Security Vulnerabilities & CVE Database

Browse the latest CVE vulnerability disclosures, CISA KEV alerts, and OSV advisories. Real-time security vulnerability database curated by 10alert.

U.S. DoJ Charges 12 Chinese Nationals in Massive State-Linked Cyber Espionage Campaign

The U.S. Department of Justice (DoJ) has charged 12 Chinese nationals, including government officers and hackers, for their roles in a global cyber espionage campaign. This coordinated effort involved data theft and suppression of dissent, targeting U.S. critics, Asian governments, and key U.S. agencies. The indictment reveals the intricate web of state-sponsored hacking and the U.S. response to safeguard national security.

#cybersecurity & data protection #chinese hackers #data theft

Read full article →

Webinar Learn How ASPM Transforms Application Security from Reactive to Proactive

Are you tired of dealing with outdated security tools that never seem to give you the full picture? You're not alone. Many organizations struggle with piecing together scattered information, leaving your apps vulnerable to modern threats. That's why we're excited to introduce a smarter, unified approach: Application Security Posture Management (ASPM). ASPM brings together the best of both worlds by combining proactive measures with reactive strategies to enhance your security posture.

#application security #cybersecurity #proactive measures

Read full article →

FBI Alerts: Cybercriminals Impersonate 'BianLian Group' to Extort Corporate Executives

The FBI's Internet Crime Complaint Center (IC3) has issued a critical alert about a data extortion scam targeting corporate executives. Cybercriminals, posing as the 'BianLian Group,' send threatening letters demanding payment to prevent the release of sensitive information. Learn how to protect your organization and report incidents to CISA.

#cybersecurity & data protection #data extortion #corporate executives

Read full article →

ABB CoreSense Path Traversal Flaw Exposes Critical Systems to Attack

A high-severity path traversal vulnerability (CVE-2025-3465) was discovered in ABB CoreSense HM and CoreSense M10 products. The flaw enables unauthenticated attackers to access restricted directories and compromise critical industrial systems. Organizations in food and agriculture, commercial facilities, and critical manufacturing sectors must apply patches immediately to mitigate risks.

CVEs: CVE-2025-3465

#abb #path-traversal #cve-2025-3465 #ot-security #critical-infrastructure

Read full article →

Critical Flaws in ScadaBR Expose Industrial Systems to Remote Attacks

Four critical vulnerabilities in ScadaBR 1.2.0 enable unauthenticated remote code execution (RCE), OS command injection, CSRF, and hard-coded credentials. These flaws threaten global industrial systems, including energy, water, chemical, and manufacturing sectors, risking catastrophic operational disruptions or unauthorized access.

CVEs: CVE-2026-8602, CVE-2026-8603, CVE-2026-8604, CVE-2026-8605

#scadabr #cve-2026-8602 #cve-2026-8603 #rce #industrial-security

Read full article →

Critical Buffer Overflow Flaw in Siemens RUGGEDCOM APE1808 Devices

Siemens disclosed CVE-2026-0300, a critical buffer overflow vulnerability in RUGGEDCOM APE1808 devices, allowing unauthenticated remote code execution with root privileges. The flaw impacts all versions of the devices, posing severe risks to critical manufacturing and industrial control systems globally, necessitating immediate mitigation actions.

CVEs: CVE-2026-0300

#siemens #ruggedcom #cve-2026-0300 #buffer-overflow #critical

Read full article →

Critical XSS Vulnerability in Kieback & Peter DDC Building Controllers Exposed

A critical cross-site scripting (XSS) vulnerability (CVE-2026-4293) has been exposed in Kieback & Peter DDC building controllers, affecting multiple versions used globally in commercial, healthcare, and government facilities. Exploitation could allow attackers to inject malicious JavaScript into user browsers, enabling unauthorized access or further network compromise, necessitating immediate mitigation measures such as firmware updates and network restrictions.

CVEs: CVE-2026-4293

#xss #building-automation #cve-2026-4293 #cybersecurity #vulnerability-management

Read full article →