Top stories.
- Citrix urges immediate patching of two newly disclosed vulnerabilities.
- Federal agencies warn of an active cyber campaign targeting Siemens PLCs.
- Latvian road traffic agency data breach affects two-thirds of the country's population.
Citrix urges immediate patching of two newly disclosed vulnerabilities.
Citrix is urging customers to immediately patch two vulnerabilities affecting NetScaler Gateway and ADC devices. One of the flaws (CVE-2026-19490) is a critical authentication bypass bug, while the other (CVE-2026-19489) is a high-severity memory overflow vulnerability. Citrix stated, "The bulletin applies to supported versions of customer-managed NetScaler ADC and NetScaler Gateway, including certain FIPS and NDcPP builds. SecurAccess ZTNA Hybrid (formerly Secure Private Access Hybrid) deployments that use customer-managed NetScaler instances are also affected and should be upgraded to the recommended builds."
While Citrix hasn't disclosed whether the flaws are being actively exploited, BleepingComputer notes that the company generally issues such urgent bulletins when it believes exploitation is imminent.
Federal agencies warn of an active cyber campaign targeting Siemens PLCs.
US intelligence agencies, alongside the Department of Energy and the EPA, have issued a cybersecurity advisory warning of an active attack campaign targeting Siemens S7 Series PLCs. The agencies state, "The threat actors are conducting reconnaissance and capability development against U.S.-based Siemens PLC installations using AI-generated exploitation scripts disguised as legitimate monitoring tools. The actors leverage Internet scanning services to find Internet-exposed PLCs running outdated software or that are otherwise poorly protected."
The attacks are primarily targeting entities in critical Manufacturing, energy, water and wastewater, chemical, commercial facilities, and food and agriculture sectors. The agencies urge organizations to isolate PLCs from the internet, apply security patches, and strengthen monitoring.
Latvian road traffic agency data breach affects two-thirds of the country's population.
Latvia's Road Traffic Safety Directorate (CSDD) has confirmed a data breach affecting around two-thirds of the country's population, the Record reports. The cyberattack, which occurred over the weekend of August 8th, exposed information belonging to more than 1.2 million people and 200,000 businesses, dating back to 2008. Officials said the attackers gained access to systems containing personal or company identification numbers, vehicle license plate numbers, payment amounts and dates, and addresses associated with vehicle registrations.
The CSDD's supervisory board stepped down yesterday after parliament and Latvia's president called for their resignations. President Edgars Rinkevics said the attack posed "a significant threat to national security."