Výsledky hledání

sektor: doprava× v celém archivu zrušit filtry

35 karet z 35 položek CZ · EN/orig

1

Rockwell Automation 1756-ENBT Module

View CSAF Summary Successful exploitation of this vulnerability could crash the module. The device requires a restart to recover. The following versions of Rockwell Automation 1756-ENBT Module are affected: 1756-ENBT module vers:all/* (CVE-2025-10478) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation 1756-ENBT Module Improper Check for Unusual or Exceptional Conditions Background Critical Infrastructure Sectors: Critical Manufacturing, Food and Agriculture,…

CVSS 7.5 CVE-2025-10478 Rockwell Automation výroba a průmysl vodárenství doprava US

tg: zranitelnost tp: průmyslové systémy

CISA Advisories ·

3

Rockwell Automation Redundancy Module Configuration Tool

View CSAF Summary Successful exploitation of these vulnerabilities could allow for an attacker to escalate and execute processes with administrator privileges. The following versions of Rockwell Automation Redundancy Module Configuration Tool are affected: Redundancy Module Configuration Tool 10.00.00 (CVE-2026-9633) Redundancy Module Configuration Tool >=9.00.00|<=10.00.00 (CVE-2026-9634) CVSS Vendor Equipment Vulnerabilities v3 7.3 Rockwell Automation Rockwell Automation Redundancy Module…

CVSS 7.3 CVE-2026-9633 CVE-2026-9634 Rockwell Automation výroba a průmysl energetika vodárenství doprava US

tg: zranitelnost tp: průmyslové systémy

CISA Advisories ·

Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set

While monitoring Mirage Kitten activity, we uncovered a previously undocumented malware family that we dubbed NodeRabbit. We identified the first sample on a system in Afghanistan. Further threat hunting revealed two additional, more advanced, variants: one on a system in Egypt and another on a system in Ethiopia. NodeRabbit is a cross-platform remote access trojan (RAT) built with Node.js. It targets Windows, Linux, and macOS. Its operators deliver it through spear-phishing messages on…

Kaspersky finance doprava RU

tg: varování tg: rozbor tp: malware tp: phishing tp: špionáž

Securelist (Kaspersky) ·

1

31th August – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 31st August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Manchester Airports Group, the UK operator of Manchester, London Stansted, and East Midlands airports, has disclosed a cyberattack that exposed data belonging to about 8.7 million customers. The compromised information includes contact details, vehicle registration numbers, and information collected through car park, lounge, fast-track, and Wi-Fi…

KEV ✓ CVSS 10.0 CVE-2026-18885 CVE-2026-18886 CVE-2026-74820 CVE-2026-75604 CVE-2026-81578 CVE-2026-82078 Check Point PaperCut Ubiquiti Vercel veřejná správa zdravotnictví doprava IL

tg: incident tg: zneužíváno tg: zranitelnost tg: přehled tp: malware tp: phishing tp: ransomware tp: únik dat tp: AI tp: špionáž tp: průmyslové systémy

Check Point Research ·

1

1

4

Rockwell Automation OTTO Fleet Manager

View CSAF Summary Successful exploitation of this vulnerability could reduce the computational cost required for an attacker to perform offline brute-force attacks against stored password hashes. The following versions of Rockwell Automation OTTO Fleet Manager are affected: OTTO Fleet Manager <=V2.36.2 (CVE-2026-75112) CVSS Vendor Equipment Vulnerabilities v3 6.8 Rockwell Automation Rockwell Automation OTTO Fleet Manager Use of Password Hash With Insufficient Computational Effort Background…

EPSS 0.00 CVSS 6.8 CVE-2026-75112 Rockwell Automation výroba a průmysl doprava US

CISA Advisories ·

All-Line Equipment Company Fuel-Boss

View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to execute arbitrary commands or code remotely on affected systems. The following versions of All-Line Equipment Company Fuel-Boss are affected: Fuel-Boss V1 Standard >=|<=PHP_7.1.5_7.1.5 (CVE-2018-19518, CVE-2019-11043) Fuel-Boss V1 Portal >=|<=PHP_7.1.5_7.1.5 (CVE-2018-19518, CVE-2019-11043) Fuel-Boss V1 Master/Slave >=|<=PHP_7.1.5_7.1.5 (CVE-2018-19518, CVE-2019-11043) Fuel-Boss V1 Backflush Systems >=|<…

KEV ✓ EPSS 1.00 CVSS 8.7 CVE-2018-19518 CVE-2019-11043 All-Line Equipment Company výroba a průmysl obrana doprava US

CISA Advisories ·

1

3

Bendix EC80 Brake ECU

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause the loss of ABS functions, steering assist, speedometer, shifting capabilities, or disable automatic traction control. The following versions of Bendix EC80 Brake ECU are affected: EC80ESP+ J1708 Z228999 EC80ESP+ 6S/6M Z228999 EC80ESP+ PLC Z228999 EC80ESP+ 2nd CAN Z228999 EC80ESP+ Integrated TPMS Z228999 EC80ESP 6S/6M Z266494 EC80ESP PLC Z266494 EC80ESP 2nd CAN Z266494 EC80ESP CAN Gateway Z266494…

EPSS 0.00 CVSS 7.5 CVE-2026-67560 CVE-2026-68967 CVE-2026-71396 Bendix doprava US

CISA Advisories ·

FURUNO FA-50 Class B AIS Transponder

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to alter device settings. The following versions of FURUNO FA-50 Class B AIS Transponder are affected: FURUNO FA-50 Class B AIS Transponder vers:all/* CVSS Vendor Equipment Vulnerabilities v3 9.1 FURUNO ELECTRIC CO.,LTD. FURUNO FA-50 Class B AIS Transponder Use of Hard-coded Credentials, Missing Authentication for Critical Function Background Critical Infrastructure Sectors: Transportation Systems…

EPSS 0.00 CVSS 9.1 CVE-2026-59769 CVE-2026-67578 FURUNO doprava US

CISA Advisories ·

Siemens SIMATIC IoT2050 Advanced

View CSAF Summary SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed contain a missing authentication vulnerability in the Node-RED HTTP interface that could allow an unauthenticated remote attacker to create malicious flows and execute arbitrary code on the underlying server with maximum privileges. Siemens has released a new version for SIMATIC IoT2050 Advanced and strongly recommends to update to the latest version. The following versions of Siemens SIMATIC…

EPSS 0.01 CVSS 10.0 CVE-2026-58115 Siemens energetika výroba a průmysl doprava US

CISA Advisories ·

2

The invisible passenger in your car

While monitoring Android threats in June 2026, we discovered a new piece of Android malware. What struck us as unusual was that it installed like an ordinary user app yet made no attempt to disguise itself as legitimate software: it had no user interface at all. This led us to suspect the app might be reaching users’ devices without their knowledge. Further investigation confirmed that hypothesis and allowed us to reconstruct the entire infection chain. Key findings: We identified new Android…

Kaspersky DoFun doprava RU

Securelist (Kaspersky) ·

CISA Releases One Industrial Control Systems Advisory

Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 5.3, CVEs: CVE-2026-27875, Summary: CISA released one Industrial Control Systems (ICS) Advisory. This advisory provides timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-26-232-01 Johnson Controls Simplex Incident Manager

EPSS 0.00 CVSS 5.8 CVE-2026-27875 Johnson Controls výroba a průmysl energetika doprava veřejná správa FI US 2 zdrojů

NCSC-FI · CISA Advisories

1

1

1

Varovanie pred rizikami cestných meradiel

Národný bezpečnostný úrad varuje pred významnou kybernetickou hrozbou spojenou s používaním viacerých typov cestných rýchlomerov s kamerou. Bezpečnostná analýza identifikovala viaceré riziká a dotknutým subjektom odporúča predmetné produkty vo svojej infraštruktúre identifikovať. Národný bezpečnostný úrad podľa § 5 ods. 1 písm. q) v spojení s § 27 ods. 1 písm. a) a ods. 2 zákona... The post Varovanie pred rizikami cestných meradiel appeared first on SK-CERT.

doprava veřejná správa SK

SK-CERT (NBÚ SR) ·

4

Siemens LOGO! Soft Comfort

View CSAF Summary Siemens LOGO! Soft Comfort contains multiple vulnerabilities in its project-file encryption and password handling mechanisms. A local attacker could exploit these vulnerabilities to extract the master key, allowing them to decrypt project data or remove project passwords. The lack of password salting enables offline dictionary or brute-force attacks against the password hashes. Successful exploitation could result in unauthorized access to, or modification of, sensitive…

EPSS 0.00 CVSS 6.8 CVE-2026-57262 CVE-2026-57263 Siemens výroba a průmysl doprava US

CISA Advisories ·

Johnson Controls Metasys

View CSAF Summary Successful exploitation of this vulnerability could allow a low-privilege user or attacker to inject a persistent malicious payload via a crafted URL that executes in the context of other users' sessions, including administrators, potentially leading to session hijacking and unauthorized access. The following versions of Johnson Controls Metasys are affected: Metasys 12 vers:all/* (CVE-2026-34491) Metasys 13 vers:all/* (CVE-2026-34491) Metasys 14 Metasys 15 CVSS Vendor…

EPSS 0.00 CVSS 8.0 CVE-2026-34491 Johnson Controls energetika výroba a průmysl veřejná správa doprava US

CISA Advisories ·

Johnson Controls Inc. Airwall

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to decrypt sensitive data, bypass authentication controls, gaining unauthorized access to read arbitrary files on the system, or gain unauthorized access to protected system resources. The following versions of Johnson Controls Inc. Airwall are affected: Airwall <=4.0.4 (CVE-2026-64887, CVE-2026-34492) CVSS Vendor Equipment Vulnerabilities v3 6.8 Johnson Controls Inc. Johnson Controls Inc. Airwall Use of…

EPSS 0.00 CVSS 6.8 CVE-2026-34492 CVE-2026-64887 Johnson Controls výroba a průmysl veřejná správa energetika doprava US

CISA Advisories ·

Siemens Desigo DXR and PXC Controllers

View CSAF Summary A vulnerability in Desigo DXR and PXC controllers has been identified that could allow an attacker to cause denial of service conditions by sending malformed BACnet packets. Recovery requires a device reset or reboot to restore normal functionality. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Desigo DXR and PXC Controllers are affected: Desigo DXR2 vers:intdot/<01.21.233.16-7862 …

EPSS 0.00 CVSS 4.3 CVE-2026-59693 Siemens energetika zdravotnictví výroba a průmysl doprava US

CISA Advisories ·

1

Siemens RUGGEDCOM APE1808

View CSAF Summary Fortinet has published information on vulnerabilities in FortiOS. This advisory lists the related Siemens Industrial products. Siemens recommends to contact customer support for additional information, and follow Fortinet advisory for workarounds and mitigation measures. The following versions of Siemens RUGGEDCOM APE1808 are affected: RUGGEDCOM APE1808 vers:all/* (CVE-2026-23573, CVE-2026-59839) CVSS Vendor Equipment Vulnerabilities v3 6.1 Siemens Siemens RUGGEDCOM APE1808…

EPSS 0.00 CVSS 6.1 CVE-2026-23573 CVE-2026-59839 Siemens Fortinet výroba a průmysl energetika doprava US

CISA Advisories ·

1

Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants

Overview of the attack In July 2026, Kaspersky experts detected a new attack by the Head Mare group. Previously, we classified them as hacktivists, but now we define them as an APT group due to the sophistication of their TTPs and the absence of destructive activity (encryption, wiping) in the targeted infrastructures. In this latest campaign, the attackers exploited a chain of vulnerabilities in the TrueConf video conferencing server and replaced the original TrueConf client installers with…

TrueConf Kaspersky Microsoft energetika výroba a průmysl doprava telekomunikace RU

Securelist (Kaspersky) ·

1

DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

In this article Pre-encryptionEncryptionPost-encryptionDefending against DeadLock ransomwareIndicators of compromise Microsoft Threat Intelligence tracks DeadLock ransomware as an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications and data leak operations. Its recovery ecosystem combines the Session messaging network with blockchain-backed services that store and deliver resources used throughout the extortion…

Microsoft doprava výroba a průmysl energetika US

Microsoft Security Blog ·

1

CPDLC over ATN-B1 Vulnerabilities

View CSAF Summary ATN-B1 CPDLC relies on legacy clear text unauthenticated radio frequency links. Research demonstrates that these characteristics allow unauthorized message injection, denial-of-service conditions, and forced session resets. These vulnerabilities do not constitute an unsafe aircraft condition but can degrade operational safety margins by increasing workload, delaying safety-critical instructions, and reducing situational awareness. The following versions of CPDLC over ATN-B1…

EPSS 0.00 CVSS 7.1 CVE-2025-71409 CVE-2025-71410 CVE-2025-71411 CVE-2025-71412 CVE-2025-71413 doprava US

CISA Advisories ·

1

Johnson Controls Inc. TL280

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to access sensitive information on the device. The following versions of Johnson Controls Inc. TL280 are affected: TL280 <5.63 (CVE-2026-27871) CVSS Vendor Equipment Vulnerabilities v3 4.1 Johnson Controls Inc. Johnson Controls Inc. TL280 Use of a Broken or Risky Cryptographic Algorithm Background Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and…

EPSS 0.00 CVSS 4.1 CVE-2026-27871 Johnson Controls energetika výroba a průmysl veřejná správa doprava US

CISA Advisories ·

1

Acrisure KARR BT and DR-100

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to perform unauthorized vehicle control operations. The following versions of Acrisure KARR BT and DR-100 are affected: KARR BT firmware <July_20_2026 DR-100 firmware <July_20_2026 CVSS Vendor Equipment Vulnerabilities v3 8.1 Acrisure Acrisure KARR BT and DR-100 Use of Hard-coded Cryptographic Key Background Critical Infrastructure Sectors: Transportation Systems Countries/Areas Deployed: Worldwide Company…

EPSS 0.00 CVSS 8.1 CVE-2026-18411 Acrisure doprava US

CISA Advisories ·

1

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

In this article The CaptiveCrunch campaignStorm-2945 and Midnight BlizzardCaptiveCrunch tradecraft and toolingHow to protect against CaptiveCrunch activityMicrosoft Defender detections and hunting guidanceIndicators of compromise Since early May 2026, Microsoft Threat Intelligence has observed Storm-2945, a sub-cluster of Midnight Blizzard, conducting widespread but targeted traffic manipulation attacks involving hospitality sector networks served by captive portals worldwide. Despite some…

Microsoft telekomunikace obchod doprava US

Microsoft Security Blog ·

1

Canada’s Bill C-8 is here: Why the 72-hour reporting rule will redefine critical infrastructure security

Canada’s new Critical Cyber Systems Protection Act (Bill C-8) introduces a strict 72-hour cyber incident reporting mandate. Find out how Tenable is helping critical national infrastructure operators bridge the IT/OT divide to ensure full compliance.Key takeaways:Bill C-8 introduces stringent new cyber incident reporting requirements and heavy financial penalties for critical infrastructure operators. Eliminating network blind spots with a hybrid IT/OT discovery approach, including Safe Active…

Tenable veřejná správa energetika telekomunikace doprava US

Tenable Research ·

1

27th July – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 27th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Nichirei, a Japan-based frozen-food supplier and logistics company, has experienced a ransomware attack that disrupted shipping operations and affected approximately 5,000 customers. KFC Japan warned of possible shortages. Nichirei confirmed personal data theft, while the RansomHouse group claimed responsibility and published a subset of the stolen…

KEV ✓ EPSS 0.85 CVE-2025-66376 CVE-2026-16232 CVE-2026-50522 Check Point Oracle Microsoft OpenAI energetika vodárenství veřejná správa doprava IL

Check Point Research ·

1

Cisco Catalyst SD-WAN Controller, Catalyst SD-WAN Manager, and Catalyst SD-WAN Validator Authenticated Privilege Escalation Vulnerability

A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by uploading a crafted file to the…

KEV ✓ EPSS 0.92 CVE-2026-20127 CVE-2026-20182 CVE-2026-20245 Cisco telekomunikace energetika doprava finance obchod zdravotnictví US 2 zdrojů

Cisco PSIRT · Mandiant / Google TI

1

JSAC2026 -Day 2-

Continuing from the previous report, this second installment introduces the presentations delivered during the Day 2 Main Track. Following the Trace: Reconstructing Attacks from Ext4 and XFS Journals Speaker: Minoru Kobayashi, Internet Initiative Japan Inc. Presentation Materials (English) Minoru Kobayashi presented an approach for inferring file operations and reconstructing them as a timeline based on the journal structures and analysis methods of the ext4 and XFS file systems. Through a…

Internet Initiative Japan Inc. NTT DOCOMO BUSINESS, Inc. Recruit Co., Ltd. finance veřejná správa doprava JP

JPCERT/CC – blog ·