ZeroHour

Search: “ethernet-ip”

29 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

New IoT Malware Uses Public Linux Exploits to Gain Root and Launch DDoS Attacks

Nozomi details KATARU, an IoT botnet that brute-forces Telnet, exploits public Linux kernel flaws for root access, and launches multi-protocol DDoS attacks.

KATARU, discovered after honeypot Telnet brute-force activity from a Vietnamese IP, downloads an ARM payload (vlxx.arm) and attempts privilege escalation by editing /etc/passwd or exploiting CVE-2026-46300 (Fragnesia), CVE-2026-43284 (Dirty Frag), and CVE-2026-31431 (Copy Fail). It combines Mirai-style TCP, UDP, ICMP, HTTP, QUIC and DNS floods with application attacks against Minecraft, FiveM, OpenVPN and WireGuard. The malware uses X25519 and ChaCha20-Poly1305 encrypted C2, unusually broad persistence across systemd, cron, init frameworks, and Android hooks, plus anti-debugging and decoy traffic to hinder analysis. Implementers copied x86 shellcode into the ARM binary and reused an RFC 7748 test-vector key, indicating low-quality but rapidly evolving commodity development.

GBHackersupdated · 5d agofirst · 5d agoMalware in the wild 2 sourcesCVE-2026-46300CVE-2026-43284CVE-2026-31431

Cisco Industrial Ethernet 1000 Series Switches Denial of Service Vulnerability

Cisco released a fix for a management-plane flooding DoS in IE-1000 switches that can make the device manager, SSH, or API inaccessible.

Insufficient protection against management plane flooding in Cisco Industrial Ethernet 1000 Series Switches allows an unauthenticated remote attacker to send high-rate ICMP, SSH, or HTTP traffic, raising CPU usage and causing a denial-of-service condition on the device manager web GUI, SSH, or API. Data traffic through the device is not affected. Cisco has released software updates to address the issue.

Cisco Security Advisories · 28d agoAdvisory

Cisco Industrial Ethernet 1000 Series Switches Stored Cross-Site Scripting Vulnerability

Cisco fixed a stored cross-site scripting flaw in Industrial Ethernet 1000 series switches exploitable by authenticated remote users.

Insufficient validation of user-supplied input in the web-based management interface of Cisco Industrial Ethernet 1000 Series Switches allows stored XSS. An authenticated remote attacker can inject malicious code into specific interface pages and execute arbitrary script in another user's context. Exploitation requires valid credentials; Cisco has released software updates.

Cisco Security Advisories · 28d agoAdvisory

Rockwell Automation 1756-ENBT Module

Rockwell's 1756-ENBT ControlLogix EtherNet/IP bridge (all versions) is vulnerable to DoS via crafted CIP packets, crashing the module until manual restart.

CISA republished Rockwell Automation's advisory for CVE-2025-10478, a CWE-754 flaw affecting all versions of the 1756-ENBT ControlLogix EtherNet/IP bridge, scored CVSS 7.5. A crafted CIP packet can crash the module, and the device requires a restart to recover. Affected critical infrastructure sectors include critical manufacturing, food and agriculture, transportation systems, and water. No public exploitation has been reported; CISA recommends minimizing network exposure.

Pyramid Solutions NetStaX EtherNet/IP Stack

CISA flags critical CVE-2026-78012 (CVSS 9.8) stack buffer overflow in Pyramid Solutions NetStaX EtherNet/IP stacks below v5.6.1, risking crashes or remote attack vectors.

CISA republished Pyramid Solutions' advisory for CVE-2026-78012, a CWE-121 stack-based buffer overflow in the NetStaX EtherNet/IP stack versions prior to 5.6.1, scored CVSS 9.8. Large Class 3 explicit-message requests can exceed the application-side receive buffer without generating a CIP error, potentially causing memory corruption, device crashes, or a silent remote attack vector. All eight adapter and scanner DLL/development kit variants, including CIP Security editions, are affected across critical manufacturing, energy, water, and chemical sectors. No public exploitation has been reported.

CISA Advisories · 13d agoAdvisoryCVE-2026-78012

MacOS 27 - First Boot, (Tue, Sep 15th)

SANS ISC documents the expected network traffic macOS 27 'Golden Gate' generates on first boot to help defenders baseline their networks.

Johannes Ullrich of SANS Internet Storm Center captured roughly 300 packets from a macOS 27 'Golden Gate' system before user login, covering DHCP, IPv6 duplicate address discovery, DNS, and TCP behavior. macOS 27 resolves hostnames like albert.apple.com (device activation, certificate-pinned), push messaging hosts, and ipv4only.arpa for NAT64 networks. The OS still uses a TCP window scale of 6, ECN, and random timestamps, with only four TCP connections observed during boot. The analysis provides a reference baseline for security teams monitoring Apple endpoints.

SANS Internet Storm Center · 1d agoResearch

Show HN: Check if your IP has appeared in a residential proxy network

Spur Intelligence launches Have I Been Proxied, a free tool that checks if your public IP appeared in residential proxy networks.

Have I Been Proxied is a free one-click web tool that checks whether a user's public IP has been observed routing traffic in residential proxy networks. Devices can be silently enrolled via apps, browser extensions, VPNs, or smart TVs, and the tool offers guidance on which apps and devices to investigate. It is powered by Spur Intelligence's network intelligence data, which serves fraud and trust teams detecting residential proxies, VPNs, and anonymization infrastructure.

[remote] ipTIME A3004T - Remote Code Execution

A remote code execution exploit was published for ipTIME A3004T routers, a flaw relevant to internet-facing devices.

Exploit-DB published exploit #52644 for the ipTIME A3004T router, demonstrating remote code execution. Router RCE flaws are typically exploitable by unauthenticated attackers on exposed devices. The disclosure text does not report exploitation in the wild.

Exploit-DB · Aug 17, 2026Exploit / PoC

Researchers open-source a Wi-Fi cyber range for security training

NTNU and Aegean researchers open-source a software-emulated Wi-Fi cyber range using mac80211_hwsim with LLM-assisted scenario building.

Researchers from the Norwegian University of Science and Technology and the University of the Aegean published a design and prototype for a cyber range dedicated to IEEE 802.11 security training, emulating access points and clients with mac80211_hwsim, Linux namespaces, hostapd, wpa_supplicant, dnsmasq, and FreeRADIUS. The platform bundles Aircrack-ng, Wireshark, and custom tools WPAxFuzz and Bl0ck, and can convert plain-language scenario descriptions into deployable definitions via a locally hosted Llama model. A working prototype covering scenario creation and deployment is on GitHub; monitoring, access control, and orchestration zones remain future work.

Help Net Security · 23d agoTools1

[remote] D-Link DNS_340L - OS Command Injection

An OS command injection exploit was published for the D-Link DNS-340L NAS, a flaw relevant to exposed network storage devices.

Exploit-DB published exploit #52643 for the D-Link DNS-340L network-attached storage device. The vulnerability is an OS command injection, which could allow arbitrary command execution on affected devices. The disclosure text does not report exploitation in the wild.

Exploit-DB · Aug 17, 2026Exploit / PoC

A Feature-Rich Embedded NIDS with eBPF/XDP: Detector and Architecture Trade-offs

eBPF/XDP-based NIDS with Isolation Forest reaches 0.965 live F1 on DDoS replay; gRPC microservices match monolithic accuracy within 2ms overhead.

The paper presents a DDoS-focused network intrusion detection system for transport networks built with Ericsson, combining a statistical baseline with an Isolation Forest trained on flow features from GoFlowMeter, an open-source Go implementation of CICFlowMeter, plus eBPF/XDP kernel-level traffic filtering. On a Raspberry Pi 5 testbed replaying CIC-DDoS2019 as real traffic, the Isolation Forest achieves 0.965 recall/F1 live in the monolithic variant, catching low-volume attack windows the baseline misses. gRPC microservices nearly match monolithic accuracy adding under 2ms per window, while the Kafka pipeline trails by roughly nine percentage points and adds about 27ms.

arXiv cs.CR · 5d agoResearch

Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Denial of Service Vulnerability

Cisco warns of a DoS flaw in SIP software on Desk Phone 9800 and IP Phone 7800/8800 series from improper HTTP packet memory handling.

Cisco disclosed a denial of service vulnerability affecting Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 devices running Cisco SIP Software. An unauthenticated remote attacker can send a continuous stream of crafted HTTP packets, causing sustained memory consumption until the device becomes unresponsive. A manual reboot is required to recover an affected device. No CVE identifier was listed in the advisory text.

Cisco Security Advisories · 14d agoAdvisory

Mitsubishi Electric Multiple FA Products (Update D)

CISA warns Mitsubishi Electric CC-Link IE TSN remote I/O modules are vulnerable to denial-of-service via crafted UDP packets (CVE-2025-3511).

CISA published Update D of advisory ICSA-25-128-03 covering Mitsubishi Electric factory automation products. Affected products include CC-Link IE TSN Remote I/O modules NZ2GN2S1-32D, NZ2GN2S1-32T, NZ2GN2S1-32TE, and NZ2GN2S1-32DT at firmware version 09 or earlier (CVE-2025-3511). A remote attacker can send a specially crafted UDP packet to cause denial-of-service conditions, timeout errors, or communication delays on the affected products.

CISA Advisories · 20d agoAdvisoryCVE-2025-3511

USN-8730-1: Linux kernel vulnerability

Ubuntu issued USN-8730-1 fixing Linux kernel flaws in IPv6 networking and Netfilter that could allow system compromise.

Ubuntu released USN-8730-1 addressing a security issue discovered in the Linux kernel. The update corrects flaws in the IPv6 networking and Netfilter subsystems. Ubuntu states an attacker could possibly use the issue to compromise the system.

Ubuntu Security Notices · 9d agoAdvisory 6 sources

Almost Half of Malware Samples Communicate Direct to IP

Unit 42 analysis of 4 million malware reports finds 45% of C2-active samples connect directly to hard-coded IPs, bypassing DNS defenses.

Palo Alto Unit 42 analyzed over 4 million Advanced WildFire dynamic analysis reports and found that 45.32% of malware samples with C2 activity made at least one direct-to-IP connection, accounting for 23.17% of all C2 connection attempts. The firm proposes zero trust IP (ZT-IP), an enforcement approach that verifies whether outbound destinations were ever sanctioned by a DNS response. ZT-IP analysis surfaced Phorpiex ransomware droppers fetching payloads directly from C2 IPs, a persistent data exfiltration campaign using an obfuscated \GET protocol, and Mozi P2P botnet payloads delivered to IoT devices without DNS. Only 1% of benign samples connected directly to untrusted IP addresses.

Palo Alto Unit 42 · Aug 17, 2026Research

A Deep Dive Into Attempted Exploitation of CVE-2023

Mirai-like botnet scans exploit TP-Link EOL router flaw CVE-2023-33538 after CISA KEV addition, though observed exploit code is flawed.

Unit 42 observed large-scale automated scans attempting to exploit CVE-2023-33538 in end-of-life TP-Link TL-WR940N, TL-WR740N and TL-WR841N routers after CISA added the flaw to its KEV catalog in June 2025. HTTP GET requests inject commands via the ssid1 parameter at the /userRpm/WlanNetworkRpm endpoint to download and execute an arm7 ELF binary, a Mirai variant related to the Condi IoT botnet. Firmware emulation and reverse engineering showed the observed exploits are flawed and would fail, but the underlying vulnerability is real and successful exploitation requires authentication to the router's web interface. TP-Link confirmed the devices are end-of-life with no patches available and recommends replacing units and eliminating default credentials.

Palo Alto Unit 42 · 28d agoExploit / PoC in the wildCVE-2023-335381

Cisco security advisory (AV26-876)

Canada's Cyber Centre relayed Cisco advisories covering a Nexus 9000 Silicon One RCE, IOS XR hardening, and denial-of-service flaws across IP phone lines.

The Canadian Centre for Cyber Security advisory AV26-876 lists Cisco vulnerabilities affecting IOS XR, Nexus 9000 Series switches, and several IP phone series. Included are a Nexus 9000 Silicon One remote code execution vulnerability, a September 2026 IOS XR security hardening release, and SIP software denial-of-service flaws in Desk Phone 9800, IP Phone 7800/8800, and Video Phone 8875. The Cyber Centre urges users and administrators to review the Cisco advisories and apply updates as they become available. No active exploitation is reported in the advisory.

Canadian Centre for Cyber Security · 13d agoAdvisory

F5 security advisory (AV26-878)

Canada's Cyber Centre relayed an F5 advisory (AV26-878) covering vulnerabilities in BIG-IP, BIG-IQ, NGINX components, and APM clients.

The Canadian Centre for Cyber Security published advisory AV26-878 noting F5 vulnerabilities affecting BIG-IP all modules prior to 17.1.3.4, 17.5.1.8, 21.0.0.3, and 21.1.0.1, plus BIG-IQ prior to 8.4.2.1, NGINX Gateway Fabric, NGINX Ingress Controller, NGINX JavaScript 9.9, and APM clients. F5 issued an out-of-band security notification (K000162872) on September 2, 2026. Administrators are encouraged to review the linked advisory and apply updates as they become available.

Canadian Centre for Cyber Security · 13d agoAdvisory

How an Emerging Industrial Protocol Family Could Put OT at Risk

New research shows unprotected Time-Sensitive Networking industrial protocols could let attackers disrupt or manipulate physical processes in OT environments.

Research covered by Dark Reading examines an emerging family of industrial protocols based on Time-Sensitive Networking (TSN) and finds that unprotected implementations could be attacked to disrupt or manipulate physical processes. The findings highlight growing OT risk as these protocols proliferate in industrial deployments; no confirmed exploitation is reported.

Dark Reading · 26d agoResearch

Tufin expands Unified Control Plane with AI intelligence and multi-vendor automation

Tufin's TOS 5.3 adds AI-powered Segmentation Intelligence and multi-vendor automation for AWS, Palo Alto, VMware NSX-T, and Cisco Meraki to its Unified Control Plane.

Tufin TOS 5.3 extends the Unified Control Plane with enhanced AWS firewall, Palo Alto Strata Cloud Manager, VMware NSX-T, and Cisco Meraki support for automated policy and access-request provisioning. The new AI-powered Segmentation Intelligence solution continuously analyzes segmentation policies to identify gaps, drift, and recommended fixes. Tufin cites research that 49% of organizations manage more than 20 security tools across hybrid environments.

Help Net Security · 27d agoTools

[webapps] Linksys E1200_2.0.04 - Unauthenticated OS Command Injection

A proof-of-concept for unauthenticated OS command injection in Linksys E1200 router firmware 2.0.04 has been published on Exploit-DB.

Exploit-DB entry 52660 discloses an unauthenticated OS command injection affecting the Linksys E1200 wireless router running firmware version 2.0.04. The flaw is categorized as a web application vulnerability. No CVE identifier or evidence of in-the-wild exploitation is provided in the listing.

Exploit-DB · 16d agoExploit / PoC

New infosec products of the week: August 21, 2026

Weekly product roundup covering NETSCOUT outbound DDoS mitigation, F5 AI Gateway enhancements, Intezer Workflows, and Tufin TOS 5.3.

NETSCOUT extended Adaptive DDoS Protection to automatically mitigate outbound attack traffic for service providers. F5 enhanced its AI Gateway and integrated it into the F5 AI Security Platform for unified AI access governance. Intezer launched Workflows, native automation and response inside its platform without a separate SOAR, and Tufin released Orchestration Suite 5.3 with AI-powered Segmentation Intelligence for multi-vendor environments.

Help Net Security · 26d agoTools

Palo Alto PAN-OS Vulnerability Enables Arbitrary Code Execution as Root User

Palo Alto Networks patched CVE-2026-0310, an unauthenticated XML-processing buffer overflow in PAN-OS allowing root code execution on PA-Series firewalls.

Palo Alto Networks disclosed CVE-2026-0310, an out-of-bounds write (CWE-787) in PAN-OS XML processing with a CVSS-B base score of 9.2 and CVSS-BT of 7.2. An unauthenticated attacker with network access to a vulnerable management or dataplane interface can send crafted XML to execute arbitrary code as root on PA-Series appliances. On VM-Series the impact is limited to denial-of-service, while Prisma Access and Cloud NGFW require authentication and carry lower risk. Fixed releases include 12.2.3, 12.1.10, 11.2.13-h2, 11.1.16-h2, and 10.2.18-h10; no workaround exists beyond restricting management interface access.

Cyber Security Newsupdated · 6d agofirst · 6d agoVulnerability 3 sourcesCVE-2026-0310

PoisonedRefresh: A Fileless Linux Rootkit That Injects PHP Web Shells Into F5 BIG-IP APM Server Memory

Sophos details PoisonedRefresh, a fileless Linux rootkit that injects a memory-resident PHP web shell into F5 BIG-IP APM after exploitation of CVE-2025-53521.

On September 8, 2026, SophosLabs published an analysis of Linux/Agnt-IC (dubbed PoisonedRefresh by ESET) found in compromised F5 BIG-IP Access Policy Manager environments. Initial access leverages CVE-2025-53521, an unauthenticated RCE in BIG-IP APM when an access policy is configured on a virtual server; F5 confirmed exploitation and links the activity to cluster c05d5254, while Shadowserver observed 795 exposed vulnerable endpoints. A first stage hidden in a modified umount binary modifies /usr/sbin/httpd and SELinux configuration and embeds itself in BIG-IP upgrade images for persistence. The second-stage ELF intercepts __libc_start_main, hooks apr_dso_load, and injects a PHP web shell into libphp memory via mmap manipulation, leaving no disk artifacts, and exposes a /bin/bash shell via a local UNIX domain socket instead of a TCP port.

Security Affairs · 7d agoMalware in the wildCVE-2025-53521

HPE security advisory (AV26-928)

Canada's Cyber Centre relayed an HPE advisory covering multiple vulnerabilities in EdgeConnect SD-WAN Gateways and Orchestrator, urging prompt updates.

On September 16, 2026, the Canadian Centre for Cyber Security published advisory AV26-928 noting that as of September 15, 2026, HPE is affected by multiple vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways and Orchestrator across multiple versions, per HPE bulletin HPESBNW05135 rev.1. The Cyber Centre encourages users and administrators to review the linked HPE security bulletins and apply available updates. No exploitation details or CVE identifiers are provided in the advisory text.

CISA Warns Water Utilities: Find Your Exposed PLCs Before Attackers Do

CISA urged water utilities to secure internet-exposed PLCs after July 2026 attacks compromised over 100 US water and wastewater systems, suspected Iran-linked.

CISA's exposure-reduction guidance, published August 21, follows July 2026 attacks in which threat actors remotely accessed PLCs connected directly through cellular modems, changed device IP addresses and passwords, and in some cases disabled alarms and shutdown processes without notifying operators. Iran is the suspected actor, though officials stopped short of formal attribution. CISA recommends routing remote access through centrally managed secure gateways, phishing-resistant MFA, unique credentials, and external scanning of industrial protocols such as Modbus, EtherNet/IP, DNP3, BACnet and OPC UA.

Security Affairs · 20d agoExploit / PoC in the wild