View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

Copeland XWEB Pro flaws give attackers root control of refrigeration

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • 23 Copeland XWEB Pro flaws could give attackers root control of refrigeration systems Claroty found 23 vulnerabilities in Copeland XWEB Pro refrigeration controllers.

    • The flaws affect commercial refrigeration, air-conditioning and food-retail operators, including supermarkets, warehouses and hospitals.
    • The XWEB Pro platform contains 23 vulnerabilities, including 21 high-severity issues.
    • An unauthenticated network attacker can bypass security controls and achieve root-level remote code execution.
    • Compromised controllers can influence connected compressors, evaporators and environmental sensors, potentially spoiling temperature-sensitive goods without immediate detection. ๐Ÿ“Ž Coverage: itwire.com ยท ๐Ÿ‘ via Cyber Security News
  • Malicious SIMs can hijack phones and cellular IoT devices via modem commands Researchers found malicious SIMs can hijack some phones and cellular IoT devices.

    • The risk affects smartphones, EV chargers, connected cars, industrial equipment, and routers.
    • Researchers tested 26 devices: 18 smartphones and eight cellular IoT modems; nine exposed SIM-accessible AT commands, including seven IoT modems.
    • Proactive SIM functionality lets a SIM invoke RUN AT and issue modem AT commands through the SIM interface.
    • CATANA-enabled attacks achieved code execution, arbitrary file reads, device shutdowns, cellular denial of service, and 4G-to-2G downgrades.
    • The Android locked-phone browser flaw is tracked as CVE-2025-48618; the broader findings include CVE-2026-57550 and CVD-2026-0122. ๐Ÿ“„ Source: usenix.org ยท ๐Ÿ“Ž Coverage: theregister.com ยท ๐Ÿ‘ via The Hacker News
  • Researchers Hire Three Suspected North Korean Operatives at Fake Crypto Startup Researchers hired three suspected North Korean IT workers through a fake crypto startup.

    • The operation targeted remote developer roles at a fabricated DeFi startup called Ballena Azul.
    • Three suspected Famous Chollima operatives obtained employee accounts and access to source code and internal systems.
    • Recruiters found inconsistent U.S. identities, mismatched state documents, proxy bank accounts and AI-processed identification images.
    • The operatives profiled issued virtual machines with dxdiag, systeminfo and wmic before checking their apparent connection countries.
    • Observed tooling included Chrome Remote Desktop, 2fa.cn, AIApply, Final Round AI, Simplify Copilot, Vultr, Gorilla Servers and AstrillVPN exit nodes. ๐Ÿ“„ Source: any.run ยท ๐Ÿ“Ž Coverage: thehackernews.com ยท ๐Ÿ‘ via The Hacker News, @zackwhittaker@mastodon.social
  • Cloudflare reports 519% surge in DDoS attacks above 1 Tbps Cloudflare reported a 519% quarter-over-quarter increase in DDoS attacks above 1 Tbps.

    • Cloudflare customers worldwide were targeted, with Media, Production, and Publishing receiving 14.2% of mitigated HTTP DDoS requests in H1 2026.
    • Cloudflare mitigated 23.2 million network-layer DDoS attacks and 29.64 trillion malicious HTTP requests in H1 2026.
    • Attacks exceeding 1 Tbps rose from 130 in Q1 to 805 in Q2 2026.
    • DNS floods accounted for 40% of network-layer attacks in Q2, while CLDAP floods increased 881.9% quarter over quarter.
    • Attackers used DNS reflection and amplification techniques, including spoofed queries against open resolvers and CLDAP traffic over UDP port 389. ๐Ÿ“„ Source: blog.cloudflare.com ยท ๐Ÿ“Ž Coverage: bleepingcomputer.com ยท ๐Ÿ‘ via BleepingComputer, Cloudflare Blog
  • US Water Utilities Get New Cybersecurity Bill and Water Watch Center US lawmakers and cybersecurity groups launched initiatives to protect water utilities from cyberattacks.

    • The effort covers US water and wastewater utilities, especially systems serving fewer than 10,000 people.
    • The Water Cyber Shield Act would expand EPA cybersecurity authority and authorize $300 million annually for water infrastructure funds.
    • The Water Watch Center was launched by DEF CON Franklin and the National Rural Water Association.
    • Five cybersecurity firms will provide managed detection and response services through the center.
    • Attackers targeted internet-facing Rockwell/Allen-Bradley MicroLogix 1100 and 1400 PLCs, changing IP addresses and passwords to disrupt monitoring and control. ๐Ÿ“Ž Coverage: securityweek.com ยท ๐Ÿ‘ via SecurityWeek

๐Ÿ“‹ ADVISORIES

๐Ÿ”“ CVEs & KEV

  • CVE-2026-58115 โ€” CVSS 10.0 โ€” A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA0...
  • CVE-2026-18972 โ€” CVSS 9.6 โ€” Velociraptor authenticated identity-spoofing vulnerabilityAn authenticated at...
  • CVE-2026-72785 โ€” CVSS 9.3 โ€” Craft CMS before 5.10.6 Authorization Bypass via structures/move-elementCraft...
  • CVE-2026-69109 โ€” CVSS 8.7 โ€” A vulnerability has been identified in Siemens License Server (SLS) (All vers...
  • CVE-2026-69108 โ€” CVSS 8.3 โ€” A vulnerability has been identified in Siemens License Server (SLS) (All vers...
  • CVE-2026-50064 โ€” CVSS 7.3 โ€” A vulnerability has been identified in Solid Edge SE2025 (All versions before V225...
  • CVE-2026-50063 โ€” CVSS 7.3 โ€” A vulnerability has been identified in Solid Edge SE2025 (All versions before V225...
  • CVE-2026-50062 โ€” CVSS 7.3 โ€” A vulnerability has been identified in Solid Edge SE2025 (All versions before V225...
  • CVE-2026-50061 โ€” CVSS 7.3 โ€” A vulnerability has been identified in Solid Edge SE2025 (All versions before V225...
  • CVE-2026-50060 โ€” CVSS 7.3 โ€” A vulnerability has been identified in Solid Edge SE2025 (All versions before V225...
  • CVE-2026-50059 โ€” CVSS 7.3 โ€” A vulnerability has been identified in Solid Edge SE2025 (All versions before V225...
  • CVE-2026-50058 โ€” CV

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check