THREAT OPS › Threat News
Threat Intelligence News
11697 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [SilentRansomGroup] H... K... posted to leak siteransomware_live · 2026-08-26
- [SilentRansomGroup] H... L... posted to leak siteransomware_live · 2026-08-26
- [SilentRansomGroup] C... O... posted to leak siteransomware_live · 2026-08-26
- Human + AI: How Our Product Managers Build Fasterzscaler_threatlabz · 2026-08-26
- Human + AI: How Our Product Managers Innovate with AIzscaler_threatlabz · 2026-08-26
- [iah6477] proampac posted to leak siteransomware_live · 2026-08-26
- [vim-security] Integer Overflow in Undo File Entry Size Check in Vim < v9.2.1014 && Vim >= v8.1.0688oss_sec · 2026-08-26
- [NVD] CVE-2026-77317 (HIGH 8.1) — SeaweedFS is a distributed storage system for files and blobs. In versions from 3.88 through 4.39, the SFTP server evaluates configured path permissions with a literal string-prefix comparison, so a user scoped to a path is also granted the same access to any sibling path whose nnvd · 2026-08-26
- [vim-security] Out-of-bounds Access in libvterm Resize Handling in Vim < 9.2.1013oss_sec · 2026-08-26
- [SilentRansomGroup] A... posted to leak siteransomware_live · 2026-08-26
- [NVD] CVE-2026-79921 — amqp091-go is a Go AMQP 0.9.1 client. Before version 1.13.0, a compromised or malicious AMQP broker can force the client to allocate resources for and process content body frames that exceed the negotiated frame_max limit. This can lead to unexpected memory consumption or applicanvd · 2026-08-26
- [NVD] CVE-2026-61792 (HIGH 7.7) — Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a project administrator can read files outside their repository through the App store metadata download feature, which resolves attacker-influenced paths witnvd · 2026-08-26
- [iah6477] mat-holdings-inc posted to leak siteransomware_live · 2026-08-26
- [NVD] CVE-2026-75601 (MEDIUM 4.3) — Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. Through 2.43.0, instances with both basic-auth and metrics features enabled process the /metrics endpoint before the basic-auth check in src/handler.rs, allowing an unauthenticated rnvd · 2026-08-26
- [NVD] CVE-2026-46370 (MEDIUM 6.5) — Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the labels host-listing endpoint (GET /api/v1/fleet/labels/{id}/hosts) allowed an authenticated user with the lowest-privilege Observer role to extract host enrollment secnvd · 2026-08-26
- [qilin] Sanatorio Modelo de Caseros posted to leak siteransomware_live · 2026-08-26
- [qilin] KenEp Resources posted to leak siteransomware_live · 2026-08-26
- [NVD] CVE-2026-32639 (MEDIUM 6.8) — Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the CMS section's Theme Editor AJAX handlers did not enforce per-template-type permission checks, allowing a backend user with any single CMS permission to act onnvd · 2026-08-26
- [GHSA] GHSA-crx4-7mmq-j74j (low) — OpenSTAManager has HTML Injection in modules/utenti/edit.phpgithub_advisories · 2026-08-26
- [GHSA] GHSA-7w8c-qgxg-m7jx (high) — LibreNMS — Stored XSS via SNMP/Syslog Data in Legacy Templatesgithub_advisories · 2026-08-26
- TeamViewer security advisory (AV26-852)cccs_ca · 2026-08-26
- Ubiquiti security advisory (AV26-850)cccs_ca · 2026-08-26
- What to Look for in a Deception Technology Solutionzscaler_threatlabz · 2026-08-26
- graphql-go/graphql <= 0.8.1: quadratic CPU-exhaustion DoS via per-error full-document rescan (GetLocation)oss_sec · 2026-08-26
- FD - Half-click unauthenticated remote code execution on Horde Groupware IMP (from a stored XSS)fulldisclosure · 2026-08-26
- [NotCVE-2026-0013] CHIRP Kenwood ITM Driver Eval Injection Allows Arbitrary Code Execution via Crafted Radio Filefulldisclosure · 2026-08-26
- [NotCVE-2026-0012] EmpManageX Hardcoded Administrative Credentials in Login API Allow Full Access to Employee Recordsfulldisclosure · 2026-08-26
- [NotCVE-2026-0011] Nmap 7.99 and Earlier nselib/packet.lua Zero-Length TCP Option Infinite Loop Allows Remote Denial of Servicefulldisclosure · 2026-08-26
- [NotCVE-2026-0010] Barrier 2.4.0 for Windows Unauthenticated IPC Command Execution Allows Local Privilege Escalation to SYSTEMfulldisclosure · 2026-08-26
- [NotCVE-2026-0009] NitroShare Desktop 0.3.4 Path Traversal Allows LAN-Adjacent Arbitrary File Writefulldisclosure · 2026-08-26
- When AI infrastructure becomes the target: Securing gateways and control pointsmsstic · 2026-08-26
- FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizationsthehackernews · 2026-08-26
- [NVD] CVE-2026-81036 (HIGH 8.1) — Stalwart Mail Server does not compare an OAuth redirect target against any registered destination in its default configuration. The validation routine in crates/http/src/auth/oauth/registration.rs returns success immediately when the client-authentication requirement is disabled,nvd · 2026-08-26
- [NVD] CVE-2026-81031 (HIGH 7.2) — IDURAR ERP CRM changes the password of whichever account a request names rather than the account making the request. The update handler in backend/src/controllers/middlewaresControllers/createUserController/updatePassword.js resolves the authenticated user from the request that tnvd · 2026-08-26
- [NVD] CVE-2026-80428 (CRITICAL 9.8) — ILIAS deserialises stored session data for an unauthenticated caller. The Shibboleth back-channel endpoint at components/ILIAS/AuthShibboleth/resources/shib_logout.php runs in a context that ilInitialisation exempts from authentication, and its logout-notification handler locatesnvd · 2026-08-26
- [NVD] CVE-2026-54614 (MEDIUM 4.3) — DebugKit provides a debugging toolbar for CakePHP applications. Prior to 4.10.3 and 5.2.4, the DebugKit MailPreview feature in src/Controller/MailPreviewController.php accepts a route-controlled previewName value in findPreview and passes the resolved class from App::className() nvd · 2026-08-26
- Cisco Advance Notification for Publication of September 2, 2026, Security Advisoriescisco_psirt · 2026-08-26
- Who Has Admin Rights in your Entra ID Directory?, (Wed, Aug 26th)sans_isc · 2026-08-26
- [krybit] finodayacapital.com posted to leak siteransomware_live · 2026-08-26
- [krybit] cgcgabon.com posted to leak siteransomware_live · 2026-08-26
- [krybit] karkinos.in posted to leak siteransomware_live · 2026-08-26
- [krybit] ferretornillos.gt posted to leak siteransomware_live · 2026-08-26
- [krybit] www.sankovn.com posted to leak siteransomware_live · 2026-08-26
- The Evolution of Hacktivism in Hybrid Warfare: Modern Tactics and Real-World Impactflashpoint · 2026-08-26
- [thegentlemen] Party Rental posted to leak siteransomware_live · 2026-08-26
- [thegentlemen] TEC Container posted to leak siteransomware_live · 2026-08-26
- [thegentlemen] Verbux posted to leak siteransomware_live · 2026-08-26
- [thegentlemen] Espinos posted to leak siteransomware_live · 2026-08-26
- Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunnelerthehackernews · 2026-08-26
- [thegentlemen] Incolur posted to leak siteransomware_live · 2026-08-26
- Next.js security advisory (AV26-851)cccs_ca · 2026-08-26
- [GHSA] GHSA-2wxc-x7rj-hg8f (high) — asyncssh has SCP Path Traversal to Arbitrary File Writegithub_advisories · 2026-08-26
- [GHSA] GHSA-qr67-gv47-xwwh (medium) — asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitutiongithub_advisories · 2026-08-26
- [krybit] www.neooftalmo.com.br posted to leak siteransomware_live · 2026-08-26
- [GHSA] GHSA-p46m-g734-vpc4 (medium) — cakephp/debug_kit: MailPreview contains unsafe reflectiongithub_advisories · 2026-08-26
- [krybit] lemonfarm.com posted to leak siteransomware_live · 2026-08-26
- Escargot v4.3.0-214-gfaee4437 Unauthenticated Remote Debugger Allows Arbitrary JavaScript Evaluation and Local File Disclosurefulldisclosure · 2026-08-26
- Escargot v4.3.0-214-gfaee4437 OS Command Injection in Crash Handler via Unsanitized Executable Pathfulldisclosure · 2026-08-26
- Escargot v4.3.0-214-gfaee4437 Debugger WebSocket Off-by-One Stack Buffer Overflowfulldisclosure · 2026-08-26
- UltraJSON v5.13.0-6-g733f9e1 Length-Boundary Violation Causes Out-of-Bounds Read During Incomplete JSON Parsingfulldisclosure · 2026-08-26
- Realtek edimax 52fc10d19 In-Band Ioctl Response Length Confusion Causes Heap Buffer Overflowfulldisclosure · 2026-08-26
- WatsonWebserver v7.1.0 HTTP/1 Chunked Request Processing Bypasses MaxRequestBodySizefulldisclosure · 2026-08-26
- Chronicle Wire v2026.8 Arbitrary Class Instantiation During YAML Deserialization via Externally Controlled YAML Type Tagsfulldisclosure · 2026-08-26
- Chronicle Wire v2026.8 Insecure Reflection Allows Unvalidated Method Invocationfulldisclosure · 2026-08-26
- Chronicle Wire v2026.8 FileMarshallableOut Append Operations Follow Symbolic Links and Allow File Write Redirectionfulldisclosure · 2026-08-26
- [krybit] wmiemporium.com posted to leak siteransomware_live · 2026-08-26
- Multiple Vulnerabilities in TBEA TLogger Communication Box 3rd Generationfulldisclosure · 2026-08-26
- [krybit] mimafoods.net posted to leak siteransomware_live · 2026-08-26
- CVE-2026-75020: Apache APISIX: ldap-auth plugin cross-subtree identity impersonationoss_sec · 2026-08-26
- [0day-rubbish] VitalPBX 4.5.2 (Asterisk 20.20.1) Authenticated root RCE via asterisk_cli to dialplan System() (8.8)fulldisclosure · 2026-08-26
- [0day-rubbish] Seeq Server R65.2.3 (default deployment with Data Lab installed via the official CLI) Unauthenticated RCE (open self-registration + Data Lab Jupyter missing authorization) (9.8)fulldisclosure · 2026-08-26
- [0day-rubbish] Raritan EMX firmware emx_ecx_3.6.1_46982 (EMX/ECX gateway) Authenticated config injection to root RCE (8.8)fulldisclosure · 2026-08-26
- [0day-rubbish] mySCADA PRO Runtime 9.4.0 (container deployment msxrun; earlier versions with the same upgrade branch are likely affected) Unauthenticated OS command injection to root RCE (9.4)fulldisclosure · 2026-08-26
- [0day-rubbish] Maian Gallery v2.1 Authenticated unrestricted file upload to PHP RCE (7.2)fulldisclosure · 2026-08-26
- [0day-rubbish] Leostream Connection Broker 9.1.37.0 two vulnerabilities (SQLi to root RCE, unauth SSRF)fulldisclosure · 2026-08-26
- [0day-rubbish] Delta DIAEnergie IEMS V1.11 Authenticated (conditional) SQL injection to VBScript RCE (8.8)fulldisclosure · 2026-08-26
- [GHSA] GHSA-jrw6-7x4q-w25j (critical) — senaite.core Vulnerable to Eval Injection and Missing Authorizationgithub_advisories · 2026-08-26
- [0day-rubbish] CacheGuard OS UF-2.5.2 Authenticated RCE via config-import eval injection (8.8)fulldisclosure · 2026-08-26
- [0day-rubbish] Biamp Devio SCR-20/25 firmware 2.3.1 Unauthenticated remote root RCE (DTP protocol quote injection) (9.8)fulldisclosure · 2026-08-26
- [0day-rubbish] SpiraTeam 9.3.0.0 (other versions with the same RetrieveByIndentLevel implementation are likely affected) Authenticated SQL injection to RCE (sysadmin + xp_cmdshell) (8.8)fulldisclosure · 2026-08-26
- [0day-rubbish] webMethods Microservices Runtime (MSR) 10.x (other versions with the same XSLT module are likely affected) Pre-authentication RCE (default factory credentials + XSLT extension functions) (9.8)fulldisclosure · 2026-08-26
- [0day-rubbish] Scan2x ScanWebClient 2.3.3.0 (other versions with the same handler are likely affected) Pre-authentication RCE (unrestricted upload to executable webroot) (9.8)fulldisclosure · 2026-08-26
- [krybit] sysconth.com posted to leak siteransomware_live · 2026-08-26
- [krybit] jindallifescience.com posted to leak siteransomware_live · 2026-08-26
- [krybit] vascara.com posted to leak siteransomware_live · 2026-08-26
- CVE-2026-75005: Apache APISIX: Unauthenticated CPU-exhaustion DoSoss_sec · 2026-08-26
- [GHSA] GHSA-w93q-cq9w-58p7 (high) — SunEditor Embed Plugin has DOM XSS via External Script Element After Iframe Embedgithub_advisories · 2026-08-26
- CVE-2026-74848: Apache APISIX: Cross-user response poisoning in serverless pluginsoss_sec · 2026-08-26
- [GHSA] GHSA-w5fv-7x5q-g8qp (high) — Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account rootgithub_advisories · 2026-08-26
- [Eclipse] Simplex Engineering posted to leak siteransomware_live · 2026-08-26
- [NVD] CVE-2026-54556 — Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, an unauthenticated HTTP/2 peer can cause an out-of-memory denial of service in the Ember backend with HTTP/2 enabled. The Hpack wrapper in ember-core/shared/src/main/scala/org/http4s/ember/core/h2/Hpacnvd · 2026-08-26
- Beyond Patching: What IT Teams Need to Know About Unfixable Exposuresqualys · 2026-08-26
- When an AI Agent Turned Attacker: What Qualys Sees Across Every Phase of the Hugging Face Kubernetes Intrusionqualys · 2026-08-26
- Ransom & Dark Web Issues Week 4, August 2026ahnlab · 2026-08-26
- The GTA VI Leak by CyberLeek Explainedsocradar_blog · 2026-08-26
- [GHSA] GHSA-x287-5c68-36wp (medium) — OpenWISP IPAM has broken object-level authorization: ExportSubnetView lets a member of one organization export another organization's subnet and all its IP addressesgithub_advisories · 2026-08-26
- [GHSA] GHSA-93qj-5q5v-3c2h (critical) — Trojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise)github_advisories · 2026-08-26
- [GHSA] GHSA-m452-q8c9-rg2f (medium) — AsyncHttpClient stores cookie for an unrelated domain (cookie tossing) via ThreadSafeCookieStoregithub_advisories · 2026-08-26
- Case Study: Conquering the EU Cyber Resilience Act (CRA) with 1,400 Upstream Security Fixesopenssf_blog · 2026-08-26
- [GHSA] GHSA-3p27-qvp9-27qf (low) — Wasmtime has a leak in WASIp1 `fd_renumber` implementationgithub_advisories · 2026-08-26