Polish Power Plant Breach via Private Cellular Network Shuts Turbine
Attackers shut down a steam turbine and the process-water treatment system at a Polish combined heat and power (CHP) plant by breaching…
Attackers shut down a steam turbine and the process-water treatment system at a Polish combined heat and power (CHP) plant by breaching…
The WAGO PFC200 controller was reachable through the private APN and had default admin credentials. The attacker used it to tunnel into…
The WAGO PFC200 controller was exposed on the private APN with default admin credentials, allowing the attacker to gain access and tunnel…
An application server whose internal console was targeted by the attacker's scripts testing default credentials. No deployment was confirmed.
SAP Help Portal provides documentation and sample configurations. In the case of CVE-2026-44761, sample scripts with hard-coded credentials were provided, leading to…
SAP has released its July 2026 security updates, addressing multiple vulnerabilities including a critical out-of-bounds write flaw in SAP NetWeaver Application Server…
Cyber Av3ngers is an Iranian-linked hacktivist group that targeted the Municipal Water Authority of Aliquippa in Pennsylvania in November 2023, exploiting default…
Paradox.ai operates the McHire platform used by McDonald's for AI-powered hiring. In 2025, researchers found a weak legacy admin account with default…
McHire is an AI-powered hiring platform operated by Paradox.ai for McDonald's. In 2025, researchers accessed it via a weak legacy admin account…