Info
2026-08-13 18:07Z · last 4h · 47 findings
· glm-5.2:cloud
Threat Brief — 2026-08-13 — ICS Flaw Flood, Medical Device Risk
Executive summary. A large batch of CISA ICS advisories dropped today covering over a dozen industrial and medical products, including a Bluetooth-reachable brain-stimulation device with overridable safety limits and multiple Siemens building-automation and engineering tools with RCE potential. Separately, AI "watermark removers" proliferated within days of Anthropic's Claude watermarking rollout, and NIST proposed reforming the NVD to account for AI-assisted patching. McDonald's ordering app was revealed to have compiled 515-page behavioral dossiers from years of customer data.
Top items
- Flow Neuroscience FL-100 brain-stimulation device — Bluetooth safety-limit override. A vulnerability allows an attacker within Bluetooth range to manipulate transcranial stimulation parameters and override built-in safety limits on the FL-100 medical device. This is a direct patient-safety risk with physical consequences. (src: CISA ICSMA)
- Siemens Siveillance Video Management Server — Remote Code Execution. A vulnerability in the video management server could allow a remote attacker to achieve RCE. Siemens has released new versions and recommends immediate update. (src: CISA ICSA)
- AVEVA Enterprise SCADA — deserialization code execution. An attacker can tamper with serialized data to achieve code execution during deserialization in AVEVA Enterprise SCADA, a product used in industrial control environments. (src: CISA ICSA)
- Haiwell IoT Cloud HMI Gateway — root-level OS command injection. Successful exploitation allows an attacker to inject and execute arbitrary OS commands with root privileges on affected Haiwell gateway versions. (src: CISA ICSA)
- Johnson Controls Airwall — authentication bypass and data decryption. Multiple vulnerabilities allow decryption of sensitive data, authentication bypass, and arbitrary file read on Airwall deployments. (src: CISA ICSA)
- Johnson Controls Metasys — persistent stored XSS escalating to admin context. A low-privilege user can inject a persistent payload via a crafted URL that executes in other users' sessions, including administrators. (src: CISA ICSA)
- Siemens Desigo DXR/PXC controllers — BACnet DoS requiring device reset. Malformed BACnet packets can cause denial-of-service conditions on building controllers; recovery requires a physical device reset or reboot. (src: CISA ICSA)
- Siemens License Server (SLS) — privilege escalation and arbitrary file read. Multiple vulnerabilities allow an attacker to elevate privileges and read arbitrary files. Siemens has released a new version. (src: CISA ICSA)
- Siemens RUGGEDCOM APE1808 — affected by Fortinet FortiOS vulnerabilities. Siemens industrial products are impacted by underlying FortiOS flaws; Siemens recommends contacting customer support. (src: CISA ICSA)
- Hitachi Energy APM Edge — "Dirty Frag" vulnerabilities. Vulnerabilities affect APM Edge product versions with potential impact on confidentiality, integrity, and availability. (src: CISA ICSA)
- ANDRITZ HIPASE-250 and 250 SCALA — data read and workstation access. Exploitation allows an attacker to read device data or gain access to affected workstations. (src: CISA ICSA)
- Siemens engineering tools (Parasolid, Simcenter Femap, Solid Edge, LOGO! Soft Comfort) — file-parsing and crypto flaws. Multiple file-parsing vulnerabilities across Parasolid (X_T format), Simcenter Femap (BMP), Solid Edge (PAR/PSM/DFT) could allow crash or arbitrary code execution via malicious files. LOGO! Soft Comfort has encryption/key-handling flaws allowing master-key extraction. (src: CISA ICSA, CISA ICSA, CISA ICSA, CISA ICSA)
- AI "watermark removers" flood the web after Anthropic's Claude watermarking. Within days of Anthropic watermarking Claude-generated text, multiple watermark-removal tools surfaced — including an open-source project with 4,500+ GitHub stars and paid detection-evasion services. None can substantiate their claims, raising concerns about adversarial tooling and false confidence in AI-content provenance. (src: BleepingComputer)
- McDonald's app compiled 515-page behavioral dossier from order history. The app logged every order, timestamp, and restaurant location for years, producing detailed behavioral forecasts — a stark illustration of how mundane consumer apps accumulate surveillance-grade profiles. (src: SecurityLab)
- NIST proposes AI-aware reform of the NVD vulnerability database. NIST has suggested reforming the National Vulnerability Database to account for AI-driven vulnerability discovery and patching, acknowledging that traditional human-paced curation cannot keep up. (src: SecurityLab)
- California launches first US state cybersecurity program powered by neural networks. The state is deploying AI-driven threat detection to identify adversaries proactively rather than reactively. (src: SecurityLab)
- AI coding tools introduce unvetted or hallucinated open-source dependencies faster than review can keep pace. ActiveState analysis highlights the supply-chain governance gap: organizations need to govern packages at the point of selection before they enter the build pipeline. (src: BleepingComputer)
Themes
- ICS/OT advisory deluge: CISA released over a dozen ICS advisories in a single batch spanning Siemens, Johnson Controls, Hitachi Energy, AVEVA, Haiwell, and ANDRITZ — covering building automation, video surveillance, SCADA, and engineering software. Teams with OT assets should prioritise triage, especially for RCE-capable flaws in Siveillance Video and AVEVA Enterprise SCADA.
- AI governance pressure on multiple fronts: Watermark circumvention tools, NIST's NVD reform proposal, California's neural-network security program, and AI-introduced supply-chain risk all point to a converging policy and operational challenge around AI's dual role as both defender and attack surface.
