THREAT OPS › Threat News
Threat Intelligence News
11701 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [NVD] CVE-2026-14457 (HIGH 7.5) — Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs) enabled, and only the private key (with no associated certificate) configured locally, a NULL pointer dereference may occur when the remote peer solicits raw public keys and also sends the typinvd · 2026-08-25
- What’s in the SOSS? Podcast #70 – S3E22 Private Forks, CRA Deadlines, and the True Cost of Open Source Compliance with Dave Russoopenssf_blog · 2026-08-25
- Horizon3 Names Chad Keefer Vice President of Federal Saleshorizon3 · 2026-08-25
- How a Real Estate Company Turned a SQL Lockout Into Actionable Security Insighthorizon3 · 2026-08-25
- [akira] WINTER Ingenieure posted to leak siteransomware_live · 2026-08-25
- Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Modethehackernews · 2026-08-25
- [qilin] STRUCTURED SETTLEMENT CAPITAL LLC posted to leak siteransomware_live · 2026-08-25
- [akira] Davis & Ferber posted to leak siteransomware_live · 2026-08-25
- [NVD] CVE-2026-79671 (MEDIUM 5.5) — Ech0 before 4.4.3 contains a server-side request forgery vulnerability in the validateWebhookURL function (webhook_setting_service.go), which only validates literal IP addresses via net.ParseIP() and fails to reject hostnames that DNS-resolve to private or internal IPs (e.g., 169nvd · 2026-08-25
- [NVD] CVE-2026-79658 (HIGH 7.5) — Ech0 before 5.0.1 does not impose any size or shape limit on the Accept-Language header processed by its i18n middleware, which runs on every HTTP request. The header is passed unfiltered to go-i18n's NewLocalizer, which internally calls golang.org/x/text/language.ParseAcceptLangnvd · 2026-08-25
- A Tale of Two SOCs: Insights From Two Red Team Assessmentscisa_advisories · 2026-08-25
- CISA Adds One Known Exploited Vulnerability to Catalogcisa_advisories · 2026-08-25
- Ebyte NE2-D11cisa_advisories · 2026-08-25
- Rently Smart Homecisa_advisories · 2026-08-25
- PayRange APIcisa_advisories · 2026-08-25
- Zonemindercisa_advisories · 2026-08-25
- Siemens SIMATIC IoT2050 Advancedcisa_advisories · 2026-08-25
- FURUNO FA-50 Class B AIS Transpondercisa_advisories · 2026-08-25
- Bendix EC80 Brake ECUcisa_advisories · 2026-08-25
- [qilin] AGROLAND S.A. posted to leak siteransomware_live · 2026-08-25
- Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flowsthehackernews · 2026-08-25
- 24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pagesthehackernews · 2026-08-25
- Encrypted instructions can fool AI assistants like Grok and Geminimalwarebytes_blog · 2026-08-25
- E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commandsthehackernews · 2026-08-25
- Frontier AI: Vulnerability Management's Systemic Revolutionthehackernews · 2026-08-25
- State divergence enables unauthorized accesstrailofbits · 2026-08-25
- Black Hat State of Security Vendorsschneier · 2026-08-25
- GTA 6 leak hunt could expose data belonging to thousands of Discord usersmalwarebytes_blog · 2026-08-25
- The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Executionunit42 · 2026-08-25
- The safety penalty: Reclaiming operational sovereignty in the age of AItalos · 2026-08-25
- Why Financial Services Is the Canary in the Code Minesonatype · 2026-08-25
- [Dark Project] Pump Engineering Company posted to leak siteransomware_live · 2026-08-25
- From ‘High/Medium/Low’ to Dollars: Making Cyber Risk Legible to Your CFOcyble · 2026-08-25
- [Dark Project] Dentist in New Britain, CT posted to leak siteransomware_live · 2026-08-25
- Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Accessthehackernews · 2026-08-25
- TikTok phishing: How to spot fake login and verification pagesmalwarebytes_blog · 2026-08-25
- Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Datathehackernews · 2026-08-25
- [NVD] CVE-2026-72699 (MEDIUM 5.3) — The Grav Login plugin (getgrav/grav-plugin-login) before 3.9.1 is vulnerable to email address enumeration. The register() method in classes/Login.php throws a distinct exception (EMAIL_NOT_AVAILABLE) when a submitted email address already belongs to an existing account, while allnvd · 2026-08-25
- Re: CVE-2026-41992 gzip 1.14 out-of-bounds memory buffer accessoss_sec · 2026-08-25
- Mexico’s Cybersecurity Plan 2025-2030: Turning Ambition Into Defenserecordedfuture · 2026-08-25
- Inside Elastic's agentic SOC: How we took AI alert triage from 60% to 92% accuracyelastic_security · 2026-08-25
- [CISA KEV] CVE-2026-60004 — Gitea Gitea: Gitea Code Injection Vulnerabilitycisa_kev · 2026-08-25
- Third-Party Script Security: How Tags, Pixels, and Embeds Can Put Websites at Risksucuri_blog · 2026-08-24
- [qilin] Consultores de Seguros posted to leak siteransomware_live · 2026-08-24
- [GHSA] GHSA-fx4f-mhw4-qm7j (medium) — vibeio-http has a DoS vulnerability in HTTP/1.x chunked encoding parser triggered by maliciously crafted chunk lengthsgithub_advisories · 2026-08-24
- [GHSA] GHSA-w8j7-39hp-8x59 (medium) — Cloudreve's remote download file paths can escape the selected destination directorygithub_advisories · 2026-08-24
- [GHSA] GHSA-vx2m-jpxr-xv7w (medium) — Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hintgithub_advisories · 2026-08-24
- [Deadlock] SHAHEEN LAW GROUP PLC - Richmond, Virginia, USA posted to leak siteransomware_live · 2026-08-24
- [Deadlock] FBC posted to leak siteransomware_live · 2026-08-24
- [GHSA] GHSA-jm48-m3rr-9hgg (high) — 3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulationgithub_advisories · 2026-08-24
- [GHSA] GHSA-w67g-5rqw-f597 (medium) — Gorilla WebSocket Uses Cryptographically Weak PRNG for WebSocket Mask Keygithub_advisories · 2026-08-24
- [GHSA] GHSA-4ph6-mjv7-3fq6 (low) — netfoil vulnerable to improper handling of untrusted DoH response datagithub_advisories · 2026-08-24
- [GHSA] GHSA-fwjf-m4qw-9f2x (medium) — django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)github_advisories · 2026-08-24
- [GHSA] GHSA-8jj7-4v57-frf5 (high) — django CMS: Plugin move endpoint allows cyclic reparenting (DoS)github_advisories · 2026-08-24
- Between Two Nerds: Attribution is dead, long live attributionriskybiz_news · 2026-08-24
- [GHSA] GHSA-3gjw-f78c-vvpw (medium) — tokio-postgres: Panic on a `DataRow` with fewer fields than columns allows denial of servicegithub_advisories · 2026-08-24
- [GHSA] GHSA-rgqc-3x5p-6gwg (medium) — postgres-protocol: Panic decoding a malformed `hstore` value allows denial of servicegithub_advisories · 2026-08-24
- [GHSA] GHSA-5x78-73v4-xg6w (high) — postgres-protocol: Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of servicegithub_advisories · 2026-08-24
- [GHSA] GHSA-9284-fjc3-fmmj (medium) — Sakai Profile Image Deletion has an IDORgithub_advisories · 2026-08-24
- [GHSA] GHSA-w2x5-gv52-9ccv (high) — Sakai Conversations has a Stored XSS Issuegithub_advisories · 2026-08-24
- [safepay] lagegepesca.it posted to leak siteransomware_live · 2026-08-24
- Google security advisory (AV26-844)cccs_ca · 2026-08-24
- Oracle security advisory – January 2026 quarterly rollup (AV26-042) – Update 2cccs_ca · 2026-08-24
- [Dark Project] The Liberty Group posted to leak siteransomware_live · 2026-08-24
- [Dark Project] Jones, Little & Co., CPAs, LLP posted to leak siteransomware_live · 2026-08-24
- Operationalize CTEM with NodeZero®horizon3 · 2026-08-24
- [Dark Project] Design-Aire Engineering, INC posted to leak siteransomware_live · 2026-08-24
- [Dark Project] Furnished Quarters posted to leak siteransomware_live · 2026-08-24
- CVE-2026-78329: Apache Camel: Camel-Undertow: the endpoint discarded the undertow-specific header filter strategy in favour of the base HTTP one, so the undertow filtering never ran on endpoint-configured routesoss_sec · 2026-08-24
- CVE-2026-71300: Apache Camel: Camel-Atmosphere-Websocket: WebSocket dispatch header injectionoss_sec · 2026-08-24
- CVE-2026-66908: Apache Camel: Camel-platform-http-main: when JWT authentication was configured with a keystore but no issuer or audience, the iss and aud claims were never validated, so any unexpired token signed by a trusted key was acceptedoss_sec · 2026-08-24
- CVE-2026-66907: Apache Camel: Camel-Google-Storage: the consumer appended the remote object name to the configured downloadFileName directory without constraining the resultoss_sec · 2026-08-24
- CVE-2026-66906: Apache Camel: Camel-Azure-Storage-Blob: the downloadBlobToFile operation built the local download target from the remote blob name without constraining it to the configured fileDiross_sec · 2026-08-24
- Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoningthehackernews · 2026-08-24
- CVE-2026-63621: Apache Camel: Camel-Knative: CloudEvent extension fields received in structured content mode were mapped onto message headers without applying any header filter strategyoss_sec · 2026-08-24
- CVE-2026-60093: Apache Camel: Camel-Azure-Storage-DataLake: the downloadToFile operation built the local download target from the remote path name without constraining it to the configured fileDiross_sec · 2026-08-24
- CVE-2026-59230: Apache Camel: Camel-Mail: the MimeMultipart data format copied MIME headers onto the Camel message without a header filter strategy when unmarshalling with headersInline enabledoss_sec · 2026-08-24
- Sensitive Data Discovery: Tools, Best Practices & How It Worksorca_security · 2026-08-24
- [NVD] CVE-2026-77915 (CRITICAL 9.8) — rConfig Core 8.0.0 before 8.2.10 contains an authentication bypass vulnerability that allows unauthenticated attackers to self-register accounts with full Administrator privileges due to a duplicate bare Auth::routes() call in routes/web.php that re-enables the POST /register rounvd · 2026-08-24
- AI Data Classification: Methods, Tools & Best Practicesorca_security · 2026-08-24
- CVE-2026-75099: Apache Allura: Unauthenticated REST disclosureoss_sec · 2026-08-24
- Fake GTA 6 Extended Look and demo sites deliver an infostealermalwarebytes_blog · 2026-08-24
- How Deception Helps Amex Global Business Travel Trap Autonomous AI Attackszscaler_threatlabz · 2026-08-24
- [dragonforce] Frato posted to leak siteransomware_live · 2026-08-24
- [dragonforce] Criba posted to leak siteransomware_live · 2026-08-24
- CVE-2026-78331 / CVE-2026-78332: Multiple Vulnerabilities in NethServeross_sec · 2026-08-24
- [dragonforce] Brookview Financial posted to leak siteransomware_live · 2026-08-24
- [dragonforce] Wozair posted to leak siteransomware_live · 2026-08-24
- No Contradiction Here: Frontier AI Requires More Digital Sovereignty, Not Lesszscaler_threatlabz · 2026-08-24
- [akira] Bihl posted to leak siteransomware_live · 2026-08-24
- [Booba Project] Davroc posted to leak siteransomware_live · 2026-08-24
- Fake Microsoft security scans trick victims into uninstalling their antivirusmalwarebytes_blog · 2026-08-24
- [Booba Project] Chernyy & Associates posted to leak siteransomware_live · 2026-08-24
- What happens to your data when you die? (Lock and Code S07E17)malwarebytes_blog · 2026-08-24
- ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and Morethehackernews · 2026-08-24
- BengalSEO Part 1: Anatomy of the Operationdfirreport · 2026-08-24
- [arcusmedia] ManagementPro posted to leak siteransomware_live · 2026-08-24
- [arcusmedia] Mark’Techno posted to leak siteransomware_live · 2026-08-24
- [Panzer] Government of Vojvodina posted to leak siteransomware_live · 2026-08-24
- AliExpress caught using silent audio to fingerprint visitors’ browsersmalwarebytes_blog · 2026-08-24