CISA

Critical Vulnerabilities in Brightpick Mission Control Allow Remote Access and Credential Exposure

Multiple high-severity vulnerabilities have been identified in all versions of Brightpick AI's Mission Control / Internal Logic Control platform. These bugs affect all versions of the product and are exploitable remotely with low attack complexity.

CISA and Partners Release Advisory Update on Akira Ransomware

As of November 2025, Akira ransomware actors have expanded their operations, deploying a new variant—Akira_v2—that features faster encryption speeds and improved mechanisms to inhibit system recovery.

Siemens LOGO! 8 BM Devices

Multiple critical vulnerabilities have been identified in Siemens LOGO! 8 BM and SIPLUS LOGO! programmable logic controller (PLC) devices. These vulnerabilities could allow remote attackers to execute arbitrary code.

Radiometrics VizAir

Multiple critical vulnerabilities have been identified in Radiometrics VizAir, a weather monitoring system used in aviation. All vulnerabilities have a CVSS v3.1 and v4 base score of 10.0, indicating maximum severity.

Survision License Plate Recognition Camera

The Survision LPR Camera system does not enforce password protection by default. This allows access to the configuration wizard immediately without a login prompt or credentials check.

New Guidance Released on Microsoft Exchange Server Security Best Practices

This guidance aims to mitigate persistent threats targeting Exchange environments by providing actionable recommendations for hardening server configurations and reducing attack surfaces.

Known Exploited Vulnerabilities Catalog

A critical privilege escalation vulnerability has been identified in Broadcom VMware Aria Operations and VMware Tools. Successful exploitation of this vulnerability enables a local attacker to gain root-level access on the affected VM.

Known Exploited Vulnerabilities Catalog

A critical bug, CVE-2025-61932, has been identified in Motex LANSCOPE Endpoint Manager. It allows remote attackers to execute arbitrary code by sending specially crafted packets due to improper verification of the source of communication channels.

Oxford Nanopore Technologies MinKNOW

Multiple vulnerabilities have been identified in Oxford Nanopore Technologies' MinKNOW software, a DNA and RNA sequencing platform. These flaws could allow attackers to gain unauthorized access, exfiltrate data, and disrupt sequencing operations.

Known Exploited Vulnerabilities Catalog

A critical vulnerability affects Adobe Experience Manager Forms JEE. This flaw allows attackers to execute arbitrary code on affected systems. The vulnerability has been added to CISA’s KEV catalog, indicating confirmed exploitation in the wild.

Defend Against Threats with Cyber Fusion

Cyware is the leading provider of cyber fusion solutions that power threat intelligence sharing , end-to-end automation and 360-degree threat response.

Trending Tags