THREAT OPS › Threat News
Threat Intelligence News
11708 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- Risky Bulletin: US warns of AI-assisted attacks against Siemens PLCsriskybiz_news · 2026-08-21
- [direwolf] NorthStar posted to leak siteransomware_live · 2026-08-21
- [direwolf] Aztec Software posted to leak siteransomware_live · 2026-08-21
- [direwolf] The Revel Collective posted to leak siteransomware_live · 2026-08-21
- [direwolf] ProSim Aviation Research posted to leak siteransomware_live · 2026-08-21
- [direwolf] Authenticate Information Systems posted to leak siteransomware_live · 2026-08-21
- [direwolf] Diaco Global posted to leak siteransomware_live · 2026-08-21
- [direwolf] iSON XPERIENCES posted to leak siteransomware_live · 2026-08-21
- [direwolf] Deer Creek-Mackinaw CUSD posted to leak siteransomware_live · 2026-08-21
- [direwolf] Allstar Industries posted to leak siteransomware_live · 2026-08-21
- [direwolf] HP Carriers posted to leak siteransomware_live · 2026-08-21
- [direwolf] MCT Group of Companies posted to leak siteransomware_live · 2026-08-21
- [direwolf] Reviso Cloud Accounting Limited posted to leak siteransomware_live · 2026-08-21
- [direwolf] Studee posted to leak siteransomware_live · 2026-08-21
- [Breach] McKesson — 6,404,340 accounts exposedhibp_breaches · 2026-08-21
- [CISA KEV] CVE-2026-69836 — Microsoft Entra ID : Microsoft Entra ID Deserialization of Untrusted Data Vulnerabilitycisa_kev · 2026-08-21
- [CISA KEV] CVE-2026-73570 — Synacor Zimbra Collaboration Suite (ZCS): Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerabilitycisa_kev · 2026-08-21
- [OSSA-2026-036] OpenStack Aodh and Watcher: Aodh cross-project alarm enumeration and Watcher webhook authorization bypass (CVE-2026-76878) errata 1oss_sec · 2026-08-20
- Inside ExploitGym: How Researchers Are Measuring AI Agent Exploitation Capabilitiesduo_decipher · 2026-08-20
- [OSSN-0108] Multiple authentication vulnerabilities in Ceph affecting OpenStackoss_sec · 2026-08-20
- CVE-2026-77176: Kata-containers: insufficient validation of createcontainer mount and storage rules in genpolicyoss_sec · 2026-08-20
- [GHSA] GHSA-8r62-w5wh-fc5m (medium) — Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689)github_advisories · 2026-08-20
- [GHSA] GHSA-r553-m4fv-5v97 (medium) — Mailpit: SMTP DATA line reader buffers over-limit input before size enforcementgithub_advisories · 2026-08-20
- CVE-2026-19478 | MeGitLab CE/EE GraphQL Directive Code Injection Vulnerabilityhorizon3 · 2026-08-20
- [SilentRansomGroup] D... posted to leak siteransomware_live · 2026-08-20
- [DYSPHOR1A] The University of Delhi (DU) posted to leak siteransomware_live · 2026-08-20
- Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloadsthehackernews · 2026-08-20
- CVE-2026-15743: Catalyst::Plugin::Static::Simple versions through 0.38 for Perl mark responses as publicly cacheableoss_sec · 2026-08-20
- [GHSA] GHSA-f4jp-rw7w-ccwg (medium) — gettext-converter: Prototype pollution in js2i18next() via crafted translation keysgithub_advisories · 2026-08-20
- Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accountsthehackernews · 2026-08-20
- [Control Systems] Johnson Controls security advisory (AV26-837)cccs_ca · 2026-08-20
- n8n security advisory (AV26-836)cccs_ca · 2026-08-20
- TrueConf security advisory (AV26-835)cccs_ca · 2026-08-20
- [xpl0itrs] Gruppo Spaggiari Parma posted to leak siteransomware_live · 2026-08-20
- [kairos] Ayuntamiento de Velilla de San Antonio posted to leak siteransomware_live · 2026-08-20
- [GHSA] GHSA-jm5p-837g-rv8g (medium) — Wagtail: Improper restriction handling on Page translation API endpointgithub_advisories · 2026-08-20
- [GHSA] GHSA-x5cx-w6p2-mxf2 (medium) — Wagtail: Improper permission handling when copying snippetsgithub_advisories · 2026-08-20
- [GHSA] GHSA-c2xx-cjmh-9q8f (medium) — Wagtail: Improper restriction handling on descendant collections in Documents and Images APIgithub_advisories · 2026-08-20
- [GHSA] GHSA-92hv-j533-69wc (low) — Wagtail: Identification of documents by SHA1 hashgithub_advisories · 2026-08-20
- [GHSA] GHSA-hq84-x37p-j6q5 (medium) — Winter: Reflected XSS through the search query parameter in the backend Table widgetgithub_advisories · 2026-08-20
- [GHSA] GHSA-p2ch-c2c3-4xm5 (medium) — Winter: CSRF through AJAX handler names reachable as backend page actionsgithub_advisories · 2026-08-20
- [GHSA] GHSA-5cwr-5jxg-pcf6 (medium) — Winter: Stored XSS through cached Brand Settings and Editor Settings custom stylesgithub_advisories · 2026-08-20
- [GHSA] GHSA-fm29-4mq3-phg6 (medium) — Winter: ImportExportController AJAX handlers bypass granular import/export permission gategithub_advisories · 2026-08-20
- BOD 26-04 Just Changed How Federal Agencies Prioritize Vulnerabilities.orca_security · 2026-08-20
- [GHSA] GHSA-mpmw-f6h6-3g26 (medium) — Winter: My Account preview exposes another backend user's profile by record IDgithub_advisories · 2026-08-20
- [GHSA] GHSA-7mpf-4465-7fc2 (low) — Winter: Stored XSS through Backend List widget image columnsgithub_advisories · 2026-08-20
- [GHSA] GHSA-rxhg-vcww-2mpw (low) — Fleet: ORDER BY column injection on activity list endpointsgithub_advisories · 2026-08-20
- [GHSA] GHSA-q9c5-pp7m-fm2g (medium) — Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLsgithub_advisories · 2026-08-20
- [GHSA] GHSA-8cfw-pcwh-v63w (high) — Winter: Authenticated Twig sandbox escape in CMS SecurityPolicy (bypass of CVE-2024-54149)github_advisories · 2026-08-20
- [GHSA] GHSA-2223-f22x-24cq (medium) — Winter: Local File Inclusion through =include directives in JavaScript asset compilationgithub_advisories · 2026-08-20
- [GHSA] GHSA-4899-mpch-38p3 (high) — netty-incubator-codec-ohttp BinaryHttpParser: Unauthenticated CPU-exhaustion DoS via infinite loop in field-section decodinggithub_advisories · 2026-08-20
- [GHSA] GHSA-58fp-mcx6-7qf9 (medium) — Winter: Local File Inclusion through @import directives in LESS compilation of backend customizable stylesheets and theme assetsgithub_advisories · 2026-08-20
- [GHSA] GHSA-hmq9-67w8-j5pw (high) — netty-incubator-codec-ohttp: BinaryHttpParser should enforce limits for variable lengths fieldsgithub_advisories · 2026-08-20
- [GHSA] GHSA-8cfx-wx3q-mh5q (high) — netty-incubator-codec-ohttp: Binary HTTP parser infinite loop on known-length field section boundarygithub_advisories · 2026-08-20
- [GHSA] GHSA-pgrf-4654-3gq8 (medium) — netty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crashgithub_advisories · 2026-08-20
- [shinyhunters] Cyrus****** posted to leak siteransomware_live · 2026-08-20
- [GHSA] GHSA-2mc4-j865-9q4r (high) — netty-incubator-codec-ohttp: BoringSSL HPKE private key bytes exposed through toString() and exception messagesgithub_advisories · 2026-08-20
- [GHSA] GHSA-8qj2-c6q4-f399 (medium) — django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staffgithub_advisories · 2026-08-20
- [GHSA] GHSA-6x92-6vx4-5fwr (medium) — django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)github_advisories · 2026-08-20
- [GHSA] GHSA-hvq6-2r72-p2x7 (medium) — django CMS: Stored XSS in edit-mode plugin exception renderinggithub_advisories · 2026-08-20
- [GHSA] GHSA-42vx-43vc-x6pr (medium) — Laravel Backpack CRUD: HasMany/MorphMany relation fields allow cross-tenant record re-parenting (IDOR) via attachManyRelationgithub_advisories · 2026-08-20
- [GHSA] GHSA-3vrh-m9w7-v94f (medium) — Wagtail: Improper restriction handling on Pages admin APIgithub_advisories · 2026-08-20
- [GHSA] GHSA-ghvf-qf6h-g8x5 (high) — NocoBase: Arbitrary File Write chained with Local file Inclusion leads to Remote code executiongithub_advisories · 2026-08-20
- [GHSA] GHSA-vgxm-h9gx-h9w7 (medium) — django CMS: Structure endpoint bypasses page-view permissiongithub_advisories · 2026-08-20
- [GHSA] GHSA-4xfr-4p46-gc6p (medium) — django CMS: Clipboard copy IDOR discloses unauthorized plugin contentgithub_advisories · 2026-08-20
- [GHSA] GHSA-23m2-mghx-vqmf (high) — Wagtail: Reflected XSS in dynamic image URL generator viewgithub_advisories · 2026-08-20
- [GHSA] GHSA-8634-mr4j-r72c (medium) — Wagtail: Pages translations can be created without page permissions when using simple_translationgithub_advisories · 2026-08-20
- [iah6477] regencycenters posted to leak siteransomware_live · 2026-08-20
- [iah6477] acima posted to leak siteransomware_live · 2026-08-20
- [iah6477] marvin posted to leak siteransomware_live · 2026-08-20
- Critical Elementor Pro File Upload Flaw Enables Unauthenticated Remote Code Execution on WordPress Sitesorca_security · 2026-08-20
- Is Cyber missing the Marque?talos · 2026-08-20
- ‘Unprecedented’ Number of Apple Users Received Recent Spyware Alertcitizenlab · 2026-08-20
- [emperador] NetExam posted to leak siteransomware_live · 2026-08-20
- The Fix Has Been Out for a Year. The Controller Is Still Exposed.zscaler_threatlabz · 2026-08-20
- Detailed Timeline of OpenAI’s Cyberattack on Hugging Faceschneier · 2026-08-20
- [GHSA] GHSA-533j-2v4q-mw5h (high) — LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposuregithub_advisories · 2026-08-20
- [GHSA] GHSA-rrwh-6jrq-wp5v (critical) — Dgraph Alpha group stores can be replaced via unauthenticated external snapshot importgithub_advisories · 2026-08-20
- [GHSA] GHSA-89v8-rhwq-hf77 (medium) — asteval has a Sandbox Escape via BaseException Subclassesgithub_advisories · 2026-08-20
- [play] Be Media posted to leak siteransomware_live · 2026-08-20
- [play] Latoplast posted to leak siteransomware_live · 2026-08-20
- [GHSA] GHSA-9w56-46f6-3qhx (medium) — asteval Sandbox Escape: arbitrary native memory read/write via numpy ctypes in default asteval Interpretergithub_advisories · 2026-08-20
- [payload] Qualiflex Datacenter | HWZ-Studiengnge (fh-hwz.ch), myenb.ch, etc posted to leak siteransomware_live · 2026-08-20
- [GHSA] GHSA-qqff-5854-px68 (high) — vouch-proxy has an Unbounded Multipart Cookie Allocation DoSgithub_advisories · 2026-08-20
- [GHSA] GHSA-42cj-99w8-cp2p (medium) — OpenTelemetry-Go: Unsynchronized baggage map can panic under concurrent accessgithub_advisories · 2026-08-20
- [GHSA] GHSA-j2g6-362q-6qc6 (medium) — Velero vulnerable to file path traversal when extracting from backup's tarballgithub_advisories · 2026-08-20
- ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and Morethehackernews · 2026-08-20
- AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructurethehackernews · 2026-08-20
- [titan] Termotecnica Industriale S.r.l. posted to leak siteransomware_live · 2026-08-20
- [Panzer] Frisian Flag Indonesia posted to leak siteransomware_live · 2026-08-20
- CVE-2026-63044: Apache InLong: Authenticated SSRF via POST /api/node/testConnectionoss_sec · 2026-08-20
- CVE-2026-63043: Apache InLong: Agent path traversal via unvalidated file source pathoss_sec · 2026-08-20
- CVE-2026-63042: Apache InLong: Missing authorization on DataNode management endpointsoss_sec · 2026-08-20
- CVE-2026-63040: Apache InLong: Missing authorization in StreamSource forceDeleteoss_sec · 2026-08-20
- CVE-2026-63039: Apache InLong: SQL Injection via Unvalidated MyBatis Dollar-Sign Interpolation in AuditAlertRuleServiceoss_sec · 2026-08-20
- CVE-2026-63038: Apache InLong: SQL Injection via String Concatenation Vulnerability Reportoss_sec · 2026-08-20
- CVE-2026-63037: Apache InLong: Unauthenticated SQL injection in Manager OpenAPI audit alert rule list endpointoss_sec · 2026-08-20
- CVE-2026-63016: Apache InLong: Ordinary users can create new packagesoss_sec · 2026-08-20
- CVE-2026-63015: Apache InLong: Non-template responsible persons can view template informationoss_sec · 2026-08-20
- [titan] CTP S.r.l. posted to leak siteransomware_live · 2026-08-20