ABB AC500 V3 Multiple Vulnerabilities
Three flaws in ABB AC500 V3 PLCs enable authentication bypass and credential theft, exposing power, water, chemical infrastructure to attacks allowing system impersonation and operational compromise.
ACTIVE THREATS: Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers • AI-powered attack exploited PaperCut flaws to hack 395 organizations • Microsoft Excel KB5002914 update breaks copy and paste for some users • Surfshark VPN says hackers breached internal testing, proxy servers • PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances ACTIVE THREATS: Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers • AI-powered attack exploited PaperCut flaws to hack 395 organizations • Microsoft Excel KB5002914 update breaks copy and paste for some users • Surfshark VPN says hackers breached internal testing, proxy servers • PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances
Latest cybersecurity vulnerabilities news, analysis, and intelligence.
Three flaws in ABB AC500 V3 PLCs enable authentication bypass and credential theft, exposing power, water, chemical infrastructure to attacks allowing system impersonation and operational compromise.
ABB WebPro SNMP Card contains critical authentication bypass that validates only the first character of credentials, enabling trivial unauthorized access to critical infrastructure devices. A second vulnerability causes Modbus denial-of-service. Versions ≤1.1.8.k vulnerable; update to 1.1.8.p.
Critical authorization flaws in PowerSYSTEM Center allow privilege escalation via REST API (CVSS 8.2). Impacts versions 2020-2026, letting low-privilege users access restricted admin resources in critical infrastructure globally.
ABB AC500 V3 PLCs have a critical buffer overflow (CVE-2025-15467) enabling unauthenticated RCE via malicious CMS messages. A single network packet triggers the flaw without authentication.
White Circle secured $11 million to build an AI governance platform that monitors enterprise AI systems for hallucinations, data leaks, and prompt injection attacks—addressing critical gaps in production AI security.
Adobe patched 52 critical vulnerabilities, with flaws in Connect and Commerce enabling unauthenticated code execution. Over 50% address RCE risks, making immediate patching urgent for enterprises.
Exaforce closed a $125M Series B to scale its AI-powered SOC platform globally. Its autonomous Exabots handle threat detection and response, reducing the need for human security analysts.
Microsoft patched 137 vulnerabilities May 12; ~12 highly exploitable. Critical: Jira/Confluence SSO flaw enables privilege escalation; Word RCE bugs trigger via preview—major email risk.
Microsoft patched 137 CVEs in May 2026 with no zero-days—but AI-accelerated discovery is driving record volumes. 2026 is already on track to exceed 2020's annual record of 1,245 bugs.
AI-powered Project Glasswing accelerates security patches. Major vendors released record volumes in May 2026—Microsoft alone patched 118 vulnerabilities—reshaping patch management cycles.
Exim MTA vulnerability CVE-2026-45185 ("Dead.Letter") enables remote code execution via use-after-free in GnuTLS deployments. Attackers exploit improper BDAT SMTP handling during TLS teardown to corrupt heap memory, requiring only basic connection access to affected servers.
Microsoft released KB5087544 for Windows 10 on May 12, 2026, patching 120 vulnerabilities from May's Patch Tuesday while fixing a critical Remote Desktop display bug. The update is available to Enterprise LTSC and ESU subscribers.
Signal launches anti-phishing defenses after Russian state actors targeted users via fake verification messages. New features slow social engineering attacks impersonating Signal Support.
IT teams struggle with incident response coordination across fragmented monitoring tools. A June 2 webinar explores AI-assisted workflows to streamline response and compress resolution times.
Android 17 adds defenses against spoofed banking calls, device theft, and stalkerware—addressing social engineering, device compromise, and personal surveillance threats. The security updates backport to Android 11+, broadening protection across billions of devices.
Microsoft patched 120 vulnerabilities in May 2026, including 31 critical RCE flaws spanning Windows, Office, and SharePoint. Office preview-pane vulnerabilities enable code execution through malicious documents, heightening enterprise risk without user interaction.
Microsoft's May 2026 Patch Tuesday fixes 120 Windows 11 vulnerabilities via KB5089549/KB5087420. Mandatory updates for versions 25H2, 24H2, and 23H2 are available through Windows Update.
Fortinet patched critical RCE vulnerabilities in FortiAuthenticator and FortiSandbox enabling unauthenticated code execution. The flaws compromise identity management and malware analysis infrastructure.
Researchers discovered a critical vulnerability in Hugging Face models where modifying the tokenizer.json configuration file allows attackers to intercept model outputs and exfiltrate credentials. The attack functions as a man-in-the-middle layer, affecting locally-run AI deployments.
Dark Reading's 20th anniversary profiles 20 leaders who transformed the CISO role from a technical afterthought to a strategic C-suite executive over two decades. Driven by major breaches and regulatory mandates, cybersecurity evolved from an IT cost center into core enterprise risk management.
SAP's May 2026 update fixes 15 flaws, including critical authentication bypass (Commerce Cloud) and SQL injection (S/4HANA) vulnerabilities enabling code execution and database theft by attackers.
OpenAI's Daybreak uses AI to accelerate vulnerability patching before exploitation. As AI-powered discovery has outpaced remediation, the platform aims to rebalance the security equation.
GM paid $12.75M—California's largest privacy penalty—for selling driver location data without consent. The settlement bars data sales for five years and limits retention to 180 days, marking the state's first major data minimization enforcement action.
Google confirmed the first AI-generated zero-day: a Python script bypassing 2FA on web admin tools. Threat actors are now using LLMs to weaponize exploits, reducing attack timelines from weeks to hours.
Human judgment is your final defense. BEC attacks account for 21% of successful compromises despite just 2% of attempts—proof that social engineering beats tech controls.
The FCC extended its foreign router ban, allowing firmware updates for existing devices. The May decision balances national security concerns about state-actor router exploits with practical device replacement challenges for consumers.
Frame Security raised $50M Series A for its AI-powered employee security training platform. Founded by Wiz/Team8 veterans, it personalizes phishing simulations to combat social engineering attacks.
Dirty Frag chains two Linux kernel flaws (CVE-2026-43284 + CVE-2026-43500) to enable local privilege escalation to root on enterprise systems. Already under limited exploitation in the wild, the vulnerability represents a persistent weakness in Linux kernel page cache management.
Google discovered the first AI-developed zero-day exploit—a 2FA bypass affecting web admin software, actively exploited in mass campaigns. The attack combines stolen credentials with authentication bypass; the LLM-generated code marks a watershed moment where AI threatens shifted from theoretical to
A critical cPanel flaw (CVE-2026-41940) is being exploited by 2,000+ attackers to deploy backdoors, miners, and ransomware worldwide. Attacks began immediately after disclosure in late April 2026.