THREAT OPS › Threat News
Threat Intelligence News
11765 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [GHSA] GHSA-38p6-h87p-r4cg (low) — Grav: Non constant time nonce comparison in Utils::verifyNonce() used for CSRF protectiongithub_advisories · 2026-09-17
- [GHSA] GHSA-9ccq-2jfg-qw33 (low) — Grav: Origin validation bypass in Uri::referrer() and Pages::referrerRoute() via unanchored prefix matchgithub_advisories · 2026-09-17
- 100,000 WordPress Sites Exposed to Remote Code Execution via PHP Object Injection Vulnerability Found by Wordfence Argus in Tutor LMSwordfence · 2026-09-17
- Tanium security advisory (AV26-935)cccs_ca · 2026-09-17
- Dell security advisory (AV26-934)cccs_ca · 2026-09-17
- CTEM Buyer’s Guide: How to Evaluate the Technologies That Turn Continuous Threat Exposure Management Into an Operating Modelhorizon3 · 2026-09-17
- The Autonomous Engine Behind Remediation, and What Finally Makes It Safequalys · 2026-09-17
- [qilin] Invincible GG posted to leak siteransomware_live · 2026-09-17
- [GHSA] GHSA-4rf6-qx84-q9fv (high) — Fulgur: Non-painting replaced elements amplify to thousands of blank PDF pages (denial of service)github_advisories · 2026-09-17
- [GHSA] GHSA-j5cx-ph8g-95v3 (high) — Fulgur: Unbounded page slicing from attacker-controlled CSS height causes denial of servicegithub_advisories · 2026-09-17
- Flock cameras are tracking people as well as carsmalwarebytes_blog · 2026-09-17
- Check Point security advisory (AV26-933)cccs_ca · 2026-09-17
- Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Rootthehackernews · 2026-09-17
- [GHSA] GHSA-vrf4-mx87-p53w (high) — libp2p: PeerStore accepts attacker-signed PeerRecords for a victim peer ID and stores certified attacker addressesgithub_advisories · 2026-09-17
- [GHSA] GHSA-8phw-xrj9-cpqp (medium) — Steeltoe.Management.Endpoint: HttpExchanges URI masking leaks query-string secretsgithub_advisories · 2026-09-17
- Should you care about an “AI slowdown?”talos · 2026-09-17
- Wordfence Intelligence Weekly WordPress Vulnerability Report (September 7, 2026 to September 13, 2026)wordfence · 2026-09-17
- ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Storiesthehackernews · 2026-09-17
- AL26-021 - Vulnerabilities Impacting Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) - CVE-2026-20192, CVE-2026-76423 and CVE-2026-76460cccs_ca · 2026-09-17
- The Vendor Access Problem We See in Almost Every OT Workshopzscaler_threatlabz · 2026-09-17
- [GHSA] GHSA-6qw9-4vv5-jr97 (medium) — Grav: Stored XSS via Markdown audio/video media <source> URLgithub_advisories · 2026-09-17
- Compliance Automation: Benefits, Tools & Best Practicesorca_security · 2026-09-17
- [GHSA] GHSA-c3gv-825q-fvmp (high) — libp2p: Gossipsub StrictSign accepts attacker-signed messages as a victim RSA peer IDgithub_advisories · 2026-09-17
- [GHSA] GHSA-269c-h76q-8cxw (medium) — Grav: Stored XSS via quoted-attribute bypass in detectXssgithub_advisories · 2026-09-17
- CyberCom 2.0 and the Revolution in AI-Enabled Offensive Cyber Operationshorizon3 · 2026-09-17
- [GHSA] GHSA-f8m2-889x-vw4x (medium) — AsyncHttpClient re-sends client-wide realm credentials to a cross-origin redirect targetgithub_advisories · 2026-09-17
- [GHSA] GHSA-xr57-gcx8-52hf (medium) — AsyncHttpClient sends origin credentials to the proxy on the plaintext CONNECT requestgithub_advisories · 2026-09-17
- [GHSA] GHSA-7grg-jcf7-rpmx (high) — AsyncHttpClient's unbounded HTTP/1.1 response decompression enables a decompression-bomb denial of servicegithub_advisories · 2026-09-17
- [GHSA] GHSA-fj9w-c36g-h5x8 (low) — AsyncHttpClient doesn't verify SCRAM and Digest mutual-authentication responsesgithub_advisories · 2026-09-17
- [GHSA] GHSA-mggc-4xg6-vcxf (high) — SSH.NET: ScpClient allows server-side RCE via default SCP path handlinggithub_advisories · 2026-09-17
- [GHSA] GHSA-hpj9-grjp-7vc7 (medium) — Kestra: Unauthenticated management/actuator endpoints exposed on port 8081 (/env, /loggers) bypass API basic-authgithub_advisories · 2026-09-17
- [GHSA] GHSA-8pw2-6jv3-mj5j (medium) — vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservationgithub_advisories · 2026-09-17
- [GHSA] GHSA-w3f4-8pj2-599w (high) — Grav: Path Traversal in ImageMedium::watermark() — arbitrary file disclosure via publicly-cached imagesgithub_advisories · 2026-09-17
- [GHSA] GHSA-7pgq-cr25-xvc8 (high) — Grav: Incomplete callable validation in blueprint dynamic fields allows arbitrary static method invocation and file disclosuregithub_advisories · 2026-09-17
- [GHSA] GHSA-h7vf-4x9w-h99v (medium) — oras-go: Blind SSRF via unvalidated Link header URL in pagination allows internal network probinggithub_advisories · 2026-09-17
- [GHSA] GHSA-m37j-52j7-pjw7 (high) — oras-go: Arbitrary file write outside file.Store root via symlink-chain bypass in tar extraction (pushDir)github_advisories · 2026-09-17
- [GHSA] GHSA-r56g-q4p6-m3p6 (high) — Kestra: SSRF via Pebble http() function allows unauthenticated access to internal services & cloud metadatagithub_advisories · 2026-09-17
- [GHSA] GHSA-c4wf-2xxc-68qm (high) — Grav: FlexDirectory::dynamicDataField() executes arbitrary callables from blueprint data with no validationgithub_advisories · 2026-09-17
- [GHSA] GHSA-5gpm-rgj3-9q76 (high) — Skipper has OPA body-authz bypass: truncated_body mitigation fails open on chunked/HTTP-2 (incomplete fix GHSA-8qqm-fp2q-v734)github_advisories · 2026-09-17
- [GHSA] GHSA-4v58-74mf-rjx3 (high) — RabbitMQ amqp091-go: Denial of Service via Malicious Field Length in AMQP Clientgithub_advisories · 2026-09-17
- [GHSA] GHSA-c5pq-fr2g-9jpf (critical) — RabbitMQ amqp091-go: Protocol Desynchronization and Frame Injection via Integer Overflow in readLongstrgithub_advisories · 2026-09-17
- [GHSA] GHSA-r9c8-gcjp-xfwh (high) — RabbitMQ amqp091-go: Resource Exhaustion (OOM) via Unbounded Body Buffer Allocationgithub_advisories · 2026-09-17
- [GHSA] GHSA-j497-x9hr-x34x (critical) — RabbitMQ amqp091-go: Silent Data Truncation and State Corruption via Shortstr Integer Overflowgithub_advisories · 2026-09-17
- [GHSA] GHSA-27gv-rfvv-22mv (high) — RabbitMQ amqp091-go: Plaintext Credential Exposure via Exported PLAIN Authentication Struct Fieldsgithub_advisories · 2026-09-17
- [GHSA] GHSA-rm6m-hrcw-jw33 (high) — RabbitMQ amqp091-go: Consumer Message Flooding via Signed-to-Unsigned Integer Casting in Qos Configurationgithub_advisories · 2026-09-17
- [GHSA] GHSA-33mj-cw25-m34h (critical) — RabbitMQ amqp091-go: Missing Explicit TLS Minimum Version Configuration In URI Parsergithub_advisories · 2026-09-17
- [GHSA] GHSA-465g-fh3v-9jw4 (high) — RabbitMQ amqp091-go: Connection Configuration Overwrite via Unsanitized TLS Path Parameter Injectiongithub_advisories · 2026-09-17
- [GHSA] GHSA-xwwf-m8fg-p9q2 (high) — RabbitMQ amqp091-go: Denial of Service via Sub-Spec Frame Size Negotiationgithub_advisories · 2026-09-17
- From guidance to action: Security fundamentals that materially reduce riskmsstic · 2026-09-17
- The GNU C Library security advisories update for 2026-09-17oss_sec · 2026-09-17
- [GHSA] GHSA-89m4-43j5-vhhx (low) — Junrar: LocalFolderExtractor mkdir escape allows directory creation outside extraction rootgithub_advisories · 2026-09-17
- [GHSA] GHSA-pq59-9fq7-m886 (medium) — Zope AccessControl vulnerable to information disclosure through Python string `format` and `format_map` functionsgithub_advisories · 2026-09-17
- [GHSA] GHSA-hp3v-5vw7-fx9w (high) — RestrictedPython vulnerable to sandbox escape via string.Formatter field resolutiongithub_advisories · 2026-09-17
- [GHSA] GHSA-pj96-35fp-cfcc (high) — ExifReader: DoS via Crafted HEIC/AVIF iloc Box - Memory Exhaustiongithub_advisories · 2026-09-17
- [GHSA] GHSA-wxmm-q36w-r9xj (low) — MariaDB Connector/J does not enforce allowLocalInfile=false on server-initiated LOCAL INFILE requestsgithub_advisories · 2026-09-17
- [GHSA] GHSA-wr57-hqmp-fgvh (high) — Umbraco: Delivery API leaks protected (Public Access) content through Content Picker / Multi-Node Tree Picker expansiongithub_advisories · 2026-09-17
- [chaos] expresspros.com posted to leak siteransomware_live · 2026-09-17
- [BrainCipher] hoyletanner.com posted to leak siteransomware_live · 2026-09-17
- [BrainCipher] aecom.com posted to leak siteransomware_live · 2026-09-17
- [qilin] Techwise posted to leak siteransomware_live · 2026-09-17
- [qilin] The Gran Hotel Ingles posted to leak siteransomware_live · 2026-09-17
- CiliumHound: Graphing Kubernetes Network Policiesspecterops · 2026-09-17
- Improving email security outcomes with real-world Microsoft Defender insightsmsstic · 2026-09-17
- Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Filesthehackernews · 2026-09-17
- Cisco security advisory (AV26-932)cccs_ca · 2026-09-17
- CVE-2026-92230: Apache Karaf: Improper release of ClassLoader references via static ThreadLocal cachingoss_sec · 2026-09-17
- Re: Retrospective by 'gpg.fail' authorsoss_sec · 2026-09-17
- [BrainCipher] xpera.ca posted to leak siteransomware_live · 2026-09-17
- [NVD] CVE-2026-81446 (HIGH 7.4) — Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery.nvd · 2026-09-17
- LausivLoader analysis, or how to pass data between malware stages, (Thu, Sep 17th)sans_isc · 2026-09-17
- August 2026 Threat Trend Report on APT Groupsahnlab · 2026-09-17
- [GHSA] GHSA-wmj6-g64g-j7q5 (medium) — sanic chunked trailer request smuggling allows hidden second request executiongithub_advisories · 2026-09-17
- [GHSA] GHSA-g74q-6g2f-874x (high) — Tina: [Broken Access Control] letting any TinaCloud user authorize against any self-hosted sitegithub_advisories · 2026-09-17
- [GHSA] GHSA-657c-g7qc-r9j2 (medium) — Redocly CLI: Path traversal when using `split` commandgithub_advisories · 2026-09-17
- [GHSA] GHSA-84vh-m24q-wjjx (high) — Pocketbase: Unhandled panic in worker goroutinesgithub_advisories · 2026-09-17
- [GHSA] GHSA-8h9x-89f2-m7x3 (medium) — Grav: Decompression-bomb size cap bypassed by forged ZIP size in ZipArchiver/Installergithub_advisories · 2026-09-17
- [GHSA] GHSA-rw4j-r22c-9gc3 (medium) — AsyncSSH: asyncio event-loop freeze via SSH maximum packet size = 0 in SSH_MSG_CHANNEL_OPEN / OPEN_CONFIRMATIONgithub_advisories · 2026-09-17
- [GHSA] GHSA-9rm7-3qhh-h2mc (high) — Wire: Unauthenticated decoder crash via 32-bit length integer overflow in ByteArrayProtoReader32 (incomplete fix of CVE-2026-45799)github_advisories · 2026-09-17
- [GHSA] GHSA-j9v4-rhgr-4m5f (medium) — oRPC: Vary Header Injection in CORS Plugin leading to potential Cache/CORS Bypassgithub_advisories · 2026-09-17
- [GHSA] GHSA-jh4v-gfqj-7rhx (high) — RabbitMQ Java client has frame-level OOM: Math.min(maxInboundMessageBodySize, 0) defeats frame size enforcementgithub_advisories · 2026-09-17
- [GHSA] GHSA-rfx3-98h7-v3xp (critical) — Marten's LINQ provider has SQL injection via unescaped string literalsgithub_advisories · 2026-09-17
- [GHSA] GHSA-hx8v-g79f-8w5f (medium) — LiteLLM Proxy has server-side request forgery via the `user_config` request parametergithub_advisories · 2026-09-17
- [GHSA] GHSA-q69g-4hcv-6jg4 (high) — @cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized --workspace Argument on Windowsgithub_advisories · 2026-09-17
- [GHSA] GHSA-6j36-r6pr-59x4 (critical) — Vendure affected by external-authentication account takeover: external login linked to a pre-existing account by email without verificationgithub_advisories · 2026-09-17
- [GHSA] GHSA-xf65-r35x-wmmv (medium) — Vendure: Shop API list queries can return non-public entities when filterOperator is ORgithub_advisories · 2026-09-17
- [GHSA] GHSA-jgm3-qmp2-c4p7 (high) — Vendure: Unauthenticated ReDoS via `regex` filter on SQLite backendsgithub_advisories · 2026-09-17
- [GHSA] GHSA-xhq9-whgq-49j5 (high) — Vendure has stored XSS in the Admin Dashboard via unsafe HTML-stripping (innerHTML) of entity descriptionsgithub_advisories · 2026-09-17
- [GHSA] GHSA-q8hw-4fvp-9rwv (medium) — Nuxt OG Image has unauthenticated SSRF via `fonts[].path` URL parametergithub_advisories · 2026-09-17
- [GHSA] GHSA-9g45-5xwm-f3wc (medium) — RMCP: Custom HTTP headers leak to cross-origin redirect targetsgithub_advisories · 2026-09-17
- AI Threat Landscape Digest: July–August 2026checkpoint_research · 2026-09-17
- [NVD] CVE-2026-92970 (HIGH 8.8) — HUBzero CMS through 2.2.32 contains a path traversal vulnerability in project file upload handlers that allows authenticated project members to write arbitrary files outside the project repository. Attackers can supply traversal sequences in upload parameters to write files to atnvd · 2026-09-17
- [NVD] CVE-2026-92944 (CRITICAL 9.8) — vm2 versions 3.10.2 through 3.11.6 contain a sandbox escape vulnerability on Node.js 26 where Promise.prototype.finally() bypasses vm2's wrapper protections due to a stale PromiseThenLookupChain protector in V8 14.6. Attackers can exploit this by creating an async function that rnvd · 2026-09-17
- [NVD] CVE-2026-92938 (CRITICAL 9.9) — vm2 versions 3.11.3 through 3.11.6 expose Node.js's host node:sqlite module to code running in NodeVM when that builtin is permitted, either explicitly or through builtin: ['*']. The module is wrapped with vm.readonly(), which prevents property assignment but leaves host-authoritnvd · 2026-09-17
- [NVD] CVE-2026-92933 (MEDIUM 5.8) — vm2 is a sandbox for running untrusted Node.js code. In versions <= 3.11.7, NodeVM exposes the host `util` module to the sandbox as an unfiltered shallow copy (`Object.assign({}, util)` in `defaultBuiltinLoaderUtil`), and the deprecated `sys` builtin (an alias of host `util`) is nvd · 2026-09-17
- [NVD] CVE-2026-81443 (MEDIUM 6.4) — Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery.nvd · 2026-09-17
- Revolut phishing texts appear days after data breachmalwarebytes_blog · 2026-09-17
- Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwordsthehackernews · 2026-09-17
- Flashpoint Named A Customer Favorite in The Forrester Wave™flashpoint · 2026-09-17
- [akira] Practice Management (maximizedrevenue.com) posted to leak siteransomware_live · 2026-09-17
- [akira] Vetta posted to leak siteransomware_live · 2026-09-17