researchers in early August. The dramatic increase in targeted paths indicates a deliberate effort by attackers to broaden their attack surface and maximize credential theft. The expansion into AI tool configurations is particularly notable as it reflects attackers adapting to modern development tooling trends.

    View original advisory →
  • medium · thehackernews.com

    Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone

    A member of Serbia's student protest movement had their iPhone infected with NSO Group's Pegasus spyware, as confirmed by Citizen Lab in collaboration with the SHARE Foundation. The attack leveraged an iMessage zero-click exploit, meaning the victim did not need to interact with any malicious content for the infection to occur. High-confidence indicators of Pegasus infection were identified on the device. This incident highlights the continued use of sophisticated commercial spyware against civil society members and activists. The NSO Group's Pegasus has been repeatedly linked to targeting journalists, activists, and political dissidents worldwide. The findings underscore ongoing concerns about the abuse of commercial surveillance tools against vulnerable populations.

    View original advisory →
  • high · nvd.nist.gov

    GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the API endpoint for creating a new formatter via file upload is unprotected and allows the upload of external uncontrolled files. An unauthenticated attacker can upload arbitrary `.xsl` or `.zip` formatter files to the server. An unauthenticated attacker can write arbitrary files into the GeoNetwork formatter directory. On its own this constitutes unauthorized write access to server storage. The issue is patched in GeoNetwork versions 4.4.12 and 4.2.17.

    A critical vulnerability (CVE-2026-63219) was discovered in GeoNetwork, a catalog application for managing spatially referenced resources. The API endpoint for creating new formatters via file upload is completely unprotected, requiring no authentication. An unauthenticated attacker can upload arbitrary .xsl or .zip formatter files to the server, resulting in unauthorized write access to server storage. The vulnerability affects GeoNetwork versions prior to 4.4.12 and 4.2.17. This flaw could potentially be chained with other vulnerabilities to achieve remote code execution, as referenced by The Hacker News article about unauthenticated RCE. Patches have been released in GeoNetwork versions 4.4.12 and 4.2.17. Users are strongly advised to upgrade to the patched versions immediately to mitigate the risk of exploitation.

    View original advisory →