THREAT OPS › Threat News
Threat Intelligence News
11702 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- AliExpress caught using silent audio to fingerprint visitors’ browsersmalwarebytes_blog · 2026-08-24
- 24th August – Threat Intelligence Reportcheckpoint_research · 2026-08-24
- [qilin] Coldfish Seafood posted to leak siteransomware_live · 2026-08-24
- [blackwater] www.ptesm.com posted to leak siteransomware_live · 2026-08-24
- ToxicPanda 2.0 can take over your Android phone and banking appsmalwarebytes_blog · 2026-08-24
- [Booba Project] Federis Abogados posted to leak siteransomware_live · 2026-08-24
- Dell security advisory (AV26-843)cccs_ca · 2026-08-24
- WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwordsthehackernews · 2026-08-24
- [Panzer] Senvibe posted to leak siteransomware_live · 2026-08-24
- CISA Adds One Known Exploited Vulnerability to Catalogcisa_advisories · 2026-08-24
- Shipping More AI Code Than You Can Secure? Watch How to Control Remediation Debtthehackernews · 2026-08-24
- Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Accountthehackernews · 2026-08-24
- Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoorthehackernews · 2026-08-24
- Tracking PavinLoader across ClickFix and fake download campaignsmalwarebytes_blog · 2026-08-24
- The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Riskthehackernews · 2026-08-24
- [qilin] A&E + SMA Design posted to leak siteransomware_live · 2026-08-24
- Exposing AnonyMousKIT: AI-Powered PhaaS Supply Chainsocradar_blog · 2026-08-24
- Criminal Deception in Silicon Valleyschneier · 2026-08-24
- [NVD] CVE-2026-66897 (CRITICAL 9.9) — A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root. When processing target template paths specified in metadata.yamnvd · 2026-08-24
- Imobiliare.ro, Klark.ai, Fortinet VPN, E-Commerce Skimming, and Solimut SQLisocradar_blog · 2026-08-24
- Cisco Crosswork, Secure Workload CVEs Patchedsocradar_blog · 2026-08-24
- UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkitthehackernews · 2026-08-24
- CVE-2026-19478: GitLab GraphQL Flaw Exploitedsocradar_blog · 2026-08-24
- A week in security (August 17 – August 23)malwarebytes_blog · 2026-08-24
- ShinyHunters Claims ReliaQuest Breachsocradar_blog · 2026-08-24
- Re: Re: Emacs zero-click local command execution via TRAMPoss_sec · 2026-08-24
- BusyBox dpkg applet: OS command injectionoss_sec · 2026-08-24
- ZDI-26-588: Fabric.js loadFromJSON Server-Side Request Forgery Vulnerabilityzdi_published · 2026-08-24
- ZDI-26-587: Ashlar-Vellum Cobalt VS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerabilityzdi_published · 2026-08-24
- ZDI-26-586: OriginLab Origin Viewer OGM File Parsing Memory Corruption Remote Code Execution Vulnerabilityzdi_published · 2026-08-24
- ZDI-26-585: OriginLab Origin Viewer OGWU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerabilityzdi_published · 2026-08-24
- ZDI-26-610: Apple Safari JavaScriptCore B3 ReduceStrength Phase Use-After-Free Remote Code Execution Vulnerabilityzdi_published · 2026-08-24
- ZDI-26-606: Microsoft Windows Compatibility Appraiser Link Following Local Privilege Escalation Vulnerabilityzdi_published · 2026-08-24
- ZDI-26-605: Microsoft Windows Localized Filenames Improper Input Validation NTLM Response Information Disclosure Vulnerabilityzdi_published · 2026-08-24
- ZDI-26-604: Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerabilityzdi_published · 2026-08-24
- ZDI-26-603: Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerabilityzdi_published · 2026-08-24
- ZDI-26-602: Foxit PDF Reader Doc Object Use-After-Free Remote Code Execution Vulnerabilityzdi_published · 2026-08-24
- ZDI-26-601: Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerabilityzdi_published · 2026-08-24
- ZDI-26-600: Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerabilityzdi_published · 2026-08-24
- ZDI-26-599: Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerabilityzdi_published · 2026-08-24
- ZDI-26-598: Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerabilityzdi_published · 2026-08-24
- ZDI-26-597: Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerabilityzdi_published · 2026-08-24
- ZDI-26-596: Foxit PDF Reader PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerabilityzdi_published · 2026-08-24
- ZDI-26-595: Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerabilityzdi_published · 2026-08-24
- ZDI-26-594: NVIDIA Megatron Bridge load_model_config Code Injection Remote Code Execution Vulnerabilityzdi_published · 2026-08-24
- ZDI-26-593: NVIDIA TensorRT ONNX File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerabilityzdi_published · 2026-08-24
- ZDI-26-592: NVIDIA TensorRT ONNX File Parsing Improper Validation of Array Index Remote Code Execution Vulnerabilityzdi_published · 2026-08-24
- ZDI-26-591: NVIDIA TensorRT ONNX File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerabilityzdi_published · 2026-08-24
- ZDI-26-589: BlueZ A2DP Stack-based Buffer Overflow Remote Code Execution Vulnerabilityzdi_published · 2026-08-24
- [Storm] Sharp Motor Group posted to leak siteransomware_live · 2026-08-24
- [Storm] City of Mitchell posted to leak siteransomware_live · 2026-08-24
- Re: Vulnerability in Kata Containers runtimes (both rust and go) (CVE-2026-50540)oss_sec · 2026-08-24
- Risky Bulletin: Expired credit cards can be used for malicious transactionsriskybiz_news · 2026-08-24
- Zimbra Multiple Vulnerabilitieshkcert · 2026-08-24
- [NVD] CVE-2026-78209 (HIGH 8.2) — exceljs through 4.4.0 fails to neutralize leading equals, plus, minus, or at signs in cell values written to CSV output. Attackers who can influence exported cell values can inject formulas that execute when the CSV file is opened in a spreadsheet application, potentially exfiltrnvd · 2026-08-24
- [NVD] CVE-2026-78208 (HIGH 7.5) — exceljs through 4.4.0 contains a path traversal vulnerability in the Workbook.addImage() function that fails to validate file paths. Attackers can supply arbitrary file paths to read any file accessible to the Node.js process and embed it in the generated workbook.nvd · 2026-08-24
- [NVD] CVE-2026-78207 (CRITICAL 9.4) — exceljs through 4.4.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject __proto__, constructor, or prototype keys when merging note objects. Attackers can assign parsed JSON with a malicious __proto__ property to cell notes, modifying Objecnvd · 2026-08-24
- [NVD] CVE-2026-78206 (HIGH 7.5) — exceljs through 4.4.0 decompresses all entries from supplied xlsx archives into memory without limits on entry size, total size, or compression ratio. Attackers can upload highly compressed workbooks that expand to gigabytes in memory, exhausting available resources and causing dnvd · 2026-08-24
- Microsoft Edge Multiple Vulnerabilitieshkcert · 2026-08-24
- [krybit] resi.com posted to leak siteransomware_live · 2026-08-24
- How a team of entity maintainers monitors, connects and scores entities in Elastic Securityelastic_security · 2026-08-24
- [CISA KEV] CVE-2026-21962 — Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in: Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerabilitycisa_kev · 2026-08-24
- [coinbasecartel] Westwing Group SE posted to leak siteransomware_live · 2026-08-23
- [shinyhunters] CyrusOne, LLC. posted to leak siteransomware_live · 2026-08-23
- CVE-2026-78183: DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_floatoss_sec · 2026-08-23
- Sponsored: Passkeys won’t stop authorisation phishingriskybiz_news · 2026-08-23
- CVE-2026-19565: Apache::AppSamurai::Util versions through 1.01 for Perl generate predictable session authentication keys from the clock and process id in CreateSessionAuthKeyoss_sec · 2026-08-23
- [qilin] S.E.M.P. s.r.l. posted to leak siteransomware_live · 2026-08-23
- CVE-2026-75922: Reverse::Proxy versions before 0.04 for Perl allow HTTP request smuggling via a percent-decoded PATH_INFO written unencoded to the upstream request lineoss_sec · 2026-08-23
- [lockbit5] adt.com posted to leak siteransomware_live · 2026-08-23
- Update: base64dump.py Version 0.0.31didier_stevens · 2026-08-23
- CVE-2026-41992 gzip 1.14 out-of-bounds memory buffer accessoss_sec · 2026-08-23
- [killsec] Global Go posted to leak siteransomware_live · 2026-08-23
- [qilin] Euroflora srl posted to leak siteransomware_live · 2026-08-23
- [qilin] Tecnici Associati STP posted to leak siteransomware_live · 2026-08-23
- [qilin] Studio BOLDRIN PAOLO posted to leak siteransomware_live · 2026-08-23
- July 2026 Threat Trend Report on Ransomwareahnlab · 2026-08-23
- [qilin] Aurore Development S.p.A. posted to leak siteransomware_live · 2026-08-23
- [NVD] CVE-2026-77088 (MEDIUM 6.1) — justhtml versions 0.9.0 through 1.21.0 contain a cross-site scripting vulnerability in to_markdown() where inline code spans fail to account for blank lines as block boundaries. Attackers can inject blank lines into code or pre element text to break the inline span, causing sanitnvd · 2026-08-23
- [NVD] CVE-2026-6827 (MEDIUM 6.1) — justhtml before 1.17.0 contains multiple security issues in sanitization, serialization, and programmatic DOM handling. When custom policies preserve foreign namespaces (SVG/MathML), dangerous content such as HTML integration points (SVG <foreignObject>, MathML <annotation-xml ennvd · 2026-08-23
- [L Group] compendiumusa.net posted to leak siteransomware_live · 2026-08-23
- [qilin] Clear Align posted to leak siteransomware_live · 2026-08-23
- [qilin] Difor posted to leak siteransomware_live · 2026-08-23
- [qilin] Black Cat Engineering & Construction WLL posted to leak siteransomware_live · 2026-08-23
- [emperador] FRUCASTRO SL posted to leak siteransomware_live · 2026-08-23
- [kazu] PappyJoe: Healthcare Management System posted to leak siteransomware_live · 2026-08-23
- [kazu] Instituto Ferrero de Neurología y Sueño posted to leak siteransomware_live · 2026-08-23
- [kazu] Brazil Mobilemed: Cloud PACS Platform posted to leak siteransomware_live · 2026-08-23
- [kazu] Canada Yocale: Appointment Management System posted to leak siteransomware_live · 2026-08-23
- [kazu] PawlyClinic: Digital Veterinary Care Platform posted to leak siteransomware_live · 2026-08-23
- [kazu] Dr Akbar Niazi Teaching Hospital posted to leak siteransomware_live · 2026-08-23
- [kazu] Centro Médico Especializado OSI: Healthcare Solutions posted to leak siteransomware_live · 2026-08-23
- [kazu] Meducar: Telemedicine and Patient Management System posted to leak siteransomware_live · 2026-08-23
- [kazu] ConsultorioMovil: Telemedicine and Healthcare System posted to leak siteransomware_live · 2026-08-23
- [metaencryptor] Woodlore International Inc. posted to leak siteransomware_live · 2026-08-23
- [metaencryptor] Trailer Transit Inc posted to leak siteransomware_live · 2026-08-23
- [metaencryptor] Weber Water Resources posted to leak siteransomware_live · 2026-08-23
- [metaencryptor] MPA Pharma GmbH posted to leak siteransomware_live · 2026-08-23
- [metaencryptor] Aquamar Inc posted to leak siteransomware_live · 2026-08-23
- [metaencryptor] Corona Corporation posted to leak siteransomware_live · 2026-08-23