THREAT OPS › Threat News
Threat Intelligence News
11762 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [N0n] BeLi Teacher / FSC education centers (AWS) posted to leak siteransomware_live · 2026-09-18
- [N0n] Vietnamese betting operator (GC789 network / Boundless TE) posted to leak siteransomware_live · 2026-09-18
- [N0n] United Federation of Teachers posted to leak siteransomware_live · 2026-09-18
- [GHSA] GHSA-26vp-8gxg-v4pg (critical) — org.xwiki.rendering:xwiki-rendering-xml has an Eval Injection issuegithub_advisories · 2026-09-18
- Teaching a Machine to Think Like an Incident Researchervaronis_blog · 2026-09-18
- Did an AI really try to break free from human control?malwarebytes_blog · 2026-09-18
- [Control systems] Advantech security advisory (AV26-937)cccs_ca · 2026-09-18
- Secure enterprise sharing with access reviews for Microsoft 365bleepingcomputer · 2026-09-18
- Re: A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpilloss_sec · 2026-09-18
- [rhysida] MPA Pharma posted to leak siteransomware_live · 2026-09-18
- Grafana security advisory (AV26-936)cccs_ca · 2026-09-18
- [akira] Anderson Industries posted to leak siteransomware_live · 2026-09-18
- [GHSA] GHSA-m6c8-jcw2-5r25 (high) — Opencast: Stored XSS in Paella player via WebVTT/DFXP caption cue textgithub_advisories · 2026-09-18
- Webinar: Which Google Workspace security controls actually matter?bleepingcomputer · 2026-09-18
- [GHSA] GHSA-j8px-rmrx-76h9 (medium) — Caddy: rewrite placeholder re-expansion, unbounded body buffer DoS, and fileHidden case-sensitivity bypassgithub_advisories · 2026-09-18
- Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalationthehackernews · 2026-09-18
- [incransom] www.roancampingholidays.com posted to leak siteransomware_live · 2026-09-18
- [incransom] www.kendallhunt.com posted to leak siteransomware_live · 2026-09-18
- CISA Adds Two Known Exploited Vulnerabilities to Catalogcisa_advisories · 2026-09-18
- CISA Adds One Known Exploited Vulnerability to Catalogcisa_advisories · 2026-09-18
- Are AIs Still Struggling with CAPTCHAs?schneier · 2026-09-18
- An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It.thehackernews · 2026-09-18
- Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agentsthehackernews · 2026-09-18
- Auditing in the age of (good enough) AItrailofbits · 2026-09-18
- WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storagethehackernews · 2026-09-18
- [qilin] Ascend Com posted to leak siteransomware_live · 2026-09-18
- [qilin] Ceres Tolvas posted to leak siteransomware_live · 2026-09-18
- [qilin] Futuro Forestal posted to leak siteransomware_live · 2026-09-18
- [qilin] Grupo Juste posted to leak siteransomware_live · 2026-09-18
- [qilin] Inland and Offshore Contractors posted to leak siteransomware_live · 2026-09-18
- A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identityunit42 · 2026-09-18
- Why Are OSS Attackers Always After CI/CD Credentials?sonatype · 2026-09-18
- The Race to Production: Why Connectivity Is Becoming a Competitive Advantagezscaler_threatlabz · 2026-09-18
- Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealerthehackernews · 2026-09-18
- [Storm] American Casting Company posted to leak siteransomware_live · 2026-09-18
- [Storm] Johnson Investment Counsel posted to leak siteransomware_live · 2026-09-18
- [Storm] First Secure Community Bank posted to leak siteransomware_live · 2026-09-18
- [Storm] The State Bank posted to leak siteransomware_live · 2026-09-18
- [Storm] First Secure Bank and Trust posted to leak siteransomware_live · 2026-09-18
- Fake parcel delivery messages steal your card and bank detailsmalwarebytes_blog · 2026-09-18
- [EndZone] Accela.com posted to leak siteransomware_live · 2026-09-18
- [EndZone] AT&T posted to leak siteransomware_live · 2026-09-18
- [Spirals] ANYTHINGIT posted to leak siteransomware_live · 2026-09-18
- RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstallthehackernews · 2026-09-18
- A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpilloss_sec · 2026-09-18
- Re: Removing dead code (was: Retrospective by 'gpg.fail' authors)oss_sec · 2026-09-18
- TSUBAME Report Overflow (Apr-Jun 2026)jpcert_blog · 2026-09-18
- ZDI-26-715: Linux Mint Xreader PDF File Parsing Type Confusion Remote Code Execution Vulnerabilityzdi_published · 2026-09-18
- CVE-2026-75157: Apache Airflow: Asset queued-events DELETE endpoints gated on Dag READ instead of Dag EDIT (asset-triggered scheduling suppression)oss_sec · 2026-09-18
- ISC BIND Multiple Vulnerabilitieshkcert · 2026-09-18
- Google Chrome Multiple Vulnerabilitieshkcert · 2026-09-18
- [Panzer] Universitt Hamburg posted to leak siteransomware_live · 2026-09-18
- [Panzer] Inovapy posted to leak siteransomware_live · 2026-09-18
- [Panzer] Stim posted to leak siteransomware_live · 2026-09-18
- [CISA KEV] CVE-2025-39964 — Linux Kernel: Linux Kernel Race Condition Vulnerabilitycisa_kev · 2026-09-18
- [CISA KEV] CVE-2026-53266 — Linux Kernel: Linux Kernel Out-of-Bounds Write Vulnerabilitycisa_kev · 2026-09-18
- One SOC, 100 projects: running centralized alert triage on Elastic Security Serverlesselastic_security · 2026-09-18
- [CISA KEV] CVE-2025-39682 — Linux Kernel: Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerabilitycisa_kev · 2026-09-18
- [SilentRansomGroup] C... posted to leak siteransomware_live · 2026-09-17
- The End of Point-in-Time Compliance: Why Continuous Audit Readiness Matters to You in the AI Eraqualys · 2026-09-17
- [krybit] www.harputyapi.com posted to leak siteransomware_live · 2026-09-17
- [krybit] www.diakonie-apolda.de posted to leak siteransomware_live · 2026-09-17
- CVE-2026-73639: Imager::File::PNG versions from 1.003 before 1.004 for Perl write past the end of the row buffer reading a PNG with a tRNS transparency chunk in read_direct8oss_sec · 2026-09-17
- CVE-2026-73638: Imager versions from 0.45_02 before 1.035 for Perl read outside the EXIF block via unchecked start offsets in tiff_load_ifdoss_sec · 2026-09-17
- Inside the Modern SOC: Defending the Cross-Environment Pivotunit42 · 2026-09-17
- [NVD] CVE-2026-52483 (HIGH 8.8) — The ping diagnostics and other similar functions of the MitraStar GPT-2741GNAC-N2-SV router with firmware BR_g8.10_1.11(WVK.0)b46 allow authenticated users execute arbitrary OS command via concatenated params on a crafted POST request for the endpoint /cgi-bin/device-management-unvd · 2026-09-17
- [NVD] CVE-2026-15815 (HIGH 8.8) — Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A crafted plugin archive can chain relative symbolic link entries to escape the plugin installation directory, writing arbitrary files and an executable backend binary outsidnvd · 2026-09-17
- [qilin] Vigatec posted to leak siteransomware_live · 2026-09-17
- [GHSA] GHSA-r94f-hx44-8jqf (high) — Grav CMS vulnerable to remote code execution via .zip file uploadgithub_advisories · 2026-09-17
- [GHSA] GHSA-xhfv-7758-r9hx (high) — Grav: Missing admin.super guard on core group blueprint access field allows admin.users operator to escalate to super-admingithub_advisories · 2026-09-17
- [GHSA] GHSA-q2j8-x8hf-63ch (medium) — Grav: Single invalid UTF-8 byte disables every rule in Security::detectXss(), bypassing the page-content XSS safety gategithub_advisories · 2026-09-17
- [GHSA] GHSA-f8wv-xp27-6gq7 (critical) — Grav: Blueprint dynamic-data bare-function branch is denylist-gated and omits error_log, giving arbitrary file writegithub_advisories · 2026-09-17
- [GHSA] GHSA-vfmf-q6x9-cw96 (critical) — Grav: detectXss() misses an event-handler attribute after an unpaired quote in an unquoted attribute value, giving stored XSSgithub_advisories · 2026-09-17
- [GHSA] GHSA-4v9q-p283-qc2m (high) — Grav: Unauthenticated Path Traversal via Missing Directory-Boundary Check in `plugin-asset-map.php` Static Asset Server (`index.php`)github_advisories · 2026-09-17
- [GHSA] GHSA-jq29-c7v8-rg55 (high) — Grav: Path Traversal in MediaUploadTrait::deleteFile() Allows Arbitrary File Deletiongithub_advisories · 2026-09-17
- [GHSA] GHSA-9gm5-9rfh-m6vx (high) — CoreDNS DoH/DoQ/gRPC bypass UPDATE rejection enforced on UDP/TCPgithub_advisories · 2026-09-17
- [GHSA] GHSA-gjv8-xp57-g29c (medium) — Soup Sieve: Polynomial-time ReDoS (O(n²)) in the `IDENTIFIER` / `VALUE` selector sub-patternsgithub_advisories · 2026-09-17
- [GHSA] GHSA-j934-xhv5-fg8f (medium) — Soup Sieve: Polynomial-time ReDoS (O(n²)) in the whitespace/comment trimming regex `RE_WS_END` (triggers on VALID selectors)github_advisories · 2026-09-17
- [GHSA] GHSA-qrfj-mgw8-j9c6 (medium) — @platejs/core HTML deserialization can trigger browser behavior during parsinggithub_advisories · 2026-09-17
- [GHSA] GHSA-x424-64qh-5j54 (high) — react/http: A malformed HTTP chunked body can lead to a denial-of-service and peg the CPUgithub_advisories · 2026-09-17
- [GHSA] GHSA-mrg3-qvqr-jw29 (high) — CoreDNS: Unauthenticated memory exhaustion in custom transportsgithub_advisories · 2026-09-17
- [GHSA] GHSA-gq9c-wmrm-5hvr (high) — HAPI FHIR: SHCParser DEFLATE infinite loop causes denial of servicegithub_advisories · 2026-09-17
- [GHSA] GHSA-3w98-rrpr-fprr (high) — HAPI FHIR: SHCParser unbounded DEFLATE decompression causes denial of servicegithub_advisories · 2026-09-17
- [GHSA] GHSA-xjw9-38cr-6372 (high) — djust: A template binding inherits a context safety grant it never earned (XSS)github_advisories · 2026-09-17
- [GHSA] GHSA-9395-2g46-rj3f (high) — djust: Six template-layer defects emit attacker-controlled markup unescaped (XSS)github_advisories · 2026-09-17
- [GHSA] GHSA-w34q-cm8f-9c5x (medium) — OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinninggithub_advisories · 2026-09-17
- [GHSA] GHSA-8wmf-6v46-5gfg (low) — OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logsgithub_advisories · 2026-09-17
- [GHSA] GHSA-5mq7-rwhj-4fh9 (medium) — Steeltoe: Header-forwarded client cert lacks proof of private-key possessiongithub_advisories · 2026-09-17
- [GHSA] GHSA-67c9-f6v2-qv86 (high) — Steeltoe.Discovery.Consul: malformed 'secure' metadata aborts service instance lookup (DoS)github_advisories · 2026-09-17
- [GHSA] GHSA-hr73-3gpv-hh6q (high) — Steeltoe.Discovery.Eureka: malformed enum/bool/timestamp field aborts entire registry fetch (DoS)github_advisories · 2026-09-17
- [GHSA] GHSA-c3mw-737p-c7g2 (high) — Jupyter Server: 5xx request logging leaks token-bearing Referer header valuesgithub_advisories · 2026-09-17
- [GHSA] GHSA-9rgm-9g3h-6x36 (medium) — Svelte devalue: DoS via malformed inputgithub_advisories · 2026-09-17
- [GHSA] GHSA-vjqc-q4mp-2rvf (critical) — CakePHP: Multiple methods in FunctionsBuilder vulnerable to SQL injectiongithub_advisories · 2026-09-17
- [GHSA] GHSA-47ch-6w46-6xm7 (high) — Grav: media_directory() Twig function allows filesystem path traversal and file content disclosure from sandboxed page contentgithub_advisories · 2026-09-17
- [GHSA] GHSA-3jhr-mxmx-38cx (high) — Grav: UserInterface offsetget/offsetexists allow-listed in Twig sandbox let editor-authored content leak hashed_password and 2FA secrets via offsetGet()github_advisories · 2026-09-17
- [GHSA] GHSA-xjw5-q542-3vmr (high) — Grav: config_denied_paths default list omits `system`, exposing real secrets (e.g. system.cache.redis.password) via the Twig sandbox when config_access is enabledgithub_advisories · 2026-09-17
- [GHSA] GHSA-p597-crqc-m349 (high) — Grav: The system, site, and theme Twig variables bypass the content sandbox entirely and are never covered by config_denied_pathsgithub_advisories · 2026-09-17
- [GHSA] GHSA-38p6-h87p-r4cg (low) — Grav: Non constant time nonce comparison in Utils::verifyNonce() used for CSRF protectiongithub_advisories · 2026-09-17
- [GHSA] GHSA-9ccq-2jfg-qw33 (low) — Grav: Origin validation bypass in Uri::referrer() and Pages::referrerRoute() via unanchored prefix matchgithub_advisories · 2026-09-17
- 100,000 WordPress Sites Exposed to Remote Code Execution via PHP Object Injection Vulnerability Found by Wordfence Argus in Tutor LMSwordfence · 2026-09-17