By industry
Manufacturing security news
Tue, 8 Sept 2026
- SAP security advisory – September 2026 monthly rollup (AV26-894)
Serial Number: AV26-894 Date: September 8, 2026 As of September 8, 2026, SAP_SE is affected by vulnerabilities in the following products: SAP Extended Passport (EPP) Processing – KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, 8.04, WEBDISP 9.16, 9.18, 9.19, 9.20, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, 9.19 and 9.20 SAP NetWeaver (Message Server) - versions KERNEL 9.16, 9.18, 9.19, and 9.20 SAP Cloud Application Programming Model (CAP) prior or equal to 1.183 prior or equal to 2.7.6 prior or equal to 3.9.6 prior or equal to 4.0.2 SAP NetWeaver (SAP GUI for Java) - version BC-FES-JAV 8.10 SAP Integration Suite Version Cloud Integration - Trading Partner Management V2 2.9.2, Version B2B Integration Factory - Cloud Integration - Trading Partner Management 1.10.0 SAP NetWeaver Business Client – versions BC-WD-CLT-BUS 8.00 and 8.10 SAP NetWeaver Application Server for ABAP and ABAP Platform – versions KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, 8.04, KERNEL 7.22, 7.53, 7.54, 7.77, 7.93, 8.04, 9.16, 9.18, 9.19 and 9.20 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become
Canadian Centre for Cyber SecuritySAP
Mon, 7 Sept 2026
- ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on. Elsewhere, a trusted software source delivered code that stole credentials, and a protocol designed for secure network management
The Hacker NewsChrome - Trezor data breach impact now reaches 81,000 customers
Cryptocurrency hardware wallet maker Trezor says an August data breach at its shipping and logistics provider, ShipMonk, affects an additional 67,000 U.S. customers.
BleepingComputer
Sat, 5 Sept 2026
- Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted
Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets
The Hacker News
Fri, 4 Sept 2026
- DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors
Overview A new Linux toolkit, identified by Rapid7 Labs, has been targeting organizations across South Korea’s automotive and media industries with minimal detection. The campaign made use of a HAProxy instance named “ted backdoor”, alongside trojanized versions of crond, agetty, atd, sshd, and polkitd. This previously undocumented framework enabled threat actors to execute remote commands on compromised servers, inject malicious scripts into web traffic, perform credential harvesting, and engage in long-term surveillance. The standout feature of this toolkit is its depth of integration with the target environment. The ted backdoor is compiled as part of the victim’s existing HAProxy version 2.8.12. It uses its native filter API, internal memory pools, event scheduler, and process management infrastructure to intercept traffic and hide from monitoring, while genuine load balancing traffic operates as expected. Operating alongside this are an SSH keylogger, a curl-based RAT, and a stager. The RAT maintains a watchdog thread dedicated to tracking HAProxy’s health, and reporting it back to the operator’s infrastructure. The earliest uploads on VirusTotal date back to mid-2025 and the
Rapid7 BlogLinux
Wed, 2 Sept 2026
- JFrog security advisory (AV26-867) – Update 1
Serial number: AV26-867 Date: September 1, 2026 Updated: September 2, 2026 As of August 28, 2026, JFrog is affected by a vulnerability in the following product: Artifactory Prior to 7.111.21 Prior to 7.117.28 Prior to 7.125.20 Prior to 7.133.29 Prior to 7.146.38 Prior to 7.161.20 Open-source reporting indicates that CVE-2026-82329 related to JFrog Artifactory is being exploited in the wild. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Update 1 On September 2, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-82329 to their Known Exploited Vulnerabilities (KEV) Database. Artifactory Self-Managed Releases JFrog Security Advisories CISA KEV: CVE-2026-82329
CriticalUsed in attacksCanadian Centre for Cyber SecurityJFrog
Tue, 1 Sept 2026
- Another Artifactory CVE under attack by AI agents or humans
Unauthenticated intruders can mint admin tokens, and exposed servers are already being hit
The Register - Attackers Pounce on Critical Artifactory Bug Following Disclosure
CVE-2026-82329 is an authentication bypass flaw in JFrog's repository manager that enables bad actors to gain admin-level access on affected systems.
CriticalUsed in attacksDark ReadingJFrog
Thu, 27 Aug 2026
- Chinese Routers Sold Worldwide Contain Backdoors
An untold number of ZBT routers sold around the world as white-label products come with several implants built by the manufacturer.
Dark Reading - Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement released today, the Australian Federal Police (AFP) said two unnamed suspects from Western Australia, aged 21 and 23, were arrested in connection with a "sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses." The AFP did not name the defendants, but KrebsOnSecurity learned the 21-year-old suspect's real identity in June, and has been communicating with him ever since. This story includes interviews with TeamPCP's self-described spokesperson, and examines clues left behind by the TeamPCP leader that likely led to his undoing.
Krebs on Security
Latest manufacturing briefing
Manufacturing Cybersecurity Weekly Intelligence Brief — week ending 2026-09-14 →12 stories affecting manufacturing tracked in the last seven days, 1 rated critical.
Named most often, last 90 days
About manufacturing news
- 36
- Stories
- 8
- In the last 7 days
- 1
- Critical in the last 7 days