// THREAT ADVISORIES

THREAT ADVISORIES

Advisories, vulnerabilities and threat intelligence for third-party risk management.

Breaches Advisories Vulnerabilities RSS
1
Last 24h
32
Last 7 Days
0
Critical (7d)
All Critical High Medium Low
✕ Clear All
THREAT INTEL VERISQ BRIEF 🛡️
VERISQ BRIEFWeekly Update 522: Live From Oslo with Scott Helme

Heads up: the first 7 mins is a bit quiet until we worked out the external mic was misbehaving - sorry! But get through that and have a listen to Scott's experiences with how Report URI is identifying malware-infected machines within orgs, all due to CSP reporting. It&

Medium · Sep 23, 2026 · Troy Hunt
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🎣
VERISQ BRIEFWebinar tomorrow: Inside real-world Google Workspace breaches

Tomorrow's webinar examines real Google Workspace breaches involving social engineering and malicious OAuth applications, from initial access through the critical first hours of incident response. Learn which security controls and response decisions can make the greatest difference. [...]

Medium · Sep 22, 2026 · BleepingComputer
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🎣
VERISQ BRIEFThe next intellectual property thief may sound like your CEO

Impersonation, phishing and domain-name abuse are the most concerning types of online intellectual property infringement, according to CSC’s The State of Online IP Risk 2026 report. Internet and branded content, online marketplaces and paid search were the channels most frequently targeted. CSC surveyed 300 senior executives specializing in intellectual property law during the second quarter of 2026. Top three operational challenges when managing IP infringements (Source: CSC) “We know from dealing with our customers that … More → The post The next intellectual property thief may sound like your CEO appeared first on Help Net Security .

Medium · Sep 22, 2026 · Help Net Security
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🛡️
VERISQ BRIEFGPT-6 Astra Breaks an Old Enigma Message

This is pretty amazing: However, the most astonishing thing about this break is that the GPT­6 Astra did it entirely on its own. Carter Leffer only directed GPT­6 Astra to see if it could break any of the unbroken Enigma messages published on the Crypto Cellar Research web page. After analysing the unbroken messages on the website, it decided that the most promising message was Nr. 172, MVUEH and it also quickly suspected that the plaintext of Nr. 173, SIPVX, might be related to the plaintext of the unbroken MVUEH message. After trying many different approaches, GPT­6 Astra focused on using the repeated place name ROSENOW ROSENOW as a crib. After developing the necessary Python and C++ software for an Enigma simulator and an Enigma Bombe, GPT­6 Astra started a thorough break with the ROSENOW crib, which in the end resulted in the correct key and plaintext for the MVUEH message being found...

Medium · Sep 22, 2026 · Schneier on Security
Read Full Intelligence Brief →
ADVISORY VERISQ BRIEF 🛡️
VERISQ BRIEFBuilding Crypto Agility Across the Enterprise

A Risk-Based Approach Can Turn an Overwhelming Migration Into a Workable Plan Experts advise organizations preparing for post-quantum cryptography to start with a focused inventory of cryptography in use, rank systems and data by business exposure, and build internal capacity to change algorithms and certificates safely. Vendors should also commit to crypto agility.

Medium · Sep 22, 2026 · DataBreachToday
Read Full Intelligence Brief →
ADVISORY VERISQ BRIEF 🛡️
VERISQ BRIEFMicrosoft to retire Microsoft 365 Companion apps in December

Microsoft will retire the Calendar, People, and Files Microsoft 365 companion apps on December 16 and has asked admins to remove them from managed devices. [...]

Medium · Sep 21, 2026 · BleepingComputer
Read Full Intelligence Brief →
ADVISORY VERISQ BRIEF 🛡️
VERISQ BRIEFMicrosoft fixes broken Excel copy and paste for all Office users

Microsoft has fixed a known issue that causes copy-and-paste failures for Excel users after installing the September 2026 security updates. [...]

Medium · Sep 21, 2026 · BleepingComputer
Read Full Intelligence Brief →
ADVISORY VERISQ BRIEF 💀
VERISQ BRIEF FBI's CJIS v6.1: What Security Teams Need to Know.

The FBI's CJIS Security Policy v6.1 strengthens requirements around encryption and vulnerability scanning while continuing the shift toward more continuous security assessment. Specops explains what changed and how agencies can address password, MFA, and identity requirements as they prepare for upcoming audits. [...]

Medium · Sep 21, 2026 · BleepingComputer
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🛡️
VERISQ BRIEFSiemba brings continuous IDOR testing to production APIs

Siemba has announced automated testing for insecure direct object reference (IDOR) as part of its API Security Testing capability, which tests REST, GraphQL and SOAP APIs for the vulnerability classes most likely to expose customer data. A 200-endpoint API collection can be tested for IDOR in under an hour. The same coverage has typically taken a human tester days or weeks, working endpoint by endpoint, and produced a written report days after that. Siemba compresses … More → The post Siemba brings continuous IDOR testing to production APIs appeared first on Help Net Security .

Medium · Sep 21, 2026 · Help Net Security
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 📧
VERISQ BRIEFThe Target Is No Longer the Model. It’s the Agent.

AI agents are becoming the new attack surface, exposed to poisoned skills, prompt injection, jailbreaks and attacks through connected tools. I read the AI security research published in a single month, February 2026, and when you put it all together, it’s not a list of curiosities. It’s a field guide to a new attack surface. […]

Medium · Sep 21, 2026 · Security Affairs
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🛡️
VERISQ BRIEFKnow what was tested before your SAP ECC migration goes live

In this Help Net Security interview, Guilherme Joventino, COO of MIGNOW, explains why some large companies plan to stay on ECC past the 2027 deadline and pay SAP for extended support until 2030. The interview covers what that choice may cost, why fear of disruption stalls projects more often than budget, and what the first ninety days of a phased migration involve. It also looks at staff who hold years of knowledge about the old … More → The post Know what was tested before your SAP ECC migration goes live appeared first on Help Net Security .

Medium · Sep 21, 2026 · Help Net Security
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF ☁️
VERISQ BRIEFIdentity Visibility in 2026: The Foundation of Identity Security

Identity visibility is a starting point for modern identity security, because stolen and misused credentials are among the most frequently reported initial access vectors in breach research, including Verizon's annual Data Breach Investigations Report. This article explains what identity visibility means in IAM, why cloud and multicloud environments complicate it, which capabilities matter in

Medium · Sep 19, 2026 · The Hacker News
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🛡️
VERISQ BRIEFCalling viral AI actress Tilly Norwood? Agree to a face scan first

AI actress Tilly Norwood went viral after glitching into Chinese on Piers Morgan Uncensored last night. Her "Talking Tilly" video call service face-scans every caller for an 18+ age check, senses callers' moods during calls, and shuts down permanently on September 27. We tried it and read the fine print. [...]

Medium · Sep 19, 2026 · BleepingComputer
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🛡️
VERISQ BRIEFViral AI actress' hotline face-scans every caller, watches their mood

AI actress Tilly Norwood went viral after glitching into Chinese on Piers Morgan Uncensored last night. Her "Talking Tilly" video call service face-scans every caller for an 18+ age check, senses callers' moods during calls, and shuts down permanently on September 27. We tried it and read the fine print. [...]

Medium · Sep 19, 2026 · BleepingComputer
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🛡️
VERISQ BRIEFBusinesses finally seeing AI ROI, but 62% can’t handle the storage demands

A Seagate study finds that 99% of IT leaders expect AI to drive increased data storage needs, but only 38% are prepared to meet them, revealing a significant readiness gap.

Medium · Sep 18, 2026 · ZDNet Security
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🛡️
VERISQ BRIEFSecure enterprise sharing with access reviews for Microsoft 365

Microsoft 365 makes sharing files easy, but access can remain long after its original purpose has ended, leaving organizations with little visibility into who can still reach sensitive data. tenfold Software explains how centralized access governance and owner-driven reviews can help identify and remove unnecessary access. [...]

Medium · Sep 18, 2026 · BleepingComputer
Read Full Intelligence Brief →
ADVISORY VERISQ BRIEF 🛡️
VERISQ BRIEFMicrosoft Teams will let admins block custom file extensions

Microsoft Teams will soon let administrators tweak the list of file extensions commonly associated with security threats to meet their company's security requirements. [...]

Medium · Sep 18, 2026 · BleepingComputer
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🛡️
VERISQ BRIEFWebinar: Which Google Workspace security controls actually matter?

Fast-growing companies face countless recommendations for securing Google Workspace, but not every control provides the same value. This webinar examines real-world breaches to explore which security controls matter most, which may be overrated, and where lean security teams should focus their resources. [...]

Medium · Sep 18, 2026 · BleepingComputer
Read Full Intelligence Brief →
ADVISORY VERISQ BRIEF 🛡️
VERISQ BRIEFMicrosoft fixes bug behind ‘Defender Antivirus is turned off’ alerts

Microsoft has resolved a known issue that causes incorrect alerts warning that Defender Antivirus was turned off after installing recent updates. [...]

Medium · Sep 18, 2026 · BleepingComputer
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🛡️
VERISQ BRIEFBots with good manners are better at fooling people on social media

Most people can’t tell a bot from a human online, and the bots most likely to fool them are the polite ones, according to a new Surfshark study. The company analyzed 1,722 participants worldwide, testing their ability to separate human comments from AI-generated ones in a social media setting. Overall, people caught just 40% of the bots placed in front of them. (Source: Surfshark) The bots that slipped by most often weren’t loud or aggressive. … More → The post Bots with good manners are better at fooling people on social media appeared first on Help Net Security .

Medium · Sep 18, 2026 · Help Net Security
Read Full Intelligence Brief →
ADVISORY VERISQ BRIEF 🛡️
VERISQ BRIEFMicrosoft fixes broken copy and paste for Excel 2016 users

Microsoft has fixed a known issue that causes copy-and-paste failures for some Excel users after installing the September 2026 KB5002914 security update. [...]

Medium · Sep 18, 2026 · BleepingComputer
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🛡️
VERISQ BRIEFZDI-26-718: Cisco Identity Services Engine MnTRESTLivelogService XML External Entity Processing Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.9. The following CVEs are assigned: CVE-2026-20235.

Medium · Sep 18, 2026 · Zero Day Initiative
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🏛️
VERISQ BRIEFMost WordPress pros still lack a breach recovery plan

Melapress, a maker of WordPress security plugins, surveyed 319 WordPress professionals and found that most had dealt with at least one known security incident. The respondents build and run WordPress sites for a living: agency staff, developers, designers, site owners and administrators. Across the whole group, fewer than three in ten have a breach recovery plan. A recovery plan settles in advance who responds, where the clean backups are, and who needs to be told. … More → The post Most WordPress pros still lack a breach recovery plan appeared first on Help Net Security .

Medium · Sep 18, 2026 · Help Net Security
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🛡️
VERISQ BRIEFStates Expand Cyber Support Beyond Their Own Networks

Local Control and Funding Gaps Complicate Critical Infrastructure Protection States are extending cyber support to local utilities and other essential services they do not control. Closing the gap will require more than grants and tools. Local operators need sustained monitoring, OT expertise and stronger, consistent vendor controls.

Medium · Sep 18, 2026 · DataBreachToday
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 📧
VERISQ BRIEFDownload: The IT leader’s guide to AI code sprawl

AI hasn’t just made building faster, it’s made everyone a builder. Across every department, employees are shipping apps, agents and automations using AI tools, often without knowing they’ve created something that needs governing at all. The result: AI code sprawl is taking root, increasing risk, compromising compliance, and wasting resources. The usual responses aren’t working: not because they’re poorly executed, but because they were never built for a problem at this scale or speed. Drawing … More → The post Download: The IT leader’s guide to AI code sprawl appeared first on Help Net Security .

Medium · Sep 17, 2026 · Help Net Security
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🛡️
VERISQ BRIEFSchneider Electric PowerChute Serial Shutdown

View CSAF Summary Schneider Electric is aware of vulnerabilities in its PowerChute Serial Shutdown product. The PowerChute Serial Shutdown product is a UPS management software enabling graceful system shutdown and energy management capabilities for desktops, servers and workstations. Failure to apply the remediation provided below may risk improper authentication validation which could result in disruption of operations and access to system data. The following versions of Schneider Electric PowerChute Serial Shutdown are affected: PowerChute Serial Shutdown vers:intdot/<=1.5, 1.6 (CVE-2026-13348) CVSS Vendor Equipment Vulnerabilities v3 5.3 Schneider Electric Schneider Electric PowerChute Serial Shutdown Improper Restriction of Excessive Authentication Attempts Background Critical Infrastructure Sectors: Commercial Facilities, Critical Manufacturing, Energy, Information Technology Countries/Areas Deployed: Worldwide Company Headquarters Location: France Vulnerabilities Expand All + CVE-2026-13348 CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to gain unauthorized access to a user account by performing an arbitrary number of authentication attempts when redirect handling is disabled. View CVE Details Affected Products Schneider Electric PowerChute Serial Shutdown Vendor: Schneider Electric Prod...

Medium · Sep 17, 2026 · CISA Advisories
Read Full Intelligence Brief →
ADVISORY VERISQ BRIEF 🛡️
VERISQ BRIEFAdversary simulation: what you need to know

Adversary simulation ('red teaming') tests your ability to prevent, detect and respond to cyber attacks.

Medium · Sep 17, 2026 · NCSC UK
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 💀
VERISQ BRIEFSmashing Security podcast #485: These researchers got drunk to hack an LG TV

Researchers wanted to test if LG's smart TVs come with any security risks - but their lawyers noticed a snag: the terms and conditions would forbid it. So they came up with a solution. They got plastered before setting up the TV, on the reasoning that you can't be legally bound to a contract you agreed to while drunk. What they discovered will make you look at your TV rather differently... Meanwhile, awful Android malware with the audacious name "Awesome" (in Indonesian) is doing the rounds, stealing your data, demanding a ransom, and then giving you a "jump scare"... Plus, in our featured interview, Andy Hornegold of Intruder explains why the mid-market is where cybercriminals are having the most fun right now - and how AI is helping attackers get from "first foot in the door" to "full ransomware disaster" in less than a working day. All this and more in episode 485 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Lianne Potter.

Medium · Sep 16, 2026 · Graham Cluley
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🛡️
VERISQ BRIEFChina’s Answer to AI Safety: More Controls, Not Slower Development

China is emphasizing technical controls for AI agents as U.S. leaders debate slowing frontier AI, raising new questions for businesses deploying autonomous systems. The post China’s Answer to AI Safety: More Controls, Not Slower Development appeared first on TechRepublic .

Medium · Sep 16, 2026 · TechRepublic Security
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🏥
VERISQ BRIEFScans Targeting Hospitality Applications, (Wed, Sep 16th)

Earlier today, I noted an odd request showing up in our "First Seen" report:

Medium · Sep 16, 2026 · SANS Internet Storm Center
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🛡️
VERISQ BRIEFInternational Meteor Organization says cyberattack dealt ‘critical blow’ to website

A website used around the world for reporting meteors faces weeks of downtime as the organization moves away from systems that were hacked recently.

Medium · Sep 16, 2026 · The Record
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🛡️
VERISQ BRIEFQuorum Cyber Adds Autonomous SOC Through Ontinue Acquisition

Proposed Purchase Combines Agentic SOC Technology With Managed Security Expertise Quorum Cyber's planned acquisition of Swiss Microsoft Gold Partner Ontinue would combine Microsoft-focused managed security with agentic SOC technology designed to investigate threats at machine speed while giving customers control over when AI can act autonomously.

Medium · Sep 16, 2026 · DataBreachToday
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🛡️
VERISQ BRIEFWebinar: What happens in the first hours of a Google Workspace breach

The first hours after discovering a Google Workspace breach can determine how an incident unfolds. This webinar examines real-world breaches to show which early response decisions can limit the impact and which can make matters worse. [...]

Medium · Sep 16, 2026 · BleepingComputer
Read Full Intelligence Brief →
ADVISORY VERISQ BRIEF 🛡️
VERISQ BRIEFWindows Server 2022 reaches end of mainstream support next month

Microsoft has reminded customers that Windows Server 2022 will reach the end of mainstream support next month and enter extended support until October 2031. [...]

Medium · Sep 16, 2026 · BleepingComputer
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 💣
VERISQ BRIEFZDI-26-708: (0Day) Microsoft Windows HTTP Proxy Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.3.

Medium · Sep 16, 2026 · Zero Day Initiative
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 💣
VERISQ BRIEFZDI-26-705: (0Day) BusyBox libarchive Symlink Directory Traversal Arbitrary File Creation Vulnerability

This vulnerability allows remote attackers to create arbitrary files on affected installations of BusyBox. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-92205.

Medium · Sep 16, 2026 · Zero Day Initiative
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 💀
VERISQ BRIEFOverview of Passive Optical Networks (PONs) Security

Passive Optical Networks (PONs) connect end-users to infrastructure using optical fibre in the last kilometre (Fibre-to-the-x). This article provides a technical overview of the security features in ITU-T specifications: Gigabit-capable PON (GPON) , 10-Gigabit-capable PON (XG-PON) , 10-Gigabit-capable Symmetric PON (XGS-PON) , Next-generation PON 2 (NG-PON2) , and 50-Gigabit-capable PON (50G-PON) . The analysis covers authentication schemes, key derivation, encryption methods, and associated security implications.

Medium · Sep 15, 2026 · Quarkslab Blog
Read Full Intelligence Brief →
ADVISORY VERISQ BRIEF 🛡️
VERISQ BRIEFBefore You Patch. Why Patch Reliability Matters for Confident Deployment

Executive Summary Microsoft’s September 2026 security updates, KB5124008 and KB5124012, have been linked to USB audio failures on some Windows systems, highlighting the operational risk that can accompany security patching. Qualys TruRisk Eliminate classified both updates as Low Reliability, signaling the need for additional validation before production deployment. Patch Reliability helps IT and security teams focus on deeper […]

Medium · Sep 15, 2026 · Qualys Blog
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🛡️
VERISQ BRIEFZelensky appoints former police chief to lead Ukraine’s cyber coordination center

Ihor Klymenko, who has experience in law enforcement and as interior minister, will run Ukraine's National Cybersecurity Coordination Center.

Medium · Sep 15, 2026 · The Record
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF ☁️
VERISQ BRIEFF5 Bot Defense uses real-time risk scoring to detect fraud and abuse

F5 has announced enhancements to F5 Distributed Cloud Bot Defense, introducing new device intelligence capabilities and specialized agentic AI protections. These capabilities bring persistent device context and continuous risk decisioning to application security, giving organizations the real-time agent management designed to help welcome trusted digital interaction while helping stop automated fraud and abuse. These updates arrive as AI agents emerge as a key channel for interacting with websites, mobile applications, and customer portals. Unlike basic … More → The post F5 Bot Defense uses real-time risk scoring to detect fraud and abuse appeared first on Help Net Security .

Medium · Sep 15, 2026 · Help Net Security
Read Full Intelligence Brief →
ADVISORY VERISQ BRIEF 🛡️
VERISQ BRIEFSiemens Teamcenter

View CSAF Summary A reflected cross site scripting vulnerability in the authentication redirect flow (/auth/) of Teamcenter allows an unauthenticated remote attacker to inject JavaScript into an authenticated user's session by crafting a malicious URL. Successful exploitation may enable the attacker to read data or perform actions within the victim's Teamcenter session. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Teamcenter are affected: Teamcenter V2412 vers:intdot/<2412.0013 (CVE-2026-58113) Teamcenter V2506 vers:intdot/<2506.0010 (CVE-2026-58113) Teamcenter V2512 vers:intdot/<2512.2607 (CVE-2026-58113) Teamcenter V2606 vers:intdot/<2606.2607 (CVE-2026-58113) CVSS Vendor Equipment Vulnerabilities v3 6.1 Siemens Siemens Teamcenter Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Background Critical Infrastructure Sectors: Critical Manufacturing, Information Technology Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-58113 Affected applications do not properly encode user-supplied input reflected into HTML attribute contexts within the authentication redirect flow (/auth/ endpoint). This could allow an unauthenticated remote attacker to inject arbitrary JavaScript into t...

Medium · Sep 15, 2026 · CISA Advisories
Read Full Intelligence Brief →
ADVISORY VERISQ BRIEF 🏛️
VERISQ BRIEFProtecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers

Developed by the National Institute of Standards and Technology (NIST) and CISA, this interagency report provides federal agencies and cloud service providers with guidelines to protect the identity assertions, access tokens, and cryptographic mechanisms that support modern authentication and authorization. As agencies adopt hybrid and multi-cloud environments, single sign-on, federation, and application programming interface (API)-based access increasingly depend on signed tokens and assertions that adversaries may target for forgery, theft, and misuse to move laterally across enterprise networks and access sensitive data. This final report updates the initial public draft and incorporates feedback on token validation, secrets management, and detection at scale, as well as input from government and industry experts that CISA gathered through its Joint Cyber Defense Collaborative. The report expands on NIST Special Publication Security and Privacy Controls for Information Systems and Organizations and supports Executive Order 14306 on secure software development practices. It provides architectural considerations and emphasizes the importance of Secure by Design principles for interoperable defense across cloud environments.

Medium · Sep 15, 2026 · CISA Advisories
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🔑
VERISQ BRIEFSchneider Electric SCADAPack x70 Products

View CSAF Summary Schneider Electric is aware of a vulnerability in its SCADAPack x70 products. The SCADAPack 47x, SCADAPack 47xi, SCADAPack 47xd, SCADAPack 470R and SCADAPack 57x products are Remote Terminal Units that provide communication capabilities for remote monitoring and control. Failure to apply the mitigations provided below may increase the risk of unauthorized access to RTU configuration through the Secure Lock functionality, potentially resulting in a loss of confidentiality. The following versions of Schneider Electric SCADAPack x70 Products are affected: SCADAPack 47x vers:all/* (CVE-2026-81861) SCADAPack 47xi vers:all/* (CVE-2026-81861) SCADAPack 47xd vers:all/* (CVE-2026-81861) SCADAPack 470R vers:all/* (CVE-2026-81861) SCADAPack 57x vers:all/* (CVE-2026-81861) SCADAPack 3xx vers:all/* (CVE-2026-81861) SCADAPack 32 vers:all/* (CVE-2026-81861) CVSS Vendor Equipment Vulnerabilities v3 6.5 Schneider Electric Schneider Electric SCADAPack x70 Products Insufficiently Protected Credentials Background Critical Infrastructure Sectors: Critical Manufacturing, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: France Vulnerabilities Expand All + CVE-2026-81861 There is an insufficiently protected credentials vulnerability that could result in exposure of authentication information and unauthorized access to RTU functionality. View CVE Deta...

Medium · Sep 15, 2026 · CISA Advisories
Read Full Intelligence Brief →
ADVISORY VERISQ BRIEF 🛡️
VERISQ BRIEFMicrosoft confirms KB5002914 Excel update breaks copy and paste

Microsoft has confirmed that copy and paste may silently fail for some Excel users after installing the September 2026 KB5002914 security update. [...]

Medium · Sep 15, 2026 · BleepingComputer
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🛡️
VERISQ BRIEFAkuity gives AI agents operational context to safely ship software

Akuity has introduced its Agentic Control Plane and MCP Server. Akuity’s Agentic Control Plane lets AI agents accelerate software delivery by giving them the operational context and permissions to act, all governed by the same controls Akuity already enforces across the pipeline. That governance is what gives engineering leadership the confidence to let agents into production, with real control over what agents can touch. Agentic engineering is driving teams to write more code than ever … More → The post Akuity gives AI agents operational context to safely ship software appeared first on Help Net Security .

Medium · Sep 15, 2026 · Help Net Security
Read Full Intelligence Brief →
THREAT INTEL VERISQ BRIEF 🛡️
VERISQ BRIEFYour employees are already using AI tools you never approved

Seventy-four percent of respondents report departmental or scaled AI adoption at their organizations, including within individual teams or departments, across business functions, and as part of processes and operations, according to the latest OneTrust 2026 AI-Ready Governance Report. The remaining respondents are planning, evaluating, or experimenting with AI, while 1% report no AI use. Which best describes how your organization currently performs AI governance? (Source: OneTrust) Putting AI governance into practice This level of adoption … More → The post Your employees are already using AI tools you never approved appeared first on Help Net Security .

Medium · Sep 15, 2026 · Help Net Security
Read Full Intelligence Brief →