
4,407 Rockwell PLCs Exposed Online, 22 in Water Cities
A Forescout scan found 4,407 internet-exposed Rockwell PLCs, including 22 in water-industry attack target cities, heightening critical infrastructure risk.

A Forescout scan found 4,407 internet-exposed Rockwell PLCs, including 22 in water-industry attack target cities, heightening critical infrastructure risk.

Researcher Hyunwoo Kim documented Zapscape, CVE-2026-64561, a KVM/x86 shadow memory flaw allowing privileged L1 guest code to escape to the

MIT CSAIL’s interrupt injection attack named TONTOU bypasses retpoline and Safe-RET defenses on AMD Zen 2 to leak Linux password

Researcher Malcolm Stagg’s NatJack technique hijacks TCP sessions and spoofs DNS through NAT table manipulation, affecting Windows Hyper-V and Linux

Novee Security found flaws in Claude Code and Google Gemini CLI that let an attacker-controlled GitHub issue reach CI workflow

PortSwigger’s AI-assisted HTTP Terminator found roughly 30,000 HTTP desync vectors and a live Apache Traffic Server zero-day affecting roughly 700

Oligo Security researchers tied the TeamPCP cluster to Redis attacks dating back to April 2020 and to its later evolution

Coinspect traced roughly $5.7 million in cryptocurrency theft to a 12-year-old weak random number generator in the CryptoJS library and

Researchers Haj Bakry and Mysk found WebKit proxy bypasses in iCloud Private Relay that can expose a user’s real IP

Huntress discovered a Go-based macOS infostealer delivered through ClickFix attacks that steals crypto assets and redirects a percentage of each
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.