THREAT OPS › Threat News
Threat Intelligence News
11712 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- CVE-2026-63037: Apache InLong: Unauthenticated SQL injection in Manager OpenAPI audit alert rule list endpointoss_sec · 2026-08-20
- CVE-2026-63016: Apache InLong: Ordinary users can create new packagesoss_sec · 2026-08-20
- CVE-2026-63015: Apache InLong: Non-template responsible persons can view template informationoss_sec · 2026-08-20
- [titan] CTP S.r.l. posted to leak siteransomware_live · 2026-08-20
- [titan] Alto Calore Servizi SPA posted to leak siteransomware_live · 2026-08-20
- [titan] Tedesco & Partners STP srl posted to leak siteransomware_live · 2026-08-20
- [titan] POEMA S.r.l. posted to leak siteransomware_live · 2026-08-20
- ChatGPT for Teens tackles risky chats and homework shortcutsmalwarebytes_blog · 2026-08-20
- [DYSPHOR1A] AYUDHYA TH Insurance posted to leak siteransomware_live · 2026-08-20
- [DYSPHOR1A] GUSTO College GLMS posted to leak siteransomware_live · 2026-08-20
- [DYSPHOR1A] Indonesian Police Database posted to leak siteransomware_live · 2026-08-20
- [DYSPHOR1A] Job Net .COM.MM posted to leak siteransomware_live · 2026-08-20
- New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Datathehackernews · 2026-08-20
- [DYSPHOR1A] Strategy First International College posted to leak siteransomware_live · 2026-08-20
- Insider Threat Report: Dark Web Recruitment & Access Trendsflashpoint · 2026-08-20
- [akira] Cascade Coffee posted to leak siteransomware_live · 2026-08-20
- [NVD] CVE-2026-76634 (MEDIUM 6.5) — WeGIA before 3.9.2 contains an insecure direct object reference vulnerability in the employee profile page that allows authenticated attackers to access arbitrary employee records by injecting an id_pessoa parameter through a request extraction function that overwrites the sessionvd · 2026-08-20
- [NVD] CVE-2026-76633 (HIGH 8.1) — WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow that allows any authenticated user to change their account password without providing existing credentials by exploiting the unconditional exclusion of the alterarSenha method from perminvd · 2026-08-20
- [thegentlemen] P**** R***** posted to leak siteransomware_live · 2026-08-20
- CVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Daysqualys · 2026-08-20
- Frequently asked questions about the active threat to Siemens S7 Series PLCstenable · 2026-08-20
- [titan] CONDOR SPA posted to leak siteransomware_live · 2026-08-20
- Going with the Flow(s): Distinct Clusters Target Individuals of Interest to Russiamandiant_gti · 2026-08-20
- [titan] Elbor S.p.A. posted to leak siteransomware_live · 2026-08-20
- Critical Arbitrary File Upload Vulnerability Patched in Elementor Pro WordPress Pluginwordfence · 2026-08-20
- rsyslog: omfile dynaFile containment hardening (GHSA-xmp9-244p-5ggv)oss_sec · 2026-08-20
- [everest] CCA Bank posted to leak siteransomware_live · 2026-08-20
- [akira] Deas Millwork posted to leak siteransomware_live · 2026-08-20
- Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCEthehackernews · 2026-08-20
- Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Serversthehackernews · 2026-08-20
- [titan] TECNOLOGICA S.r.l. posted to leak siteransomware_live · 2026-08-20
- Twitch wants your content for Amazon AI training. Here’s how to opt outmalwarebytes_blog · 2026-08-20
- Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Executionthehackernews · 2026-08-20
- Cisco security advisory (AV26-834)cccs_ca · 2026-08-20
- Zero Trust can’t stop at a claim. You need to prove it.zscaler_threatlabz · 2026-08-20
- BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitivecheckpoint_research · 2026-08-20
- An Air Gap Doesn't Remove the Supply Chain. It Makes Every Crossing a Decision.sonatype · 2026-08-20
- Your Mac already has a built-in firewall. Here’s how to get more from itmalwarebytes_blog · 2026-08-20
- Using Microsoft Graph and Powershell to Mine for Information - Stale Accounts and Licenses, (Thu, Aug 20th)sans_isc · 2026-08-20
- CISA Adds Two Known Exploited Vulnerabilities to Catalogcisa_advisories · 2026-08-20
- Johnson Controls Simplex Incident Managercisa_advisories · 2026-08-20
- 9 million images of people’s faces exposed by reverse lookup servicemalwarebytes_blog · 2026-08-20
- Why "Shady AI" is Security's Next Big Governance Problemthehackernews · 2026-08-20
- CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplificationthehackernews · 2026-08-20
- [pear] Medical Arts Chemists and Surgicals posted to leak siteransomware_live · 2026-08-20
- [pear] Club One Casino posted to leak siteransomware_live · 2026-08-20
- [pear] Practi-Cal posted to leak siteransomware_live · 2026-08-20
- [pear] Austin Plastic Surgery Institute posted to leak siteransomware_live · 2026-08-20
- NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commandsthehackernews · 2026-08-20
- [titan] ELCON MEGARAD S.p.A posted to leak siteransomware_live · 2026-08-20
- ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraudthehackernews · 2026-08-20
- [lockbit5] usbank.com posted to leak siteransomware_live · 2026-08-20
- [majinahanashi] Grand Ion Delemen Hotel posted to leak siteransomware_live · 2026-08-20
- [majinahanashi] The Margo Hotel posted to leak siteransomware_live · 2026-08-20
- [NVD] CVE-2026-18917 (HIGH 7.8) — A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This flaw allows crafted values to bypass a size check, leading to an undersized memory buffer. Subsequently, real NUMA node data can overwnvd · 2026-08-20
- UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilitiestalos · 2026-08-20
- UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operationstalos · 2026-08-20
- Identity Abuse Through Trusted Communication Channelsunit42 · 2026-08-20
- Police Are Hiding Their Use of Flock Surveillance Camerasschneier · 2026-08-20
- [qilin] Questronix posted to leak siteransomware_live · 2026-08-20
- [qilin] Provite posted to leak siteransomware_live · 2026-08-20
- [qilin] Trends And Concepts posted to leak siteransomware_live · 2026-08-20
- 40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secretsthehackernews · 2026-08-20
- [0day-rubbish] VMS 6.48.809 Authenticated command injection to root RCE (8.8)fulldisclosure · 2026-08-20
- [0day-rubbish] ONE Reporter 13.1 Authenticated RCE / privilege escalation via CommandExecutor (8.8)fulldisclosure · 2026-08-20
- [0day-rubbish] Gemini 7.3.0 Authenticated SQL injection to xp_cmdshell RCE (8.8)fulldisclosure · 2026-08-20
- [0day-rubbish] RoboTask 11.0.5.1229 Unauthenticated REST API remote task execution (9.8)fulldisclosure · 2026-08-20
- [0day-rubbish] ActiveFax Server 10.70 Unauthenticated LPD Ghostscript %pipe% SYSTEM RCE (9.8)fulldisclosure · 2026-08-20
- [0day-rubbish] Tornado 2.11.3 Unauthenticated arbitrary file write to root RCE (storeTo=file: to cron) (9.8)fulldisclosure · 2026-08-20
- [0day-rubbish] Datalore On-Premises 2026.2.3 Unauthenticated RCE via InteractiveReport access-mapping flaw (9.8)fulldisclosure · 2026-08-20
- APPLE-SA-08-18-2026-1 Safari 26.6.1fulldisclosure · 2026-08-20
- Cudy WR3000: Hard-coded JWT Secret to Root Command Injectionfulldisclosure · 2026-08-20
- [Deadlock] JP Molyneux Studio posted to leak siteransomware_live · 2026-08-20
- Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Codethehackernews · 2026-08-20
- Srsly Risky Biz: Trump's private hacker memo is the right ideariskybiz_news · 2026-08-20
- [everest] Kingston Technology posted to leak siteransomware_live · 2026-08-20
- [everest] Experts Entreprendre posted to leak siteransomware_live · 2026-08-20
- Re: libmspack: heap buffer overflow in make_decode_table() (Huffman decode table construction) -- CVE requestedoss_sec · 2026-08-20
- Fwd: [pfx] Postfix stable release 3.11.6 and legacy releases 3.10.13, 3.9.14, 3.8.20, 3.7.22, 3.6.20, 3.5.27oss_sec · 2026-08-20
- Multiple vulnerabilities fixed in libgit2-1.9.5, 1.9.7oss_sec · 2026-08-20
- GNU Emacs vulnerability upon opening arbitrary fileoss_sec · 2026-08-20
- uutils coreutils 'stdbuf' uses LD_PRELOAD on a world-writable temporary fileoss_sec · 2026-08-20
- [everest] Grupo DT posted to leak siteransomware_live · 2026-08-20
- [everest] Capgemini Engineering posted to leak siteransomware_live · 2026-08-20
- Splunk Products Multiple Vulnerabilitieshkcert · 2026-08-20
- CVE-2026-75628: Punk::OAuth2 versions before 0.03 for Perl allow an attacker-chosen off-site redirect after login because same_origin_path accepts a backslash or tab in the return parameteross_sec · 2026-08-20
- [xpl0itrs] Target posted to leak siteransomware_live · 2026-08-20
- [CISA KEV] CVE-2026-72530 — TrueConf Server: TrueConf Server Code Injection Vulnerabilitycisa_kev · 2026-08-20
- [CISA KEV] CVE-2026-72529 — TrueConf Server: TrueConf Server Missing Authentication for Critical Function Vulnerabilitycisa_kev · 2026-08-20
- WebKitGTK and WPE WebKit Security Advisory WSA-2026-0005oss_sec · 2026-08-19
- Aligning ITAR Compliance to Zscaler’s Zero Trust Exchangeszscaler_threatlabz · 2026-08-19
- [OSSA-2026-008] ERRATA 2: Ironic Command Injection in IPMI Console Implementationsoss_sec · 2026-08-19
- [qilin] Semana posted to leak siteransomware_live · 2026-08-19
- [GHSA] GHSA-rgr9-r7mj-mf6x (medium) — Tina: Cross-origin `POST /media/upload/*` requests can write arbitrary files into the Tina dev server media rootgithub_advisories · 2026-08-19
- [GHSA] GHSA-8mq9-5fw2-5rm4 (medium) — Tina: Broken Access Control: arbitrary bucket-key write/delete in `next-tinacms-s3` (and sibling production media adapters)github_advisories · 2026-08-19
- [NVD] CVE-2026-76827 (MEDIUM 6.8) — A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed cluster to tamper with or delete another cluster's indexed search data. This is possible because the delta-sync write paths in search-indexer do not properly restrict UPDATE/DELETnvd · 2026-08-19
- [NVD] CVE-2026-76139 (HIGH 8.0) — A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from a remote source without verifying its authenticity or integrity. This script gains access to sensitive credentials, such as GitHub access tokens and registry passwords, nvd · 2026-08-19
- [NVD] CVE-2026-75569 (HIGH 7.7) — A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remote repository without performing integrity checks, such as commit pinning or signature verification. This allows a malicious actor with write access to the remote repository to injenvd · 2026-08-19
- [GHSA] GHSA-rxjr-6c9q-h67x (high) — logto-tunnel serves files outside --experience-path via path traversalgithub_advisories · 2026-08-19
- [GHSA] GHSA-72x6-4j93-7w86 (low) — BuildKit has a possible runtime DoS via unbounded group parsinggithub_advisories · 2026-08-19