Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
This advisory highlights a vulnerability in MikroTik RouterOS and Cloud Hosted Router, where the API lacks effective rate-limiting or account lockout, allowing rapid password guessing. Attackers can bypass a fixed per-connection delay with concurrent sessions, risking unauthorized administrative access.
View CSAF Summary OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution.
Siemens SIMATIC S7-PLCSIM Advanced contains CVE-2026-54429, a vulnerability allowing denial of service attacks. Siemens is preparing patches and has recommended mitigations.
CISA disclosed a vulnerability in igloohome Smart Lock Mobile Application where successful exploitation could allow unauthorized actors to access backend services and sensitive functions.
View CSAF Summary SIMATIC S7-PLCSIM Advanced contains a vulnerability that could allow an attacker to cause a denial of service condition.
This article announces joint guidance from CISA and ASD's ACSC for critical infrastructure organizations. The guidance provides practical steps to isolate vital operational technology and enabling systems from other networks.