THREAT OPS › Threat News
Threat Intelligence News
11693 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [GHSA] GHSA-gmxc-r82q-347r (medium) — libreoffice-convert vulnerable to path traversal / arbitrary file writegithub_advisories · 2026-08-27
- [SilentRansomGroup] G... T... posted to leak siteransomware_live · 2026-08-27
- [NVD] CVE-2026-81678 (HIGH 7.5) — AVideo before 24.0 contains a server-side request forgery vulnerability in the isSSRFSafeURL function that fails to extract embedded IPv4 addresses from NAT64, 6to4, and Teredo IPv6 transition address formats. Unauthenticated attackers can bypass SSRF protections via the LiveLinknvd · 2026-08-27
- [NVD] CVE-2026-81100 (MEDIUM 6.8) — tiger-gh-mcp-server started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. src/httpServer.ts called the shared httpServerFactory helper and never set the DNS-rebinding-protection option, so the transport accepted a request whatever host invd · 2026-08-27
- [NVD] CVE-2026-81095 (MEDIUM 6.8) — pg-aiguide started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. src/httpServer.ts called the shared httpServerFactory helper and never set the DNS-rebinding-protection option, so the transport accepted a request whatever host it named. nvd · 2026-08-27
- [NVD] CVE-2026-80211 (MEDIUM 5.9) — FrontAccounting through 2.4.20 stores and verifies user passwords as unsalted MD5 digests. admin/users.php passes md5($_POST['password']) to add_user() and update_user_password(), admin/change_current_user_password.php does the same when a user changes their own password, the fornvd · 2026-08-27
- [GHSA] GHSA-39mm-rwm3-29jp (high) — silverstripe-advancedworkflow vulnerable to remote code execution via advanced workflow email templategithub_advisories · 2026-08-27
- [NVD] CVE-2026-78002 (HIGH 7.5) — A flaw was found in rsyslog. An unauthenticated remote attacker can trigger a heap buffer overflow in the RainerScript `replace()` function by sending specially crafted syslog messages. This vulnerability arises from an incorrect buffer size calculation during string replacement,nvd · 2026-08-27
- [NVD] CVE-2026-5680 (HIGH 7.5) — A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with permessage-deflate negotiated. This could lead to excessive memory consumption due to the PerMessageDeflateFunction.largerBuffer() method using exnvd · 2026-08-27
- [NVD] CVE-2026-40526 (MEDIUM 6.5) — Volmarg Personal Management System contains a path traversal vulnerability that allows authenticated attackers to read arbitrary files by supplying absolute filesystem paths to the GET /public/get-file/{path} endpoint. The path route parameter is passed directly to file_get_contenvd · 2026-08-27
- [GHSA] GHSA-g7gw-m874-7rmf (low) — Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parametergithub_advisories · 2026-08-27
- [GHSA] GHSA-q7m3-rhxg-7vxr (medium) — n8n-nodes-sqlite3 vulnerable to path traversal via user-controlled database file path (db_path parameter)github_advisories · 2026-08-27
- [GHSA] GHSA-r5pm-vrc5-3m73 (low) — cakephp/queue's Incomplete Comparison in getUniqueId vulnerable to collisionsgithub_advisories · 2026-08-27
- [qilin] Kling Automaten posted to leak siteransomware_live · 2026-08-27
- [qilin] Dotlines posted to leak siteransomware_live · 2026-08-27
- [GHSA] GHSA-g8wr-r2v2-vqc6 (high) — silverstripe/userforms vulnerable to remote code execution via userforms email subjectgithub_advisories · 2026-08-27
- It No Longer Takes an Expert to Attack a Factoryzscaler_threatlabz · 2026-08-27
- Cleartext Credential Recovery in ServiceNowspecterops · 2026-08-27
- OpenClaw went viral. Meet the maintainers building and securing it.github_security_lab · 2026-08-27
- What’s new in Microsoft Security: August 2026msstic · 2026-08-27
- [emperador] Ipro.com(revealdata.com) customer DB + full database backup posted to leak siteransomware_live · 2026-08-27
- Flock wants privacy to meet surveillance halfwaymalwarebytes_blog · 2026-08-27
- Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCEthehackernews · 2026-08-27
- ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Storiesthehackernews · 2026-08-27
- July 2026 Threat Trend Report on APT Attacks (South Korea)ahnlab · 2026-08-27
- Wordfence Intelligence Weekly WordPress Vulnerability Report (August 17, 2026 to August 23, 2026)wordfence · 2026-08-27
- Fake listings can turn trusted platforms into scam springboardsmalwarebytes_blog · 2026-08-27
- [incransom] Rohloff Group posted to leak siteransomware_live · 2026-08-27
- How to build an exposure management program the business trusts: Lessons from Tenable’s CSOtenable · 2026-08-27
- [akira] Cetylite posted to leak siteransomware_live · 2026-08-27
- [akira] CGP MEP posted to leak siteransomware_live · 2026-08-27
- [akira] Seabrook Island posted to leak siteransomware_live · 2026-08-27
- TeamPCP Arrests: Two Charged in Australia Over the Supply Chain Campaign That Hit 1,000+ Organizationssocradar_blog · 2026-08-27
- The ECB Wants Your AI Cyber Action Plan by 31 October. Here’s How to Build One.orca_security · 2026-08-27
- Veeam security advisory (AV26-855)cccs_ca · 2026-08-27
- Identity-as-a-Service: Uncovering Dark Web Marketplaces Trading Executive SSNsrapid7 · 2026-08-27
- Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powersthehackernews · 2026-08-27
- [incransom] Ruby Seven Studios posted to leak siteransomware_live · 2026-08-27
- [NVD] CVE-2026-81560 (MEDIUM 5.3) — A vulnerability was identified in blackms aistack up to 1.6.1. Affected by this issue is some unknown functionality of the file src/web/server.ts of the component Static File Handler. Such manipulation of the argument req.url leads to path traversal. The attack can be executed renvd · 2026-08-27
- [qilin] GPS Grothkopp und Partner posted to leak siteransomware_live · 2026-08-27
- [lockbit5] theheartcenterofmemphis.com posted to leak siteransomware_live · 2026-08-27
- [lockbit5] dece.cz posted to leak siteransomware_live · 2026-08-27
- [lockbit5] takt.be posted to leak siteransomware_live · 2026-08-27
- WebPros security advisory (AV26-854)cccs_ca · 2026-08-27
- SonicWall security advisory (AV26-853)cccs_ca · 2026-08-27
- Fake Apple Pay charge brings the classic tech support scam to your phonemalwarebytes_blog · 2026-08-27
- CISA Adds Three Known Exploited Vulnerabilities to Catalogcisa_advisories · 2026-08-27
- Mitsubishi Electric Multiple FA Products (Update D)cisa_advisories · 2026-08-27
- Applied Systems Engineering ASE2000 V2 Communications Test Setcisa_advisories · 2026-08-27
- All-Line Equipment Company Fuel-Bosscisa_advisories · 2026-08-27
- Ebyte NA111-Mcisa_advisories · 2026-08-27
- Rockwell Automation OTTO Fleet Managercisa_advisories · 2026-08-27
- Xiiaozet LK100Wcisa_advisories · 2026-08-27
- Mitsubishi Electric CNC Series (Update A)cisa_advisories · 2026-08-27
- [qilin] Providence Investments posted to leak siteransomware_live · 2026-08-27
- [qilin] LGG Advisors posted to leak siteransomware_live · 2026-08-27
- [qilin] Open Sports posted to leak siteransomware_live · 2026-08-27
- Learn How to Build Security Operations Ready for AI-Powered Attacksthehackernews · 2026-08-27
- [AuditTeam] PI***al posted to leak siteransomware_live · 2026-08-27
- What the Data Says About AI in Security Operations in 2026thehackernews · 2026-08-27
- [qilin] DAB Investments posted to leak siteransomware_live · 2026-08-27
- [qilin] Displaydata posted to leak siteransomware_live · 2026-08-27
- Qilin Claims ATF Breach as Agency Confirms “Major Incident”socradar_blog · 2026-08-27
- Two Alleged ‘TeamPCP’ Hackers Arrested in Australiakrebs · 2026-08-27
- Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Toolsthehackernews · 2026-08-27
- [aurora] SCA Logistik & Fulfillment GmbH posted to leak siteransomware_live · 2026-08-27
- New Instagram and Facebook rules set a default two-hour limit for teensmalwarebytes_blog · 2026-08-27
- Threat landscape for industrial automation systems. Q2 2026securelist · 2026-08-27
- JavaScript obfuscation: From party trick to phishing kittalos · 2026-08-27
- The AI Productivity Paradox: More Code, Not More Deliverysonatype · 2026-08-27
- LLM-Based Social Engineering Scamsschneier · 2026-08-27
- GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Addressthehackernews · 2026-08-27
- [emperador] Capitol Mechanics posted to leak siteransomware_live · 2026-08-27
- Critical Avada WordPress Flaw (CVE-2026-18431) Enables RCEsocradar_blog · 2026-08-27
- New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Accessthehackernews · 2026-08-27
- CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugsthehackernews · 2026-08-27
- [medusalocker] Jgsee posted to leak siteransomware_live · 2026-08-27
- [medusalocker] Servifruit posted to leak siteransomware_live · 2026-08-27
- [medusalocker] Hungry Lion posted to leak siteransomware_live · 2026-08-27
- [medusalocker] Qualisteel posted to leak siteransomware_live · 2026-08-27
- [medusalocker] Health posted to leak siteransomware_live · 2026-08-27
- Re: Re: Reporter attribution is absent from GitHub's machine-readable vulnerability records, and from the NVD entirelyoss_sec · 2026-08-27
- Srsly Risky Biz: China's AI-Enabled APT Operations Are Getting Interestingriskybiz_news · 2026-08-27
- Re: Reporter attribution is absent from GitHub's machine-readable vulnerability records, and from the NVD entirelyoss_sec · 2026-08-27
- Breaking Claude Code Opus 5 Auto Modeembracethered · 2026-08-27
- Reporter attribution is absent from GitHub's machine-readable vulnerability records, and from the NVD entirelyoss_sec · 2026-08-27
- F5 BIG-IP Denial of Service Vulnerabilityhkcert · 2026-08-27
- A Reported Log4j RCE Is More Complicated Than It Lookssonatype · 2026-08-27
- Zscaler WebMCP Security Controls: Bringing Zero Trust to the Agentic Webzscaler_threatlabz · 2026-08-27
- BlueDelta Targets Defense and Diplomacy with HOOKEDGErecordedfuture · 2026-08-27
- [CISA KEV] CVE-2023-49105 — ownCloud ownCloud: ownCloud Improper Authentication Vulnerabilitycisa_kev · 2026-08-27
- [CISA KEV] CVE-2026-53362 — Linux Kernel: Linux Kernel Unspecified Vulnerabilitycisa_kev · 2026-08-27
- [CISA KEV] CVE-2026-66384 — JFrog Artifactory: JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerabilitycisa_kev · 2026-08-27
- [Breach] Manchester Airports Group — 8,728,451 accounts exposedhibp_breaches · 2026-08-27
- [NVD] CVE-2026-81203 (HIGH 7.3) — A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown function of the file /admin/ajax.php?action=login2. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The nvd · 2026-08-26
- [NVD] CVE-2026-65956 — KubePi is a Kubernetes multi-cluster management panel. In versions up to and including 1.6.15, the SSO configuration API endpoints are exposed on the same public routing boundary as the SSO login and callback endpoints, so SSO, OIDC, and SAML management operations can be reached nvd · 2026-08-26
- [SilentRansomGroup] Q... E... posted to leak siteransomware_live · 2026-08-26
- [SilentRansomGroup] N... M... posted to leak siteransomware_live · 2026-08-26
- [SilentRansomGroup] S... P... posted to leak siteransomware_live · 2026-08-26
- [SilentRansomGroup] K... M... posted to leak siteransomware_live · 2026-08-26