CISA alerts to cleartext data exposure in Johnson Controls EasyIO Neo controllers
Organizations using Johnson Controls EasyIO Neo EC V3.3b62/63 or CW V3.3b24/25 must address the cleartext transmission flaw disclosed on Oct. 1 2026.
TrendingSEC and Global Regulators Issue Joint Bulletin for World Investor WeekGAO Finds Vertically Integrated Medicare Part D Sponsors Use Own Pharmacies for 24% of PrescriptionsCommerce urged to formalize oversight of concrete masonry checkoff programFederal Reserve publishes change-in-control notice for Shnaider Family Trust acquisitionSEC Sets Deadline for Hearing on SLR BDC Share-Class ExemptionNasdaq proposes written clearing affirmation for Night Session tradesNasdaq MRX adopts immediate rule change to reflect Nasdaq Texas nameNasdaq ISE rule change updates rules to reflect Nasdaq Texas name
Organizations using Johnson Controls EasyIO Neo EC V3.3b62/63 or CW V3.3b24/25 must address the cleartext transmission flaw disclosed on Oct. 1 2026.
Operators of Toptech TMS7 and TopHAT version 7.6.3 must address ten CVEs identified by CISA on Sept. 29, 2026.
Operators of Baicells Nova 430H eNodeB (model pBS3101SH) running firmware BaiBLQ_3.0.12 or earlier must address the CVE-2026-96274 flaw.
Community banks are urged to boost cyber hygiene and consider AI threats following opening remarks by Vice Chair Bowman.
Industry leaders in energy, finance and health sectors say overlapping federal rules hinder compliance, per a July 16 2026 GAO panel.
The Department of Transportation has concurred with all nine GAO recommendations, which remain open pending FAA action.
Operators of Schneider Electric PowerChute Serial Shutdown version 1.5 or earlier must apply the vendor fix after the advisory's 2026-09-17 release.
Organizations using FCP versions with GWS component from 2020 onward must address nine critical CVEs effective immediately
All versions of Mitsubishi Electric GX Works3 and Motion Control Settings are flagged for a critical authentication bypass, effective immediately.
The Department of Health and Human Services must adopt the GAO's recommendations to improve oversight and security controls for the 988 Suicide and Crisis Lifeline, effective immediately.
U.S. AI firms must adopt detection, response and intelligence-sharing measures against industrial-scale knowledge-distillation by Chinese companies, effective immediately
Owners of Schneider Electric Easergy, EcoStruxure, PowerLogic and Saitel devices must apply the supplied patch immediately to prevent session hijacking.
Owners of ASE2000 V2 units version 2.25-2.37 must address CVE-2018-1285 and CVE-2026-18717 as of August 27 2026.
All versions of Furuno's FA-50 Class B AIS transponder are vulnerable to CVE-2026-59769 as of the advisory issued 25 August 2026.
Issued Aug. 25 2026, the advisory directs federal, state, local and critical-infrastructure entities to adopt its mitigation steps immediately.
The advisory, issued Aug. 20 2026, warns users of Simplex Incident Manager version 2.01 and earlier of a memory-cleartext credential risk.
The extension applies to all U.S. investments subject to Executive Order 14105, effective August 9, 2026, for an additional year.