THREAT OPS › Threat News
Threat Intelligence News
11618 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- Between Two Nerds: The perfect hackerriskybiz_news · 2026-08-31
- The Coding-Agent Trap: When a "Free" LLM Endpoint Is the Adversary, (Mon, Aug 31st)sans_isc · 2026-08-31
- [BrainCipher] icot.es posted to leak siteransomware_live · 2026-08-31
- [BrainCipher] aeiconsultants.com posted to leak siteransomware_live · 2026-08-31
- [GHSA] GHSA-mfqj-cqv3-h7xw (medium) — TYPO3 CMS - Unrestricted File Upload in Form Frameworkgithub_advisories · 2026-08-31
- [BrainCipher] syc.es posted to leak siteransomware_live · 2026-08-31
- [BrainCipher] Adviesbureau De Beuckelaer BV posted to leak siteransomware_live · 2026-08-31
- [BrainCipher] ahadandco.com posted to leak siteransomware_live · 2026-08-31
- [BrainCipher] sago.com posted to leak siteransomware_live · 2026-08-31
- [BrainCipher] crmeyer.com posted to leak siteransomware_live · 2026-08-31
- [BrainCipher] ccsperfusion.com posted to leak siteransomware_live · 2026-08-31
- [qilin] Inmac posted to leak siteransomware_live · 2026-08-31
- WatchGuard security advisory (AV26-865)cccs_ca · 2026-08-31
- OpenSSF Newsletter – August 2026openssf_blog · 2026-08-31
- Is Someone Hacking DoD Refrigerators?schneier · 2026-08-31
- CVE-2026-19953: URI versions before 5.36 for Perl encode non-NFC host names to non-standard punycode labels via missing normalization in namepreposs_sec · 2026-08-31
- libexpat 2.8.4 fixes 4 vulnerabilitiesoss_sec · 2026-08-31
- [Global Secret Group] R L Fine Chem Pvt. Ltd. posted to leak siteransomware_live · 2026-08-31
- North Korean Job Fraud Expands Beyond IT Into Healthcare and Salesthehackernews · 2026-08-31
- [NVD] CVE-2026-17615 (HIGH 7.5) — A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote file read. By sending a specially crafted XML body with a DOCTYPE declaration referencing external entities to an endpoint that accepts applicnvd · 2026-08-31
- [Orova] ASYS Corporation posted to leak siteransomware_live · 2026-08-31
- [Orova] Fu Sheng Industrial Co., Ltd posted to leak siteransomware_live · 2026-08-31
- Rethinking OT Boundaries: Sandworm's Cellular Breach of a Polish Power Plantzscaler_threatlabz · 2026-08-31
- SIEM Is Not Enough: Why You Need DAM for Your Databasesvaronis_blog · 2026-08-31
- [Control Systems] Siemens security advisory (AV26-864)cccs_ca · 2026-08-31
- [interlock] Super Systems Inc posted to leak siteransomware_live · 2026-08-31
- Dell security advisory (AV26-863)cccs_ca · 2026-08-31
- IBM security advisory (AV26-862)cccs_ca · 2026-08-31
- Plone security advisory 20260831oss_sec · 2026-08-31
- Re: Fwd: [Announce] Libgcrypt 1.12.3 releasedoss_sec · 2026-08-31
- libksba-1.8.1 fixes a possible CMS parser infinite looposs_sec · 2026-08-31
- [Falcon] Hayward Holdings posted to leak siteransomware_live · 2026-08-31
- [qilin] Allied Recycling posted to leak siteransomware_live · 2026-08-31
- [incransom] New Century Ophthalmology Group posted to leak siteransomware_live · 2026-08-31
- McKesson confirms cyber incident after ShinyHunters claims patient-data theftmalwarebytes_blog · 2026-08-31
- [play] MEQ posted to leak siteransomware_live · 2026-08-31
- [play] Figgins Family Wine Estates posted to leak siteransomware_live · 2026-08-31
- [play] KRC Machine Tool Solutions posted to leak siteransomware_live · 2026-08-31
- [play] Meteor Group posted to leak siteransomware_live · 2026-08-31
- LACT: Polkit Authentication Bypass and Temporary File Handling Issues (CVE-2026-75037, CVE-2026-75038)oss_sec · 2026-08-31
- [akira] KFZ-MEISTERBETRIEB JOST GmbH posted to leak siteransomware_live · 2026-08-31
- ⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and Morethehackernews · 2026-08-31
- Frontier AI Changes Vulnerability Discovery. It Doesn’t Change How Breaches Happen.horizon3 · 2026-08-31
- Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecodecheckpoint_research · 2026-08-31
- Fwd: [Announce] Libgcrypt 1.12.3 releasedoss_sec · 2026-08-31
- [akira] Gale Credit Union posted to leak siteransomware_live · 2026-08-31
- [Wallstreet] Cedar County Memorial Hospital posted to leak siteransomware_live · 2026-08-31
- [NVD] CVE-2026-12894 (HIGH 8.8) — A flaw was found in the Qute template engine, which is used by Quarkus to generate dynamic content like HTML pages or emails. The issue exists in the component responsible for looking up data values (ReflectionValueResolver), which fails to properly block access to sensitive Javanvd · 2026-08-31
- ServiceNow Patches Multiple CVSS 10.0 Flawssocradar_blog · 2026-08-31
- 31th August – Threat Intelligence Reportcheckpoint_research · 2026-08-31
- [akira] WEMS posted to leak siteransomware_live · 2026-08-31
- ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusionsthehackernews · 2026-08-31
- [thegentlemen] EP Manufacturing Bhd posted to leak siteransomware_live · 2026-08-31
- [thegentlemen] Saudi Consulting Services SAUD CONSULT posted to leak siteransomware_live · 2026-08-31
- [incransom] zummocorp.com posted to leak siteransomware_live · 2026-08-31
- [incransom] www.lichtvision.com posted to leak siteransomware_live · 2026-08-31
- [incransom] www.renorefractories.com posted to leak siteransomware_live · 2026-08-31
- [incransom] cimbsecurities.com posted to leak siteransomware_live · 2026-08-31
- CISA Adds Two Known Exploited Vulnerabilities to Catalogcisa_advisories · 2026-08-31
- Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targetsthehackernews · 2026-08-31
- Securing Claude Code: The New Compliance API, Local Visibility, and Identity Governancethehackernews · 2026-08-31
- Finnish Kennel Club, Shell Access, UK Iframe, Salt Mobile, and Brazil SERPRO Claimssocradar_blog · 2026-08-31
- CVE-2026-19873: HTML::FormFu versions through 2.08 for Perl allow resource exhaustion via an unbounded repeat count from the query string in Repeatable elementsoss_sec · 2026-08-31
- [aurora] Ishbia & Gagleard, P.C. posted to leak siteransomware_live · 2026-08-31
- Simulating legitimate Active Directory services on the network: the case of GPO exploitationsynacktiv · 2026-08-31
- Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teamsunit42 · 2026-08-31
- ValleyRAT masquerading as adwaresecurelist · 2026-08-31
- Anthropic Links Claude Session Theft to Infostealer Malwaresocradar_blog · 2026-08-31
- [lockbit5] bartelsbv.nl posted to leak siteransomware_live · 2026-08-31
- [lockbit5] vkj.nl posted to leak siteransomware_live · 2026-08-31
- [lockbit5] allsteelproducts.nl posted to leak siteransomware_live · 2026-08-31
- [lockbit5] bkc.org posted to leak siteransomware_live · 2026-08-31
- China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logsthehackernews · 2026-08-31
- DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victimsthehackernews · 2026-08-31
- CVE-2026-76986: Apache Wicket: XSS in AbstractSingleSelectChoice via getNullValidDisplayValueoss_sec · 2026-08-31
- CVE-2026-76985: Apache Wicket: XSS in Palette via getAdditionalAttributesoss_sec · 2026-08-31
- CVE-2026-76984: Apache Wicket: XSS in MetaDataHeaderItem via addTagAttributeoss_sec · 2026-08-31
- CVE-2026-76983: Apache Wicket: XSS in AutoLabelTextResolver via FormComponent.setLabeloss_sec · 2026-08-31
- The Hugging Face Breach: Key Questions Every Security Leader Must Answerzscaler_threatlabz · 2026-08-31
- CVE-2026-76982: Apache Wicket: XSS in Button via its model objectoss_sec · 2026-08-31
- CVE-2026-75802: Apache Wicket: XSS in AjaxEditableLabel and its subclasses via IChoiceRenderer and defaultNullLabeloss_sec · 2026-08-31
- A week in security (August 24 – August 30)malwarebytes_blog · 2026-08-31
- Risky Bulletin: New powers for Dutch intelligence servicesriskybiz_news · 2026-08-31
- PaperCut Multiple Vulnerabilitieshkcert · 2026-08-31
- Microsoft Edge Multiple Vulnerabilitieshkcert · 2026-08-31
- GreyNoise + CrowdStrike: Real-Time Edge Intelligence in Falcon Next-Gen SIEM and Charlotte Agentic SOARgreynoise_blog · 2026-08-31
- CVE-2026-71378: Apache Wicket: Cross-Site Request Forgery (CSRF) protection bypass in ResourceIsolationRequestCycleListeneross_sec · 2026-08-30
- CVE-2026-71257: Apache Wicket: Configured file upload limits are not enforced when the multipart request has already been parsedoss_sec · 2026-08-30
- CVE-2026-70449: Apache Wicket: Path traversal in resource style/variation/localeoss_sec · 2026-08-30
- CVE-2026-58301: Apache Shiro: Server-side POST request may be steered to an alternate hostoss_sec · 2026-08-30
- Exiv2 0.28.9 releasedoss_sec · 2026-08-30
- Sponsored: Attackers need to be right more than onceriskybiz_news · 2026-08-30
- [NVD] CVE-2026-82552 (MEDIUM 4.3) — A security vulnerability has been detected in Linux Foundation Magma 1.9.0. Affected by this vulnerability is an unknown functionality of the file tasks/ngap/ngap_amf.c of the component gNB Termination Handler. The manipulation leads to denial of service. The attack is possible tnvd · 2026-08-30
- [NVD] CVE-2026-82551 (MEDIUM 5.3) — A weakness has been identified in Linux Foundation Magma 1.9.0. Affected is an unknown function of the file ngap_amf_handlers.c of the component NGSetup Handler. Executing a manipulation can lead to state issue. The attack can be executed remotely. The exploit has been made availnvd · 2026-08-30
- [NVD] CVE-2026-82550 (MEDIUM 5.3) — A security flaw has been discovered in Linux Foundation Magma 1.9.0. This impacts an unknown function of the component NGSetupRequest Handler. Performing a manipulation of the argument NG-IoT-DefaultPagingDRX results in improper input validation. Remote exploitation of the attacknvd · 2026-08-30
- [NVD] CVE-2026-82549 (HIGH 8.3) — A vulnerability was identified in Linux Foundation Magma 1.9.0. This affects an unknown function of the component SecurityModeComplete Handler. Such manipulation leads to improper validation of integrity check value. The attack may be launched remotely. The exploit is publicly avnvd · 2026-08-30
- [NVD] CVE-2026-78699 — Unchecked Return Value vulnerability in ash-project ash_postgres allows a user who can drive a tenant rename to a name that collides with an existing tenant's schema to have their tenant record repointed at that other tenant's live schema, gaining access to its data. AshPostgresnvd · 2026-08-30
- [qilin] AFSARD posted to leak siteransomware_live · 2026-08-30
- [Security Blog] Mid-Year Review: HKCERT Security Incident Statistics and Cybersecurity Trends in the First Half of 2026hkcert · 2026-08-30
- [Wallstreet] Andover posted to leak siteransomware_live · 2026-08-30