THREAT OPS › Threat News
Threat Intelligence News
11606 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [GHSA] GHSA-928x-9mpw-8h56 (medium) — Grav: Decompression Bomb via ZipArchiver - Missing Extraction Limitsgithub_advisories · 2026-09-02
- [GHSA] GHSA-cpjf-6666-r8fx (high) — link-preview-js DNS Rebinding SSRF Bypass / Incomplete Fix for CVE-2026-43897github_advisories · 2026-09-02
- [NVD] CVE-2026-75135 (MEDIUM 6.1) — UpSignOn for Windows before 7.19.0 contains a sensitive data exposure vulnerability that allows local attackers to recover the master password and decrypt vault contents by reading a retained backup key from the process memory of UpSignOn.exe, even after the vault has been re-locnvd · 2026-09-02
- [SilentRansomGroup] G... ...g posted to leak siteransomware_live · 2026-09-02
- [SilentRansomGroup] S... M... posted to leak siteransomware_live · 2026-09-02
- [NVD] CVE-2026-84841 (HIGH 7.3) — A security flaw has been discovered in tsi-coop tsi-dpdp-cms up to 0.5.0. This vulnerability affects unknown code. The manipulation results in client-side enforcement of server-side security. The attack can be launched remotely. The exploit has been released to the public and maynvd · 2026-09-02
- [NVD] CVE-2026-84381 (HIGH 8.1) — HTTPX2 is a next generation HTTP client for Python. Prior to 2.10.0, httpcore2 fails to start TLS in src/httpcore2/httpcore2/_sync/socks_proxy.py and src/httpcore2/httpcore2/_async/socks_proxy.py when the remote origin uses wss through a SOCKS5 proxy because the TLS upgrade condinvd · 2026-09-02
- Fwd: Vulnerabilities in golang.org/x/cryptooss_sec · 2026-09-02
- AI Agents Are Now Emailing Me with Their Security Concernsschneier · 2026-09-02
- Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programsthehackernews · 2026-09-02
- [NVD] CVE-2026-66786 (CRITICAL 9.1) — A flaw was found in submariner. In cert-auth mode, the connection configuration is built using free-form strings from the Custom Resource Definition (CRD) without proper validation. A malicious cluster can exploit this by publishing a CableName that includes newlines and ipsec.convd · 2026-09-02
- [NVD] CVE-2026-53671 — PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Interpretation Layer. Prior to version 0.2.4, the abstract transformer in prevail treats writes through a T_CTX-typed base register as a silent no-op: do_mem_store in src/crab/ebpf_transformer.cpp only models T_STACKnvd · 2026-09-02
- Demystifying Agent Tradecraft: Introducing SpecterOps Skillsspecterops · 2026-09-02
- [direwolf] Cartrack Holdings posted to leak siteransomware_live · 2026-09-02
- [NVD] CVE-2026-20280 (HIGH 8.8) — As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovernvd · 2026-09-02
- [NVD] CVE-2026-20279 (CRITICAL 9.8) — As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vunvd · 2026-09-02
- [NVD] CVE-2026-20278 (HIGH 8.8) — As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vunvd · 2026-09-02
- [NVD] CVE-2026-20277 (HIGH 8.2) — As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vunvd · 2026-09-02
- [NVD] CVE-2026-20276 (HIGH 8.6) — As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vunvd · 2026-09-02
- [NVD] CVE-2026-20275 (HIGH 8.8) — As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vunvd · 2026-09-02
- [NVD] CVE-2026-20274 (CRITICAL 9.8) — As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vunvd · 2026-09-02
- [direwolf] PTT Oil and Retail Business posted to leak siteransomware_live · 2026-09-02
- [Wallstreet] Ormond Beach Florida posted to leak siteransomware_live · 2026-09-02
- Fake Software Installers Disable Windows Update and Weaken Microsoft Defenderthehackernews · 2026-09-02
- [NVD] CVE-2026-84657 (MEDIUM 4.2) — In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the build CLI command does not check the Item/Cancel permission when using the -s flag to cancel a build triggered to wait for completion, allowing attackers with Item/Build permission to cancel builds started by other users.nvd · 2026-09-02
- [NVD] CVE-2026-84655 (MEDIUM 4.3) — Jenkins 2.579 and earlier, LTS 2.568.2 and earlier does not escape map keys when serializing objects as JSON and Python through its REST API, allowing attackers able to control map property names to inject arbitrary fields into JSON and Python API responses.nvd · 2026-09-02
- [NVD] CVE-2026-84653 (LOW 3.5) — Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not correctly perform permission checks in the Appearance configuration page, allowing attackers with Overall/Manage permission to modify Appearance configuration options they should nnvd · 2026-09-02
- [NVD] CVE-2026-84652 (HIGH 7.3) — In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenkins does not rotate the session when a user is authenticated via the "remember me" cookie, allowing attackers able to serve content on the same site as Jenkins to set a known session cookie in the victim's browser, which nvd · 2026-09-02
- [NVD] CVE-2026-84651 (MEDIUM 6.3) — In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the REST API and CLI endpoints for updating agent configuration do not prevent a submitted configuration from overwriting a different agent by specifying that agent's name in the submitted XML document, allowing attackers witnvd · 2026-09-02
- [NVD] CVE-2026-84650 (HIGH 8.8) — In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded from deserialization, allowing attackers able to submit configuration updates to specify the values of transient fields that will be deserialized, the impact depending on how those fields anvd · 2026-09-02
- [NVD] CVE-2026-84648 (HIGH 8.8) — In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the system log viewer does not escape log record metadata (source, level, and timestamp) resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers in control of agent processes.nvd · 2026-09-02
- [NVD] CVE-2026-84646 (MEDIUM 4.3) — In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user objects can appear as nested field values in other deserialized XML objects, allowing attackers with Overall/Read permission to create user objects by submitting crafted XML.nvd · 2026-09-02
- [NVD] CVE-2026-84645 (HIGH 8.8) — In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marked as storing their configuration in independent top-level configuration files in Jenkins (such as the global configuration and jobs) can appear as nested field values in user-submitted `config.xml` documnvd · 2026-09-02
- [NVD] CVE-2026-78408 (HIGH 7.9) — The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a prnvd · 2026-09-02
- [NVD] CVE-2026-63020 (LOW 3.1) — A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages Impact: An attacker may trick authenticated BIG-IP users into accessing malicious links and reflect a spoofed error message in the victim's BIG-nvd · 2026-09-02
- [NVD] CVE-2026-14199 (HIGH 7.1) — Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delimiter, so distinct identities could collidnvd · 2026-09-02
- Cisco IOS XR Software Security Hardening Release: September 2026cisco_psirt · 2026-09-02
- Cisco Secure Email Secure/Multipurpose Internet Mail Extensions Ciphertext Decryption Vulnerabilitiescisco_psirt · 2026-09-02
- Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerabilitycisco_psirt · 2026-09-02
- Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Denial of Service Vulnerabilitycisco_psirt · 2026-09-02
- M-25-21 Changes the AI Conversation for Federal Civilian Agencieszscaler_threatlabz · 2026-09-02
- Tech support scams look different now. Here’s what to watch formalwarebytes_blog · 2026-09-02
- [GHSA] GHSA-5jgf-p345-68v8 (high) — fast-uri vulnerable to host confusion via skipped IDN canonicalization on scheme-relative referencesgithub_advisories · 2026-09-02
- [GHSA] GHSA-f65p-4m7j-42xc (high) — fast-uri vulnerable to server-side request forgery via malformed IPv6 normalizationgithub_advisories · 2026-09-02
- [GHSA] GHSA-fph4-wmhf-6fwf (high) — fast-uri vulnerable to server-side request forgery via repeated hostname percent-decodinggithub_advisories · 2026-09-02
- [GHSA] GHSA-jqff-g426-hqxp (high) — fast-uri vulnerable to host confusion via percent-encoded scheme normalizationgithub_advisories · 2026-09-02
- [GHSA] GHSA-p3m8-78j2-g5p3 (high) — NLTK: Default ENFORCE=False Disables All pathsec Security Controlsgithub_advisories · 2026-09-02
- [GHSA] GHSA-3gqm-fcw5-w839 (medium) — NLTK: SSRF Fail-Open in validate_network_url() via DNS Resolution Failuregithub_advisories · 2026-09-02
- When to Use Orca’s Threat Investigator Agent vs. Build Your Own on the Orca MCP Serverorca_security · 2026-09-02
- Progress Software security advisory (AV26-875)cccs_ca · 2026-09-02
- Zscaler and CrowdStrike Expand Strategic Partnership with Integrations to Unify Cross-Domain Securityzscaler_threatlabz · 2026-09-02
- [GHSA] GHSA-6gmq-8vp8-gcm6 (medium) — xmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFormed serializationgithub_advisories · 2026-09-02
- [GHSA] GHSA-6m44-fpc8-c3rq (high) — Mistune: Denial of Service — RecursionError via Excessive Emphasis Markers in Markdowngithub_advisories · 2026-09-02
- [GHSA] GHSA-3m5p-2c4r-xxw2 (medium) — fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-countgithub_advisories · 2026-09-02
- [GHSA] GHSA-w2qp-rph6-63g4 (medium) — fastify vulnerable to schema validation bypass via root primitive coercion mismatchgithub_advisories · 2026-09-02
- [GHSA] GHSA-vmg4-6gfg-83qx (high) — ApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persistent DoSgithub_advisories · 2026-09-02
- [GHSA] GHSA-pp4x-ccxq-6r33 (medium) — Sulu: Stored XSS via media download inline-disposition overridegithub_advisories · 2026-09-02
- [GHSA] GHSA-65cv-w493-7vhq (medium) — Sulu: Fix authorization bypass when creating preview linksgithub_advisories · 2026-09-02
- Attackers Actively Exploiting Critical Vulnerability in Elementor Pro Pluginwordfence · 2026-09-02
- Anatomy of a Silent Domain Takeoverqualys · 2026-09-02
- Ransom & Dark Web Issues Week 1, September 2026ahnlab · 2026-09-02
- Attack Cases in Korea Involving the Installation of Radmin and UltraVNCahnlab · 2026-09-02
- Detection and Removal of the Syslogk Rootkit in a Linux Environmentahnlab · 2026-09-02
- I just trusted the security certificate prompt… Beware of the LegionLoader malware being distributed via the ClickFix methodahnlab · 2026-09-02
- [incransom] Asfaltos y Pavimentos S.A. (Asfalpasa) posted to leak siteransomware_live · 2026-09-02
- [GHSA] GHSA-h6cx-gjxx-v25c (medium) — Sulu: Media move/update authorization bypass (IDOR)github_advisories · 2026-09-02
- [incransom] Westfield Public School District posted to leak siteransomware_live · 2026-09-02
- [incransom] Trucka posted to leak siteransomware_live · 2026-09-02
- [incransom] Policlinico Triestino posted to leak siteransomware_live · 2026-09-02
- [incransom] Multiver Ltée posted to leak siteransomware_live · 2026-09-02
- [GHSA] GHSA-79qf-vqgc-7xx3 (medium) — ApostropheCMS: Arbitrary file read via import-export attachment-name path traversalgithub_advisories · 2026-09-02
- [incransom] Metales Panamericanos posted to leak siteransomware_live · 2026-09-02
- [GHSA] GHSA-6j4c-mgqr-qv76 (medium) — Kirby: Access to image files outside of the site root via path traversal in the media handlinggithub_advisories · 2026-09-02
- [GHSA] GHSA-cxq5-97v7-87j8 (high) — Orval: Generation-time SSRF + remote/local file inclusion via unrestricted $refgithub_advisories · 2026-09-02
- [GHSA] GHSA-p4cg-3328-rvfg (critical) — Orval: Import-time RCE via query-parameter default -> zod module-level template literalgithub_advisories · 2026-09-02
- [GHSA] GHSA-6mr6-jvcr-2f25 (critical) — Orval: Import-time RCE via schema property name -> computed-property-key injection in the zod clientgithub_advisories · 2026-09-02
- [GHSA] GHSA-83x6-42hr-jc76 (medium) — CKAN MCP Server: MQA server allowlist bypass via unanchored regex (`isValidMqaServer`)github_advisories · 2026-09-02
- [GHSA] GHSA-2v6v-25fm-p4fg (critical) — SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative controlgithub_advisories · 2026-09-02
- [GHSA] GHSA-fj2p-qj2f-74v5 (high) — Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData()github_advisories · 2026-09-02
- [GHSA] GHSA-x5fp-wj9c-mxmx (medium) — qs array-limit bypass via bracket-key comma parsinggithub_advisories · 2026-09-02
- [GHSA] GHSA-4mjr-xmp4-gh2g (medium) — qs: Denial of Service via Attacker Controlled isBuffergithub_advisories · 2026-09-02
- [GHSA] GHSA-cp6q-959q-f8rh (medium) — Tiptap: mergeAttributes() turns an own __proto__ key into inherited executable DOM attributesgithub_advisories · 2026-09-02
- [GHSA] GHSA-g2fm-8hr4-j82h (high) — EasyAdmin custom-action dispatcher bypasses access_control on other routesgithub_advisories · 2026-09-02
- [GHSA] GHSA-g3hc-697w-wm82 (medium) — Livewire DOM-based cross-site scripting during client-side state handlinggithub_advisories · 2026-09-02
- [GHSA] GHSA-mpf4-983q-p7j4 (high) — Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loopgithub_advisories · 2026-09-02
- [GHSA] GHSA-x8wg-4xgc-vr54 (medium) — Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry rootgithub_advisories · 2026-09-02
- [GHSA] GHSA-fc8x-2rww-xw9m (medium) — pypdf: Inefficient handling of non-whitespace inputs in read_until_whitespacegithub_advisories · 2026-09-02
- [GHSA] GHSA-gxmj-r5rf-ggwq (high) — elFinder: ZIP extraction bypasses uploadDeny MIME filter allowing PHP file upload (RCE)github_advisories · 2026-09-02
- [GHSA] GHSA-9hjf-w35w-6vx2 (medium) — elFinder: CSRF in netmount allows forced FTP mounts and server-side FTP connectionsgithub_advisories · 2026-09-02
- [GHSA] GHSA-c59q-g84q-2gj5 (high) — pnpm: Virtual store linker path traversal via unvalidated depPath name in lockfileToDepGraphgithub_advisories · 2026-09-02
- [GHSA] GHSA-vq4v-j7r6-jq4m (high) — pnpm: A tarball dependency's manifest `name` escapes node_modules → arbitrary file write/overwrite on installgithub_advisories · 2026-09-02
- [GHSA] GHSA-ww6m-cw3f-q94g (medium) — NLTK: Quadratic-time DoS in PorterStemmer via long runs of 'y'github_advisories · 2026-09-02
- [GHSA] GHSA-f794-5jv7-7672 (medium) — NLTK: Downloader.download follows hardlinks and overwrites outside-root filesgithub_advisories · 2026-09-02
- [GHSA] GHSA-8mgp-746c-j5xp (high) — NLTK: Model-artifact APIs bypass pathsec and touch files outside allowed rootsgithub_advisories · 2026-09-02
- [GHSA] GHSA-vp2x-qp44-57v7 (medium) — NLTK: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()`github_advisories · 2026-09-02
- [GHSA] GHSA-ff5c-cp5c-9wjf (medium) — NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammarsgithub_advisories · 2026-09-02
- [GHSA] GHSA-cw6x-m8jw-qmrh (medium) — NLTK: Uncontrolled recursion in nltk.featstruct.FeatStructReader causes unhandled RecursionError (DoS) via deeply nested feature-structure inputgithub_advisories · 2026-09-02
- Google security advisory (AV26-874)cccs_ca · 2026-09-02
- [GHSA] GHSA-p498-v437-472g (medium) — humanfs: Recursive copy follows symlinked files and copies data from outside the source treegithub_advisories · 2026-09-02
- [kairos] Ville de Libercourt posted to leak siteransomware_live · 2026-09-02