THREAT OPS › Threat News
Threat Intelligence News
11584 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [play] GT Distributors posted to leak siteransomware_live · 2026-09-08
- [GHSA] GHSA-h4x7-gw46-3wm6 (medium) — HTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headersgithub_advisories · 2026-09-08
- [GHSA] GHSA-f2fp-rgf2-35cp (medium) — HTTPX2: Quadratic SSE line buffering can cause CPU denial of servicegithub_advisories · 2026-09-08
- [GHSA] GHSA-7mj9-2mp8-4m2p (high) — HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxiesgithub_advisories · 2026-09-08
- [GHSA] GHSA-4hhp-h66f-j5j7 (medium) — vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protectionsgithub_advisories · 2026-09-08
- [GHSA] GHSA-c7r6-vx3h-w5g2 (high) — Laravel Excel writes exports outside the configured filesystem disk when given a caller-controlled pathgithub_advisories · 2026-09-08
- [GHSA] GHSA-g53g-w8rj-fmg7 (high) — xmldom PI grammar regex ReDoS: quadratic backtracking on unterminated processing instructionsgithub_advisories · 2026-09-08
- [GHSA] GHSA-w2rr-34g9-rvrj (high) — xmldom: Element name injection via createElement() bypasses requireWellFormedgithub_advisories · 2026-09-08
- [GHSA] GHSA-4w3w-2rp5-g8jm (high) — xmldom: Attribute name injection via setAttribute() bypasses requireWellFormedgithub_advisories · 2026-09-08
- CVE-2026-85630: HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs methodoss_sec · 2026-09-08
- [GHSA] GHSA-gh2h-rhph-h37g (high) — Microsoft Security Advisory CVE-2026-50646 – .NET Remote Code Execution Vulnerabilitygithub_advisories · 2026-09-08
- [GHSA] GHSA-8mpw-7fpc-4gqj (medium) — NLTK: Pl196xCorpusReader has quadratic ReDoS on malformed TEI blocksgithub_advisories · 2026-09-08
- CVE-2026-85485: HTML::FormHandler versions before 0.410002 for Perl render some error messages into HTML without escapingoss_sec · 2026-09-08
- [GHSA] GHSA-w3v8-gmh9-3wv7 (high) — NLTK: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressionsgithub_advisories · 2026-09-08
- [GHSA] GHSA-rrv8-h7p8-rx55 (high) — NLTK: ReDoS in nltk.text.Text.findall() via unvalidated user-supplied regular expressionsgithub_advisories · 2026-09-08
- [GHSA] GHSA-92f5-vc22-8j33 (critical) — Microsoft QUIC: Remote Code Execution Vulnerabilitygithub_advisories · 2026-09-08
- [GHSA] GHSA-23fw-v26w-5fgq (medium) — Microsoft Security Advisory CVE-2026-62900 – .NET Information Disclosure Vulnerabilitygithub_advisories · 2026-09-08
- [GHSA] GHSA-7m6h-x95x-82q5 (medium) — vLLM: Cross-User Data Leak Vulnerabilitygithub_advisories · 2026-09-08
- The EU CRA's Real Question: What Shipped, and When Did You Know?bleepingcomputer · 2026-09-08
- [NVD] CVE-2026-75740 (MEDIUM 5.4) — Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the nvd · 2026-09-08
- [NVD] CVE-2026-75735 (MEDIUM 5.4) — Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the nvd · 2026-09-08
- [NVD] CVE-2026-75729 (MEDIUM 5.4) — Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the nvd · 2026-09-08
- [NVD] CVE-2026-75722 (MEDIUM 5.4) — Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires unvd · 2026-09-08
- [NVD] CVE-2026-75716 (MEDIUM 5.4) — Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires unvd · 2026-09-08
- [NVD] CVE-2026-75706 (MEDIUM 5.4) — Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires unvd · 2026-09-08
- [NVD] CVE-2026-75683 (MEDIUM 5.4) — Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires unvd · 2026-09-08
- [NVD] CVE-2026-75677 (MEDIUM 5.4) — Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires unvd · 2026-09-08
- [NVD] CVE-2026-75661 (MEDIUM 5.4) — Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires unvd · 2026-09-08
- [NVD] CVE-2026-75642 (MEDIUM 5.4) — Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the nvd · 2026-09-08
- [NVD] CVE-2026-75635 (MEDIUM 5.4) — Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires unvd · 2026-09-08
- [NVD] CVE-2026-19713 (MEDIUM 5.4) — Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires unvd · 2026-09-08
- [NVD] CVE-2025-64618 (MEDIUM 5.4) — Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the nvd · 2026-09-08
- CVE-2026-85484: HTML::FormHandler versions before 0.410002 for Perl render option group labels and radio button labels into HTML without escapingoss_sec · 2026-09-08
- CVE-2026-19872: HTML::FormHandler versions before 0.410000 for Perl allow cross-site scripting via a submitted value rendered unescaped in an error messageoss_sec · 2026-09-08
- [safepay] palmettoeyeinstitute.com posted to leak siteransomware_live · 2026-09-08
- [safepay] reichenau.at posted to leak siteransomware_live · 2026-09-08
- [safepay] cannonpuntana.com posted to leak siteransomware_live · 2026-09-08
- [safepay] assiprime.it posted to leak siteransomware_live · 2026-09-08
- [safepay] gayafores.es posted to leak siteransomware_live · 2026-09-08
- [safepay] cenmar-manila.com posted to leak siteransomware_live · 2026-09-08
- [safepay] gsngestion.es posted to leak siteransomware_live · 2026-09-08
- [safepay] hbpro.pt posted to leak siteransomware_live · 2026-09-08
- [GHSA] GHSA-3wxw-xv34-2frg (medium) — GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)github_advisories · 2026-09-08
- Ivanti security advisory (AV26-897)cccs_ca · 2026-09-08
- September 2026 Microsoft Patch Tuesday, (Tue, Sep 8th)sans_isc · 2026-09-08
- [NVD] CVE-2026-82536 (HIGH 8.8) — Roo-Code through 3.54.0 contains an auto-approve bypass vulnerability in the shell command parsing logic that allows attackers to execute denied shell commands by exploiting the omission of the bash pipe operator from the command parser's operator token set. Attackers can craft anvd · 2026-09-08
- Microsoft Patch Tuesday, September 2026 Security Update Reviewqualys · 2026-09-08
- Microsoft security advisory – September 2026 monthly rollup (AV26-896) – Update 1cccs_ca · 2026-09-08
- [safepay] recoverycafe.org posted to leak siteransomware_live · 2026-09-08
- [safepay] mcnishsteel.com posted to leak siteransomware_live · 2026-09-08
- [GHSA] GHSA-8mcc-hrx5-hvxc (high) — GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destinationgithub_advisories · 2026-09-08
- [GHSA] GHSA-5xxx-qhh7-9287 (medium) — GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame()github_advisories · 2026-09-08
- [GHSA] GHSA-284h-m62q-gf8w (critical) — GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCEgithub_advisories · 2026-09-08
- [GHSA] GHSA-7833-fr7j-v32q (high) — GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)github_advisories · 2026-09-08
- The September 2026 Security Update Reviewzdi_blog · 2026-09-08
- [NVD] CVE-2026-48707 (LOW 3.1) — InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Server-Side Request Forgery (SSRF) vulnerability in the file upload functionality (`system/core/uploader.php` at lines 509-532). When the "upload from URL" feature follows an HTTP redinvd · 2026-09-08
- [GHSA] GHSA-c4c3-7fpv-j4q5 (critical) — Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContextgithub_advisories · 2026-09-08
- [GHSA] GHSA-fccg-mwvh-qqg4 (medium) — Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsinggithub_advisories · 2026-09-08
- [GHSA] GHSA-6x6c-w9w9-hv4h (medium) — Infracost: Terraform Cloud and registry token disclosure via unvalidated hostnamegithub_advisories · 2026-09-08
- [GHSA] GHSA-mmg6-4qmv-6pc8 (medium) — Infracost: Arbitrary file read via config-template readFile symlink traversalgithub_advisories · 2026-09-08
- Commvault security advisory (AV26-895)cccs_ca · 2026-09-08
- [GHSA] GHSA-p2w3-6x73-2f6x (low) — Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatchergithub_advisories · 2026-09-08
- [GHSA] GHSA-4r6h-5v86-94p3 (high) — LiquidJS: Uncontrolled Resource Consumption in `join` filter allows template authors to bypass `memoryLimit` and crash the processgithub_advisories · 2026-09-08
- [GHSA] GHSA-c2jg-2778-ggm4 (medium) — Prowler: Stored XSS in HTML reports through unescaped cloud resource tagsgithub_advisories · 2026-09-08
- Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)tenable · 2026-09-08
- SAP security advisory – September 2026 monthly rollup (AV26-894)cccs_ca · 2026-09-08
- [GHSA] GHSA-8cw4-87c7-c6xx (medium) — node-csv: Prototype replacement still reachable via columns pathgithub_advisories · 2026-09-08
- [GHSA] GHSA-5qr2-v392-m9g8 (medium) — SWC HTML minifier may allow script element breakout when minifying embedded JSONgithub_advisories · 2026-09-08
- [GHSA] GHSA-xp7j-h7jc-4w8p (critical) — Semaphore U: OS Command Injectiongithub_advisories · 2026-09-08
- [GHSA] GHSA-rcr6-4jqh-j84m (critical) — Gitea: Remote Code Execution via diffpatch Git Hook Installationgithub_advisories · 2026-09-08
- [GHSA] GHSA-v684-q882-jgmq (high) — SiYuan: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully decrypted document content while a notebook is unlockedgithub_advisories · 2026-09-08
- [GHSA] GHSA-74pj-6g7r-j55c (medium) — SiYuan: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfogithub_advisories · 2026-09-08
- [GHSA] GHSA-57v5-wqx3-cgj4 (medium) — SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAttributeViewFieldViewsgithub_advisories · 2026-09-08
- [0day-rubbish] Royal Server 5.04.50529.0 Local privilege escalation to LocalSystem on the execution path without credential override (7.2)fulldisclosure · 2026-09-08
- [0day-rubbish] core-admin 1.0.164 (build 16468) Systemic shell command injection via ineffective quote escaping (8.8)fulldisclosure · 2026-09-08
- [0day-rubbish] OP5 Monitor 9.20 Command injection surviving the CVE-2025-34115 patch (OPT-IN fix ineffective) (8.8)fulldisclosure · 2026-09-08
- [0day-rubbish] QuantaStor 6.8.3.018 Command injection in the alert-mail command via the smtpPassword field (8.8)fulldisclosure · 2026-09-08
- [0day-rubbish] SmarterMail 100.0.9693 (Build 9693) Antivirus command-line configuration executing as NT AUTHORITY\SYSTEM (7.2)fulldisclosure · 2026-09-08
- [0day-rubbish] Jitterbit Agent 12.8.1.6 (Docker jitterbit/agent:12.8.1.6) Unauthenticated SOAP with hard-coded credentials leading to OS command execution (9.8)fulldisclosure · 2026-09-08
- [0day-rubbish] Accurate Online Private Cloud on-prem (current) Unauthenticated Hessian deserialization leading to JNDI remote class loading (9.8)fulldisclosure · 2026-09-08
- [0day-rubbish] DBxtra .NET 13.1.1.0 Unauthenticated SOAP API to xp_cmdshell code execution (9.8)fulldisclosure · 2026-09-08
- **Subject:** CVE-2026-2035703: Tozed ZLT X300 5G CPE — Unauthenticated Remote Root Code Execution via TR-069 Command Injection (CVSS 9.8)fulldisclosure · 2026-09-08
- Token Analysis and Tracking System (TATS)specterops · 2026-09-08
- Hitachi security advisory (AV26-893)cccs_ca · 2026-09-08
- [Control Systems] Inductive Automation security advisory (AV26-892)cccs_ca · 2026-09-08
- JetBrains security advisory (AV26-891)cccs_ca · 2026-09-08
- [direwolf] Sales Boomerang posted to leak siteransomware_live · 2026-09-08
- [Control Systems] Siemens security advisory (AV26-890)cccs_ca · 2026-09-08
- CVE-2026-52307: Stored XSS in 1CMS v5.6fulldisclosure · 2026-09-08
- Claude Mythos 5 is coming to Tenable One, powering the new “Adversary View”tenable · 2026-09-08
- [NVD] CVE-2026-86668 (MEDIUM 4.3) — A security vulnerability has been detected in aircheng-org iWebShop-5 up to 5.15. The impacted element is the function uploadFile of the file controllers/pic.php. Such manipulation of the argument outerSrc/selectPhoto leads to cross site scripting. The attack may be performed fronvd · 2026-09-08
- AIs as Modern Geniesschneier · 2026-09-08
- Re: Linux kernel LPEs: ZcopyReaper (CVE-2026-43502) and 20 moreoss_sec · 2026-09-08
- From Findings to Fixes: Getting Value from Red Team Resultsspecterops · 2026-09-08
- [GHSA] GHSA-3gq4-3j92-5w49 (high) — NLTK: Corpus Reader Sandbox Bypassgithub_advisories · 2026-09-08
- [GHSA] GHSA-p4rw-rvv2-7xwr (high) — NLTK: Corpus readers follow symlinks outside trusted roots despite pathsec enforcementgithub_advisories · 2026-09-08
- Cloud Transformation Strategy, Benefits & Best Practicesorca_security · 2026-09-08
- [Panzer] Financière d'Uzès posted to leak siteransomware_live · 2026-09-08
- [AuditTeam] bu***en posted to leak siteransomware_live · 2026-09-08
- [GHSA] GHSA-x99w-6fgc-pmfw (critical) — NLTK: Allowlisted pickle loaders still permit code execution in current sourcegithub_advisories · 2026-09-08