๐ต๏ธ RESEARCH & DEEP DIVES
-
23 Copeland XWEB Pro flaws could give attackers root control of refrigeration systems Claroty found 23 vulnerabilities in Copeland XWEB Pro refrigeration controllers.
- The flaws affect commercial refrigeration, air-conditioning and food-retail operators, including supermarkets, warehouses and hospitals.
- The XWEB Pro platform contains 23 vulnerabilities, including 21 high-severity issues.
- An unauthenticated network attacker can bypass security controls and achieve root-level remote code execution.
- Compromised controllers can influence connected compressors, evaporators and environmental sensors, potentially spoiling temperature-sensitive goods without immediate detection. ๐ Coverage: itwire.com ยท ๐ via Cyber Security News
-
Malicious SIMs can hijack phones and cellular IoT devices via modem commands Researchers found malicious SIMs can hijack some phones and cellular IoT devices.
- The risk affects smartphones, EV chargers, connected cars, industrial equipment, and routers.
- Researchers tested 26 devices: 18 smartphones and eight cellular IoT modems; nine exposed SIM-accessible AT commands, including seven IoT modems.
- Proactive SIM functionality lets a SIM invoke RUN AT and issue modem AT commands through the SIM interface.
- CATANA-enabled attacks achieved code execution, arbitrary file reads, device shutdowns, cellular denial of service, and 4G-to-2G downgrades.
- The Android locked-phone browser flaw is tracked as
CVE-2025-48618; the broader findings includeCVE-2026-57550andCVD-2026-0122. ๐ Source: usenix.org ยท ๐ Coverage: theregister.com ยท ๐ via The Hacker News
-
Researchers Hire Three Suspected North Korean Operatives at Fake Crypto Startup Researchers hired three suspected North Korean IT workers through a fake crypto startup.
- The operation targeted remote developer roles at a fabricated DeFi startup called Ballena Azul.
- Three suspected Famous Chollima operatives obtained employee accounts and access to source code and internal systems.
- Recruiters found inconsistent U.S. identities, mismatched state documents, proxy bank accounts and AI-processed identification images.
- The operatives profiled issued virtual machines with dxdiag, systeminfo and wmic before checking their apparent connection countries.
- Observed tooling included Chrome Remote Desktop, 2fa.cn, AIApply, Final Round AI, Simplify Copilot, Vultr, Gorilla Servers and AstrillVPN exit nodes. ๐ Source: any.run ยท ๐ Coverage: thehackernews.com ยท ๐ via The Hacker News, @zackwhittaker@mastodon.social
-
Cloudflare reports 519% surge in DDoS attacks above 1 Tbps Cloudflare reported a 519% quarter-over-quarter increase in DDoS attacks above 1 Tbps.
- Cloudflare customers worldwide were targeted, with Media, Production, and Publishing receiving 14.2% of mitigated HTTP DDoS requests in H1 2026.
- Cloudflare mitigated 23.2 million network-layer DDoS attacks and 29.64 trillion malicious HTTP requests in H1 2026.
- Attacks exceeding 1 Tbps rose from 130 in Q1 to 805 in Q2 2026.
- DNS floods accounted for 40% of network-layer attacks in Q2, while CLDAP floods increased 881.9% quarter over quarter.
- Attackers used DNS reflection and amplification techniques, including spoofed queries against open resolvers and CLDAP traffic over UDP port 389. ๐ Source: blog.cloudflare.com ยท ๐ Coverage: bleepingcomputer.com ยท ๐ via BleepingComputer, Cloudflare Blog
-
US Water Utilities Get New Cybersecurity Bill and Water Watch Center US lawmakers and cybersecurity groups launched initiatives to protect water utilities from cyberattacks.
- The effort covers US water and wastewater utilities, especially systems serving fewer than 10,000 people.
- The Water Cyber Shield Act would expand EPA cybersecurity authority and authorize $300 million annually for water infrastructure funds.
- The Water Watch Center was launched by DEF CON Franklin and the National Rural Water Association.
- Five cybersecurity firms will provide managed detection and response services through the center.
- Attackers targeted internet-facing Rockwell/Allen-Bradley MicroLogix 1100 and 1400 PLCs, changing IP addresses and passwords to disrupt monitoring and control. ๐ Coverage: securityweek.com ยท ๐ via SecurityWeek
๐ ADVISORIES
-
SAP Patches Critical Code-Injection and Memory-Corruption Flaws SAP released security updates for critical code-injection and memory-corruption vulnerabilities.
- SAP customers using affected SAP products are impacted.
- SAP issued 28 new and two updated security notes.
- Four of the new notes address critical-severity flaws.
- The critical flaws include code injection and memory corruption vulnerabilities. ๐ Coverage: securityweek.com ยท ๐ via SecurityWeek
-
Plug & Pwn Chains Windows PnP Driver Installs Into SYSTEM Access ๐ Source: plugandpwn.com
๐ CVEs & KEV
- CVE-2026-58115 โ CVSS 10.0 โ A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA0...
- CVE-2026-18972 โ CVSS 9.6 โ Velociraptor authenticated identity-spoofing vulnerabilityAn authenticated at...
- CVE-2026-72785 โ CVSS 9.3 โ Craft CMS before 5.10.6 Authorization Bypass via structures/move-elementCraft...
- CVE-2026-69109 โ CVSS 8.7 โ A vulnerability has been identified in Siemens License Server (SLS) (All vers...
- CVE-2026-69108 โ CVSS 8.3 โ A vulnerability has been identified in Siemens License Server (SLS) (All vers...
- CVE-2026-50064 โ CVSS 7.3 โ A vulnerability has been identified in Solid Edge SE2025 (All versions before V225...
- CVE-2026-50063 โ CVSS 7.3 โ A vulnerability has been identified in Solid Edge SE2025 (All versions before V225...
- CVE-2026-50062 โ CVSS 7.3 โ A vulnerability has been identified in Solid Edge SE2025 (All versions before V225...
- CVE-2026-50061 โ CVSS 7.3 โ A vulnerability has been identified in Solid Edge SE2025 (All versions before V225...
- CVE-2026-50060 โ CVSS 7.3 โ A vulnerability has been identified in Solid Edge SE2025 (All versions before V225...
- CVE-2026-50059 โ CVSS 7.3 โ A vulnerability has been identified in Solid Edge SE2025 (All versions before V225...
- CVE-2026-50058 โ CV