News
Short updates on security, GRC, and AI developments, with enough context to be worth reading.
- Brief
Johnson Controls C-CURE 9000 and Victor application server
Summary: View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker with network access to achieve remote code execution. Why it matters: This …Read brief - Brief
Johnson Controls XAAP Android
Summary: View CSAF Summary Successful exploitation of this vulnerability could result in an attacker obtaining confidential information from the device. Why it matters: This …Read brief - Brief
MZ Automation lib60870
Summary: View CSAF Summary Successful exploitation of this vulnerability could cause the parsing process to crash, which will cause a denial of service. Why it matters: This …Read brief - Brief
MZ Automation libIEC61850
Summary: View CSAF Summary Successful exploitation of these vulnerabilities could allow an unauthenticated network-adjacent attacker to crash critical IEC 61850 services or execute …Read brief - Brief
Panduit IntraVUE
Summary: View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker with access to the IT network to manipulate industrial control devices without …Read brief - Brief
Rockwell Automation ThinManager
Summary: View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to restricted system directories outside of …Read brief - Brief
Stakeholder event on guidelines on the interplay between data protection and competition law: save the date
Summary: Brussels, 23 July – The EDPB and the European Commission organise a remote stakeholder event in the context of their joint work on upcoming guidelines on the interplay …Read brief - Brief
Weintek cMT3092X
Summary: View CSAF Summary Successful exploitation of these vulnerabilities could allow a non-privileged user to escalate privileges or view the credentials of other users. Why it …Read brief - Brief
SEC Announces Departure of Principal Deputy Director of Enforcement Sam Waldon
Summary: The Securities and Exchange Commission today announced that Sam Waldon, Principal Deputy Director of the Division of Enforcement, will depart the agency on July 31, 2026, …Read brief - Brief
CISA Adds Two Known Exploited Vulnerabilities to Catalog
Summary: CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. Why it matters: This matters if it …Read brief - Brief
CISA, FBI, EPA and U.S. Government Partners Update Warning of Iran-Affiliated Threat Actors Targeting ...
Summary: CISA, FBI, EPA and U.S. Government Partners Update Warning of Iran-Affiliated Threat Actors Targeting … Why it matters: This matters if it changes how teams think …Read brief - Brief
NTT DATA Group cuts incident analysis to 30 minutes with Codex
Summary: NTT DATA Group uses ChatGPT Enterprise and Codex to help 9,000 employees automate work, cut incident analysis to 30 minutes, and scale secure AI adoption. Why it matters: …Read brief - Brief
CISA Adds Four Known Exploited Vulnerabilities to Catalog
Summary: CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. Why it matters: This matters if it …Read brief - Brief
Rockwell Automation 1718-AENTR/1719-AENTR
Summary: View CSAF Summary Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product. Why it matters: This …Read brief - Brief
Rockwell Automation 1734 POINT I/O
Summary: View CSAF Summary Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product. Why it matters: This …Read brief