A severe vulnerability known as CVE-2025-41646 has been found in RevPi Webstatus, a web-based frontend deployed in industrial automation systems by KUNBUS. The vulnerability has a CVSS of 9.8 and makes it possible for an unauthenticated attacker to completely bypass the login mechanism by taking advantage of a type coercion bug in the JSON parsing logic. Particularly, the authentication logic incorrectly considers a JSON boolean true value as an acceptable password, permitting access without credentials. Versions through and including RevPi Webstatus v2.4.5 are vulnerable, especially in the Revolution Pi OS Bullseye releases between June 2023 and April 2024. This vulnerability is due to a logic error in which the routine for verifying passwords does not sufficiently check the data type of the hashcode parameter during JSON parsing. If the attacker sends a login request with { "hashcode": true }, the app considers it a valid authentication. Such bypass allows would-be attackers to have complete access to the RevPi Webstatus interface, where they might alter system settings, perform eavesdropping, or carry out denial-of-service attacks causing great harm in Industrial Control System (ICS) environments. Users are highly recommended to upgrade their systems promptly with standard Debian-based commands (sudo apt-get update && sudo apt-get upgrade) or manually download the patched package. Not patching this vulnerability may leave critical infrastructure vulnerable to substantial cyber threats.
Cybersecurity researchers have uncovered another evolution of the ongoing supply chain attack linked to the Mini Shai Hulud, Miasma, and Hades malware family, targeting both the np...
Amazon has addressed a high-severity security vulnerability, tracked as CVE-2026-12957, affecting Amazon Q Developer IDE plugins. The flaw could allow a malicious Git repository to...
?An active phishing campaign has targeted hotels and hospitality organizations across Europe and Asia since April 2026. Attackers send emails impersonating "Booking Manager (vi...