Saturday , August 22 2026
switch

CISA Warns
Network switch RCE flaw impacts critical infrastructure

CISA warns of two serious vulnerabilities in Optigo Networks ONS-S8 Aggregation Switches, which could allow authentication bypass and remote code execution in critical infrastructure.

The flaws involve weak authentication, allowing users to bypass password requirements, and issues with validating user input, which could lead to remote code execution, arbitrary file uploads, and directory traversal.

Five new malware families actively targeting Asian Gov.t infra

Central Asian government agencies have been attacked in a cyber spy operation that used a small but different range of...
Read More
Five new malware families actively targeting Asian Gov.t infra

T-Mobile Cuts Cables to Remove Chiness Salt Typhoon Hackers from Network

T-Mobile’s cybersecurity team reportedly physically cut a network cable connecting compromised infrastructure to the outside world. According to Bloomberg, the move...
Read More
T-Mobile Cuts Cables to Remove Chiness Salt Typhoon Hackers from Network

Splunk, Zyxel Patch Multiple Flaws Enabling RCE and Root Command Execution

Splunk has issued security fixes for 17 weaknesses in different apps and add-ons, such as Splunk MCP Server, Splunk AI...
Read More
Splunk, Zyxel Patch Multiple Flaws Enabling RCE and Root Command Execution

“Zombie Card” attack revels expired Visa card may be used for contactless payments

Security experts have shown that expired credit cards can still be used. A study from the University of Massachusetts Amherst,...
Read More
“Zombie Card” attack revels expired Visa card may be used for contactless payments

Critical Zimbra RCE Flaw Actively Exploited in the Wild

CERT Polska has alerted that bad actors are actively exploiting a security flaw in Zimbra Collaboration Suite to execute code...
Read More
Critical Zimbra RCE Flaw Actively Exploited in the Wild

Operation CameraSwarm
A single hacker compromise 1400+ Dahua camera worldwide 

Operation CameraSwarm compromised 14,500+ Dahua IP cameras mostly in Ukraine and Russia. The operation lasted for at least 35 days...
Read More
Operation CameraSwarm  A single hacker compromise 1400+ Dahua camera worldwide 

Cl0p Ransomware Listed 40+ Victims of PTC Windchill Campaign

The Cl0p ransomware group has listed over 40 organizations that they say they targeted in a recent attack. This attack...
Read More
Cl0p Ransomware Listed 40+ Victims of PTC Windchill Campaign

Oracle Issues 943 Security Patches, Including Critical WebLogic Flaw

Oracle has put out 943 new security updates in its August 2026 Critical Security Patch Update. These updates fix problems...
Read More
Oracle Issues 943 Security Patches, Including Critical WebLogic Flaw

500+ critical infrastructure hit by Medusa ransomware

Medusa ransomware hit over 500 critical infrastructure. The Cybersecurity and Infrastructure Security Agency (CISA) said on Tuesday that the Medusa...
Read More
500+ critical infrastructure hit by Medusa ransomware

Critical WordPress Plugin Flaw Exposes 600,000 Sites to Attacks

A big security flaw in the Forminator Forms WordPress plugin might let unapproved users upload harmful PHP files. This could...
Read More
Critical WordPress Plugin Flaw Exposes 600,000 Sites to Attacks

The device is used in critical infrastructure and manufacturing worldwide. Since the flaws can be exploited remotely and are easy to attack, the risk is very high. No fixes are currently available, so users should follow the mitigations suggested by the Canadian vendor.

The first issue, CVE-2024-41925, is a PHP Remote File Inclusion (RFI) vulnerability caused by improper validation of user-provided file paths.

An attacker could exploit this vulnerability to access directories, bypass authentication, and run remote code.

CVE-2024-45367 is a weak authentication issue caused by inadequate password verification in the authentication process.

An attacker can misuse this to gain unauthorized access to the switches’ management interface, change settings, access sensitive information, or move to other parts of the network.

Claroty Team82 identified two critical vulnerabilities rated 9.3 on the CVSS v4 scale. These affect all versions of the ONS-S8 Spectra Aggregation Switch up to 1.3.7.

Securing the switches:

While CISA has not seen signs of these flaws being actively exploited, system administrators are recommended to perform the following actions to mitigate the flaws:

Separate ONS-S8 management traffic into its own VLAN to limit exposure to normal network traffic.

Connect to OneView using a dedicated NIC on the BMS computer for secure access to the OT network.

Set up the router’s firewall to allow only specific devices, ensuring that OneView can be accessed only by authorized systems and blocking any unauthorized access.

Use a secure VPN for OneView connections to ensure encrypted communication and protect against interception.

Follow CISA’s cybersecurity guidance by conducting risk assessments, using layered security, and following ICS security best practices.

CISA advises organizations seeing suspicious activity on devices to follow their breach protocols and report the incident to the cybersecurity agency for tracking and correlation with other incidents.

Check Also

card

“Zombie Card” attack revels expired Visa card may be used for contactless payments

Security experts have shown that expired credit cards can still be used. A study from …