Tag
Insufficiently Protected Credentials Vulnerability in Schneider Electric SCADAPack x70
1 TTP 1 CVESchneider Electric SCADAPack x70 series RTUs contain a vulnerability (CVE-2026-81861) in the legacy 'Secure Lock' functionality that could lead to unauthorized exposure of authentication information.
Critical Vulnerabilities in Digital Watchdog VMAX DVR and NVR Products
2 TTPsMultiple high-severity vulnerabilities in Digital Watchdog VMAX series devices allow unauthenticated remote attackers to bypass authentication, gain root access via hard-coded credentials, and execute arbitrary system commands.
Multiple Vulnerabilities in AVEVA Pipeline Integrity Monitor
4 CVEsAVEVA Pipeline Integrity Monitor versions through 2025_SP1_P1_build_7.1.9580.8513 contain multiple vulnerabilities including hard-coded keys and improper authorization, facilitating information disclosure, credential brute-forcing, and XSS-based code execution.
Critical Authentication Bypass in Tenda AC18 Telnet Handler
1 TTP 1 CVEA critical authentication bypass vulnerability in the Tenda AC18 router allows remote, unauthenticated attackers to gain unauthorized access via the Telnet service.
Denial of Service Vulnerability in Mitsubishi Electric CNC Series
An out-of-bounds read vulnerability (CVE-2025-2399) in Mitsubishi Electric CNC Series controllers allows remote attackers to trigger a denial-of-service condition via crafted packets sent to TCP port 683.
Active Exploitation of Siemens S7 Series PLCs in US Critical Infrastructure
1 TTPThe IC3 has issued an advisory regarding the active exploitation of Siemens S7 Series PLCs within US critical infrastructure sectors using CVE-2026-4357 to disrupt operational technology.
Medusa Ransomware Operations and Tactics
3 TTPsMedusa ransomware affiliates target critical infrastructure and healthcare entities using rapid exploitation of newly disclosed vulnerabilities and abuse of legitimate RMM software for persistence and exfiltration.
Critical OS Command Injection in Haiwell IoT Cloud HMI Gateway
1 rule 2 TTPsAn unauthenticated OS command injection vulnerability in the Haiwell IoT Cloud HMI Gateway allows attackers to achieve arbitrary command execution with root privileges via the Net Check feature.
Gunra Ransomware Gang Exploitation of Fortinet Appliances
4 TTPs 2 CVEsThe Gunra ransomware-as-a-service group is leveraging critical Fortinet vulnerabilities (CVE-2024-55591 and CVE-2025-24472) to gain initial access, hijack VDI sessions, and bypass multi-factor authentication in attacks against critical infrastructure.
Authentication Bypass in AMMOS Instrument Toolkit GUI
1 TTP 1 CVEThe AMMOS Instrument Toolkit (AIT) GUI before version 2.5.1 allows unauthenticated attackers to bypass credential checks to establish sessions and issue arbitrary spacecraft commands.
Critical Unauthenticated Remote Access Vulnerability in Rockwell Automation 1715-AENTR EtherNet/IP Adapter (CVE-2026-10577)
1 TTP 1 CVEA critical unauthenticated remote access vulnerability, CVE-2026-10577, in Rockwell Automation 1715-AENTR EtherNet/IP Adapter versions <=3.003 allows an attacker to exploit a network-accessible debug port with missing privilege controls, enabling remote command-line interface access to read/delete files, modify memory, and change I/O states, impacting the confidentiality, integrity, and availability of industrial control systems.
NCSC Warns of State-Sponsored Espionage via IP Cameras Targeting Critical Infrastructure
2 TTPsRussian state-sponsored actors, along with hacktivist groups and cybercriminals, are exploiting IP cameras to spy on critical infrastructure in NATO countries, including the Netherlands, prompting NCSC to advise organizations and home users to secure their devices through updates, network segmentation, and attack surface reduction.
Multiple Vulnerabilities in Schneider Electric PowerChute Serial Shutdown
5 TTPs 5 CVEsMultiple vulnerabilities, including CVE-2026-2399, CVE-2026-2404, CVE-2026-2405, CVE-2026-2403, CVE-2026-2400, and CVE-2026-2401, in Schneider Electric PowerChute Serial Shutdown versions 1.4 and prior could allow attackers with adjacent network access and high privileges to overwrite critical system files via path traversal, forge or inject malicious log data, gain unauthorized account access through excessive authentication attempts, trigger denial-of-service conditions, or expose sensitive information.
CVE-2026-8377: Missing Authorization in Armiya GKS Allows Data Collection
2 TTPs 1 CVEA critical Missing Authorization vulnerability (CVE-2026-8377) in Armiya Information Technologies Ltd. Co.'s Access Control System (GKS) before Version 2 allows an unauthenticated or unauthorized attacker to collect sensitive data from common resource locations, leading to unauthorized information disclosure.
FortiBleed Campaign: 73,932 FortiGate Systems Credentials Exposed
3 rules 9 TTPs 1 IOCA Russian-speaking threat group utilized a large dataset of administrative and VPN credentials, likely sourced from exposed FortiGate configuration files and active credential harvesting, to access government, critical infrastructure, and multinational corporate networks, resulting in widespread data exfiltration.
Hitachi Energy GMS600 Vulnerable to Bleichenbacher Attack via CVE-2022-4304
2 rules 1 TTP 1 CVEHitachi Energy GMS600 versions 1.3.0 and 1.3.1 are affected by CVE-2022-4304, a vulnerability in the OpenSSL RSA Decryption implementation; an attacker could exploit this timing-based side channel to recover plaintext across a network in a Bleichenbacher-style attack by sending trial messages to the server and recording processing times, eventually decrypting application data.
Siemens SIPROTEC 5 Insufficient Session ID Randomness Leads to Session Hijacking (CVE-2024-54017)
2 rules 1 TTP 1 CVESiemens SIPROTEC 5 devices are vulnerable to session hijacking (CVE-2024-54017) due to the use of insufficiently random numbers in session identifier generation, potentially allowing an unauthenticated remote attacker to brute-force a valid session and gain unauthorized read access.
ABB Edgenius Management Portal Authentication Bypass Vulnerability
2 rules 1 TTP 1 CVEAn authentication bypass vulnerability in ABB Edgenius Management Portal versions 3.2.0.0 and 3.2.1.1 allows attackers to execute arbitrary code and modify application configurations by sending a specially crafted message to the system node.