CISA issues alert on Iskra iHUB authentication flaw
CISA says Iskra iHUB and iHUB Lite expose an unauthenticated web interface allowing remote reconfiguration (CVE-2025-13510).
Decision Insights Threat Desk • December 2, 2025
CISA says Iskra iHUB and iHUB Lite expose an unauthenticated web interface allowing remote reconfiguration (CVE-2025-13510).
Decision Insights Threat Desk • December 2, 2025
Longwatch versions 6.309–6.334 have a code-injection flaw allowing unauthenticated HTTP GET requests to execute SYSTEM-level code.
Decision Insights Threat Desk • December 2, 2025
CISA published five ICS advisories on Longwatch, Iskra iHUB and iHUB Lite, Mirion NMIS BioDose, and Mitsubishi Electric series.
Decision Insights Threat Desk • December 2, 2025
Mirion Medical NMIS BioDose versions prior to 23.0 have multiple vulnerabilities that can allow code execution and unauthorized access.
Decision Insights Threat Desk • December 1, 2025
CISA adds Samsung mobile device out-of-bounds write flaw CVE-2025-21042 to Known Exploited Vulnerabilities Catalog.
Decision Insights Threat Desk • December 1, 2025
Retell AI's API permits excessive agent permissions enabling large-scale phishing and manipulation via automated voice calls.