THREAT OPS › Threat News
Threat Intelligence News
11618 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [GHSA] GHSA-xwg4-73v4-xw9w (high) — nanoid: Integer Overflow or Wraparoundgithub_advisories · 2026-09-01
- [GHSA] GHSA-vx52-2968-3vc6 (high) — pnpm: Environment secrets exfiltrated via env-placeholder expansion in proxy settings read from an untrusted pnpm-workspace.yamlgithub_advisories · 2026-09-01
- [GHSA] GHSA-2rx9-3g3h-c2jv (high) — pnpm: pacquet trust-lockfile install can create dependency symlinks outside the projectgithub_advisories · 2026-09-01
- Cybersecurity IR Workshop: The workshop you shouldn’t missmsstic · 2026-09-01
- [GHSA] GHSA-3wgp-x9p5-c7cc (medium) — Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routesgithub_advisories · 2026-09-01
- Erlang security advisory (AV26-870)cccs_ca · 2026-09-01
- Rockwell Automation security advisory (AV26-869)cccs_ca · 2026-09-01
- [NVD] CVE-2026-52023 (HIGH 7.5) — An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the ims_registrar_pcscf module, specifically the pcscf_save_pending/save_pending path and security-agreement parsing in sec_agree.c:parse_sec_agree()nvd · 2026-09-01
- Mozilla security advisory (AV26-868)cccs_ca · 2026-09-01
- Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosurethehackernews · 2026-09-01
- Wordfence Argus Finds Unauthenticated Arbitrary File Upload Vulnerability in Gravity Formswordfence · 2026-09-01
- JFrog security advisory (AV26-867)cccs_ca · 2026-09-01
- What’s the Scam?schneier · 2026-09-01
- Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systemsthehackernews · 2026-09-01
- [GHSA] GHSA-gqvg-gmmx-x4hm (high) — MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False safety control bypassed by mlflow.statsmodels flavor — RCE via crafted model artifactgithub_advisories · 2026-09-01
- [GHSA] GHSA-c83g-rgw3-j3cx (high) — Browserslist: Unbounded memory growth (no cache eviction) via distinct query results, leading to eventual OOMgithub_advisories · 2026-09-01
- [GHSA] GHSA-73wf-gq98-2v4g (high) — Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats)github_advisories · 2026-09-01
- [GHSA] GHSA-3f6p-5ww8-9rcr (high) — MySQL2: Auth Plugin Downgrade to mysql_clear_password Leaks Plaintext Credentialsgithub_advisories · 2026-09-01
- [GHSA] GHSA-cq55-c7wv-pxmq (medium) — Smarty: SSRF via redirect bypass of trusted_uri using {fetch}github_advisories · 2026-09-01
- [GHSA] GHSA-rf2p-vh74-7vvh (medium) — Kirby: System path exposure from error messages in the REST APIgithub_advisories · 2026-09-01
- Leaked Russian Cyber-Operations Training Materialsschneier · 2026-09-01
- [direwolf] Oportunidados posted to leak siteransomware_live · 2026-09-01
- Fake GTA 6 leaked copy drains your crypto walletmalwarebytes_blog · 2026-09-01
- [direwolf] Honeycomb Programs Inc posted to leak siteransomware_live · 2026-09-01
- [direwolf] PT Intraco Penta Tbk posted to leak siteransomware_live · 2026-09-01
- 5 Million WordPress Sites Affected by SQL Injection Vulnerability in All-in-One WP Migration and Backup WordPress Pluginwordfence · 2026-09-01
- [akira] Congressional Iron Works posted to leak siteransomware_live · 2026-09-01
- [NVD] CVE-2026-78012 (CRITICAL 9.8) — An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow a large Class 3 explicit-message request to exceed the application-side receive buffer without generating an error or warning. The result could be memory corruption, a device crash, or a potential remote attacknvd · 2026-09-01
- “Evasive” Malware Attack Tactics: Hiding, Bypassing, and Reappearingahnlab · 2026-09-01
- Kim Sooki again? This time, it was disguised as a request for seafood ingredientsahnlab · 2026-09-01
- Cybercrime at Machine Speed: Key Takeaways from Flashpoint’s 2026 Midyear Threat Intelligence Briefingflashpoint · 2026-09-01
- Linux Detection Engineering - Fileless Executionelastic_security · 2026-09-01
- [akira] Flex1 posted to leak siteransomware_live · 2026-09-01
- [akira] BYK Construction posted to leak siteransomware_live · 2026-09-01
- FreeRDP <= 3.30.0: five server-side vulnerabilities fixed in 3.31.0, pre-auth RCE demonstratedoss_sec · 2026-09-01
- 13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seedsthehackernews · 2026-09-01
- Why Even the Best Edge Security Still Misses High-Risk Sessionsbleepingcomputer · 2026-09-01
- Financially Motivated Threat Actor BREEZE COMET Targets Brazilmandiant_gti · 2026-09-01
- Critical Artifactory Bug Under Attackduo_decipher · 2026-09-01
- WebPros security advisory (AV26-866)cccs_ca · 2026-09-01
- Langflow and Rails Exploitation Raises Credential Riskssocradar_blog · 2026-09-01
- What’s in the SOSS? Podcast #71 – S3E23 Navigating the New Era: The EU Cyber Resilience Act Explained with Madalin Neagopenssf_blog · 2026-09-01
- Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Teststhehackernews · 2026-09-01
- [nightspire] Transportes Montejo S.A.S. posted to leak siteransomware_live · 2026-09-01
- [bravox] SCHMIDT posted to leak siteransomware_live · 2026-09-01
- Varonis Achieves Snowflake Premier Partner Tier and Is Now Available on Snowflake Marketplacevaronis_blog · 2026-09-01
- [thegentlemen] CareerSource Palm Beach County posted to leak siteransomware_live · 2026-09-01
- [thegentlemen] Nutex Health posted to leak siteransomware_live · 2026-09-01
- [thegentlemen] The Sole posted to leak siteransomware_live · 2026-09-01
- TerminalFix looks like ClickFix, but delivers a very different payloadmalwarebytes_blog · 2026-09-01
- Rockwell Automation RSLinx Classiccisa_advisories · 2026-09-01
- Rockwell Automation Historian MEcisa_advisories · 2026-09-01
- Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogixcisa_advisories · 2026-09-01
- Rockwell Automation Logix Platformcisa_advisories · 2026-09-01
- Rockwell Automation Redundancy Module Configuration Toolcisa_advisories · 2026-09-01
- Rockwell Automation FactoryTalk Activation Managercisa_advisories · 2026-09-01
- Threat Actors Don’t Want Better Attacks. They Want Repeatable Onesthehackernews · 2026-09-01
- [fulcrumsec] Manchester Airports Group posted to leak siteransomware_live · 2026-09-01
- Infostealers are hijacking Claude accounts at users’ expensemalwarebytes_blog · 2026-09-01
- Off the Hook: Discovering and Observing Active Exploitation of Sangoma Switchvox CVE-2026-9586horizon3 · 2026-09-01
- Hugging Face Security Incident: A New Class of Threat Is Heresonatype · 2026-09-01
- Rewiring Democracy Series on The Renovatorschneier · 2026-09-01
- [ransomhouse] REXT Holdings Co., Ltd. posted to leak siteransomware_live · 2026-09-01
- [Wallstreet] Total Education Solutions posted to leak siteransomware_live · 2026-09-01
- Attackers Steal METR API Key and Consume AI Credits Worth About $600,000thehackernews · 2026-09-01
- [krybit] seashellhospital.com posted to leak siteransomware_live · 2026-09-01
- [krybit] uicc.org posted to leak siteransomware_live · 2026-09-01
- [krybit] tum.com.mx posted to leak siteransomware_live · 2026-09-01
- [krybit] www.alphaplantes.com posted to leak siteransomware_live · 2026-09-01
- [krybit] reignwoodpark.com posted to leak siteransomware_live · 2026-09-01
- [krybit] orex.co.th posted to leak siteransomware_live · 2026-09-01
- [krybit] amptc.net posted to leak siteransomware_live · 2026-09-01
- [krybit] dmt-group.com posted to leak siteransomware_live · 2026-09-01
- [krybit] jswlaw.bt posted to leak siteransomware_live · 2026-09-01
- [krybit] vedantaainstitute.in posted to leak siteransomware_live · 2026-09-01
- [krybit] meccahighfeed.blogspot.com posted to leak siteransomware_live · 2026-09-01
- [krybit] transportesmontejo.com posted to leak siteransomware_live · 2026-09-01
- [krybit] southsign.in posted to leak siteransomware_live · 2026-09-01
- [krybit] hccd-construction.com posted to leak siteransomware_live · 2026-09-01
- [majinahanashi] TERRACOM & MONTCAU posted to leak siteransomware_live · 2026-09-01
- Overview of Content Published in Augustdidier_stevens · 2026-09-01
- Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysisthehackernews · 2026-09-01
- Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activitythehackernews · 2026-09-01
- Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware setsecurelist · 2026-09-01
- [medusalocker] Lawter posted to leak siteransomware_live · 2026-09-01
- [qilin] Commission de la construction du Quebec posted to leak siteransomware_live · 2026-09-01
- SUSE Linux Kernel Multiple Vulnerabilitieshkcert · 2026-09-01
- [everest] Rise UP posted to leak siteransomware_live · 2026-09-01
- [everest] VIVOTEK posted to leak siteransomware_live · 2026-09-01
- [everest] Italtel Peru posted to leak siteransomware_live · 2026-09-01
- Vulnerability & Patch Roundup — August 2026sucuri_blog · 2026-09-01
- The Agentic SOC – From AI Theater to Real Defenserecordedfuture · 2026-09-01
- [lockbit5] svfcu.org posted to leak siteransomware_live · 2026-08-31
- [lockbit5] hoaattorneys.com posted to leak siteransomware_live · 2026-08-31
- [GHSA] GHSA-67mx-6wf2-92xp (high) — Kirby: File upload permissions are not checked during processing of chunk datagithub_advisories · 2026-08-31
- [GHSA] GHSA-9vx2-j98c-p72w (high) — Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handlinggithub_advisories · 2026-08-31
- [GHSA] GHSA-vcc3-ghjq-m6fr (medium) — decode-uri-component: Denial of service via exponential decoding of malformed percent-encoded inputgithub_advisories · 2026-08-31
- [GHSA] GHSA-gr94-w7qr-f4j3 (high) — Socket.IO: Engine.IO WebTransport SID DoSgithub_advisories · 2026-08-31
- [GHSA] GHSA-fm3f-ch8h-qw8q (medium) — @hono/oauth-providers: OAuth state check fails open on omitted state, enabling login CSRF and forced account linkinggithub_advisories · 2026-08-31
- [GHSA] GHSA-8x3q-jpjh-qh5c (high) — elFinder: SSRF protection bypass via DNS rebinding in the `fsock_get_contents()` fallbackgithub_advisories · 2026-08-31