THREAT OPS › Threat News
Threat Intelligence News
11600 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [GHSA] GHSA-62f5-cp2p-vq95 (high) — CodeWhale: Project config `instructions` override enables arbitrary file read into AI system prompt via cloned repositorygithub_advisories · 2026-09-04
- [direwolf] Wolfram Research posted to leak siteransomware_live · 2026-09-04
- What Fal.Con 2026 Reinforced: AI Makes Proving Exposure More Important Than Everhorizon3 · 2026-09-04
- [GHSA] GHSA-w7wx-5q49-r59w (high) — CodeWhale: image_analyze follows workspace symlinks, leaking external file bytesgithub_advisories · 2026-09-04
- [spacebears] Sports Endeavors posted to leak siteransomware_live · 2026-09-04
- [GHSA] GHSA-6hxq-p678-4hr2 (low) — SimpleWebAuthn: Registration verification does not sufficiently ensure that attestation certificates chain to a trust anchorgithub_advisories · 2026-09-04
- [GHSA] GHSA-m3c3-78fh-w3w7 (medium) — SurrealDB allows bypass of deny-net flags via DNS resolutiongithub_advisories · 2026-09-04
- ZPA and AI Guard in Actionzscaler_threatlabz · 2026-09-04
- [NVD] CVE-2026-85008 (LOW 3.7) — undici's cache interceptor documents that only safe HTTP methods are cached, but its logic to skip caching is built by subtracting the configured methods from the set of safe methods, so an unsafe method such as POST, PUT, or DELETE is never placed in the skip list and instead fanvd · 2026-09-04
- [NVD] CVE-2026-84961 (HIGH 7.4) — undici's BalancedPool constructor passes its entire options object through an internal deep-clone that serializes and reparses the value as JSON. Because JSON cannot represent functions, any function-valued TLS option, such as a caller-supplied checkServerIdentity callback or a cnvd · 2026-09-04
- [NVD] CVE-2026-84947 (LOW 3.7) — undici's dump interceptor reads and discards a response body up to a configurable maximum size. When a response declares a Content-Length that exceeds the maximum, the interceptor aborts cleanly, but when a response has no Content-Length and is chunked, the interceptor instead sinvd · 2026-09-04
- [NVD] CVE-2026-84933 (MEDIUM 6.5) — undici's cache interceptor does not handle the Set-Cookie response header anywhere in its cache path, so it neither refuses to store nor strips that header. In shared cache mode, which is the default, an otherwise cacheable response that carries a Set-Cookie header, for example onvd · 2026-09-04
- The hidden work of modernizing Malwarebytesmalwarebytes_blog · 2026-09-04
- [DYSPHOR1A] MBT Telecom posted to leak siteransomware_live · 2026-09-04
- Using a VM to Contain an AI Agentschneier · 2026-09-04
- [Vexy Ransomware] Palsana Enviro (PEPL) posted to leak siteransomware_live · 2026-09-04
- [Vexy Ransomware] Annapurna Fashion posted to leak siteransomware_live · 2026-09-04
- [Vexy Ransomware] Sancity Soft Touch posted to leak siteransomware_live · 2026-09-04
- [NVD] CVE-2026-79418 (HIGH 8.7) — EMX Tecnologia Gestao X version <= 8.4 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Help Chat functionality. Improper neutralization of user-controlled input during web page generation allows authenticated attackers to execute arbitrary JavaScript in the contnvd · 2026-09-04
- Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filtersthehackernews · 2026-09-04
- PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Executionthehackernews · 2026-09-04
- [NVD] CVE-2026-85665 (MEDIUM 6.5) — Bruno versions through 4.1.0 fail to validate file paths in request body declarations, allowing attackers to read arbitrary local files by using parent-directory traversal segments. When a collection is executed, attackers can craft a request with a body:file path containing ../ nvd · 2026-09-04
- [akira] Stransky Heiz-Mess-Regeltechnik GmbH posted to leak siteransomware_live · 2026-09-04
- New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Trafficthehackernews · 2026-09-04
- CVE-2026-73749: HPE ArubaOS-CX RCEsocradar_blog · 2026-09-04
- [qilin] AP CAPITAL PARTNERS LIMITED posted to leak siteransomware_live · 2026-09-04
- Google security advisory (AV26-883)cccs_ca · 2026-09-04
- [tridentlocker] SouthernCarlson posted to leak siteransomware_live · 2026-09-04
- 39 New Methods That Compromise Passkey Authenticationbleepingcomputer · 2026-09-04
- CVE-2026-20212: Cisco Nexus 9000 RCE Flawsocradar_blog · 2026-09-04
- [akira] Worrell posted to leak siteransomware_live · 2026-09-04
- Elementor Pro RCE Flaw Under Active Attacksocradar_blog · 2026-09-04
- CVE-2026-52691: Apache Griffin Hive Metastore Module: SQL Injection Vulnerability in Hive Metastore Moduleoss_sec · 2026-09-04
- CVE-2026-82309: Robots::Validate versions from 0.3.2 before 0.3.11 for Perl allow unbounded outbound DNS queries per validation via a forward-confirmation loop that does not bound the names it queriesoss_sec · 2026-09-04
- AI-Driven Threat Intelligence for Gulf Enterprises: Why Detection Speed Is Now a Regulatory Requirementcyble · 2026-09-04
- [NVD] CVE-2026-85516 (HIGH 7.3) — A vulnerability was detected in code-projects Vehicle Management System 1.0. The affected element is an unknown function of the file /busprofile.php. Performing a manipulation of the argument busid results in sql injection. It is possible to initiate the attack remotely. The explnvd · 2026-09-04
- X Money rollout linked to password-reset attacksmalwarebytes_blog · 2026-09-04
- [NVD] CVE-2026-85604 (HIGH 8.8) — Grav before 2.0.18 (affected versions <= 2.0.17) contains a remote code execution vulnerability in the Twig sort filter. The sortFunc wrapper in GravExtension.php hardcodes Twig's isSandboxed argument to false, so unlike |map/|filter/|reduce, |sort accepts a plain function name invd · 2026-09-04
- [NVD] CVE-2026-85602 (MEDIUM 5.3) — The Grav Form plugin (getgrav/grav-plugin-form) versions 8.0.6 through 9.1.19 select the reCAPTCHA version to validate based solely on which response field key is present in the submitted payload. On a site configured for reCAPTCHA v3, an anonymous attacker can place their v3 toknvd · 2026-09-04
- [NVD] CVE-2026-85600 (MEDIUM 5.4) — Grav Admin (getgrav/grav-plugin-admin2) versions <= 2.0.19 contain a stored cross-site scripting vulnerability in the tHtml() function (src/lib/stores/i18n.svelte.ts), which substitutes untrusted parameters such as usernames into translation templates before parsing the result asnvd · 2026-09-04
- [NVD] CVE-2026-85599 (HIGH 7.2) — Grav Shortcode Core before 6.2.5 contains stored cross-site scripting vulnerabilities in the [lorem] tag parameter and [details] summary parameter that are written to rendered pages without escaping. Attackers with page-edit access can inject arbitrary HTML and JavaScript that exnvd · 2026-09-04
- [NVD] CVE-2026-85598 (MEDIUM 6.4) — Grav versions 2.0.0 through 2.0.17 fail to apply save-time XSS detection to modular pages, allowing authenticated page editors to store Twig-assembled XSS payloads. Attackers with page-edit rights can create modular pages with malicious Twig code that executes in visitor browsersnvd · 2026-09-04
- [NVD] CVE-2026-85597 — Traefik before v2.11.55 and v3.0.0 through v3.7.10 contain a TLS option conflict resolution vulnerability that allows unauthenticated attackers to bypass client-certificate authentication by creating conflicting TLS options on multi-host routers. Attackers can reach protected bacnvd · 2026-09-04
- [NVD] CVE-2026-85596 — Traefik versions >= v3.7.0 and <= v3.7.10 contain an authentication bypass in the Kubernetes Ingress NGINX provider. The TLS option generated for an Ingress carrying the nginx.ingress.kubernetes.io/auth-tls-secret annotation was named after the Ingress namespace and name. As a renvd · 2026-09-04
- [NVD] CVE-2026-85595 — Traefik versions before v2.11.55 and versions v3.0.0 through v3.7.10 contain an authentication bypass vulnerability in the digestAuth middleware where unknown usernames receive an empty secret instead of rejection. Attackers can compute a valid digest response using the empty secnvd · 2026-09-04
- DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectorsrapid7 · 2026-09-04
- CISA Adds One Known Exploited Vulnerability to Catalogcisa_advisories · 2026-09-04
- [qilin] Commission de la construction du Quebec (CCQ) posted to leak siteransomware_live · 2026-09-04
- [NVD] CVE-2026-84428 (HIGH 7.5) — fastify versions before 5.12.2 implement the case-insensitive nature of HTTP header names by lowercasing names in a route's header schema before compiling it, but the transformation is incomplete: it lowercases the properties keys and the root-level required array, and does not lnvd · 2026-09-04
- Security Vulnerability in a Voting Systemschneier · 2026-09-04
- AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networksschneier · 2026-09-04
- [NVD] CVE-2026-85184 (CRITICAL 9.1) — @fastify/middie versions >= 9.1.0 and before 9.3.4 decide whether to run path-scoped middleware by matching against the raw request target, while the Fastify router resolves an absolute-form request target to its path before dispatching. Because the two layers evaluate different nvd · 2026-09-04
- [NVD] CVE-2026-84504 (HIGH 8.1) — fastify versions before 5.12.2 treat the object resolved by a successful Ajv async validator as the value result protocol used by custom validator compilers. If a request that passes its route schema contains a property named value at the root, fastify replaces the entire requestnvd · 2026-09-04
- [NVD] CVE-2026-84469 (HIGH 7.5) — fastify versions before 5.12.2 decide whether to compile a request schema based on JavaScript truthiness, but JSON Schema Draft 7 defines the boolean false as a valid schema that rejects every instance. When an application assigns false to a route's body, querystring, params, or nvd · 2026-09-04
- [NVD] CVE-2026-76169 (HIGH 7.5) — fastify versions >= 4.0.0 and before 5.12.2 can route a malformed URL sent under one plugin prefix to the custom not-found handler of a different sibling plugin, and invoke it without the preHandler hook declared for that handler. The internal not-found router for encapsulated hanvd · 2026-09-04
- Angry Birds: Toy Ghouls’ new toyssecurelist · 2026-09-04
- PEEP: A Browser RAT Posing as a Chrome Extensionsocradar_blog · 2026-09-04
- Free streaming boxes may be routing criminal traffic through your homemalwarebytes_blog · 2026-09-04
- [NVD] CVE-2026-81665 (HIGH 7.5) — A heap-based buffer overflow was found in Corosync's Totem Process Group (totempg) message reassembly. When processing fragmented multicast messages, the buffer used to reassemble fragments lacks a runtime bounds check in release builds. A network-adjacent attacker able to send cnvd · 2026-09-04
- Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flawsthehackernews · 2026-09-04
- Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flawsthehackernews · 2026-09-04
- Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Daythehackernews · 2026-09-04
- [gunra] Blanco & Etcheverry posted to leak siteransomware_live · 2026-09-04
- GPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit Requeststhehackernews · 2026-09-04
- [NVD] CVE-2026-85408 (MEDIUM 4.3) — A vulnerability was determined in Eleveo Quality Management 9.7.0. Impacted is an unknown function of the file /enc-fwk-data/api/v3/conversations/<ID>/events of the component Conversation Handler. This manipulation of the argument createdBy causes dynamically-determined object atnvd · 2026-09-04
- [NVD] CVE-2026-11613 (CRITICAL 9.8) — The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.1.2 via the 'custom_loop_template' parameter parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the nvd · 2026-09-04
- [NVD] CVE-2026-85402 (HIGH 7.3) — A vulnerability was detected in code-projects Doctor Appointment System 1.0. This vulnerability affects unknown code of the file /patient/booking.php. The manipulation of the argument doc_id results in sql injection. The attack may be launched remotely. The exploit is now public nvd · 2026-09-04
- Risky Bulletin: Russia tells data centers to deploy drone defensesriskybiz_news · 2026-09-04
- [NVD] CVE-2026-85383 (MEDIUM 6.3) — A flaw has been found in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/inv_del.php. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been publinvd · 2026-09-04
- Google Chrome Multiple Vulnerabilitieshkcert · 2026-09-04
- [qilin] Complete Packaging Solutions posted to leak siteransomware_live · 2026-09-04
- [qilin] Tanner posted to leak siteransomware_live · 2026-09-04
- Microsoft Edge Multiple Vulnerabilitieshkcert · 2026-09-04
- [Panzer] Hochschule Heilbronn Bildungscampus posted to leak siteransomware_live · 2026-09-04
- CVE-2026-85229: Apache SkyWalking: CWE-79 stored XSS in Booster UI dashboard widgets (incomplete fix of CVE-2025-54057)oss_sec · 2026-09-04
- CVE-2026-71216: Apache SkyWalking: PagerDuty alarm hook transmits the integration routing key over cleartext HTTPoss_sec · 2026-09-04
- HP Easy Start for macOS: CVE-2026-12554 / CVE-2026-12555 / CVE-2026-12556fulldisclosure · 2026-09-04
- Next.js 16.4.0-canary.13 Image Optimizer DNS Rebinding TOCTOU SSRF Still Existsfulldisclosure · 2026-09-04
- O-CMS 1.0.0 Authenticated OS Command Injection via ai_cli_scriptfulldisclosure · 2026-09-04
- Flextype v1.0.0-alpha.3 CMS registerShortcodes() Remote Code Execution via Attacker-Controlled File Inclusionfulldisclosure · 2026-09-04
- Flextype v1.0.0-alpha.3 Stored Fetch Shortcode Allows Server-Side Request Forgeryfulldisclosure · 2026-09-04
- Flextype v1.0.0-alpha.3 Stored Filesystem Shortcode Allows Arbitrary File Readfulldisclosure · 2026-09-04
- Flextype v1.0.0-alpha.3 Stored Expression Injection Enables PHP Remote Code Executionfulldisclosure · 2026-09-04
- Flextype v1.0.0-alpha.3 NULL access_token Authentication Bypassfulldisclosure · 2026-09-04
- Flextype v1.0.0-alpha.3 Path Traversal in Entry Copy Allows Arbitrary Directory Copy and File Disclosurefulldisclosure · 2026-09-04
- Flextype v1.0.0-alpha.3 Server-Side Request Forgery via fetch() in Query APIfulldisclosure · 2026-09-04
- Flextype v1.0.0-alpha.3 Stored Arbitrary Expression Injection in ExpressionsDirective Allows Arbitrary File Readfulldisclosure · 2026-09-04
- Payara 7.2026.1.RC1 Remote Code Execution via Server-Side Includes #exec Directive in Payara Serverfulldisclosure · 2026-09-04
- Payara 7.2026.1.RC1 Arbitrary EJB Method Invocation via Insecure Reflection in Payara Serverfulldisclosure · 2026-09-04
- WireGuard-Linux Stack-Based Buffer Overflow in lsiio (Linux IIO Userspace Tool) Due to Unbounded fscanffulldisclosure · 2026-09-04
- thttpd v2.26 Stack-Based Buffer Overflow in thttpd redirect CGI Programfulldisclosure · 2026-09-04
- Paho v1.3.15 Arbitrary Code Execution via Shared Library Search Path Hijackingfulldisclosure · 2026-09-04
- [0day-rubbish] ZesleCP 3.1.21 Authenticated arbitrary file write to root RCE via cron (8.8)fulldisclosure · 2026-09-04
- [0day-rubbish] StreamSets DataCollector 6.4.1 (official Docker image) Default credentials plus unsandboxed Shell Executor to root RCE (9.8)fulldisclosure · 2026-09-04
- [0day-rubbish] Puppet Enterprise 2025.10.0 Authenticated command injection to root RCE (patch-bypass variant of CVE-2025-5459) (8.8)fulldisclosure · 2026-09-04
- [0day-rubbish] NoMachine Terminal Server 10.0.57 two vulnerabilitiesfulldisclosure · 2026-09-04
- [0day-rubbish] Minuteman UPS Network Management Card 1.60.3 Unauthenticated OS command injection to root RCE (9.8)fulldisclosure · 2026-09-04
- [0day-rubbish] Lantronix EDS3000PR 3.2.0.0R2 two vulnerabilitiesfulldisclosure · 2026-09-04
- [0day-rubbish] GeoVision GV-TBL4700 V1.06 Authenticated command injection to root RCE via SNMPv3 user configuration (8.8)fulldisclosure · 2026-09-04
- [0day-rubbish] DrayTek Vigor 2960 v1.5.1.6 Authenticated command injection to root RCE in uploadlangs (8.8)fulldisclosure · 2026-09-04