
Section
Threats, page 5
Vulnerability intelligence, exploited CVEs, malware families and live campaigns — with the detection guidance and mitigations defenders need first.
231 articles
ThreatsCloud & SaaSHighCST Newsroom
ThreatsIndustrial & OTHighSiemens SICAM 8 Remote Parameterization Resource Exhaustion Flaw Disables Substation Automation Controllers
CST Newsroom
ThreatsCloud & SaaSCriticalMicrosoft Azure Active Directory B2C Authentication Bypass Flaw Enables Remote Privilege Escalation
Mei-Lin Chen
ThreatsIndustrial & OTCriticalCritical Schneider Electric Modicon M580 Controllers Authentication Flaw Risks Industrial Process Takeover
CST Newsroom
ThreatsCloud & SaaSCriticalCritical vLLM Multimodal Video Parser Buffer Overflow Flaw Enables Remote Root Code Execution
Daniel Okafor
ThreatsIndustrial & OTHighRockwell Automation FactoryTalk Activation Manager Flaw Enables Local SYSTEM Privilege Escalation
CST Newsroom
ThreatsCloud & SaaSCriticalLinux Kernel Fragnesia Flaw Weaponized for GKE Container Escapes via Socket Buffer Page-Cache Overwrite
Daniel Okafor
ThreatsCloud & SaaSCriticalLiteLLM Pre-Authentication SQL Injection Flaw Exposes Enterprise Master Keys and AI Model Routing Gateways
CST Newsroom
ThreatsCloud & SaaSCriticalCheck Point Security Management Buffer Overflow Flaw Enables Unauthenticated Remote Root Code Execution
Mei-Lin Chen
ThreatsCloud & SaaSHighAmazon SSM Agent Path Traversal Flaw Enables Root Host Takeover via Malicious S3 Object Keys
Daniel Okafor
ThreatsIndustrial & OTCriticalCritical Flaws in Digital Watchdog VMAX Recorders Enable Unauthenticated Remote Root Takeover
Mei-Lin Chen
ThreatsCloud & SaaSHighFlowise SSRF Vulnerability Bypasses Network Guardrails to Steal Cloud Instance Credentials
Daniel Okafor
ThreatsCloud & SaaSHighOpenSearch Dashboards Route Handler Flaw Triggers Denial of Service Across Cloud Clusters
Priya Raman
ThreatsIndustrial & OTCriticalThreat Actors Weaponize AI Tooling and S7comm to Target Siemens S7 Industrial Controllers
Mei-Lin Chen
ThreatsCloud & SaaSHighAmazon Bedrock AgentCore Flaw Allows Attackers to Bypass LLM Guardrails via Injected Tool-Use Payloads
Daniel Okafor
ThreatsCloud & SaaSHighAzure Kubernetes Service Container Path Traversal Flaw Enables Node Escape and Code Execution
Priya Raman
ThreatsIndustrial & OTCriticalJohnson Controls C-CURE 9000 Vulnerabilities Allow Attackers to Hijack Physical Facility Access Gateways
Mei-Lin Chen
ThreatsCloud & SaaSCriticalMicrosoft Entra ID Critical Deserialization Vulnerability Enables Unauthenticated Remote Code Execution
Daniel Okafor
ThreatsCloud & SaaSCriticalCritical Cisco Secure Firewall Flaw Weaponized to Compromise Enterprise Perimeter Gateways
Priya Raman
ThreatsIndustrial & OTCriticalMitsubishi Electric GX Works3 Authentication Bypass Exposes Industrial PLCs to Memory Manipulation Attacks
Mei-Lin Chen
ThreatsCloud & SaaSHighAWS Discloses Security Policy Bypass in API Model Context Protocol Server Enabling Unauthorized Agent Tool Execution
Daniel Okafor
ThreatsCloud & SaaSHighAWS Discloses Command Injection Flaw in projen Tooling Enabling CI/CD Runner Takeover
Daniel Okafor
ThreatsCloud & SaaSCriticalSiemens Mendix SAML Single Sign-On Flaw Exposes Enterprise Cloud Portals to Account Takeover
Priya Raman
ThreatsIndustrial & OTCriticalSchneider Electric NetBotz Command Injection Flaw Allows Root System Compromise via Malicious Backups
CST Newsroom