Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products

Rockwell Automation recently released patches for over a dozen vulnerabilities that affect its industrial automation products. The company has made available workarounds and fixes for these issues, which range from denial-of-service (DoS) flaws to remote code execution problems. One critical vulnerability, identified as CVE-2026-9637, affects the RSLinx Classic communications software and could cause it to … Read more

UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure

A landmark piece of legislation aimed at safeguarding the UK’s critical infrastructure has taken a significant step forward in Parliament. The UK Cyber Security and Resilience Bill (CSRB) has been amended to give ministers powers to block high-risk technology suppliers from serving critical sector organizations, following a recent cyberattack that left a small-scale energy facility … Read more

OpenLeash Adds a Human Check to Risky AI Agent Actions

As AI agents become increasingly integral to our digital lives, their autonomous actions can pose a significant threat to network security if left unchecked. A new product, OpenLeash, aims to mitigate this risk by introducing a human oversight layer that ensures AI agents’ actions align with user intent. Developed by Max Brin, OpenLeash provides an … Read more

CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners

A new wave of attacks has been detected, leveraging seven exploited flaws identified by CISA. The US Cybersecurity and Infrastructure Security Agency (CISA) has added these vulnerabilities to its list of actively exploited issues, sparking concerns among security experts that attackers are gaining a foothold in networks. The exploitation is primarily occurring through the use … Read more

Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon

A Critical Vulnerability in CrowdStrike Falcon Exposed by Researcher’s Proof-of-Concept Exploit A researcher has unveiled a proof-of-concept (PoC) exploit for a previously unknown vulnerability in CrowdStrike Falcon, a popular cloud-delivered endpoint security platform. The flaw allows an attacker to escalate privileges from a standard user account to an administrator-level position on the system, essentially giving … Read more

Exploit Published for Fresh Cleo Harmony Vulnerability

A Critical Cleo Harmony Vulnerability Has Been Exploited, Leaving Organizations Exposed to Privilege Elevation and Lateral Movement Attacks Cleo Harmony users are facing a pressing security threat after a fresh authentication bypass vulnerability was discovered in the file transfer application. The vulnerability, tracked as CVE-2026-84115, allows remote attackers to manipulate JWT refresh tokens, granting them … Read more

Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products

Rockwell Automation Patches Dozens of Vulnerabilities Across Industrial Automation Products Industrial automation giant Rockwell Automation has issued patches or workarounds for over a dozen vulnerabilities discovered across its products. The company’s advisory highlights critical and high-severity issues that could compromise sensitive operations, making it essential for customers to take immediate action. The most concerning vulnerability, … Read more

UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure

The UK government has taken a significant step towards bolstering its national resilience against cyber threats by proposing amendments to the Cyber Security and Resilience Bill (CSRB). The bill, which is poised to become an Act of Parliament, aims to prevent high-risk technology suppliers from being used by critical infrastructure organizations. This move comes on … Read more

OpenLeash Adds a Human Check to Risky AI Agent Actions

As AI agents become increasingly prevalent in our daily lives, they also bring with them a new set of risks and challenges. Autonomous systems can be incredibly powerful, but their ability to act without human oversight or control has raised concerns about accountability and security. A recent innovation aims to address this issue by introducing … Read more

Threat Gang ‘Springs’ Vishing Attacks on Microsoft Teams Users

Cyber attackers have been using a new tactic to compromise Microsoft Teams users, according to researchers from Palo Alto Networks. The “Spring Ring” operation has targeted at least 150 employees across multiple companies with voice phishing (vishing) attacks that aim to install remote monitoring and management tools on their machines. The campaign is significant because … Read more