VulnHub

AI-Powered Cybersecurity Intelligence

Last Update Check:

Latest Intelligence

darkreading
Critical Infrastructure Under Siege: OT Security Still Lags

The article highlights the ongoing cybersecurity threats facing critical infrastructure, particularly in operational technology (OT) networks, which remain inadequately secured despite warnings from federal agencies. This security gap poses significant risks to essential services and systems that rely on OT technology.


Impact: Not specified

In the Wild: Unknown

Age: Unknown

Remediation: None available

Published:

SecurityWeek
Production at Steelmaker Nucor Disrupted by Cyberattack

Nucor, a major American steel manufacturer, has reported a cybersecurity incident that appears to be a ransomware attack, leading to disruptions in their production processes. This incident highlights the increasing vulnerability of critical infrastructure to cyber threats.


Impact: Not specified

In the Wild: Unknown

Age: Recently disclosed

Remediation: Vendor advisory pending

Ransomware

Published:

SecurityWeek
Proofpoint to Acquire Hornetsecurity in Reported $1 Billion Deal

Proofpoint, a leading enterprise cybersecurity company, is set to acquire Hornetsecurity, a provider of Microsoft 365 security solutions based in Germany, in a deal reportedly valued at $1 billion. This acquisition highlights the growing importance of cybersecurity solutions in the enterprise sector, particularly for Microsoft 365 users.


Impact: ["Microsoft 365"]

In the Wild: Unknown

Age: Unknown

Remediation: None available

Microsoft

Published:

All CISA Advisories
CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities Catalog, highlighting the risks posed by active exploitation of these vulnerabilities. Organizations are urged to prioritize their remediation to protect against potential cyber threats.


Impact: ["DrayTek Vigor Routers", "Google Chromium", "SAP NetWeaver"]

In the Wild: Yes

Age: Recently disclosed

Remediation: Remediate identified vulnerabilities by the due date as per BOD 22-01 guidelines.

CVE Google Vulnerability

Published:

All CISA Advisories
Siemens MS/TP Point Pickup Module

The Siemens MS/TP Point Pickup Module has a vulnerability due to improper input validation, allowing potential denial of service conditions that necessitate a power cycle to restore normal operation. This vulnerability poses risks across multiple critical infrastructure sectors and requires attention to minimize exploitation risk.


Impact: ["Siemens MS/TP Point Pickup Module"]

In the Wild: No

Age: Recently disclosed

Remediation: None available; users are advised to implement network access protections and follow Siemens' operational guidelines.

CVE Vulnerability Update

Published:

All CISA Advisories
CISA Releases Twenty-Two Industrial Control Systems Advisories

CISA has issued twenty-two advisories regarding vulnerabilities in various Industrial Control Systems (ICS) as of May 15, 2025. These advisories highlight critical security issues that could affect numerous Siemens and Mitsubishi Electric products, underscoring the importance of timely updates and mitigations to enhance cybersecurity in industrial environments.


Impact: ["Siemens RUGGEDCOM APE1808 Devices", "Siemens INTRALOG WMS", "Siemens BACnet ATEC Devices", "Siemens Desigo", "Siemens SIPROTEC and SICAM", "Siemens Teamcenter Visualization", "Siemens IPC RS-828A", "Siemens VersiCharge AC Series EV Chargers", "Siemens User Management Component (UMC)", "Siemens OZW Web Servers", "Siemens Polarion", "Siemens SIMATIC PCS neo", "Siemens SIRIUS 3SK2 Safety Relays and 3RK3 Modular Safety Systems", "Siemens APOGEE PXC and TALON TC Series", "Siemens Mendix OIDC SSO", "Siemens MS/TP Point Pickup Module", "Siemens RUGGEDCOM ROX II", "Siemens SCALANCE LPE9403", "ECOVACS DEEBOT Vacuum and Base Station", "Schneider Electric EcoStruxure Power Build Rapsody", "Mitsubishi Electric Multiple FA Engineering Software Products", "Mitsubishi Electric MELSOFT MaiLab and MELSOFT VIXIO"]

In the Wild: Unknown

Age: Recently disclosed

Remediation: CISA encourages users and administrators to review newly released ICS advisories for technical details and mitigations.

Update

Published:

All CISA Advisories
Schneider Electric EcoStruxure Power Build Rapsody

The Schneider Electric EcoStruxure Power Build Rapsody has a stack-based buffer overflow vulnerability that could allow local attackers to execute arbitrary code by exploiting malicious project files. The vulnerability, identified as CVE-2025-3916, affects versions v2.7.12 FR and prior, posing significant risks to critical infrastructure sectors.


Impact: ["EcoStruxure Power Build Rapsody", "Schneider Electric"]

In the Wild: No

Age: Recently disclosed

Remediation: Update to EcoStruxure Power Build Rapsody version v2.8.2 FR and implement recommended cybersecurity best practices.

Phishing CVE Exploit Vulnerability Update

Published:

All CISA Advisories
Siemens APOGEE PXC and TALON TC Series

Siemens has reported a vulnerability in its APOGEE PXC and TALON TC Series products, which could allow an attacker to cause a partial denial of service by sending unsolicited BACnet messages. This issue is significant as it can reduce network availability and requires a power cycle to restore normal operation.


Impact: ["Siemens APOGEE PXC", "Siemens TALON TC Series"]

In the Wild: No

Age: Recently disclosed

Remediation: Currently no fix is planned; users are advised to protect network access and follow operational guidelines.

CVE Vulnerability Update

Published:

All CISA Advisories
Siemens Polarion

The article discusses multiple vulnerabilities found in Siemens' Polarion software, including SQL injection and cross-site scripting flaws, which could allow attackers to extract sensitive data. As of January 10, 2023, CISA will no longer update advisories for these vulnerabilities, emphasizing the need for users to apply mitigations and updates to protect their systems.


Impact: ["Polarion V2310: All versions", "Polarion V2404: Versions prior to V2404.4", "Polarion V2404: Versions prior to V2404.2"]

In the Wild: Unknown

Age: Recently disclosed

Remediation: Update to the latest versions of Polarion or implement specific workarounds as recommended by Siemens.

Phishing CVE Vulnerability Update

Published:

All CISA Advisories
Siemens RUGGEDCOM ROX II

The Siemens RUGGEDCOM ROX II products have critical vulnerabilities that allow authenticated remote attackers to execute arbitrary code with root privileges due to command injection flaws in various web interface tools. This poses significant risks to critical manufacturing sectors and requires immediate attention for mitigation.


Impact: ["RUGGEDCOM ROX MX5000: Versions prior to V2.16.5", "RUGGEDCOM ROX RX1536: Versions prior to V2.16.5", "RUGGEDCOM ROX RX5000: Versions prior to V2.16.5", "RUGGEDCOM ROX MX5000RE: Versions prior to V2.16.5", "RUGGEDCOM ROX RX1400: Versions prior to V2.16.5", "RUGGEDCOM ROX RX1500: Versions prior to V2.16.5", "RUGGEDCOM ROX RX1501: Versions prior to V2.16.5", "RUGGEDCOM ROX RX1510: Versions prior to V2.16.5", "RUGGEDCOM ROX RX1511: Versions prior to V2.16.5", "RUGGEDCOM ROX RX1512: Versions prior to V2.16.5", "RUGGEDCOM ROX RX1524: Versions prior to V2.16.5"]

In the Wild: Unknown

Age: Recently disclosed

Remediation: Update to V2.16.5 or later version and implement network protection measures.

Phishing CVE Vulnerability Update

Published:

All CISA Advisories
ECOVACS DEEBOT Vacuum and Base Station

ECOVACS DEEBOT vacuum and base station devices have critical vulnerabilities that allow attackers to send malicious updates or execute code remotely. These issues stem from hard-coded cryptographic keys and lack of integrity checks in firmware updates, posing significant security risks to users.


Impact: ["ECOVACS DEEBOT X1S PRO: Versions prior to 2.5.38", "ECOVACS DEEBOT X1 PRO OMNI: Versions prior to 2.5.38", "ECOVACS DEEBOT X1 OMNI: Versions prior to 2.4.45", "ECOVACS DEEBOT X1 TURBO: Versions prior to 2.4.45", "ECOVACS DEEBOT T10 Series: Versions prior to 1.11.0", "ECOVACS DEEBOT T20 Series: Versions prior to 1.25.0", "ECOVACS DEEBOT T30 Series: Versions prior to 1.100.0"]

In the Wild: No

Age: Recently disclosed

Remediation: ECOVACS has released software updates for some devices, with remaining updates expected by May 31, 2025. Users should perform system updates.

Phishing CVE Vulnerability Update

Published:

All CISA Advisories
Siemens Mendix OIDC SSO

A vulnerability in Siemens Mendix OIDC SSO allows unauthorized privilege escalation, potentially enabling an attacker to modify the system with administrator rights. This issue is significant as it affects critical infrastructure sectors and poses a risk to system integrity and security.


Impact: ["Siemens Mendix OIDC SSO (Mendix 9 compatible): All versions", "Siemens Mendix OIDC SSO (Mendix 10 compatible): All versions before V4.0.0"]

In the Wild: No

Age: Recently disclosed

Remediation: Update to Mendix OIDC SSO V4.0.0 or later; apply specific workarounds.

CVE Vulnerability Update

Published:

All CISA Advisories
Siemens SIRIUS 3SK2 Safety Relays and 3RK3 Modular Safety Systems

Siemens SIRIUS 3SK2 Safety Relays and 3RK3 Modular Safety Systems have multiple vulnerabilities that could allow attackers to exploit weak cryptographic algorithms and access sensitive information. The vulnerabilities pose significant risks, including the potential retrieval of safety passwords and eavesdropping on connections.


Impact: ["SIRIUS 3RK3 Modular Safety System (MSS)", "SIRIUS Safety Relays 3SK2"]

In the Wild: No

Age: Recently disclosed

Remediation: Currently no fix is available; users are advised to limit physical access and ensure network isolation.

CVE Vulnerability Update

Published:

All CISA Advisories
Siemens SCALANCE LPE9403

The Siemens SCALANCE LPE9403 has multiple vulnerabilities that could compromise the confidentiality, integrity, and availability of affected devices. These vulnerabilities, including incorrect permission assignments and various forms of injection attacks, pose significant security risks, especially since they can be exploited by local attackers with low complexity.


Impact: ["SCALANCE LPE9403 (6GK5998-3GS00-2AC2)"]

In the Wild: Unknown

Age: Recently disclosed

Remediation: See source

Phishing CVE Exploit Vulnerability Update

Published:

All CISA Advisories
Siemens SIMATIC PCS neo

The Siemens SIMATIC PCS neo has a significant vulnerability related to insufficient session expiration, allowing remote attackers to reuse legitimate user sessions after logout. This issue affects multiple versions of the software and poses a risk to critical manufacturing sectors globally.


Impact: ["SIMATIC PCS neo V4.1: All versions prior to V4.1 Update 3", "SIMATIC PCS neo V5.0: All versions prior to V5.0 Update 1"]

In the Wild: No

Age: Recently disclosed

Remediation: Update to the latest versions: V4.1 Update 3 or later for V4.1 and V5.0 Update 1 or later for V5.0.

Phishing CVE Vulnerability Update

Published: