THREAT OPS › Threat News
Threat Intelligence News
11752 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [NVD] CVE-2026-76245 — stigmem (pip package stigmem-node) version 0.9.0a1 contains a timestamp-handling mismatch in federation peer-token validation that can cause valid peer tokens to be incorrectly treated as expired. This affects the availability and reliability of authenticated federation flows on nvd · 2026-08-19
- [NVD] CVE-2026-76244 — stigmem-node contains an insecure default configuration vulnerability that allows federation traffic to traverse networks without mTLS protection when non-loopback endpoints are enabled. Operators who explicitly disabled mTLS while binding federation to non-loopback addresses expnvd · 2026-08-19
- [NVD] CVE-2026-76242 — stigmem-node 0.9.0a1 accepts federation peer key material during peer registration without a separate administrator out-of-band fingerprint approval step. On nodes that accept federation peer registration over a network where initial registration can be intercepted or misdirectednvd · 2026-08-19
- [NVD] CVE-2026-76241 — stigmem-node 0.9.0a1 allows plugin signature enforcement to be disabled via a single configuration flag without a second explicit acknowledgment. If that setting is carried into an environment where plugin directories are writable by less-trusted users, unsigned (potentially malinvd · 2026-08-19
- [NVD] CVE-2026-76240 — stigmem-node 0.9.0a1 interpolates Postgres backend schema identifiers into SQL strings without defensive quoting. In the affected code path the schema value is operator-controlled, but the unsafe pattern could allow SQL injection if a schema name were derived from tenant, requestnvd · 2026-08-19
- [NVD] CVE-2026-76236 — stigmem-node before 0.9.0a12 contains a cross-tenant broken object level authorization (BOLA) flaw in the RTBF (right-to-be-forgotten) tombstone mechanism. issue_tombstone defaulted the tenant to "default" instead of the caller's tenant, allowing deletion records to be written tonvd · 2026-08-19
- [NVD] CVE-2026-43961 (HIGH 7.8) — A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can break out of the quoted context during mark/unmark operations, allowing arbitrary Vimscript execution. This can be leveraged to run shell commands with the privilegnvd · 2026-08-19
- When the Attacker Wears Your Logo: Detecting and Taking Down Impersonation at AI Speedcyble · 2026-08-19
- [incransom] BANGKOKCABLE posted to leak siteransomware_live · 2026-08-19
- [incransom] UNIPLASTICS.COM posted to leak siteransomware_live · 2026-08-19
- [incransom] CDGARVINLAW posted to leak siteransomware_live · 2026-08-19
- [incransom] EXEL posted to leak siteransomware_live · 2026-08-19
- Oracle Critical Patch Update, August 2026 Security Update Reviewqualys · 2026-08-19
- SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATsthehackernews · 2026-08-19
- July 2026: OpenAI Agent Incident, KDDI Breachsocradar_blog · 2026-08-19
- Atlassian security advisory (AV26-829)cccs_ca · 2026-08-19
- [qilin] Thrifty Building Supply posted to leak siteransomware_live · 2026-08-19
- [qilin] Estech posted to leak siteransomware_live · 2026-08-19
- [qilin] Constructora Jimenez posted to leak siteransomware_live · 2026-08-19
- [qilin] Movitecnica posted to leak siteransomware_live · 2026-08-19
- Defending Against an Active Threat to Siemens S7 Series PLCscisa_advisories · 2026-08-19
- Rapid7 and Licencias OnLine Partner to Accelerate Cybersecurity Maturity across Latin Americarapid7 · 2026-08-19
- CISA Adds One Known Exploited Vulnerability to Catalogcisa_advisories · 2026-08-19
- [krybit] www.mestojilemnice.cz posted to leak siteransomware_live · 2026-08-19
- [krybit] automotoresrosedal.com.ar posted to leak siteransomware_live · 2026-08-19
- [krybit] sipresitalia.it posted to leak siteransomware_live · 2026-08-19
- [krybit] www.hsi.info posted to leak siteransomware_live · 2026-08-19
- Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2Pthehackernews · 2026-08-19
- [qilin] WIS LOGISTICS posted to leak siteransomware_live · 2026-08-19
- [qilin] InVentry posted to leak siteransomware_live · 2026-08-19
- [qilin] Philippe Hottinguer Finance posted to leak siteransomware_live · 2026-08-19
- Phishing 3.0: The Fight Moves to Agent Versus Agentthehackernews · 2026-08-19
- StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Datathehackernews · 2026-08-19
- Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitationthehackernews · 2026-08-19
- [qilin] Medochemie posted to leak siteransomware_live · 2026-08-19
- [qilin] Smart Energies posted to leak siteransomware_live · 2026-08-19
- Scammers are using fake crypto AML checkers to drain your walletmalwarebytes_blog · 2026-08-19
- Update Chrome now: Two critical vulnerabilities fixedmalwarebytes_blog · 2026-08-19
- Telegram Applied for .gram: What It Means for the Threat Landscapesocradar_blog · 2026-08-19
- Describing attacks with crime script analysistalos · 2026-08-19
- Your polite reply to that text is worth $2 on the dark webmalwarebytes_blog · 2026-08-19
- [qilin] Integraduanas posted to leak siteransomware_live · 2026-08-19
- [threeam] mecasem.org posted to leak siteransomware_live · 2026-08-19
- [thegentlemen] Euroscreen posted to leak siteransomware_live · 2026-08-19
- [thegentlemen] CRASL posted to leak siteransomware_live · 2026-08-19
- [thegentlemen] Senvest Capital posted to leak siteransomware_live · 2026-08-19
- [thegentlemen] Roadvision Systems posted to leak siteransomware_live · 2026-08-19
- [thegentlemen] Babcock posted to leak siteransomware_live · 2026-08-19
- [Storm] American Contractors Insurance Group posted to leak siteransomware_live · 2026-08-19
- Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructurethehackernews · 2026-08-19
- Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Datathehackernews · 2026-08-19
- Risky Bulletin: Slovakia finds Russian backdoors on its speed camerasriskybiz_news · 2026-08-19
- Google Chrome Multiple Vulnerabilitieshkcert · 2026-08-19
- Mozilla Products Multiple Vulnerabilitieshkcert · 2026-08-19
- GitLab Multiple Vulnerabilitieshkcert · 2026-08-19
- Oracle Products Multiple Vulnerabilitieshkcert · 2026-08-19
- [direwolf] Photon Health, Inc. posted to leak siteransomware_live · 2026-08-19
- [direwolf] InfoFlo CRM posted to leak siteransomware_live · 2026-08-19
- [direwolf] PayUp posted to leak siteransomware_live · 2026-08-19
- [direwolf] Lifesum posted to leak siteransomware_live · 2026-08-19
- Oracle August 2026 Critical Security Patch Update Addresses 925 CVEstenable · 2026-08-19
- Re: GNU Inetutils talkd buffer overflow with long DNS names.oss_sec · 2026-08-19
- [CISA KEV] CVE-2026-64849 — MLflow MLflow: MLflow Server-Side Request Forgery Vulnerabilitycisa_kev · 2026-08-19
- [SilentRansomGroup] Troutman Pepper Locke posted to leak siteransomware_live · 2026-08-18
- [GHSA] GHSA-rh9c-rqvg-f7pr (medium) — linuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across sudoers-whitelisted plugins (LPE)github_advisories · 2026-08-18
- [NVD] CVE-2026-71067 (HIGH 8.8) — Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLnvd · 2026-08-18
- [NVD] CVE-2026-71065 (CRITICAL 9.3) — Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While thenvd · 2026-08-18
- [NVD] CVE-2026-71064 (CRITICAL 9.6) — Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment nvd · 2026-08-18
- [NVD] CVE-2026-71035 (HIGH 8.1) — Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTnvd · 2026-08-18
- [NVD] CVE-2026-71034 (HIGH 7.5) — Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAPnvd · 2026-08-18
- [NVD] CVE-2026-71033 (MEDIUM 5.5) — Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with nvd · 2026-08-18
- [NVD] CVE-2026-71032 (HIGH 7.2) — Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker withnvd · 2026-08-18
- [NVD] CVE-2026-71031 (MEDIUM 6.1) — Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker withnvd · 2026-08-18
- [NVD] CVE-2026-71030 (HIGH 7.2) — Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker withnvd · 2026-08-18
- [NVD] CVE-2026-71029 (MEDIUM 6.8) — Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Whinvd · 2026-08-18
- [NVD] CVE-2026-71028 (HIGH 7.8) — Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with nvd · 2026-08-18
- [NVD] CVE-2026-71027 (HIGH 7.6) — Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with nvd · 2026-08-18
- [NVD] CVE-2026-71026 (CRITICAL 9.1) — Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker withnvd · 2026-08-18
- [NVD] CVE-2026-71025 (MEDIUM 6.1) — Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker withnvd · 2026-08-18
- [NVD] CVE-2026-71018 (HIGH 8.2) — Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker withnvd · 2026-08-18
- [NVD] CVE-2026-71016 (HIGH 8.2) — Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker withnvd · 2026-08-18
- [NVD] CVE-2026-71015 (CRITICAL 9.1) — Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker withnvd · 2026-08-18
- [NVD] CVE-2026-71014 (CRITICAL 9.1) — Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker withnvd · 2026-08-18
- [NVD] CVE-2026-71013 (MEDIUM 6.0) — Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hynvd · 2026-08-18
- [NVD] CVE-2026-70990 (MEDIUM 6.8) — Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with nvd · 2026-08-18
- [NVD] CVE-2026-70979 (CRITICAL 9.1) — Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with nenvd · 2026-08-18
- [NVD] CVE-2026-70978 (CRITICAL 9.1) — Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with nenvd · 2026-08-18
- [NVD] CVE-2026-70977 (CRITICAL 9.1) — Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with nenvd · 2026-08-18
- [NVD] CVE-2026-70976 (CRITICAL 9.1) — Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with nenvd · 2026-08-18
- [NVD] CVE-2026-70975 (MEDIUM 6.5) — Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oraclenvd · 2026-08-18
- [NVD] CVE-2026-70974 (MEDIUM 5.3) — Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracnvd · 2026-08-18
- [NVD] CVE-2026-70973 (HIGH 7.5) — Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access nvd · 2026-08-18
- [NVD] CVE-2026-70960 (HIGH 7.6) — Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oraclenvd · 2026-08-18
- [NVD] CVE-2026-70959 (HIGH 8.1) — Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access vinvd · 2026-08-18
- [NVD] CVE-2026-70958 (CRITICAL 9.6) — Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access vnvd · 2026-08-18
- [NVD] CVE-2026-70957 (HIGH 8.1) — Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access vinvd · 2026-08-18
- [NVD] CVE-2026-70956 (HIGH 8.8) — Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access vinvd · 2026-08-18
- [NVD] CVE-2026-70955 (HIGH 7.5) — Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segnvd · 2026-08-18
- [NVD] CVE-2026-70954 (CRITICAL 9.8) — Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracnvd · 2026-08-18
- [NVD] CVE-2026-70953 (CRITICAL 9.8) — Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oraclnvd · 2026-08-18