Toggle light / dark theme

Get the latest international news and world events from around the world.

Log in for authorized contributors

Researchers Use Claude to Port PreAuth RCE Exploit From One PLC Model to Another

Forescout Research — Vedere Labs said it used Anthropic’s Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another, executing attacker-supplied ARM shellcode on live hardware.

The exploit targets CVE-2021–31886, a stack-based buffer overflow in the Nucleus FTP server’s handling of the USER command, which carries a Siemens-assigned CVSS score of 9.8 and is accessible before authentication over TCP port 21.

CERT@VDE says no updates are available for the affected WAGO controllers, and advises owners to disable or block FTP on port 21, enforce segmentation controls, and monitor network traffic for anomalies.

Sality botnet infrastructure dismantled in joint global takedown

International law enforcement agencies and private partners have seized Sality malware infrastructure in a joint action aiming to disrupt and take down the peer-to-peer (P2P) botnet.

As part of this operation, supported by Europol and Eurojust, the U.S. Department of Justice (DOJ), FBI, and DCIS seized Sality-linked domains in the United States, while authorities in Bulgaria, Hungary, and Romania seized additional Sality-linked domains hosted in Europe.

CrowdStrike’s Counter Adversary Operations team, in collaboration with international law enforcement and private industry partners, also dismantled the botnet’s control channels in a peer-to-peer sinkhole operation that isolated infected machines.

SonicWall warns of actively exploited SMA1000 zero-day flaws

SonicWall warned customers that threat actors are chaining two new SMA1000 zero-day vulnerabilities in remote code execution attacks.

The first is a maximum-severity command injection flaw (CVE-2026–83548) found in the SMA1000 Appliance WorkPlace interface that stems from a server-side request forgery (SSRF) weakness.

This actively exploited zero-day chain also targets a command injection vulnerability (CVE-2026–83549) in the SMA1000 Appliance Management Console that attackers with admin privileges can exploit to execute arbitrary OS commands on vulnerable devices.

Hackers abuse Faronics Deploy admin tool to install ScreenConnect

Phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control over victim computers and install the ScreenConnect remote support software.

In activity observed between July 21 and August 20, Faronics-themed lures reached more than 457 endpoints via emails disguised as invoices, tax documents, or other business files.

Faronics Deploy is a cloud-based endpoint management platform that allows IT administrators to remotely enroll and manage computers, deploy software, and execute scripts.

/* */