THREAT OPS › Threat News
Threat Intelligence News
11730 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [GHSA] GHSA-8mq9-5fw2-5rm4 (medium) — Tina: Broken Access Control: arbitrary bucket-key write/delete in `next-tinacms-s3` (and sibling production media adapters)github_advisories · 2026-08-19
- [NVD] CVE-2026-76827 (MEDIUM 6.8) — A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed cluster to tamper with or delete another cluster's indexed search data. This is possible because the delta-sync write paths in search-indexer do not properly restrict UPDATE/DELETnvd · 2026-08-19
- [NVD] CVE-2026-76139 (HIGH 8.0) — A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from a remote source without verifying its authenticity or integrity. This script gains access to sensitive credentials, such as GitHub access tokens and registry passwords, nvd · 2026-08-19
- [NVD] CVE-2026-75569 (HIGH 7.7) — A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remote repository without performing integrity checks, such as commit pinning or signature verification. This allows a malicious actor with write access to the remote repository to injenvd · 2026-08-19
- [GHSA] GHSA-rxjr-6c9q-h67x (high) — logto-tunnel serves files outside --experience-path via path traversalgithub_advisories · 2026-08-19
- [GHSA] GHSA-72x6-4j93-7w86 (low) — BuildKit has a possible runtime DoS via unbounded group parsinggithub_advisories · 2026-08-19
- [GHSA] GHSA-7236-3392-c5c6 (medium) — BuildKit: Custom frontend could bypass Seccomp/AppArmorgithub_advisories · 2026-08-19
- [NVD] CVE-2026-16661 (HIGH 8.2) — IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the service processor mailbox interface. An attacker with authenticated service-level access to the FSP can exploit this vulnvd · 2026-08-19
- What Is a Website Attack Surface? A Beginner’s Guide to Reducing Risksucuri_blog · 2026-08-19
- [GHSA] GHSA-hjwh-xvfw-qrwj (medium) — SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responsesgithub_advisories · 2026-08-19
- [GHSA] GHSA-vwg3-w8w3-pc79 (high) — Grav: .htaccess file extension rules bypass via case variation on case-insensitive filesystemsgithub_advisories · 2026-08-19
- [GHSA] GHSA-c8qc-wf67-342w (medium) — Snipe-IT: Stored DOM XSS via table selected-count IDsgithub_advisories · 2026-08-19
- [GHSA] GHSA-r9r3-g9fp-3q4q (medium) — Snipe-IT: Maintenance Record Disclosure via Missing Authorization on GETgithub_advisories · 2026-08-19
- [GHSA] GHSA-3hgv-jr5j-cg9x (high) — Snipe-IT: Chained Information Disclosure and IDOR Leads to Full EULA File Takeovergithub_advisories · 2026-08-19
- [GHSA] GHSA-wf6j-gr27-g7ch (high) — GeoServer has a Server-Side Template Injection (SSTI) vulnerability in processing FreeMarker templatesgithub_advisories · 2026-08-19
- [GHSA] GHSA-wppf-h75h-6pm6 (medium) — SearXNG MCP Server: Additional hardened-mode SSRF bypassesgithub_advisories · 2026-08-19
- [GHSA] GHSA-q87f-qc2r-2gw4 (medium) — SearXNG MCP Server is Vulnerable to SSRF in web_url_read: the internal-address guard is disabled by default (MCP_HTTP_HARDEN off)github_advisories · 2026-08-19
- [GHSA] GHSA-p77j-g7h5-r2vw (high) — GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)github_advisories · 2026-08-19
- [GHSA] GHSA-45ph-gxxr-gwgw (high) — XWiki Platform Live Data Live Table Connector has privilege escalation from edit to script right through Live Data editinggithub_advisories · 2026-08-19
- [GHSA] GHSA-7m52-jw36-44r3 (high) — MCP PHP SDK: client HttpTransport SSE buffer (sseBuffer .= chunk) grows unbounded when server withholds the event delimitergithub_advisories · 2026-08-19
- [GHSA] GHSA-w47q-945m-q9pc (high) — Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)github_advisories · 2026-08-19
- [NVD] CVE-2026-17494 (HIGH 8.2) — IBM Power Systems Firmware FW1120.00, and FW1110.00 through FW1110.30 is affected by a vulnerability in the interface between the BMC and the host system. An attacker with service access to the BMC can send a specially crafted command, allowing arbitrary code to be executed on thnvd · 2026-08-19
- [NVD] CVE-2026-16930 (HIGH 8.2) — IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in the interface between the BMC/FSP and the host system. An attacker with service account or root access to the BMC/FSP can execute arbitrary code onnvd · 2026-08-19
- [NVD] CVE-2026-16835 (CRITICAL 9.6) — IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP management network protocol. An unauthenticated attacker on the management network can bypass authentication andnvd · 2026-08-19
- [NVD] CVE-2026-16832 (HIGH 8.4) — IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP management network protocol. An attacker with authenticated HMC administrator access can execute arbitrary code nvd · 2026-08-19
- [NVD] CVE-2026-16687 (CRITICAL 9.6) — IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the ASMI web interface. An unauthenticated attacker with network access can send the FSP a malformed request, allowing nvd · 2026-08-19
- [GHSA] GHSA-2xhg-73j7-rrgx (high) — Contentful MCP Server: export_space/import_space tools pass LLM-controlled `host`/`proxy` args to CMA client, redirecting server PAT to attacker-controlled endpointgithub_advisories · 2026-08-19
- [GHSA] GHSA-9gmc-jqmh-3rvm (high) — Copier has a trust-prefix bypass via path traversal that runs tasks unpromptedgithub_advisories · 2026-08-19
- [GHSA] GHSA-vjhx-2cqw-3q6q (medium) — Uprobe gadgets: unprivileged container's ld.so.cache causes high CPU utilization and container startup DoSgithub_advisories · 2026-08-19
- [GHSA] GHSA-qwgh-2vcv-g2f7 (medium) — block_buffer: panic corrupts inline buffer positiongithub_advisories · 2026-08-19
- [GHSA] GHSA-rr55-jp92-8wp2 (high) — claude-faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF toolsgithub_advisories · 2026-08-19
- [GHSA] GHSA-j4r7-8ph4-43g3 (high) — faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF toolsgithub_advisories · 2026-08-19
- [GHSA] GHSA-cc2g-gq8c-r332 (high) — grok-faf-mcp has an arbitrary local file read via unconfined `path` argument in FAF toolsgithub_advisories · 2026-08-19
- [OSSA-2026-036] OpenStack Aodh and Watcher: Aodh cross-project alarm enumeration and Watcher webhook authorization bypass (CVE-2026-pending)oss_sec · 2026-08-19
- Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Secondthehackernews · 2026-08-19
- Ceph 20.2.4 and Ceph 19.2.6 are released with 4 security fixes.oss_sec · 2026-08-19
- [GHSA] GHSA-jfj5-wrj9-63x4 (medium) — langgraph-api: Incomplete assistant authorization in LangGraph Server run creationgithub_advisories · 2026-08-19
- [GHSA] GHSA-2c9q-c2q9-qgqv (medium) — langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authenticationgithub_advisories · 2026-08-19
- Citrix security advisory (AV26-833)cccs_ca · 2026-08-19
- CVE-2026-75589: Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLAINTEXT signatures with a non-constant-time comparison in verifyoss_sec · 2026-08-19
- CVE-2026-72889: Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verifyoss_sec · 2026-08-19
- MLflow security advisory (AV26-832)cccs_ca · 2026-08-19
- Oracle Corporation security advisory (AV26-831)cccs_ca · 2026-08-19
- [Helix] Delek US posted to leak siteransomware_live · 2026-08-19
- [Deadlock] UFOC posted to leak siteransomware_live · 2026-08-19
- [Deadlock] Global Terminal Services posted to leak siteransomware_live · 2026-08-19
- [NVD] CVE-2026-75149 (HIGH 8.8) — marimo before 0.23.15 contains a code injection vulnerability in the notebook configuration handler that allows attackers to execute arbitrary commands by supplying a crafted MCP server entry with an attacker-controlled command value embedded in a notebook. When the notebook is onvd · 2026-08-19
- [NVD] CVE-2026-66794 (CRITICAL 9.3) — A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker, who can access the user-facing route, to bypass authentication and authorization checks. By manipulating URL path segments, the atnvd · 2026-08-19
- [NVD] CVE-2026-18874 (MEDIUM 6.2) — A flaw was found in volsync-addon-controller. This vulnerability allows an attacker to inject malicious YAML (Yet Another Markup Language) code into the OpenShift Lifecycle Manager (OLM) Subscription resource. This is due to improper escaping of annotation values when they are renvd · 2026-08-19
- 41 deceptive download sites show a real link, then send you somewhere elsemalwarebytes_blog · 2026-08-19
- OpenAI Pauses Frontier RL Training as It Tightens Defenses Against Unsafe AI Behaviorthehackernews · 2026-08-19
- [xpl0itrs] Mihuru posted to leak siteransomware_live · 2026-08-19
- Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026msstic · 2026-08-19
- Agentic Workflows: A Complete Guide for 2026orca_security · 2026-08-19
- [NVD] CVE-2026-49441 (CRITICAL 9.1) — Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.3.0 until 4.14.6 and 5.0.0-beta3, the non-merged branch of process_files_from_worker() in framework/wazuh/core/cluster/master.py trusts a peer-controlled file_path key from files_nvd · 2026-08-19
- [NVD] CVE-2026-49392 (MEDIUM 5.3) — Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.6.0 until 4.14.6 and 5.0.0-beta3, DB::getFile() and DB::searchFile() in src/syscheckd/src/db/src/file.cpp concatenate a monitored file path into SQLite row filters. On non-Windowsnvd · 2026-08-19
- [NVD] CVE-2026-48162 (CRITICAL 9.1) — Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta3, DistributedAPI.send_tmp_file() in framework/wazuh/core/cluster/dapi/dapi.py joins an attacker-controlled tmp_file value to WAZUH_PATH without cannvd · 2026-08-19
- [NVD] CVE-2026-48024 (CRITICAL 9.1) — Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta3, cluster.unmerge_info() in framework/wazuh/core/cluster/cluster.py constructs paths from peer-controlled merge_type and name values in a merged synvd · 2026-08-19
- [NVD] CVE-2026-45798 (HIGH 7.5) — Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.5.0 until 4.14.6 and 5.0.0-beta2, compare_wazuh_versions() in src/shared/version_op.c copies the attacker-controlled enrollment V: field into a 10-byte stack buffer with strncpy()nvd · 2026-08-19
- [NVD] CVE-2026-44901 (HIGH 8.4) — Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta2, AffectedItemsWazuhResult.merge() in framework/wazuh/core/results.py trusts the sort_casting field in a cluster worker's JSON response. During a dnvd · 2026-08-19
- NVIDIA security advisory (AV26-830)cccs_ca · 2026-08-19
- CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gatewayrapid7 · 2026-08-19
- Building Capacity and Resilience for U.S. Partnershorizon3 · 2026-08-19
- CTEM: From Visibility to Measurable Risk Reductionhorizon3 · 2026-08-19
- Cisco Secure Workload Software Security Hardening Release: August 2026cisco_psirt · 2026-08-19
- Cisco Industrial Ethernet 1000 Series Switches Stored Cross-Site Scripting Vulnerabilitycisco_psirt · 2026-08-19
- Cisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise Server-Side Request Forgery Vulnerabilitycisco_psirt · 2026-08-19
- Cisco Unified Intelligence Center SQL Injection Vulnerabilitycisco_psirt · 2026-08-19
- Cisco Industrial Ethernet 1000 Series Switches Denial of Service Vulnerabilitycisco_psirt · 2026-08-19
- Cisco RoomOS Stack Overflow Vulnerabilitycisco_psirt · 2026-08-19
- Cisco BroadWorks Out-of-Band Blind XML External Entity Injection Vulnerabilitycisco_psirt · 2026-08-19
- Cisco Crosswork Security Hardening Release: August 2026cisco_psirt · 2026-08-19
- AWSHound: An OpenSource AWS OpenGraph Collectorspecterops · 2026-08-19
- [krybit] sunsea.co.th posted to leak siteransomware_live · 2026-08-19
- Autonomous SOC: AI-Driven Security Operations Explainedorca_security · 2026-08-19
- [coinbasecartel] Crowe posted to leak siteransomware_live · 2026-08-19
- [coinbasecartel] Advanced Engineering Consultants posted to leak siteransomware_live · 2026-08-19
- [akira] Ericksen Krentel posted to leak siteransomware_live · 2026-08-19
- Sideloading on Android: What it is, why it’s risky, and how to do it more safelymalwarebytes_blog · 2026-08-19
- July 2026 Threat Trend Report on APT Groupsahnlab · 2026-08-19
- Ransom & Dark Web Issues Week 3, August 2026ahnlab · 2026-08-19
- [insomnia] *********** posted to leak siteransomware_live · 2026-08-19
- [Orova] DL HOLDINGS GROUP posted to leak siteransomware_live · 2026-08-19
- Simple Scans for Cloud Metadata Service, (Wed, Aug 19th)sans_isc · 2026-08-19
- [NVD] CVE-2026-76245 — stigmem (pip package stigmem-node) version 0.9.0a1 contains a timestamp-handling mismatch in federation peer-token validation that can cause valid peer tokens to be incorrectly treated as expired. This affects the availability and reliability of authenticated federation flows on nvd · 2026-08-19
- [NVD] CVE-2026-76244 — stigmem-node contains an insecure default configuration vulnerability that allows federation traffic to traverse networks without mTLS protection when non-loopback endpoints are enabled. Operators who explicitly disabled mTLS while binding federation to non-loopback addresses expnvd · 2026-08-19
- [NVD] CVE-2026-76242 — stigmem-node 0.9.0a1 accepts federation peer key material during peer registration without a separate administrator out-of-band fingerprint approval step. On nodes that accept federation peer registration over a network where initial registration can be intercepted or misdirectednvd · 2026-08-19
- [NVD] CVE-2026-76241 — stigmem-node 0.9.0a1 allows plugin signature enforcement to be disabled via a single configuration flag without a second explicit acknowledgment. If that setting is carried into an environment where plugin directories are writable by less-trusted users, unsigned (potentially malinvd · 2026-08-19
- [NVD] CVE-2026-76240 — stigmem-node 0.9.0a1 interpolates Postgres backend schema identifiers into SQL strings without defensive quoting. In the affected code path the schema value is operator-controlled, but the unsafe pattern could allow SQL injection if a schema name were derived from tenant, requestnvd · 2026-08-19
- [NVD] CVE-2026-76236 — stigmem-node before 0.9.0a12 contains a cross-tenant broken object level authorization (BOLA) flaw in the RTBF (right-to-be-forgotten) tombstone mechanism. issue_tombstone defaulted the tenant to "default" instead of the caller's tenant, allowing deletion records to be written tonvd · 2026-08-19
- [NVD] CVE-2026-43961 (HIGH 7.8) — A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can break out of the quoted context during mark/unmark operations, allowing arbitrary Vimscript execution. This can be leveraged to run shell commands with the privilegnvd · 2026-08-19
- When the Attacker Wears Your Logo: Detecting and Taking Down Impersonation at AI Speedcyble · 2026-08-19
- [incransom] BANGKOKCABLE posted to leak siteransomware_live · 2026-08-19
- [incransom] UNIPLASTICS.COM posted to leak siteransomware_live · 2026-08-19
- [incransom] CDGARVINLAW posted to leak siteransomware_live · 2026-08-19
- [incransom] EXEL posted to leak siteransomware_live · 2026-08-19
- Oracle Critical Patch Update, August 2026 Security Update Reviewqualys · 2026-08-19
- SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATsthehackernews · 2026-08-19
- July 2026: OpenAI Agent Incident, KDDI Breachsocradar_blog · 2026-08-19
- Atlassian security advisory (AV26-829)cccs_ca · 2026-08-19