THREAT OPS › Threat News
Threat Intelligence News
11697 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [GHSA] GHSA-8h6h-x5pq-56fq (high) — @logtape/syslog: syslog log injection via unescaped control characters and unvalidated SD-NAME keysgithub_advisories · 2026-08-26
- [GHSA] GHSA-f63g-88cj-hjf9 (high) — IzPack has Path Traversal in UnpackerBase that allows writing files outside the installation directory via malicious pack entriesgithub_advisories · 2026-08-26
- [GHSA] GHSA-79gf-7frw-68m9 (critical) — Kyverno's NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-systemgithub_advisories · 2026-08-26
- [GHSA] GHSA-mv8m-v9v6-5f94 (low) — kas Persistently Disables SSH Host Key Checkinggithub_advisories · 2026-08-26
- [NVD] CVE-2026-73108 (HIGH 7.5) — RustDesk versions before 1.4.7 contain an uncontrolled speculative memory allocation vulnerability in BytesCodec. Before authentication, the decoder trusts the payload length encoded in a four-byte frame header and reserves that amount before receiving the payload. A crafted headnvd · 2026-08-26
- NVIDIA security advisory (AV26-849)cccs_ca · 2026-08-26
- [GHSA] GHSA-6753-gr46-6wpr (medium) — Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoSgithub_advisories · 2026-08-26
- [GHSA] GHSA-vmm3-xgcx-67hm (high) — http4s has HTTP/2 Denial of Service with Ember Backendgithub_advisories · 2026-08-26
- [GHSA] GHSA-6x9p-4r67-5gjx (high) — Budibase authenticated arbitrary S3 signed upload URL issuance via `/api/attachments/:datasourceId/url`github_advisories · 2026-08-26
- Adobe security advisory (AV26-848)cccs_ca · 2026-08-26
- [akira] Gill Rock Drill posted to leak siteransomware_live · 2026-08-26
- NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessionsthehackernews · 2026-08-26
- [akira] Oral and Maxillofacial Surgery posted to leak siteransomware_live · 2026-08-26
- [akira] PA-ID posted to leak siteransomware_live · 2026-08-26
- Update Chrome before you browse againmalwarebytes_blog · 2026-08-26
- CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothingthehackernews · 2026-08-26
- Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimetertenable · 2026-08-26
- [qilin] Metal Conversions posted to leak siteransomware_live · 2026-08-26
- [qilin] California Truck Equipment posted to leak siteransomware_live · 2026-08-26
- [qilin] Northern Leasing Systems posted to leak siteransomware_live · 2026-08-26
- Popular school apps may be sharing student data with advertisersmalwarebytes_blog · 2026-08-26
- Spyware for Babiesschneier · 2026-08-26
- CISA Vulnerability Reviewcisa_advisories · 2026-08-26
- CISA Adds Six Known Exploited Vulnerabilities to Catalogcisa_advisories · 2026-08-26
- Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Codethehackernews · 2026-08-26
- Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Enginethehackernews · 2026-08-26
- [qilin] Integrex RCM posted to leak siteransomware_live · 2026-08-26
- [qilin] ATF posted to leak siteransomware_live · 2026-08-26
- [qilin] WireCo posted to leak siteransomware_live · 2026-08-26
- [aurora] ERPIS LLC posted to leak siteransomware_live · 2026-08-26
- [NVD] CVE-2026-80203 (CRITICAL 9.8) — The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope in the requireNotSuperTarget() function in UsersController.php across seven sensitive user-management endpoints. The check uses isSuperAdmin() on the acting account rather than verifying whether the snvd · 2026-08-26
- VMs won't contain cyber-capable agentstrailofbits · 2026-08-26
- Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in Teststhehackernews · 2026-08-26
- [NVD] CVE-2026-80346 (HIGH 7.1) — StarRocks performs no privilege check when a legacy synchronous materialized view is dropped. Every other statement type routed through AuthorizerStmtVisitor calls into Authorizer before execution, but visitDropMaterializedViewStatement returns immediately with a comment stating nvd · 2026-08-26
- Choose your fighter: Balancing competing requirements to select models for your AI SOCtalos · 2026-08-26
- Exploits and vulnerabilities in Q2 2026securelist · 2026-08-26
- [abyss] MEMSIC posted to leak siteransomware_live · 2026-08-26
- [AiLock] Morgan Services posted to leak siteransomware_live · 2026-08-26
- [AiLock] Hamilton posted to leak siteransomware_live · 2026-08-26
- OpenAI Bans Russian ChatGPT Accounts Used to Run Influence Operationthehackernews · 2026-08-26
- What’s New in GovCloud: August 2026 Zscaler Product Updateszscaler_threatlabz · 2026-08-26
- Beware of fake Indeed interview apps used to install spywaremalwarebytes_blog · 2026-08-26
- INTERPOL Operation Jackal IV Arrests 58, Identifies 263 in Global Cyber Fraud Crackdownthehackernews · 2026-08-26
- Newly SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecodethehackernews · 2026-08-26
- Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payloadthehackernews · 2026-08-26
- [NVD] CVE-2026-79654 (MEDIUM 4.3) — A flaw was found in Katello where the Content View History API does not properly enforce authorization when accessing a Content View specified by the user. An authenticated user with permission to view Content Views in one organization may be able to access the lifecycle history nvd · 2026-08-26
- CVE-2026-63041: Apache APISIX: attach-consumer-label does not strip client-supplied consumer-label headersoss_sec · 2026-08-26
- Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codesthehackernews · 2026-08-26
- [NVD] CVE-2026-80198 (HIGH 7.5) — Kimai versions before 2.56.0 fail to restrict the config() Twig function in sandboxed invoice and export templates, allowing administrators to access arbitrary configuration keys. Attackers with admin privileges can upload malicious templates to exfiltrate server-wide secrets incnvd · 2026-08-26
- [NVD] CVE-2026-80193 (HIGH 8.8) — Kimai before 2.62.0 fails to validate create_other_timesheet permission in the QuickEntry controller when creating new timesheets. Authenticated users with view_other_timesheet and edit_other_timesheet permissions can create timesheet records for team members by submitting the Qunvd · 2026-08-26
- [NVD] CVE-2026-80192 (HIGH 8.1) — @better-auth/sso before 1.6.27 (and before 1.4.8 in the 1.4.x line and before 1.7.0-rc.5 in the 1.7 prerelease line) contains two domain-ownership flaws. When domain verification is disabled, automatic organization assignment accepts unverified provider domains, allowing an authenvd · 2026-08-26
- [NVD] CVE-2026-57170 (HIGH 7.8) — Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions prior to 3.12.4 and 4.0.0 through 4.0.3, the custom Jinja2 include tags mdsection_include and md_clean_include re-parse the content of an included Markdown filenvd · 2026-08-26
- Risky Bulletin: Russia starts blocking DoH and DoTriskybiz_news · 2026-08-26
- Google Chrome Multiple Vulnerabilitieshkcert · 2026-08-26
- Veeam Backup & Replication Information Disclosure Vulnerabilityhkcert · 2026-08-26
- [qilin] Air International Thermal Systems posted to leak siteransomware_live · 2026-08-26
- Linux Foundation Backs New TRACE AI Security Standardduo_decipher · 2026-08-26
- CVE-2026-73180: Apache Tomcat: Authenticated WebSocket session survives end of HTTP sessionoss_sec · 2026-08-26
- CVE-2026-68763: Apache Tomcat: DoS via allocation leak in HTTP/2 backlog tracking when a stream is resetoss_sec · 2026-08-26
- CVE-2026-68569: Apache Tomcat: Principal lookup can fail open in some casesoss_sec · 2026-08-26
- CVE-2026-68525: Apache Tomcat: Redirect after FORM auth may bypass method specific constraintsoss_sec · 2026-08-26
- CVE-2026-66422: Apache Tomcat: Servlet role references can bypass declarative role constraintsoss_sec · 2026-08-26
- CVE-2026-65927: Apache Tomcat: RewriteValve [N] restarts at the second rule and may bypass access controloss_sec · 2026-08-26
- CVE-2026-65905: Apache Tomcat: Limited replay attack possible with DIGEST authenticationoss_sec · 2026-08-26
- CVE-2026-65637: Apache Tomcat: HTTP/2 no-authority bypass of strict SNI validation - CVE-2026-32990 fix incompleteoss_sec · 2026-08-26
- CVE-2026-65183: Apache Tomcat: TOCTOU when setting specific permissions for Unix Domain Socketsoss_sec · 2026-08-26
- CVE-2026-65182: Apache Tomcat: Bypass longest prefix security constraintoss_sec · 2026-08-26
- Recorded Future Launches AI Alert Filteringrecordedfuture · 2026-08-26
- [CISA KEV] CVE-2021-23758 — Ajax.NET Professional Ajax.NET Professional: Ajax.NET Professional Deserialization of Untrusted Data Vulnerabilitycisa_kev · 2026-08-26
- [CISA KEV] CVE-2015-3246 — Red Hat Libuser: Red Hat Libuser Race Condition Vulnerabilitycisa_kev · 2026-08-26
- [CISA KEV] CVE-2015-5287 — Red Hat Automatic Bug Reporting Tool: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerabilitycisa_kev · 2026-08-26
- [CISA KEV] CVE-2022-0995 — Linux Kernel: Linux Kernel Out-of-Bounds Write Vulnerabilitycisa_kev · 2026-08-26
- [CISA KEV] CVE-2026-8452 — Citrix NetScaler ADC and NetScaler Gateway: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerabilitycisa_kev · 2026-08-26
- [CISA KEV] CVE-2019-1068 — Microsoft SQL Server: Microsoft SQL Server Remote Code Execution Vulnerabilitycisa_kev · 2026-08-26
- [CVE-2026-19672] CPython: tarfile extraction filter bypass allows creation of directories outside the destinationoss_sec · 2026-08-25
- [Orova] Central Florida Civil LLC posted to leak siteransomware_live · 2026-08-25
- [Orova] Arich Enterprise Co., Ltd. posted to leak siteransomware_live · 2026-08-25
- [Orova] Bai-chi CPA Firm posted to leak siteransomware_live · 2026-08-25
- Re: [OSSA-2026-037] OpenStack Keystone: Inconsistent scope enforcement for delegated tokens (CVE-2026-80182, CVE-2026-80184)oss_sec · 2026-08-25
- [NVD] CVE-2026-79804 (HIGH 7.3) — A vulnerability was found in SililaWijesinghe Food Ordering System up to ba314e897e3365600461e5ea59432e39ceaa0fa5. Affected by this issue is some unknown functionality of the file /search.php. Performing a manipulation of the argument search_box results in sql injection. Remote envd · 2026-08-25
- [NVD] CVE-2026-63404 — Faktory is a language-agnostic background job server. In versions prior to 1.10.0, the embedded Redis bootstrapper is vulnerable to an insecure temporary file flaw that lets a local unprivileged user hijack the Redis configuration and escalate to root. It writes its startup confinvd · 2026-08-25
- [NVD] CVE-2026-32637 — Velero is an open source tool for backing up, restoring, and migrating Kubernetes cluster resources and persistent volumes. Prior to 1.18.1, an attacker who compromises the backup object-storage backend can upload a malicious backup tarball containing parent-directory paths that nvd · 2026-08-25
- [vim-security] Arbitrary Ex Command Execution via File Names in C Omni-Completion in Vim < 9.2.1011oss_sec · 2026-08-25
- CVE-2026-78655: Punk::Plugin::TOTP versions before 0.05 for Perl allow the second-factor attempt limit to be reset by replaying an earlier session cookie because the challenge route counts failures in the sessionoss_sec · 2026-08-25
- CVE-2026-78619: Punk::Plugin::TOTP versions before 0.05 for Perl accept another account's recovery code at the two-factor challenge because totp_use_recovery compares user identifiers numericallyoss_sec · 2026-08-25
- Zero Trust or Bust: Winning Compliance in an AI-Driven Multicloud Worldzscaler_threatlabz · 2026-08-25
- [qilin] Brazosport College posted to leak siteransomware_live · 2026-08-25
- [AuditTeam] ma***up posted to leak siteransomware_live · 2026-08-25
- [NVD] CVE-2026-80104 (CRITICAL 9.8) — DB-GPT builds the destination path for an uploaded skill from the multipart filename without constraining it to the upload directory. skill_upload in packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py takes file.filename as given and writes the request body to upnvd · 2026-08-25
- [safepay] industry.airliquide.kr posted to leak siteransomware_live · 2026-08-25
- [NVD] CVE-2026-68513 (HIGH 7.1) — OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13 contain a heap buffer overflow in PyOpenEXR triggered by a channel-name key collision between litnvd · 2026-08-25
- [NVD] CVE-2026-59981 (HIGH 7.1) — OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, the OpenEXRUtil library returns an out-of-bounds pointer from the Samplnvd · 2026-08-25
- [GHSA] GHSA-p43p-whwx-q52h (medium) — JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Logingithub_advisories · 2026-08-25
- [GHSA] GHSA-cv84-9p8j-fj68 (high) — icalendar has Algorithmic Complexity in Equalitygithub_advisories · 2026-08-25
- [chaos] parkderochie.com posted to leak siteransomware_live · 2026-08-25
- [chaos] mswalker.com posted to leak siteransomware_live · 2026-08-25
- [chaos] copcp.com posted to leak siteransomware_live · 2026-08-25
- [GHSA] GHSA-hvfh-5mj3-5f3j (high) — Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network accessgithub_advisories · 2026-08-25
- [GHSA] GHSA-w3fx-mc44-mf6j (critical) — Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code executiongithub_advisories · 2026-08-25
- [NVD] CVE-2026-79786 (HIGH 7.1) — Coroot's unauthenticated MCP OAuth dynamic client registration endpoint accepts any syntactically valid redirect URI without validation, allowing attackers to register clients pointing to attacker-controlled hosts. Attackers can send authorization URLs to signed-in users, capturenvd · 2026-08-25