THREAT OPS › Threat News
Threat Intelligence News
11581 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [thegentlemen] PharmaEssentia Corporation posted to leak siteransomware_live · 2026-09-09
- [thegentlemen] Air Canada posted to leak siteransomware_live · 2026-09-09
- [AuditTeam] mo***al posted to leak siteransomware_live · 2026-09-09
- Threat Matrix: Mapping threats across cloud web applicationsmsstic · 2026-09-09
- [lockbit5] amorsaude.com.br posted to leak siteransomware_live · 2026-09-09
- [Panzer] Aqualogus posted to leak siteransomware_live · 2026-09-09
- [qilin] Mitsuwa Trading Co., Ltd posted to leak siteransomware_live · 2026-09-09
- Cisco security advisory (AV26-197) – Update 3cccs_ca · 2026-09-09
- [incransom] cullottalaw.com posted to leak siteransomware_live · 2026-09-09
- [embargo] gardensalive.com, bitsandpieces.com, iselinursery.local, weeksroses.org, esm.local posted to leak siteransomware_live · 2026-09-09
- Fortinet security advisory (AV26-023) - Update 1cccs_ca · 2026-09-09
- Google security advisory (AV26-904)cccs_ca · 2026-09-09
- ConnectWise security advisory (AV26-903)cccs_ca · 2026-09-09
- Check Point security advisory (AV26-902)cccs_ca · 2026-09-09
- Fwd: XZ Utils 5.8.4 and a security fixoss_sec · 2026-09-09
- U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Cryptothehackernews · 2026-09-09
- When AI Workloads Start Acting Like Userszscaler_threatlabz · 2026-09-09
- [GHSA] GHSA-7w5x-hrqm-74c2 (high) — smol-toml: Denial of Service via malformed TOML documentsgithub_advisories · 2026-09-09
- [GHSA] GHSA-jf6q-chmf-3h3v (medium) — weasyprint Has Server-Side Request Forgery (SSRF)github_advisories · 2026-09-09
- [GHSA] GHSA-ccg5-9c8w-xh6v (medium) — SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`github_advisories · 2026-09-09
- [GHSA] GHSA-7jxh-36q5-gcqv (medium) — containerd: CRI ExecSync Goroutine Leak Leads to Node-Level Denial of Servicegithub_advisories · 2026-09-09
- [GHSA] GHSA-hr3m-4qwq-3mgc (medium) — GitHacker: Path traversal in ref/hash parsing enables existence oracle and hex-fragment exfiltration via malicious .git servergithub_advisories · 2026-09-09
- [GHSA] GHSA-9mvp-w4rr-5c6x (medium) — decidim-elections: Election question titles allow stored script executiongithub_advisories · 2026-09-09
- [GHSA] GHSA-c23q-fw86-9h5x (medium) — LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpointgithub_advisories · 2026-09-09
- [GHSA] GHSA-pqqc-8v73-9gg2 (medium) — LF Edge eKuiper: SSRF in External Servicegithub_advisories · 2026-09-09
- [GHSA] GHSA-g8rh-fjm6-h2h9 (low) — LF Edge eKuiper: Self-XSS in External Service Creationgithub_advisories · 2026-09-09
- Passkey-themed social engineering leads to identity and cloud compromisemsstic · 2026-09-09
- Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windowsvolexity · 2026-09-09
- [NVD] CVE-2026-87875 (MEDIUM 4.3) — The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a source-length bound and can read past the end of the source buffer, resulting in a heap out-of-bounds read. This is reachable via SNMP supply-description parsing in backend/snmp-supplies.c with attacker-controlled nvd · 2026-09-09
- [AuditTeam] dg***kr posted to leak siteransomware_live · 2026-09-09
- [AuditTeam] go***et posted to leak siteransomware_live · 2026-09-09
- [AuditTeam] kr***rg posted to leak siteransomware_live · 2026-09-09
- ChatGPT Desktop App Includes an In-App Browser: How Do You Secure Embedded Browsers?zscaler_threatlabz · 2026-09-09
- [GHSA] GHSA-7rhf-42qf-vrvc (medium) — gix-sec safe.directory protections absent for elevated administratorsgithub_advisories · 2026-09-09
- Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Weekthehackernews · 2026-09-09
- Active exploitation of Cisco Secure Firewall Management Center vulnerabilitiestalos · 2026-09-09
- Driver’s License Data for Saleschneier · 2026-09-09
- [GHSA] GHSA-8cp2-47hg-mfgh (medium) — Microsoft Security Advisory CVE-2026-69304 – ASP.NET Core Denial of Service Vulnerabilitygithub_advisories · 2026-09-09
- [GHSA] GHSA-2j8r-3c22-8565 (high) — Microsoft Security Advisory CVE-2026-69522 – .NET and Visual Studio Remote Code Execution Vulnerabilitygithub_advisories · 2026-09-09
- [GHSA] GHSA-527h-q9f6-p7qx (high) — Microsoft Security Advisory CVE-2026-69439 – .NET and Visual Studio Elevation of Privilege Vulnerabilitygithub_advisories · 2026-09-09
- [GHSA] GHSA-63gh-g2x5-x69v (high) — Microsoft Security Advisory CVE-2026-71328 – .NET and Visual Studio Remote Code Execution Vulnerabilitygithub_advisories · 2026-09-09
- Cisco Advance Notification for Publication of September 16, 2026, Security Advisoriescisco_psirt · 2026-09-09
- Patch Tuesday to Pentest Wednesday: How an Equipment Rental Company Is Turning Continuous Testing Into Continuous Exposure Managementhorizon3 · 2026-09-09
- MISP security advisory (AV26-901)cccs_ca · 2026-09-09
- Incident Automation: Benefits, Tools & Best Practicesorca_security · 2026-09-09
- NVIDIA security advisory (AV26-900)cccs_ca · 2026-09-09
- [NVD] CVE-2026-87824 (HIGH 7.5) — zstd-jni before 1.5.7-14 fails to validate the samples buffer capacity in Zstd.trainFromBufferDirect, allowing attackers to read past buffer boundaries by supplying oversized per-sample lengths. Attackers can trigger out-of-bounds memory access by providing crafted sample length nvd · 2026-09-09
- Credentialed Pre-Port Discovery: Don't Probe the Host, Ask itrapid7 · 2026-09-09
- 2026-011: Critical Vulnerabilities in SAP Kernel and NetWeaver Message Servercert_eu · 2026-09-09
- More than 100,000 fake stores are out to steal your card detailsmalwarebytes_blog · 2026-09-09
- The Models That Found 10,000 Zero-Days Broke Into Three Companies Using Weak Passwordsqualys · 2026-09-09
- Ransom & Dark Web Issues Week 2, September 2026ahnlab · 2026-09-09
- [Vexy Ransomware] Logar Network Solutions posted to leak siteransomware_live · 2026-09-09
- The Flashpoint Threat Intelligence Brief: Middle Eastflashpoint · 2026-09-09
- CVE-2026-37171: SuperTokens Core cross-tenant session isolation bypass (6.0.0-11.4.0)oss_sec · 2026-09-09
- Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFAthehackernews · 2026-09-09
- [NVD] CVE-2026-86774 (MEDIUM 6.3) — Snipe-IT versions before 8.7.0 contain a broken access control vulnerability in AssetModelPolicy where the files() method cascades from assets.files permission, allowing authenticated users to upload and delete file attachments on Asset Model records without the required models.fnvd · 2026-09-09
- [NVD] CVE-2026-86769 (MEDIUM 4.3) — Snipe-IT versions before 8.7.0 contain an improper ownership management vulnerability in the consumables checkout API endpoint that records the checkout target user's id in the created_by column instead of the authenticated caller's id. Authenticated attackers with consumables.chnvd · 2026-09-09
- [NVD] CVE-2026-86764 (MEDIUM 6.5) — Snipe-IT through 8.6.4 (fixed in 8.7.0) does not enforce the components.view permission on the authenticated endpoint GET /api/v1/hardware/<asset-id>/assigned/components. The endpoint authorizes only assets.view on the parent asset before returning linked component details; the cnvd · 2026-09-09
- [NVD] CVE-2026-86759 (HIGH 7.1) — Snipe-IT versions before 8.7.0 fail to authorize the POST /hardware/history endpoint, allowing any authenticated user to reassign arbitrary assets and modify audit logs. Attackers can submit a CSV file to reassign assets across companies and inject fraudulent audit trail entries,nvd · 2026-09-09
- [NVD] CVE-2026-86754 (HIGH 7.3) — Snipe-IT before 8.7.0 fails to properly gate Laravel Passport's OAuth client management routes, allowing any authenticated user to register OAuth clients with attacker-controlled redirect URIs. Attackers can trick administrators into approving consent screens, then exchange authonvd · 2026-09-09
- [NVD] CVE-2026-86749 (MEDIUM 6.3) — Snipe-IT versions <= 8.6.3 (fixed in 8.7.0) do not check the return value of storage write operations in ImageUploadRequest::handleImages(). Because Laravel's default disk mode does not throw on failure, a silently failed Storage::disk('public')->put(...) call still caused the apnvd · 2026-09-09
- [NVD] CVE-2026-73324 (MEDIUM 4.3) — Certain VLC media player builds in versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing media from an attacker-controlled network source. Exploitation requires user interaction and may disclose a limited, layout-dependent amount of VLC pronvd · 2026-09-09
- [NVD] CVE-2026-56711 (HIGH 7.0) — VLC media player versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing crafted media. Exploitation requires user interaction and may result in application termination or code execution with the privileges of the VLC process.nvd · 2026-09-09
- MFA's Weakest Link: Account Recovery Is the New Attack Pathbleepingcomputer · 2026-09-09
- Commvault security advisory (AV26-899)cccs_ca · 2026-09-09
- Fortinet security advisory (AV26-898)cccs_ca · 2026-09-09
- [incransom] https://mediengruppethiel.de/ posted to leak siteransomware_live · 2026-09-09
- [direwolf] RelyComply AML Platform posted to leak siteransomware_live · 2026-09-09
- [akira] Kyodo USA posted to leak siteransomware_live · 2026-09-09
- Introducing the CyberAgents Exchange AI Inspector: Rigorous review for community-built AItenable · 2026-09-09
- [emperador] Bosnia and Herzegovina Mine Action Center posted to leak siteransomware_live · 2026-09-09
- [Dark Project] Specchem LLC posted to leak siteransomware_live · 2026-09-09
- [qilin] Jet Specialty posted to leak siteransomware_live · 2026-09-09
- CISA Adds Four Known Exploited Vulnerabilities to Catalogcisa_advisories · 2026-09-09
- Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVEthehackernews · 2026-09-09
- [emperador] Universal Starch-Chem Allied Ltd posted to leak siteransomware_live · 2026-09-09
- September 2026 Patch Tuesday: 974 Flaws, 2 Zero-Dayssocradar_blog · 2026-09-09
- DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approvalthehackernews · 2026-09-09
- Claude Fable Solves a Historical Cipherschneier · 2026-09-09
- A “proof” of Fermat’s Last Theorem that fits the margintrailofbits · 2026-09-09
- Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Walletsthehackernews · 2026-09-09
- AI Is Raising the Stakes for the SOC – Here’s What Comes Nextzscaler_threatlabz · 2026-09-09
- [Storm] Technology Dynamics posted to leak siteransomware_live · 2026-09-09
- [Storm] Flexmaster posted to leak siteransomware_live · 2026-09-09
- [Storm] Lowerys posted to leak siteransomware_live · 2026-09-09
- [Storm] Melitron posted to leak siteransomware_live · 2026-09-09
- Microsoft fixes record 964 flaws, including 2 exploited zero-daysmalwarebytes_blog · 2026-09-09
- Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructureunit42 · 2026-09-09
- U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grokthehackernews · 2026-09-09
- Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandboxthehackernews · 2026-09-09
- The push to stop algorithms controlling social media feeds has begunmalwarebytes_blog · 2026-09-09
- New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Rootthehackernews · 2026-09-09
- The SecOps Revolution: How AI and Agentic Technology Are Changing Security Foreverzscaler_threatlabz · 2026-09-09
- F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scansthehackernews · 2026-09-09
- Optimising Out the Waste in Open Source Publishingsonatype · 2026-09-09
- Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassedthehackernews · 2026-09-09
- SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Executionthehackernews · 2026-09-09
- Risky Bulletin: Ukraine's top prosecutor resigns amid scam call center scandalriskybiz_news · 2026-09-09
- ZDI-26-628: Backblaze Personal Computer Backup bzreports Link Following Denial-of-Service Vulnerabilityzdi_published · 2026-09-09