New Controller Flaws Expose Highway Signs and Billboards to Remote Hacking

CISA has published an advisory to inform organizations about three vulnerabilities found by a researcher in Daktronics controllers.
The post New Controller Flaws Expose Highway Signs and Billboards to Remote Hacking appeared first on SecurityWeek.
Continue reading New Controller Flaws Expose Highway Signs and Billboards to Remote Hacking

WhatsApp Rolling Out Username Feature to Bolster Phone Number Privacy

An optional ‘username key’ adds another layer by requiring a secondary credential before someone can message users.
The post WhatsApp Rolling Out Username Feature to Bolster Phone Number Privacy appeared first on SecurityWeek.
Continue reading WhatsApp Rolling Out Username Feature to Bolster Phone Number Privacy

Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories

AWS has patched the vulnerability and published its own advisory to inform customers about the potential impact. 
The post Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories appeared first on SecurityWeek.
Continue reading Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories

First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the Wild

CISA has added the remote code execution flaw CVE-2026-12569 to its Known Exploited Vulnerabilities catalog.
The post First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the Wild appeared first on SecurityWeek.
Continue reading First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the Wild

Cal Water Finds No Evidence of OT Activity After Hackers Claimed They Could Disrupt Water Supply

Mandiant has helped the California water utility investigate the cyberattack launched by Iranian hacker group Handala.
The post Cal Water Finds No Evidence of OT Activity After Hackers Claimed They Could Disrupt Water Supply appeared first on SecurityW… Continue reading Cal Water Finds No Evidence of OT Activity After Hackers Claimed They Could Disrupt Water Supply

Lantronix Serial-to-IP Converter Flaw Exploited in Attacks After OT Threat Warning

The exploited flaw, CVE-2025-67038, is one of the vulnerabilities disclosed in April as part of the BRIDGE:BREAK research project.
The post Lantronix Serial-to-IP Converter Flaw Exploited in Attacks After OT Threat Warning appeared first on SecurityWeek.
Continue reading Lantronix Serial-to-IP Converter Flaw Exploited in Attacks After OT Threat Warning