Threat Advisories
Jake McDowell · 2026-08-31
A new advisory highlights a weakness in Rockwell Automation OTTO Fleet Manager where password hashes are stored with insufficient computational effort. This vulnerability lowers the barrier for offline brute-force attacks if an attacker compromises a backup.
Threat Advisories
Jake McDowell · 2026-08-24
CISA has added a critical Zimbra vulnerability to its Known Exploited Vulnerabilities catalog. Here is what this means for mid-market organizations and how to prioritize remediation.
Threat Advisories
Jake McDowell · 2026-08-10
CISA has added a new command injection vulnerability to its KEV Catalog. Here is what IT leaders and MSPs need to know about CVE-2026-8037 and the immediate steps required for risk-based remediation.
Threat Advisories
Jake McDowell · 2026-08-03
A detailed examination of CVE-2026-18064 affecting the NASA Core Flight System and actionable guidance for IT teams managing embedded and industrial control systems.
Threat Advisories
Jake McDowell · 2026-07-27
A CISA advisory highlights critical vulnerabilities in MZ Automation libIEC61850 that could crash industrial systems or allow remote code execution. This analysis breaks down the impact for mid-market organizations and outlines immediate mitigation steps.
Threat Advisories
Jake McDowell · 2026-07-27
A breakdown of the Johnson Controls XAAP Android vulnerability affecting critical manufacturing and actionable security measures for mid-market organizations.
Threat Advisories
Jake McDowell · 2026-07-27
Russian state-sponsored actors have shifted tactics to exploit a zero-day vulnerability in Zimbra Collaboration Suite, allowing them to harvest email data with a single view of a malicious message.
Threat Advisories
Jake McDowell · 2026-07-27
A Russian state-supported group called LAUNDRY BEAR is actively exploiting a zero-day vulnerability in Zimbra Collaboration Suite to exfiltrate email data. This campaign targets Western government and commercial entities with a novel, view-only attack.
Threat Advisories
Jake McDowell · 2026-07-27
A new path traversal vulnerability in Rockwell Automation ThinManager allows authenticated attackers to write files to restricted system directories. This advisory outlines the affected versions, risk levels, and immediate remediation steps for mid-market organizations.
Threat Advisories
Jake McDowell · 2026-07-23
A new CISA advisory details four high-severity vulnerabilities in the Weintek cMT3092X HMI, allowing privilege escalation and credential theft. For mid-market operators and MSP partners, this represents a tangible risk to industrial control systems requiring immediate patch management attention.