SEV2 — MajorCLOSEDCyber✓ Corroborated · 5 sources18d ago

Critical CVE Alerts: Labcenter Proteus 9 and Digi International PortServer Vulnerabilities — Denver, CO

Two Severity-10 sentinel alerts have fired in Denver flagging critical vulnerabilities in Labcenter Proteus 9 (EDA/PCB design software) and Digi International PortServer TS / Digi One SP IA (serial-to-network device servers commonly used in contact-center and back-office infrastructure). The Digi International vulnerabilities are of particular operational concern given that PortServer and similar serial-device gateway products are frequently deployed in telephony, workforce management, and facility-control environments within dense contact-center hubs. With Denver carrying ~28K contact-center seats and ~334K combined back-office and knowledge-worker seats, unpatched Digi devices could expose network segments to lateral movement, especially in the context of the concurrent Russian cyber-espionage campaign flagged by Finnish intelligence (Supo). Operations leaders should verify Digi device inventory and patch status across Denver sites and coordinate with IT security on isolation or firmware updates as a priority action.

Impact Summary

Two Severity-10 sentinel alerts have fired in Denver flagging critical vulnerabilities in Labcenter Proteus 9 (EDA/PCB design software) and Digi International PortServer TS / Digi One SP IA (serial-to-network device servers commonly used in contact-center and back-office infrastructure). The Digi International vulnerabilities are of particular operational concern given that PortServer and similar serial-device gateway products are frequently deployed in telephony, workforce management, and facility-control environments within dense contact-center hubs. With Denver carrying ~28K contact-center seats and ~334K combined back-office and knowledge-worker seats, unpatched Digi devices could expose network segments to lateral movement, especially in the context of the concurrent Russian cyber-espionage campaign flagged by Finnish intelligence (Supo). Operations leaders should verify Digi device inventory and patch status across Denver sites and coordinate with IT security on isolation or firmware updates as a priority action.

Domain
Cyber
Region
Denver, US, US
Opened By
watchkeeper
Jul 14, 2026, 01:01 AM UTC
Event Cluster
2 events
OVIX Score
10.0
Closed
watchkeeper-auto(resolved)
Jul 18, 2026, 01:30 AM UTC

Timeline6

Incident openedby watchkeeperJul 14, 2026, 01:01 AM UTC
Declared from 2 signals. OVIX 10. News 3. BPO 3. High-confidence (auto).
Note addedby watchkeeperJul 14, 2026, 01:01 AM UTC
External corroboration: corroborated (5 sources via Exa). csirts.com, chemical-facility-security-news.blogspot.com, windowsnews.ai, radar.offseq.com, waterisac.org
Revalidatedby watchkeeperJul 15, 2026, 01:30 AM UTC
Revalidated: no new activity. Next reval in 24h.
Revalidatedby watchkeeperJul 16, 2026, 01:30 AM UTC
Revalidated: no new activity. Next reval in 24h.
Revalidatedby watchkeeperJul 17, 2026, 02:00 AM UTC
Revalidated: 1 new signal(s) recorded, no material-clock advance (agents-019 §C). Next reval in 24h.
Incident closedby watchkeeperJul 18, 2026, 01:30 AM UTC
Auto-closed: no new material events within 4d for this incident.

Evidence / Why this?

Traced to source — read-onlyUpdated Jul 14, 01:01 AM UTC
Why declareddeclareHybrid
Incident declaration (deterministic floor + LLM relevance gate + geo-exposure floor)v2
DECLARE when deterministicFloor AND (llm.declare OR acuteWeatherFloor OR geoExposureFloor) AND NOT aggregateTitle, and no open same-domain incident merges it. deterministicFloor = maxSeverity>=8 AND (newsScore>=1 OR bpoScore>=1 OR acuteWeatherFloor). acuteWeatherFloor = maxSeverity>=9 AND any signal is an acute severe-weather WARNING (tornado/severe-thunderstorm/flash-flood) — overrides the LLM footprint-based suppression. geoExposureFloor (agents-034) = domain in {geopolitical, financial, labor, supply_chain, travel, infrastructure, seismic, disaster, environmental, health} AND maxSeverity>=8 AND bpoScore>=3 (density_class high/very_high — a major member hub). Anchored to member exposure (geo_density), it overrides the LLM footprint suppression so any of the ten previously-blind domains can declare when genuinely material; corroboration (2+ signals OR domain news) is guaranteed by the worthAnalyzing gate. Weather + cyber are excluded (their tuned paths are unchanged). aggregateTitle (grab-bag "Multiple/Several/Various…") is refused (agents-019 §D). Asset-class deny (military/war-zone, WFM-37) suppresses earlier. cyberFloor disabled (agents-009 hotfix).
domain
cyber
regions
["Denver"]
bpo score
3
news score
3
llm declare
yes
max severity
10
signal count
2
llm rationale
Declaring true because Severity-10 alerts involve a device class (Digi serial-to-network servers) with direct deployment relevance to contact-center and back-office infrastructure in a high-density Denver footprint, distinct from the open Hitachi Energy e-mesh incident, and occurring against a backdrop of active state-sponsored espionage warnings.
aggregate title
no
high confidence
yes
geo exposure floor
no
acute weather floor
no
deterministic floor
yes
model claude-sonnet-4-6 · prompt watchkeeper-declare-2026-06
Why SEV2SEV2score 2Deterministic
Incident severity level (SEV1–SEV4) at declarationv1
Base: SEV2 if sev>=9 AND news>=2 AND bpo>=1; else SEV3 if sev>=8 AND (news>=1 OR bpo>=1); else SEV4. Acute severe-weather (agents-028): if sev>=9 floor to SEV3 (SEV2→SEV3); minor/transient watches+advisories drop SEV2/SEV3→SEV4. Single-event cap: any SEV2 caps to SEV3 absent sustained multi-day BPO-region corroboration (SEV2 promotion is human-gated via revalidation). score = numeric SEV (1=most severe … 4); SEV3/SEV4 auto-validate, SEV1/SEV2 require human validation.
domain
cyber
bpo score
3
news score
3
persistent
no
max severity
10
auto validated
no
acute weather floor
no
Geo Provenance
Tierapprox
Sourcenone
Deterministic
Sources✓ Corroborated · 5 sources

Related Signals20

[Denver] cyber 10.0 — CISA Adds Four Known Exploited Vulnerabilities to Catalogsentinel14d ago[Denver] cyber 10.0 — NASA Core Flight System (cFS) Health & Safety (HS) Applicationsentinel15d ago[Denver] cyber 10.0 — Improve Router Hygiene to Protect Against Russian State-Sponsored Targetingsentinel15d ago[Denver] cyber 10.0 — AutomationDirect Productivity Suitesentinel15d ago[Denver] cyber 10.0 — SALTO ProAccess Spacesentinel15d ago[Denver] cyber 10.0 — AutomationDirect Productivity Suitesentinel15d ago[Denver] cyber 10.0 — NASA Core Flight System (cFS) Health & Safety (HS) Applicationsentinel15d ago[Denver] cyber 10.0 — Improve Router Hygiene to Protect Against Russian State-Sponsored Targetingsentinel15d ago[Denver] cyber 10.0 — AutomationDirect Productivity Suitesentinel15d ago[Denver] cyber 10.0 — NASA Core Flight System (cFS) Health & Safety (HS) Applicationsentinel15d ago[Denver] cyber 10.0 — AutomationDirect Productivity Suitesentinel16d ago[Denver] cyber 10.0 — Improve Router Hygiene to Protect Against Russian State-Sponsored Targetingsentinel16d ago[Denver] cyber 10.0 — OpenPLC v3sentinel16d ago[Denver] cyber 10.0 — OpenPLC v3sentinel16d ago[Denver] cyber 10.0 — Improve Router Hygiene to Protect Against Russian State-Sponsored Targetingsentinel17d ago[Denver] cyber 10.0 — CISA Adds Four Known Exploited Vulnerabilities to Catalogsentinel17d ago[Denver] cyber 10.0 — Improve Router Hygiene to Protect Against Russian State-Sponsored Targetingsentinel17d ago[Denver] cyber 10.0 — CISA Adds Four Known Exploited Vulnerabilities to Catalogsentinel17d ago[Denver] cyber 10.0 — Improve Router Hygiene to Protect Against Russian State-Sponsored Targetingsentinel17d ago[Denver] cyber 10.0 — Improve Router Hygiene to Protect Against Russian State-Sponsored Targetingsentinel17d ago

External Corroboration

✓ Corroborated · 5 sourcesChecked Jul 14, 2026, 01:01 AM UTC
Digi International PortServer TS, Digi One SP IA · CSIRTScsirts.comJul 7, 2026, 12:00 PM UTCChemical Facility Security News: 7 Advisories Published – 7-7-26chemical-facility-security-news.blogspot.comJul 13, 2026, 07:38 PM UTCCISA Warns Engineers: Proteus 9.1 SP4 Memory Bugs Expose Windows Workstations—Update Immediately - Windows Newswindowsnews.aiJul 7, 2026, 06:26 PM UTCCVE-2026-12948: CWE-79 Improper neutralization of input during web page generation ('cross-site scripting') in Digi International Digi PortServer TS - Live Threat Intelligence - Threat Radar | OffSeq.comradar.offseq.comJul 7, 2026, 02:32 PM UTC(TLP:CLEAR) CISA ICS Advisories, Additional Alerts, Updates, and Bulletins – July 9, 2026 - WaterISACwaterisac.orgJul 9, 2026, 06:30 PM UTC

Affected Regions

Denver