THREAT OPS › Threat News
Threat Intelligence News
11701 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [NVD] CVE-2026-79786 (HIGH 7.1) — Coroot's unauthenticated MCP OAuth dynamic client registration endpoint accepts any syntactically valid redirect URI without validation, allowing attackers to register clients pointing to attacker-controlled hosts. Attackers can send authorization URLs to signed-in users, capturenvd · 2026-08-25
- [NVD] CVE-2026-55618 (MEDIUM 6.5) — eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed information. Prior to 3.0.2, the clean_found_uri function in eml_parser/parser.py validates potential URL strings before unescaping HTML entities unvd · 2026-08-25
- WatchGuard security advisory (AV26-847)cccs_ca · 2026-08-25
- [qilin] SC PaderTeG Cabluri Electrice posted to leak siteransomware_live · 2026-08-25
- OpenSSL security advisory (AV26-846)cccs_ca · 2026-08-25
- [GHSA] GHSA-72f3-6w86-7rv3 (medium) — @arikusi/deepseek-mcp-server: Missing Authentication on Self-Hosted HTTP MCP Endpointgithub_advisories · 2026-08-25
- [GHSA] GHSA-fh3r-g96v-f578 (high) — @arikusi/deepseek-mcp-server has an Authorization Bypass Through User-Controlled Keygithub_advisories · 2026-08-25
- [GHSA] GHSA-xc9g-j69q-37xw (high) — consciousness-explorer / sublinear-time-solver MCP export_state has an arbitrary file writegithub_advisories · 2026-08-25
- [GHSA] GHSA-3vfr-4gwf-qxfp (high) — Whistle vulnerable to path traversalgithub_advisories · 2026-08-25
- Gitea security advisory (AV26-845)cccs_ca · 2026-08-25
- [GHSA] GHSA-g7gc-gmgp-wgqg (high) — eml_parser vulnerable to DoS via deeply nested parens in Received headersgithub_advisories · 2026-08-25
- [GHSA] GHSA-m66c-fw79-6359 (medium) — eml_parser has parser DoS via deeply nested parentheses in e-mail headersgithub_advisories · 2026-08-25
- [GHSA] GHSA-fxgq-9m89-cxj9 (medium) — eml_parser has a URL extraction bypass via HTML entities in URLsgithub_advisories · 2026-08-25
- [GHSA] GHSA-777c-2fxx-qr28 (critical) — AshAuthentication vulnerable to OAuth2/OIDC account takeover via email-based user matchinggithub_advisories · 2026-08-25
- [NVD] CVE-2026-76197 (CRITICAL 10.0) — Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability tnvd · 2026-08-25
- [NVD] CVE-2026-76195 (CRITICAL 10.0) — Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability tnvd · 2026-08-25
- [NVD] CVE-2026-76193 (CRITICAL 10.0) — Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue doesnvd · 2026-08-25
- [NVD] CVE-2026-71399 (HIGH 7.8) — Adobe XD is affected by a Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim nvd · 2026-08-25
- [GHSA] GHSA-p7x2-g5cq-fhmq (medium) — mediasoup: SCTP state cookie lacks cryptographic authentication, enabling unauthorized association establishment (RFC 9260 violation)github_advisories · 2026-08-25
- U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breachesthehackernews · 2026-08-25
- [GHSA] GHSA-6ccx-9c9f-327w (high) — gRPC Erlang package has unbounded gzip decompression (decompression bomb)github_advisories · 2026-08-25
- [GHSA] GHSA-q8gf-9rvj-gmgj (high) — gRPC Erlang package has unbounded request body accumulation in `read_full_body/3`github_advisories · 2026-08-25
- [GHSA] GHSA-mwr4-5g34-j5cq (high) — gRPC Erlang package's path bindings are overridable by query string and request bodygithub_advisories · 2026-08-25
- [GHSA] GHSA-grp7-v8xh-rj7h (critical) — gRPC Erlang package vulnerable to Remote Code Execution with attacker-controlled gRPC payloadsgithub_advisories · 2026-08-25
- [GHSA] GHSA-cmwv-wf9p-p8wx (high) — genieacs-mcp: DNS rebinding reaches local GenieACS MCP Streamable HTTP transportgithub_advisories · 2026-08-25
- Wordfence Argus Finds Complex 6 Step Critical RCE in Avada Theme with 1 Million Saleswordfence · 2026-08-25
- [GHSA] GHSA-vwf3-4xxj-qg6h (high) — mcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environmentgithub_advisories · 2026-08-25
- [GHSA] GHSA-m2pc-3q4q-w6jr (medium) — reachy_mini Allows Unrestricted Upload of File with Dangerous Typegithub_advisories · 2026-08-25
- [GHSA] GHSA-mcj4-mphf-j9ff (high) — Trivy has a path traversal via a crafted vulnerability database or other downloaded artifactsgithub_advisories · 2026-08-25
- [GHSA] GHSA-pg62-f8g4-4wqh (high) — phpMyFAQ privilege escalation: GroupController::updatePermissions lets a GROUP_EDIT admin grant rights they do not holdgithub_advisories · 2026-08-25
- [GHSA] GHSA-mf8r-wm2w-f8c5 (medium) — phpMyFAQ public FAQ APIs expose inactive FAQ contentgithub_advisories · 2026-08-25
- [GHSA] GHSA-88g4-74f3-63x9 (medium) — phpMyFAQ has Potential Authenticated Path Traversal in PDF Exportgithub_advisories · 2026-08-25
- [NVD] CVE-2026-55585 (HIGH 8.8) — QWED is open-source AI verification infrastructure for deterministic verification of LLM outputs, tool calls, code, schemas, and agent state before production execution. Prior to 5.1.2, the qwed package passes caller-controlled math expressions directly to SymPy parse_expr() withnvd · 2026-08-25
- [OSSA-2026-037] OpenStack Keystone: Inconsistent scope enforcement for delegated tokens (CVE-2026-pending)oss_sec · 2026-08-25
- [GHSA] GHSA-qj6x-xx2h-8hvv (high) — Plate: Media embed provider metadata can bypass URL sanitization and execute iframe JavaScriptgithub_advisories · 2026-08-25
- [GHSA] GHSA-m9mq-7m7q-xc6p (high) — browse-mcp has an arbitrary file write via unconfined download and state pathsgithub_advisories · 2026-08-25
- [GHSA] GHSA-q27q-98j4-9pfv (high) — qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()`github_advisories · 2026-08-25
- OpenRGB: Remote System Compromise via Custom Network Protocol (CVE-2026-59682, CVE-2026-59683, CVE-2026-18794)oss_sec · 2026-08-25
- OpenSSL Security Advisory [25th August 2026]oss_sec · 2026-08-25
- [GHSA] GHSA-hq3h-g68c-hp78 (high) — urllib's cross-origin redirects preserve credential-bearing request headers, leading to potential credential leakagegithub_advisories · 2026-08-25
- graphql-go/graphql <= 0.8.1: improper scalar input-type validation -> type confusion and unrecoverable stack-overflow DoSoss_sec · 2026-08-25
- [NVD] CVE-2026-79782 (LOW 3.1) — rclone before 1.74.4 fails to strip the X-Amz-Security-Token header when an S3 redirect changes scheme from HTTPS to HTTP on the same host. Attackers can intercept plaintext HTTP traffic to capture AWS STS session tokens sent in request headers.nvd · 2026-08-25
- [NVD] CVE-2026-79775 (MEDIUM 6.5) — rclone versions >= v1.72.0 and <= v1.74.4 (fixed in v1.75.0) contain multiple denial-of-service vulnerabilities in the archive backend's SquashFS parser, which relies on the github.com/diskfs/go-diskfs dependency. The parser fails to validate attacker-controlled superblock and menvd · 2026-08-25
- [NVD] CVE-2026-79772 (MEDIUM 5.3) — Nokogiri versions before 1.19.1 fail to check the return value from xmlC14NExecute in the canonicalize method, returning an empty string on failure instead of raising an exception. Attackers can exploit this to bypass signature validation in downstream SAML libraries by providingnvd · 2026-08-25
- [NVD] CVE-2026-55582 (HIGH 8.4) — mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default security.yaml allows /usr/bin/git, while security.go omits ! from containsShellMetacharacters and containsDangerousShellConstructs and applies no per-executable anvd · 2026-08-25
- [NVD] CVE-2026-55536 (CRITICAL 9.1) — PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, Browser Server _handle_connection() checks Chrome extension origins with re.match() and the unanchored expression chrome-extension://[a-z0-9]{32}. Extra trailing characters pass before websocket.accept(), allowinnvd · 2026-08-25
- [NVD] CVE-2024-58378 (CRITICAL 9.8) — Nokogiri before 1.15.6 and 1.16.x before 1.16.2 (CRuby, when using the packaged libxml2) is affected by a use-after-free vulnerability in libxml2 (CVE-2024-25062) in the xmlTextReader module, which underlies Nokogiri::XML::Reader. When using the XML Reader interface with DTD valinvd · 2026-08-25
- [GHSA] GHSA-vfp3-v2gw-7wfq (high) — Echo: Encoded slash (%2F) bypasses route-level protection and exposes static filesgithub_advisories · 2026-08-25
- [GHSA] GHSA-xx4j-w367-7247 (high) — djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler callsgithub_advisories · 2026-08-25
- [GHSA] GHSA-8vh3-g2qg-2h2c (critical) — nextcloud-mcp-server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( default )github_advisories · 2026-08-25
- The patch window is collapsing: Why security needs a new control planemsstic · 2026-08-25
- [GHSA] GHSA-8qx3-8gm5-9cj2 (high) — pickem vulnerable to terminal escape-sequence injection via unsanitized item textgithub_advisories · 2026-08-25
- [direwolf] National Kidney Registry posted to leak siteransomware_live · 2026-08-25
- [direwolf] Studio Legale ESE posted to leak siteransomware_live · 2026-08-25
- [GHSA] GHSA-8cp3-qxj6-px34 (high) — utcp-http has an OAuth2 `tokenUrl` Trust Boundary Bypass in OpenAPI Conversiongithub_advisories · 2026-08-25
- [Global Secret Group] Tiseo Paving posted to leak siteransomware_live · 2026-08-25
- [Global Secret Group] Johnson City Honda posted to leak siteransomware_live · 2026-08-25
- [GHSA] GHSA-ppx3-28rw-8fpf (medium) — utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket pluginsgithub_advisories · 2026-08-25
- [Global Secret Group] Lockheed Architectural Solutions, Inc. posted to leak siteransomware_live · 2026-08-25
- [GHSA] GHSA-9qhg-99ww-9mqc (high) — utcp-http SSRF: HTTP tool invocation follows redirects without re-validating the targetgithub_advisories · 2026-08-25
- [GHSA] GHSA-f5pj-2738-996m (high) — mcp-shell — Security Disabled by Default in Bare-Binary Deploy Path + Shell Interpreter in Secure-Mode Allowlistgithub_advisories · 2026-08-25
- [GHSA] GHSA-3x77-wg38-92r3 (high) — mcp-shell has a Secure Mode Allowlist Bypass via Default `/bin/bash` Executablegithub_advisories · 2026-08-25
- [GHSA] GHSA-74hp-mggr-hv58 (high) — mcp-shell has a Secure Mode Allowlist Bypass via Git Shell Aliasgithub_advisories · 2026-08-25
- [GHSA] GHSA-mw6r-2hvm-4rp2 (critical) — qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Inputgithub_advisories · 2026-08-25
- [GHSA] GHSA-6g6r-q6gw-w8fg (critical) — PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92)github_advisories · 2026-08-25
- [GHSA] GHSA-pvph-5j39-v8qc (high) — PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP servergithub_advisories · 2026-08-25
- [GHSA] GHSA-gfq8-hmph-9gjv (high) — PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secretgithub_advisories · 2026-08-25
- [GHSA] GHSA-2jgc-f764-c5r2 (high) — PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, cancel and deletegithub_advisories · 2026-08-25
- 400,000 WordPress Sites Affected by Account Takeover Vulnerability in TranslatePress WordPress Pluginwordfence · 2026-08-25
- [GHSA] GHSA-gxmw-5f7x-6g22 (high) — praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable locationgithub_advisories · 2026-08-25
- [GHSA] GHSA-pvxx-r596-f5qj (high) — PraisonAI: `--api-key` flag on `praisonai serve` is not properly enforcedgithub_advisories · 2026-08-25
- Obfuscating IP Addresses as Hostnames, (Tue, Aug 25th)sans_isc · 2026-08-25
- [GHSA] GHSA-hmfx-4v44-9qw9 (medium) — PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validationgithub_advisories · 2026-08-25
- [GHSA] GHSA-rg5q-pp8p-f7jm (high) — PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114github_advisories · 2026-08-25
- [GHSA] GHSA-r7v3-x45f-g7hp (high) — PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticatedgithub_advisories · 2026-08-25
- [GHSA] GHSA-ch89-h4r2-c8f8 (high) — PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinksgithub_advisories · 2026-08-25
- WhatsApp Says One Billion Users Are Now Protected by Passkeyssocradar_blog · 2026-08-25
- [GHSA] GHSA-cfxv-8fw8-rwpv (medium) — praisonaiagents: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation toolgithub_advisories · 2026-08-25
- [GHSA] GHSA-vg6p-v9vm-6fgj (high) — praisonaiagents vulnerable to SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap)github_advisories · 2026-08-25
- [GHSA] GHSA-7ww9-85pg-cv4x (high) — PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent executiongithub_advisories · 2026-08-25
- [GHSA] GHSA-x44h-65qv-cw74 (high) — praisonaiagents has an SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)github_advisories · 2026-08-25
- [GHSA] GHSA-wv94-5qcp-6m36 (medium) — PraisonAI MCP HTTP server has unauthenticated unbounded session accumulation (memory exhaustion; session TTL never enforced)github_advisories · 2026-08-25
- [GHSA] GHSA-7g3p-92qq-8wvh (high) — praisonaiagents: AgentServer declares auth_token but never enforces it on any routegithub_advisories · 2026-08-25
- [GHSA] GHSA-wj6g-v78p-6fx3 (medium) — PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on local MCP servergithub_advisories · 2026-08-25
- [ShadowByt3$] Sinar Mas Agribusiness and Food Golden Agri-Resources) posted to leak siteransomware_live · 2026-08-25
- [ShadowByt3$] A-Plus Software Limited posted to leak siteransomware_live · 2026-08-25
- [ShadowByt3$] Knottingham Trent University posted to leak siteransomware_live · 2026-08-25
- [GHSA] GHSA-8hjw-25cg-g52h (high) — praisonaiagents has a `web_crawl` SSRF protection bypass via unchecked redirect targetsgithub_advisories · 2026-08-25
- [GHSA] GHSA-hxmv-c4g6-5fqc (high) — PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe codegithub_advisories · 2026-08-25
- A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClawthehackernews · 2026-08-25
- [GHSA] GHSA-5r34-2g38-6569 (high) — praisonaiagents web_crawl vulnerable to SSRF via redirect-followinggithub_advisories · 2026-08-25
- [genesis] S******* posted to leak siteransomware_live · 2026-08-25
- WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Androidthehackernews · 2026-08-25
- [NVD] CVE-2026-75803 (CRITICAL 9.1) — Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the operation is finalized by calling the EVP_Cipher() function. Impact summary: Applications calling EVP_Cipher() on an empnvd · 2026-08-25
- [NVD] CVE-2026-63076 (HIGH 7.5) — Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter. A crafted message can contain a parameter of a different type, which is then dereferenced anvd · 2026-08-25
- [NVD] CVE-2026-63075 (HIGH 7.5) — Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly sends ack-eliciting packets while not acknowledging ACK-only responses, the QUIC stack can retain ACK-only packet metadata for the lifetime of the connection. Impact summary: A remote peer that can convd · 2026-08-25
- [NVD] CVE-2026-63074 (MEDIUM 5.9) — Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP message, but never expunges them (for instance if they are invalid). If a server reuses an OSSL_CMP_CTX frequently, this cache of extraCerts may grow unbounnvd · 2026-08-25
- [NVD] CVE-2026-63073 (CRITICAL 9.8) — Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_data()`. Impact summary: A malicious or intercepted CMP endpoint can crash a CMP client that enforces an expected sender or uses a pnvd · 2026-08-25
- [NVD] CVE-2026-63072 (HIGH 7.5) — Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that query reports, causing an 8-byte out-of-bounds heap write. Impact summary: An attacnvd · 2026-08-25
- [NVD] CVE-2026-54874 (HIGH 7.5) — Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes OpenSSL to buffer far more memory than the record itself requires. Impact summary: A peer can use a small amount of network traffic to make an OpenSSL DTLS endpoint retain a dispropnvd · 2026-08-25