CISA Adds OpenPLC ScadaBR XSS Vulnerability to KEV Amid Exploits

1 min read
Source: The Hacker News
CISA Adds OpenPLC ScadaBR XSS Vulnerability to KEV Amid Exploits
Photo: The Hacker News
TL;DR Summary

CISA has added the actively exploited CVE-2021-26829 XSS vulnerability in OpenPLC ScadaBR to its KEV catalog, highlighting ongoing threats from hacktivist groups like TwoNet, which exploited this flaw in a honeypot to deface a system. The attack involved using default credentials and web application layer exploits, with federal agencies required to patch by December 19, 2025. Additionally, a long-running exploit operation targeting Brazil has been observed, utilizing legitimate cloud infrastructure to evade detection.

Share this article

Reading Insights

Total Reads

0

Unique Readers

3

Time Saved

3 min

vs 4 min read

Condensed

88%

62273 words

Want the full story? Read the original article

Read on The Hacker News