Breaking
AviaMasters: Het Hoogvliegende Crash Game dat Spelers Alert HoudtPlay real money slots at Zizobet Casino: enjoy fast payouts and live actionThe Wellness of Tea Goes Beyond What’s in the CupAquaspins Casino: come sfruttare al meglio il bonus di benvenuto nel 2026Bursa Malaysia ends lower as selling pressure in oil-related counters weighs - The StarUCSI University strengthens global health and science diplomacy collaboration with UNU Global HealthAstro Celebrates 30th Anniversary With Free Access to All Channels and Exclusive Offers for CustomersJulia Farhana Initiates Divorce Proceedings Against Dr Che Hafiz After Seven Months of SeparationHarga tiket GP Bahrain di Sepang serendah RM200‘I Never Intended To Hurt Or Kill Rocky,’ Says Man Accused Of Animal CrueltyNo criminal or corruption elements found in KWAP investigationAdam Lee says old debts remain unpaid as new loans are taken.Malaysians To Receive Free 10GB Data From Five Telcos For Merdeka And Malaysia DayTEEAM at “Think Business, Think Hong Kong” SymposiumBrunei Darussalam Capital Market Development Seminar Series: An Introduction to Sukuk IssuanceOver 90% of UGM Educators Are Gemini Certified through Academic Upskilling InitiativeURIIS 2026 sasar percepat pengkomersialan inovasi universitiLelaki disyaki terjun sungai elak pemeriksaan polis ditemukan lemasBangladesh humble Australia with worst total in contest as Hasan takes 6-55How I Got My Career in Foreign Policy: Sadanand DhumeAviaMasters: Het Hoogvliegende Crash Game dat Spelers Alert HoudtPlay real money slots at Zizobet Casino: enjoy fast payouts and live actionThe Wellness of Tea Goes Beyond What’s in the CupAquaspins Casino: come sfruttare al meglio il bonus di benvenuto nel 2026Bursa Malaysia ends lower as selling pressure in oil-related counters weighs - The StarUCSI University strengthens global health and science diplomacy collaboration with UNU Global HealthAstro Celebrates 30th Anniversary With Free Access to All Channels and Exclusive Offers for CustomersJulia Farhana Initiates Divorce Proceedings Against Dr Che Hafiz After Seven Months of SeparationHarga tiket GP Bahrain di Sepang serendah RM200‘I Never Intended To Hurt Or Kill Rocky,’ Says Man Accused Of Animal CrueltyNo criminal or corruption elements found in KWAP investigationAdam Lee says old debts remain unpaid as new loans are taken.Malaysians To Receive Free 10GB Data From Five Telcos For Merdeka And Malaysia DayTEEAM at “Think Business, Think Hong Kong” SymposiumBrunei Darussalam Capital Market Development Seminar Series: An Introduction to Sukuk IssuanceOver 90% of UGM Educators Are Gemini Certified through Academic Upskilling InitiativeURIIS 2026 sasar percepat pengkomersialan inovasi universitiLelaki disyaki terjun sungai elak pemeriksaan polis ditemukan lemasBangladesh humble Australia with worst total in contest as Hasan takes 6-55How I Got My Career in Foreign Policy: Sadanand Dhume
Economy

Cyber warning issued for MZ Automation’s lib60870 library

A critical out-of-bounds read flaw in MZ Automation’s lib60870 library can crash parsing processes and trigger denial-of-service attacks, according to a joint advisory by CISA and the vendor.

Source: CISA · July 24, 2026 at 11:01 PM · AI-assisted report

Cyber warning issued for MZ Automation’s lib60870 library
Photo: Wikimedia Commons

KUALA LUMPUR, 25 JULY 2026 —

Listen to this article

DomainFork Audio · read aloud

A critical out-of-bounds read flaw in MZ Automation’s lib60870 library can crash parsing processes and trigger denial-of-service attacks, according to a joint advisory by CISA and the vendor.

Market Impact

Malaysian operators using lib60870 in critical-infrastructure sectors such as energy and water need to check exposure immediately, since many downstream control systems rely on IEC 60870-5-104 stacks for telemetry and command-and-control.

The flaw, tracked as CVE-2026-16002, carries a CVSS v3.1 score of 8.2 and affects all versions of lib60870 prior to 2.4.1. Successful exploitation would let an unauthenticated attacker on the network force a crash by sending malformed frames, disrupting grid or pipeline monitoring.

MZ Automation said users should update to version 2.4.1 or later and isolate affected devices behind firewalls. CISA recommends segmenting operational networks, using VPNs for remote access, and reviewing incident-detection signatures in ICS-TIP-12-146-01B.

No known in-the-wild attacks have been reported, but the high base score and ease of exploitation make patching urgent for regional utilities and Malaysian industrial firms that integrate the library into supervisory-control software.

Reporting based on CISA. Figures and claims are subject to revision as the story develops. DomainFork publishes editorial context, not investment advice — see our editorial standards.