Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Toptech Systems RCU II+ and Multiload II+ contain a missing authentication vulnerability in a debug interface. An unauthenticated TCF service exposes full root-level access, allowing an attacker to fully control the system.
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to gain full system control and misuse it to access or manipulate connected networks and resources.
CISA urgently warns water and wastewater systems sector organizations to protect OT systems against escalating cyber threats. Recent incidents show adversaries targeting critical water treatment infrastructure.
A security issue exists in Rockwell Automation CompactLogix 5380, ControlLogix 5580, and EN4TR communication modules related to CIP Security certificate revocation handling. The controller fails to properly reject certificates signed by an intermediate certificate that has been revoked via a CRL, potentially allowing a network-based attacker to establish an untrusted connection and cause a denial-of-service condition.
CISA is currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) Sector.
CISA disclosed multiple vulnerabilities in o6 Automation's open62541 OPC UA implementation, including integer underflow, overflow, and use-after-free flaws. Successful exploitation could lead to sensitive information disclosure, denial of service, or arbitrary code execution.