search

Sections

Cyber Security

2432 articles

Rockwell Automation FactoryTalk DataMosaix
cybersecurity

Rockwell Automation FactoryTalk DataMosaix

A vulnerability in Rockwell Automation’s FactoryTalk DataMosaix Private Cloud (versions 8.02 and earlier) allows authenticated attackers to inject malicious scripts due to improper input neutralization. This issue, classified as a stored cross-site scripting vulnerability (CVE-2026-9292), could lead to account takeovers and credential theft. Users are urged to upgrade to version 8.03 or later. CISA advises enhancing network security and following best practices to mitigate risks, with no known active exploitation reported.

All CISA Advisories ·
SALTO ProAccess Space
cybersecurity

SALTO ProAccess Space

A critical vulnerability in SALTO ProAccess Space versions earlier than 6.13 allows authenticated attackers to escalate privileges and access restricted spaces within a system, assuming valid operator credentials are available and partition features are enabled. To mitigate this risk, users are advised to upgrade to version 6.13 and implement several security practices, including using internal networks, applying least-privilege principles, and considering separate instances for strong tenant separation. CISA emphasizes the need for cybersecurity strategies to defend industrial control systems and encourages organizations to report any suspicious activities related to this vulnerability.

All CISA Advisories ·
Siemens SICAM 8
cybersecurity

Siemens SICAM 8

Multiple vulnerabilities have been identified in Siemens’ SICAM 8 products, potentially leading to denial of service and unauthorized access. Affected devices include various firmware versions, with specific vulnerabilities (CVE-2026-54798, CVE-2026-54799, CVE-2026-54800, CVE-2026-54801) impacting the CPCI85 and SICORE systems among others. Siemens recommends that users update to firmware versions V26.20 or later to mitigate these risks. The company emphasizes the need for protective measures in critical infrastructure networks to enhance overall system security and resilience. Users are encouraged to follow security guidelines and conduct proper risk assessments when implementing updates.

All CISA Advisories ·
CISA Adds Two Known Exploited Vulnerabilities to Catalog
cybersecurity

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, reflecting active exploitation risks: CVE-2023-4346 related to a KNX protocol issue and CVE-2026-46817 concerning Oracle E-Business Suite’s privilege management. The Binding Operational Directive 26-04 directs federal agencies to prioritize high-risk vulnerabilities for quick remediation. CISA encourages all organizations to adopt similar risk-based management practices and will continue to expand the KEV Catalog. Submissions for new vulnerabilities can be made through CISA’s KEV Nomination Form.

All CISA Advisories ·
Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers
cybersecurity

Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers

The National Security Agency, CISA, and international partners have developed guidance for software manufacturers and online service providers to establish a coordinated vulnerability disclosure (CVD) program. This includes creating a clear vulnerability disclosure policy and a process for managing reported vulnerabilities, including assigning Common Vulnerabilities and Exposures (CVE) identifiers. The guidelines recommend using third-party intermediaries to enhance CVD programs, fostering collaboration with security researchers for effective vulnerability remediation and improved product security.

All CISA Advisories ·
ICYMI: June 2026 @AWS Security
cybersecurity

ICYMI: June 2026 @AWS Security

The latest monthly digest from AWS highlights new security features, compliance updates, and hands-on resources. It includes expert blog posts focusing on identity and access management, threat intelligence, network security, AI-driven security tools, and multi-account strategies. Additionally, readers will find information on new service capabilities, code samples, and workshops designed to enhance security practices within AWS environments.

AWS Security Blog ·
Follow the money
cybersecurity

Follow the money

Why give away the most valuable data in security? Learn how Athena’s business model aligns trust, incentives, and open source defense.

Chainguard: Unchained ·