SEV2 — MajorCLOSEDCyber✓ Corroborated · 4 sources18d ago

Critical CVE Advisories: Labcenter Proteus 9 and Digi International PortServer — Dallas-Fort Worth Operations Footprint at Risk

Two severity-10 cyber advisories have been flagged for the Dallas-Fort Worth metro, targeting Labcenter Proteus 9 (EDA/design software) and Digi International PortServer TS/One SP IA (serial-to-network device servers commonly used in contact-center and back-office infrastructure for terminal and device connectivity). The Digi International vulnerability is of particular operational concern given PortServer devices are widely deployed in high-density contact-center and back-office environments to manage legacy terminal equipment and networked serial devices — exploitation could disrupt agent workstation connectivity or site communications. These advisories coincide with active Russian cyber espionage campaign warnings from Finnish intelligence (SUPO), elevating the threat context for organizations with distributed customer-operations infrastructure. DFW operations leaders should urgently verify Digi PortServer device inventory and patching status across contact-center and back-office sites.

Impact Summary

Two severity-10 cyber advisories have been flagged for the Dallas-Fort Worth metro, targeting Labcenter Proteus 9 (EDA/design software) and Digi International PortServer TS/One SP IA (serial-to-network device servers commonly used in contact-center and back-office infrastructure for terminal and device connectivity). The Digi International vulnerability is of particular operational concern given PortServer devices are widely deployed in high-density contact-center and back-office environments to manage legacy terminal equipment and networked serial devices — exploitation could disrupt agent workstation connectivity or site communications. These advisories coincide with active Russian cyber espionage campaign warnings from Finnish intelligence (SUPO), elevating the threat context for organizations with distributed customer-operations infrastructure. DFW operations leaders should urgently verify Digi PortServer device inventory and patching status across contact-center and back-office sites.

Domain
Cyber
Region
Dallas-Fort Worth, US, US
Opened By
watchkeeper
Jul 14, 2026, 01:01 AM UTC
Event Cluster
2 events
OVIX Score
10.0
Closed
watchkeeper-auto(resolved)
Jul 18, 2026, 01:30 AM UTC

Timeline6

Incident openedby watchkeeperJul 14, 2026, 01:01 AM UTC
Declared from 2 signals. OVIX 10. News 3. BPO 3. High-confidence (auto).
Note addedby watchkeeperJul 14, 2026, 01:01 AM UTC
External corroboration: corroborated (4 sources via Exa). cisa.gov, csirts.com, isssource.com, chemical-facility-security-news.blogspot.com
Revalidatedby watchkeeperJul 15, 2026, 01:30 AM UTC
Revalidated: no new activity. Next reval in 24h.
Revalidatedby watchkeeperJul 16, 2026, 01:30 AM UTC
Revalidated: no new activity. Next reval in 24h.
Revalidatedby watchkeeperJul 17, 2026, 02:00 AM UTC
Revalidated: no new activity. Next reval in 24h.
Incident closedby watchkeeperJul 18, 2026, 01:30 AM UTC
Auto-closed: no new material events within 4d for this incident.

Evidence / Why this?

Traced to source — read-onlyUpdated Jul 14, 01:01 AM UTC
Why declareddeclareHybrid
Incident declaration (deterministic floor + LLM relevance gate + geo-exposure floor)v2
DECLARE when deterministicFloor AND (llm.declare OR acuteWeatherFloor OR geoExposureFloor) AND NOT aggregateTitle, and no open same-domain incident merges it. deterministicFloor = maxSeverity>=8 AND (newsScore>=1 OR bpoScore>=1 OR acuteWeatherFloor). acuteWeatherFloor = maxSeverity>=9 AND any signal is an acute severe-weather WARNING (tornado/severe-thunderstorm/flash-flood) — overrides the LLM footprint-based suppression. geoExposureFloor (agents-034) = domain in {geopolitical, financial, labor, supply_chain, travel, infrastructure, seismic, disaster, environmental, health} AND maxSeverity>=8 AND bpoScore>=3 (density_class high/very_high — a major member hub). Anchored to member exposure (geo_density), it overrides the LLM footprint suppression so any of the ten previously-blind domains can declare when genuinely material; corroboration (2+ signals OR domain news) is guaranteed by the worthAnalyzing gate. Weather + cyber are excluded (their tuned paths are unchanged). aggregateTitle (grab-bag "Multiple/Several/Various…") is refused (agents-019 §D). Asset-class deny (military/war-zone, WFM-37) suppresses earlier. cyberFloor disabled (agents-009 hotfix).
domain
cyber
regions
["Dfw"]
bpo score
3
news score
3
llm declare
yes
max severity
10
signal count
2
llm rationale
Declaring true: severity-10 advisories in a high-density DFW operations footprint (~790K combined seats), with the Digi International PortServer vulnerability directly applicable to contact-center and back-office serial device infrastructure, elevated by concurrent state-sponsored espionage campaign warnings — not materially duplicative of the open Denver Hitachi Energy incident.
aggregate title
no
high confidence
yes
geo exposure floor
no
acute weather floor
no
deterministic floor
yes
model claude-sonnet-4-6 · prompt watchkeeper-declare-2026-06
Why SEV2SEV2score 2Deterministic
Incident severity level (SEV1–SEV4) at declarationv1
Base: SEV2 if sev>=9 AND news>=2 AND bpo>=1; else SEV3 if sev>=8 AND (news>=1 OR bpo>=1); else SEV4. Acute severe-weather (agents-028): if sev>=9 floor to SEV3 (SEV2→SEV3); minor/transient watches+advisories drop SEV2/SEV3→SEV4. Single-event cap: any SEV2 caps to SEV3 absent sustained multi-day BPO-region corroboration (SEV2 promotion is human-gated via revalidation). score = numeric SEV (1=most severe … 4); SEV3/SEV4 auto-validate, SEV1/SEV2 require human validation.
domain
cyber
bpo score
3
news score
3
persistent
no
max severity
10
auto validated
no
acute weather floor
no
Geo Provenance
Tierapprox
Sourcenone
Deterministic

Related Signals20

[Dfw] cyber 10.0 — SALTO ProAccess Spacesentinel15d ago[Dfw] cyber 10.0 — AutomationDirect Productivity Suitesentinel15d ago[Dfw] cyber 10.0 — SALTO ProAccess Spacesentinel15d ago[Dfw] cyber 10.0 — AutomationDirect Productivity Suitesentinel15d ago[Dfw] cyber 10.0 — NASA Core Flight System (cFS) Health & Safety (HS) Applicationsentinel15d ago[Dfw] cyber 10.0 — Improve Router Hygiene to Protect Against Russian State-Sponsored Targetingsentinel15d ago[Dfw] cyber 10.0 — SALTO ProAccess Spacesentinel15d ago[Dfw] cyber 10.0 — AutomationDirect Productivity Suitesentinel16d ago[Dfw] cyber 10.0 — CISA Adds Four Known Exploited Vulnerabilities to Catalogsentinel16d ago[Dfw] cyber 10.0 — CISA Adds Four Known Exploited Vulnerabilities to Catalogsentinel16d ago[Dfw] cyber 10.0 — Improve Router Hygiene to Protect Against Russian State-Sponsored Targetingsentinel17d ago[Dfw] cyber 10.0 — CISA Adds Four Known Exploited Vulnerabilities to Catalogsentinel17d ago[Dfw] cyber 10.0 — Improve Router Hygiene to Protect Against Russian State-Sponsored Targetingsentinel17d ago[Dfw] cyber 10.0 — Improve Router Hygiene to Protect Against Russian State-Sponsored Targetingsentinel18d ago[Dfw] cyber 10.0 — Improve Router Hygiene to Protect Against Russian State-Sponsored Targetingsentinel18d ago[Dfw] cyber 10.0 — Hitachi Energy PROMOD Vsentinel18d ago[Dfw] cyber 10.0 — Labcenter Proteus 9sentinel18d ago[Dfw] cyber 10.0 — Hitachi Energy PROMOD Vsentinel18d ago[Dfw] cyber 10.0 — Digi International PortServer TS, Digi One SP IAsentinel18d ago[Dfw] cyber 10.0 — Labcenter Proteus 9sentinel18d ago

External Corroboration

✓ Corroborated · 4 sourcesChecked Jul 14, 2026, 01:01 AM UTC
Labcenter Proteus 9 - ICS Advisoriescisa.govJul 7, 2026, 01:01 AM UTCDigi International PortServer TS, Digi One SP IA · CSIRTScsirts.comJul 7, 2026, 12:00 PM UTCDigi Fixes Ethernet Device Servers - ISSSourceisssource.comJul 8, 2026, 03:27 PM UTCChemical Facility Security News: 7 Advisories Published – 7-7-26chemical-facility-security-news.blogspot.comJul 13, 2026, 07:38 PM UTC

Affected Regions

Dfw