Johnson Controls CEM AC2000
Johnson Controls' CEM AC2000 has a critical privilege escalation flaw (CVE-2026-21661) that could compromise critical infrastructure security systems. Patches exist but many systems remain unpatched.
ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks • How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts • The US military just turned off ad tracking on its phones. Maybe you should too • Hackers exploit Tencent app flaw to deploy GrayRabbit malware • CRPx0 ransomware: what you need to know ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks • How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts • The US military just turned off ad tracking on its phones. Maybe you should too • Hackers exploit Tencent app flaw to deploy GrayRabbit malware • CRPx0 ransomware: what you need to know
The full HackWire archive — 3,892 stories, newest first.
Johnson Controls' CEM AC2000 has a critical privilege escalation flaw (CVE-2026-21661) that could compromise critical infrastructure security systems. Patches exist but many systems remain unpatched.
Hitachi Energy's PCM600 power control platform has a Zip-Slip path traversal flaw (CVE-2018-1002208) allowing local attackers to write arbitrary files. The vulnerability threatens data integrity across critical energy infrastructure systems globally.
ABB's B&R Automation Runtime has a critical race condition (CVE-2025-11044) allowing unauthenticated attackers to permanently disable industrial systems through resource exhaustion. The flaw requires no user interaction and ABB has released patches.
Trellix source code breach exposes core components to threat actors, compromising enterprise defenses. The supply chain attack demonstrates how security vendors themselves are vulnerable targets.
ABB B&R Automation Studio versions before 6.5 contain a critical certificate validation bypass vulnerability (CVE-2025-11043, CVSS 7.4) that allows network attackers to perform man-in-the-middle attacks. Attackers can intercept OPC-UA and ANSL communications to steal data and inject malicious comman
Apache patched critical RCE vulnerabilities in MINA networking library enabling unauthenticated remote code execution. Organizations using MINA must apply updates immediately to prevent system compromise.
Cargo theft evolved from street heists to supply chain cyberattacks. Criminals now compromise logistics systems to reroute shipments, enabling multimillion-dollar thefts with a few keystrokes.
Microsoft Edge stores plaintext passwords in process memory, exposing enterprise credentials to admin-level attackers. This vulnerability enables credential theft and lateral movement within corporate networks.
Attackers trojanized DAEMON Tools installers on the official website starting April 8, 2026, delivering backdoor malware to thousands of users. This supply chain attack demonstrates how compromises at trusted sources can bypass standard user security practices at scale.
China-linked APT group UAT-8302 targets South American and Eastern European governments with custom malware for persistence and data theft since late 2024. The campaign demonstrates sophisticated state-sponsored capabilities and sustained operational intent.
Attackers compromised DAEMON Tools installers on the official website with valid certificates, bypassing security checks. This supply chain attack targeted millions of users who trusted the vendor, exploiting the fundamental vulnerability of software distribution pipelines.
CVE-2026-23918: Apache HTTP/2 critical double-free flaw enables remote DoS and potential RCE. Requires only port 80/443 access; exploitable via crafted HTTP/2 frames.
End-of-life software escapes vulnerability monitoring when projects are abandoned. Flaws discovered in EOL code often lack CVE numbers and go undetected, leaving organizations unknowingly exposed to exploitable code.
A 23-year-old was arrested for hacking Taiwan's High-Speed Rail TETRA communication system, triggering emergency brakes on moving trains. The breach exposed critical infrastructure vulnerabilities in transportation networks across East Asia.
Android patched CVE-2026-0073, a critical RCE vulnerability in its System component requiring no user interaction. It threatened millions of devices worldwide with complete device takeover.
Bleeding Llama exposes 300,000 Ollama deployments to unauthenticated remote memory theft via heap out-of-bounds read vulnerability, risking sensitive data leaks from AI systems worldwide.
Red team specialist Joey Melo discusses how AI guardrails are vulnerable to text-based attacks. Exploited systems could generate misinformation, assist fraud, and create liability for organizations.
Microsoft warns of a sophisticated phishing campaign using fake conduct reports and adversary-in-the-middle attacks to intercept credentials and session tokens, bypassing MFA protections. The attack demonstrates nation-state-level sophistication targeting US organizations.
FTC bans Kochava from selling location data on hundreds of millions of devices without explicit consumer consent. The settlement escalates regulatory scrutiny of data brokers.
CVE-2026-29014 is a critical flaw in MetInfo CMS enabling unauthenticated PHP code execution. Already under active exploitation, it requires no credentials or user interaction. Organizations must patch immediately.
Third-party OAuth tokens often don't expire, creating persistent backdoors that bypass passwords and MFA. When employees connect apps like ChatGPT or Zapier to their work accounts, they unknowingly grant permanent access that organizations rarely monitor, leaving a critical security blind spot.
Vimeo suffered a data breach in April 2026 exposing personal information of 119,000 users, with the ShinyHunters extortion gang suspected. The incident was discovered via Have I Been Pwned, highlighting the threat actor's typical extortion tactics targeting high-profile platforms.
EOL software represents an undetected vulnerability risk: CVE databases stop tracking flaws once vendor support ends, yet organizations often unknowingly run these components, leaving them invisible to security scanners.
ScarCruft compromised a gaming platform to distribute BirdCall malware across Android and Windows devices for surveillance and data theft. This represents a shift from their traditional targeted approach toward mass-distribution campaigns.