Cybersecuritynews Honeywell Trend IQ4xx Controllers Exposed Online Without Authentication
Article Content
Browse articles
Thousands of Honeywell Trend IQ4xx building-management controllers are accessible online without authentication, allowing unauthorized access to web-based controls. The vulnerability was disclosed by Zero Science Lab in advisory ZSL-2026-5979, which details the issue affecting devices in their factory-default configuration. The advisory was released on March 2, 2026, following months of research.
Ask AI about this cluster
Answers cite the sources they use
Updated 197d ago How this analysis works
Timeline
2026-03-02
Zero Science Lab released advisory ZSL-2026-5979
2026-03-04
Cybersecurity news articles published about the exposure
More articles in this cluster (2)
Following this threat?
Track Honeywell in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…
Massive Network of AI Proxy Servers Used for Malicious Activities Uncovered Security researchers from Team Cymru have identified over 10,000 proxy servers in China facilitating malicious AI activities. These servers, termed 'transfer stations,' are primarily used to bypass geographic restrictions and conduct model distillation attacks against frontier AI models. The infrastructure allows…