Category index

Cyber Security

4276 articles

4276 ARTICLES

FEATURED REPORT

Labcenter Proteus 9

View CSAF Summary Successful exploitation of these vulnerabilities could disclose information and allow a malicious user to execute arbitrary code on affected installations. The following versions of Labcenter Proteus 9 are affected: Proteus 9.1_SP4_Build_42914 CVSS Vendor Equipment Vulnerabilities v3 7.8 Labcenter Electronics Labcenter Proteus 9 Out-of-bounds Write, Stack-based Buffer Overflow, Use After Free Background Critical Infrastructure Sectors: Communications, Critical Manufacturing, Defense Industrial Base, Energy, Healthcare and Public Health, Transportation Systems, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: United Kingdom Vulnerabilities Expand All + CVE-2026-42953 The application contains an out-of-bounds write vulnerability that can be exploited by an attacker to cause the program to write data past the end of an allocated memory buffer. This can lead to arbitrary code execution. View CVE Details Affected Products Labcenter Proteus 9 Vendor: Labcenter Electronics Product Version: Labcenter Electronics Proteus: 9.1_SP4_Build_42914 Product Status: known_affected Remediations Vendor fix Labcenter recommends ensuring you are using the latest version (9.2 SPO) of the software. Version can be found by looking at the bottom left of the Proteus home page (Version 8 or higher) or by selecting the About ISIS or About ARES option from the Help menu. Update notifications appear in the new and information section of the home page where you can activate the download and installation directly. Mitigation If you have questions or need help please contact Labcenter or your local distributor. Relevant CWE: CWE-787 Out-of-bounds Write Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 4.0 8.4 HIGH CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-49033 The application contains a stack-based buffer overflow vulnerability that can be exploited by an attacker to execute arbitrary code. View CVE Details Affected Products Labcenter Proteus 9 Vendor: Labcenter Electronics Product Version: Labcenter Electronics Proteus: 9.1_SP4_Build_42914 Product Status: known_affected Remediations Vendor fix Labcenter recommends ensuring you are using the latest version (9.2 SPO) of the software. Version can be found by looking at the bottom left of the Proteus home page (Version 8 or higher) or by selecting the About ISIS or About ARES option from the Help menu. Update notifications appear in the new and information section of the home page where you can activate the download and installation directly. Mitigation If you have questions or need help please contact Labcenter or your local distributor. Relevant CWE: CWE-121 Stack-based Buffer Overflow Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 4.0 8.4 HIGH CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-42958 The application contains a use-after-free vulnerability that can be exploited to cause memory corruption while parsing specially crafted files. This could allow an attacker to execute arbitrary code in the context of the current process. View CVE Details Affected Products Labcenter Proteus 9 Vendor: Labcenter Electronics Product Version: Labcenter Electronics Proteus: 9.1_SP4_Build_42914 Product Status: known_affected Remediations Vendor fix Labcenter recommends ensuring you are using the latest version (9.2 SPO) of the software. Version can be found by looking at the bottom left of the Proteus home page (Version 8 or higher) or by selecting the About ISIS or About ARES option from the Help menu. Update notifications appear in the new and information section of the home page where you can activate the download and installation directly. Mitigation If you have questions or need help please contact Labcenter or your local distributor. Relevant CWE: CWE-416 Use After Free Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 4.0 8.4 HIGH CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Acknowledgments Michael Heinzl reported these vulnerabilities to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B–Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. These vulnerabilities are not exploitable remotely. Revision History Initial Release Date: 2026-07-07 Date Revision Summary 2026-07-07 1 Initial Publication Legal Notice and Terms of Use

BY CISA
MIN READ 5 MIN READ
EXPLORE north_east
Labcenter Proteus 9
Siemens Mendix Studio Pro
CYBERSECURITY

Siemens Mendix Studio Pro

View CSAF Summary Mendix Studio Pro versions before V11.12 are affected by a file parsing vulnerability that could be triggered when the application reads specially crafted malicious project during the build pipeline. This could allow an attacker to execute arbitrary code in the context of that user. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available. The following versions of Siemens Mendix Studio Pro are affected: Mendix Studio Pro 10.11 vers:all/* Mendix Studio Pro 10.12 vers:all/* Mendix Studio Pro 10.13 vers:all/* Mendix Studio Pro 10.14 vers:all/* Mendix Studio Pro 10.15 vers:all/* Mendix Studio Pro 10.16 vers:all/* Mendix Studio Pro 10.17 vers:all/* Mendix Studio Pro 10.18 vers:all/* Mendix Studio Pro 10.19 vers:all/* Mendix Studio Pro 10.20 vers:all/* Mendix Studio Pro 10.21 vers:all/* Mendix Studio Pro 10.22 vers:all/* Mendix Studio Pro 10.23 vers:all/* Mendix Studio Pro 10.24 vers:intdot/<10.24.21 Mendix Studio Pro 11.0 vers:all/* Mendix Studio Pro 11.1 vers:all/* Mendix Studio Pro 11.10 vers:all/* Mendix Studio Pro 11.11 vers:all/* Mendix Studio Pro 11.2 vers:all/* Mendix Studio Pro 11.3 vers:all/* Mendix Studio Pro 11.4 vers:all/* Mendix Studio Pro 11.5 vers:all/* Mendix Studio Pro 11.6 vers:intdot/<11.6.7 Mendix Studio Pro 11.7 vers:all/* Mendix Studio Pro 11.8 vers:all/* Mendix Studio Pro 11.9 vers:all/* CVSS Vendor Equipment Vulnerabilities v3 5.4 Siemens Siemens Mendix Studio Pro Improper Control of Generation of Code (‘Code Injection’) Background Critical Infrastructure Sectors: Critical Manufacturing, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-48192 Affected versions of Mendix Studio Pro do not properly validate or sanitize project files processed during the build pipeline. This could allow an attacker who tricks a user into opening and running a specially crafted malicious project locally on their system to execute arbitrary code in the context of that user. View CVE Details Affected Products Siemens Mendix Studio Pro Vendor: Siemens Product Version: Mendix Studio Pro 10.11, Mendix Studio Pro 10.12, Mendix Studio Pro 10.13, Mendix Studio Pro 10.14, Mendix Studio Pro 10.15, Mendix Studio Pro 10.16, Mendix Studio Pro 10.17, Mendix Studio Pro 10.18, Mendix Studio Pro 10.19, Mendix Studio Pro 10.20, Mendix Studio Pro 10.21, Mendix Studio Pro 10.22, Mendix Studio Pro 10.23, Mendix Studio Pro 10.24 < V10.24.21, Mendix Studio Pro 11.0, Mendix Studio Pro 11.1, Mendix Studio Pro 11.10, Mendix Studio Pro 11.11, Mendix Studio Pro 11.2, Mendix Studio Pro 11.3, Mendix Studio Pro 11.4, Mendix Studio Pro 11.5, Mendix Studio Pro 11.6 < V11.6.7, Mendix Studio Pro 11.7, Mendix Studio Pro 11.8, Mendix Studio Pro 11.9 Product Status: known_affected Remediations No fix planned Currently no fix is planned Vendor fix Update to V10.24.21 or later version https://docs.mendix.com/releasenotes/studio-pro/10.24/ Vendor fix Update to V11.6.7 or later version https://docs.mendix.com/releasenotes/studio-pro/11.6/ Relevant CWE: CWE-94 Improper Control of Generation of Code (‘Code Injection’) Metrics CVSS Version Base Score Base Severity Vector String 3.1 5.4 MEDIUM CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:N/I:H/A:N Acknowledgments Siemens ProductCERT reported this vulnerability to CISA. General Recommendations As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens’ operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity Additional Resources For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories Terms of Use The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolate them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B–Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. Advisory Conversion Disclaimer This ICSA is a verbatim republication of Siemens ProductCERT SSA-779310 from a direct conversion of the vendor’s Common Security Advisory Framework (CSAF) advisory. This is republished to CISA’s website as a means of increasing visibility and is provided “as-is” for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory. Revision History Initial Release Date: 2026-06-30 Date Revision Summary 2026-06-30 1 Publication Date 2026-07-07 2 Initial CISA Republication of Siemens ProductCERT SSA-779310 advisory Legal Notice and Terms of Use

5 MIN READ arrow_forward
Expanding Athena
CYBERSECURITY

Expanding Athena

See how Athena is helping secure open source by coordinating AI-discovered vulnerabilities, partner protections, and upstream fixes at scale.

1 MIN READ arrow_forward
PCI DSS 6.4.3 and 11.6.1: A Deep Dive into Payment Page Security and Integrity Requirements
CYBERSECURITY

PCI DSS 6.4.3 and 11.6.1: A Deep Dive into Payment Page Security and Integrity Requirements

For organizations that process payment card data online, the payment page has become one of the most targeted points of attack. Modern e-commerce environments rely heavily on third-party scripts, embedded payment forms, and dynamic content—all of which expand the attack surface in ways that can be difficult to monitor. At the same time, client-side attacks—particularly e-skimming and malicious script injection—have surged. Attackers are no longer trying to break into backend systems fi…

1 MIN READ arrow_forward
CMMC Certification Deadlines are Coming Soon. Here’s What That Means for You
CYBERSECURITY

CMMC Certification Deadlines are Coming Soon. Here’s What That Means for You

Organizations can no longer treat CMMC compliance as something to address later. In November 2025, the U.S. Department of War (DoW) began incorporating CMMC assessment requirements into applicable defense procurements. While the first phase of implementation focuses primarily on Level 1 and Level 2 self-assessments, organizations should not mistake this for a grace period. For contractors that handle Controlled Unclassified Information (CUI), CMMC readiness is quickly becoming a business…

1 MIN READ arrow_forward
The Growing Threat of Docusign Phishing Attacks
CYBERSECURITY

The Growing Threat of Docusign Phishing Attacks

Introduction: Docusign phishing attacks Researchers from Cado Security Labs (now part of Darktrace) identified a recent Docusign spearphishing email campaign targeting tech executives. Docusign email phishing is a type of email phishing where malicious actors send fraudulent emails mimicking legitimate Docusign communications to trick recipients, typically to input credentials into an illegitimate site. These emails often appear authentic, using Docusign branding and layouts to…

1 MIN READ arrow_forward
Humans, Machines, and the Future of Work
CYBERSECURITY

Humans, Machines, and the Future of Work

As AI becomes increasingly capable, where we are headed will be determined by the guidance and guardrails provided by those of us working in the field. How humans and AI will work together is an essential, some might say existential, question that will shape the future. What we need to remember is that purpose inherently shapes performance. This is true whether we’re talking about a human being, a tool or a technology. When things are engineered for a particular objective, that’s what t…

1 MIN READ arrow_forward
Today's Global Event. Tomorrow's Brand: The DNS Security Risks Behind Brand Impersonation
CYBERSECURITY

Today's Global Event. Tomorrow's Brand: The DNS Security Risks Behind Brand Impersonation

Executive Summary Every major global event creates opportunities for cybercriminals to exploit trust. Whether it’s an international sporting tournament, a holiday shopping season, tax season, a product launch, or a breaking news event, attackers quickly register lookalike domains, create convincing phishing websites, and impersonate trusted organizations to steal credentials, payment information, and sensitive data. While the themes of these campaigns change, the underlying atta…

1 MIN READ arrow_forward
How Organizations Build Mature Cloud Governance Programs
CYBERSECURITY

How Organizations Build Mature Cloud Governance Programs

Most organizations have successfully adopted cloud technologies. However, far fewer have developed the governance maturity required to manage cloud environments consistently, securely, and at scale. As cloud ecosystems become more distributed, automated, and identity-driven, governance challenges extend far beyond basic compliance requirements. Operational blind spots, fragmented accountability, inconsistent controls, and limited visibility across multi-cloud environments are now creating…

1 MIN READ arrow_forward