Security Vulnerabilities & CVE Database

Browse the latest CVE vulnerability disclosures, CISA KEV alerts, and OSV advisories. Real-time security vulnerability database curated by 10alert.

U.S. DoJ Charges 12 Chinese Nationals in Massive State-Linked Cyber Espionage Campaign

The U.S. Department of Justice (DoJ) has charged 12 Chinese nationals, including government officers and hackers, for their roles in a global cyber espionage campaign. This coordinated effort involved data theft and suppression of dissent, targeting U.S. critics, Asian governments, and key U.S. agencies. The indictment reveals the intricate web of state-sponsored hacking and the U.S. response to safeguard national security.

#cybersecurity & data protection #chinese hackers #data theft

Read full article →

Webinar Learn How ASPM Transforms Application Security from Reactive to Proactive

Are you tired of dealing with outdated security tools that never seem to give you the full picture? You're not alone. Many organizations struggle with piecing together scattered information, leaving your apps vulnerable to modern threats. That's why we're excited to introduce a smarter, unified approach: Application Security Posture Management (ASPM). ASPM brings together the best of both worlds by combining proactive measures with reactive strategies to enhance your security posture.

#application security #cybersecurity #proactive measures

Read full article →

FBI Alerts: Cybercriminals Impersonate 'BianLian Group' to Extort Corporate Executives

The FBI's Internet Crime Complaint Center (IC3) has issued a critical alert about a data extortion scam targeting corporate executives. Cybercriminals, posing as the 'BianLian Group,' send threatening letters demanding payment to prevent the release of sensitive information. Learn how to protect your organization and report incidents to CISA.

#cybersecurity & data protection #data extortion #corporate executives

Read full article →

G7 and CISA Release SBOM Guidelines for AI Security and Transparency

The G7 and CISA jointly released guidelines outlining minimum elements for Software Bill of Materials (SBOM) in AI systems to enhance transparency and security in AI supply chains. The initiative targets organizations developing, deploying, or managing AI systems, aiming to mitigate risks through improved supply chain visibility and risk assessment.

#sbom #ai security #cybersecurity #g7 #supply chain

Read full article →

Critical Buffer Overflow Flaw in ABB AC500 V3 PLCs Threatens Industrial Systems

ABB disclosed a critical stack buffer overflow vulnerability (CVE-2025-15467) in AC500 V3 PLC firmware versions 3.9.0 and 3.9.0_HF1 that allows remote code execution (RCE), denial-of-service (DoS), or system crashes. The flaw impacts industrial control systems (ICS) in critical sectors such as energy, manufacturing, water treatment, and chemical industries, posing severe risks to operational technology (OT) environments.

CVEs: CVE-2025-15467

#abb #plc #cve-2025-15467 #buffer-overflow #industrial-security

Read full article →

Critical Vulnerabilities in Subnet PowerSYSTEM Center Expose Sensitive Data

Four critical vulnerabilities (CVE-2026-26289, CVE-2026-33570, CVE-2026-35555, CVE-2026-35504) were discovered in Subnet Solutions PowerSYSTEM Center versions 2020–2026, enabling authenticated attackers to access sensitive data, manipulate email notifications via CRLF injection, or delete project groups. These flaws expose energy and manufacturing sectors to data breaches and operational disruptions if left unpatched.

CVEs: CVE-2026-26289, CVE-2026-33570, CVE-2026-35555, CVE-2026-35504

#powersystem-center #cve-2026-26289 #cve-2026-35504 #crlf-injection #ot-security

Read full article →

ABB AC500 V3 PLCs Hit by Critical Vulnerabilities: Patch Now

ABB AC500 V3 PLCs contain three critical vulnerabilities (CVE-2025-2595, CVE-2025-41659, CVE-2025-41691) enabling unauthorized access, certificate manipulation, and DoS attacks. These flaws impact global industrial sectors, including energy, water, and manufacturing, potentially disrupting critical infrastructure operations. Immediate patching is required to mitigate risks.

CVEs: CVE-2025-2595, CVE-2025-41659, CVE-2025-41691

#abb #plc #industrial-security #cve-2025 #dos

Read full article →