Skip to content

Cybersecurity PSA

Top Attack
ALERTVerified Cybersecurity PSA briefing
September 3, 2026·Top Attack·2 min read

Pyramid Solutions NetStaX EtherNet/IP Stack

TL;DR

View CSAF Summary Successful exploitation of this vulnerability could result in memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed. The following versions of…

What happened View CSAF Summary Successful exploitation of this vulnerability could result in memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the…

Voice options

Voice names come from your browser and device.

Open article → CISA Cybersecurity Advisories & Alerts ↗

What happened

View CSAF Summary Successful exploitation of this vulnerability could result in memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed.

The following versions of Pyramid Solutions NetStaX EtherNet/IP Stack are affected: EtherNet/IP Adapter DLL Kit (EIPA) EtherNet/IP Adapter DLL Kit with CIP Security (EIPA-SECURE) EtherNet/IP Adapter Development Kit (EADK) EtherNet/IP Adapter Development Kit with CIP Security (EADK-SECURE) EtherNet/IP…

What is verified

The result could be memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed.

View CVE Details Affected Products Pyramid Solutions NetStaX EtherNet/IP Stack Vendor: Pyramid Solutions Product Version: Pyramid Solutions EtherNet/IP Adapter DLL Kit (EIPA):

Why it matters

A security flaw matters when an attacker can use it to cross a trust boundary, gain access, run code, bypass authentication, or expose data. The exact risk depends on the affected product, vulnerable versions, exploit conditions, and whether exploitation has been observed. Those details should come from the cited source rather than assumption.

What you should do

Check the vendor or authoritative advisory for affected versions and remediation. Apply the recommended update or mitigation, restart devices or services when required, and prioritize internet-facing or privileged systems. If the source does not report active exploitation, do not treat exploitation as confirmed.

Impersonating IT support: how threat actors turn a remote session into enterprise-wide access Top Attack
ALERTVerified Cybersecurity PSA briefing
September 3, 2026·Top Attack·2 min read

Impersonating IT support: how threat actors turn a remote session into enterprise-wide access

TL;DR

In this article Risk to enterprise environments Attack chain overview Mitigation and response recommendations Learn more Microsoft Threat Intelligence has observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT or helpdesk personnel and socially engineer users into…

What happened Once remote control is established via RMM tools, the threat actor uses PowerShell to download and silently install a malicious MSI package, which in turn stages a portable Node.js runtime and an obfuscated…

Voice options

Voice names come from your browser and device.

Open article → Microsoft Security Blog ↗

What happened

Once remote control is established via RMM tools, the threat actor uses PowerShell to download and silently install a malicious MSI package, which in turn stages a portable Node.js runtime and an obfuscated JavaScript implant that provides persistent…

Unlike commodity phishing that ends with an infostealer, this campaign follows a full hands-on-keyboard playbook.

What is verified

After the implant is deployed, the threat actor performs extensive host and Active Directory reconnaissance, periodically captures screenshots of the victim’s desktop, executes follow-on payloads through trusted Windows binaries, and pivots across the enterprise over Windows Remote Management…

The intrusion relies heavily on legitimate tooling, including Microsoft Teams, remote support software, Windows Installer, Node.js, and native administrative protocols, allowing the activity to blend into expected enterprise operations at nearly every stage.

The reconnaissance and lateral movement patterns observed: domain enumeration, server discovery, and WinRM pivoting toward identity systems, are consistent with intrusion activity that can precede data theft, extortion, ransomware deployment, or other follow-on objectives, in which threat actors…

Why it matters

The practical risk is that convincing impersonation and social-engineering tactics can turn a single message, login prompt, or support interaction into account takeover or financial fraud. Consumers should treat urgency, requests for credentials, and unexpected payment instructions as signals to verify independently.

What you should do

Verify unusual requests through a trusted channel you initiate yourself. Do not use phone numbers or links supplied in a suspicious message. Use multifactor authentication where available, avoid password reuse, and review account activity after any interaction that may have exposed credentials or payment information.

Chrome Beta for Desktop Update Top Attack
ALERTVerified Cybersecurity PSA briefing
September 2, 2026·Top Attack·1 min read

Chrome Beta for Desktop Update

TL;DR

The Chrome team is excited to announce the promotion of Chrome 154 to the Beta channel for Windows, Mac and Linux. Chrome 154.0.8037.0 contains our usual under-the-hood performance and stability tweaks, but there are also some cool new features to explore -…

What happened The Chrome team is excited to announce the promotion of Chrome 154 to the Beta channel for Windows, Mac and Linux. Interested in switching release channels? What is verified The community help forum…

Voice options

Voice names come from your browser and device.

Open article → Google Chrome Releases ↗

What happened

The Chrome team is excited to announce the promotion of Chrome 154 to the Beta channel for Windows, Mac and Linux.

Interested in switching release channels?

What is verified

The community help forum is also a great place to reach out for help or learn about common issues.

Chrome Release Team Google Chrome

Why it matters

Software updates can contain security, stability, and compatibility fixes, but the value of an update depends on what the vendor actually changed. Consumers and administrators should distinguish a routine release from a confirmed security emergency unless the source explicitly says exploitation or urgent remediation is involved.

What you should do

Use the vendor-supported update channel, install the applicable stable update, and restart the device or application when the update requires it. Organizations should test changes that affect managed fleets or production systems. Beta or preview channels should generally remain limited to systems intentionally used for testing.

Top Attack
ALERTVerified Cybersecurity PSA briefing
September 2, 2026·Top Attack·1 min read

CISA Adds Seven Known Exploited Vulnerabilities to Catalog

TL;DR

CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-9586 Sangoma Switchvox SQL Injection Vulnerability CVE-2026-48710 Kludex Starlette HTTP Request/Response Smuggling Vulnerability CVE-2026-49869 Kestra OSS OS Command Injection Vulnerability CVE-2026-59822 BerriAI LiteLLM…

What happened CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to…

Voice options

Voice names come from your browser and device.

Open article → CISA Cybersecurity Advisories & Alerts ↗

What happened

CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.

BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets…

What is verified

While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities.

CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.

Aware of an exploited vulnerability not currently listed in the KEV Catalog?

Why it matters

A confirmed cyber incident can create secondary risk long after the initial intrusion. Stolen account data, contact information, or business records may be reused for phishing, credential attacks, identity fraud, or targeted social engineering. The source-backed facts above describe the incident; the downstream risk depends on what information was actually exposed.

What you should do

If you are notified that your information or account was affected, follow the organization’s incident instructions first. Change reused passwords, enable multifactor authentication, watch for targeted phishing, review security alerts and account sessions, and monitor financial or identity activity when sensitive personal information may have been involved.

Counterfeit installers to system compromise: Tracking a deceptive software download campaign Top Attack
ALERTVerified Cybersecurity PSA briefing
September 2, 2026·Top Attack·1 min read

Counterfeit installers to system compromise: Tracking a deceptive software download campaign

TL;DR

In this article Attack chain overview Campaign scope and targeting Mitigation and protection guidance References Learn more Microsoft Defender Experts is tracking an active malware campaign that uses counterfeit software-download websites to impersonate trusted vendors and distribute malicious installers. The campaign has…

What happened The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users. Microsoft has observed…

Voice options

Voice names come from your browser and device.

Open article → Microsoft Security Blog ↗

What happened

The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users.

Microsoft has observed victims across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors.

What is verified

Microsoft assesses with moderate confidence that this activity is consistent with the publicly reported Silver Fox (also known as Yinhu, 银狐) fake software campaign but has not attributed it to a nation-state actor.

Organizations should prioritize preventing downloads from untrusted software sources and ensure protections such as SmartScreen, network protection, tamper protection, and Microsoft Defender XDR are enabled to help identify, block, and respond to related activity.

Campaign scope and targeting Microsoft observed affected devices predominantly associated…

Why it matters

The practical risk is that convincing impersonation and social-engineering tactics can turn a single message, login prompt, or support interaction into account takeover or financial fraud. Consumers should treat urgency, requests for credentials, and unexpected payment instructions as signals to verify independently.

What you should do

Verify unusual requests through a trusted channel you initiate yourself. Do not use phone numbers or links supplied in a suspicious message. Use multifactor authentication where available, avoid password reuse, and review account activity after any interaction that may have exposed credentials or payment information.

FBI Probes Service Selling 153M+ Drivers Licenses Top Attack
ALERTVerified Cybersecurity PSA briefing
September 1, 2026·Top Attack·2 min read

FBI Probes Service Selling 153M+ Drivers Licenses

TL;DR

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase…

What happened A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on…

Voice options

Voice names come from your browser and device.

Open article → KrebsOnSecurity ↗

What happened

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada.

Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana.

What is verified

government officials whose drivers licenses can be found for sale.

The source brought it to my attention because the proprietor of this identity theft service offered my Virginia drivers license as a free sample in their initial sales thread on Exploit.

The service, dubbed Nexus, claims to have more than 153 million drivers licenses for people in the United States and Canada, as well as more than 10 million identification cards; more than three million travel documents and/or international…

Why it matters

A security flaw matters when an attacker can use it to cross a trust boundary, gain access, run code, bypass authentication, or expose data. The exact risk depends on the affected product, vulnerable versions, exploit conditions, and whether exploitation has been observed. Those details should come from the cited source rather than assumption.

What you should do

Check the vendor or authoritative advisory for affected versions and remediation. Apply the recommended update or mitigation, restart devices or services when required, and prioritize internet-facing or privileged systems. If the source does not report active exploitation, do not treat exploitation as confirmed.

Top Attack
ALERTVerified Cybersecurity PSA briefing
September 1, 2026·Top Attack·1 min read

Cybersecurity IR Workshop: The workshop you shouldn’t miss

TL;DR

In this article What is the Cybersecurity Incident Response Readiness Workshop? Our approach: How we assess your maturity Learn more Cybersecurity incidents can unfold in hours, but response plans often fail at the point of execution: ownership is unclear, investigation findings is…

What happened In this article What is the Cybersecurity Incident Response Readiness Workshop? That is why incident response cannot be something your organization figures out in real time. What is verified The Detection and Response…

Voice options

Voice names come from your browser and device.

Open article → Microsoft Security Blog ↗

What happened

In this article What is the Cybersecurity Incident Response Readiness Workshop?

That is why incident response cannot be something your organization figures out in real time.

What is verified

The Detection and Response Team (DART) – the Microsoft team that delivers Defender Experts Cybersecurity Incident Response – has supported organizations across 54 countries and regions through some of their most challenging security moments; and while we sincerely…

That’s exactly what the Cybersecurity Incident Response Readiness Workshop is designed to do.

The Cybersecurity Incident Response Workshop is a collaborative, scenario driven workshop designed to evaluate your organization’s incident response (IR) plan against realistic, real-world security events, guided by DART researchers.

Why it matters

The security significance comes from the verified facts in the source: what changed, who or what is affected, and what consequence is actually supported. Cybersecurity PSA does not treat speculation, marketing language, or an unverified claim as evidence of compromise or exploitation.

What you should do

Use the original source and vendor or government guidance for product-specific actions. Keep software supported and updated, use multifactor authentication, avoid password reuse, and treat unexpected security messages or account changes as a reason to verify activity directly.

Top Attack
ALERTVerified Cybersecurity PSA briefing
September 1, 2026·Top Attack·2 min read

Rockwell Automation Historian ME

TL;DR

View CSAF Summary Successful exploitation of these vulnerabilities could crash the device being accessed; an out-of-bounds write condition may allow remote code execution. The following versions of Rockwell Automation Historian ME are affected: Series B 5.202 (CVE-2025-12768, CVE-2026-12661) Series C 7.101 (CVE-2025-12768,…

What happened The following versions of Rockwell Automation Historian ME are affected: Series B 5.202 (CVE-2025-12768, CVE-2026-12661) Series C 7.101 (CVE-2025-12768, CVE-2026-12661) CVSS Vendor Equipment Vulnerabilities v3 8 Rockwell Automation Rockwell Automation Historian ME Out-of-bounds…

Voice options

Voice names come from your browser and device.

Open article → CISA Cybersecurity Advisories & Alerts ↗

What happened

The following versions of Rockwell Automation Historian ME are affected: Series B 5.202 (CVE-2025-12768, CVE-2026-12661) Series C 7.101 (CVE-2025-12768, CVE-2026-12661) CVSS Vendor Equipment Vulnerabilities v3 8 Rockwell Automation Rockwell Automation Historian ME Out-of-bounds Write, Stack-based Buffer Overflow Background…

An attacker with low-level authentication could exploit this vulnerability to achieveremote code execution on the affected device.

What is verified

View CVE Details Affected Products Rockwell Automation Historian ME Vendor: Rockwell Automation Product Version: Rockwell Automation Series B: 5.202, Rockwell Automation Series C: 7.101 Product Status: known_affected Remediations Mitigation Customers using the affected software, who are not able…

More information can be found at https://www.rockwellautomation.com/en-us/company/about-us/contact-us.html.

https://www.rockwellautomation.com/en-us/company/about-us/contact-us.html Mitigation If you have any questions regarding this disclosure, please contact PSIRT Email: [email protected] mailto:[email protected] Relevant CWE: CWE-787 Out-of-bounds Write Metrics CVSS Version Base Score Base Severity Vector String 3.1 8 HIGH CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 4.0 8.6 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N…

Why it matters

A security flaw matters when an attacker can use it to cross a trust boundary, gain access, run code, bypass authentication, or expose data. The exact risk depends on the affected product, vulnerable versions, exploit conditions, and whether exploitation has been observed. Those details should come from the cited source rather than assumption.

What you should do

Check the vendor or authoritative advisory for affected versions and remediation. Apply the recommended update or mitigation, restart devices or services when required, and prioritize internet-facing or privileged systems. If the source does not report active exploitation, do not treat exploitation as confirmed.

Create a high-quality editorial cybersecurity illustration in a dramatic split-screen composition showing “a tale of two security operations centers.” On the left, a dim, chaotic SOC overwhelmed by dense alert streams, red warning lights, unattended dashboards, and a subtle shadowy intrusion spreading from enterprise servers toward cloud systems and operational technology; analysts appear distracted by false positives and unable to contain the breach. On the right, a calm, well-organized SOC with focused defenders rapidly isolating compromised endpoints, segmented network zones, secured cloud infrastructure, and protected industrial control systems, while a contained red intrusion is stopped at the perimeter. Visually contrast disorder and delayed detection with disciplined monitoring, incident response, network segmentation, multifactor authentication, and resilience. Realistic cinematic lighting, sophisticated blue-and-red color palette, modern critical-infrastructure setting, subtle sense of urgency, professional magazine feature aesthetic, no readable text, no logos, no branding, no gore. Top Attack
ALERTVerified Cybersecurity PSA briefing
August 31, 2026·Top Attack·2 min read

A Tale of Two SOCs: Insights From Two Red Team Assessments

TL;DR

Advisory at a Glance Title A Tale of Two SOCs: Insights From Two Red Team Assessments Original Publication August 25, 2026 Executive Summary The Cybersecurity and Infrastructure Security Agency (CISA) conducted simultaneous red team assessments at two organizations and observed different defensive…

What happened Advisory at a Glance Title A Tale of Two SOCs: Insights From Two Red Team Assessments Original Publication August 25, 2026 Executive Summary The Cybersecurity and Infrastructure Security Agency (CISA) conducted simultaneous red…

Voice options

Voice names come from your browser and device.

Open article → CISA Cybersecurity Advisories & Alerts ↗
Create a high-quality editorial cybersecurity illustration in a dramatic split-screen composition showing “a tale of two security operations centers.” On the left, a dim, chaotic SOC overwhelmed by dense alert streams, red warning lights, unattended dashboards, and a subtle shadowy intrusion spreading from enterprise servers toward cloud systems and operational technology; analysts appear distracted by false positives and unable to contain the breach. On the right, a calm, well-organized SOC with focused defenders rapidly isolating compromised endpoints, segmented network zones, secured cloud infrastructure, and protected industrial control systems, while a contained red intrusion is stopped at the perimeter. Visually contrast disorder and delayed detection with disciplined monitoring, incident response, network segmentation, multifactor authentication, and resilience. Realistic cinematic lighting, sophisticated blue-and-red color palette, modern critical-infrastructure setting, subtle sense of urgency, professional magazine feature aesthetic, no readable text, no logos, no branding, no gore.

What happened

Advisory at a Glance Title A Tale of Two SOCs: Insights From Two Red Team Assessments Original Publication August 25, 2026 Executive Summary The Cybersecurity and Infrastructure Security Agency (CISA) conducted simultaneous red team assessments at two organizations…

In both environments, the red team achieved full domain compromise and accessed sensitive business systems (SBSs) and cloud resources.

What is verified

Organization A failed to detect or contain the activity, but Organization B rapidly identified initial compromise attempts, isolated affected systems, and forced the red team into an assume breach model.

This advisory details the red team’s activity and organizations’ defensive actions, offering lessons learned and mitigations to help critical infrastructure organizations strengthen detection, response, and protections in IT, cloud, and operational technology (OT) environments.

Without well-defined baselines and alert filtering, false positives and routine alerts overwhelm network defenders.

Why it matters

A confirmed cyber incident can create secondary risk long after the initial intrusion. Stolen account data, contact information, or business records may be reused for phishing, credential attacks, identity fraud, or targeted social engineering. The source-backed facts above describe the incident; the downstream risk depends on what information was actually exposed.

What you should do

If you are notified that your information or account was affected, follow the organization’s incident instructions first. Change reused passwords, enable multifactor authentication, watch for targeted phishing, review security alerts and account sessions, and monitor financial or identity activity when sensitive personal information may have been involved.

Top Attack
ALERTVerified Cybersecurity PSA briefing
August 31, 2026·Top Attack·1 min read

CISA Adds Two Known Exploited Vulnerabilities to Catalog

TL;DR

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-81578 PaperCut NG/MF Missing Authentication for Critical Function Vulnerability CVE-2026-82078 PaperCut NG/MF Unsafe Reflection Vulnerability These types of vulnerabilities are a frequent attack…

What happened CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to…

Voice options

Voice names come from your browser and device.

Open article → CISA Cybersecurity Advisories & Alerts ↗

What happened

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.

BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets…

What is verified

While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities.

CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.

Aware of an exploited vulnerability not currently listed in the KEV Catalog?

Why it matters

A confirmed cyber incident can create secondary risk long after the initial intrusion. Stolen account data, contact information, or business records may be reused for phishing, credential attacks, identity fraud, or targeted social engineering. The source-backed facts above describe the incident; the downstream risk depends on what information was actually exposed.

What you should do

If you are notified that your information or account was affected, follow the organization’s incident instructions first. Change reused passwords, enable multifactor authentication, watch for targeted phishing, review security alerts and account sessions, and monitor financial or identity activity when sensitive personal information may have been involved.