Critical Mendix Runtime Vulnerability Exposes User Data via Insecure Inherited Permissions

A critical vulnerability (CVE-2026-7891) in Siemens Mendix Runtime allows privilege escalation and unauthorized access to sensitive user data due to inadequate documentation of System.User entity behavior, enabling misconfigured access rules that expose all records to anonymous users. Read more

Research Digest: Multi-Path Retrieval Enhances L MLLM Improves MLPS Compliance Analysis in China

A new large language model framework integrates hierarchical, tree-based, and tokenization-based retrieval to improve accuracy and traceability in China's Multi-Level Protection Scheme (MLPS) compliance analysis, addressing limitations of general-purpose LLMs in standards-intensive cybersecurity governance. Read more

AtlasRAT Loader Chain Reveals Builder-Based Malware Framework Targeting WeChat in East Asia

AhnLab ASEC details a four-stage in-memory loader chain for AtlasRAT, a Windows RAT using Delphi-based Flash Player lures, TLS-ChaCha20 C2, offline keylogging, and WeChat.exe DLL injection, with evidence pointing to a builder-based framework rather than a single operator, highlighting implications for regional threat monitoring. Read more

AWS DevOps Agent Accelerates Network Firewall Troubleshooting by Automating Root Cause Analysis

AWS DevOps Agent reduces AWS Network Firewall troubleshooting time from hours to minutes by automatically correlating CloudWatch alarms, firewall logs, route tables, and CloudTrail API calls to identify rule changes causing connectivity drops, demonstrated through three failure scenarios including domain deny lists, stateless rule misconfigurations, and asymmetric AZ routing. Read more

CISA Advisory Highlights Critical Session Management Flaws in Weintek cMT3092X HMI Used in Global Manufacturing

CISA advisory ICSA-26-204-03 discloses four vulnerabilities in Weintek cMT3092X HMI firmware, including two critical flaws allowing privilege escalation via cookie and token manipulation, plaintext password storage, and improper user management. All affect firmware versions prior to 20210218 and EasyWeb versions prior to v2.1.20. Weintek has released a patch-only update (cmt_typeB_20260316_007.patch) upgrading EasyWeb to 2.3.17-typeb. No public exploitation has been reported to CISA as of the advisory date. The vulnerabilities collectively undermine authentication and authorization in HMI systems deployed in critical manufacturing environments worldwide. Read more

Russian State-Supported APT LAUNDRY BEAR Exploits Zero-Day in Zimbra Webmail for Global Email Espionage

Russian state-supported cyber actors (LAUNDRY BEAR) have exploited a zero-day XSS vulnerability (CVE-2025-66376) in Zimbra Collaboration Suite since July 2025 to exfiltrate 90 days of email, GAL, and authentication data via a view-only phishing technique, requiring only that victims open a malicious email in a vulnerable web client. Read more

June 2026 Financial Sector Threat Analysis Reveals Multi-Stage Attack Chain Dominance

AhnLab's June 2026 report shows phishing as the top initial attack vector against financial institutions globally, followed by droppers/downloaders and infostealers, with HTML-based smuggling and script-based execution prevalent. Dark web markets actively traded financial data from Canada Life, Robinhood, Prudential, Robinhood, and AYA Bank, while ransomware groups like Lapsus$ and MORPHEUS claimed large-scale data theft. Read more

ASEC June 2026 Report Details Multi-Stage Financial Sector Threats with Telegram Exfiltration and Dark Web Data Trading

In June 2026, ASEC documented a multi-stage threat campaign targeting the Korean financial sector, where phishing via HTML attachments initiated attacks, droppers/downloaders delivered secondary payloads, and infostealers exfiltrated data via Telegram, representing 5% of observed leaks, while dark web markets traded stolen data from global financial entities including Robinhood, Prudential, and AYA Bank, alongside access credentials and KYC documents. Read more

CylindricalCanine Subgroup Exploits DigiCert Support Portal to Steal Code-Signing Certificates

The stolen certificates were used to sign Zhong Stealer malware, highlighting a critical gap in internal trust controls at certificate authorities. The incident underscores how legitimate support functions, when inadequately isolated, can be weaponized in supply chain attacks targeting software signing infrastructure. Read more