THREAT OPS › Threat News
Threat Intelligence News
12154 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [NVD] CVE-2026-42043 (HIGH 7.2) — Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axios request can use any address in the 127.0.0.0/8 range (other than 127.0.0.1) to completely bypass the NO_PROXY protection. This vunvd · 2026-04-24
- [NVD] CVE-2026-42041 (MEDIUM 4.8) — Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution to silently suppress all HTTP error responses (401, 403, 500, etc.), cnvd · 2026-04-24
- [NVD] CVE-2026-42039 (HIGH 7.5) — Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, toFormData recursively walks nested objects with no depth limit, so a deeply nested value passed as request data crashes the Node.js process with a RangeError. This vulnerability is fixenvd · 2026-04-24
- [NVD] CVE-2026-42033 (HIGH 7.4) — Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when Object.prototype has been polluted by any co-dependency with keys that axios reads without a hasOwnProperty guard, an attacker can (a) silently intercept and modify every JSON responvd · 2026-04-24
- [NVD] CVE-2026-30368 (MEDIUM 5.4) — A client-side authorization flaw in Lightspeed Systems Classroom v5.1.2.1763770643 allows unauthenticated attackers to impersonate users by bypassing integrity checks and abusing client-generated authorization tokens, leading to unauthorized control and monitoring of student devinvd · 2026-04-24
- [NVD] CVE-2026-31663 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: xfrm: hold dev ref until after transport_finish NF_HOOK After async crypto completes, xfrm_input_resume() calls dev_put() immediately on re-entry before the skb reaches transport_finish. The skb->dev pointer isnvd · 2026-04-24
- [NVD] CVE-2026-31641 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix RxGK token loading to check bounds rxrpc_preparse_xdr_yfs_rxgk() reads the raw key length and ticket length from the XDR token as u32 values and passes each through round_up(x, 4) before using the ronvd · 2026-04-24
- [NVD] CVE-2026-31617 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_ncm: validate minimum block_len in ncm_unwrap_ntb() The block_len read from the host-supplied NTB header is checked against ntb_max but has no lower bound. When block_len is smaller than opts->ndnvd · 2026-04-24
- [NVD] CVE-2026-31607 (CRITICAL 9.8) — In the Linux kernel, the following vulnerability has been resolved: usbip: validate number_of_packets in usbip_pack_ret_submit() When a USB/IP client receives a RET_SUBMIT response, usbip_pack_ret_submit() unconditionally overwrites urb->number_of_packets from the network PDU. nvd · 2026-04-24
- Cisco ACI Multi-Site CloudSec Encryption Information Disclosure Vulnerabilitycisco_psirt · 2026-04-24
- [NVD] CVE-2026-21728 (HIGH 7.5) — Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy. Mitigation can be done by setting max_result_limit in the search config, e.g. to 262144 (2^18). Alternatively, automaticallynvd · 2026-04-24
- [NVD] CVE-2026-5428 (MEDIUM 6.4) — The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image captions in the Image Grid/Slider/Carousel widget in versions up to and including 1.7.1056. This is due to insufficient output escaping in the render_post_thumbnail() function, nvd · 2026-04-24
- [NVD] CVE-2026-5488 (MEDIUM 5.3) — The ExactMetrics – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 9.1.2. This is due to missing capability checks in the get_ads_access_token() and reset_experience() AJAX handlers. While the minvd · 2026-04-24
- [NVD] CVE-2026-41316 (HIGH 8.1) — ERB is a templating system for Ruby. Ruby 2.7.0 (before ERB 2.2.0 was published on rubygems.org) introduced an `@_init` instance variable guard in `ERB#result` and `ERB#run` to prevent code execution when an ERB object is reconstructed via `Marshal.load` (deserialization). Howevenvd · 2026-04-24
- From Overwhelmed to Autonomous: Rethinking Threat Intelligence in 2026recordedfuture · 2026-04-24
- [Breach] Udemy — 1,401,259 accounts exposedhibp_breaches · 2026-04-24
- [NVD] CVE-2026-6732 (MEDIUM 6.5) — A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit this by providing a malicious document, leading to a type connvd · 2026-04-23
- AI threats in the wild: The current state of prompt injections on the webgoogle_security · 2026-04-23
- [NVD] CVE-2026-33694 (HIGH 7.8) — This vulnerability allows an attacker to create a junction, enabling the deletion of arbitrary files with SYSTEM privileges. As a result, this condition potentially facilitates arbitrary code execution, whereby an attacker may exploit the vulnerability to execute malicious code wnvd · 2026-04-23
- MSSQLHound Now Available in Gospecterops · 2026-04-23
- Microsoft Vibing — capturing screenshots and voice samples without governancedoublepulsar · 2026-04-23
- CVE-2026-33824: Remote Code Execution in Windows IKEv2zdi_blog · 2026-04-23
- Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suitemandiant_gti · 2026-04-23
- Trailmark turns code into graphstrailofbits · 2026-04-23
- Critical minerals and cyber operationsrecordedfuture · 2026-04-23
- Today, trust is the superpower that makes innovation possiblerecordedfuture · 2026-04-23
- [NVD] CVE-2026-41134 (HIGH 7.8) — Kiota is an OpenAPI based HTTP Client code generator. Versions prior to 1.29.1 and 1.31.1 are affected by a code-generation literal injection vulnerability in multiple writer sinks (for example: serialization/deserialization keys, path/query parameter mappings, URL template metadnvd · 2026-04-22
- Cisco Integrated Management Controller Cross-Site Scripting Vulnerabilitiescisco_psirt · 2026-04-22
- SpecterOps Selected for OpenAI’s Trusted Access for Cyber Programspecterops · 2026-04-22
- Cisco Integrated Management Controller Command Injection and Remote Code Execution Vulnerabilitiescisco_psirt · 2026-04-22
- Cisco Catalyst SD-WAN Vulnerabilitiescisco_psirt · 2026-04-22
- Bissa Scanner Exposed: AI-Assisted Mass Exploitation and Credential Harvestingdfirreport · 2026-04-22
- [NVD] CVE-2026-6862 (MEDIUM 5.5) — A flaw was found in libefiboot, a component of efivar. The device path node parser in libefiboot fails to validate that each node's Length field is at least 4 bytes, which is the minimum size for an EFI (Extensible Firmware Interface) device path node header. A local user could envd · 2026-04-22
- [NVD] CVE-2026-31449 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: ext4: validate p_idx bounds in ext4_ext_correct_indexes ext4_ext_correct_indexes() walks up the extent tree correcting index entries when the first extent in a leaf is modified. Before accessing path[k].p_idx->nvd · 2026-04-22
- [NVD] CVE-2026-6857 (HIGH 7.5) — A flaw was found in camel-infinispan. This vulnerability involves unsafe deserialization in the ProtoStream remote aggregation repository. A remote attacker with low privileges could exploit this by sending specially crafted data, leading to arbitrary code execution. This allows nvd · 2026-04-22
- [NVD] CVE-2026-6846 (HIGH 7.8) — A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrnvd · 2026-04-22
- [NVD] CVE-2026-6845 (MEDIUM 5.0) — A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. The exploitation of this flaw cnvd · 2026-04-22
- [NVD] CVE-2026-6844 (MEDIUM 5.5) — A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource exhaustion (CWE-400), can lead tnvd · 2026-04-22
- [NVD] CVE-2026-6843 (MEDIUM 5.5) — A flaw was found in nano. A local user could exploit a format string vulnerability in the `statusline()` function. By creating a directory with a name containing `printf` specifiers, the application attempts to display this name, leading to a segmentation fault (SEGV). This resulnvd · 2026-04-22
- [NVD] CVE-2026-6235 (CRITICAL 9.8) — The Sendmachine for WordPress plugin for WordPress is vulnerable to authorization bypass via the 'manage_admin_requests' function in all versions up to, and including, 1.0.20. This is due to the plugin not properly verifying that a user is authorized to perform an action. This manvd · 2026-04-22
- [NVD] CVE-2026-31431 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the sonvd · 2026-04-22
- [NVD] CVE-2026-6842 (LOW 2.5) — A flaw was found in nano. In environments with permissive umask settings, a local attacker can exploit incorrect directory permissions (0777 instead of 0700) for the `~/.local` directory. This allows the attacker to inject a malicious `.desktop` launcher, which could lead to uninnvd · 2026-04-22
- [NVD] CVE-2026-40542 (HIGH 7.3) — Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification. Users are recommended to upgrade to version 5.6.1, which fixes this issue.nvd · 2026-04-22
- Evolution of Chinese-Language Guarantee Telegram Marketplacesrecordedfuture · 2026-04-22
- AI Hype vs. Reality: Is AI Really Rewriting the Vulnerability Equation?recordedfuture · 2026-04-22
- [NVD] CVE-2026-40938 (HIGH 7.5) — Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, the git resolver's revision parameter is passed directly as a positional argument to git fetch withounvd · 2026-04-21
- [NVD] CVE-2026-40895 (HIGH 7.5) — follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. Prior to 1.16.0, when an HTTP request follows a cross-domain redirect (301/302/307/308), follow-redirects only strips authorization, proxy-authorizanvd · 2026-04-21
- [NVD] CVE-2026-35244 (MEDIUM 5.2) — Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Lifecycle Management). The supported version that is affected is 11.2.24.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP tonvd · 2026-04-21
- [NVD] CVE-2026-34282 (HIGH 7.5) — Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 8u481-perf, 11.0.30, 17.0.18, 21.0.10, 25.0.2, 26; Oracle GraalVM for JDK: 1nvd · 2026-04-21
- [NVD] CVE-2026-22016 (HIGH 7.5) — Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 8u481, 8u481-b50, 8u481-perf, 11.0.30, 17.0.18, 21.0.10, 25.0.2, 26; Oracle GraalVnvd · 2026-04-21
- The Vercel Breach Explains Why Identity Attack Path Management Can’t Waitspecterops · 2026-04-21
- [NVD] CVE-2026-3298 — The method "sock_recvfrom_into()" of "asyncio.ProacterEventLoop" (Windows only) was missing a boundary check for the data buffer when using nbytes parameter. This allowed for an out-of-bounds buffer write if data was larger than the buffer size. Non-Windows platforms are not affenvd · 2026-04-21
- Emerging Enterprise Security Risks of AIrecordedfuture · 2026-04-21
- The Cost of Understanding: LLM-Driven Reverse Engineering vs Iterative LLM Obfuscationelastic_security · 2026-04-21
- [NVD] CVE-2026-41245 (MEDIUM 5.9) — Junrar is an open source java RAR archive library. Prior to version 7.5.10, a path traversal vulnerability in `LocalFolderExtractor` allows an attacker to write arbitrary files with attacker-controlled content into sibling directories when a crafted RAR archive is extracted. Versnvd · 2026-04-20
- [Breach] Canada Life — 237,810 accounts exposedhibp_breaches · 2026-04-20
- [Breach] Aman — 215,563 accounts exposedhibp_breaches · 2026-04-20
- [Breach] Pitney Bowes — 8,243,989 accounts exposedhibp_breaches · 2026-04-20
- [Breach] ADT — 5,488,888 accounts exposedhibp_breaches · 2026-04-20
- Update: cut-bytes.py Version 0.0.18didier_stevens · 2026-04-19
- [NVD] CVE-2026-41242 (CRITICAL 9.8) — protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the "type" fields of protobuf definitions, which will then execute during object decoding using that definition. Versions 8.0.1 annvd · 2026-04-18
- [Breach] Carnival — 7,531,359 accounts exposedhibp_breaches · 2026-04-18
- Breaking Opus 4.7 with ChatGPT (Hacking Claude's Memory)embracethered · 2026-04-17
- [NVD] CVE-2026-40478 (CRITICAL 9.0) — Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the the expression execution mechanisms. Although the library provides mechanisms to prevent expression injection, it fnvd · 2026-04-17
- [NVD] CVE-2026-40476 (HIGH 7.5) — graphql-go is a Go implementation of GraphQL. In versions 15.31.4 and below, the OverlappingFieldsCanBeMerged validation rule performs O(n²) pairwise comparisons of fields sharing the same response name. An attacker can send a query with thousands of repeated identical fields, canvd · 2026-04-17
- [NVD] CVE-2026-40293 (MEDIUM 6.5) — OpenFGA is an authorization/permission engine built for developers. In versions 0.1.4 through 1.13.1, when OpenFGA is configured to use preshared-key authentication with the built-in playground enabled, the local server includes the preshared API key in the HTML response of the /nvd · 2026-04-17
- [NVD] CVE-2026-6492 (MEDIUM 5.3) — A vulnerability was detected in arnobt78 Hotel Booking Management System up to f8922d0e0f6ac1cc761974c7616f44c2bbc04bea. The impacted element is an unknown function of the file /api/health/detailed of the component Health Check Endpoint. Performing a manipulation results in infornvd · 2026-04-17
- [NVD] CVE-2026-6507 (HIGH 7.5) — A flaw was found in dnsmasq. A remote attacker could exploit an out-of-bounds write vulnerability by sending a specially crafted BOOTREPLY (Bootstrap Protocol Reply) packet to a dnsmasq server configured with the `--dhcp-split-relay` option. This can lead to memory corruption, canvd · 2026-04-17
- We beat Google’s zero-knowledge proof of quantum cryptanalysistrailofbits · 2026-04-17
- 4 Essential Integration Workflows for Operationalizing Threat Intelligence Recorded Futurerecordedfuture · 2026-04-17
- [NVD] CVE-2026-35469 (MEDIUM 6.5) — spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocating memory. Three allocation paths are affected: the SETTINGS frame entry count, nvd · 2026-04-16
- Cisco Webex Services Certificate Validation Vulnerabilitycisco_psirt · 2026-04-16
- Into The Rainbow: Google’s NTLMv1 Rainbow Tables Explained in a Bit Too Much Detailspecterops · 2026-04-16
- VirusTotal Inside the Agent Loopvirustotal_blog · 2026-04-16
- Defending Your Enterprise When AI Models Can Find Vulnerabilities Faster Than Evermandiant_gti · 2026-04-16
- [NVD] CVE-2026-31843 (CRITICAL 9.8) — The goodoneuz/pay-uz Laravel package (<= 2.2.24) contains a critical vulnerability in the /payment/api/editable/update endpoint that allows unauthenticated attackers to overwrite existing PHP payment hook files. The endpoint is exposed via Route::any without authentication middlenvd · 2026-04-16
- Cisco Secure Web Appliance Authentication Bypass Vulnerabilitycisco_psirt · 2026-04-16
- [NVD] CVE-2026-41035 (HIGH 7.4) — In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are nvd · 2026-04-16
- [NVD] CVE-2026-3885 (MEDIUM 6.4) — The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'su_box' shortcode in all versions up to, and including, 7.4.9 due to insufficient input sanitization and output escaping on user supplied attributes.nvd · 2026-04-16
- [NVD] CVE-2026-1880 — An Incorrect Permission Assignment for Critical Resource vulnerability in the ASUS DriverHub update process allows privilege escalation due to improper protection of required execution resources during the validation phase, permitting a local user to make unprivileged modificationvd · 2026-04-16
- [NVD] CVE-2026-40192 (HIGH 7.5) — Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leadinvd · 2026-04-15
- [NVD] CVE-2026-21727 (LOW 3.3) — A cross-tenant isolation vulnerability was found in Grafana’s Correlations feature affecting legacy correlation records. Due to a backward compatibility condition allowing org_id = 0 records to be returned across organizations, a user with datasource management privileges could rnvd · 2026-04-15
- [NVD] CVE-2025-41118 (CRITICAL 9.1) — Pyroscope is an open-source continuous profiling database. The database supports various storage backends, including Tencent Cloud Object Storage (COS). If the database is configured to use Tencent COS as the storage backend, an attacker could extract the secret_key configurationvd · 2026-04-15
- [NVD] CVE-2026-6245 (MEDIUM 5.5) — A flaw was found in the System Security Services Daemon (SSSD). The pam_passkey_child_read_data() function within the PAM passkey responder fails to properly handle raw bytes received from a pipe. Because the data is treated as a NUL-terminated C string without explicit terminatinvd · 2026-04-15
- [NVD] CVE-2026-5189 (CRITICAL 9.8) — CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unauthenticated attacker with network access to gain unauthorized read/write access to the internal database and execute arbitrary OS commands as the Nexus process nvd · 2026-04-15
- [NVD] CVE-2026-34632 (HIGH 8.6) — Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in the context of the current user. An attacker could have exploited this vulnerability by placing a malicious library in a directory snvd · 2026-04-15
- Cisco Identity Services Engine Remote Code Execution Vulnerabilitiescisco_psirt · 2026-04-15
- Cisco Identity Services Engine Authenticated Privilege Escalation Vulnerabilitycisco_psirt · 2026-04-15
- Cisco Identity Services Engine Multiple Cross-Site Scripting Vulnerabilitiescisco_psirt · 2026-04-15
- Cisco ThousandEyes Enterprise Agent Arbitrary File Overwrite Vulnerabilitycisco_psirt · 2026-04-15
- Cisco Unity Connection Arbitrary File Download Vulnerabilitiescisco_psirt · 2026-04-15
- Cisco Unity Connection Cross-Site Scripting, Open Redirect, and SQL Injection Vulnerabilitiescisco_psirt · 2026-04-15
- Cisco Webex Contact Center Cross-Site Scripting Vulnerabilitycisco_psirt · 2026-04-15
- What’s New in the BloodHound Query Library: BYOL, OpenGraph, Multi-Server, and Morespecterops · 2026-04-15
- The German Cyber Criminal Überfall: Shifts in Europe's Data Leak Landscapemandiant_gti · 2026-04-15
- [NVD] CVE-2026-0827 (HIGH 7.1) — During an internal security assessment, a potential vulnerability was discovered in Lenovo Diagnostics and the HardwareScanAddin used in Lenovo Vantage that, during installation or when using hardware scan, could allow a local authenticated user to perform an arbitrary file writenvd · 2026-04-15
- [NVD] CVE-2026-5598 (HIGH 7.5) — Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules). This vulnerability is associated with program files FrodoEngine.Java. This issue affects BC-JAVA: from 1.71 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.nvd · 2026-04-15
- [NVD] CVE-2026-5588 (HIGH 7.5) — Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all (pkix modules), Legion of the Bouncy Castle Inc. BCPKIX-FIPS bcpkix on All (pkix modules), Legion of the Bouncy Castle Inc. BCPIX-LTS bcpkix on All (pkix modulnvd · 2026-04-15
- [NVD] CVE-2026-3505 (HIGH 7.5) — Allocation of resources without limits or throttling, Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpg on all (pg modules). This vulnerability is associated with program files AEADEncDataPacket.Java, BcAEADUtil.Java, JceAEADUtil.Jnvd · 2026-04-15
- [NVD] CVE-2026-0636 (MEDIUM 6.5) — Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (prov modules). This vulnerability is associated with program files LDAPStoreHelper. This issue affects BC-JAVA: from nvd · 2026-04-15