Intelligence · Updated daily

Security Intelligence

AI-analysed threats, vulnerabilities and campaigns. Not just what happened — what it means, who's affected, and what to do about it.

Page 16 of 26

376–400 of 632
criticalVulnerabilityActive

CISA Emergency Patch Directive for Critical Cisco FMC RCE – Federal Mandate Signals Active Exploitation Risk

CISA has issued an emergency patching order for CVE-2026-20131, a maximum-severity vulnerability in Cisco Secure Firewall Management Center, requiring federal agencies to remediate by March 22, 2026. This indicates either active exploitation or imminent threat intelligence suggesting weaponization.

CVE-2026-20131
Cisco Secure Firewall Management Center (FMC)
highCampaignContained

Operation Alice dismantles 373K fake CSAM scam infrastructure, exposing predatory fraud economy

International law enforcement shut down 373,000 dark web sites distributing fake child sexual abuse material (CSAM) packages, disrupting a fraud scheme that victimizes both potential offenders seeking illegal content and defrauds them. This represents a significant takedown of deceptive criminal commerce infrastructure.

Dark web marketplaces, Tor infrastructure, Anonymous payment systems
highCampaignActive

Russian Intelligence Phishing Campaign Targets CMA User Accounts - Encryption Circumvention Through Social Engineering

Russian intelligence services are conducting widespread phishing campaigns targeting commercial messaging application accounts of U.S. government officials, military personnel, and journalists. Attackers have successfully compromised thousands of individual accounts to access messages and contact lists, demonstrating a shift from targeting application encryption to exploiting user-level account security.

Commercial Messaging Applications (generic - specific vendors not named in excerpt), Current and former U.S. government officials, U.S. military personnel +2
criticalVulnerabilityEmerging

Critical RCE in Schneider Electric EcoStruxure Automation Expert - Engineering Workstation Compromise Risk

Schneider Electric EcoStruxure Automation Expert versions ≤25.0.1 contain a vulnerability enabling arbitrary command execution on engineering workstations. This threatens the integrity of critical industrial control systems across discrete, hybrid, and continuous manufacturing processes.

Schneider Electric EcoStruxure Automation Expert versions <25.0.1 and 25.0.1
highVulnerabilityActive

Critical XSS and DoS Vulnerabilities in Schneider Electric Modicon Industrial Controllers Expose OT Environments

Schneider Electric Modicon Controllers (M241, M251, M258, M262, LMC058) contain XSS/open redirect and denial-of-service vulnerabilities affecting web interfaces. Exploitation could lead to account takeover, browser-based code execution, or operational disruption in industrial environments.

Schneider Electric Modicon M241 (versions < 5.4.13.12), Schneider Electric Modicon M251 (versions < 5.4.13.12), Schneider Electric Modicon M258 (all firmware versions) +2
highVulnerabilityActive

Apple Introduces Background Security Improvements model to patch WebKit vulnerability without full OS update

Apple released a new Background Security Improvements update addressing WebKit CVE-2026-20643 across iOS, iPadOS, and macOS without requiring full operating system upgrades. This represents a significant shift in Apple's patching strategy, enabling faster security remediation for critical browser engine vulnerabilities.

CVE-2026-20643
Apple iPhone, Apple iPad, Apple Mac
criticalVulnerabilityActive

CODESYS Runtime Vulnerability in Festo Automation Suite Enables Unauthenticated Code Execution

A vulnerability in CODESYS runtime components bundled with Festo Automation Suite prior to v2.8.0.138 allows unauthenticated remote attackers to execute arbitrary code on industrial automation systems. This affects a widely-used ICS development platform with significant operational technology footprint.

Festo Automation Suite (versions < 2.8.0.138), CODESYS Development System 3.0, CODESYS Development System 3.5.16.10
criticalVulnerabilityActive

Schneider Electric SCADAPack RTU Authentication Bypass Exposes Critical ICS Infrastructure

Schneider Electric SCADAPack x70 RTUs and RemoteConnect products contain an authentication or access control vulnerability affecting firmware versions prior to 9.12.2, potentially allowing unauthorized remote access to critical industrial control systems with downstream impacts on device integrity and availability.

Schneider Electric SCADAPack 47xi, Schneider Electric SCADAPack 47x, Schneider Electric SCADAPack 57x +1