THREAT OPS › Threat News
Threat Intelligence News
11600 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [0day-rubbish] Codoforum 5.4.1 Authenticated arbitrary file upload to PHP RCE (7.2)fulldisclosure · 2026-09-04
- [0day-rubbish] Akana API Platform 8.4.29 Unauthenticated RCE via path-normalization filter/dispatcher discrepancy (9.8)fulldisclosure · 2026-09-04
- Acunetix 25.11.x - Local Privilege Escalation Vulnerability via OpenSSL Configuration (CVE-2026-6958)fulldisclosure · 2026-09-04
- [spacebears] Schwartz, Giannini, Lantsberger & Adamson (SGLA) posted to leak siteransomware_live · 2026-09-04
- Zscaler and OpenAI: Bringing Frontier AI-Powered Security to the Enterprisezscaler_threatlabz · 2026-09-04
- Data access: the hidden cost of security vendor lock-inelastic_security · 2026-09-04
- Recorded Future Announces Automated Signature Creation, Accelerating Vulnerability Prioritizationrecordedfuture · 2026-09-04
- [CISA KEV] CVE-2026-85046 — Google Chromium V8: Google Chromium V8 Type Confusion Vulnerabilitycisa_kev · 2026-09-04
- [NVD] CVE-2026-85444 (HIGH 7.5) — MOOS-IvP through 24.8.1 contains a buffer over-read vulnerability in isQuoted(), isBraced(), and isChevroned() functions that strip whitespace but index using the original string length. Attackers can send NODE_REPORT messages with leading or trailing whitespace to read past buffnvd · 2026-09-03
- [NVD] CVE-2026-85439 (HIGH 7.8) — MOOS-IvP through 24.8.1 contains a remote code execution vulnerability in alogsplit's SplitHandler::handlePreCheckSplitDir() function that fails to sanitize shell metacharacters in log file pathnames. Attackers can embed shell syntax in log file names or the --dir parameter to exnvd · 2026-09-03
- [NVD] CVE-2026-85434 (CRITICAL 9.1) — MOOS-IvP uFldShoreBroker through 24.8.1 fails to verify node ping authenticity before creating outbound bridge routes. Attackers can publish NODE_BROKER_PING messages with crafted HostRecord data to redirect bridged variables to attacker-controlled addresses.nvd · 2026-09-03
- [NVD] CVE-2026-85429 (HIGH 7.5) — MOOS-IvP uFldNodeComms through 24.8.1 trusts the source node identity from the message body rather than validating it from the connection source. Attackers can craft NODE_MESSAGE packets with spoofed source identities to impersonate other nodes and post arbitrary variable notificnvd · 2026-09-03
- [NVD] CVE-2026-85424 (CRITICAL 9.8) — MOOS core-moos through 10.4.0 lacks authentication in the wire protocol, allowing unauthenticated clients to connect with full publish, subscribe, and database clear privileges. Attackers can bypass the compile-time protocol string check and connect with arbitrary client names tonvd · 2026-09-03
- [NVD] CVE-2026-85378 (HIGH 7.3) — A vulnerability was identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. Affected by this issue is the function AuthController::_initialize of the file App/Admin/Controller/ChapterController.class.php of the component Chapnvd · 2026-09-03
- [NVD] CVE-2026-85225 (HIGH 7.3) — A vulnerability was identified in code-projects Doctor Appointment System 1.0. This vulnerability affects unknown code of the file /patient_login.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit is publicly avainvd · 2026-09-03
- [GHSA] GHSA-5fhr-f75j-8wr9 (medium) — SiYuan: Missing publish-access filter on getAttributeViewKeysByID discloses database column schema, plus two unscoped block-ID enumeration oracles (publish mode)github_advisories · 2026-09-03
- [GHSA] GHSA-8x84-r2ff-h8pq (high) — SiYuan: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline master-password crackinggithub_advisories · 2026-09-03
- [GHSA] GHSA-jv8v-xq2h-657v (medium) — SiYuan: Absolute filesystem path and OS username disclosure via resolveAssetPathgithub_advisories · 2026-09-03
- [spacebears] Studio Oculistico Ciraci posted to leak siteransomware_live · 2026-09-03
- [GHSA] GHSA-qvq9-hq6p-v378 (medium) — SiYuan: Missing publish-access filter on getBlockAttrs and batchGetBlockAttrs discloses block attributes (name, alias, memo, custom fields) of protected documentsgithub_advisories · 2026-09-03
- [GHSA] GHSA-vpjw-wf5h-cgpq (high) — SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documentsgithub_advisories · 2026-09-03
- [GHSA] GHSA-67x2-mq63-v9vm (medium) — SiYuan: Missing publish-access check on getBlockBreadcrumb, getRefText, and getBlockTreeInfos discloses content and metadata of protected/forbidden documentsgithub_advisories · 2026-09-03
- [GHSA] GHSA-6mcf-g667-w3qv (medium) — SiYuan: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents without the password (publish mode)github_advisories · 2026-09-03
- [GHSA] GHSA-x67c-8pwr-m8g3 (high) — SiYuan: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernelgithub_advisories · 2026-09-03
- [GHSA] GHSA-v7ph-r5r6-4jcj (medium) — SiYuan: Missing publish-access filter on getFileAnnotation discloses private PDF annotations of forbidden/protected documents (publish mode)github_advisories · 2026-09-03
- [GHSA] GHSA-3mp7-4rh5-jrv9 (high) — SiYuan: Localhost-trust admin bypass on auth-code-gated endpoints, with potential remote reachability via the fixed-port proxygithub_advisories · 2026-09-03
- [GHSA] GHSA-mw8r-mw84-88v2 (high) — SiYuan: Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfiltered feed of all edits including protected/forbidden documents (publish mode)github_advisories · 2026-09-03
- [GHSA] GHSA-q2vg-7qgx-x5fc (critical) — SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handlegithub_advisories · 2026-09-03
- [GHSA] GHSA-wgwx-479j-23vq (medium) — SiYuan: Missing authorization on refreshBacklink allows anonymous readers to trigger persistent server-side writes and unauthenticated resource amplification (publish mode)github_advisories · 2026-09-03
- [GHSA] GHSA-7j72-f6wg-cxw6 (high) — SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)github_advisories · 2026-09-03
- [GHSA] GHSA-pm3w-vxp9-ccwc (medium) — SiYuan: Cross-boundary metadata disclosure via getBlockInfo (publish mode): reader-reachable document title/root info for publish-forbidden docs; sibling getDocInfo is filteredgithub_advisories · 2026-09-03
- [GHSA] GHSA-36v8-mpjm-8j5r (high) — SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-forbidden docs; sibling list endpoints are filteredgithub_advisories · 2026-09-03
- [GHSA] GHSA-69mh-gvh4-8gp7 (high) — SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access checkgithub_advisories · 2026-09-03
- [NVD] CVE-2026-63376 (HIGH 8.2) — toml-node is a TOML parser for Node.js and the browser. Prior to 4.1.2, toml.parse() in lib/compiler.js can be tricked by a table path such as a.b.y.__proto__.__proto__, allowing traversal from a scalar value into Number.prototype and Object.prototype. The currentPath tracking vanvd · 2026-09-03
- Introducing context-aware vulnerability discovery and remediation with Cloudflare Managed Defense and OpenAI Daybreak modelscloudflare_security · 2026-09-03
- [GHSA] GHSA-fph3-ghq9-vw66 (critical) — SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DBgithub_advisories · 2026-09-03
- [GHSA] GHSA-82x6-q7mm-w9cf (high) — toml-node: Uncontrolled Recursiongithub_advisories · 2026-09-03
- [GHSA] GHSA-v5mp-jgw5-2x6j (high) — toml-node: Prototype Pollution Leads to `Object.prototype` Corruption via `__proto__` Key-Path Desynchronizationgithub_advisories · 2026-09-03
- [GHSA] GHSA-7hm9-v7vf-7g4w (high) — SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosuregithub_advisories · 2026-09-03
- [GHSA] GHSA-6983-jfq8-485w (high) — Phoenix: Unbounded channel joins per transport enables DoS over few connectionsgithub_advisories · 2026-09-03
- [GHSA] GHSA-63mc-hw7g-86rr (medium) — Phoenix: Presence keys colliding with `Object.prototype` members break existence checksgithub_advisories · 2026-09-03
- [GHSA] GHSA-528h-pc64-c93x (medium) — stream-json: pick/ignore/filter/replace filters are O(depth²) on nested input — small crafted JSON blocks the event loop for seconds→minutes (DoS)github_advisories · 2026-09-03
- [SilentRansomGroup] Katten Muchin Rosenman posted to leak siteransomware_live · 2026-09-03
- [SilentRansomGroup] P... S... posted to leak siteransomware_live · 2026-09-03
- [SilentRansomGroup] A...en posted to leak siteransomware_live · 2026-09-03
- Microsoft Exchange Vulnerability CVE-2026-62911: What Administrators Should Do and How Zscaler Can Helpzscaler_threatlabz · 2026-09-03
- Microsoft Exchange Vulnerability CVE-2026-62911: What Administrators Should Do and How Zscaler Can Helpzscaler_threatlabz · 2026-09-03
- [GHSA] GHSA-vh22-h7hf-www7 (critical) — SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/writegithub_advisories · 2026-09-03
- [NVD] CVE-2026-85207 (LOW 3.5) — A vulnerability was identified in itsourcecode Online Medicine Delivery System 1.0. Impacted is an unknown function of the file /index.php?q=orderdetails. Such manipulation of the argument location leads to cross site scripting. The attack may be launched remotely. The exploit isnvd · 2026-09-03
- [GHSA] GHSA-6c5v-hqjr-5xxp (high) — amqp091-go has a Potential Memory Exhaustion/Protocol Violation via Broker-Controlled Oversized Payloadgithub_advisories · 2026-09-03
- [GHSA] GHSA-jxwj-j7wr-gfrw (medium) — ApostropheCMS: Mutation-XSS / allowedTags bypass via literal `</textarea/>` solidus closegithub_advisories · 2026-09-03
- [GHSA] GHSA-wr5r-wqp2-x4fh (medium) — ApostropheCMS: Missing destination-parent authorization in page `move()` allows a low-privileged editor to move and re-rank pages inside a restricted subtreegithub_advisories · 2026-09-03
- [GHSA] GHSA-xvg9-69gf-fjrf (medium) — Material for MkDocs: DOM XSS in search suggestions via query parametergithub_advisories · 2026-09-03
- [GHSA] GHSA-p95v-992w-h6c3 (high) — TOON: Prototype pollution when decoding untrusted TOON inputgithub_advisories · 2026-09-03
- [GHSA] GHSA-79wm-x847-7cvg (high) — Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (--studio)github_advisories · 2026-09-03
- SUSE Linux security advisory (AV26-882)cccs_ca · 2026-09-03
- [Control Systems] Siemens security advisory (AV26-881)cccs_ca · 2026-09-03
- [GHSA] GHSA-cxvf-gvfq-36w2 (high) — Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collisiongithub_advisories · 2026-09-03
- [GHSA] GHSA-8cj9-r88m-8945 (high) — Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmationgithub_advisories · 2026-09-03
- [GHSA] GHSA-fg9p-mrxr-hvq7 (critical) — Orval: RCE via OpenAPI path -> unescaped request-URL template literal (backtick breakout)github_advisories · 2026-09-03
- [NVD] CVE-2026-85395 (HIGH 7.1) — UnoPim before 2.1.3 fails to include integration store, update, and key-generation routes in its ACL map, allowing any admin user to bypass permission checks. Attackers with minimal admin privileges can create OAuth API integrations, mint client credentials, and escalate permissinvd · 2026-09-03
- [NVD] CVE-2026-85390 (HIGH 7.1) — Checkmate through 3.11.0 omits the isAllowed role guard middleware on maintenance-window, notification, and check-deletion routes, allowing read-only users to perform administrative actions. Attackers with user-role sessions can create arbitrary maintenance windows to silence alenvd · 2026-09-03
- [NVD] CVE-2026-85205 (MEDIUM 6.3) — A vulnerability was determined in itsourcecode Online Medicine Delivery System 1.0. This issue affects the function addwishlist of the file /customer/controller.php?action=addwish of the component Wishlist. This manipulation of the argument proid causes sql injection. The attack nvd · 2026-09-03
- [NVD] CVE-2026-33630 (HIGH 7.5) — c-ares is an asynchronous resolver library. From ver 1.32.3 until 1.34.7, a use-after-free / double-free in c-ares' query-completion handling. The same flaw — a query's callback being invoked while the query is still linked in the channel's internal lookup structures — is presentnvd · 2026-09-03
- CVE-2026-81270: Apache Allura: Information exposure via searchoss_sec · 2026-09-03
- [GHSA] GHSA-88f2-fpv8-89q2 (critical) — Orval: RCE via servers[].url -> unescaped request-URL template literal (with getBaseUrlFromSpecification)github_advisories · 2026-09-03
- CVE-2026-80190: Apache Allura: Stored XSS via code repositoriesoss_sec · 2026-09-03
- CVE-2026-80181: Apache Allura: Server-side request forgeryoss_sec · 2026-09-03
- [GHSA] GHSA-w727-8j6c-2rj4 (critical) — Orval: Import-time RCE via schema default -> zod module-level template literalgithub_advisories · 2026-09-03
- CVE-2026-80180: Apache Allura: Stored XSS via markdown HTML processingoss_sec · 2026-09-03
- n8n security advisory (AV26-880)cccs_ca · 2026-09-03
- [GHSA] GHSA-2h9g-j24r-h63g (critical) — Orval: Import-time RCE via array-items default -> zod module-level template literalgithub_advisories · 2026-09-03
- Attackers Actively Exploiting Critical Vulnerability in Super Forms Pluginwordfence · 2026-09-03
- [GHSA] GHSA-8j6p-r8jg-mxqh (critical) — Orval: Import-time RCE via header-parameter default -> zod module-level template literalgithub_advisories · 2026-09-03
- Wordfence Intelligence Weekly WordPress Vulnerability Report (August 24, 2026 to August 30, 2026)wordfence · 2026-09-03
- [GHSA] GHSA-2w86-xfrc-g85r (critical) — Orval: RCE via schema property name -> computed-property-key injection in the MSW mock generatorgithub_advisories · 2026-09-03
- [incransom] myglobal.com posted to leak siteransomware_live · 2026-09-03
- [GHSA] GHSA-3575-w9fc-c2j6 (critical) — Orval: Import-time RCE via enum-typed default -> zod module-level template literalgithub_advisories · 2026-09-03
- [GHSA] GHSA-653q-5476-x79g (critical) — Orval: Import-time RCE via query parameter name -> computed-property-key injection in the zod cligithub_advisories · 2026-09-03
- [NVD] CVE-2026-82023 (MEDIUM 4.3) — LearnPress WordPress Plugin before 4.4.6 contains a broken object-level authorization vulnerability that allows authenticated attackers with the Instructor role to add answers to quiz questions owned by other instructors by exploiting a missing ownership check on the question ansnvd · 2026-09-03
- [GHSA] GHSA-6437-gxhq-pqv8 (critical) — Orval: Import-time RCE via header parameter name -> computed-property-key injection in the zod clientgithub_advisories · 2026-09-03
- ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Storiesthehackernews · 2026-09-03
- [GHSA] GHSA-jcvh-xf52-2cwm (high) — ffuf denial of service (OOM) via HTTP response decompression bombgithub_advisories · 2026-09-03
- The story behind the intelligencetalos · 2026-09-03
- [GHSA] GHSA-8q3c-rjr9-xxrp (medium) — VictoriaMetrics vmrestore: Path traversal via crafted backup part names escapes restore rootgithub_advisories · 2026-09-03
- [GHSA] GHSA-m7fp-h3p4-hr49 (high) — LiquidJS has an infinite loop vulnerability in its `strip_html` filtergithub_advisories · 2026-09-03
- [GHSA] GHSA-h6cj-26g5-67fv (medium) — OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download toolgithub_advisories · 2026-09-03
- [GHSA] GHSA-w8wf-3qvj-6xqf (high) — OpenClaw Feishu permission tools could ignore per-account disablementgithub_advisories · 2026-09-03
- [GHSA] GHSA-2q7j-2vhx-56g8 (high) — OpenClaw Feishu tools could ignore per-account disablementgithub_advisories · 2026-09-03
- [GHSA] GHSA-fm8w-2m5w-9j7r (medium) — Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock matchgithub_advisories · 2026-09-03
- [NVD] CVE-2026-85302 (MEDIUM 6.5) — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPKoi WordPress Themes WPKoi Templates for Elementor allows DOM-Based XSS. This issue affects WPKoi Templates for Elementor: from n/a through 3.7.2.nvd · 2026-09-03
- [NVD] CVE-2026-75602 (MEDIUM 6.5) — OpenList a file list program that supports multiple storage. Prior to 4.2.3, OpenList's offline-download feature at POST /api/fs/add_offline_download with tool: "SimpleHttp" accepts an attacker-supplied URL and saves its bytes under a per-task temporary directory before transferrnvd · 2026-09-03
- [GHSA] GHSA-4mvj-m6j5-pmf7 (critical) — unstructured: Server-Side Request Forgery in the URL-based partitioninggithub_advisories · 2026-09-03
- How Virginia Tech Connected Pentesting to Its Engineering Workflowhorizon3 · 2026-09-03
- [NVD] CVE-2026-85236 — A cross-site request forgery (CSRF) vulnerability existed in the cullEmptyEvents action of MISP. The endpoint performed a state-changing and irreversible operation while accepting HTTP GET requests. Because bodyless GET requests are not subject to CakePHP's CSRF validation, an nvd · 2026-09-03
- [NVD] CVE-2026-85137 (HIGH 7.3) — A security vulnerability has been detected in SeaCMS up to 13.6. This impacts the function parseIf of the file seacms_locoy_news.php of the component Locoy Collector. The manipulation of the argument pwd leads to code injection. The attack may be initiated remotely. The exploit hnvd · 2026-09-03
- [NVD] CVE-2026-75036 — A security vulnerability was discovered in Fleet's Helm template preprocessing where templates evaluated by the Fleet controller could reach network resources outside the management cluster. A user who can supply bundle content to a repository referenced by a `GitRepo` resource cnvd · 2026-09-03
- [NVD] CVE-2026-75035 (HIGH 7.7) — A flaw was found in Rancher Manager. When a non-administrative caller supplied a label selector naming a different user, the ext.cattle.io/v1 Token store dropped its internal owner filter instead of returning an empty result. Any authenticated user could therefore list and watch nvd · 2026-09-03
- [NVD] CVE-2026-55658 (HIGH 7.7) — Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. In 3e595f3 and prior, when a streaming proposal is funded, the cluster of streaming contracts moves real pool fnvd · 2026-09-03
- Orca Security and ServiceNow Keep Your CMDB Accurate at the Speed of Cloudorca_security · 2026-09-03