View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

U.S. Agencies Warn of Active Threat to Siemens S7 PLCs

🚨 ACTIVE EXPLOITATION

  • U.S. Agencies Warn of Active Threat to Siemens S7 PLCs
    Threat actors are actively targeting Siemens S7 Series PLCs.
    • U.S.-based Siemens PLC installations in manufacturing, energy, water, chemical, food and agriculture, and commercial facilities are targeted.
    • Affected models include S7-200, S7-300, S7-400, S7-1200, and S7-1500 series PLCs, including F-series safety controllers.
    • Attackers use Censys and ZoomEye to find Internet-exposed or poorly segmented PLCs running outdated software or weak authentication.
    • AI-generated Python tools using snap7.dll or python-snap7 masquerade as monitoring software and provide S7comm read/write access to memory, configuration data, and ladder logic.
      πŸ“„ Source: cisa.gov Β· πŸ“Ž Coverage: yahoo.com Β· πŸ‘ via CISA Advisories

πŸ•΅οΈ RESEARCH & DEEP DIVES

  • China-Nexus Actor Uses JPEG-Masquerading VHDs to Deliver QUICAgent
    A China-nexus actor targeted Myanmar government personnel with QUICAgent malware.

    • Targets Myanmar government, diplomatic, and technology personnel with Burmese-language lures impersonating ITCSD.
    • Malicious VHD files masquerade as JPEG images and contain a decoy graduation invitation plus QUICAgent, a Go-based backdoor.
    • An LNK abuses ftp.exe to run scripts, reconstruct split payloads, and launch the implant from the user’s application-data folder.
    • QUICAgent resolves C2 through Cloudflare Workers, communicates over HTTP/3 QUIC with RC4 encryption, and persists via a Startup-folder shortcut.
    • Reported IOCs include 38.60.244.141, maui-cocktailbar.com, register.mediumser.com, and SHA-256 26f735cbbb1257be94e6d01656a35bf66a8ae9c34868548d69ec5cb588f9f916.
      πŸ“„ Source: seqrite.com Β· πŸ“Ž Coverage: cybersecuritynews.com Β· πŸ‘ via Cyber Security News
  • PoC Escapes WABT wasm2c Sandbox to Execute Host Shell Commands
    A proof of concept escaped WABT's wasm2c sandbox and executed shell commands on the host.

    • WABT wasm2c users are affected, including projects using Firefox through RLBox.
    • The generated C code does not preserve WebAssembly sandbox security, allowing host command execution.
    • A published proof of concept demonstrates the sandbox escape and arbitrary shell execution.
      πŸ“„ Source: threads.net Β· πŸ“Ž Coverage: trustsig.eu Β· πŸ‘ via r/netsec
  • Mirage2FA Steals Microsoft 365 Sessions After Users Complete MFA
    Mirage2FA is stealing Microsoft 365 sessions after users complete MFA.

    • Microsoft 365 users, especially in U.S. technology, manufacturing, and education sectors, are targeted.
    • Researchers identified 4,532 potentially compromised addresses among 9,426 targets.
    • The AiTM proxy relays credentials and MFA in real time before capturing session cookies and refresh tokens.
    • HTML-smuggled attachments, fake CAPTCHA pages, QR codes, JavaScript obfuscation, and WebSocket communications support delivery and evasion.
    • Reported indicators include cheacker[.]store and 185.174.100.224.
      πŸ“Ž Coverage: brinztech.com Β· πŸ‘ via Cyber Security News
  • Cloudflare Revisits Remote Spectre Attacks Against Workers
    Cloudflare has reassessed remote Spectre attacks targeting its Workers infrastructure.

    • Cloudflare Workers infrastructure is affected.
    • Remote Spectre attacks target isolation between Workers workloads.
    • The research examines Spectre gadgets, remote timers, and achieving co-location.
    • Cloudflare describes additional defenses that harden Workers against these attacks.
      πŸ“Ž Coverage: blog.cloudflare.com Β· πŸ‘ via Cloudflare Blog
  • Kimi K3 reportedly succeeds on CyScenarioBench cyber evaluations
    Kimi K3 has demonstrated near-autonomous cyber campaign capabilities.

    • Moonshot AI’s Kimi K3 is the first reported open-weight model to succeed on CyScenarioBench.
    • K3 can conduct cyber campaigns autonomously or near-autonomously.
    • The model turns partial access into complete attack chains by adapting public exploit techniques to constrained environments.
    • K3 builds custom tooling, diagnoses implementation failures, and validates each stage before proceeding.
    • K3 trails closed frontier models by about six months and costs roughly three times less than Fable 5.
      πŸ“Ž Coverage: reddit.com Β· πŸ‘ via r/cybersecurity
  • Black Kite finds mid-market firms account for 73% of ransomware victims
    Black Kite found that mid-market firms accounted for 73% of ransomware victims.

    • Organizations with $10 million to $1 billion in revenue across North America and Europe were the primary targets.
    • Manufacturing represented 26% of mid-market ransomware victims, followed by professional, scientific and technical services and construction.
    • Black Kite analyzed 13,336 disclosed incidents since January 2023 and scanned 120,128 mid-market companies.
    • Exposure findings included known exploited vulnerabilities at 28% of firms and significant patch-management issues on public-facing software at 55%.
    • Other findings included high-severity vulnerabilities at 48% of firms, stealer-log exposures at 32% and inadequate DMARC at 47%.
      πŸ“„ Source: blackkite.com Β· πŸ“Ž Coverage: infosecurity-magazine.com Β· πŸ‘ via Cybersecurity Dive

πŸ“‹ ADVISORIES

  • U.S. Agencies Warn of Active Threat to Siemens S7 PLCs
    Threat actors are actively targeting Siemens S7 Series PLCs.

    • U.S.-based Siemens PLC installations in manufacturing, energy, water, chemical, food and agriculture, and commercial facilities are targeted.
    • Affected models include S7-200, S7-300, S7-400, S7-1200, and S7-1500 series PLCs, including F-series safety controllers.
    • Attackers use Censys and ZoomEye to find Internet-exposed or poorly segmented PLCs running outdated software or weak authentication.
    • AI-generated Python tools using snap7.dll or python-snap7 masquerade as monitoring software and provide S7comm read/write access to memory, configuration data, and ladder logic.
      πŸ“„ Source: cisa.gov Β· πŸ“Ž Coverage: yahoo.com Β· πŸ‘ via CISA Advisories
  • Critical NetScaler Flaws Enable Authentication Bypass and Denial of Service CVE-2026-19489 CVE-2026-19490
    Cloud Software Group disclosed two critical NetScaler vulnerabilities.

    • NetScaler ADC and NetScaler Gateway customers, including customer-managed Secure Private Access Hybrid deployments, are affected.
    • CVE-2026-19490 enables authentication bypass on SSL VPN, ICA Proxy, CVPN, RDP Proxy, and AAA virtual-server configurations.
    • On newer builds, CVE-2026-19490 requires a SAML action; earlier builds are exposed through any Gateway or AAA virtual server.
    • CVE-2026-19489 is a memory overflow triggered by SIP ALG enabled in an LSN group, causing unpredictable behavior or denial of service.
    • Affected versions are NetScaler 14.1 before 73.32 and 13.1 before 63.21, including corresponding FIPS and NDcPP variants.
      πŸ“„ Source: support.citrix.com Β· πŸ“Ž Coverage: cybersecuritynews.com Β· πŸ‘ via Cyber Security News
  • CISA and partners expand SBOM minimum elements to cover AI and SaaS
    CISA and international partners released updated SBOM minimum-elements guidance.

    • The guidance applies to all software, including open source, AI systems, and software-as-a-service products.
    • CISA, NSA, FBI, and 15 international agencies replaced the 2021 NTIA baseline on July 29, 2026.
    • Ten new fields include component hashes, licenses, SBOM tool name, and generation context.
    • AI-specific models, datasets, and weights remain covered by separate supplemental guidance rather than dedicated general-baseline fields.
      πŸ“„ Source: cisa.gov Β· πŸ“Ž Coverage: paubox.com Β· πŸ‘ via securityboulevard.com (discovered)

πŸ”“ CVEs & KEV

  • CVE-2026-71176 β€” CVSS 8.8 β€” Dell OpenManage Enterprise SQL Injection (CVE-2026-71176)

  • [ADVISORIES] πŸ“„ Source for CISA Adds Actively Exploited Microsoft Windows IKE RCE Flaw β€” msrc.microsoft.com

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check