<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Advisoryloom Editor</title>
	<atom:link href="https://advisoryloom.com/almain/author/advisoryloom-editor/feed/" rel="self" type="application/rss+xml" />
	<link>https://advisoryloom.com/almain</link>
	<description>Weaving cybersecurity advisories into one clear view</description>
	<lastBuildDate>Thu, 03 Sep 2026 16:47:01 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1</generator>

<image>
	<url>https://advisoryloom.com/almain/wp-content/uploads/2026/04/cropped-ChatGPT-Image-Apr-17-2026-03_10_38-PM-32x32.png</url>
	<title>Advisoryloom Editor</title>
	<link>https://advisoryloom.com/almain</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Your AI Agent Never Sleeps. That&#8217;s the Problem.</title>
		<link>https://www.youtube.com/shorts/JICY_6vKj2s</link>
		
		<dc:creator><![CDATA[Advisoryloom Editor]]></dc:creator>
		<pubDate>Thu, 03 Sep 2026 16:47:01 +0000</pubDate>
				<category><![CDATA[Cyber Videos]]></category>
		<category><![CDATA[Advisories]]></category>
		<category><![CDATA[Threats]]></category>
		<category><![CDATA[Videos]]></category>
		<guid isPermaLink="false">https://advisoryloom.com/almain/your-ai-agent-never-sleeps-thats-the-problem/</guid>

					<description><![CDATA[Confirmed Zero-Day AlertPaperCut NG/MF zero-day exploit chain used in data-theft attacksVerified September 1, 2026 8:00 amView verified coverage]]></description>
										<content:encoded><![CDATA[]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root</title>
		<link>https://thehackernews.com/2026/09/critical-cisco-nexus-9000-flaw-lets.html</link>
		
		<dc:creator><![CDATA[Advisoryloom Editor]]></dc:creator>
		<pubDate>Thu, 03 Sep 2026 16:46:57 +0000</pubDate>
				<category><![CDATA[Threat Intelligence]]></category>
		<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://advisoryloom.com/almain/critical-cisco-nexus-9000-flaw-lets-unauthenticated-remote-attackers-run-code-as-root/</guid>

					<description><![CDATA[Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that]]></description>
										<content:encoded><![CDATA[<div>Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7 umbrella CVEs, 2 of which are rated 9.8, with no workaround for any IOS XR version.</p>
<p>The Nexus vulnerability, tracked as CVE-2026-20212 (CVSS score: 9.8), is</p></div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory</title>
		<link>https://thehackernews.com/2026/09/brazetsu-malware-turns-compromised.html</link>
		
		<dc:creator><![CDATA[Advisoryloom Editor]]></dc:creator>
		<pubDate>Thu, 03 Sep 2026 16:46:57 +0000</pubDate>
				<category><![CDATA[Threat Intelligence]]></category>
		<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://advisoryloom.com/almain/brazetsu-malware-turns-compromised-windows-hosts-into-criminal-marketplace-inventory/</guid>

					<description><![CDATA[Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground]]></description>
										<content:encoded><![CDATA[<div>Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts.</p>
<p>&#8220;Unlike the standard infostealer model, BraZetsu is a comprehensive master toolkit that empowers Initial Access Brokers (IABs) by turning compromised systems into highly valuable commercial</p></div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data</title>
		<link>https://thehackernews.com/2026/09/thomson-reuters-court-software-breach.html</link>
		
		<dc:creator><![CDATA[Advisoryloom Editor]]></dc:creator>
		<pubDate>Thu, 03 Sep 2026 16:46:55 +0000</pubDate>
				<category><![CDATA[Threat Intelligence]]></category>
		<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://advisoryloom.com/almain/thomson-reuters-court-software-breach-may-have-exposed-ssns-and-sealed-data/</guid>

					<description><![CDATA[Thomson Reuters disclosed on Wednesday that an unauthorized party obtained files from C-Track, the court case management platform]]></description>
										<content:encoded><![CDATA[<div>Thomson Reuters disclosed on Wednesday that an unauthorized party obtained files from C-Track, the court case management platform sold by its West Publishing Corporation unit, in March 2026, affecting courts in 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada.</p>
<p>West Publishing said it discovered the activity on June 30, 2026. A subset of court records could contain individuals&#8217; names</p></div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Rockwell Automation 1756-ENBT Module</title>
		<link>https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-05</link>
					<comments>https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-05#respond</comments>
		
		<dc:creator><![CDATA[Advisoryloom Editor]]></dc:creator>
		<pubDate>Thu, 03 Sep 2026 16:46:52 +0000</pubDate>
				<category><![CDATA[CISA Alerts]]></category>
		<category><![CDATA[CISA]]></category>
		<category><![CDATA[Gov]]></category>
		<category><![CDATA[ICSA]]></category>
		<category><![CDATA[KEV]]></category>
		<guid isPermaLink="false">https://advisoryloom.com/almain/rockwell-automation-1756-enbt-module/</guid>

					<description><![CDATA[View CSAF Summary Successful exploitation of this vulnerability could crash the module. The device requires a restart to]]></description>
										<content:encoded><![CDATA[<div>
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-246-05.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Successful exploitation of this vulnerability could crash the module. The device requires a restart to recover.</strong></p>
<p>The following versions of Rockwell Automation 1756-ENBT Module are affected:</p>
<ul>
<li>1756-ENBT module vers:all/* (CVE-2025-10478)</li>
</ul>
<div class="csaf-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS</th>
<th role="columnheader">Vendor</th>
<th role="columnheader">Equipment</th>
<th role="columnheader">Vulnerabilities</th>
</tr>
</thead>
<tbody>
<tr>
<td>v3 7.5</td>
<td>Rockwell Automation</td>
<td>Rockwell Automation 1756-ENBT Module</td>
<td>Improper Check for Unusual or Exceptional Conditions</td>
</tr>
</tbody>
</table>
</div>
<h3>Background</h3>
<ul>
<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Food and Agriculture, Transportation Systems, Water and Wastewater</li>
<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>
<li><strong>Company Headquarters Location: </strong>United States</li>
</ul>
<hr>
<h2>Vulnerabilities</h2>
<div class="csaf-accordion">
<p><a class="csaf-accordion-toggle-all" href="https://www.cisa.gov/#">Expand All +</a></p>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-10478</a></h3>
<div class="csaf-accordion-content">
<p>A denial-of-service security issue exists in the Rockwell Automation 1756-ENBT module which is a ControlLogix EtherNet/IP bridge that enables communication between Logix 5000 controllers and Ethernet devices. An attacker could exploit this vulnerability by sending a crafted CIP packet, causing the module to crash. The device requires a restart to recover.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-10478">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Rockwell Automation 1756-ENBT Module</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br />Rockwell Automation</div>
<div class="ics-version"><strong>Product Version:</strong><br />Rockwell Automation 1756-ENBT module: vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br />known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br />Rockwell Automation recommends that users upgrade to 1756-EN2T or 1756-EN4TR. Users who are not able to upgrade should use Rockwell Automation&#8217;s security best practices.<br /><a href="https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight">https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight</a></p>
<p><strong>Mitigation</strong><br />For more information on this issue, see the corresponding Rockwell Automation security advisory.<br /><a href="https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html">https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/754.html">CWE-754 Improper Check for Unusual or Exceptional Conditions</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
<tr>
<td>4.0</td>
<td>8.7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<hr>
<h2>Acknowledgments</h2>
<ul>
<li>Rockwell Automation reported this vulnerability to CISA.</li>
</ul>
<hr>
<h2>Legal Notice and Terms of Use</h2>
<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>
<hr>
<h2>Recommended Practices</h2>
<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>
<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>
<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>
<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>
<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B&#8211;Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>
<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>
<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>
<hr>
<h2>Revision History</h2>
<ul>
<li><strong>Initial Release Date: </strong>2026-09-03</li>
</ul>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Date</th>
<th role="columnheader">Revision</th>
<th role="columnheader">Summary</th>
</tr>
</thead>
<tbody>
<tr>
<td>2026-09-03</td>
<td>1</td>
<td>Initial Republication of Rockwell Automation security advisory.</td>
</tr>
</tbody>
</table>
<hr>
<h2>Legal Notice and Terms of Use</h2>
</div>
]]></content:encoded>
					
					<wfw:commentRss>https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-05/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Inductive Automation Ignition</title>
		<link>https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-06</link>
					<comments>https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-06#respond</comments>
		
		<dc:creator><![CDATA[Advisoryloom Editor]]></dc:creator>
		<pubDate>Thu, 03 Sep 2026 16:46:51 +0000</pubDate>
				<category><![CDATA[CISA Alerts]]></category>
		<category><![CDATA[CISA]]></category>
		<category><![CDATA[Gov]]></category>
		<category><![CDATA[ICSA]]></category>
		<category><![CDATA[KEV]]></category>
		<guid isPermaLink="false">https://advisoryloom.com/almain/inductive-automation-ignition/</guid>

					<description><![CDATA[View CSAF Summary Successful exploitation of this vulnerability could allow any authenticated user to create projects. The following]]></description>
										<content:encoded><![CDATA[<div>
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-246-06.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Successful exploitation of this vulnerability could allow any authenticated user to create projects.</strong></p>
<p>The following versions of Inductive Automation Ignition are affected:</p>
<ul>
<li>Ignition &lt;=8.1.53 (CVE-2026-77393)</li>
</ul>
<div class="csaf-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS</th>
<th role="columnheader">Vendor</th>
<th role="columnheader">Equipment</th>
<th role="columnheader">Vulnerabilities</th>
</tr>
</thead>
<tbody>
<tr>
<td>v3 8.8</td>
<td>Inductive Automation</td>
<td>Inductive Automation Ignition</td>
<td>Incorrect Default Permissions</td>
</tr>
</tbody>
</table>
</div>
<h3>Background</h3>
<ul>
<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Energy, Information Technology</li>
<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>
<li><strong>Company Headquarters Location: </strong>United States</li>
</ul>
<hr>
<h2>Vulnerabilities</h2>
<div class="csaf-accordion">
<p><a class="csaf-accordion-toggle-all" href="https://www.cisa.gov/#">Expand All +</a></p>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-77393</a></h3>
<div class="csaf-accordion-content">
<p>In Ignition 8.1.53 and earlier, the Gateway &#8220;Create Project Role(s)&#8221; setting shipped blank, which permitted any authenticated user to create projects (if they can execute gateway scripts). Ignition 8.1.54 restricts project creation to Designer sessions and no longer relies on this setting. The 8.3 series is not affected.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-77393">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Inductive Automation Ignition</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br />Inductive Automation</div>
<div class="ics-version"><strong>Product Version:</strong><br />Inductive Automation Ignition: &lt;=8.1.53</div>
<div class="ics-status"><strong>Product Status:</strong><br />known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br />Inductive Automation has determined that this issue is a default-value configuration, not a flaw in the access control itself. The security control enforces exactly what the &#8220;Create Project Role(s)&#8221; setting specifies; because the setting shipped blank, no role was required to create a project. Populating the setting fully closes the vulnerability.</p>
<p><strong>Mitigation</strong><br />Inductive Automation recommends users upgrade to 8.1.54 or later (or the latest 8.3 version), which restricts project creation to Designer sessions and no longer relies on this setting. Users who must remain on an earlier 8.1 version can fully remediate the issue by setting &#8220;Create Project Role(s)&#8221; to match their Designer Role. Once the setting is populated, only users holding that role can create projects. See Gateway General Security Settings.<br /><a href="https://docs.inductiveautomation.com/docs/8.1/platform/security/gateway-general-security-settings#gateway-security-settings-table">https://docs.inductiveautomation.com/docs/8.1/platform/security/gateway-general-security-settings#gateway-security-settings-table</a></p>
<p><strong>Mitigation</strong><br />For more information, see the publication at the Inductive Automation Trust Center.<br /><a href="https://security.inductiveautomation.com/?tcuUid=34477620-731d-4b70-b22b-9450f9a659a3">https://security.inductiveautomation.com/?tcuUid=34477620-731d-4b70-b22b-9450f9a659a3</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/276.html">CWE-276 Incorrect Default Permissions</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
<tr>
<td>4.0</td>
<td>8.7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<hr>
<h2>Acknowledgments</h2>
<ul>
<li>Christopher Lusk of North Echo Security Research reported this vulnerability to Inductive Automation.</li>
<li>Elhussain Fathy (0xSphinx) independently reported this vulnerability and confirmed the fix.</li>
</ul>
<hr>
<h2>Legal Notice and Terms of Use</h2>
<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>
<hr>
<h2>Recommended Practices</h2>
<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>
<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>
<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>
<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>
<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B&#8211;Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>
<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>
<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>
<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>
<hr>
<h2>Revision History</h2>
<ul>
<li><strong>Initial Release Date: </strong>2026-09-03</li>
</ul>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Date</th>
<th role="columnheader">Revision</th>
<th role="columnheader">Summary</th>
</tr>
</thead>
<tbody>
<tr>
<td>2026-09-03</td>
<td>1</td>
<td>Initial Republication of Inductive Automation Trust Center update.</td>
</tr>
</tbody>
</table>
<hr>
<h2>Legal Notice and Terms of Use</h2>
</div>
]]></content:encoded>
					
					<wfw:commentRss>https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-06/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>OPCFoundation OPC UA LocalDiscoveryServer (LDS)</title>
		<link>https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-01</link>
					<comments>https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-01#respond</comments>
		
		<dc:creator><![CDATA[Advisoryloom Editor]]></dc:creator>
		<pubDate>Thu, 03 Sep 2026 16:46:51 +0000</pubDate>
				<category><![CDATA[CISA Alerts]]></category>
		<category><![CDATA[CISA]]></category>
		<category><![CDATA[Gov]]></category>
		<category><![CDATA[ICSA]]></category>
		<category><![CDATA[KEV]]></category>
		<guid isPermaLink="false">https://advisoryloom.com/almain/opcfoundation-opc-ua-localdiscoveryserver-lds/</guid>

					<description><![CDATA[View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to take control of a high-privilege]]></description>
										<content:encoded><![CDATA[<div>
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-246-01.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Successful exploitation of this vulnerability could allow an attacker to take control of a high-privilege terminal during installation and run arbitrary commands.</strong></p>
<p>The following versions of OPCFoundation OPC UA LocalDiscoveryServer (LDS) are affected:</p>
<ul>
<li>UA-LDS-Installers &lt;1.04.420 (CVE-2026-77477)</li>
</ul>
<div class="csaf-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS</th>
<th role="columnheader">Vendor</th>
<th role="columnheader">Equipment</th>
<th role="columnheader">Vulnerabilities</th>
</tr>
</thead>
<tbody>
<tr>
<td>v3 4.6</td>
<td>OPCFoundation</td>
<td>OPCFoundation OPC UA LocalDiscoveryServer (LDS)</td>
<td>Execution with Unnecessary Privileges</td>
</tr>
</tbody>
</table>
</div>
<h3>Background</h3>
<ul>
<li><strong>Critical Infrastructure Sectors: </strong>Chemical, Energy, Food and Agriculture, Water and Wastewater, Critical Manufacturing</li>
<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>
<li><strong>Company Headquarters Location: </strong>United States</li>
</ul>
<hr>
<h2>Vulnerabilities</h2>
<div class="csaf-accordion">
<p><a class="csaf-accordion-toggle-all" href="https://www.cisa.gov/#">Expand All +</a></p>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-77477</a></h3>
<div class="csaf-accordion-content">
<p>An attacker can intercept a high-privilege console window launched during installation of the LDS. The attacker must be able to launch an installer with elevated privileges and have access to the keyboard and display while the installation is taking place.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-77477">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>OPCFoundation OPC UA LocalDiscoveryServer (LDS)</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br />OPCFoundation</div>
<div class="ics-version"><strong>Product Version:</strong><br />OPCFoundation UA-LDS-Installers: &lt;1.04.420</div>
<div class="ics-status"><strong>Product Status:</strong><br />known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br />OPCFoundation recommends users update to OPC UA LDS Installers 1.04.420 or later.</p>
<p><strong>Mitigation</strong><br />For more information about this vulnerability and its mitigation, see the OPCFoundation security advisory.<br /><a href="https://github.com/OPCFoundation/OPC-SecurityAdvisories/tree/latest/csaf/2026/009">https://github.com/OPCFoundation/OPC-SecurityAdvisories/tree/latest/csaf/2026/009</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/250.html">CWE-250 Execution with Unnecessary Privileges</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4.6</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N">CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N</a></td>
</tr>
<tr>
<td>4.0</td>
<td>2.4</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N">CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<hr>
<h2>Acknowledgments</h2>
<ul>
<li>Lukas Schumaker of Rockwell Automation reported this vulnerability to OPCFoundation.</li>
</ul>
<hr>
<h2>Legal Notice and Terms of Use</h2>
<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>
<hr>
<h2>Recommended Practices</h2>
<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>
<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>
<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>
<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B&#8211;Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>
<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>
<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>
<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely.</p>
<hr>
<h2>Revision History</h2>
<ul>
<li><strong>Initial Release Date: </strong>2026-09-03</li>
</ul>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Date</th>
<th role="columnheader">Revision</th>
<th role="columnheader">Summary</th>
</tr>
</thead>
<tbody>
<tr>
<td>2026-09-03</td>
<td>1</td>
<td>Initial Publication</td>
</tr>
</tbody>
</table>
<hr>
<h2>Legal Notice and Terms of Use</h2>
</div>
]]></content:encoded>
					
					<wfw:commentRss>https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-01/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Tycon Systems TPDIN-Monitor-WEB2 (Update A)</title>
		<link>https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-01</link>
					<comments>https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-01#respond</comments>
		
		<dc:creator><![CDATA[Advisoryloom Editor]]></dc:creator>
		<pubDate>Thu, 03 Sep 2026 16:46:51 +0000</pubDate>
				<category><![CDATA[CISA Alerts]]></category>
		<category><![CDATA[CISA]]></category>
		<category><![CDATA[Gov]]></category>
		<category><![CDATA[ICSA]]></category>
		<category><![CDATA[KEV]]></category>
		<guid isPermaLink="false">https://advisoryloom.com/almain/tycon-systems-tpdin-monitor-web2-update-a/</guid>

					<description><![CDATA[View CSAF Summary Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected]]></description>
										<content:encoded><![CDATA[<div>
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-01.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk.</strong></p>
<p>The following versions of Tycon Systems TPDIN-Monitor-WEB2 (Update A) are affected:</p>
<ul>
<li>TPDIN-Monitor-WEB2 &lt;2.4.5 (CVE-2026-61884, CVE-2026-55985)</li>
</ul>
<div class="csaf-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS</th>
<th role="columnheader">Vendor</th>
<th role="columnheader">Equipment</th>
<th role="columnheader">Vulnerabilities</th>
</tr>
</thead>
<tbody>
<tr>
<td>v3 9.8</td>
<td>Tycon Systems</td>
<td>Tycon Systems TPDIN-Monitor-WEB2</td>
<td>Missing Authentication for Critical Function, Cleartext Storage of Sensitive Information</td>
</tr>
</tbody>
</table>
</div>
<h3>Background</h3>
<ul>
<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>
<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>
<li><strong>Company Headquarters Location: </strong>United States</li>
</ul>
<hr>
<h2>Vulnerabilities</h2>
<div class="csaf-accordion">
<p><a class="csaf-accordion-toggle-all" href="https://www.cisa.gov/#">Expand All +</a></p>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-61884</a></h3>
<div class="csaf-accordion-content">
<p>The device ships without HTTP credentials configured, intended for an installer to set them on first use. On firmware 2.4.4 and earlier, a unit left in this unconfigured state serves the web management interface without requiring any login. An attacker with network access to such a unit can reach full device controls, including power relay management, device reboot, remote access service configuration, and network settings, which could allow disruption of connected infrastructure or physical damage to equipment.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-61884">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Tycon Systems TPDIN-Monitor-WEB2 (Update A)</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br />Tycon Systems</div>
<div class="ics-version"><strong>Product Version:</strong><br />Tycon Systems TPDIN-Monitor-WEB2: &lt;2.4.5</div>
<div class="ics-status"><strong>Product Status:</strong><br />known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br />Tycon Systems has released firmware 2.4.5, which resolves this vulnerability by requiring an administrator username and password to be set before the web interface is served. Further inquiries can be directed to security@tyconsystems.com.</p>
<p><strong>Mitigation</strong><br />Tycon Systems recommends setting an administrative username and strong password on the Network Configuration page and confirming in a private browser window that a login is required, for units still running firmware 2.4.4 or earlier. Repeat this after any factory reset.</p>
<p><strong>Mitigation</strong><br />Tycon Systems recommends not exposing the web interface to the Internet, as it is HTTP only. The unit should be kept on a private network, behind a firewall or VPN.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/306.html">CWE-306 Missing Authentication for Critical Function</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9.8</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
<tr>
<td>4.0</td>
<td>9.3</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-55985</a></h3>
<div class="csaf-accordion-content">
<p>The device&#8217;s web management interface stores and displays system credentials in cleartext on a certain configuration page accessible to authenticated users. Any party with access to the administrative dashboard can immediately read these credentials, which may be used to compromise other systems on the local network.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-55985">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Tycon Systems TPDIN-Monitor-WEB2 (Update A)</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br />Tycon Systems</div>
<div class="ics-version"><strong>Product Version:</strong><br />Tycon Systems TPDIN-Monitor-WEB2: &lt;2.4.5</div>
<div class="ics-status"><strong>Product Status:</strong><br />known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br />Tycon Systems has released firmware 2.4.5, which resolves this vulnerability by removing cleartext credentials from the web interface response. Further inquiries can be directed to security@tyconsystems.com.</p>
<p><strong>Mitigation</strong><br />Tycon Systems recommends changing any factory-default SNMP community strings and the Telnet password if they were left at shipped values. Leave Telnet disabled unless required.</p>
<p><strong>Mitigation</strong><br />Tycon Systems recommends using a dedicated mail account for device alerts, rather than an account also used for other sensitive purposes, to limit exposure if credentials are compromised.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/312.html">CWE-312 Cleartext Storage of Sensitive Information</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4.3</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N</a></td>
</tr>
<tr>
<td>4.0</td>
<td>5.3</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<hr>
<h2>Acknowledgments</h2>
<ul>
<li>Abdiwelli Guled reported these vulnerabilities to CISA.</li>
</ul>
<hr>
<h2>Legal Notice and Terms of Use</h2>
<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>
<hr>
<h2>Recommended Practices</h2>
<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>
<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>
<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>
<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>
<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>
<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>
<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>
<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B&#8211;Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>
<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>
<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>
<hr>
<h2>Revision History</h2>
<ul>
<li><strong>Initial Release Date: </strong>2026-07-21</li>
</ul>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Date</th>
<th role="columnheader">Revision</th>
<th role="columnheader">Summary</th>
</tr>
</thead>
<tbody>
<tr>
<td>2026-07-21</td>
<td>1</td>
<td>Initial Publication</td>
</tr>
<tr>
<td>2026-09-03</td>
<td>2</td>
<td>Updated affected version range and vulnerability details based on vendor input.</td>
</tr>
</tbody>
</table>
<hr>
<h2>Legal Notice and Terms of Use</h2>
</div>
]]></content:encoded>
					
					<wfw:commentRss>https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-01/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Tycon Systems TPDIN-Monitor-WEB3</title>
		<link>https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-08</link>
					<comments>https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-08#respond</comments>
		
		<dc:creator><![CDATA[Advisoryloom Editor]]></dc:creator>
		<pubDate>Thu, 03 Sep 2026 16:46:50 +0000</pubDate>
				<category><![CDATA[CISA Alerts]]></category>
		<category><![CDATA[CISA]]></category>
		<category><![CDATA[Gov]]></category>
		<category><![CDATA[ICSA]]></category>
		<category><![CDATA[KEV]]></category>
		<guid isPermaLink="false">https://advisoryloom.com/almain/tycon-systems-tpdin-monitor-web3/</guid>

					<description><![CDATA[View CSAF Summary Successful exploitation of these vulnerabilities could allow for an attacker to perform a man-in-the-middle (MitM)]]></description>
										<content:encoded><![CDATA[<div>
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-246-08.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Successful exploitation of these vulnerabilities could allow for an attacker to perform a man-in-the-middle (MitM) attack, cause a factory reset, wipe credentials, or retrieve sensitive information.</strong></p>
<p>The following versions of Tycon Systems TPDIN-Monitor-WEB3 are affected:</p>
<ul>
<li>TPDIN-Monitor-WEB3 &lt;=2.2.9 (CVE-2026-77847, CVE-2026-82712, CVE-2026-82684)</li>
</ul>
<div class="csaf-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS</th>
<th role="columnheader">Vendor</th>
<th role="columnheader">Equipment</th>
<th role="columnheader">Vulnerabilities</th>
</tr>
</thead>
<tbody>
<tr>
<td>v3 8.8</td>
<td>Tycon Systems</td>
<td>Tycon Systems TPDIN-Monitor-WEB3</td>
<td>Use of Hard-coded Credentials, Cross-Site Request Forgery (CSRF), Missing Authorization</td>
</tr>
</tbody>
</table>
</div>
<h3>Background</h3>
<ul>
<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Energy</li>
<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>
<li><strong>Company Headquarters Location: </strong>United States</li>
</ul>
<hr>
<h2>Vulnerabilities</h2>
<div class="csaf-accordion">
<p><a class="csaf-accordion-toggle-all" href="https://www.cisa.gov/#">Expand All +</a></p>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-77847</a></h3>
<div class="csaf-accordion-content">
<p>Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Use of Hard-coded Credential vulnerability. This could allow an attacker to intercept sensitive information or credentials.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-77847">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Tycon Systems TPDIN-Monitor-WEB3</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br />Tycon Systems</div>
<div class="ics-version"><strong>Product Version:</strong><br />Tycon Systems TPDIN-Monitor-WEB3: &lt;=2.2.9</div>
<div class="ics-status"><strong>Product Status:</strong><br />known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br />Tycon Systems has released TPDIN-Monitor-WEB3 Firmware v2.4.2.</p>
<p><strong>Mitigation</strong><br />Units already running v2.4.2, for subsequent updates (signed container): <br /><a href="https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2.tfw">https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2.tfw</a></p>
<p><strong>Mitigation</strong><br />All units currently in the field, including the v2.2.9 covered by this report (legacy Intel HEX): <br /><a href="https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2T.hex">https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2T.hex</a></p>
<p><strong>Mitigation</strong><br />A unit running v2.2.9 installs the .hex build directly and arrives at v2.4.2 in a single step; no intermediate version is required. The signed .tfw container cannot be read by a v2.2.9 updater, which accepts only Intel HEX, so the .hex artifact is the one every deployed unit needs.</p>
<p><strong>Mitigation</strong><br />For more information, contact Tycon Systems: <br /><a href="https://www.tyconsystems.com/contact">https://www.tyconsystems.com/contact</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/798.html">CWE-798 Use of Hard-coded Credentials</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>
</tr>
<tr>
<td>4.0</td>
<td>7.1</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-82712</a></h3>
<div class="csaf-accordion-content">
<p>Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Cross-Site Request Forgery vulnerability. This could allow an attacker to perform state changing operations on the device.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-82712">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Tycon Systems TPDIN-Monitor-WEB3</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br />Tycon Systems</div>
<div class="ics-version"><strong>Product Version:</strong><br />Tycon Systems TPDIN-Monitor-WEB3: &lt;=2.2.9</div>
<div class="ics-status"><strong>Product Status:</strong><br />known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br />Tycon Systems has released TPDIN-Monitor-WEB3 Firmware v2.4.2.</p>
<p><strong>Mitigation</strong><br />Units already running v2.4.2, for subsequent updates (signed container): <br /><a href="https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2.tfw">https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2.tfw</a></p>
<p><strong>Mitigation</strong><br />All units currently in the field, including the v2.2.9 covered by this report (legacy Intel HEX): <br /><a href="https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2T.hex">https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2T.hex</a></p>
<p><strong>Mitigation</strong><br />A unit running v2.2.9 installs the .hex build directly and arrives at v2.4.2 in a single step; no intermediate version is required. The signed .tfw container cannot be read by a v2.2.9 updater, which accepts only Intel HEX, so the .hex artifact is the one every deployed unit needs.</p>
<p><strong>Mitigation</strong><br />For more information, contact Tycon Systems: <br /><a href="https://www.tyconsystems.com/contact">https://www.tyconsystems.com/contact</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/352.html">CWE-352 Cross-Site Request Forgery (CSRF)</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>
</tr>
<tr>
<td>4.0</td>
<td>8.6</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-82684</a></h3>
<div class="csaf-accordion-content">
<p>Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Missing Authorization vulnerability. This could allow an attacker to extract system credentials, configurations, or flash contents.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-82684">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Tycon Systems TPDIN-Monitor-WEB3</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br />Tycon Systems</div>
<div class="ics-version"><strong>Product Version:</strong><br />Tycon Systems TPDIN-Monitor-WEB3: &lt;=2.2.9</div>
<div class="ics-status"><strong>Product Status:</strong><br />known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br />Tycon Systems has released TPDIN-Monitor-WEB3 Firmware v2.4.2.</p>
<p><strong>Mitigation</strong><br />Units already running v2.4.2, for subsequent updates (signed container): <br /><a href="https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2.tfw">https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2.tfw</a></p>
<p><strong>Mitigation</strong><br />All units currently in the field, including the v2.2.9 covered by this report (legacy Intel HEX): <br /><a href="https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2T.hex">https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2T.hex</a></p>
<p><strong>Mitigation</strong><br />A unit running v2.2.9 installs the .hex build directly and arrives at v2.4.2 in a single step; no intermediate version is required. The signed .tfw container cannot be read by a v2.2.9 updater, which accepts only Intel HEX, so the .hex artifact is the one every deployed unit needs.</p>
<p><strong>Mitigation</strong><br />For more information, contact Tycon Systems: <br /><a href="https://www.tyconsystems.com/contact">https://www.tyconsystems.com/contact</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/862.html">CWE-862 Missing Authorization</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.1</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N</a></td>
</tr>
<tr>
<td>4.0</td>
<td>8.6</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<hr>
<h2>Acknowledgments</h2>
<ul>
<li>Abdiwelli Guled reported these vulnerabilities to CISA.</li>
</ul>
<hr>
<h2>Legal Notice and Terms of Use</h2>
<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>
<hr>
<h2>Recommended Practices</h2>
<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>
<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>
<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>
<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>
<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>
<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>
<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>
<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B&#8211;Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>
<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>
<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>
<p>Do not click web links or open attachments in unsolicited email messages.</p>
<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>
<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>
<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>
<hr>
<h2>Revision History</h2>
<ul>
<li><strong>Initial Release Date: </strong>2026-09-03</li>
</ul>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Date</th>
<th role="columnheader">Revision</th>
<th role="columnheader">Summary</th>
</tr>
</thead>
<tbody>
<tr>
<td>2026-09-03</td>
<td>1</td>
<td>Initial Publication</td>
</tr>
</tbody>
</table>
<hr>
<h2>Legal Notice and Terms of Use</h2>
</div>
]]></content:encoded>
					
					<wfw:commentRss>https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-08/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Pegasus Zero-Click Exploit Infects Serbian Student Activist&#8217;s iPhone</title>
		<link>https://www.infosecurity-magazine.com/news/pegasus-zero-click-exploit/</link>
		
		<dc:creator><![CDATA[Advisoryloom Editor]]></dc:creator>
		<pubDate>Thu, 03 Sep 2026 16:03:25 +0000</pubDate>
				<category><![CDATA[Cyber News]]></category>
		<category><![CDATA[Alerts]]></category>
		<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://advisoryloom.com/almain/pegasus-zero-click-exploit-infects-serbian-student-activists-iphone/</guid>

					<description><![CDATA[Pegasus infected a Serbian student activist&#8217;s iPhone through an iMessage zero-click exploit]]></description>
										<content:encoded><![CDATA[<div>Pegasus infected a Serbian student activist&#8217;s iPhone through an iMessage zero-click exploit</div>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
