THREAT OPS › Threat News
Threat Intelligence News
11607 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [kairos] Ville de Libercourt posted to leak siteransomware_live · 2026-09-02
- [insomnia] N*************** posted to leak siteransomware_live · 2026-09-02
- Multiple vulnerabilities in Jenkins and Jenkins pluginsoss_sec · 2026-09-02
- [akira] PennFab posted to leak siteransomware_live · 2026-09-02
- [GHSA] GHSA-qxc2-j82w-r537 (high) — Faker: helpers.fake exploitable into arbritary code executiongithub_advisories · 2026-09-02
- [GHSA] GHSA-275h-v5h9-vr82 (high) — Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.dbgithub_advisories · 2026-09-02
- [GHSA] GHSA-h89q-4j2h-7h88 (high) — SiYuan: SQL Query in Block Search Exposes Hidden Published Document Contentgithub_advisories · 2026-09-02
- U.K. Supreme Court Opens Door for Spyware Victims to Sue Foreign Statescitizenlab · 2026-09-02
- Bring Orca Security Context Into the AWS Console with the Orca Browser Extensionorca_security · 2026-09-02
- Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Codethehackernews · 2026-09-02
- [akira] ScrubaDub Auto Wash Centers posted to leak siteransomware_live · 2026-09-02
- [akira] Algra Group posted to leak siteransomware_live · 2026-09-02
- Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pagesthehackernews · 2026-09-02
- HPE security advisory (AV26-873)cccs_ca · 2026-09-02
- One Year of Decipher (Relaunched)duo_decipher · 2026-09-02
- [Eclipse] part1.simplexengg.in posted to leak siteransomware_live · 2026-09-02
- BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Accessthehackernews · 2026-09-02
- CTEM Is Not About the Stages. It’s About the Outcome.horizon3 · 2026-09-02
- [qilin] Uak University posted to leak siteransomware_live · 2026-09-02
- SonicWall security advisory (AV26-872)cccs_ca · 2026-09-02
- Scammers are getting smarter about where they target youmalwarebytes_blog · 2026-09-02
- [Control systems] Schneider Electric security advisory (AV26-871)cccs_ca · 2026-09-02
- Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Controlthehackernews · 2026-09-02
- [Eclipse] Royal Plaza On Scotts posted to leak siteransomware_live · 2026-09-02
- Communicating Under Pressure: Best Practices for Service Providerscisa_advisories · 2026-09-02
- CISA Adds Seven Known Exploited Vulnerabilities to Catalogcisa_advisories · 2026-09-02
- How to Secure Enterprise AI: From Adoption to Incident Readinessthehackernews · 2026-09-02
- Two critical Chrome flaws put users at risk on malicious websitesmalwarebytes_blog · 2026-09-02
- Re: Fwd: [Announce] Libgcrypt 1.12.3 releasedoss_sec · 2026-09-02
- [SECURITY ADVISORIES] curl 8.22.0oss_sec · 2026-09-02
- Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chainthehackernews · 2026-09-02
- [thegentlemen] Seasia Infotech posted to leak siteransomware_live · 2026-09-02
- Wireless Routers as Motion Detectorsschneier · 2026-09-02
- Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weaponcheckpoint_research · 2026-09-02
- Dark web site puts 153 million driver’s licenses and millions more IDs up for salemalwarebytes_blog · 2026-09-02
- An AI-Assisted Cyber Attack: Inside a Unit 42 Investigationunit42 · 2026-09-02
- [incransom] specialtytextile.com posted to leak siteransomware_live · 2026-09-02
- [medusalocker] Licindia posted to leak siteransomware_live · 2026-09-02
- Your AI chats could be used in courtmalwarebytes_blog · 2026-09-02
- GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backendsthehackernews · 2026-09-02
- [NVD] CVE-2026-53683 (MEDIUM 4.3) — reset_password.html parses query string parameters and uses the 'url' parameter as a redirection target (window.location = url) after password reset, optionally delayed by a 'delay' parameter. No validation or allowlisting is performed on url, enabling an attacker to redirect usenvd · 2026-09-02
- Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousandsthehackernews · 2026-09-02
- CVE-2026-81928: Net::DNS versions before 1.57 for Perl allow memory exhaustion via unbounded recursion in sig_data when re-encoding a message with a misplaced TSIG recordoss_sec · 2026-09-02
- Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Anotherthehackernews · 2026-09-02
- Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentialsthehackernews · 2026-09-02
- Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloadsthehackernews · 2026-09-02
- [aurora] Chip 1 Exchange posted to leak siteransomware_live · 2026-09-02
- [qilin] Grayson Rural Electric Cooperative posted to leak siteransomware_live · 2026-09-02
- [anubis] Marlborough Partners posted to leak siteransomware_live · 2026-09-02
- Mozilla Products Multiple Vulnerabilitieshkcert · 2026-09-02
- Risky Bulletin: BGP hijack delivers malicious Virtualizor updatesriskybiz_news · 2026-09-02
- Google Chrome Multiple Vulnerabilitieshkcert · 2026-09-02
- F5 Products Multiple Vulnerabilitieshkcert · 2026-09-02
- RedHat Linux Kernel Multiple Vulnerabilitieshkcert · 2026-09-02
- [CISA KEV] CVE-2026-59822 — BerriAI LiteLLM: BerriAI LiteLLM Improper Authentication Vulnerabilitycisa_kev · 2026-09-02
- [CISA KEV] CVE-2026-48710 — Kludex Starlette: Kludex Starlette HTTP Request/Response Smuggling Vulnerabilitycisa_kev · 2026-09-02
- [CISA KEV] CVE-2026-49869 — Kestra Kestra OSS: Kestra OSS OS Command Injection Vulnerabilitycisa_kev · 2026-09-02
- [CISA KEV] CVE-2026-83549 — SonicWall SMA1000 Appliances: SonicWall SMA1000 Appliances OS Command Injection Vulnerabilitycisa_kev · 2026-09-02
- REVSTEALER ramps up: analysis of up-and-coming infostealerelastic_security · 2026-09-02
- [CISA KEV] CVE-2026-82329 — JFrog Artifactory: JFrog Artifactory Improper Authentication Vulnerabilitycisa_kev · 2026-09-02
- [CISA KEV] CVE-2026-9586 — Sangoma Switchvox: Sangoma Switchvox SQL Injection Vulnerabilitycisa_kev · 2026-09-02
- [CISA KEV] CVE-2026-83548 — SonicWall SMA1000 Appliances: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerabilitycisa_kev · 2026-09-02
- Counterfeit installers to system compromise: Tracking a deceptive software download campaignmsstic · 2026-09-01
- FBI Probes Service Selling 153M+ Drivers Licenseskrebs · 2026-09-01
- [Global Secret Group] Quality Resource Pvt posted to leak siteransomware_live · 2026-09-01
- [GHSA] GHSA-vp52-pcj8-j9qc (high) — gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentationgithub_advisories · 2026-09-01
- [GHSA] GHSA-68jx-f42c-7599 (high) — TYPO3 CMS - Broken Access Control in Backend and Install Toolgithub_advisories · 2026-09-01
- [GHSA] GHSA-r3j6-gpjw-qfjr (medium) — Filament: Multi-factor authentication (app) codes can still be used after a newer code has been usedgithub_advisories · 2026-09-01
- [GHSA] GHSA-xwpv-pqxp-5v36 (low) — Filament: Password validity disclosure for accounts denied panel access on login pagegithub_advisories · 2026-09-01
- [GHSA] GHSA-52xp-w8hr-xv3c (high) — Filament: Multi-factor authentication (app) can be bypassed when recovery codes are enabledgithub_advisories · 2026-09-01
- [GHSA] GHSA-23w6-3w8w-8484 (medium) — pypdf: Possible long runtimes/large memory usage when retrieving outlinesgithub_advisories · 2026-09-01
- [GHSA] GHSA-763m-79hh-57f2 (medium) — pypdf: Possible long runtimes/large memory usage when extracting XForm objectsgithub_advisories · 2026-09-01
- [SilentRansomGroup] Holland & Knight posted to leak siteransomware_live · 2026-09-01
- [GHSA] GHSA-jp53-mhqp-8xcg (medium) — pypdf: Possible infinite loop for TreeObject.insert_childgithub_advisories · 2026-09-01
- [GHSA] GHSA-cfqr-cjx5-5jcm (medium) — sqlparse: Reindentation of tuple lists causes near-cap quadratic CPU consumptiongithub_advisories · 2026-09-01
- [GHSA] GHSA-g8qq-57p8-ggw5 (medium) — ApostropheCMS: Stored XSS via SVG SMIL URI-list scheme-policy bypassgithub_advisories · 2026-09-01
- [NVD] CVE-2026-73750 (HIGH 8.8) — Vulnerabilities exist in the authentication module that may improperly process malformed or truncated input. An authenticated remote attacker could exploit these vulnerabilities by providing specially crafted input from a compromised or hostile authentication server. Successful envd · 2026-09-01
- CVE-2026-32773: Apache Spark: XSS Vulnerability in Spark Web 3.5.4oss_sec · 2026-09-01
- CVE-2026-80205 : ReDoS in NLTK Text.findall() (CVSS 8.7 High)oss_sec · 2026-09-01
- [GHSA] GHSA-m4rf-3fr8-xwx3 (critical) — NLTK: JVM argument injection bypass via per-call options in the NLTK Stanford wrappers (incomplete fix of CVE-2026-12841)github_advisories · 2026-09-01
- [GHSA] GHSA-8rr7-cvq3-gmfh (high) — league/commonmark: Denial of service via distinctly-named attributes in the Attributes extensiongithub_advisories · 2026-09-01
- [GHSA] GHSA-6hwm-xvph-95vm (high) — NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binarygithub_advisories · 2026-09-01
- [GHSA] GHSA-jjv6-8j6v-6j52 (high) — league/commonmark: Denial of service in the SmartPunct and Attributes extensionsgithub_advisories · 2026-09-01
- [GHSA] GHSA-f8fg-pg57-v4j8 (high) — league/commonmark XSS: `on*` event-handler filter in `AttributesExtension` bypassed with a U+000C form feedgithub_advisories · 2026-09-01
- [GHSA] GHSA-j8pm-gj4c-rq4x (high) — league/commonmark: Denial of service via crafted code fences, reference links, and emphasis delimitersgithub_advisories · 2026-09-01
- [GHSA] GHSA-8423-8fgw-73vq (medium) — tornado: multipart split() creates huge temp list before max_parts check -> memory amplification DoS (httputil.py:34)github_advisories · 2026-09-01
- [GHSA] GHSA-wwv5-g3v4-889x (low) — Tornado: Incomplete fix for CVE-2026-35536: cookie attribute injection re-opened via the legacy case-insensitive `**kwargs` path in `set_cookie`github_advisories · 2026-09-01
- [GHSA] GHSA-2m8g-3cmr-wg3w (medium) — Django REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZE` when parsing oversized JSON and urlencoded request bodies via DRF `request.data`github_advisories · 2026-09-01
- [GHSA] GHSA-g47c-3xmw-q6m2 (medium) — Django REST framework: AdminRenderer may disclose GET-protected data when rendering invalid write requestsgithub_advisories · 2026-09-01
- [GHSA] GHSA-xwg4-73v4-xw9w (high) — nanoid: Integer Overflow or Wraparoundgithub_advisories · 2026-09-01
- [GHSA] GHSA-vx52-2968-3vc6 (high) — pnpm: Environment secrets exfiltrated via env-placeholder expansion in proxy settings read from an untrusted pnpm-workspace.yamlgithub_advisories · 2026-09-01
- [GHSA] GHSA-2rx9-3g3h-c2jv (high) — pnpm: pacquet trust-lockfile install can create dependency symlinks outside the projectgithub_advisories · 2026-09-01
- Cybersecurity IR Workshop: The workshop you shouldn’t missmsstic · 2026-09-01
- [GHSA] GHSA-3wgp-x9p5-c7cc (medium) — Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routesgithub_advisories · 2026-09-01
- Erlang security advisory (AV26-870)cccs_ca · 2026-09-01
- Rockwell Automation security advisory (AV26-869)cccs_ca · 2026-09-01
- [NVD] CVE-2026-52023 (HIGH 7.5) — An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the ims_registrar_pcscf module, specifically the pcscf_save_pending/save_pending path and security-agreement parsing in sec_agree.c:parse_sec_agree()nvd · 2026-09-01
- Mozilla security advisory (AV26-868)cccs_ca · 2026-09-01
- Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosurethehackernews · 2026-09-01
- Wordfence Argus Finds Unauthenticated Arbitrary File Upload Vulnerability in Gravity Formswordfence · 2026-09-01