By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: CISA Adds Actively Exploited XSS Bug CVE-2021-26829 in OpenPLC ScadaBR to KEV
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > CISA Adds Actively Exploited XSS Bug CVE-2021-26829 in OpenPLC ScadaBR to KEV
Computing

CISA Adds Actively Exploited XSS Bug CVE-2021-26829 in OpenPLC ScadaBR to KEV

News Room
Last updated: 2025/11/30 at 4:50 AM
News Room Published 30 November 2025
Share
CISA Adds Actively Exploited XSS Bug CVE-2021-26829 in OpenPLC ScadaBR to KEV
SHARE

Nov 30, 2025Ravie LakshmananHacktivism / Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has updated its Known Exploited Vulnerabilities (KEV) catalog to include a security flaw impacting OpenPLC ScadaBR, citing evidence of active exploitation.

The vulnerability in question is CVE-2021-26829 (CVSS score: 5.4), a cross-site scripting (XSS) flaw that affects Windows and Linux versions of the software via system_settings.shtm. It impacts the following versions –

  • OpenPLC ScadaBR through 1.12.4 on Windows
  • OpenPLC ScadaBR through 0.9.1 on Linux
DFIR Retainer Services

The addition of the security defect to the KEV catalog comes a little over a month after Forescout said it caught a pro-Russian hacktivist group known as TwoNet targeting its honeypot in September 2025, mistaking it for a water treatment facility.

In the compromise aimed at the decoy plant, the threat actor is said to have moved from initial access to disruptive action in about 26 hours, using default credentials to obtain initial access, followed by carrying out reconnaissance and persistence activities by creating a new user account named “BARLATI.”

The attackers then proceeded to exploit CVE-2021-26829 to deface the HMI login page description to display a pop-up message “Hacked by Barlati,” and modify system settings to disable logs and alarms unaware that they were breaching a honeypot system.

TwoNet Attack Chain

“The attacker did not attempt privilege escalation or exploitation of the underlying host, focusing exclusively on the web application layer of the HMI,” Forescout said.

TwoNet began its operations on Telegram earlier this January, initially focusing on distributed denial-of-service (DDoS) attacks, before pivoting to a broader set of activities, including the targeting of industrial systems, doxxing, and commercial offerings like ransomware-as-a-service (RaaS), hack-for-hire, and initial access brokerage.

It has also claimed to be affiliated with other hacktivist brands such as CyberTroops and OverFlame. “TwoNet now mixes legacy web tactics with attention-grabbing claims around industrial systems,” the cybersecurity company added.

In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies are required to apply the necessary fixes by December 19, 2025, for optimal protection.

OAST Service Fuels Exploit Operation

The development comes as VulnCheck said it observed a “long-running” Out-of-Band Application Security Testing (OAST) endpoint on Google Cloud driving a regionally-focused exploit operation. Data from internet sensors deployed by the firm shows that the activity is aimed at Brazil.

“We observed roughly 1,400 exploit attempts spanning more than 200 CVEs linked to this infrastructure,” Jacob Baines, VulnCheck CTO, said. “While most of the activity resembled standard Nuclei templates, the attacker’s hosting choices, payloads, and regional targeting did not align with typical OAST use.”

CIS Build Kits

The activity entails exploiting a flaw, and if it is successful, issue an HTTP request to one of the attacker’s OAST subdomains (“*.i-sh.detectors-testing[.]com”). The OAST callbacks associated with the domain date back to at least November 2024, suggesting it has been ongoing for about a year.

The attempts have been found to emanate from U.S.-based Google Cloud infrastructure, illustrating how bad actors are weaponizing legitimate internet services to evade detection and blend in with normal network traffic.

VulnCheck said it also identified a Java class file (“TouchFile.class”) hosted on the IP address (“34.136.22[.]26”) linked to the OAST domain that expands on a publicly available exploit for a Fastjson remote code execution flaw to accept commands and URL parameters, and execute those commands and make outbound HTTP requests to the URLs passed as input.

“The long-lived OAST infrastructure and the consistent regional focus suggest an actor that is running a sustained scanning effort rather than short-lived opportunistic probes,” Baines said. “Attackers continue to take off-the-shelf tooling like Nuclei and spray exploits across the internet to quickly identify and compromise vulnerable assets.”

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Samsung might finally fix dark mode’s biggest home screen eyesore Samsung might finally fix dark mode’s biggest home screen eyesore
Next Article A ’90s Keanu Reeves Sci-Fi Movie Was Based On A Brilliant Cyberpunk Short Story – BGR A ’90s Keanu Reeves Sci-Fi Movie Was Based On A Brilliant Cyberpunk Short Story – BGR
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

This startup hired a sci-fi novelist to give its AI companions a soul
This startup hired a sci-fi novelist to give its AI companions a soul
Software
This subscription-free smart ring is a stylish Oura Ring alternative
This subscription-free smart ring is a stylish Oura Ring alternative
News
Need a New Tree or Christmas Lights? Our Favorite Ones Are on Sale
Need a New Tree or Christmas Lights? Our Favorite Ones Are on Sale
Gadget
Mums and dads are using AI to help with tough parenting decisions, study shows
Mums and dads are using AI to help with tough parenting decisions, study shows
News

You Might also Like

Linux 6.19 Will Allow You To Write I2C Drivers In Rust
Computing

Linux 6.19 Will Allow You To Write I2C Drivers In Rust

2 Min Read
Broadcom “BNG_RE” Next-Generation RoCE Driver Slated For Linux 6.19
Computing

Broadcom “BNG_RE” Next-Generation RoCE Driver Slated For Linux 6.19

2 Min Read
Black Sesame SoC Support To Be Merged For Linux 6.19
Computing

Black Sesame SoC Support To Be Merged For Linux 6.19

2 Min Read
Genode OS Framework 25.11 Adds Intel Alder Lake Graphics Support
Computing

Genode OS Framework 25.11 Adds Intel Alder Lake Graphics Support

2 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?