A recent recap highlights growing evidence that attackers are exploiting a ServiceNow pre-auth remote code execution (RCE) condition in real environments. The key risk for defenders is that pre-auth flaws can enable compromise without any valid credentials, turning scanning and opportunistic exploitation into a practical attack path. Organizations using ServiceNow should prioritize verifying patch status, restricting exposure where possible, and hunting for suspicious requests around the vulnerable endpoints.
Source: Help Net Security
Origin Energy Confirms Data Breach After Claimed Theft of 2 Million Customer Records
Origin Energy disclosed a cyberattack following claims by a threat actor that sensitive customer data—reported to involve around 2 million people—was stolen. The most important takeaway is how breaches often become multi-stage narratives: initial compromise, data exfiltration, and then pressure tactics via threatened publication. Incident response teams should validate what data was accessed, review identity and access controls, and be ready for downstream phishing and credential-stuffing aimed at affected users.
Source: Security Affairs
Iran-Linked Actors Targeting U.S. Water and Energy Control Systems
U.S. agencies issued updated warnings that Iran-linked threat actors are targeting internet-exposed water and energy control systems, with an elevated focus on disruption risk. The emphasis on “internet-exposed” infrastructure underscores a persistent operational vulnerability: services reachable from the public internet are frequently probed, tested, and then abused. Defenders should review perimeter exposure, segment OT/ICS networks, and confirm monitoring for manipulation attempts—not just indicators of ransomware.
Source: Security Affairs
Rockwell Patches Code Execution Flaws in Arena Simulation Software
Rockwell has released patches addressing code execution issues in its Arena simulation software, with researchers describing plausible attacker paths against industrial organizations. Even when affected products are “simulation” tools, the risk profile matters because exploitation can provide a foothold inside environments supporting industrial operations. Organizations should patch promptly, review logs for exploitation attempts, and ensure software inventory covers engineering and simulation tooling—not only production systems.
Source: SecurityWeek
GitLab RCE PoC Published for Authenticated Users to Execute Commands as git
A researcher published a proof-of-concept (PoC) enabling authenticated users to execute commands as the git user on unpatched self-managed GitLab 18.11.3 servers. The practical danger is that authenticated access is often easier to obtain than many teams assume—via stolen credentials, misconfigurations, or weak account protections—making “auth-required” RCE still high impact. Administrators should accelerate patching and evaluate whether public or semi-public GitLab instances are exposed to untrusted collaborators.
Source: The Hacker News
Fastjson 1.x RCE Targets Spring Boot Apps (No Patched Version Yet)
Security firms report that attackers are targeting a critical Fastjson 1.x RCE vulnerability (CVE-2026-16723, CVSS 9.0) in the wild, including within affected Spring Boot applications. The alarming aspect is that it may be exploitable without authentication, with the payload running under the Java process privileges. With “no patched available” guidance, defenders should treat this as an urgent mitigation event: apply compensating controls, detect exploit attempts, and prioritize reducing exposure of vulnerable services.
Source: The Hacker News
X Scammers Use “Near-Exact” Fake Login Warnings to Steal Credentials
Researchers warn that scam campaigns on X are deploying login notification messages designed to closely resemble legitimate alerts, aiming to trick users into entering passwords. This is a reminder that social engineering is increasingly tailored to the exact UI patterns users expect, increasing the odds of success. Users and security teams should reinforce phishing-resistant training, tighten protections around account takeover (MFA, session monitoring), and watch for suspicious login attempts following social posts.
Source: Forbes Security
You May Also Be Interested In...
Troy Hunt Weekly Update 514: This Week in Data Breaches
Wired: The OpenAI Models That Hacked Hugging Face Were ‘Active on the Internet’ for Days
Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE