THREAT OPS › Threat News
Threat Intelligence News
11585 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [GHSA] GHSA-x99w-6fgc-pmfw (critical) — NLTK: Allowlisted pickle loaders still permit code execution in current sourcegithub_advisories · 2026-09-08
- [GHSA] GHSA-97qj-x29f-37w7 (high) — NLTK: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parsesgithub_advisories · 2026-09-08
- [GHSA] GHSA-6ww7-3frv-cqxh (high) — NLTK: pathsec SSRF protection can be bypassed when a proxy is configuredgithub_advisories · 2026-09-08
- [GHSA] GHSA-rhp5-r9x4-f5g2 (critical) — NLTK: Unsafe Pickle Deserialization in TransitionParser Allows Remote Code Executiongithub_advisories · 2026-09-08
- [GHSA] GHSA-3hhw-38pf-pxj6 (medium) — NLTK: Symlink-based arbitrary file read in IPIPANCorpusReader, bypasses nltk.pathsec entirelygithub_advisories · 2026-09-08
- [GHSA] GHSA-f833-7jw8-xwrv (high) — NLTK: Symlink-based sandbox bypass in FramenetCorpusReader (bypasses the fix for CVE-2026-54292)github_advisories · 2026-09-08
- [GHSA] GHSA-568f-pv23-39p4 (high) — NLTK: Stable FrameNet and NKJP readers parse outside-root XMLgithub_advisories · 2026-09-08
- CVE-2026-75156: Apache Airflow FAB provider: FAB Azure AD OAuth: id_token issuer/audience not validated — cross-tenant authentication bypassoss_sec · 2026-09-08
- What is Cloud Security?orca_security · 2026-09-08
- [chaos] copeplastics.com posted to leak siteransomware_live · 2026-09-08
- Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institutionthehackernews · 2026-09-08
- [NVD] CVE-2026-86736 (MEDIUM 4.3) — snipe-it before 8.7.0 contains an incorrect calculation vulnerability in checkout request handling that allows authenticated users to corrupt the assets.requests_counter through duplicate submissions and cancellations without active requests. Attackers can repeatedly call cancel nvd · 2026-09-08
- [NVD] CVE-2026-86731 (MEDIUM 6.5) — Craft CMS versions 5.0.0-RC1 through 5.10.11 are missing an admin-target guard in UsersController::actionActivateUser (the users/activate-user action). While the action requires the administrateUsers permission, it does not call requireAdmin() when the targeted user is an adminisnvd · 2026-09-08
- [NVD] CVE-2026-86726 (MEDIUM 6.5) — AVideo through 29.0 contains an information disclosure vulnerability in restreamsActive.json.php that allows authenticated streamers to enumerate source stream keys and identities of all other streamers' active restreams. The endpoint fails to filter results by user ownership, exnvd · 2026-09-08
- [NVD] CVE-2026-86721 (HIGH 7.5) — AVideo through commit c3edcc274c contains an authorization bypass vulnerability where a session cookie named 'key' with value 'value' overrides the $_REQUEST['key'] parameter in saveLive.php and related endpoints. Attackers can publish to any user's RTMP stream without authenticanvd · 2026-09-08
- Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerabilitycisco_psirt · 2026-09-08
- 4 Questions to Ask When Evaluating an Exposure Management Platformqualys · 2026-09-08
- CVE-2026-74761: Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Spoofing of RemoveSubscription clientIdoss_sec · 2026-09-08
- CVE-2026-73334: Apache Parquet Hadoop: File-controlled KMS URL is forwarded to pluggable KmsClient that skips host validationoss_sec · 2026-09-08
- Xen Security Advisory 513 v3 (CVE-2026-79605,CVE-2026-79606) - Out-of-bounds accesses in Tapdiskoss_sec · 2026-09-08
- Xen Security Advisory 512 v3 (CVE-2026-79604) - oxenstored: Unbounded accumulation of watchesoss_sec · 2026-09-08
- Federal AI Security Needs More Than a Governance Checklistorca_security · 2026-09-08
- Xen Security Advisory 511 v3 (CVE-2026-79603) - Unconditionally do TLB flushing ahead of page scrubbingoss_sec · 2026-09-08
- Xen Security Advisory 510 v3 (CVE-2026-79602) - x86: improper handling of HVM emulation return codesoss_sec · 2026-09-08
- [lockbit5] fdcputman.nl posted to leak siteransomware_live · 2026-09-08
- [lockbit5] contreras.com.ar posted to leak siteransomware_live · 2026-09-08
- Xen Security Advisory 509 v3 (CVE-2026-62437) - x86: DMs may cause mem leak by IRQ bindingoss_sec · 2026-09-08
- CVE-2026-41871: Apache Nutch: Unauthenticated reflection-based job execution in Nutch Server (Nutch REST API)oss_sec · 2026-09-08
- [direwolf] EMS1R posted to leak siteransomware_live · 2026-09-08
- CVE-2026-41870: Apache Nutch: Unauthenticated remote code execution (RCE) via JEXL injection in Nutch Server (Nutch REST API)oss_sec · 2026-09-08
- CVE-2026-41869: Apache Nutch: Unauthenticated forced shutdown and job interruption in Nutch Server (Nutch REST API)oss_sec · 2026-09-08
- [GHSA] GHSA-5wp5-5229-5g6q (medium) — NLTK: Missing Post-Download Integrity Verification Allows Malicious Package Injectiongithub_advisories · 2026-09-08
- [GHSA] GHSA-x5ph-mj9p-rfr8 (high) — NLTK: StreamBackedCorpusView Bypasses pathsec.ENFORCE - Arbitrary Local File Readgithub_advisories · 2026-09-08
- [GHSA] GHSA-72r2-7mfr-5xr9 (medium) — NLTK: FileSystemPathPointer.open() sandbox check is dead code — arbitrary file read via file:// protocolgithub_advisories · 2026-09-08
- CVE-2026-84939: Apache FreeMarker: A malformed locale may be exploitable for path traversal attacksoss_sec · 2026-09-08
- [GHSA] GHSA-r6gq-whwq-mvg9 (high) — NLTK: Symlink escape in CorpusReader allows arbitrary local file read outside the corpus rootgithub_advisories · 2026-09-08
- OpenVPN security advisory (AV26-889)cccs_ca · 2026-09-08
- [NVD] CVE-2026-61516 (CRITICAL 9.8) — Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an information disclosure vulnerability that allows unauthenticated attackers to retrieve the administrator password by sending a request to the sysinfo action in the web management interface without a valid session. Attackenvd · 2026-09-08
- Liquid Hackers Return 3,400 Bitcoin Taken via Elements Bug, Still Holding $47M in BTCthehackernews · 2026-09-08
- [akira] Brent Electric posted to leak siteransomware_live · 2026-09-08
- ChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another Accountthehackernews · 2026-09-08
- Adobe security advisory (AV26-888)cccs_ca · 2026-09-08
- Mikrotik security advisory (AV26-887)cccs_ca · 2026-09-08
- Dell security advisory (AV26-886)cccs_ca · 2026-09-08
- N-able security advisory (AV26-885)cccs_ca · 2026-09-08
- SonicWall security advisory (AV26-884)cccs_ca · 2026-09-08
- GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AImandiant_gti · 2026-09-08
- [akira] Brentwood Country Club posted to leak siteransomware_live · 2026-09-08
- [akira] CreateASoft posted to leak siteransomware_live · 2026-09-08
- [Eclipse] The Zhou Law Group posted to leak siteransomware_live · 2026-09-08
- What’s in the SOSS? Podcast #72 – S3E24 Balancing AI’s Double-Edged Sword: Software Engineering, Unlearning, and Ecosystem Sustainability with Mark Russinovichopenssf_blog · 2026-09-08
- [Eclipse] TTG Asia Media posted to leak siteransomware_live · 2026-09-08
- Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hoursthehackernews · 2026-09-08
- [qilin] Alaska Electrical Apprenticeship posted to leak siteransomware_live · 2026-09-08
- The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPTcheckpoint_research · 2026-09-08
- Grindr settles HIV status data-sharing lawsuit for $35 millionmalwarebytes_blog · 2026-09-08
- Dark Web Market: Anubis Marketsocradar_blog · 2026-09-08
- China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companiescisa_advisories · 2026-09-08
- CISA Adds Four Known Exploited Vulnerabilities to Catalogcisa_advisories · 2026-09-08
- CareCam Pro IP Camerascisa_advisories · 2026-09-08
- WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Callsthehackernews · 2026-09-08
- What It Took to Reach 1 Billion Build Manifeststhehackernews · 2026-09-08
- FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentialsthehackernews · 2026-09-08
- [AuditTeam] Wi***IT posted to leak siteransomware_live · 2026-09-08
- CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED)rapid7 · 2026-09-08
- Stealing AI Reasoning Tracesschneier · 2026-09-08
- ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Managertalos · 2026-09-08
- ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2talos · 2026-09-08
- MikroTik router flaws allow takeover without a passwordmalwarebytes_blog · 2026-09-08
- Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shellthehackernews · 2026-09-08
- BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scamsthehackernews · 2026-09-08
- 220 million traveler records exposed in Vietnam-linked APIS leakbleepingcomputer · 2026-09-08
- Grindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data Sharingthehackernews · 2026-09-08
- Testing race conditions with memory access tracing and stack-based delay injectionproject_zero · 2026-09-08
- [rhysida] SAD'S Interim posted to leak siteransomware_live · 2026-09-08
- [NVD] CVE-2026-86519 (MEDIUM 5.3) — A vulnerability was found in code-projects Student Crud Operation 1.0. This impacts an unknown function of the file /card_activation.sql of the component Backup File Handler. The manipulation results in information disclosure. The attack can be launched remotely. The exploit has nvd · 2026-09-08
- ZDI-26-622: Microsoft Windows IKEv2 AES-GCM Decryption Integer Underflow Remote Code Execution Vulnerabilityzdi_published · 2026-09-08
- ZDI-26-621: Microsoft Windows UMPDDrvRealizeBrush Improper Object Management Local Privilege Escalation Vulnerabilityzdi_published · 2026-09-08
- ZDI-26-620: Microsoft Windows UMPDDrvPlgBlt Improper Object Management Local Privilege Escalation Vulnerabilityzdi_published · 2026-09-08
- ZDI-26-619: Microsoft Windows UMPDDrvStretchBltROP Improper Object Management Local Privilege Escalation Vulnerabilityzdi_published · 2026-09-08
- ZDI-26-618: Microsoft Windows UMPDDrvStretchBlt Improper Object Management Local Privilege Escalation Vulnerabilityzdi_published · 2026-09-08
- ZDI-26-617: Microsoft Windows MIDI Service Incorrect Permission Assignment Local Privilege Escalation Vulnerabilityzdi_published · 2026-09-08
- [AuditTeam] pa***op posted to leak siteransomware_live · 2026-09-08
- AD Rights Management Service (Part 1): Architecture, Deprecation, and Reconnaissancehuntress · 2026-09-08
- Linux kernel LPEs: ZcopyReaper (CVE-2026-43502) and 20 moreoss_sec · 2026-09-08
- [NVD] CVE-2026-86514 (MEDIUM 6.3) — A weakness has been identified in vgmstream up to r2117. This issue affects the function sscanf of the file src/meta/txth.c of the component txth-txtp. This manipulation causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been manvd · 2026-09-08
- [NVD] CVE-2026-86509 (CRITICAL 9.6) — A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function sendOffer/sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack can only be done within the local network. The exploit hasnvd · 2026-09-08
- [CISA KEV] CVE-2026-81963 — Microsoft Windows: Microsoft Windows Link Following Vulnerabilitycisa_kev · 2026-09-08
- [CISA KEV] CVE-2026-85880 — Microsoft Windows: Microsoft Windows Heap-Based Buffer Overflow Vulnerabilitycisa_kev · 2026-09-08
- August 2026 CVE Landscaperecordedfuture · 2026-09-08
- [CISA KEV] CVE-2026-75650 — Adobe Commerce and Magento: Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerabilitycisa_kev · 2026-09-08
- [CISA KEV] CVE-2026-86218 — N-able N-central: N-able N-central Static Code Injection Vulnerabilitycisa_kev · 2026-09-08
- [Dark Project] MEI Architects posted to leak siteransomware_live · 2026-09-07
- [thegentlemen] Hollard Insurance Group posted to leak siteransomware_live · 2026-09-07
- [thegentlemen] Drogueria Saporiti Sacifia posted to leak siteransomware_live · 2026-09-07
- [thegentlemen] Mutant posted to leak siteransomware_live · 2026-09-07
- [thegentlemen] University of San Francisco posted to leak siteransomware_live · 2026-09-07
- [thegentlemen] Nile Projects Trading posted to leak siteransomware_live · 2026-09-07
- [thegentlemen] Chip7 posted to leak siteransomware_live · 2026-09-07
- [thegentlemen] Sharp Office posted to leak siteransomware_live · 2026-09-07