Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
View CSAF Summary Successful exploitation of these vulnerabilities could grant full administrative control of the device, allowing an attacker to view live and recorded surveillance, alter device configurations, and use the device as a network pivot point. The following versions of Digital Watchdog VMAX DVR and NVR Product Lineups are affected: VMAX A1 G4 DVRs vers:all/* (CVE-2026-68953, CVE-2026-66890, CVE-2026-68070, CVE-2026-68950, CVE-2026-66887, CVE-2026-66372) VMAX IP G4 NVRs vers:all/* (CVE-2026-68953, CVE-2026-66890, CVE-2026-68070, CVE-2026-68950, CVE-2026-66887, CVE-2026-66372) VMAX A1 PLUS vers:all/* (CVE-2026-68953, CVE-2026-66890, CVE-2026-68070, CVE-2026-68950, CVE-2026-66887, CVE-2026-66372) VA1G4 Recorder vers:all/* (CVE-2026-68953, CVE-2026-66890, CVE-2026-68070, CVE-2026-68950, CVE-2026-66887, CVE-2026-66372) VG4 Recorder vers:all/* (CVE-2026-68953, CVE-2026-66890, CVE-2026-68070, CVE-2026-68950, CVE-2026-66887, CVE-2026-66372) CVSS Vendor Equipment Vulnerabilities v3 9.6 Digital Watchdog Digital Watchdog VMAX DVR and NVR Product Lineups Missing Authentication for Critical Function, Use of Hard-coded Credentials, Missing Authorization, Predictable Seed in Pseudo-Random Number Generator (PRNG) Background Critical Infrastructure Sectors: Commercial Facilities, Government Services and Facilities, Healthcare and Public Health, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-68953 The affected products are vulnerable to an authentication bypass that allows unauthenticated remote attackers to disclose sensitive device information, including administrator credentials in plaintext, by sending crafted HTTP(S) requests.
The Mendix SAML module contains a vulnerability tracked as CVE-2026-80465 that could allow unauthenticated remote attackers to hijack user accounts in specific SSO configurations. The flaw affects Mendix SAML versions prior to 4.2.3 for Mendix 10 and 11 compatibility, and versions prior to 3.6.27 for Mendix 9.24 compatibility.
View CSAF Summary A reflected cross site scripting vulnerability in the authentication redirect flow (/auth/) of Teamcenter allows an unauthenticated remote attacker to inject JavaScript into an authenticated user's session by crafting a malicious URL. Successful exploitation may enable the attacker to read data or perform actions within the victim's Teamcenter session. Siemens has released new versions for the affected products and recommends to update to the latest versions.
Wärtsilä FOS-Onboard version 5.07.0923.01 is affected by multiple vulnerabilities that could allow an attacker to deliver unauthorized updates, execute arbitrary code, or extract credentials to impersonate a privileged client. The vulnerabilities involve the use of hard-coded cryptographic keys, with a CVSS v3 base score of 9.1.
Advisory on CHOSEN BRICK malware, including technical analysis and advice to help individuals and organisations protect themselves.
Sysdig has documented a skilled human attacker who exploited a vulnerable Marimo notebook and pivoted to an SSH bastion host in just eight seconds using a custom Python toolkit written by hand without AI assistance. The findings demonstrate that while AI is shrinking the window between vulnerability disclosure and exploitation, experienced human operators can still move faster than automated attacks.