Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
The Mendix SAML module contains a vulnerability tracked as CVE-2026-80465 that could allow unauthenticated remote attackers to hijack user accounts in specific SSO configurations. The flaw affects Mendix SAML versions prior to 4.2.3 for Mendix 10 and 11 compatibility, and versions prior to 3.6.27 for Mendix 9.24 compatibility.
View CSAF Summary Schneider Electric is aware of a vulnerability in its SCADAPack x70 products. The SCADAPack 47x, SCADAPack 47xi, SCADAPack 47xd, SCADAPack 470R and SCADAPack 57x products are Remote Terminal Units that provide communication capabilities for remote monitoring and control.
Wärtsilä FOS-Onboard version 5.07.0923.01 is affected by multiple vulnerabilities that could allow an attacker to deliver unauthorized updates, execute arbitrary code, or extract credentials to impersonate a privileged client. The vulnerabilities involve the use of hard-coded cryptographic keys, with a CVSS v3 base score of 9.1.
UK and allies provide advice to help organisations and individuals at risk detect and counter the threat from CHOSEN BRICK malware.
Developed by the National Institute of Standards and Technology (NIST) and CISA, this interagency report provides federal agencies and cloud service providers with guidelines to protect the identity assertions, access tokens, and cryptographic mechanisms that support modern authentication and authorization. As agencies adopt hybrid and multi-cloud environments, single sign-on, federation, and application programming interface (API)-based access increasingly depend on signed tokens and assertions that adversaries may target for forgery, theft, and misuse to move laterally across enterprise networks and access sensitive data.
Advisory on CHOSEN BRICK malware, including technical analysis and advice to help individuals and organisations protect themselves.