Latest Cybersecurity News

Real-time cybersecurity news aggregation: CVE alerts, malware analysis, ransomware updates, data breaches, AI security and threat intelligence from 50+ trusted sources.

U.S. DoJ Charges 12 Chinese Nationals in Massive State-Linked Cyber Espionage Campaign

The U.S. Department of Justice (DoJ) has charged 12 Chinese nationals, including government officers and hackers, for their roles in a global cyber espionage campaign. This coordinated effort involved data theft and suppression of dissent, targeting U.S. critics, Asian governments, and key U.S. agencies. The indictment reveals the intricate web of state-sponsored hacking and the U.S. response to safeguard national security.

#cybersecurity & data protection #chinese hackers #data theft

Read full article →

Webinar Learn How ASPM Transforms Application Security from Reactive to Proactive

Are you tired of dealing with outdated security tools that never seem to give you the full picture? You're not alone. Many organizations struggle with piecing together scattered information, leaving your apps vulnerable to modern threats. That's why we're excited to introduce a smarter, unified approach: Application Security Posture Management (ASPM). ASPM brings together the best of both worlds by combining proactive measures with reactive strategies to enhance your security posture.

#application security #cybersecurity #proactive measures

Read full article →

FBI Alerts: Cybercriminals Impersonate 'BianLian Group' to Extort Corporate Executives

The FBI's Internet Crime Complaint Center (IC3) has issued a critical alert about a data extortion scam targeting corporate executives. Cybercriminals, posing as the 'BianLian Group,' send threatening letters demanding payment to prevent the release of sensitive information. Learn how to protect your organization and report incidents to CISA.

#cybersecurity & data protection #data extortion #corporate executives

Read full article →

Critical Vulnerabilities in ABB Terra AC Wallbox: Heap and Buffer Overflow Risks

ABB has disclosed three critical vulnerabilities in its **Terra AC Wallbox** electric vehicle (EV) chargers, affecting versions up to **1.8.33**. Exploitation could lead to **heap memory pollution, remote control, or firmware manipulation** via Bluetooth or custom protocols. ABB has released **version 1.8.36** to patch these flaws, urging immediate updates to prevent attacks on energy infrastructure.

CVEs: CVE-2025-10504, CVE-2025-12142, CVE-2025-12143

#abb #ev-chargers #buffer-overflow #cve-2025 #cybersecurity

Read full article →

Hitachi Energy GMS600 Vulnerability Exposes Systems to Decryption Attacks

Hitachi Energy has disclosed a **medium-severity vulnerability (CVE-2022-4304)** in its GMS600 product, affecting versions 1.3.0 and 1.3.1. The flaw, a timing-based side-channel attack in OpenSSL, could allow attackers to decrypt sensitive data by recovering the pre-master secret. Immediate mitigation includes upgrading to version 1.3.2 and implementing network security best practices.

CVEs: CVE-2022-4304

#hitachi-energy #openssl #cve-2022-4304 #side-channel-attack #critical-infrastructure

Read full article →

Critical Vulnerabilities in ABB B&R Automation Studio Demand Immediate Update

ABB has released a critical update for **B&R Automation Studio**, addressing **24 vulnerabilities** in versions prior to 6.5. These flaws, including **remote code execution (RCE), heap-based buffer overflows, and memory corruption**, could allow attackers to gain unauthorized access, expose sensitive data, or disrupt industrial operations. Users are urged to update to **version 6.5 immediately** to mitigate risks in energy and other critical infrastructure sectors.

CVEs: CVE-2025-6965, CVE-2025-3277, CVE-2023-7104, CVE-2022-35737, CVE-2020-15358

#abb #industrial-security #cve #rce #memory-corruption

Read full article →

Critical Vulnerabilities in ABB B&R Automation Runtime Expose Industrial Systems

ABB B&R Automation Runtime versions prior to 6.4 are affected by three critical vulnerabilities, including **session hijacking, cross-site scripting (XSS), and CSV formula injection**. Exploitation could allow attackers to execute arbitrary code or take over remote sessions. ABB has released **Automation Runtime 6.4** to patch these flaws, and users are urged to update immediately, especially in **energy sector** deployments.

CVEs: CVE-2025-3449, CVE-2025-3448, CVE-2025-11498

#abb #industrial-security #cve-2025 #xss #session-hijacking

Read full article →