Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Haiwell IoT Cloud HMI Gateway version 3.40.1.12 is vulnerable to OS command injection in the Net Check feature accessed through /setting. The cmdPing Socket.io event passes unsanitized input to the OS, allowing remote attackers to execute commands as root.
Siemens LOGO! Soft Comfort before V9 uses a hardcoded AES master key (CVE-2026-57262) and unsalted password hashes (CVE-2026-57263), allowing local attackers to decrypt project data or brute-force passwords. A hardware upgrade to LOGO! V9 BM or later is also required to fully resolve the vulnerabilities.
Hitachi Energy APM Edge 6.10 and earlier is affected by Dirty Frag vulnerabilities in the Linux kernel IPsec ESP subsystem. Locally authenticated users can exploit kernel memory handling flaws to gain root privileges and compromise the device.
Simcenter Femap has two out-of-bounds read vulnerabilities triggered when reading specially crafted BMP files. Successful exploitation can crash the application or execute arbitrary code in the current process.
Group-IB researchers have identified WindRelay, a previously unseen Android NFC relay malware deployed alongside the SpyNote RAT to facilitate contactless payment fraud. The attack uses social engineering to trick victims into sideloading a personalized malicious app, then silently installs the NFC reader component, which intercepts live card data and relays it via WebSocket to a fraudster's device for real-time cashouts.
WhatsApp has introduced an optional 'Scam Alert' feature that leverages local machine learning to identify and warn users about potential scam messages. This update is designed to improve user security by proactively detecting and alerting users to suspicious activities.