THREAT OPS › Threat News
Threat Intelligence News
11578 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- 1.1.1.1 now supports post-quantum DNSSEC, all 2,420 bytes of itcloudflare_security · 2026-09-10
- Casbaneiro: A Banking Trojan with Distributed Data-Receiving Serversfortinet_research · 2026-09-10
- [akira] AK Stamping posted to leak siteransomware_live · 2026-09-10
- [akira] Eagle Construction posted to leak siteransomware_live · 2026-09-10
- [akira] George Cameron Nash posted to leak siteransomware_live · 2026-09-10
- Fortra security advisory (AV26-906)cccs_ca · 2026-09-10
- Cyble Introduces Major Upgrade to its Executive Monitoring Modulecyble · 2026-09-10
- Will AI kill us all within the next decade?malwarebytes_blog · 2026-09-10
- ShieldCrash PoC: Microsoft Defender Fix Bypasssocradar_blog · 2026-09-10
- Palo Alto Networks security advisory (AV26-905)cccs_ca · 2026-09-10
- Orthanc DICOM Servercisa_advisories · 2026-09-10
- NextGen Healthcare Mirth Connectcisa_advisories · 2026-09-10
- CISA Adds Two Known Exploited Vulnerabilities to Catalogcisa_advisories · 2026-09-10
- ST Engineering iDirect iQ-Series Terminals (Update A)cisa_advisories · 2026-09-10
- AVEVA Pipeline Integrity Monitorcisa_advisories · 2026-09-10
- Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCEthehackernews · 2026-09-10
- PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instancesthehackernews · 2026-09-10
- Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checksthehackernews · 2026-09-10
- Update Chrome now to protect against an actively exploited vulnerabilitymalwarebytes_blog · 2026-09-10
- [emperador] EASY JOB S.A.S. posted to leak siteransomware_live · 2026-09-10
- From Infostealer Log to Marketplace Listing: A Technical Walkthrough of the Credential Theft Pipelinecyble · 2026-09-10
- AIs Compress Exploit Timelineschneier · 2026-09-10
- CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadlinethehackernews · 2026-09-10
- [clop] HENRYPRATT.COM posted to leak siteransomware_live · 2026-09-10
- [clop] HARLEY-DAVIDSON.COM posted to leak siteransomware_live · 2026-09-10
- 2026-012: Critical Vulnerabilities in Check Point Productscert_eu · 2026-09-10
- The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIREunit42 · 2026-09-10
- Copyright scammers get Instagram accounts suspended and demand paymentmalwarebytes_blog · 2026-09-10
- What Is ISPM? How It Differs from IAM, PAM, IGA, and IDaaSqualys · 2026-09-10
- Open by Default After AI: The GDS Guidance and the Enforcement Questionopenssf_blog · 2026-09-10
- Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Keythehackernews · 2026-09-10
- Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6thehackernews · 2026-09-10
- [ShadowByt3$] John Engel Team posted to leak siteransomware_live · 2026-09-10
- ZDI-26-679: Adobe Photoshop DCM JPEG Image Parsing Integer Overflow Remote Code Execution Vulnerabilityzdi_published · 2026-09-10
- ZDI-26-678: Adobe Photoshop DCM File Parsing Integer Overflow Remote Code Execution Vulnerabilityzdi_published · 2026-09-10
- ZDI-26-677: Adobe Photoshop DCM JPEG-LS Image Parsing Integer Overflow Remote Code Execution Vulnerabilityzdi_published · 2026-09-10
- ZDI-26-676: Adobe Acrobat Reader DC DigSig Use-After-Free Remote Code Execution Vulnerabilityzdi_published · 2026-09-10
- ZDI-26-675: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerabilityzdi_published · 2026-09-10
- ZDI-26-674: Adobe Acrobat Reader DC Annotation Out-Of-Bounds Write Remote Code Execution Vulnerabilityzdi_published · 2026-09-10
- ZDI-26-673: Adobe Acrobat Pro DC Doc Object Use-After-Free Remote Code Execution Vulnerabilityzdi_published · 2026-09-10
- ZDI-26-672: Adobe Acrobat Reader DC PDF File Parsing Integer Underflow Information Disclosure Vulnerabilityzdi_published · 2026-09-10
- ZDI-26-671: Adobe Acrobat Reader DC Dialog Object Type Confusion Remote Code Execution Vulnerabilityzdi_published · 2026-09-10
- ZDI-26-670: Adobe Acrobat Pro DC Doc Object Out-Of-Bounds Read Information Disclosure Vulnerabilityzdi_published · 2026-09-10
- ZDI-26-669: Adobe Acrobat Reader DC JBIG2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerabilityzdi_published · 2026-09-10
- ZDI-26-668: Adobe Acrobat Reader DC Annotation Use-After-Free Information Disclosure Vulnerabilityzdi_published · 2026-09-10
- ZDI-26-667: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerabilityzdi_published · 2026-09-10
- ZDI-26-666: Adobe Acrobat Reader DC JPEG2000 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerabilityzdi_published · 2026-09-10
- ZDI-26-665: Adobe Acrobat Reader DC Annots Report Use-After-Free Remote Code Execution Vulnerabilityzdi_published · 2026-09-10
- ZDI-26-664: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerabilityzdi_published · 2026-09-10
- ZDI-26-663: Adobe Acrobat Pro DC Annotation Use-After-Free Remote Code Execution Vulnerabilityzdi_published · 2026-09-10
- ZDI-26-662: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerabilityzdi_published · 2026-09-10
- ZDI-26-661: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerabilityzdi_published · 2026-09-10
- ZDI-26-660: Adobe Acrobat Reader DC Font Parsing Use-After-Free Information Disclosure Vulnerabilityzdi_published · 2026-09-10
- ZDI-26-659: Adobe Acrobat Reader DC JPEG2000 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerabilityzdi_published · 2026-09-10
- ZDI-26-658: Adobe Acrobat Pro DC JPEG Parsing Integer Overflow Remote Code Execution Vulnerabilityzdi_published · 2026-09-10
- ZDI-26-654: TrendAI Apex One Incomplete Cleanup Local Privilege Escalation Vulnerabilityzdi_published · 2026-09-10
- ZDI-26-653: TrendAI Apex One Security Agent Cache Mechanism Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerabilityzdi_published · 2026-09-10
- ZDI-26-652: TrendAI Apex One Security Agent Cache Mechanism Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerabilityzdi_published · 2026-09-10
- ZDI-26-651: (Pwn2Own) OpenAI Codex External Control of System or Configuration Setting Remote Code Execution Vulnerabilityzdi_published · 2026-09-10
- ZDI-26-650: (Pwn2Own) OpenAI Codex External Control of Configuration Setting Remote Code Execution Vulnerabilityzdi_published · 2026-09-10
- ZDI-26-649: (Pwn2Own) OpenAI Codex Improper Neutralization of Control Sequences Remote Code Execution Vulnerabilityzdi_published · 2026-09-10
- ZDI-26-648: (Pwn2Own) OpenAI Codex External Control of System or Configuration Setting Remote Code Execution Vulnerabilityzdi_published · 2026-09-10
- GDCM <= 3.2.7: six memory-safety and denial-of-service vulnerabilities, no CVEoss_sec · 2026-09-10
- Srsly Risky Biz: America's drivers licence breach is a national security disasterriskybiz_news · 2026-09-10
- Palo Alto Products Multiple Vulnerabilitieshkcert · 2026-09-10
- MongoDB Multiple Vulnerabilitieshkcert · 2026-09-10
- Google Chrome Multiple Vulnerabilitieshkcert · 2026-09-10
- AI slops from Eveoss_sec · 2026-09-10
- iceener/files-stdio-mcp-server: sandbox escape in fs_search via a symlinked directory (recursive walker validates only the top level)oss_sec · 2026-09-10
- Survey of filesystem MCP servers: how the "sandboxed filesystem" boundary is enforced (one breach, four defended-by-design)oss_sec · 2026-09-10
- Memory-safety defects in the upstream (abandoned) AOSP OpenCORE AAC decoder, shipped unpatched by Samsung TizenRToss_sec · 2026-09-10
- Postfix: SMTP smuggling, remote crash, and hardening fixes in 3.11.7 and related legacy releasesoss_sec · 2026-09-10
- Citrix Products Multiple Vulnerabilitieshkcert · 2026-09-10
- CVE-2026-75880: Apache Artemis, Apache ActiveMQ Artemis: Message selector wildcard handling could lead to denial of serviceoss_sec · 2026-09-10
- CVE-2026-67593: Apache Artemis, Apache ActiveMQ Artemis: Pre-authentication Openwire protocol handling can result in queue deletionoss_sec · 2026-09-10
- CVE-2026-57967: Apache Artemis, Apache ActiveMQ Artemis: Missing authentication on CORE protocol session reattachmentoss_sec · 2026-09-10
- CVE-2026-57822: Apache Artemis, Apache ActiveMQ Artemis: Message-based management parameter deserialization may lead to denial of serviceoss_sec · 2026-09-10
- CVE-2026-49364: Apache Artemis, Apache ActiveMQ Artemis: Pre-Authentication Cluster Credential Exposure to Discovered Peersoss_sec · 2026-09-10
- CVE-2026-49363: Apache Artemis, Apache ActiveMQ Artemis: Pre-Authentication Information Disclosure in CORE Protocol Topology Subscriptionoss_sec · 2026-09-10
- CVE-2026-49362: Apache Artemis, Apache ActiveMQ Artemis: Missing Authentication in CORE Protocol Handler Allows Unauthorized Queue Creationoss_sec · 2026-09-10
- The Intelligible World of Agentsrecordedfuture · 2026-09-10
- [CISA KEV] CVE-2026-86060 — MikroTik RouterOS: MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerabilitycisa_kev · 2026-09-10
- [CISA KEV] CVE-2026-67277 — MikroTik RouterOS: MikroTik RouterOS Missing Authentication for Critical Function Vulnerabilitycisa_kev · 2026-09-10
- [GHSA] GHSA-3cgp-3cqx-j8w2 (medium) — Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat treegithub_advisories · 2026-09-09
- [GHSA] GHSA-5x7x-4c3c-qf5w (medium) — Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targetsgithub_advisories · 2026-09-09
- [GHSA] GHSA-jqhh-cjmq-vmv6 (medium) — Open WebUI: Any authenticated user can hang the server via a cyclic chat message historygithub_advisories · 2026-09-09
- [Global Secret Group] Mesan USA posted to leak siteransomware_live · 2026-09-09
- [GHSA] GHSA-cp3j-m783-3ph5 (high) — Identrail Cross-tenant IDOR: Client-supplied GitHub App installation_id is bound to the caller's workspace without ownership verificationgithub_advisories · 2026-09-09
- [GHSA] GHSA-g72f-jw3w-mgh7 (high) — @openhop/server: Path Traversal in Flow ID File Operationsgithub_advisories · 2026-09-09
- [GHSA] GHSA-vv4j-m4vr-f3g6 (high) — ESPHome Device Builder Dashboard: Unauthenticated dashboard access via the HA add-on ingress site bound to all interfacesgithub_advisories · 2026-09-09
- [GHSA] GHSA-wcjj-9m6g-2fr2 (high) — functype-mcp-server: MCP `set_functype_version` Package Alias RCE via Unsanitized pnpm install + Dynamic Importgithub_advisories · 2026-09-09
- [GHSA] GHSA-m835-3cm9-rggg (high) — Joker linter executed project-local .jokerd/linter.* files during lintinggithub_advisories · 2026-09-09
- [GHSA] GHSA-hxjg-93wc-h8p8 (high) — Komari: Management Interface CSRFgithub_advisories · 2026-09-09
- [GHSA] GHSA-2r5q-h53f-9rp3 (high) — @yeger/turbo-graph: Unauthenticated Network-Exposed Task Execution via /api/rungithub_advisories · 2026-09-09
- [GHSA] GHSA-fxg7-897c-57mp (high) — Nuxt Ollama: Public Runtime Config Exposes Ollama API Key to Browser Clientsgithub_advisories · 2026-09-09
- [GHSA] GHSA-v25g-mvwr-f5fp (medium) — webhookd: Unrestricted HTTP Header to Shell Variable Injectiongithub_advisories · 2026-09-09
- [GHSA] GHSA-5hx7-j24v-rffj (high) — GeoNetwork Web Module: Unauthenticaded Server-Side Request Forgery in SLD Toolgithub_advisories · 2026-09-09
- [thegentlemen] PharmaEssentia Corporation posted to leak siteransomware_live · 2026-09-09
- [thegentlemen] Air Canada posted to leak siteransomware_live · 2026-09-09
- [AuditTeam] mo***al posted to leak siteransomware_live · 2026-09-09