Intelligence · Updated daily

Security Intelligence

AI-analysed threats, vulnerabilities and campaigns. Not just what happened — what it means, who's affected, and what to do about it.

Page 6 of 17

126–150 of 403
criticalVulnerabilityEmerging

Deserialization RCE in Schneider Electric Foxboro DCS Workstations: Critical ICS Risk in Distributed Control Systems

Schneider Electric patched a critical untrusted deserialization vulnerability in EcoStruxure Foxboro DCS workstations and servers that enables remote code execution. The vulnerability affects control software on engineering stations but spares runtime components, yet poses significant risk to DCS environments managing critical infrastructure.

Schneider Electric EcoStruxure Foxboro DCS (workstations and servers)
criticalVulnerabilityActive

Critical Privilege Escalation in Schneider Electric Plant iT/Brewmaxx Enables RCE Across Industrial Operations

Schneider Electric Plant iT/Brewmaxx versions 9.60 and above contain four critical vulnerabilities (CVSS 9.9) enabling privilege escalation to remote code execution. Organizations using this brewing and plant management software face immediate risk of full system compromise.

CVE-2025-49844CVE-2025-46817CVE-2025-46818CVE-2025-46819
Schneider Electric Plant iT/Brewmaxx 9.60 and later
criticalVulnerabilityActive

Maximum-Severity Quest KACE SMA Exploitation Campaign Signals Internet-Exposed Admin Tools as Prime Targets

Threat actors are actively exploiting CVE-2025-32975, a critical remote code execution flaw in Quest KACE Systems Management Appliance (SMA), against unpatched internet-exposed instances since March 2026. SMA is enterprise-grade IT infrastructure management software, making compromises particularly damaging.

CVE-2025-32975
Quest KACE Systems Management Appliance (SMA)
criticalVulnerabilityActive

CISA Emergency Patch Directive for Critical Cisco FMC RCE – Federal Mandate Signals Active Exploitation Risk

CISA has issued an emergency patching order for CVE-2026-20131, a maximum-severity vulnerability in Cisco Secure Firewall Management Center, requiring federal agencies to remediate by March 22, 2026. This indicates either active exploitation or imminent threat intelligence suggesting weaponization.

CVE-2026-20131
Cisco Secure Firewall Management Center (FMC)
highCampaignContained

Operation Alice dismantles 373K fake CSAM scam infrastructure, exposing predatory fraud economy

International law enforcement shut down 373,000 dark web sites distributing fake child sexual abuse material (CSAM) packages, disrupting a fraud scheme that victimizes both potential offenders seeking illegal content and defrauds them. This represents a significant takedown of deceptive criminal commerce infrastructure.

Dark web marketplaces, Tor infrastructure, Anonymous payment systems