Latest Cybersecurity News

Real-time cybersecurity news aggregation: CVE alerts, malware analysis, ransomware updates, data breaches, AI security and threat intelligence from 50+ trusted sources.

U.S. DoJ Charges 12 Chinese Nationals in Massive State-Linked Cyber Espionage Campaign

The U.S. Department of Justice (DoJ) has charged 12 Chinese nationals, including government officers and hackers, for their roles in a global cyber espionage campaign. This coordinated effort involved data theft and suppression of dissent, targeting U.S. critics, Asian governments, and key U.S. agencies. The indictment reveals the intricate web of state-sponsored hacking and the U.S. response to safeguard national security.

#cybersecurity & data protection #chinese hackers #data theft

Read full article →

Webinar Learn How ASPM Transforms Application Security from Reactive to Proactive

Are you tired of dealing with outdated security tools that never seem to give you the full picture? You're not alone. Many organizations struggle with piecing together scattered information, leaving your apps vulnerable to modern threats. That's why we're excited to introduce a smarter, unified approach: Application Security Posture Management (ASPM). ASPM brings together the best of both worlds by combining proactive measures with reactive strategies to enhance your security posture.

#application security #cybersecurity #proactive measures

Read full article →

FBI Alerts: Cybercriminals Impersonate 'BianLian Group' to Extort Corporate Executives

The FBI's Internet Crime Complaint Center (IC3) has issued a critical alert about a data extortion scam targeting corporate executives. Cybercriminals, posing as the 'BianLian Group,' send threatening letters demanding payment to prevent the release of sensitive information. Learn how to protect your organization and report incidents to CISA.

#cybersecurity & data protection #data extortion #corporate executives

Read full article →

ABB B&R PVI Vulnerability Exposes Sensitive Data in Log Files

ABB patched a medium-severity vulnerability (CVE-2026-0936) in B&R PVI software, where authenticated local attackers could access sensitive data stored in log files. The flaw affects PVI versions prior to 6.5.0 and requires logging to be manually enabled for exploitation. Users must update to PVI 6.5.0 and disable logging unless necessary for troubleshooting.

CVEs: CVE-2026-0936

#abb #pvi #cve-2026-0936 #industrial-security #data-leak

Read full article →

ABB B&R Automation Runtime Vulnerability Exposes Critical Systems to DoS Attacks

ABB patched a medium-severity DoS vulnerability (CVE-2025-11044) in B&R Automation Runtime versions prior to 6.5 or R4.93. If exploited by unauthenticated attackers on the same network, this flaw could cause permanent system disruptions, impacting critical manufacturing sectors globally. Immediate patch application and network-level mitigations are strongly advised.

CVEs: CVE-2025-11044

#abb #automation runtime #dos #cve-2025-11044 #ics security

Read full article →

Critical Path Traversal Flaw in Hitachi Energy PCM600 Threatens Energy Sector

Hitachi Energy disclosed a critical path traversal vulnerability (CVE-2018-1002208) in its PCM600 power system management product, affecting versions ≤2.11 (Legacy) and 3.0 to 3.1 SP3. Exploitation could allow attackers to write arbitrary files to affected systems, risking unauthorized access and operational disruption in global energy infrastructure.

CVEs: CVE-2018-1002208

#hitachi-energy #pcm600 #cve-2018-1002208 #path-traversal #energy-sector

Read full article →

Critical Flaw in ABB B&R Automation Studio Exposes Industrial Systems to Attacks

ABB disclosed a high-severity flaw (CVE-2025-11043) in B&R Automation Studio versions prior to 6.5 that allows attackers to spoof trusted servers during secure communications via ANSL over TLS or OPC-UA. This vulnerability impacts critical industrial control systems (ICS) worldwide, enabling data interception or manipulation if exploited. ABB urges immediate patching to mitigate risks in automation environments.

CVEs: CVE-2025-11043

#abb #automation-studio #cve-2025-11043 #ics-security #opc-ua

Read full article →