THREAT OPS › Threat News
Threat Intelligence News
11761 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- Re: A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpilloss_sec · 2026-09-19
- CVE-2026-82560: Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output widthoss_sec · 2026-09-19
- Re: Vulnerabilities in libheif and libde265oss_sec · 2026-09-19
- CVE-2026-78030: DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBMoss_sec · 2026-09-19
- [rhysida] Kreishandwerkerschaft Borken posted to leak siteransomware_live · 2026-09-19
- Identity Visibility in 2026: The Foundation of Identity Securitythehackernews · 2026-09-19
- Calling viral AI actress Tilly Norwood? Agree to a face scan firstbleepingcomputer · 2026-09-19
- Viral AI actress' hotline face-scans every caller, watches their moodbleepingcomputer · 2026-09-19
- [AuditTeam] td***up posted to leak siteransomware_live · 2026-09-19
- Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flawsthehackernews · 2026-09-19
- SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCEthehackernews · 2026-09-19
- Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wildthehackernews · 2026-09-19
- [Vexy Ransomware] Quy Nhon University posted to leak siteransomware_live · 2026-09-19
- Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Upthehackernews · 2026-09-19
- [emperador] Cassias MG Government posted to leak siteransomware_live · 2026-09-19
- CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositoriesthehackernews · 2026-09-19
- CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wildthehackernews · 2026-09-19
- Exim Security Release 4.100.1oss_sec · 2026-09-19
- Vulnerabilities in libheif and libde265oss_sec · 2026-09-18
- [anubis] Quest Group posted to leak siteransomware_live · 2026-09-18
- [Panzer] K3G Solutions Brazil posted to leak siteransomware_live · 2026-09-18
- [lockbit5] hygear.com posted to leak siteransomware_live · 2026-09-18
- [lockbit5] forus.cl posted to leak siteransomware_live · 2026-09-18
- Friday Squid Blogging: On Squid Egg Sacsschneier · 2026-09-18
- [play] Vista Plastic Solutions posted to leak siteransomware_live · 2026-09-18
- [play] Inglewood Golf posted to leak siteransomware_live · 2026-09-18
- [play] Barrett Mahony Consulting Engineers posted to leak siteransomware_live · 2026-09-18
- [Spirals] PITTSRAD posted to leak siteransomware_live · 2026-09-18
- [N0n] Inter (Venezuela's largest internet provider) posted to leak siteransomware_live · 2026-09-18
- Wordfence Argus Discovers Critical Vulnerability in libheif, the Library That Opens iPhone Photos on Your Serverwordfence · 2026-09-18
- When AI Agents Go Rogue- What the OpenAI–Hugging Face Incident Teaches Us About Workload Zero Trustzscaler_threatlabz · 2026-09-18
- Public Exploits Released for Four Linux Kernel Flaws That Enable Local Rootthehackernews · 2026-09-18
- [GHSA] GHSA-jgh3-fggc-mcpm (high) — Obot: Server-Side Request Forgery via remote MCP server URLgithub_advisories · 2026-09-18
- [GHSA] GHSA-pr6h-vr44-xq8j (medium) — Obot: MCP Registry API readable without authenticationgithub_advisories · 2026-09-18
- [GHSA] GHSA-xwmw-prc4-v3cr (high) — Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusiongithub_advisories · 2026-09-18
- Re: A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpilloss_sec · 2026-09-18
- [GHSA] GHSA-5gmm-hjfj-8ff7 (medium) — Paymenter has a credit-refund double-spend race condition in service downgrade (doUpgrade)github_advisories · 2026-09-18
- [GHSA] GHSA-9jjc-fw8x-fmwx (high) — io.moquette:moquette-broker has a Missing Authorization issuegithub_advisories · 2026-09-18
- [GHSA] GHSA-xcw4-53cc-hv32 (critical) — Mnemosyne has JWT signature verification bypass sync server that allows authentication bypassgithub_advisories · 2026-09-18
- [Control systems] ABB security advisory (AV26-942)cccs_ca · 2026-09-18
- [Gammax] Premier Lighting & Controls posted to leak siteransomware_live · 2026-09-18
- SolarWinds security advisory (AV26-941)cccs_ca · 2026-09-18
- [GHSA] GHSA-vr5f-w35q-98jp (high) — Perses's unvalidated project parameter enables filesystem path traversalgithub_advisories · 2026-09-18
- [GHSA] GHSA-4227-9989-jrhx (high) — Perses's missing authorization in datasource proxy allows cross-scope secret disclosuregithub_advisories · 2026-09-18
- [GHSA] GHSA-cjgj-2fwf-4c2w (high) — Perses's project query parameter authorization bypass exposes cross-project resourcesgithub_advisories · 2026-09-18
- Arista Networks security advisory (AV26-940)cccs_ca · 2026-09-18
- [GHSA] GHSA-3753-m2x2-q623 (high) — File Viewer: DOM XSS via unsafe hyperlink schemes in the legacy DOC renderergithub_advisories · 2026-09-18
- [GHSA] GHSA-7q85-xj36-vmfc (high) — adm-zip: Uncontrolled memory allocation via the declared uncompressed size (DoS)github_advisories · 2026-09-18
- [GHSA] GHSA-5gm3-9crp-6g3v (medium) — Process Compose: Browser DNS rebinding lets websites control local process-compose MCP toolsgithub_advisories · 2026-09-18
- [GHSA] GHSA-p5vg-v7mj-f6q4 (high) — Convoy: Cross-Tenant Source IDOR Leaks Plaintext Message Broker Credentialsgithub_advisories · 2026-09-18
- [GHSA] GHSA-3rm2-h79c-8qw6 (medium) — md-editor-v3: XSS via fenced-code language rendering bypassgithub_advisories · 2026-09-18
- [GHSA] GHSA-w72w-9qmj-c9qm (medium) — AnyCable: Telemetry Subsystem Contains Hardcoded Authentication Token and Transmits CLI Arguments Including Secretsgithub_advisories · 2026-09-18
- [GHSA] GHSA-3w57-8xmc-8v26 (high) — AnyIO run_process/open_process ignores extra_groups and can retain parent supplementary groupsgithub_advisories · 2026-09-18
- [GHSA] GHSA-82r6-8w77-94w6 (critical) — AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofinggithub_advisories · 2026-09-18
- [GHSA] GHSA-5p39-cfhj-2xmp (medium) — AnyIO process-pool workers can block indefinitely on undrained stderrgithub_advisories · 2026-09-18
- [GHSA] GHSA-5p54-whvp-x327 (medium) — AnyCable: Pusher REST API Does Not Verify Request Body MD5 Enabling Signed-Request Replay with Arbitrary Bodygithub_advisories · 2026-09-18
- [GHSA] GHSA-qg2g-g9w3-m5h8 (high) — ToolHive: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movementgithub_advisories · 2026-09-18
- [GHSA] GHSA-c8w2-fgvx-vhv4 (critical) — kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspacegithub_advisories · 2026-09-18
- [GHSA] GHSA-qg67-7m6v-qg25 (high) — zot: Bearer authentication maps DELETE to push scope, allowing unauthorized deletiongithub_advisories · 2026-09-18
- [GHSA] GHSA-f94q-w3w8-cj67 (medium) — Capsule: hostnameRegexHandler.OnUpdate validates stale (old) Tenant regex, allowing invalid AllowedHostnames regex to bypass webhook validationgithub_advisories · 2026-09-18
- [GHSA] GHSA-gjw4-3v3v-rqxg (high) — Capsule: Tenant owner bypasses Capsule's forbidden namespace/service/node label and annotation enforcementgithub_advisories · 2026-09-18
- [GHSA] GHSA-gxjc-74v5-3vx3 (medium) — Capsule: Malformed ForbiddenAnnotations.Regex can bypass Tenant validation and trigger namespace admission panicgithub_advisories · 2026-09-18
- [GHSA] GHSA-39wr-7q6h-cf68 (high) — LMDeploy has an SSRF bypassgithub_advisories · 2026-09-18
- [GHSA] GHSA-3hmm-rh5q-gwwr (high) — LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loadinggithub_advisories · 2026-09-18
- [GHSA] GHSA-2vh9-42vm-xmv2 (critical) — LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.pygithub_advisories · 2026-09-18
- Don’t Call Us, We’ll Call Your APIs | TraderTraitor Backdoors Resurface on Victim With No Crypto Tiessentinelone · 2026-09-18
- [GHSA] GHSA-jr78-w6w5-m8f8 (high) — Semantic MediaWiki'a missing authorization in the smwtask API module allows unauthenticated access to admin-only maintenance tasksgithub_advisories · 2026-09-18
- [GHSA] GHSA-9rcc-pmj8-ffhr (medium) — Semantic MediaWiki's Special:FacetedSearch cstate hidden inputs enable reflected XSS (residual of CVE-2025-10354)github_advisories · 2026-09-18
- [GHSA] GHSA-cx86-7xwp-w9wf (medium) — Semantic MediaWiki affected by reflected XSS in `Special:Ask` via a forged cursor pagination tokengithub_advisories · 2026-09-18
- New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Executionthehackernews · 2026-09-18
- [GHSA] GHSA-q5fm-9mx6-44f4 (medium) — Semantic MediaWiki has a query debug output XSS (`DebugFormatter`)github_advisories · 2026-09-18
- [GHSA] GHSA-hw3m-8j5x-94ff (medium) — Semantic MediaWiki has an open redirect in Special:URIResolvergithub_advisories · 2026-09-18
- [GHSA] GHSA-7xv3-gf2g-498h (medium) — Semantic MediaWiki affected by Special:Ask table `sep` parameter reflected XSSgithub_advisories · 2026-09-18
- [GHSA] GHSA-59xw-qv23-j3rc (medium) — Semantic MediaWiki has reflected XSS in `Special:SearchByProperty` (`property` and `value` parameters)github_advisories · 2026-09-18
- [GHSA] GHSA-3jp5-3h47-28qf (medium) — Semantic MediaWiki has reflected XSS in Special:Ask plain table headersgithub_advisories · 2026-09-18
- CVE-2026-91867: Apache Neethi: Remote policy fetch lacks a total timeout, allowing a slow server to hang the request indefinitelyoss_sec · 2026-09-18
- CVE-2026-91866: Apache Neethi: Crafted policies cause unbounded work during intersection leading to denial of serviceoss_sec · 2026-09-18
- CVE-2026-91865: Apache Neethi: Crafted policy references cause exponential expansion during normalization leading to denial of serviceoss_sec · 2026-09-18
- CVE-2026-91864: Apache Neethi: Crafted WS-Policy documents bypass element/attribute limits causing memory exhaustionoss_sec · 2026-09-18
- CVE-2026-91863: Apache Neethi: Uncontrolled recursion while parsing crafted WS-Policy documents allows denial of serviceoss_sec · 2026-09-18
- CVE-2026-93019: Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_readoss_sec · 2026-09-18
- How Kyocera AVX Built a Global Security Validation Program from Zerohorizon3 · 2026-09-18
- CVE-2026-93018: Imager versions before 1.036 for Perl disclose uninitialised heap memory reading a paletted image with pixel indexes past its colour map in i_gpix_p and i_glin_poss_sec · 2026-09-18
- Re: Removing dead code (was: Retrospective by 'gpg.fail' authors)oss_sec · 2026-09-18
- [GHSA] GHSA-hg8h-557g-q8pp (high) — Semantic MediaWiki vulnerable to stored XSS through wikitext via improper use of non-reserved data attributesgithub_advisories · 2026-09-18
- Re: A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpilloss_sec · 2026-09-18
- Re: A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpilloss_sec · 2026-09-18
- [AuditTeam] Paid Victim 192EB2B6AD7B98D9 posted to leak siteransomware_live · 2026-09-18
- [securotrop] Prefix Corp posted to leak siteransomware_live · 2026-09-18
- Google security advisory (AV26-939)cccs_ca · 2026-09-18
- New Android malware uses AI to steal bank logins and PINsmalwarebytes_blog · 2026-09-18
- [N0n] PayPal support operations (Transcom WorldWide) posted to leak siteransomware_live · 2026-09-18
- [N0n] Ministry of Education — Argentina posted to leak siteransomware_live · 2026-09-18
- [N0n] Argentem Creek Partners (investment firm) posted to leak siteransomware_live · 2026-09-18
- [N0n] AstraZeneca Türkiye posted to leak siteransomware_live · 2026-09-18
- [N0n] STOKR (digital securities platform) posted to leak siteransomware_live · 2026-09-18
- [N0n] Konnatus (usucapião legal services) posted to leak siteransomware_live · 2026-09-18
- [Control Systems] Moxa security advisory (AV26-938)cccs_ca · 2026-09-18
- Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2thehackernews · 2026-09-18
- [N0n] BeLi Teacher / FSC education centers (AWS) posted to leak siteransomware_live · 2026-09-18
Page 1 of 118Older →