ABB Ability Zenon
Successful exploitation of these vulnerabilities could allow attackers to bypass security, crash systems, execute unauthorized actions, or compromise data. The following versions of ABB Ability Zenon are affected: IIo...
Active vulnerabilities, advisories, and threat intelligence — filtered for IT practitioners.
Successful exploitation of these vulnerabilities could allow attackers to bypass security, crash systems, execute unauthorized actions, or compromise data. The following versions of ABB Ability Zenon are affected: IIo...
Successful exploitation of this vulnerability could allow an attacker with access to the same network segment to tamper with communication data in the affected product by sending specially crafted packets under specif...
Successful exploitation of these vulnerabilities could allow an attacker to disclose sensitive information, cause a denial of service, or potentially execute arbitrary code. The following versions of o6 Automation ope...
Microsoft patched a zero-day in the Windows Common Log File System driver that ransomware operators Storm-0506 and RansomEXX actively exploited to escalate from standard user to SYSTEM before deploying payloads.
A zero-click NTLM hash leak via .library-ms files is being actively exploited in phishing campaigns targeting government and private sector organizations in Poland and Romania.
CISA added six actively exploited vulnerabilities to its KEV catalog this week, including flaws in Microsoft Windows, Cisco, and SAP products, requiring federal agencies to patch within 21 days.
A Windows Management Console security feature bypass was exploited by the Russian-linked Water Gamayun group to execute malicious .msc files, bypassing Windows file reputation and MotW protections.
Microsoft's January 2025 Patch Tuesday addressed 159 vulnerabilities including 8 zero-days (3 exploited in the wild) and critical RCE flaws in Windows OLE, LDAP, and Hyper-V.