THREAT OPS › Threat News
Threat Intelligence News
11790 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [akira] Javep Chevrolet posted to leak siteransomware_live · 2026-09-17
- [metaencryptor] Beckman Coulter, Inc posted to leak siteransomware_live · 2026-09-17
- [metaencryptor] AECOM posted to leak siteransomware_live · 2026-09-17
- [metaencryptor] Promantra, Inc posted to leak siteransomware_live · 2026-09-17
- The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrentssecurelist · 2026-09-17
- CVE-2026-76460: Cisco ISE Flaw Actively Exploitedsocradar_blog · 2026-09-17
- Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zonethehackernews · 2026-09-17
- [NVD] CVE-2026-92917 (HIGH 7.5) — Grav is a flat-file CMS. In versions 2.0.0-rc.1 through 2.0.21, the Twig content sandbox fails to restrict the dump and serialize filters (print_r, vardump, json_encode, yaml_encode, string): GravExtension::assertSandboxDumpSafe() determines sandbox state by calling SandboxExtensnvd · 2026-09-17
- [NVD] CVE-2026-92912 (MEDIUM 6.5) — AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 uses cryptographically weak uniqid() values for RTMP publish keys in LiveTransmition, reducing key entropy to approximately one million possibilities per creation second. Attackers who know the channel creation time can brutnvd · 2026-09-17
- [NVD] CVE-2026-92860 (CRITICAL 9.1) — A security flaw has been discovered in rcourtman Pulse up to 6.0.4/6.1.0-rc.4. Affected by this issue is the function fmt.Sprintf of the file /api/security/quick-setup of the component Quick Security Setup Handler. The manipulation of the argument Username results in improper inpnvd · 2026-09-17
- Schneider Electric PowerChute Serial Shutdowncisa_ics · 2026-09-17
- ABB Ability Edgeniuscisa_ics · 2026-09-17
- Schneider Electric NetBotz 5 750/755cisa_ics · 2026-09-17
- Schneider Electric Modicon M340 Controller and Communication Modulescisa_ics · 2026-09-17
- Hitachi Energy FACTS Control Platform (FCP)cisa_ics · 2026-09-17
- Mitsubishi Electric GX Works3 and Motion Control Settingscisa_ics · 2026-09-17
- Bransys ELDcisa_ics · 2026-09-17
- Mitsubishi Electric GX Works3 and Motion Control Settingscisa_advisories · 2026-09-17
- Hitachi Energy FACTS Control Platform (FCP)cisa_advisories · 2026-09-17
- Bransys ELDcisa_advisories · 2026-09-17
- Schneider Electric NetBotz 5 750/755cisa_advisories · 2026-09-17
- Schneider Electric Modicon M340 Controller and Communication Modulescisa_advisories · 2026-09-17
- Schneider Electric PowerChute Serial Shutdowncisa_advisories · 2026-09-17
- ABB Ability Edgeniuscisa_advisories · 2026-09-17
- Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinarthehackernews · 2026-09-17
- 12 celebrity deepfake websites seized by Manhattan DAmalwarebytes_blog · 2026-09-17
- How Candidates Could Use AI for Goodschneier · 2026-09-17
- CISO's Expert Guide to Agentic Pentesting for Websitesthehackernews · 2026-09-17
- T-Mobile rewards points expiry texts are a phishing scammalwarebytes_blog · 2026-09-17
- China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin Americathehackernews · 2026-09-17
- Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI usetalos · 2026-09-17
- New SparroWocky Backdoor Targets Latin Americaduo_decipher · 2026-09-17
- Why APAC Enterprises Need Real-Time Threat Intelligence as Singapore, Malaysia, and Thailand Tighten Cyber Compliance in 2026cyble · 2026-09-17
- OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized Uploadsthehackernews · 2026-09-17
- [Vexy Ransomware] STP Fashion Lab posted to leak siteransomware_live · 2026-09-17
- [emperador] Westbridge Institute of Technology, Inc. posted to leak siteransomware_live · 2026-09-17
- HEAVYGRAM: A Telegram-based Surveillance Backdoor Linked to Handala Hackgroupib_blog · 2026-09-17
- BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPSthehackernews · 2026-09-17
- Manage SOCRadar Alerts Where Your Team Already Works with SOCRadar and Zendesksocradar_blog · 2026-09-17
- Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Recordsthehackernews · 2026-09-17
- [incransom] www.appliancefactory.com posted to leak siteransomware_live · 2026-09-17
- [incransom] www.diarco.com.ar posted to leak siteransomware_live · 2026-09-17
- Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacksthehackernews · 2026-09-17
- [NVD] CVE-2026-87935 (HIGH 8.1) — The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.15 via the admin_request_handler function. This is due to missing authorization and file type validation in the admin_request_handler function, which is reachablnvd · 2026-09-17
- [NVD] CVE-2026-87796 (CRITICAL 9.8) — The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function. This is due to insufficient file type validation during chunked upload handling. This makes it possible for unanvd · 2026-09-17
- U.S. Seizes NightmareStresser Domains Linked to Hundreds of Thousands of DDoS Attacksthehackernews · 2026-09-17
- ZDI-26-714: Samsung rlottie Stack-based Buffer Overflow Remote Code Execution Vulnerabilityzdi_published · 2026-09-17
- Re: Retrospective by 'gpg.fail' authorsoss_sec · 2026-09-17
- Mozilla Products Multiple Vulnerabilitieshkcert · 2026-09-17
- Cisco Products Multiple Vulnerabilitieshkcert · 2026-09-17
- [shinyhunters] Qi**** posted to leak siteransomware_live · 2026-09-17
- US, UK Agencies Detail Iranian Malware Campaign Targeting Dissidentsduo_decipher · 2026-09-17
- Our View on What It Takes To Be Named an Industry-Recognized Threat Intelligence Leaderrecordedfuture · 2026-09-17
- The New Rules of Machine Speed Defenserecordedfuture · 2026-09-17
- [NVD] CVE-2026-61588 (MEDIUM 6.5) — djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, when a Django `Model` instance is assigned to a public view attribute, djust serialized it to the client with no sensitive-field denylist — sendinvd · 2026-09-16
- CVE-2026-91752: GNU libextractor < 1.15 Stack Overflow via OLE2oss_sec · 2026-09-16
- [NVD] CVE-2026-92595 (MEDIUM 5.9) — Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do not honor the `disableFileAccess` and `disableUrlAccess` sandbox options when message content is resolved through the public plugin API `MailMessage.resolveContent()` using the documented legacy three-argument sinvd · 2026-09-16
- [NVD] CVE-2026-92590 (MEDIUM 5.4) — Craft CMS versions from 5.7.0 before 5.10.13 contain a stored cross-site scripting vulnerability in the Generated Fields feature that disables Twig autoescaping and fails to encode cached values. Content editors can inject malicious JavaScript through editable fields that executenvd · 2026-09-16
- [NVD] CVE-2026-92589 (MEDIUM 4.3) — Craft CMS 5.0.0 through 5.10.12 (fixed in 5.10.13) contains a broken access control flaw in the nested-elements reorder endpoint. When an authenticated control panel user with viewEntries and viewPeerEntries (but without savePeerEntries) opens another author's entry in read-only nvd · 2026-09-16
- [NVD] CVE-2026-92585 (MEDIUM 4.3) — AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to validate video access permissions in the API like endpoint, allowing logged-in users to vote on password-protected and group-restricted videos. Attackers can submit like and dislike requests to incremenvd · 2026-09-16
- [NVD] CVE-2026-92580 (HIGH 8.8) — In AVideo through 29.0, the CloneSite plugin is vulnerable to stored OS command injection. In plugin/CloneSite/cloneClient.json.php (line ~270) the stored SSH password is substituted into the command string `sshpass -p '{password}' rsync ...` with a plain str_replace and no escapnvd · 2026-09-16
- [NVD] CVE-2026-92579 (MEDIUM 5.4) — In AVideo through 29.0, the autoCSRFGuard() function maintains a hardcoded allowlist of exempt basenames tested without directory context, allowing plugin files matching core filenames to inherit CSRF exemptions. The LoginWordPress plugin file login.json.php inherits an exemptionnvd · 2026-09-16
- [NVD] CVE-2026-89034 (MEDIUM 6.5) — TCH QRing smart ring model R20_B006 running firmware RT09R20_1.00.00_250318 contains an unauthenticated Bluetooth Low Energy access vulnerability that allows any nearby attacker to connect to the device without pairing, authentication, or user approval by exploiting the exposed Nnvd · 2026-09-16
- [NVD] CVE-2026-64684 (MEDIUM 6.8) — RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.1.0, the rmcp crate's StreamableHttpClientTransport in crates/rmcp/src/transport/common/reqwest/streamable_http_client.rs builds its default_http_client with reqwest's automatic redirect policy and applies canvd · 2026-09-16
- [GHSA] GHSA-g3pg-frfm-pr2m (medium) — OpenFGA: ListUsers returns a deliberately-excluded user when a `but not` exclusion under a type-bound wildcard is intersected (`and`) with another relation that also grants that usergithub_advisories · 2026-09-16
- [GHSA] GHSA-ffmg-hfvg-jhg9 (medium) — Grav: Stored CSS injection via Markdown image resize() bypasses prior media style sanitizers in Gravgithub_advisories · 2026-09-16
- [GHSA] GHSA-mxm6-v9r6-r94c (high) — @nuxtjs/mdc's URL sanitizer misses SVG xlink:href and data:text/html, allowing XSS from untrusted markdown at the default configurationgithub_advisories · 2026-09-16
- [GHSA] GHSA-9pj6-vhgr-3mwh (high) — RMCP: Unauthenticated permanent session-table leak in rmcp Streamable HTTP server transport leads to remote denial-of-servicegithub_advisories · 2026-09-16
- [GHSA] GHSA-33f5-2c5q-wgwj (high) — RMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata Discoverygithub_advisories · 2026-09-16
- [GHSA] GHSA-2c4f-86xc-cr74 (medium) — Grav: XSS Blueprint Validation Bypass via Twig String Concatenationgithub_advisories · 2026-09-16
- [GHSA] GHSA-hcwq-8wjf-3gcr (medium) — vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completionsgithub_advisories · 2026-09-16
- [GHSA] GHSA-2vcx-h8p2-9pg9 (medium) — Grav CMS — Improper Handling of Highly Compressed Data in Installer::unZip()github_advisories · 2026-09-16
- [GHSA] GHSA-7prp-2623-8g45 (high) — djust has an unauthenticated arbitrary module import via the WebSocket/SSE view-mount pathgithub_advisories · 2026-09-16
- [GHSA] GHSA-v9rj-xjfv-xj9r (medium) — djust: WebSocket/runtime reconstructed request omits the client Host, causing host/subdomain TenantResolvers to misresolve the tenant on the live pathgithub_advisories · 2026-09-16
- [GHSA] GHSA-c7c5-5j6r-q957 (high) — djust has broken object-level access control (IDOR)github_advisories · 2026-09-16
- [GHSA] GHSA-pvg3-6q9j-mj3x (medium) — djust's Django model serialization has no sensitive-field denylist: password hashes, privilege flags, and PII on a public view attribute are sent to the clientgithub_advisories · 2026-09-16
- [GHSA] GHSA-xhhm-f6hp-2qwj (critical) — djust has an authorization bypass on the WebSocket/SSE mount pathgithub_advisories · 2026-09-16
- [GHSA] GHSA-c67v-vqrp-m5wj (high) — djust: Unsigned client state snapshot is restored as trusted view state (privilege escalation / state injection)github_advisories · 2026-09-16
- [GHSA] GHSA-f795-p5jw-j6g2 (high) — djust: SSE sessions are not bound to the authenticated user; the client-chosen session_id is the sole authorization capability (session hijack)github_advisories · 2026-09-16
- [ShadowByt3$] HandyTrac Greystar AZ WARNING posted to leak siteransomware_live · 2026-09-16
- [GHSA] GHSA-4mf4-73j6-mvrw (medium) — djust is vulnerable to stored/reflected XSS via javascript: URLs in built-in component template tagsgithub_advisories · 2026-09-16
- [NVD] CVE-2026-92812 (MEDIUM 6.8) — decap-server contains a path traversal vulnerability in the local proxy containment guard that uses plain string prefix comparison without path separator validation. Attackers can access sibling directories whose names begin with the repository directory name to read, write, or dnvd · 2026-09-16
- [NVD] CVE-2026-92805 (CRITICAL 9.8) — UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in ConfigureHelpdesk controller actions. Unauthenticated attackers can repoint the database and create super administrator accounts by submitting crafted requests to wnvd · 2026-09-16
- [NVD] CVE-2026-92800 (MEDIUM 6.8) — Docs before 5.4.1 fails to properly revoke websocket collaboration connections when access is revoked at parent documents. Attackers with revoked access can retain real-time read and write access to sub-documents through open websocket sessions that are never disconnected.nvd · 2026-09-16
- [NVD] CVE-2026-92792 (HIGH 7.5) — OpenNHP through 1.0.2 selects its trusted-execution attestation verifier based on attacker-supplied evidence containing a test_purpose key, causing the FallbackVerifier to execute unconditionally. Attackers can bypass attestation verification by including the test_purpose key in nvd · 2026-09-16
- [NVD] CVE-2026-92787 (CRITICAL 9.8) — Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypass all role-based access control by presenting an unverified token with a hardcoded claim value. Attackers can obtain trusted internal identity and gain uncheckenvd · 2026-09-16
- [NVD] CVE-2026-92782 (HIGH 8.1) — Chroma through 1.5.9 fails to validate tenant and database segments when resolving collections, allowing authenticated attackers to access collections from other tenants by knowing the collection identifier. Attackers can read, modify, and update records in foreign collections bynvd · 2026-09-16
- [NVD] CVE-2026-76451 (MEDIUM 4.9) — A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct an SQL or HQL injection attack on an affected device. This vulnerability is due to insufficient validation of usenvd · 2026-09-16
- [NVD] CVE-2026-76444 (MEDIUM 5.3) — A vulnerability in an internal service of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to retrieve sensitive configuration information from an affected device. This vulnerability is due to missing authentication on the Policy Runtime Repository Tnvd · 2026-09-16
- [NVD] CVE-2026-76432 (MEDIUM 4.9) — A vulnerability in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker with administrative-level privileges to write arbitrary files on an affected device. This vulnerability exists because the affected software does nvd · 2026-09-16
- [NVD] CVE-2026-76431 (MEDIUM 4.9) — A vulnerability in the file management function of the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to delete arbitrary files and directories on an affected device. To exploit this vulnerability, the attacker must havnvd · 2026-09-16
- [NVD] CVE-2026-75513 (CRITICAL 9.1) — Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. From version 7.0.0 until 9.13.0, several Marten LINQ and tenant-management paths interpolate runtime, potentially attacker-controlled strings into single-quoted SQL literals without escaping or parameterizanvd · 2026-09-16
- [NVD] CVE-2026-20072 (MEDIUM 4.9) — A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to obtain sensitive information from network users that are outside the security group that the attacker is assigned to. This vulnerability exists because cenvd · 2026-09-16
- [emperador] RDA MOTORS S.P.A. posted to leak siteransomware_live · 2026-09-16
- The Apple Security Update Review for September 2026zdi_blog · 2026-09-16
- [blacknevas] Optimum First Mortgage (Pear's acting group's promotional blog) posted to leak siteransomware_live · 2026-09-16
- ISC BIND security advisory (AV26-931)cccs_ca · 2026-09-16
- Apple security advisory (AV26-930)cccs_ca · 2026-09-16
- Oracle Corporation security advisory (AV26-929)cccs_ca · 2026-09-16
- [emperador] SEVENOAKS s.r.o. posted to leak siteransomware_live · 2026-09-16