THREAT OPS › Threat News
Threat Intelligence News
11604 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [NVD] CVE-2026-75036 — A security vulnerability was discovered in Fleet's Helm template preprocessing where templates evaluated by the Fleet controller could reach network resources outside the management cluster. A user who can supply bundle content to a repository referenced by a `GitRepo` resource cnvd · 2026-09-03
- [NVD] CVE-2026-75035 (HIGH 7.7) — A flaw was found in Rancher Manager. When a non-administrative caller supplied a label selector naming a different user, the ext.cattle.io/v1 Token store dropped its internal owner filter instead of returning an empty result. Any authenticated user could therefore list and watch nvd · 2026-09-03
- [NVD] CVE-2026-55658 (HIGH 7.7) — Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. In 3e595f3 and prior, when a streaming proposal is funded, the cluster of streaming contracts moves real pool fnvd · 2026-09-03
- Orca Security and ServiceNow Keep Your CMDB Accurate at the Speed of Cloudorca_security · 2026-09-03
- [OSSA-2026-038] OpenStack Glance: Multiple SSRF vulnerabilities in web-download and HTTP image APIs (CVE-2026-71196, CVE-2026-71197, CVE-2026-71198)oss_sec · 2026-09-03
- StreamRat Android malware spreads through Meta and TikTok adsmalwarebytes_blog · 2026-09-03
- ASCII smuggling crosses over from AI prompt injection to phishing evasionmsstic · 2026-09-03
- Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Rootthehackernews · 2026-09-03
- New Campaign Weaponizes Microsoft Teams for Remote Accessduo_decipher · 2026-09-03
- BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventorythehackernews · 2026-09-03
- How to correlate Kubernetes audit logs with container runtime dataelastic_security · 2026-09-03
- [NVD] CVE-2026-85210 (MEDIUM 4.3) — Oppia's AdminRoleHandler GET endpoint in core/controllers/admin.py is decorated with open_access, allowing any registered user to enumerate privileged accounts and roles. Attackers can query the endpoint with filter_criterion parameters to retrieve usernames holding specific rolenvd · 2026-09-03
- [NVD] CVE-2026-85179 (HIGH 8.5) — Label Studio through 1.23.0 fails to validate webhook URLs, allowing authenticated users to dispatch requests to internal services including RFC 1918 addresses and cloud metadata endpoints. Attackers can create webhooks targeting private networks and exfiltrate annotation data bynvd · 2026-09-03
- [NVD] CVE-2026-56126 (MEDIUM 5.4) — pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Status: Monitoring privilege to inject arbitrary JavaScript via graph configuration parameters in /status_monitoring.php. Multiple POST parameters including graph-left, graph-right, time-period, resonvd · 2026-09-03
- AMD security advisory (AV26-879)cccs_ca · 2026-09-03
- [GHSA] GHSA-gw25-m53r-qh88 (medium) — SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f)github_advisories · 2026-09-03
- [GHSA] GHSA-99rq-75j6-5j9f (high) — SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypassgithub_advisories · 2026-09-03
- FalconFlank: CrowdStrike Falcon 0-Day PoCsocradar_blog · 2026-09-03
- [GHSA] GHSA-78x9-fhhx-v2g6 (medium) — CKAN MCP Server: Cache-key canonicalization collision enables cache confusion / poisoninggithub_advisories · 2026-09-03
- [GHSA] GHSA-6f9w-9hf2-5rg3 (low) — CKAN MCP Server: Information disclosure via verbose error reflectiongithub_advisories · 2026-09-03
- F5 security advisory (AV26-878)cccs_ca · 2026-09-03
- Jenkins security advisory (AV26-877)cccs_ca · 2026-09-03
- CVE-2026-80530: Linux XFS EXCHANGE_RANGE reflink flag clearing leading to local privilege escalationoss_sec · 2026-09-03
- Cisco security advisory (AV26-876)cccs_ca · 2026-09-03
- [NVD] CVE-2026-85174 (HIGH 8.8) — SiYuan before v3.8.2 logs API tokens from query parameters in plaintext to an accessible log file when full-text search requests exceed timing thresholds. Authenticated attackers can read the log file via the getFile endpoint to recover admin API tokens and gain permanent adminisnvd · 2026-09-03
- [NVD] CVE-2026-85164 (HIGH 7.1) — WWBN AVideo through commit c91b5975d contains a server-side request forgery vulnerability in the set_api_userImages API endpoint that fails to validate profileImg and backgroundImg URLs before fetching them. Authenticated API clients can supply internal URLs to fetch cloud metadanvd · 2026-09-03
- [NVD] CVE-2026-85159 (MEDIUM 5.4) — AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in userLogin.php where the cancelUri parameter is echoed in an href attribute after isSafeRedirectURL checks protocol only, not HTML characters. Unauthenticated attackers can inject event handnvd · 2026-09-03
- [NVD] CVE-2026-85154 (CRITICAL 9.8) — WWBN AVideo contains an authentication failure vulnerability where the video_id_hash credential is a non-expiring, non-revocable bearer token that grants full administrator session access to the video owner's account. Attackers who obtain a video_id_hash can replay it indefinitelnvd · 2026-09-03
- [NVD] CVE-2026-85150 (HIGH 7.5) — A NULL pointer dereference flaw was found in GStreamer's RTSP support library. The vulnerability occurs while parsing an Authorization or WWW-Authenticate header that uses Digest authentication. Specially crafted whitespace placement around a parameter's terminator can cause an invd · 2026-09-03
- [NVD] CVE-2026-85106 (MEDIUM 6.3) — A vulnerability has been found in NousResearch hermes-agent 0.18.0. This affects the function fetchLinkTitle of the file apps/desktop/src/app/artifacts/index.tsx of the component Link Title Fetch. Such manipulation of the argument url leads to server-side request forgery. The attnvd · 2026-09-03
- [NVD] CVE-2026-85090 (MEDIUM 5.4) — FreeRDP before 3.31.0 contains a heap out-of-bounds read vulnerability in the general_ChromaV1ToYUV444 function during AVC444 chroma plane reconstruction. A malicious RDP server can craft a RFX_AVC444_BITMAP_STREAM with specific frame geometry to trigger an out-of-bounds memory rnvd · 2026-09-03
- [NVD] CVE-2026-85030 (LOW 3.7) — A vulnerability has been found in HKUDS AI-Trader up to d03ff6c056b32ced735adf7c19ed8175adb1c8df. The affected element is an unknown function of the file service/server/routes_agent.py of the component selfRegister API Endpoint. Such manipulation of the argument initial_balance lnvd · 2026-09-03
- [NVD] CVE-2026-74769 (MEDIUM 6.5) — Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain an Incorrect Authorization vulnerability in the REST API. A low privileged remote attacker could potentially exploit this vulnerability, leading to Protection mechanism bypass.nvd · 2026-09-03
- [NVD] CVE-2026-71222 (MEDIUM 5.3) — A heap out-of-bounds read vulnerability was found in gfs2-utils. The ea_num_ptrs field from on-disk extended attribute metadata is consumed without bounds validation, causing a heap buffer over-read that may disclose sensitive memory contents or cause a crash when processing crafnvd · 2026-09-03
- [NVD] CVE-2026-3416 (MEDIUM 5.9) — The API Publisher component previously used a non-cryptographic pseudorandom number generator (PRNG) to create shared secrets for Webhook HMAC validation. This PRNG lacks sufficient entropy for security-sensitive operations, allowing a sophisticated attacker to predict future secnvd · 2026-09-03
- Someone Else Is Using Your AIfortinet_research · 2026-09-03
- [krybit] ligacancerguate.org posted to leak siteransomware_live · 2026-09-03
- [Vexy Ransomware] McDonald's Ecuador posted to leak siteransomware_live · 2026-09-03
- Preparing for the Post-Quantum Era: A Call to Actioncisa_advisories · 2026-09-03
- Tycon Systems TPDIN-Monitor-WEB2 (Update A)cisa_advisories · 2026-09-03
- Rockwell Automation 1756-ENBT Modulecisa_advisories · 2026-09-03
- Inductive Automation Ignitioncisa_advisories · 2026-09-03
- OPCFoundation OPC UA LocalDiscoveryServer (LDS)cisa_advisories · 2026-09-03
- Tycon Systems TPDIN-Monitor-WEB3cisa_advisories · 2026-09-03
- Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products (Update A)cisa_advisories · 2026-09-03
- Rockwell Automation ControlFLASHcisa_advisories · 2026-09-03
- Rockwell Automation ArmorStart LTcisa_advisories · 2026-09-03
- IXON VPN Clientcisa_advisories · 2026-09-03
- Pyramid Solutions NetStaX EtherNet/IP Stackcisa_advisories · 2026-09-03
- US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countriesthehackernews · 2026-09-03
- [Panzer] Dinas Komunikasi dan Informatika posted to leak siteransomware_live · 2026-09-03
- [Wallstreet] America’s Food Basket posted to leak siteransomware_live · 2026-09-03
- Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacksthehackernews · 2026-09-03
- Shai-Hulud's Reach Just Grew to 469 Credential Locations. Here's What That Meansthehackernews · 2026-09-03
- Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin Americaunit42 · 2026-09-03
- [Vexy Ransomware] Engefitas posted to leak siteransomware_live · 2026-09-03
- Your phone or computer may soon ask how old you aremalwarebytes_blog · 2026-09-03
- FBI Investigates Nexus Claim of 153M+ Driver’s License Recordssocradar_blog · 2026-09-03
- Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhonethehackernews · 2026-09-03
- [Storm] Petrocare Construction posted to leak siteransomware_live · 2026-09-03
- [Storm] Star Aviation, Inc posted to leak siteransomware_live · 2026-09-03
- [Storm] GSAC Auto Financing posted to leak siteransomware_live · 2026-09-03
- [Storm] GSAC posted to leak siteransomware_live · 2026-09-03
- [Storm] Superior Ag posted to leak siteransomware_live · 2026-09-03
- [Storm] Chicago Partners Wealth Advisors posted to leak siteransomware_live · 2026-09-03
- [Storm] Macquarrie posted to leak siteransomware_live · 2026-09-03
- [Storm] SITES Medical posted to leak siteransomware_live · 2026-09-03
- Supply Chain Attacks in 2026: Why Threat Intelligence Is the Only Early Warning System That Workscyble · 2026-09-03
- Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falconthehackernews · 2026-09-03
- The CRA Reporting Deadline Is Almost Heresonatype · 2026-09-03
- CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Minersthehackernews · 2026-09-03
- [NVD] CVE-2026-84886 (MEDIUM 5.3) — A vulnerability was determined in simular-ai Agent-S up to 0.3.2. Affected by this vulnerability is the function ImageData of the file gui_agents/s1/utils/ocr_server.py of the component OCR HTTP API. Executing a manipulation of the argument img_bytes can lead to resource consumptnvd · 2026-09-03
- Srsly Risky Biz: China's botnets are worth disruptingriskybiz_news · 2026-09-03
- GitHub Enterprise Server Multiple Vulnerabilitieshkcert · 2026-09-03
- Cisco Products Multiple Vulnerabilitieshkcert · 2026-09-03
- Jenkins Multiple Vulnerabilitieshkcert · 2026-09-03
- H1 2026 Malware Vulnerability Trendsrecordedfuture · 2026-09-03
- [GHSA] GHSA-2mw5-23gm-pccq (high) — OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged podsgithub_advisories · 2026-09-02
- [GHSA] GHSA-c5f6-2rm9-2w8g (medium) — OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass)github_advisories · 2026-09-02
- [GHSA] GHSA-52gf-6rpq-fgmx (high) — OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpointsgithub_advisories · 2026-09-02
- [GHSA] GHSA-qh9r-j7rp-4x2m (critical) — OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIsgithub_advisories · 2026-09-02
- [GHSA] GHSA-w878-pj84-3j5v (high) — Mailpit: SMTP command parser buffers unbounded command lines before syntax rejectiongithub_advisories · 2026-09-02
- [GHSA] GHSA-gv5w-hfx8-8cwq (high) — SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling pathsgithub_advisories · 2026-09-02
- [GHSA] GHSA-75mr-qw9x-3r39 (high) — Mailpit: Thumbnail generation decodes unbounded image dimensions before scalinggithub_advisories · 2026-09-02
- [SilentRansomGroup] Greenberg Traurig posted to leak siteransomware_live · 2026-09-02
- Impersonating IT support: how threat actors turn a remote session into enterprise-wide accessmsstic · 2026-09-02
- [GHSA] GHSA-76g3-c3x4-crvx (high) — Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by defaultgithub_advisories · 2026-09-02
- [GHSA] GHSA-gcr2-9v8m-gq45 (medium) — DiceBear: SVG injection via the unescaped rotate option in @dicebear/core (and fontSize/fontWeight in @dicebear/initials)github_advisories · 2026-09-02
- [GHSA] GHSA-7mqg-cx4g-x2rf (high) — Omnigent Guardrail policy bypass: shell-command parser fails open in policies/builtins/_shell.pygithub_advisories · 2026-09-02
- [GHSA] GHSA-4q39-2jhr-7qx8 (high) — Plate: SSRF with response disclosure in DOCX image embeddinggithub_advisories · 2026-09-02
- [GHSA] GHSA-g29j-rwfv-h99w (high) — Handlebars.java: Arbitrary file read in `SpringTemplateLoader` via URL-fragment suffix bypassgithub_advisories · 2026-09-02
- [GHSA] GHSA-7w2g-9mf9-324m (medium) — Hurl: Cookies in Cookies section leak when redirecting to a different hostgithub_advisories · 2026-09-02
- [GHSA] GHSA-mvxr-6m87-mv2q (medium) — Mail: Email address spoofing via malformed RFC 2047 encoded-wordsgithub_advisories · 2026-09-02
- [GHSA] GHSA-7mgc-c7pq-3rr3 (high) — Grav: 2FA Bypass via 'login.regenerate2FASecret' - Secret Rotation During Pending Challengegithub_advisories · 2026-09-02
- [GHSA] GHSA-p8rw-8qj3-hf33 (high) — Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNNER_WORKSPACEgithub_advisories · 2026-09-02
- [GHSA] GHSA-jrrm-9hc7-2v3h (critical) — Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCEgithub_advisories · 2026-09-02
- [GHSA] GHSA-756x-9hf6-q4h4 (high) — Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Toolsgithub_advisories · 2026-09-02
- [GHSA] GHSA-mc5q-6hpj-rp7j (medium) — Grav: Twig sandbox config exfiltration via grav.offsetGet + dump filter (CVE-2026-44738 bypass)github_advisories · 2026-09-02
- [GHSA] GHSA-928x-9mpw-8h56 (medium) — Grav: Decompression Bomb via ZipArchiver - Missing Extraction Limitsgithub_advisories · 2026-09-02
- [GHSA] GHSA-cpjf-6666-r8fx (high) — link-preview-js DNS Rebinding SSRF Bypass / Incomplete Fix for CVE-2026-43897github_advisories · 2026-09-02