CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2026-33825 Microsoft Defender Insufficient Granularity of Access Control Vulnerability
This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.
Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
This product is provided subject to this Notification and this Privacy & Use policy.
Apr 23, 2026 · via cisa.gov
byPriyanka Neelakrishnan@hackerclup7sajo00003b6s2naft6zw
Author: Priyanka Neelakrishnan, B.E., M.S., M.B.A. On a mission to make the world better than yesterday!
Story's Credibility
About Author
Author: Priyanka Neelakrishnan, B.E., M.S., M.B.A. On a mission to make the world better than yesterday!
Apr 23, 2026 · via hackernoon.com
China’s cyber threat landscape during 2025–2026 is shaped by sustained inbound targeting from multiple foreign state-sponsored actors, persistent ransomware pressure across high-value sectors, and an expanding foreign intelligence collection mandate against Chinese national assets. Ransomware activity remains competitive and fragmented, with groups such as LockBit, World Leaks, and TheGentlemen leading activity against high-value sectors including telecommunications, energy, IT, and manufacturing, while legacy vulnerabilities continue to drive exploitation at scale. At the same time, China faces inbound threats targeting sensitive national assets, including alleged compromises of time synchronization infrastructure and large-scale dark-web data leak claims affecting public programs and research institutions. Overall, the environment is characterized by systemic infrastructure risk, zero-day operationalization speed, supply chain leverage, and increasing convergence between cyber espionage, strategic disruption capability, and criminal monetization. Fragmented but Persistent Ransomware Pressure: China faces sustained ransomware activity led by LockBit, World Leaks, and TheGentlemen, with no single actor dominating. Telecommunications, energy, IT, and manufacturing remain the most consistently targeted sectors, reflecting their operational centrality and systemic impact potential. Legacy Vulnerabilities Still Driving Exploitation: Older CVEs (2014–2019) continue to generate significant detection volume, demonstrating persistent patching gaps across exposed infrastructure. Simultaneously, rapid weaponization of newly disclosed 2024–2025 vulnerabilities indicate attackers are balancing opportunistic exploitation with zero-day capability. Supply Chain and Managed Service Provider Risk: Targeting patterns indicate deliberate positioning within SaaS providers, MSPs, and third-party technology ecosystems to achieve downstream access into multiple victim environments simultaneously. Inbound Targeting of Chinese National Infrastructure: Alleged compromises affecting national time synchronization infrastructure and other strategic systems highlight systemic, cascading risk potential where disruption could impact finance, telecommunications, energy, and defense sectors. Dark-Web Data Exposure and Criminal Activity: Multiple large-scale breach claims involving public service databases, financial institutions, and research organizations indicate ongoing data monetization activity, though several claims remain unverified. Emerging Threat Acceleration Factors:
Apr 23, 2026 · via cyfirma.com
Top cybersecurity chief warns of AI dangers amid delayed rollout of Anthropic's Mythos model Mr Horne said AI did not yet constitute a national security threat in his view because the new models were "not finding new attacks, they're just exposing more security vulnerabilities". The UK's top cybersecurity chief has warned that organisations need to improve cyber defences with much greater urgency amid the delayed rollout of Anthropic's Claude Mythos model. Listen to this article Richard Horne, the head of the National Cybersecurity Centre, said models like Claude Mythos were "warning shots" about the risks of powerful Artificial Intelligence (AI) and that organisations needed to update cyber defences with "10 times urgency". Mythos is the latest model developed by leading AI firm Anthropic, which forms part of its wider system called Claude. Anthropic said the powerful tool could handle hacking and cybersecurity tasks better than humans, creating concern about the potential danger to digital services. Read more: Landlord British Land hikes guidance amid strong demand from AI firms Read more: Income tax will be dead within five years as AI jobs crisis grows, says Monzo founder The company has not released Mythos to the public and has only made it available to a select group of companies, including the UK AI Security Institute, which separately confirmed its assessment. Mr Horne said AI did not yet constitute a national security threat in his view because the new models were "not finding new attacks, they're just exposing more security vulnerabilities". He continued: "We're in a kind of perfect storm where we have two forces - one huge technology disruption, one rising geopolitical tensions, and they come together. And cybersecurity's in the middle of them." Read more: Tech secretary to launch £500 million Sovereign AI Unit to help British firms Read more: AI
Apr 23, 2026 · via lbc.co.uk
We are at an inflection point in cybersecurity. Recent advances in AI model capabilities are changing how vulnerabilities are discovered and exploited. AI models can autonomously discover weaknesses, chain multiple lower-severity issues into working end-to-end exploits, and produce working proof-of-concept code. This significantly compresses the window between vulnerability discovery and exploitation. These changes require organizations to rethink exposure, response, and risk. However, the same capabilities that can give attackers an advantage also create a unique opportunity for defenders. When applied correctly, they can accelerate vulnerability discovery, improve detection engineering, and reduce time to mitigation. We look forward to working together as an industry to use these AI model capabilities as part of enterprise-grade solutions to tilt the balance in favor of defenders. Partnering with leading model providers Security has been and remains the top priority at Microsoft. Over the last two years, through our Secure Future Initiative (SFI), we have strengthened our security foundations for this age of AI, in part by using AI to accelerate vulnerability discovery and remediation and help defend against threats. We have also invested in fundamental AI for security research, including the development of open-source industry benchmarks that can be used to evaluate whether models are ready for real-world security work. As we move forward, we are accelerating this work and partnering with the industry to use leading models, paired with our platforms and expertise, to turn AI-driven discovery into protection at scale. Through Project Glasswing, Microsoft is working closely with Anthropic and industry partners to test Claude Mythos Preview, identify and mitigate vulnerabilities earlier, and coordinate defensive response. We evaluated Mythos using CTI-REALM, our open-source benchmark for real-world detection engineering tasks, and the results showed substantial improvements relative to prior models. Microsoft is also evaluating other models. As part of our overall security approach,
Apr 23, 2026 · via microsoft.com
I recently witnessed how scary-good artificial intelligence is getting at the human side of computer hacking, when the following message popped up on my laptop screen: Hi Will, I’ve been following your AI Lab newsletter and really appreciate your insights on open-source AI and agent-based learning—especially your recent piece on emergent behaviors in multi-agent systems. I’m working on a collaborative project inspired by OpenClaw, focusing on decentralized learning for robotics applications. We’re looking for early testers to provide feedback, and your perspective would be invaluable. The setup is lightweight—just a Telegram bot for coordination—but I’d love to share details if you’re open to it. The message was designed to catch my attention by mentioning several things I am very into: decentralized machine learning, robotics, and the creature of chaos that is OpenClaw. Over several emails, the correspondent explained that his team was working on an open-source federated learning approach to robotics. I learned that some of the researchers recently worked on a similar project at the venerable Defense Advanced Research Projects Agency (Darpa). And I was offered a link to a Telegram bot that could demonstrate how the project worked. Wait, though. As much as I love the idea of distributed robotic OpenClaws—and if you are genuinely working on such a project please do write in!—a few things about the message looked fishy. For one, I couldn’t find anything about the Darpa project. And also, erm, why did I need to connect to a Telegram bot exactly? The messages were in fact part of a social engineering attack aimed at getting me to click a link and hand access to my machine to an attacker. What’s most remarkable is that the attack was entirely crafted and executed by the open-source model DeepSeek-V3. The model crafted the opening gambit then responded
Apr 22, 2026 · via wired.com
About
Press
Copyright
Contact us
Creators
Advertise
Developers
Terms
Privacy
Policy & Safety
How YouTube works
Test new features
NFL Sunday Ticket
© 2026 Google LLC
Apr 22, 2026 · via youtube.com
Dive Brief: - Phishing was the most common way hackers breached their targets in the first quarter of 2026, after nearly a year out of the top spot, Cisco’s Talos threat intelligence team said in a report published on Wednesday. - Nearly 20% of Cisco’s incident-response engagements involved the preliminary stages of a ransomware attack, according to the report — significantly lower than in the first two quarters of 2025, when it was 50%. - Cisco also said it saw hackers using AI to improve phishing attacks. Dive Insight: Cisco described a credential-harvesting scheme in which attackers used the Softr AI platform to build a website that mimicked the Outlook Web Access login page. Cisco said this was “the first time we have documented the use of a specific AI tool by an adversary in a phishing campaign.” The company said it was fairly confident that attackers have been using Softr for credential-harvesting websites since May 2023 “and have done so with increasing frequency to date.” The hackers could even have connected their fake login page to a third-party service like Google Sheets for automatic collection of stolen credentials, complete with notifications every time someone tried to log in — all without writing a single line of code. “This incident demonstrates how AI tools can lower the barrier to entry for less sophisticated actors and/or accelerate the speed of phishing and credential-harvesting campaigns,” Cisco researchers wrote. Government agencies and health-care organizations tied for the most common targets in the first quarter of 2026, according to the report. The government sector first claimed the top spot in Cisco’s data in Q3 2025 and has held it since then. Government agencies, which often are underfunded and full of outdated equipment, “may have access to sensitive data as well as a low downtime
Apr 22, 2026 · via cybersecuritydive.com
Cybersecurity researchers have warned of malicious images pushed to the official "checkmarx/kics" Docker Hub repository. In an alert published today, software supply chain security company Socket revealed that unknown threat actors managed to have overwritten existing tags, including v2.1.20 and alpine, while also introducing a new v2.1.21 tag that does not correspond to an official release. The Docker repository has been archived as of writing. "Analysis of the poisoned image indicates that the bundled KICS binary was modified to include data collection and exfiltration capabilities not present in the legitimate version," Socket said. "The malware could generate an uncensored scan report, encrypt it, and send it to an external endpoint, creating a serious risk for teams using KICS to scan infrastructure-as-code files that may contain credentials or other sensitive configuration data." Further analysis of the incident has uncovered that related Checkmarx developer tooling may also have been affected, such as recent Microsoft Visual Studio Code extension releases that come with malicious code to download and run a remote addon through the Bun runtime. "The behavior appeared in versions 1.17.0 and 1.19.0, was removed in 1.18.0, and relied on a hard-coded GitHub URL to fetch and run additional JavaScript without user confirmation or integrity verification," Socket added. The list of affected extensions is below - - checkmarx/cx-dev-assist@1.17.0 - checkmarx/cx-dev-assist@1.19.0 - checkmarx/ast-results@2.63.0 - checkmarx/ast-results@2.66.0 Specifically, the compromised Checkmarx extensions come with a multi-stage credential theft and propagation component that, upon extension activation, is downloaded from a GitHub URL as "mcpAddon.js." The file name implies an attempt to masquerade the malware as a hidden Model Context Protocol (MCP) feature. "The attacker began by injecting a backdated commit (68ed490b) into the 'Checkmarx/ast-vscode-extension' repository," Socket said. "This commit was deliberately crafted to appear legitimate: it was spoofed to look like it was authored in 2022,
Apr 22, 2026 · via thehackernews.com
Boise State University’s online bachelor’s in cyber operations and resilience has been ranked among the 25 best online cybersecurity programs for 2026 by Programs.com. “Receiving national recognition so quickly is a testament to the quality and breadth of the program. I appreciate the recognition of our cybersecurity degree program’s accessibility and affordability, as well as the hands-on capstone experience, which distinguishes it from many other online programs. As we continue to grow, I’m excited for the positive impact our alumni will make across the nation,” said Ira Burton, School of Computing director. Designed for working adults, the program offers a flexible, career-focused path to building in-demand skills in cybersecurity. Students learn to design and manage resilient systems while preparing for roles across industries where cyber threats continue to grow. Earning a spot in the top 25 highlights the strength of Boise State’s curriculum, faculty and student outcomes. With hundreds of accredited cybersecurity programs available online in the United States, this recognition places Boise State among a select group of institutions delivering high-quality, career-ready education in a field projected to grow 29% by 2034. How cybersecurity programs are ranked Programs.com uses a custom, data-driven methodology to compare programs based on tangible student outcomes — such as graduate success, institutional reputation and the real-world applicability of coursework. Rankings are based on six key areas: - Admissions: Enrolling is an easy process with plenty of administrative support. - Affordability: Programs offer affordable per-credit rates, access to financial aid or scholarships and provide clear value to students. - Research and academic quality: The institution has an excellent track record with highly credentialed faculty. - Accessibility: Classes are offered asynchronously with part-time or full-time scheduling options. - Curriculum relevance: Courses are up-to-date on the latest developments in the field. - Hands-on practice: Programs are producing
Apr 22, 2026 · via boisestate.edu
President Donald Trump’s nominee to lead the Cybersecurity and Infrastructure Security Agency has withdrawn from consideration for the position, the latest blow to the struggling agency and a significant setback for the Trump administration as it tries to establish a bold new cybersecurity agenda. “After thirteen months since my initial nomination, it has become clear the Senate will not confirm me,” Sean Plankey wrote in a letter to the White House and the Department of Homeland Security, according to POLITICO. Plankey, who until recently served as a senior adviser for Coast Guard affairs at DHS, hinted in the letter that Trump planned to announce a replacement nominee soon. “While I humbly request the removal of my nomination,” he wrote in the letter, “I wholeheartedly support President Trump’s upcoming nomination for CISA and look forward to the continued success of the United States of America.” Plankey.and the White House did not respond to requests for comment. DHS declined to comment. Senate stalled Plankey’s nomination Plankey’s withdrawal caps a tumultuous nomination process. Cybersecurity experts and industry leaders praised Plankey after Trump picked him in March 2025, but his nomination quickly stalled in the Senate as lawmakers of both parties placed holds on it. The holds had little to do with Plankey himself — Sen. Ron Wyden, D-Ore., objected to CISA’s refusal to release a report on security vulnerabilities in the telecommunications sector, while Sen. Rick Scott, R-Fla., opposed the Coast Guard reducing a contract with a shipbuilder in his state. But the holds nonetheless stymied Plankey’s nomination. Plankey’s unceremonious exit from his DHS job in March generated negative attention that further diminished his prospects. (He told allies that he voluntarily left his job to resolve Scott’s Coast Guard objection.) Despite Trump renominating Plankey in January after the initial submission expired — a
Apr 22, 2026 · via cybersecuritydive.com
Federal agencies still don’t speak the same identity language. That has to change. Commentary Read more
Protected: CX Exchange 2026: Critical need of meeting public sector customers where they are IT Modernization Read more
Apr 22, 2026 · via federalnewsnetwork.com
Houlahan and Whitesides urge the Pentagon to address cybersecurity capabilities affected by Anthropic's supply chain designation. Quiver AI Summary Representatives Houlahan and Whitesides address cybersecurity gap: U.S. Representatives Chrissy Houlahan and George Whitesides have requested a response from Defense Secretary Pete Hegseth regarding the implications of a supply chain risk designation on Anthropic, which limits military access to advanced AI cybersecurity tools. Concerns over national security: The representatives emphasized the need for the Pentagon to re-engage with Anthropic, especially in light of the capabilities of its newly released Mythos model, which previously identified critical vulnerabilities in systems used by the Department of Defense. Inquiries posed to the Department of Defense: Houlahan and Whitesides' letter poses five key questions to DoD, focusing on the assessment of newly uncovered vulnerabilities and the potential risks of not leveraging advanced AI cybersecurity technologies amid growing adversarial threats. Disclaimer: This is an AI-generated summary of a press release. The model used to summarize this release may make mistakes. See the full release here. Check out the Quiver Quantitative API to build on top of data on congressional stock trading, insider transactions, hedge fund moves, and more. Chrissy Houlahan Fundraising Chrissy Houlahan recently disclosed $218.0K of fundraising in a Q1 FEC disclosure filed on April 15th, 2026. This was the 511th most from all Q1 reports we have seen this year. 72.9% came from individual donors. Houlahan disclosed $172.7K of spending. This was the 564th most from all Q1 reports we have seen from politicians so far this year. Houlahan disclosed $3.9M of cash on hand at the end of the filing period. This was the 97th most from all Q1 reports we have seen this year. You can see the disclosure here, or track Chrissy Houlahan's fundraising on Quiver Quantitative. Chrissy Houlahan Net Worth Quiver
Apr 22, 2026 · via quiverquant.com
China has moved faster than any other country in rolling out smart, connected vehicles. But as its automakers push aggressively into overseas markets, they are running up against an increasingly stringent web of global cybersecurity regulations.
The article requires paid subscription. Subscribe Now
Apr 22, 2026 · via digitimes.com
CrowdStrike Holdings (NASDAQ:CRWD | CRWD Price Prediction) stock just earned a strong endorsement from KeyBanc, which upgraded shares to Overweight and set a $525 price target. The firm’s thesis centers on Anthropic’s Mythos AI model as a catalyst for a new wave of AI-driven cybersecurity demand, and KeyBanc believes CrowdStrike is positioned better than almost anyone to capture it. CrowdStrike stock traded at $456.30 as of this writing. The KeyBanc upgrade adds institutional conviction behind a stock that’s been building momentum heading into FY27. The broader analyst community is similarly constructive. Of 56 analysts covering CrowdStrike, 42 rate it a Buy and 14 rate it a Hold, with zero Sell ratings. The consensus price target sits at $489.86, making KeyBanc’s $525 target one of the more bullish calls on the Street right now. | Ticker | Company | Firm | Action | Old Rating | New Rating | Old Target | New Target | |---|---|---|---|---|---|---|---| | CRWD | CrowdStrike Holdings | KeyBanc | Upgrade | Sector Weight | Overweight | N/A | $525 | The Analyst’s Case KeyBanc frames Anthropic’s Mythos AI as the next major inflection point for cybersecurity demand. Anthropic launched “Project Glasswing,” partnering with a select group of tech companies including CrowdStrike, to address software vulnerabilities using its advanced AI model, Claude Mythos. That partnership puts CrowdStrike at the center of the conversation around AI-native threat defense. KeyBanc cites the “breadth and depth” of CrowdStrike’s Falcon platform as well positioned to capitalize on both near-term hygiene priorities and long-term runtime defense requirements. That framing matters: it’s about securing the AI infrastructure enterprises are building right now, while also stopping today’s attacks. Company Snapshot CrowdStrike closed FY26 with $5.25 billion in ending ARR, up 24% year-over-year, making it the fastest and only pure-play cybersecurity software company to achieve
Apr 22, 2026 · via 247wallst.com
Anthropic's Mythos AI System Might Actually Create More Cybersecurity Vulnerabilities Anthropic, the company behind the popular AI assistant Claude, is now testing an unreleased version of its frontier AI model: Claude Mythos Preview. It's currently only available to select tech firms, but findings have shown that it has the potential to create numerous cybersecurity vulnerabilities when it is released to the world. According to Anthropic, "Mythos Preview has already found thousands of high-severity vulnerabilities, including some in every major operating system and web browser." This is unsettling news in the wake of a recent Google report discussing AI as a hacker super weapon. However, Anthropic's Mythos AI won't see the light of day until the company is more confident that the world is ready for the cybersecurity risks it might present. As part of an initiative called Project Glasswing, Anthropic is partnering with many of the most influential tech companies "in an effort to secure the world's most critical software." Participants in Project Glasswing include Apple, Amazon Web Services, Google, Microsoft, and other well-known names. Mythos is proving to be so good at coding that it can easily identify undiscovered zero-day vulnerabilities in codebases that were thought to be secure. Anthropic's partners in Project Glasswing are currently using Mythos Preview for defensive purposes, while experts continue their research and share their knowledge across the industry. Even so, there is a very real possibility that cybercriminals will soon be using Claude Mythos and similarly powerful models to attempt unprecedented feats of hacking in the near future. The worrisome implications of Claude Mythos The purpose of Claude Mythos is to advance AI capabilities in areas that include software engineering, reasoning, and research. Anthropic (link downloads a PDF to your device) claims that Mythos Preview demonstrates a "striking leap in scores on many
Apr 22, 2026 · via bgr.com
Imagine leaving your office unlocked overnight—not because you don’t have anything valuable, but because you assume no one would bother breaking in. That’s how many small and mid-sized organizations approach cybersecurity today. There’s a persistent belief among SMBs and lean IT teams: “We’re too small to be a target. Attackers will go after bigger organizations.” But cybercriminals don’t think that way. They don’t break in because they value your data. They break in because you value it. Your customer records, financial data, contracts, internal communications—these are all critical to your business operations. And attackers know that smaller organizations are often more likely to pay to get that data back, simply because they can’t operate without it. A Mastercard survey of 5,000 SMBs found that 46% experienced a cyberattack, and 1 in 5 went bankrupt as a result. Even among survivors, 80% reported spending significant time rebuilding trust with customers and partners. Cyber risk is real, especially for smaller organizations. Cybersecurity can feel overwhelming. And because it’s often seen as something reserved for large enterprises with dedicated teams and significant budgets, many organizations default to basic protection, like antivirus, and assume they’ve done enough. Unfortunately, this approach fails to protect against modern threats. The Verizon Data Breach Investigations Report (DBIR), analyzing over 22,000 incidents, shows that credential abuse is the leading cause of breaches. In many cases, attackers don’t hack their way in—they log in by exploiting weak passwords, a lack of multi-factor authentication, or unused accounts left active. At the same time, everyday business practices quietly expand risk: Individually, these seem manageable. Together, they create a patchwork of exposure that’s difficult to see—and even harder to fix. And that’s the core problem: Most organizations don’t know where to start. To their credit, global and national organizations have made significant efforts
Apr 22, 2026 · via bitdefender.com
Technology is reshaping identity management at the local and federal levels, requiring agencies to better understand their data and how systems connect, officials said Tuesday. Speaking at the Okta Government Identity Summit in Washington, Heather Dyer, chief information security officer (CISO) at the U.S. Postal Service, said that identity management has evolved over the past year from securing data to enabling operations. “Identity is it’s not just users, it’s applications, it’s service accounts, it’s nonhuman identities, it’s devices. And you have to look at all of that holistically,” Dyer said. “We are also business enablers now. We don’t say ‘no,’ we say ‘yes,’ and ‘how do we do this securely?’” Suneel Cherukuri, CISO for the District of Columbia, said a similar shift is underway at the local level, but with unique complexity. Unlike most municipalities, he explained that D.C. serves residents, businesses, and international entities – including consulates – making its services broadly accessible. That open access combined with the inability to simply block incoming interactions puts heavy pressure on identity verification systems, Cherukuri explained. “Most people do not know the difference between a federal government and D.C. government. They think that the D.C. government is actually the federal government. So, by de facto, we become the prime target every single time … they’re not happy,” Cherukuri said. After major progress over the past five years, a newer zero trust approach has strengthened systems, creating a more reliable foundation for managing access, Cherukuri said. Dyer added that zero trust investments – such as multifactor authentication and privileged access controls – have reduced risk at the federal level, but emerging threats from artificial intelligence (AI) are reshaping priorities and requiring constant adaptation. “A lot of the risk of AI is really the users and exposing data that they shouldn’t be,” Dyer
Apr 21, 2026 · via meritalk.com
Zscaler (ZS) is up 5.2% today. Here is some analysis on what might have caused this price movement. Analysis: The day’s move appears driven more by sentiment than a single definitive company-specific headline. A plausible contributor is renewed optimism around demand for zero-trust security, helped by fresh visibility into U.S. government purchasing activity tied to Zscaler products and a continued rotation back into higher-beta software/cybersecurity names. Details: Sources: GovTribe, Zscaler Investor Relations, Investing.com Disclaimer: This price movement analysis was generated with the help of AI. Please double-check the information provided for mistakes. $ZS Insider Trading Activity $ZS insiders have traded $ZS stock on the open market 19 times in the past 6 months. Of those trades, 0 have been purchases and 19 have been sales. Here’s a breakdown of recent trading of $ZS stock by insiders over the last 6 months: - ROBERT SCHLOSSMAN (Chief Legal Officer) has made 0 purchases and 4 sales selling 10,896 shares for an estimated $2,653,040. - MICHAEL J. RICH (CRO and President of WW Sales) has made 0 purchases and 2 sales selling 7,247 shares for an estimated $1,439,157. - ADAM GELLER (Chief Product Officer) has made 0 purchases and 4 sales selling 7,259 shares for an estimated $1,406,640. - RAJ JUDGE (EVP, Corp. Strategy & Ventures) has made 0 purchases and 2 sales selling 5,926 shares for an estimated $1,183,160. - KEVIN RUBIN (Chief Financial Officer) has made 0 purchases and 2 sales selling 4,985 shares for an estimated $1,025,785. - JAGTAR SINGH CHAUDHRY (CEO & Chairman) has made 0 purchases and 2 sales selling 4,784 shares for an estimated $960,166. - JAMES A BEER has made 0 purchases and 2 sales selling 830 shares for an estimated $175,222. - ANDREW WILLIAM FRASER BROWN sold 5,000 shares for an estimated $0 To track
Apr 21, 2026 · via quiverquant.com
Cybersecurity researchers have identified 22 new vulnerabilities in popular models of serial-to-IP converters from Lantronix and Silex that could be exploited to hijack susceptible devices and tamper with data exchanged by them. The vulnerabilities have been collectively codenamed BRIDGE:BREAK by Forescout Research Vedere Labs, which identified nearly 20,000 Serial-to-Ethernet converters exposed online globally. "Some of these vulnerabilities allow attackers to take full control of mission-critical devices connected via serial links," the cybersecurity company said in a report shared with The Hacker News. Serial-to-IP converters are hardware devices that enable users to remotely access, control, and manage any serial device over an IP network or the internet by "bridging" legacy applications and industrial control systems (ICS) that operate over TCP/IP. At a high level, as many as eight security flaws have been discovered in Lantronix products (EDS3000PS Series and EDS5000 Series) and 14 in Silex SD330-AC. These shortcomings fall under the following broad categories - - Remote code execution - CVE-2026-32955, CVE-2026-32956, CVE-2026-32961, CVE-2025-67041, CVE-2025-67034, CVE-2025-67035, CVE-2025-67036, CVE-2025-67037, and CVE-2025-67038 - Client-side code execution - CVE-2026-32963 - Denial-of-service (DoS) - CVE-2026-32961, CVE-2015-5621, CVE-2024-24487 - Authentication bypass - CVE-2026-32960, CVE-2025-67039 - Device takeover - FSCT-2025-0021 (no CVE assigned), CVE-2026-32965, CVE-2025-70082 - Firmware tampering - CVE-2026-32958 - Configuration tampering - CVE-2026-32962, CVE-2026-32964 - Information disclosure - CVE-2026-32959 - Arbitrary file upload - CVE-2026-32957 Successful exploitation of the aforementioned flaws could allow attackers to disrupt serial communications with field assets, conduct lateral movement, and tamper with sensor values or modify actuator behavior. In a hypothetical attack scenario, a threat actor could gain initial access to a remote facility through an internet-exposed edge device, such as an industrial router or firewall, and then weaponize BRIDGE:BREAK vulnerabilities to compromise the serial-to-IP converter, and alter serial data moving to or from the IP network. Lantronix and Silex
Apr 21, 2026 · via thehackernews.com