💥 BREACHES & INCIDENTS
- Novocure cyberattack exposed records of more than 1,400 U.S. cancer patients
Novocure disclosed a cyberattack exposing records of more than 1,400 U.S. cancer patients.- Novocure patients and employees were affected, including more than 1,400 U.S. cancer patients.
- Patient records contained internal IDs; fewer than 50 western U.S. patients also had identifying information exposed.
- Healthcare provider contact details and employee job titles and phone numbers were exposed.
- Attackers gained unauthorized access to Novocure information systems in mid-August; the entry method was not disclosed.
📄 Source: sec.gov · 📎 Coverage: bleepingcomputer.com · 👁 via BleepingComputer
🕵️ RESEARCH & DEEP DIVES
-
ESET Links Backdoor Activity to Financial Services in the Netherlands and Kazakhstan
ESET identified a backdoor targeting financial services in the Netherlands and Kazakhstan.- Financial services organizations in the Netherlands and Kazakhstan were targeted between November 2020 and November 2023.
- ESET found a DLL variant compiled on August 3, 2020, exporting as versiond.dll, and a standalone EXE compiled on November 18, 2020.
- A WMI subscription named Realtek launched the 12 KB backdoor and kept it running.
- The malware concealed its C2 domain by counting spaces in a fake desktop.ini file and continued contacting an abandoned domain for 11 months.
- The samples used a singleton event to prevent duplicate execution and supported three commands.
📎 Coverage: infosec.exchange · 👁 via @ESETresearch@infosec.exchange
-
trusted-cloud-services-financial-phishing — Cyber Security News
📋 ADVISORIES
-
CISA Flags Two Vulnerabilities in Rockwell FactoryTalk Historian ME
CVE-2025-12768CVE-2026-12661
CISA reported two vulnerabilities affecting Rockwell FactoryTalk Historian Machine Edition.- Affected users include worldwide operators in chemical, critical manufacturing, food and agriculture, healthcare, and water sectors.
- Series B 5.202 and Series C 7.101 are affected by CVE-2025-12768 and CVE-2026-12661.
- CVE-2025-12768 is an out-of-bounds write that may enable remote code execution for a low-privileged authenticated attacker.
- CVE-2026-12661 is a stack-based buffer overflow triggered by crafted web-interface requests from an authenticated adjacent-network attacker, potentially crashing the device.
📄 Source: rockwellautomation.com · 📎 Coverage: cisa.gov · 👁 via CISA Advisories, CVE ThreatInt (+1)
-
Rockwell FactoryTalk Activation Manager flaw enables SYSTEM privilege escalation
CVE-2026-16675
CISA disclosed a high-severity privilege-escalation flaw in Rockwell FactoryTalk Activation Manager.- Critical manufacturing organizations worldwide using FactoryTalk Activation Manager are affected.
- FactoryTalk Activation Manager V5.02 and earlier contain CVE-2026-16675, rated 7.8 HIGH under CVSS 3.1.
- An authenticated attacker with Windows credentials can hijack installer console windows spawned with SYSTEM privileges during installation or repair.
- Successful exploitation provides a SYSTEM-level command prompt and access to files, processes, and system resources.
📄 Source: rockwellautomation.com · 📎 Coverage: cisa.gov · 👁 via CISA Advisories
-
CISA discloses four denial-of-service flaws in Rockwell RSLinx Classic
CVE-2026-9621CVE-2026-9622CVE-2026-9624CVE-2026-9625
CISA disclosed four denial-of-service vulnerabilities in Rockwell RSLinx Classic.- Rockwell Automation RSLinx Classic users in critical manufacturing worldwide are affected.
- RSLinx Classic versions 4.50 and earlier are vulnerable to service crashes.
- Crafted CIP packets can trigger crashes through malformed data, Forward Close requests, or oversized embedded messages.
- The flaws are tracked as CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, and CVE-2026-9625.
📄 Source: rockwellautomation.com · 📎 Coverage: cisa.gov · 👁 via CISA Advisories, CVE ThreatInt (+3)
-
CISA discloses two denial-of-service flaws in Rockwell Logix controllers
CVE-2021-42260CVE-2026-9637
CISA disclosed denial-of-service flaws affecting Rockwell Automation Logix controllers.- Affected products include ControlLogix 5580, CompactLogix 5380 and 5480, GuardLogix 5580, and Compact GuardLogix 5380 used in critical manufacturing worldwide.
- CVE-2021-42260 affects firmware below 34.015, 35.014, 36.013, and 37.011.
- CVE-2026-9637 affects versions V33 and earlier, V34.011–V34.014, V35.011–V35.013, and V36.011–V36.012.
- CVE-2021-42260 can be triggered with corrupt crafted data, causing a major nonrecoverable fault.
- CVE-2026-9637 stems from improper input-length validation during CIP message processing and can cause a major nonrecoverable fault requiring a power cycle.
📄 Source: rockwellautomation.com · 📎 Coverage: cisa.gov · 👁 via CISA Advisories, CVE ThreatInt (+1)
-
Rockwell Redundancy Module Configuration Tool Has Two Privilege-Escalation Flaws
CVE-2026-9633CVE-2026-9634
Rockwell's Redundancy Module Configuration Tool has two privilege-escalation vulnerabilities.- Affects critical-manufacturing environments using Rockwell Automation's Redundancy Module Configuration Tool worldwide.
- Version 10.00.00 is affected by CVE-2026-9633; versions 9.00.00 through 10.00.00 are affected by CVE-2026-9634.
- Incorrect default permissions leave system-path directories writable by standard users.
- A local attacker can place a malicious DLL that RM3ConfigTool.exe or RMConfigTool.exe loads when an administrator runs the tool, enabling Administrator/SYSTEM execution.
📄 Source: rockwellautomation.com · 📎 Coverage: cisa.gov · 👁 via CISA Advisories, CVE ThreatInt (+1)
-
📄 Source for Attackers Exploit Critical Langflow and Rails Vulnerabilities — vulncheck.com
-
📄 Source for CVE-2026-80047 lets Transformers write remote code before consent checks — kb.cert.org
🔓 CVEs & KEV
-
CVE-2026-9621 — Rockwell Automation RSLinx Classic® — CVSS 9.2 — RSLinx Classic® - Multiple VulnerabilitiesA denial-of-service security issue ...
-
CVE-2026-58571 — Dell PowerStore 500T — CVSS 8.8 — Dell PowerStore contains an OS Command Injection vulnerability. An authentica...
-
CVE-2026-79684 — Dell PowerStore 500T — CVSS 8.8 — Dell PowerStore contains a Protection Mechanism Failure vulnerability. An aut...
-
CVE-2026-9625 — Rockwell Automation RSLinx Classic® — CVSS 8.7 — RSLinx Classic® - Multiple VulnerabilitiesA denial-of-service security issue ...
-
CVE-2026-9624 — Rockwell Automation RSLinx Classic® — CVSS 8.7 — RSLinx Classic® - Multiple VulnerabilitiesA denial-of-service security issue ...
-
CVE-2026-9622 — Rockwell Automation RSLinx Classic® — CVSS 8.7 — RSLinx Classic® - Multiple VulnerabilitiesA denial-of-service security issue ...
-
CVE-2026-9637 — Rockwell Automation CompactLogix® 5380 / ControlLogix® 5580 — CVSS 8.7 — CompactLogix® 5380 / ControlLogix® 5580 - Multiple VulnerabilitiesA denial-of...
-
CVE-2025-12768 — Rockwell Automation FactoryTalk® Historian Machine Edition — CVSS 8.6 — FactoryTalk® Historian Machine Edition - Out-of-Bounds Write VulnerabilityA s...
-
CVE-2026-19513 — Gravity Forms — CVSS 8.1 — Gravity Forms through 3.0.2 - Unauthenticated Arbitr