THREAT OPS › Threat News
Threat Intelligence News
11708 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [metaencryptor] MPA Pharma GmbH posted to leak siteransomware_live · 2026-08-23
- [metaencryptor] Aquamar Inc posted to leak siteransomware_live · 2026-08-23
- [metaencryptor] Corona Corporation posted to leak siteransomware_live · 2026-08-23
- [metaencryptor] FactoryFive posted to leak siteransomware_live · 2026-08-23
- [Barracuda] Skyline Implants & Periodontics posted to leak siteransomware_live · 2026-08-23
- [Barracuda] Namyang Industrial Co., Ltd. posted to leak siteransomware_live · 2026-08-23
- [Barracuda] Clinical Associates of the Finger Lakes (CAFL) posted to leak siteransomware_live · 2026-08-23
- [majinahanashi] PCA ***** posted to leak siteransomware_live · 2026-08-23
- [Storm] AutoDie posted to leak siteransomware_live · 2026-08-23
- [Storm] Pinnacle Hospital posted to leak siteransomware_live · 2026-08-23
- [Storm] Phoenix Group of Companies posted to leak siteransomware_live · 2026-08-23
- [Storm] Schardein Mechanical posted to leak siteransomware_live · 2026-08-23
- [Storm] The Cecilian Bank posted to leak siteransomware_live · 2026-08-23
- [Eclipse] Crystal Pharmatech posted to leak siteransomware_live · 2026-08-23
- [thegentlemen] AGS Cinemas posted to leak siteransomware_live · 2026-08-23
- [thegentlemen] Eyecare Center of Snohomish posted to leak siteransomware_live · 2026-08-23
- [thegentlemen] Gould Sherwood Consulting posted to leak siteransomware_live · 2026-08-23
- [thegentlemen] Espac posted to leak siteransomware_live · 2026-08-23
- [thegentlemen] Layher posted to leak siteransomware_live · 2026-08-23
- [thegentlemen] Volktek posted to leak siteransomware_live · 2026-08-23
- [shinyhunters] ReliaQuest, LLC posted to leak siteransomware_live · 2026-08-23
- [incransom] el-group posted to leak siteransomware_live · 2026-08-22
- [Helix] AmSpec posted to leak siteransomware_live · 2026-08-22
- [NotCVE-2026-0013] CHIRP Kenwood ITM Driver Eval Injection Allows Arbitrary Code Execution via Crafted Radio Fileoss_sec · 2026-08-22
- [emperador] Vietnam Electricity(EVNHANOI) posted to leak siteransomware_live · 2026-08-22
- [NVD] CVE-2026-76571 — Joomla Extension - fabrikar.com - Unauthenticated SQL injection in list filter condition parameter in Fabrik < 4.7.3 - The condition parameter passed to a list filter is concatenated verbatim into the WHERE clause built by getFilterQuery(). An unauthenticated attacker can supply nvd · 2026-08-22
- [NVD] CVE-2026-74584 — In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: zero shared page before exposing to userspace bnxt_re_alloc_ucontext() allocates uctx->shpg via __get_free_page(GFP_KERNEL). The buddy allocator does not zero pages without __GFP_ZERO, so the pagenvd · 2026-08-22
- [NVD] CVE-2026-70626 (MEDIUM 6.2) — NLTK versions before 3.9.4 contain a symlink escape vulnerability in CorpusReader.open() that allows local attackers to read arbitrary files outside the corpus root. The vulnerability exists because path validation is lexical and does not account for symlink resolution, enabling nvd · 2026-08-22
- [NVD] CVE-2026-68768 (MEDIUM 6.1) — hashcat contains a heap-based buffer overflow (out-of-bounds write) in the outfile_write() function in src/outfile.c. When assembling output into a fixed-size buffer (HCBUFSIZ_LARGE, ~16 MB), the function sequentially appends the username, separator, hash, and plaintext via memcpnvd · 2026-08-22
- [NVD] CVE-2026-68767 (MEDIUM 6.1) — hashcat's fgetl() function in src/filehandling.c writes a null terminator one byte past the caller's buffer when an input line is exactly the buffer length. Attackers can trigger this out-of-bounds heap write by providing a hash file, potfile, or wordlist containing a line of exanvd · 2026-08-22
- [NVD] CVE-2026-68766 (HIGH 7.8) — hashcat fails to restrict command-line options when parsing restore files, allowing attackers to inject output-redirecting options like --outfile and --potfile-path. Attackers can craft restore files with malicious options to append attacker-controlled content to arbitrary files,nvd · 2026-08-22
- [NVD] CVE-2026-66393 (HIGH 7.5) — NLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONTaggedDecoder.decode_obj() that allows attackers to cause denial of service by supplying deeply nested JSON structures. Attackers can craft JSON payloads exceeding the recursion limit to trigger an unhnvd · 2026-08-22
- [NVD] CVE-2026-65915 (MEDIUM 6.5) — NLTK versions before 3.10.0 contain a logic bug in FileSystemPathPointer.open() where the sandbox validation check compares a normalized path against itself, making the security check permanently inert. Attackers can pass file:// URLs to nltk.data.load() to read arbitrary files anvd · 2026-08-22
- [NVD] CVE-2026-63312 (HIGH 7.5) — NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.ENFORCE by calling builtins.open() directly instead of pathsec.open(). Attackers who control the fileid argument can read arbitrary local files regardless of thenvd · 2026-08-22
- [NVD] CVE-2026-63311 (MEDIUM 5.3) — NLTK before 3.10.0 (affected versions <= 3.9.4) contains a server-side request forgery (SSRF) vulnerability in the validate_network_url() function in nltk/pathsec.py. The _resolve_hostname() helper catches OSError and ValueError during socket.getaddrinfo() and returns an empty linvd · 2026-08-22
- [NVD] CVE-2026-63310 (HIGH 7.1) — NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS poisoning to inject malicious package contents that are extracted without validation.nvd · 2026-08-22
- [NVD] CVE-2026-62388 (HIGH 7.5) — NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit warnings instead of raising exceptions. Attackers can bypass path traversal and pickle deserialization protections by exploiting the disabled security controls thnvd · 2026-08-22
- [NVD] CVE-2026-62385 (MEDIUM 5.9) — NLTK versions before 3.10.0 contain a path traversal vulnerability in FramenetCorpusReader and NKJPCorpusReader that allows attackers to parse XML files outside the corpus root by supplying unsafe selectors or poisoned index state. Attackers can exploit frame_by_name, doc, lu, annvd · 2026-08-22
- [NVD] CVE-2026-62384 (HIGH 7.5) — NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader that allows attackers to read arbitrary XML files outside the corpus root. Attackers can place symlinks with names containing no path separators inside the corpus subdirectory, which pass tnvd · 2026-08-22
- [NVD] CVE-2026-62383 (MEDIUM 5.5) — nltk versions before 3.10.2 contain a symlink-based arbitrary file read vulnerability in IPIPANCorpusReader methods that bypass nltk.pathsec validation entirely. Attackers can place a symlink in the corpus root directory and read arbitrary files accessible to the process by callinvd · 2026-08-22
- TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuitthehackernews · 2026-08-22
- [NVD] CVE-2026-75870 — Punk versions before 0.18 for Perl allow session cookie forgery via an empty default HMAC key when a session is declared without a secret. The session keyword freezes its options onto the application as given: it does not require a secret, warn, or refuse to start when one is abnvd · 2026-08-22
- [NVD] CVE-2026-75866 — Punk::OAuth2::Server versions through 0.03 for Perl issue access tokens outside a client's registered scopes and grant types because no authorization path reads them. Punk::OAuth2::Server::Store registers scopes and grant_types per client and documents both as client registrationvd · 2026-08-22
- [NVD] CVE-2026-71514 (LOW 2.5) — NLTK 3.9.4 through 3.10.2 contains a path traversal vulnerability in CrubadanCorpusReader. _load_lang_ngrams joins the corpus root with crubadan_code, the column-0 value read from the corpus table.txt mapping file, and opens the result with the builtin open() rather than the pathnvd · 2026-08-22
- [NVD] CVE-2026-71513 (HIGH 8.8) — NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pickle module string and not the global name, allowing attackers to resolve dotted names by attribute traversal to callables outside the allowlisted namespace. Attackernvd · 2026-08-22
- [NVD] CVE-2026-5093 (MEDIUM 4.3) — The GreenShift – Animation and Page Builder Blocks plugin for WordPress is vulnerable to unauthorized modification of data in versions up to, and including, 12.8.9. This is due to a missing capability check on the 'gspb_update_global_wp_settings' function that only verifies the 'nvd · 2026-08-22
- [NVD] CVE-2026-4561 (MEDIUM 6.4) — The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form response message post meta fields (e.g., 'text_subscribed', 'text_error') in all versions up to, and including, 4.12.0 due to insufficient input sanitization and outpnvd · 2026-08-22
- [NVD] CVE-2026-4559 (MEDIUM 6.4) — The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'delay' shortcode attribute in all versions up to, and including, 3.6.12 due to insufficient input sanitization and output escaping. This makes it possible for authenvd · 2026-08-22
- [NVD] CVE-2026-2996 (HIGH 7.5) — The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 1.6.21. This is due to a logic flaw in the 'validate_cart_data' function. This makes it possible for unauthenticated nvd · 2026-08-22
- [shinyhunters] NovoCure Limited posted to leak siteransomware_live · 2026-08-22
- [shinyhunters] BOK Financial posted to leak siteransomware_live · 2026-08-22
- [coinbasecartel] Integrated Health Systems posted to leak siteransomware_live · 2026-08-22
- [coinbasecartel] RXPE Group posted to leak siteransomware_live · 2026-08-22
- [coinbasecartel] Tower Insurance posted to leak siteransomware_live · 2026-08-22
- [coinbasecartel] Flecha Bus posted to leak siteransomware_live · 2026-08-22
- [coinbasecartel] OTEIS Conseil & Ingénierie posted to leak siteransomware_live · 2026-08-22
- [coinbasecartel] Longhorn Investments posted to leak siteransomware_live · 2026-08-22
- [coinbasecartel] Kessler Creative posted to leak siteransomware_live · 2026-08-22
- [coinbasecartel] Klasko Immigration Law Partners posted to leak siteransomware_live · 2026-08-22
- [coinbasecartel] Patel posted to leak siteransomware_live · 2026-08-22
- [coinbasecartel] Abacus Advisors posted to leak siteransomware_live · 2026-08-22
- [coinbasecartel] LifeBank Microfinance Foundation posted to leak siteransomware_live · 2026-08-22
- [coinbasecartel] PT Perusahaan Jamu Air Mancur posted to leak siteransomware_live · 2026-08-22
- [coinbasecartel] PT. Bank Perekonomian Rakyat Bintan posted to leak siteransomware_live · 2026-08-22
- [NVD] CVE-2026-62382 — PasswordPusher versions v1.45.11 through v2.9.5 contain an improper authorization vulnerability in the push deletion logic. The ownership check compares @push.user against current_user; for an anonymously created push both values are nil, and Ruby evaluates nil == nil as true, sonvd · 2026-08-22
- [NVD] CVE-2026-62381 (MEDIUM 6.6) — luci-lib-px5g (LuCI) contains a heap-based buffer overflow in the native ASN.1 encoding routine asn1_add_obj (x509write.c) when signing a certificate with a 2040-bit RSA key. For a 255-byte signature, the BIT STRING allocation is computed from the DER length encoding of 255 bytesnvd · 2026-08-22
- [NVD] CVE-2026-62380 — Netty (io.netty:netty-codec-socks) versions 4.2.0.Final through 4.2.16.Final and 4.1.x through 4.1.136.Final contain null byte, CRLF, and credential injection vulnerabilities in the SOCKS4 (Socks4ClientEncoder) and SOCKS5 (Socks5ClientEncoder) client encoders, which fail to validnvd · 2026-08-22
- [NVD] CVE-2026-62243 (HIGH 7.5) — Netty (io.netty:netty-handler) versions from 4.2.0.Final through 4.2.16.Final and versions through 4.1.136.Final disable TLS hostname verification on the SslProvider.OPENSSL client path when a plain (non-extended) X509TrustManager is used and Unsafe-based trust-manager wrapping invd · 2026-08-22
- [NVD] CVE-2026-62204 (MEDIUM 6.6) — SiYuan versions before v3.7.4 fail to validate that packageName matches the downloaded package content in bazaar install endpoints. Attackers with same-origin access can overwrite existing trusted plugins by supplying mismatched packageName and repoURL parameters, achieving persinvd · 2026-08-22
- [NVD] CVE-2026-60084 (HIGH 8.7) — SiYuan versions before v3.7.4 contain an arbitrary file deletion vulnerability in the /api/search/removeTemplate endpoint that accepts an unvalidated path parameter passed directly to os.RemoveAll. Authenticated admin attackers can supply absolute filesystem paths to recursively nvd · 2026-08-22
- [NVD] CVE-2026-60083 (MEDIUM 4.9) — SiYuan versions before v3.8.0 contain an incomplete path blocklist in the MCP file tool that fails to restrict access to sensitive workspace files protected by the HTTP API. Authenticated administrators can read plaintext publish-mode passwords from data/.siyuan/publishAccess.jsonvd · 2026-08-22
- [NVD] CVE-2026-59809 (MEDIUM 4.9) — SiYuan before v3.8.0 interpolates secret placeholders into the destination URL parameter of the http_request MCP tool, allowing attackers to exfiltrate stored secrets. An MCP client can craft a request with an attacker-controlled URL containing secret placeholders to send plaintenvd · 2026-08-22
- [NVD] CVE-2026-59808 (HIGH 8.8) — AVideo through commit 9c39d8c8 contains an authentication bypass vulnerability where deduplicateByEncoderQueueId() returns video_id_hash credentials for any video by encoder_queue_id without ownership verification, and useVideoHashOrLogin() converts this hash into passwordless lonvd · 2026-08-22
- [NVD] CVE-2026-59256 (HIGH 7.5) — WWBN AVideo through commit 9c39d8c8 contains an authorization bypass vulnerability where getToken() creates tokens without binding to user identity or purpose, and plugin/Gallery/view/sections.php issues valid tokens to unauthenticated visitors. Attackers can retrieve a token fronvd · 2026-08-22
- [NVD] CVE-2026-58003 (HIGH 7.1) — WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the releaseVideoNow.json.php endpoint that lacks authenticity checks and accepts GET requests. Attackers can craft a malicious cross-site GET request carrying an administrator's session coonvd · 2026-08-22
- [NVD] CVE-2026-58002 (MEDIUM 6.5) — WWBN AVideo through commit 9c39d8c8b4c1f75540788d6b391740852ceb0732 contains an authorization bypass vulnerability in the Users_affiliations add.json.php endpoint that allows authenticated users to forge two-party consent records by supplying the counterparty's agreement timestamnvd · 2026-08-22
- [NVD] CVE-2026-58001 (MEDIUM 5.7) — WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in objects/videoEditLight.php that lacks request authenticity checks and accepts GET requests. Attackers can store an img tag in a video description that transfers video ownership to an attacknvd · 2026-08-22
- [NVD] CVE-2026-57998 (HIGH 7.8) — better-npm-audit through 3.11.0, and the 4.0.0-rc.2 prerelease, builds its npm audit command by interpolating the user-supplied --registry option into a command string in src/handlers/handleInput.ts without validation or quoting, then passes that string to child_process.exec() innvd · 2026-08-22
- [NVD] CVE-2026-57944 (MEDIUM 5.4) — AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in channelToGallery.json.php that allows attackers to modify site-wide Gallery configuration by performing unauthorized writes to plugin data. Attackers can craft a cross-site GET request carrying nvd · 2026-08-22
- [NVD] CVE-2026-56380 (MEDIUM 5.3) — AVideo through commit 9c39d8c8 contains an information exposure vulnerability in feed/index.php that allows unauthenticated attackers to retrieve channel owner email addresses by supplying a public channel name parameter. Attackers can enumerate all creator email addresses by itenvd · 2026-08-22
- [NVD] CVE-2026-4244 (MEDIUM 4.3) — The Post Duplicator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `duplicate_post()` function in all versions up to, and including, 3.0.11. This is due to the function not verifying that the user has `edit_others_nvd · 2026-08-22
- Named Pipes Under Attack: Securing Windows Interprocess Communicationbleepingcomputer · 2026-08-22
- [lockbit5] icnavais.com posted to leak siteransomware_live · 2026-08-22
- [NVD] CVE-2026-77988 (MEDIUM 6.6) — A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. This vulnerability affects the function nvram_get of the component CLI Configuration Tool. This manipulation causes command injection. The attack is possible to be carried out remotely. The exploit has been made avanvd · 2026-08-22
- [NVD] CVE-2026-66916 — Joomla Extension - joomgalleryfriends.net - Password-Protected Category Bypass via JSON Format in JoomGallery < 4.4.0- An unauthenticated access control bypass exists in JoomGallery's category JSON view. When a gallery category is protected with a password, the HTML view correctlnvd · 2026-08-22
- [NVD] CVE-2026-4245 (MEDIUM 4.3) — The Post Duplicator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.11. This is due to the `duplicate_post_permissions()` permission callback only verifying the `duplicate_posts` capability without checking whether the requestinvd · 2026-08-22
- [NVD] CVE-2026-3424 (MEDIUM 5.3) — The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.4.10.3. This is due to the software allowing users to execute an action that does not properly validate the 'panvd · 2026-08-22
- [NVD] CVE-2026-77946 (CRITICAL 10.0) — A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe_get of the file /cgi-bin/apply_time.cgi of the component NTP Timezone Configuration Handler. Executing a manipulation of the argument system.ntp.server/system.nvd · 2026-08-22
- [NVD] CVE-2026-77945 (HIGH 7.4) — A vulnerability was found in TRENDnet TEW-821DAP 2.2.01b05. Affected is an unknown function of the file /cgi-bin/upload.cgi of the component ssi. Performing a manipulation of the argument filename results in command injection. The attack may be initiated remotely. The exploit hasnvd · 2026-08-22
- [NVD] CVE-2026-78003 (CRITICAL 9.8) — The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This is due to insufficient input validation in the add_list() function, which accepts user-controlled array keys from $_POnvd · 2026-08-22
- [NVD] CVE-2026-12710 — A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud Application Integration (versions from 2025-04-28 to 2026-04-04) allows an external attacker to access sensitive internal data. The issue was patched on April 4, 2026; no customer action is required.nvd · 2026-08-22
- [spacebears] holzmarkt chemnitz posted to leak siteransomware_live · 2026-08-22
- [spacebears] Freelom posted to leak siteransomware_live · 2026-08-22
- [pear] Island Networks posted to leak siteransomware_live · 2026-08-22
- [pear] Mogren, Glessner & Ahrens, P.S. posted to leak siteransomware_live · 2026-08-22
- [NVD] CVE-2026-77002 — The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity it is asked to authenticate, allowing unauthenticated users to log in as any registered account, including administrators.nvd · 2026-08-22
- [NVD] CVE-2026-77001 — The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or nonce checks in one of its publicly accessible login handlers, allowing unauthenticated attackers to obtain a valid session as any exnvd · 2026-08-22
- [NVD] CVE-2026-77000 — The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with the identity provider before authenticating a visitor, allowing unauthenticated attackers to log in as any existing user, including administrators, by supplyinnvd · 2026-08-22
- [NVD] CVE-2026-76793 — The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an authentication token to be verified before matching it to a WordPress account and issuing a session, allowing unauthenticated attackers to log in as any user, including administratonvd · 2026-08-22
- [NVD] CVE-2026-76789 — The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 does not have authorisation and nonce checks on two of its request handlers, and does not escape a stored setting before outputting it, allowing unauthenticated users to store malicious JavaScript whicnvd · 2026-08-22