The Canadian Centre for Cyber Security issued a series of advisories highlighting a broad patch wave from major technology vendors, spanning enterprise infrastructure, operating systems, and industrial environments. IBM released updates for products including AIX, MQ, QRadar Suite Software, Cloud Pak for Security, multiple IBM Verify offerings, and other middleware and cloud components, while Dell published fixes affecting Avamar Data Store Gen5A, Connectrix B-Series FOS and SANnav, PowerSwitch E3200-ON Series, PowerSwitch Z9664F-ON, and Secure Connect Gateway. Red Hat and Ubuntu also pushed Linux kernel-related updates, with Red Hat covering several RHEL and CodeReady Linux Builder variants and Ubuntu addressing kernel issues in Ubuntu 22.04 LTS and 24.04 LTS, including NVIDIA-related vulnerabilities referenced in USN-8060-7 and USN-8059-8.
Industrial and telecom systems were also affected. CISA advisories cited vulnerabilities across products from Apeman, Ceragon, Honeywell, Inductive Automation, Lantronix, Siemens, and Trane, impacting industrial control systems, building management platforms, EV chargers, networking devices, and industrial software. Separately, HPE disclosed a remote buffer overflow in HPE Telco Service Orchestrator affecting versions prior to v4.2.12 under bulletin HPESBNW05029 revision 1. The Cyber Centre urged organizations to review vendor guidance, implement recommended mitigations, and apply updates promptly to reduce exposure across both IT and OT environments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
13 events from the most recent confirmed update back to the earliest known activity.
On 2026-06-25, HPE published security bulletin HPESBNW05070 revision 1 addressing critical vulnerabilities in HPE Telco Service Orchestrator. The advisory states that versions prior to v5.6.1 are affected, and the Canadian Centre for Cyber Security urged users to review the bulletin and apply updates.
Between June 15 and 21, 2026, Red Hat published security advisories addressing Linux kernel vulnerabilities across multiple offerings, including Red Hat CodeReady Linux Builder, Red Hat Enterprise Linux, Red Hat Enterprise Linux Server, and Red Hat Enterprise Linux for Real Time. The Canadian Centre for Cyber Security urged users and administrators to review the referenced Red Hat advisories and apply the necessary updates.
Between June 15 and 21, 2026, Ubuntu published security notices addressing Linux kernel vulnerabilities affecting Ubuntu 16.04 LTS, 20.04 LTS, and 22.04 LTS. The Canadian Centre for Cyber Security advised users and administrators to review the referenced Ubuntu Security Notices and apply the necessary updates.
Between June 8 and 14, 2026, Ubuntu published security notices addressing Linux kernel vulnerabilities affecting Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. The Canadian Centre for Cyber Security advised users and administrators to review the referenced Ubuntu Security Notices and apply the necessary updates.
Between June 8 and 14, 2026, Red Hat published security advisories addressing Linux kernel vulnerabilities across multiple offerings, including Red Hat CodeReady Linux Builder, Red Hat Enterprise Linux, Red Hat Enterprise Linux Server, and Red Hat Enterprise Linux for Real Time. The Canadian Centre for Cyber Security advised users and administrators to review the referenced Red Hat advisories and apply the necessary updates.
Between June 1 and June 7, 2026, Ubuntu published security notices addressing Linux kernel vulnerabilities across multiple Ubuntu releases, from Ubuntu 14.04 LTS through Ubuntu 26.04 LTS. The Canadian Centre for Cyber Security advised users and administrators to review the referenced Ubuntu Security Notices and apply the necessary updates.
Between June 1 and June 7, 2026, Red Hat published security advisories addressing Linux kernel vulnerabilities across multiple offerings, including Red Hat CodeReady Linux Builder, Red Hat Enterprise Linux, Red Hat Enterprise Linux Server, and Red Hat Enterprise Linux for Real Time. The Canadian Centre for Cyber Security advised users and administrators to review the referenced Red Hat advisories and apply the necessary updates.
Between March 9 and 15, 2026, Red Hat published security advisories addressing Linux kernel vulnerabilities across multiple offerings, including Red Hat Enterprise Linux variants and CodeReady Linux Builder. The updates applied to several versions and platforms.
Between March 9 and 15, 2026, CISA released a set of ICS advisories covering vulnerabilities in products from vendors including Apeman, Ceragon, Honeywell, Inductive Automation, Lantronix, Siemens, and Trane. The disclosures spanned industrial control systems, building management systems, EV chargers, networking devices, and industrial software.
Between March 9 and 15, 2026, Ubuntu issued security notices for Linux kernel vulnerabilities affecting Ubuntu 22.04 LTS and 24.04 LTS. The notices specifically referenced NVIDIA-related kernel issues via USN-8060-7 and USN-8059-8.
Between March 9 and 15, 2026, IBM published a broad set of security advisories affecting products such as AIX, MQ, QRadar Suite Software, Cloud Pak for Security, IBM Verify offerings, and other enterprise software. Users were urged to review IBM PSIRT guidance and apply the relevant fixes.
Between March 9 and 15, 2026, Dell published security advisories covering vulnerabilities in multiple products including Avamar Data Store Gen5A, Connectrix B-Series FOS and SANnav, PowerSwitch platforms, and Secure Connect Gateway. The advisories identified affected version ranges and directed customers to apply updates.
On March 16, 2026, HPE published security advisory HPESBNW05029 revision 1 for a remote buffer overflow vulnerability in HPE Telco Service Orchestrator. The issue affects versions prior to v4.2.12 and customers were advised to apply the vendor's updates.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
14 references tracked. Mallory keeps watching after this page renders.
cyber.gc.ca
Open sourcecyber.gc.ca
Open sourcecyber.gc.ca
Open sourcecyber.gc.ca
Open sourcecyber.gc.ca
Open sourcecyber.gc.ca
Open sourcecyber.gc.ca
Open sourcecyber.gc.ca
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.