THREAT OPS › Threat News
Threat Intelligence News
11594 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [CISA KEV] CVE-2026-86218 — N-able N-central: N-able N-central Static Code Injection Vulnerabilitycisa_kev · 2026-09-08
- [Dark Project] MEI Architects posted to leak siteransomware_live · 2026-09-07
- [thegentlemen] Hollard Insurance Group posted to leak siteransomware_live · 2026-09-07
- [thegentlemen] Drogueria Saporiti Sacifia posted to leak siteransomware_live · 2026-09-07
- [thegentlemen] Mutant posted to leak siteransomware_live · 2026-09-07
- [thegentlemen] University of San Francisco posted to leak siteransomware_live · 2026-09-07
- [thegentlemen] Nile Projects Trading posted to leak siteransomware_live · 2026-09-07
- [thegentlemen] Chip7 posted to leak siteransomware_live · 2026-09-07
- [thegentlemen] Sharp Office posted to leak siteransomware_live · 2026-09-07
- [thegentlemen] S A Chile posted to leak siteransomware_live · 2026-09-07
- [thegentlemen] Yapı Merkezi posted to leak siteransomware_live · 2026-09-07
- [thegentlemen] Soni Dwarkadas Virchand posted to leak siteransomware_live · 2026-09-07
- [thegentlemen] Zanini posted to leak siteransomware_live · 2026-09-07
- [thegentlemen] Domis posted to leak siteransomware_live · 2026-09-07
- [thegentlemen] Metro posted to leak siteransomware_live · 2026-09-07
- [thegentlemen] Biotipo Jeans posted to leak siteransomware_live · 2026-09-07
- [thegentlemen] Ritz Safety posted to leak siteransomware_live · 2026-09-07
- [thegentlemen] Comin Sac posted to leak siteransomware_live · 2026-09-07
- [thegentlemen] AbacoViaggi posted to leak siteransomware_live · 2026-09-07
- [thegentlemen] El Carriel posted to leak siteransomware_live · 2026-09-07
- [thegentlemen] Superstore posted to leak siteransomware_live · 2026-09-07
- [qilin] Partners Group SK posted to leak siteransomware_live · 2026-09-07
- [lockbit5] vsbattorneys.co.za posted to leak siteransomware_live · 2026-09-07
- [shinyhunters] State of Florida DMV posted to leak siteransomware_live · 2026-09-07
- Between Two Nerds: Can AI defend critical infrastructure?riskybiz_news · 2026-09-07
- [incransom] Wellness Partners network(combined revenue) posted to leak siteransomware_live · 2026-09-07
- CVE-2026-16028: Protocol::HTTP2 versions before 1.14 for Perl allow memory exhaustion via closed streams that stream_state never removes from the connection stream tableoss_sec · 2026-09-07
- CVE-2026-86287: Net::IP::LPM versions before 1.12 for Perl accept malformed prefix lengthsoss_sec · 2026-09-07
- Loyalty points fraud is funding hacker holidays (Lock and Code S07E18)malwarebytes_blog · 2026-09-07
- PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Executionthehackernews · 2026-09-07
- [Vexy Ransomware] United Group posted to leak siteransomware_live · 2026-09-07
- [Dark Project] Master Manufacturing Co., Inc. posted to leak siteransomware_live · 2026-09-07
- [Dark Project] Alurwalls posted to leak siteransomware_live · 2026-09-07
- [direwolf] Precision Vehicle Logistics posted to leak siteransomware_live · 2026-09-07
- [rhysida] Rug & Home posted to leak siteransomware_live · 2026-09-07
- [direwolf] TrainMe posted to leak siteransomware_live · 2026-09-07
- Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacksthehackernews · 2026-09-07
- [interlock] NFM Lending posted to leak siteransomware_live · 2026-09-07
- [everest] GGS posted to leak siteransomware_live · 2026-09-07
- [everest] KÖRBER posted to leak siteransomware_live · 2026-09-07
- [everest] GENESILICO posted to leak siteransomware_live · 2026-09-07
- [NVD] CVE-2026-80057 (MEDIUM 5.5) — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Cryptographic Key vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to infornvd · 2026-09-07
- [NVD] CVE-2026-80056 (MEDIUM 5.5) — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leanvd · 2026-09-07
- [NVD] CVE-2026-79645 (HIGH 8.2) — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leadinvd · 2026-09-07
- [NVD] CVE-2026-79644 (HIGH 7.4) — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthnvd · 2026-09-07
- [NVD] CVE-2026-78488 (MEDIUM 6.5) — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could nvd · 2026-09-07
- [NVD] CVE-2026-78480 (HIGH 7.5) — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leadinvd · 2026-09-07
- 7th September – Threat Intelligence Reportcheckpoint_research · 2026-09-07
- ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and Morethehackernews · 2026-09-07
- [direwolf] Lightcast posted to leak siteransomware_live · 2026-09-07
- [aurora] Jinny Beauty Supply posted to leak siteransomware_live · 2026-09-07
- [NVD] CVE-2026-86452 (HIGH 7.5) — Affected versions of MISP permit unauthenticated or weakly constrained request paths to perform persistent work without adequate input bounds or rate limiting. The users/forgot password-reset endpoint accepted an attacker-controlled email value without first imposing a reasonabnvd · 2026-09-07
- [NVD] CVE-2026-86310 (MEDIUM 6.3) — A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/cust_edit1.php. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disnvd · 2026-09-07
- [NVD] CVE-2026-80170 (MEDIUM 6.5) — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protectinvd · 2026-09-07
- LG TV flaws could let attackers listen in, even in standby modemalwarebytes_blog · 2026-09-07
- [direwolf] Semper Laser posted to leak siteransomware_live · 2026-09-07
- [NVD] CVE-2026-86434 (HIGH 7.5) — league/commonmark versions >= 2.0.0 and < 2.8.4 (patched in 2.9.0) contain a denial of service vulnerability in UniqueSlugNormalizer::normalize(), which restarts its numeric-suffix search from 1 on every slug collision, resulting in O(K^2) time complexity for K headings that collnvd · 2026-09-07
- [NVD] CVE-2026-86429 (HIGH 7.5) — The league/commonmark (thephpleague/commonmark) library in versions >= 1.5.0 and < 2.9.1 contains quadratic parsing complexity in its SmartPunctExtension and AttributesExtension. When either extension is explicitly registered on the Environment (they are not enabled by default annvd · 2026-09-07
- [NVD] CVE-2026-86424 (LOW 2.5) — ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-time-of-use (TOCTOU) vulnerability in the video decoder that allows attackers to bypass path policy write restrictions via symlink swaps. An attacker can replace a symlink between policy validation (check-time) annvd · 2026-09-07
- [NVD] CVE-2026-86418 (MEDIUM 4.3) — Affected versions of MISP expose organisation metadata through the dashboard organisation picker without applying the same visibility restrictions enforced by the normal organisation index and per-organisation view. The affected endpoint returned fields including: - organisatinvd · 2026-09-07
- [NVD] CVE-2026-86305 (HIGH 7.3) — A security flaw has been discovered in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. Affected by this issue is the function Upload::upload of the file ThinkPHP/Library/Think/Upload.class.php. Performing a manipulation results in nvd · 2026-09-07
- [NVD] CVE-2026-80238 (CRITICAL 9.3) — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Execution with Unnecessary Privileges vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Pnvd · 2026-09-07
- [NVD] CVE-2026-80178 (MEDIUM 5.5) — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to elevation onvd · 2026-09-07
- [NVD] CVE-2026-80135 (HIGH 7.5) — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Check or Handling of Exceptional Conditions vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerabilinvd · 2026-09-07
- [NVD] CVE-2026-80134 (HIGH 7.7) — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthornvd · 2026-09-07
- [NVD] CVE-2026-80133 (HIGH 7.4) — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Relative Path Traversal vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote executionvd · 2026-09-07
- [NVD] CVE-2026-80132 (HIGH 8.1) — ell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leadinnvd · 2026-09-07
- [NVD] CVE-2026-61410 (CRITICAL 9.4) — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authorization vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution.nvd · 2026-09-07
- [metaencryptor] EllisDon Corporation posted to leak siteransomware_live · 2026-09-07
- Qatar’s Digital Boom Has a Blind Spot: What the 2025-26 Threat Data Is Telling Uscyble · 2026-09-07
- [NVD] CVE-2026-86299 (CRITICAL 9.9) — A vulnerability was detected in Linksys RE7000 2.0.15. This affects the function platform_event_pingTest of the file /cgi-bin/json.cgi?PingTest of the component PingTest Handler. The manipulation of the argument pingTestIp/pingTestPktSize/pingTestTimes results in os command injecnvd · 2026-09-07
- [qilin] Jbc posted to leak siteransomware_live · 2026-09-07
- [metaencryptor] SIFCO Industries INC. posted to leak siteransomware_live · 2026-09-07
- [metaencryptor] ST Engineering posted to leak siteransomware_live · 2026-09-07
- [metaencryptor] Hologic, Inc. posted to leak siteransomware_live · 2026-09-07
- Your Cloud Security Checklist Doesn't Work the Way You Think It Doesthehackernews · 2026-09-07
- Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hoststhehackernews · 2026-09-07
- StyleSmuggler: Unpatched Magento and Adobe Commerce Zero-Day Exploitedsocradar_blog · 2026-09-07
- Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Releasedthehackernews · 2026-09-07
- Flirty OnlyFans promoters on X may be using AI to appear humanmalwarebytes_blog · 2026-09-07
- [NVD] CVE-2026-86294 (MEDIUM 4.3) — A vulnerability has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this issue is some unknown functionality of the file save-settings.php of the component Settings Update Endpoint. The manipulation of the argument site_name/site_desc leads to cross sinvd · 2026-09-07
- Bring Licensed Threat Intelligence into Every Conversation with SOCRadar and ChatGPTsocradar_blog · 2026-09-07
- E-Commerce Access, Vedicline Data, Langflow RCE, ASUS Claim, and Energy Shell Accesssocradar_blog · 2026-09-07
- [NVD] CVE-2026-86289 (MEDIUM 4.3) — A vulnerability was found in Ollama up to 0.31.1. This issue affects the function readGGUFV1String of the file fs/ggml/gguf.go of the component GGUF Decoder. Performing a manipulation results in integer overflow. The attack is possible to be carried out remotely. The exploit has nvd · 2026-09-07
- N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flawthehackernews · 2026-09-07
- [Vexy Ransomware] LIBRERIA SANTA FE A P S SRL posted to leak siteransomware_live · 2026-09-07
- [NVD] CVE-2026-86281 (MEDIUM 4.3) — A security flaw has been discovered in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This impacts an unknown function. Performing a manipulation results in cross-site request forgery. The attack can be initiated remotely. The exploit has been releanvd · 2026-09-07
- JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookiesthehackernews · 2026-09-07
- N-able N-central HF4 Fixes Critical RCE After Series of Authentication Flawssocradar_blog · 2026-09-07
- [NVD] CVE-2026-79698 (CRITICAL 9.9) — A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. This vulnerabilnvd · 2026-09-07
- A week in security (August 31 – September 6)malwarebytes_blog · 2026-09-07
- [NVD] CVE-2026-86273 (HIGH 7.3) — A weakness has been identified in projeto-siga siga up to 11.1.1. Affected by this issue is the function DownloadExterno.getUrl of the file sigaex/src/main/java/br/gov/jfrj/siga/vraptor/ExUtilController.java of the component HTML-to-PDF Endpoint. This manipulation of the argumentnvd · 2026-09-07
- [kazu] MSM Unify: Global Education Platform - CA posted to leak siteransomware_live · 2026-09-07
- [NVD] CVE-2026-86268 (HIGH 7.3) — A vulnerability was detected in itsourcecode School Management System 1.0. Impacted is an unknown function of the file User_Login.php. The manipulation of the argument email results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.nvd · 2026-09-07
- [ShadowByt3$] Ben Leeds Properties posted to leak siteransomware_live · 2026-09-07
- Risky Bulletin: BEC campaign steals €35 million from French notariesriskybiz_news · 2026-09-07
- [NVD] CVE-2026-86262 (HIGH 7.3) — A security vulnerability has been detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This affects the function updateOrderSta1/updateOrderdiseaseInfo of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order Handlernvd · 2026-09-07
- Aruba Products Multiple Vulnerabilitieshkcert · 2026-09-07
- [NVD] CVE-2026-86241 (MEDIUM 4.3) — A weakness has been identified in liufee FeehiCMS up to 2.1.1. This impacts an unknown function of the file environments/prod/backend/config/main-local.php of the component Cookie Validation. This manipulation of the argument cookieValidationKey causes use of hard-coded cryptogranvd · 2026-09-07
- [NVD] CVE-2026-20501 (HIGH 8.4) — In vdec, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11262030; Issue ID: MSV-9197.nvd · 2026-09-07