THREAT OPS › Threat News
Threat Intelligence News
11795 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- Staying Ahead of Adversarial AI Through Agentic Source Code Reviewmandiant_gti · 2026-08-18
- MLflow Bug Actively Exploited to Steal Credentialsduo_decipher · 2026-08-18
- BeyondTrust security advisory (AV26-826)cccs_ca · 2026-08-18
- [shinyhunters] Logitech/ Streamlabs posted to leak siteransomware_live · 2026-08-18
- Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtectcheckpoint_research · 2026-08-18
- JetBrains security advisory (AV26-825)cccs_ca · 2026-08-18
- CoSnitch: When Your AI Assistant Becomes Its Own Whistleblowervaronis_blog · 2026-08-18
- New Report: AI threats are here. Why Q2 2026 signals the end of traditional patch cyclesrapid7 · 2026-08-18
- AI "Mind Viruses" Can Spread Between Agents Through Persistent Prompt Filesthehackernews · 2026-08-18
- TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networksthehackernews · 2026-08-18
- Siemens Simcenter Nastrancisa_advisories · 2026-08-18
- CISA Adds Four Known Exploited Vulnerabilities to Catalogcisa_advisories · 2026-08-18
- Siemens Simcenter Nastrancisa_advisories · 2026-08-18
- CISA Malcolmcisa_advisories · 2026-08-18
- [qilin] Berlin Brandenburgische Wohnungsbaugenossenschaft posted to leak siteransomware_live · 2026-08-18
- Can NVD Modernization Keep Pace With AI?socradar_blog · 2026-08-18
- 16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Walletsthehackernews · 2026-08-18
- One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025thehackernews · 2026-08-18
- Be careful what you put in “anyone with the link” Google Docsmalwarebytes_blog · 2026-08-18
- LLMs and Contextual Integrityschneier · 2026-08-18
- Heights Finance data breach: What customers need to knowmalwarebytes_blog · 2026-08-18
- [incransom] SpearFin Ltd posted to leak siteransomware_live · 2026-08-18
- [incransom] ssf-int.com ssf-ing.de posted to leak siteransomware_live · 2026-08-18
- [incransom] nyklawfirm.com nyk.ae posted to leak siteransomware_live · 2026-08-18
- Securing Software at the Speed of AI: What Four Years of Data Revealsonatype · 2026-08-18
- SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customersthehackernews · 2026-08-18
- [incransom] Foresee Pharmaceuticals posted to leak siteransomware_live · 2026-08-18
- [emperador] Prefeitura Municipal de Arcos posted to leak siteransomware_live · 2026-08-18
- CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCEthehackernews · 2026-08-18
- Security advisory: Pre-authentication RCE (SQL injection) in XPressEntry 3.7.7454 (Telaeris Inc)fulldisclosure · 2026-08-18
- Security advisory: Authenticated RCE (SQL injection) in Scrutinizer 19.7.0 (Plixer)fulldisclosure · 2026-08-18
- Security advisory: Pre-authentication SYSTEM RCE (Zip-Slip plugin planting) in Output Messenger Server 2.0.x (>= 2.0.63) (Srimax Software (Output Technology))fulldisclosure · 2026-08-18
- Security advisory: Pre-authentication RCE (arbitrary file write) in RapidDeploy 5.2.2 (MidVision)fulldisclosure · 2026-08-18
- Security advisory: Authenticated RCE (second-order SQL injection) in Lansweeper 12.2.1.0 (web reports 12.2.1.6) (Lansweeper)fulldisclosure · 2026-08-18
- Security advisory: Authenticated RCE (command injection) in Kerio Connect 10.0.9 Patch 2 (build 10320) (GFI Software)fulldisclosure · 2026-08-18
- Security advisory: Pre-authentication RCE (default credentials + path traversal) in PulseNET Enterprise 6.0.3 (build 6975) (GE Vernova)fulldisclosure · 2026-08-18
- Security advisory: Pre-authentication RCE (BinaryFormatter deserialization) in Cinegy Cinegize 2026-02-05 installer (Cinegy GmbH)fulldisclosure · 2026-08-18
- Security advisory: Pre-authentication RCE in Wyn Enterprise 9.1.00145.0 (Mescius (GrapeCity))fulldisclosure · 2026-08-18
- Security advisory: Pre-authentication RCE (default credentials) in ObjectDB 2.9.5 server mode (ObjectDB Software)fulldisclosure · 2026-08-18
- Security advisory: Pre-authentication RCE in nanoDLP stable build #10729 (Nano3Dtech)fulldisclosure · 2026-08-18
- Security advisory: Pre-authentication SYSTEM RCE in MAPS SCADA 4.0.5.5 (Adroit Technologies)fulldisclosure · 2026-08-18
- Security advisory: Pre-authentication RCE in Confluent Platform (ksqlDB) 7.9.1-ce (Confluent, Inc.)fulldisclosure · 2026-08-18
- Security advisory: Pre-authentication SYSTEM RCE in iMonnit Express 4.0.5.5 (Monnit / iMonnit)fulldisclosure · 2026-08-18
- Security advisory: Pre-authentication RCE in Ontotext GraphDB 11.4.3 Free edition (Ontotext / Graphwise)fulldisclosure · 2026-08-18
- AI slop "Combined chain advisory — fallback.efi/SBAT/memdisk bypass"oss_sec · 2026-08-18
- [Storm] Valor Defense Solutions, Inc posted to leak siteransomware_live · 2026-08-18
- [Storm] Standard Tool & Die posted to leak siteransomware_live · 2026-08-18
- [Storm] Westco Motors Cairns posted to leak siteransomware_live · 2026-08-18
- [Storm] WindRose Health Network posted to leak siteransomware_live · 2026-08-18
- [Storm] Penfold posted to leak siteransomware_live · 2026-08-18
- [Storm] Ramsey Bros posted to leak siteransomware_live · 2026-08-18
- [lockbit5] terra-petra.com posted to leak siteransomware_live · 2026-08-18
- [anubis] Scholle IPN / SIG posted to leak siteransomware_live · 2026-08-18
- [AuditTeam] De***up posted to leak siteransomware_live · 2026-08-18
- Apple Products Multiple Vulnerabilitieshkcert · 2026-08-18
- [incransom] SD Associates Sdn Bhd posted to leak siteransomware_live · 2026-08-18
- [incransom] Third Coast Bancshares posted to leak siteransomware_live · 2026-08-18
- [CISA KEV] CVE-2025-62593 — Ray-Project Ray: Ray-Project Ray Code Injection Vulnerabilitycisa_kev · 2026-08-18
- PurpleDelta's Fraudulent Employment Operationsrecordedfuture · 2026-08-18
- [CISA KEV] CVE-2026-59310 — Broadcom VMware vCenter: Broadcom VMware vCenter Path Traversal Vulnerabilitycisa_kev · 2026-08-18
- [CISA KEV] CVE-2026-55040 — Microsoft SharePoint: Microsoft SharePoint Weak Authentication Vulnerabilitycisa_kev · 2026-08-18
- [CISA KEV] CVE-2026-65400 — Apple macOS: Apple macOS Improper Authentication Vulnerabilitycisa_kev · 2026-08-18
- CopyCop Targets AI Investment in Armeniarecordedfuture · 2026-08-18
- [CISA KEV] CVE-2026-33824 — Microsoft Internet Key Exchange (IKE) Service Extensions: Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerabilitycisa_kev · 2026-08-18
- [NVD] CVE-2026-56677 (HIGH 8.6) — 9Router is an AI router & token saver. In 0.5.4 and earlier, the POST /api/auth/oidc/test endpoint in src/app/api/auth/oidc/test/route.js passes the user-controlled issuerUrl parameter to fetchOidcDiscovery() in src/lib/auth/oidc.js without restricting private or loopback destinanvd · 2026-08-17
- APPLE-SA-08-17-2026-2 iOS 18.7.10 and iPadOS 18.7.10fulldisclosure · 2026-08-17
- [GHSA] GHSA-gqch-g4w5-7qcw (high) — MLflow: CreateModelVersion source validation does not check READ permission on referenced run_idgithub_advisories · 2026-08-17
- [GHSA] GHSA-3p64-6gvh-82v5 (medium) — MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-authgithub_advisories · 2026-08-17
- [GHSA] GHSA-7gwp-5pfp-969j (critical) — MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)github_advisories · 2026-08-17
- [GHSA] GHSA-8g4w-4ffg-8vgx (high) — 9Router: Authenticated Server-Side Request Forgery (SSRF) via OIDC Provider Test Endpointgithub_advisories · 2026-08-17
- [GHSA] GHSA-p28p-j94q-pg32 (high) — http4k: `DigestAuthProvider.verify` did not bind to request URIgithub_advisories · 2026-08-17
- Securing the Unsecurable: OT, IoT, and the Factory Floorzscaler_threatlabz · 2026-08-17
- [GHSA] GHSA-vxxm-wwqh-mh47 (medium) — http4k: `DigestAuthProvider.verify` ignored configured algorithm and did not bind to request URIgithub_advisories · 2026-08-17
- [GHSA] GHSA-8qf9-62x2-82pp (medium) — chrome-devtools-mcp: validatePath() does not canonicalize symlinks before enforcing rootsgithub_advisories · 2026-08-17
- [GHSA] GHSA-mpwr-8vm7-h73f (medium) — package pkcs12: Authentication bypass in Decode functionsgithub_advisories · 2026-08-17
- [GHSA] GHSA-gc95-3vw8-vg43 (high) — docx4j: Stack Overflow via Cyclic `w:basedOn` Style Chain leads to Denial of Servicegithub_advisories · 2026-08-17
- [GHSA] GHSA-g4w2-6h2r-3m3w (high) — http4k: Unbounded gzip decompression in `ServerFilters.GZip` / `RequestFilters.GunZip` allowed memory-exhaustion DoSgithub_advisories · 2026-08-17
- [GHSA] GHSA-j659-8xh6-5pq5 (high) — atomic-agents-stack: Parallel helper/delegate batch reserves $0 for models absent from the pricing table, bypassing the cost-cap fan-out guardgithub_advisories · 2026-08-17
- [GHSA] GHSA-xhcr-cqfr-m3hv (high) — atomic-agents-stack: HTTP MCP catalog accepts cleartext http and spawns catalog-supplied commands (MITM to RCE)github_advisories · 2026-08-17
- [qilin] GSW Gemeinschaftsstadtwerke GmbH posted to leak siteransomware_live · 2026-08-17
- [qilin] White-Daters & Associates, Inc posted to leak siteransomware_live · 2026-08-17
- [qilin] The University of the West Indies posted to leak siteransomware_live · 2026-08-17
- [qilin] EmpireWorks posted to leak siteransomware_live · 2026-08-17
- [NVD] CVE-2026-71518 (HIGH 7.5) — Typemill before 2.26.0 contains an authorization bypass vulnerability in the media file download route that allows unauthenticated attackers to access restricted files by submitting path-equivalent URL variants. Attackers can substitute normalized path forms such as dot-slash prenvd · 2026-08-17
- [NVD] CVE-2026-66795 (CRITICAL 9.9) — A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSRs, specifically by not inspecting the signer name or decoding the PEM-encoded x509 CSR. This vulnerability allows a privileged servnvd · 2026-08-17
- Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projectsthehackernews · 2026-08-17
- Zscaler CXO Monthly Roundup | July 2026zscaler_threatlabz · 2026-08-17
- [play] Bridgeport Capital Services posted to leak siteransomware_live · 2026-08-17
- [play] Sam Pack Auto Group posted to leak siteransomware_live · 2026-08-17
- [play] Woodhaven Association posted to leak siteransomware_live · 2026-08-17
- [NVD] CVE-2026-74234 (HIGH 7.7) — Legora before 2026-08-14 contains a cross-site scripting vulnerability that allows attackers to achieve arbitrary JavaScript execution in a victim's browser by embedding a Mermaid block prefixed with a gray-matter JavaScript front-matter directive, causing the front-matter parsernvd · 2026-08-17
- Between Two Nerds: The eye of Sauronriskybiz_news · 2026-08-17
- Re: [OSSA-2026-035] OpenStack Octavia: Unauthorized QoS policy deletion lock (CVE-2026-74248) errata 1oss_sec · 2026-08-17
- [NVD] CVE-2026-66792 (CRITICAL 9.9) — A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Successful exploitation grants the attacker the ability to deploynvd · 2026-08-17
- Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injectionthehackernews · 2026-08-17
- [xpl0itrs] BMW Group posted to leak siteransomware_live · 2026-08-17
- [incransom] Lansing Urgent Care posted to leak siteransomware_live · 2026-08-17
- [GHSA] GHSA-8c42-7qj2-3j46 (medium) — Netty Vulnerable to Cache Poisoning and Information Disclosure via CORS Vary Header Overwritegithub_advisories · 2026-08-17
- Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploadsthehackernews · 2026-08-17
- [Global Secret Group] The Rubber Group posted to leak siteransomware_live · 2026-08-17