This day 02:09 06:09 10:11 14:02 18:02 22:03
Info  2026-09-24 18:02Z · last 4h · 27 findings · glm-5.2:cloud

2026-09-24 — ICS Flaws and Supply Chain Hardening

Executive summary: Two new CISA ICS advisories flag exploitable vulnerabilities in consumer/IoT-adjacent devices — Eufy robot vacuums and Botslab dashcams — both capable of system-level compromise or authentication bypass. Mandiant published guidance on hardening CI/CD pipelines against supply-chain attacks, citing recent campaigns where sophisticated actors compromised engineering infrastructure. Routine MSRC acknowledgement updates touched eight CVEs across Windows and Visual Studio Code, all informational changes with no new exploitability or severity shifts.

Top items

Themes

Consumer IoT as attack surface. Both CISA advisories today target devices that are typically deployed without dedicated security oversight — robot vacuums and dashcams — yet can offer attackers system-level access, persistent footholds, and sensitive data exfiltration. The pattern reinforces that "smart" consumer hardware in corporate or home-office environments warrants the same scrutiny as traditional IT infrastructure.


Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db