Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
This advisory describes a vulnerability in Siemens Mendix Runtime, where documentation fails to clarify the special behavior of the System.User entity. This gap can lead developers to set overly permissive access rules, causing sensitive data exposure or privilege escalation.
CISA disclosed a vulnerability in igloohome Smart Lock Mobile Application where successful exploitation could allow unauthorized actors to access backend services and sensitive functions.
View CSAF Summary ABB has been contacted by a researcher who identified a vulnerability in one of its products.
View CSAF Summary Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl.
The Iranian state-sponsored hacking group Nimbus Manticore, also known as UNC1549 and Mirage Kitten, has been linked to a new campaign targeting organizations in the Middle East, Africa, and South Asia. The group deployed a previously undocumented Windows backdoor called NightLedger, along with custom WebSocket tunnelers BridgeHead and ArcBridge, to maintain stealthy access to victim systems.
Iranian state-backed group Nimbus Manticore (aka GalaxyGato, Smoke Sandstorm, UNC1549) targeted entities across the Middle East, Africa, and South Asia using a previously undocumented Windows backdoor called NightLedger and two custom WebSocket tunnelers (BridgeHead and ArcBridge). Targets included government, aviation, telecom, and financial organizations in Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso.