DAILY DIGEST

Cyberattack Law and Disclosure Digest for 2026-10-07

Record Date: 2026-10-07

Key Facts

  • Primary record digest compiled for 2026-10-07.
  • Aggregates official announcements from DOJ, CISA, SEC EDGAR, and allied cyber agencies.
  • All cited documents are in the public domain or official government publications.

Summary of official government advisories, court filings, and sanctions published on 2026-10-07.

Johnson Controls EasyIO FG ↗

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to gain full unauthorized access to the device.

The following versions of Johnson Controls EasyIO FG are affected:

  • EasyIO FG firmware <=2.0b52 (CVE-2026-27872, CVE-2026-27873)
Hitachi Energy SOI ↗

View CSAF

Summary

Hitachi Energy is aware of RCE (Remote Code Execution) vulnerability in Apache ActiveMQ component of SOI product versions listed in this document. These vulnerabilities can be exploited to carry out various attacks affecting confidentiality, integrity, and availability of the product. Please refer to the Recommended Immediate Action

Hitachi Energy REB500 ↗

View CSAF

Summary

Hitachi Energy is aware of open-source software vulnerabilities that affect REB500 product versions listed in this document. These vulnerabilities can be exploited to carry out Denial of Service (DoS) attack on the product. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation.

Savannah lwIP SMTP client ↗

View CSAF

Summary

Successful exploitation of this vulnerability could crash the device being accessed; a buffer overflow condition may allow remote code execution.

The following versions of Savannah lwIP SMTP client are affected:

  • lwIP SMTP client 2.2.1 (CVE-2026-15340)
Hitachi Energy Asset Suite ↗

View CSAF

Summary

Hitachi Energy is aware of unauthenticated servlet access vulnerabilities that affect Asset Suite product versions listed in this document. These vulnerabilities can be exploited to potentially cause confidentiality, integrity and availability impact on the product. Please refer to the Recommended Immediate Actions for information a

Hitachi Energy RTU500 ↗

View CSAF

Summary

Hitachi Energy is publishing this cybersecurity advisory in response to the security findings reported by Dragos affecting end-of-life RTU500 CMU firmware version 9.x. The reported findings are associated with legacy RTU500 firmware versions that were developed according to the cybersecurity requirements, threat landscape, and indus