THREAT OPS › Threat News
Threat Intelligence News
11576 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [GHSA] GHSA-c476-6w5q-jw77 (high) — rclone: FTP cross-session auth-proxy backend confusiongithub_advisories · 2026-09-10
- [GHSA] GHSA-38xv-hf3p-h7mq (medium) — rclone: source object names can escape the configured root on uploadgithub_advisories · 2026-09-10
- [GHSA] GHSA-2p48-j3qc-rx9f (high) — rclone: S3 multipart declared-length memory exhaustiongithub_advisories · 2026-09-10
- [GHSA] GHSA-3g9q-v48f-hh9w (high) — Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logoutgithub_advisories · 2026-09-10
- [GHSA] GHSA-v39v-59xw-j98g (medium) — Open WebUI: Any authenticated user can suppress calendar alerts instance-wide via a non-numeric alert valuegithub_advisories · 2026-09-10
- [GHSA] GHSA-8r35-5x5r-hv74 (medium) — Open WebUI: Any authenticated user can start a non-terminating request via a folder parent cyclegithub_advisories · 2026-09-10
- [GHSA] GHSA-wjwr-xfp9-r66p (medium) — Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notesgithub_advisories · 2026-09-10
- [GHSA] GHSA-4qpv-39hg-f7fx (high) — @jhb.software/payload-alt-text-plugin: Alt Text Endpoint Authorization Bypass via Payload Local API `overrideAccess` Omissiongithub_advisories · 2026-09-10
- [GHSA] GHSA-4x45-gxvp-6283 (high) — @argos-ci/core: CI Branch Name OS Command Injectiongithub_advisories · 2026-09-10
- [NVD] CVE-2026-86093 (HIGH 7.5) — IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands on Db2 clients due to a stack-based buffer overflow that improperly copies user-controlled data into a nvd · 2026-09-10
- [NVD] CVE-2026-81941 (HIGH 8.8) — IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user could execute arbitrary operating system commands on the server at the privilege level of the application process by constructing a flow with an MCP Tools component configured to use a local stdnvd · 2026-09-10
- [NVD] CVE-2026-76059 (HIGH 8.8) — IBM Langflow OSS 1.0.0 through 1.11.5 An attacker who could submit custom component source code could bypass the static security scanner by crafting an annotated class-body assignment that resolved to a dangerous callable through alias tracking; the resolved value was never checknvd · 2026-09-10
- [GHSA] GHSA-m3wp-48jr-vr4g (high) — mistral.rs: Unbounded Remote Media Fetch and Video Frame Expansion DoSgithub_advisories · 2026-09-10
- [GHSA] GHSA-wfgq-w7cq-qj7j (high) — mistral.rs Media Loader: Unauthenticated SSRF and arbitrary local file read via image_urlgithub_advisories · 2026-09-10
- [Vexy Ransomware] i2k2 Networks posted to leak siteransomware_live · 2026-09-10
- [GHSA] GHSA-p78m-89r6-pgf7 (medium) — Open WebUI: A user's session cookies are sent to tool servers configured for bearer authenticationgithub_advisories · 2026-09-10
- [GHSA] GHSA-wpmr-8h3q-fwj7 (high) — Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLitegithub_advisories · 2026-09-10
- [GHSA] GHSA-hf57-cqmx-p4gr (critical) — OmniRoute ACP Custom-Agent Remote Code Execution (RCE)github_advisories · 2026-09-10
- [GHSA] GHSA-cw9w-vv67-hf73 (medium) — n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitutiongithub_advisories · 2026-09-10
- [GHSA] GHSA-q5wm-mgqx-fv2f (medium) — n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Contentgithub_advisories · 2026-09-10
- [NVD] CVE-2026-9176 (MEDIUM 6.7) — IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a security bypass due to improper authentication controls. A local attacker could exploit this vulnerability to escalate privileges and gain unauthorized access to protected resources.nvd · 2026-09-10
- [NVD] CVE-2026-85025 (CRITICAL 9.8) — IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and access or modify chat sessions through publicly shared MCP project endpoints due to improper enforcement of public-flow security restrictions and session isolationnvd · 2026-09-10
- [GHSA] GHSA-qgpw-8g46-w95v (medium) — n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository Readgithub_advisories · 2026-09-10
- [GHSA] GHSA-cqr2-h44g-v75v (medium) — n8n: Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Role Assignment Endpointsgithub_advisories · 2026-09-10
- [GHSA] GHSA-pq6c-vh67-xpm3 (medium) — n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Checkgithub_advisories · 2026-09-10
- [GHSA] GHSA-pf83-w3f9-8m37 (medium) — n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessionsgithub_advisories · 2026-09-10
- [GHSA] GHSA-5m98-cgcr-xx3q (medium) — n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Opengithub_advisories · 2026-09-10
- [GHSA] GHSA-f2cp-m7mv-8jpv (medium) — n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded Identifiersgithub_advisories · 2026-09-10
- [GHSA] GHSA-679f-58pq-4v2c (medium) — n8n: Prototype Pollution via Workflow Structure Summary Can Lead to Denial of Servicegithub_advisories · 2026-09-10
- [GHSA] GHSA-65xw-2v52-jhxc (medium) — n8n: Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId Filtergithub_advisories · 2026-09-10
- The Containment Tax: When OT Outages Aren't OT Attackszscaler_threatlabz · 2026-09-10
- [GHSA] GHSA-6xcw-7xm6-48c6 (high) — n8n: Expression Sandbox Escape via Shared Builtin Tampering and Code-Printer Injection Leads to Code Executiongithub_advisories · 2026-09-10
- [GHSA] GHSA-35jj-42hp-8gmq (medium) — n8n: Anonymous Approval-Gate Bypass via Reused resumeToken over the Chat WebSocketgithub_advisories · 2026-09-10
- [GHSA] GHSA-rf44-j88r-hh8c (medium) — Traefik: ForwardAuth identity spoofing via dot-form header aliasgithub_advisories · 2026-09-10
- [GHSA] GHSA-7ghq-v6jf-g56c (medium) — Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unboundedgithub_advisories · 2026-09-10
- [GHSA] GHSA-v3p8-whq6-r5jg (high) — Angular: SSR XSS via Unescaped <template> Content Across DocumentFragment Boundaries in Fallback Raw-Content Elementsgithub_advisories · 2026-09-10
- [GHSA] GHSA-f6mr-pjwc-34m4 (high) — Angular: SSRF and Cross-Origin Credential Disclosure via URL Resolution Discrepancy in SSRgithub_advisories · 2026-09-10
- [GHSA] GHSA-p297-fm68-3q8c (medium) — Angular: Information Leak via `HttpTransferCache` Bypass When Using `withRequestsMadeViaParent`github_advisories · 2026-09-10
- [GHSA] GHSA-hh8m-fm6v-7cvg (medium) — Angular: Sanitization bypass via directive host bindings on concrete host elements in @angular/core and @angular/compilergithub_advisories · 2026-09-10
- AL26-020 - Vulnerabilities Impacting MikroTik RouterOS - CVE-2026-67276, CVE-2026-67277 and CVE-2026-86060cccs_ca · 2026-09-10
- Tech Talk Recap: A Practitioner’s Guide to CRA Readinessopenssf_blog · 2026-09-10
- [GHSA] GHSA-23rh-xw42-fq82 (high) — Pimcore: SQL Injection in Custom Reports via Malicious Report Configurationgithub_advisories · 2026-09-10
- [AuditTeam] ki***jp posted to leak siteransomware_live · 2026-09-10
- [AuditTeam] my***ru posted to leak siteransomware_live · 2026-09-10
- Wordfence Intelligence Weekly WordPress Vulnerability Report (August 31, 2026 to September 6, 2026)wordfence · 2026-09-10
- [play] Sys-kool posted to leak siteransomware_live · 2026-09-10
- [play] Grunthal Welding & Supplies posted to leak siteransomware_live · 2026-09-10
- [lockbit5] alphaomega-eng.com posted to leak siteransomware_live · 2026-09-10
- The Modern Admin Experience Comes to GovCloudzscaler_threatlabz · 2026-09-10
- Follow the Money: The Financial Sector's Threat Landscape in 2026intel471 · 2026-09-10
- [rhysida] General Santos Doctors Hospital posted to leak siteransomware_live · 2026-09-10
- [rhysida] Professional Retail Services posted to leak siteransomware_live · 2026-09-10
- HPE security advisory (AV26-909)cccs_ca · 2026-09-10
- Re: AI slops from Eveoss_sec · 2026-09-10
- We've got one word for it, and it's usually the wrong onetalos · 2026-09-10
- ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Storiesthehackernews · 2026-09-10
- WebPros security advisory (AV26-908)cccs_ca · 2026-09-10
- Protecting organizations from AI-assisted executive impersonation and invoice fraudmsstic · 2026-09-10
- Group of Bipartisan Lawmakers Ask US Government to Ban Several Hack-for-Hire Firmscitizenlab · 2026-09-10
- Re: AI slops from Eveoss_sec · 2026-09-10
- [chaos] mankatoclinic.com posted to leak siteransomware_live · 2026-09-10
- Reduce AI Token Waste by Getting Decisions Right Earliersonatype · 2026-09-10
- [chaos] artiflexmfg.com posted to leak siteransomware_live · 2026-09-10
- [NVD] CVE-2026-4130 (HIGH 7.1) — There is a storage of sensitive information in cleartext vulnerability in NI SystemLink. This vulnerability may allow an attacker with local access to obtain sensitive information stored by the system in the clear. This vulnerability affects NI SystemLink and NI SystemLink Servenvd · 2026-09-10
- [NVD] CVE-2026-4129 (HIGH 8.1) — There is an improper access control vulnerability in NI SystemLink that may allow an authenticated user with limited privileges to access host operating system files and directories that should be restricted. This vulnerability affects NI SystemLink and NI SystemLink Server 2026 nvd · 2026-09-10
- Fixing the Leaks: An Examination of Zero Trust for Water Infrastructurezscaler_threatlabz · 2026-09-10
- Unmasking SCCM Application Executionspecterops · 2026-09-10
- Detect and disrupt AI-themed attacks with Microsoft Defendermsstic · 2026-09-10
- BlueMoon exploit kit turns Chrome and Windows flaws into attacksmalwarebytes_blog · 2026-09-10
- [NVD] CVE-2026-88924 (HIGH 7.0) — A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled directory. A local attacker can exploit this via a Tnvd · 2026-09-10
- [GHSA] GHSA-34ff-336r-5q23 (high) — n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model Nodegithub_advisories · 2026-09-10
- [GHSA] GHSA-j535-v25q-vx3q (high) — n8n: Regular Expression Denial of Service in the Default Blocked-File-Pattern Match via a Git Node Clone Pathgithub_advisories · 2026-09-10
- [GHSA] GHSA-hh89-3r9w-qj3j (high) — n8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpointgithub_advisories · 2026-09-10
- [GHSA] GHSA-hw8v-xxg5-vvvx (high) — n8n: Expression Sandbox Escape via Class-Field Sanitizer Rebinding Can Lead to Code Executiongithub_advisories · 2026-09-10
- [GHSA] GHSA-pcvc-8vrv-8q6w (medium) — Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backendsgithub_advisories · 2026-09-10
- [GHSA] GHSA-fmqh-xp37-5hr8 (medium) — Open WebUI: Channel members can overwrite another member's message via the chat completions endpointgithub_advisories · 2026-09-10
- [GHSA] GHSA-jmc6-2wr8-h3wj (high) — Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origingithub_advisories · 2026-09-10
- [GHSA] GHSA-4v28-j6q3-5m4r (high) — Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loadergithub_advisories · 2026-09-10
- [GHSA] GHSA-3pf7-q2g3-wj28 (medium) — Open WebUI: Any authenticated user can inject chats into another user's folder via chat completionsgithub_advisories · 2026-09-10
- [GHSA] GHSA-2724-6cpj-gf3v (high) — Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletiongithub_advisories · 2026-09-10
- [GHSA] GHSA-34r3-9m95-vq73 (high) — Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetchgithub_advisories · 2026-09-10
- [GHSA] GHSA-4qg5-cxx4-g927 (medium) — Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchangegithub_advisories · 2026-09-10
- [GHSA] GHSA-q5j5-6p94-4gwc (high) — Excelize: Streaming GetRows row-bound bypass causes attacker-controlled allocationgithub_advisories · 2026-09-10
- [GHSA] GHSA-fx5j-qcqg-grpf (medium) — Excelize: Negative shared-string index causes panic in GetCellValue and GetRowsgithub_advisories · 2026-09-10
- [GHSA] GHSA-x7m8-jrm8-hpvx (high) — @eigenpal/docx-editor-react: CSS injection and print-time XSS via unescaped embedded font-family namegithub_advisories · 2026-09-10
- SloppyRAT: A New Tool For Ransomware Attackszscaler_threatlabz · 2026-09-10
- Google Play Early Access Abused to Push Thousands of Deceptive Android Appsthehackernews · 2026-09-10
- PuzzleMask: Abusing Plain Prose as a Covert AI Attack Vectorcheckpoint_research · 2026-09-10
- CVE-2026-87464: RCE outside sandbox in Chromium prior to 153.0.8010.36oss_sec · 2026-09-10
- CVE-2026-80354: Apache Camel K: Camel K Builder trait mavenProfiles ValueSources resolve tenant-named secrets in operator namespaceoss_sec · 2026-09-10
- CVE-2026-80352: Apache Camel K: Camel K Master trait serviceAccountName YAML injection lets CR author apply arbitrary objectsoss_sec · 2026-09-10
- CVE-2026-80351: Apache Camel K: Camel K Tenant repositories reach Maven execution inside operator podoss_sec · 2026-09-10
- [Wallstreet] NcbChurch posted to leak siteransomware_live · 2026-09-10
- [Wallstreet] On Demand Occupational Medicine posted to leak siteransomware_live · 2026-09-10
- [Wallstreet] Goldston Oil Corporation posted to leak siteransomware_live · 2026-09-10
- [Control systems] Advantech security advisory (AV26-907)cccs_ca · 2026-09-10
- Beyond Tier Zerospecterops · 2026-09-10
- [incransom] jms building corporation posted to leak siteransomware_live · 2026-09-10
- The agentic harness for Tenable Hexa AI: How Tenable prevents AI agents from going off the railstenable · 2026-09-10
- 1.1.1.1 now supports post-quantum DNSSEC, all 2,420 bytes of itcloudflare_security · 2026-09-10