THREAT OPS › Threat News
Threat Intelligence News
11708 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [NVD] CVE-2026-19222 — The Forminator Forms WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it applies to registration forms, allowing users who are permitted to build forms to configure one that assigns the administrator role to any visitor who registers through itnvd · 2026-08-22
- [NVD] CVE-2026-19221 — The Forminator Forms WordPress plugin before 1.57.0.5 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network.nvd · 2026-08-22
- [NVD] CVE-2026-19093 — The Tutor LMS WordPress plugin before 4.0.6 does not validate a stored file path before using it to stream media, allowing users with the instructor role to read arbitrary files on the server, including files outside the web root. The readable files include the WordPress confignvd · 2026-08-22
- [NVD] CVE-2026-18052 — The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the signature which authorises the login, nor prevent an already used login link from being replayed, allowing attackers who obtain such a link to gain a session as any user on the sitnvd · 2026-08-22
- [NVD] CVE-2026-16738 — The Conekta Payment Gateway WordPress plugin before 6.2.2 does not verify the authenticity of incoming payment gateway webhook notifications, nor bind the confirmed payment to the targeted order or verify its amount, allowing unauthenticated attackers to mark arbitrary orders as nvd · 2026-08-22
- [NVD] CVE-2026-16612 — The FiboSearch WordPress plugin before 1.34.1 does not consistently exclude password-protected products from its unauthenticated AJAX endpoints, allowing unauthenticated users to disclose and enumerate password-protected products and their metadata without entering the product pnvd · 2026-08-22
- [NVD] CVE-2026-16260 — The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.8.1 does not sanitise and escape one of its custom post type settings before outputting it in an HTML attribute on the admin edit screen, allowing users with the Contributor role and above to inject JavaScript tnvd · 2026-08-22
- [rhysida] CRI Electric posted to leak siteransomware_live · 2026-08-22
- [thegentlemen] Meridian Logistics Group posted to leak siteransomware_live · 2026-08-22
- CVE-2026-77781: Tie::Hash::Regex versions before 2.0.0 for Perl will throw an exception on unparseable lookup keysoss_sec · 2026-08-22
- How to Close The AI Security Gapzscaler_threatlabz · 2026-08-22
- Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chainunit42 · 2026-08-21
- [NVD] CVE-2026-69238 (LOW 3.5) — There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.5 and prior that allows a remote, highly priviliged attacker to insert arbitrary HTML into the Portal for ArcGIS Home application. Users working with ArcGIS Enterprise 11.1, 11.3, and 11.5 are encouragnvd · 2026-08-21
- [NVD] CVE-2026-69237 (LOW 3.8) — There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.3 and prior that allows a remote attacker with administrative privileges to insert arbitrary HTML into an administrative API. Users working with ArcGIS Enterprise 11.1, and 11.3 are encouraged to patchnvd · 2026-08-21
- [NVD] CVE-2026-69236 (MEDIUM 6.1) — There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 12.1 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary JavaScript in a victim’s browser. Users working with ArcGIS Enterprise 11.nvd · 2026-08-21
- [NVD] CVE-2026-69235 (MEDIUM 6.1) — There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary in a victim’s browser. Users working with ArcGIS Enterprise 11.1, 11.3, annvd · 2026-08-21
- [NVD] CVE-2026-69234 (MEDIUM 6.1) — There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS versions 11.5 and prior which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. Usnvd · 2026-08-21
- [NVD] CVE-2026-69233 (MEDIUM 5.5) — There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, administratively privileged attacker to inject malicious code that could potentially execute arbitrary in a victim’s browser. Users working with ArcGIS Enterprinvd · 2026-08-21
- [NVD] CVE-2026-69232 (MEDIUM 5.5) — There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary JavaScript in a victim’s browser. Users working with ArcGIS Enterprise 11.nvd · 2026-08-21
- [NVD] CVE-2026-69231 (MEDIUM 5.5) — There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary JavaScript in a victim’s browser. Users working with ArcGIS Enterprise 11.nvd · 2026-08-21
- [NVD] CVE-2026-69230 (MEDIUM 5.5) — There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, administratively privileged attacker to inject malicious code that could potentially execute arbitrary in a victim’s browser. Users working with ArcGIS Enterprinvd · 2026-08-21
- [NVD] CVE-2026-69229 (MEDIUM 5.4) — There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that allows a remote, authenticated attacker to insert arbitrary HTML into the Portal for ArcGIS Home application. Users working with ArcGIS Enterprise 11.1, 11.3, 11.5 and 12.0 are encouranvd · 2026-08-21
- [NVD] CVE-2026-69228 (MEDIUM 5.3) — There is a missing authentication vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that may allow a remote, unauthenticated attacker to access a specific resource (not user content) that should only be accessible by authenticated users. Users working with ArcGIS Ennvd · 2026-08-21
- [NVD] CVE-2026-69224 (MEDIUM 5.9) — There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 12.0 and earlier that may under difficult to reproduce circumstances allow a remote, unauthenticated attacker to reflect sensitive information in a http response body.nvd · 2026-08-21
- [NVD] CVE-2026-54457 (HIGH 7.7) — TensorZero is an open-source LLMOps platform that unifies an LLM gateway, observability, evaluation, optimization, and experimentation. Prior to 2026.6.0, the TensorZero Gateway /internal/object_storage endpoint accepts a caller-supplied JSON storage_path parameter that dynamicalnvd · 2026-08-21
- Friday Squid Blogging: Neon Flying Squidschneier · 2026-08-21
- [GHSA] GHSA-66mm-25pp-rfff (critical) — JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressionsgithub_advisories · 2026-08-21
- [GHSA] GHSA-2943-5xfg-gq5f (critical) — JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressionsgithub_advisories · 2026-08-21
- [GHSA] GHSA-2cp2-2r3c-7p7r (high) — Hydra: hydra.utils.instantiate with untrusted config can lead to code executiongithub_advisories · 2026-08-21
- [GHSA] GHSA-5h77-88j3-r659 (high) — YOURLS has stored XSS in referrer statistics chart via crafted Referer headergithub_advisories · 2026-08-21
- [GHSA] GHSA-8gq3-vp5j-2grp (critical) — JSONata: Arbitrary Code Execution via crafted JSONata expressionsgithub_advisories · 2026-08-21
- [GHSA] GHSA-xhj3-7xw9-vr34 (high) — kin-openapi has uncontrolled resource consumption in openapi3filter deepObject query parameter decodinggithub_advisories · 2026-08-21
- [GHSA] GHSA-x2rj-828p-hx9m (critical) — Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsinggithub_advisories · 2026-08-21
- [GHSA] GHSA-hrwp-4hh9-c8r8 (critical) — Phalcon Volt compiler `join` filter compile-time PHP code injection (SSTI leads to RCE)github_advisories · 2026-08-21
- [GHSA] GHSA-mmfr-pmjx-hw9w (high) — kin-openapi openai3filter: nil-pointer panic in ConvertErrors on malformed multipart/form-data body enables unauthenticated DoSgithub_advisories · 2026-08-21
- [GHSA] GHSA-26w5-6g95-gj28 (high) — Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creationgithub_advisories · 2026-08-21
- [GHSA] GHSA-cqmq-8755-7xvh (high) — Keystone vulnerable to `graphql.maxTake` bypass with negative `take`github_advisories · 2026-08-21
- [GHSA] GHSA-jg4p-g6xj-4qmf (high) — Defuddle vulnerable to XSS via unescaped attribute interpolation in site extractorsgithub_advisories · 2026-08-21
- Spring security advisory (AV26-842)cccs_ca · 2026-08-21
- [GHSA] GHSA-mqjf-5f49-2fjh (critical) — GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layersgithub_advisories · 2026-08-21
- 91 Spring CVEs: The AI Vulnerability Consumption Problemsonatype · 2026-08-21
- [Control Systems] CISA security advisory (AV26-841)cccs_ca · 2026-08-21
- [GHSA] GHSA-8hgv-xc77-jmcr (medium) — Grav: Page editors can inject arbitrary script into rendered pages via the Twig sandbox's assets.addJs/addCss allowlist, escalating to super-admingithub_advisories · 2026-08-21
- [GHSA] GHSA-w4mq-xh27-6xpx (medium) — Unleash: Global Mustache.escape override disables HTML escaping process-wide, enabling Slack/Teams link-injection via unrestricted usernamegithub_advisories · 2026-08-21
- [GHSA] GHSA-5vf6-jrqr-78fj (medium) — Unleash: Addon webhook URL is dialed server-side with no internal-address filtering, enabling SSRF to internal services / cloud metadata and exfiltration of configured request headersgithub_advisories · 2026-08-21
- [GHSA] GHSA-r5pq-6chh-j3xp (high) — Unleash: Unauthenticated single-request DoS via OpenAPI validation error formattergithub_advisories · 2026-08-21
- 3 Takeaways from Forrester’s 2026 Data Security Platforms Landscape Reportvaronis_blog · 2026-08-21
- 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2thehackernews · 2026-08-21
- Emacs zero-click local command execution via TRAMPoss_sec · 2026-08-21
- Wordfence Intelligence Weekly WordPress Vulnerability Report (August 10, 2026 to August 16, 2026)wordfence · 2026-08-21
- AI Is Learning to Write Genetic Codeschneier · 2026-08-21
- [Panzer] Nteitalia posted to leak siteransomware_live · 2026-08-21
- Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Bootthehackernews · 2026-08-21
- 100,000 WordPress Sites Affected by Privilege Escalation Vulnerability in Pods WordPress Pluginwordfence · 2026-08-21
- How a Manufacturer Turned Password Risk Into Measurable Security Actionhorizon3 · 2026-08-21
- Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnetthehackernews · 2026-08-21
- [qilin] Quaker State Mexico posted to leak siteransomware_live · 2026-08-21
- [qilin] iPic posted to leak siteransomware_live · 2026-08-21
- AWS EKS forensics: data sources and investigation toolingsynacktiv · 2026-08-21
- Mozilla security advisory (AV26-840)cccs_ca · 2026-08-21
- Zombie Card: An expired Visa credit card can be used for purchasesmalwarebytes_blog · 2026-08-21
- Apple security advisory (AV26-839)cccs_ca · 2026-08-21
- [akira] JC Sales posted to leak siteransomware_live · 2026-08-21
- Splunk security advisory (AV26-838)cccs_ca · 2026-08-21
- [qilin] Cinépolis posted to leak siteransomware_live · 2026-08-21
- [rhysida] Fairview Dental Group posted to leak siteransomware_live · 2026-08-21
- SOCRadar Ranks No. 542 on the 2026 Inc. 5000 List of America’s Fastest-Growing Private Companiessocradar_blog · 2026-08-21
- CISA Adds One Known Exploited Vulnerability to Catalogcisa_advisories · 2026-08-21
- [qilin] Gindre India posted to leak siteransomware_live · 2026-08-21
- Medical records, SSNs, and bank details exposed in CareCloud data breachmalwarebytes_blog · 2026-08-21
- Wazuh and AI For Enhanced SOC Workflowsthehackernews · 2026-08-21
- FTP Banners: The New Dead Drop Resolver Delivering Novel RATssocradar_blog · 2026-08-21
- [rhysida] Battle Creek Public Schools posted to leak siteransomware_live · 2026-08-21
- Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0thehackernews · 2026-08-21
- [qilin] The Pendas Law Firm posted to leak siteransomware_live · 2026-08-21
- [qilin] Blake Services posted to leak siteransomware_live · 2026-08-21
- [qilin] Professional posted to leak siteransomware_live · 2026-08-21
- More Incidents of AIs Going Rogue in Cybersecurity Challengesschneier · 2026-08-21
- [thegentlemen] UOLconsult posted to leak siteransomware_live · 2026-08-21
- [thegentlemen] dlp motive posted to leak siteransomware_live · 2026-08-21
- [thegentlemen] AWJ Holding posted to leak siteransomware_live · 2026-08-21
- [thegentlemen] Lexacaucho posted to leak siteransomware_live · 2026-08-21
- [thegentlemen] LOG Systems posted to leak siteransomware_live · 2026-08-21
- [thegentlemen] Magdalena Grand Beach Golf Resort posted to leak siteransomware_live · 2026-08-21
- [thegentlemen] Akatake Engineering posted to leak siteransomware_live · 2026-08-21
- [thegentlemen] ESCON Group posted to leak siteransomware_live · 2026-08-21
- [thegentlemen] Almeer posted to leak siteransomware_live · 2026-08-21
- [thegentlemen] Geb Sas posted to leak siteransomware_live · 2026-08-21
- [thegentlemen] ARBEITERKAMMERN posted to leak siteransomware_live · 2026-08-21
- [thegentlemen] Aquasea posted to leak siteransomware_live · 2026-08-21
- [thegentlemen] CAZ Investments posted to leak siteransomware_live · 2026-08-21
- [thegentlemen] Oceanica Internacional posted to leak siteransomware_live · 2026-08-21
- [thegentlemen] Ariel Energia posted to leak siteransomware_live · 2026-08-21
- The invisible passenger in your carsecurelist · 2026-08-21
- Endpoint Blind Spots: The 5 Places Ransomware Hides Before It Detonatescyble · 2026-08-21
- [dragonforce] Hogan Omidi P.C. posted to leak siteransomware_live · 2026-08-21
- Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Executionthehackernews · 2026-08-21
- [NVD] CVE-2026-73267 (HIGH 7.7) — A flaw was found in the clusterclaims-controller component of multicluster engine (MCE). A tenant with standard permissions to create and delete ClusterClaim resources can exploit this by manipulating the `spec.namespace` field. This allows the tenant to specify and delete any Manvd · 2026-08-21
- Google Chrome Multiple Vulnerabilitieshkcert · 2026-08-21
- [anubis] Interim HealthCare [Head office] posted to leak siteransomware_live · 2026-08-21