THREAT OPS › Threat News
Threat Intelligence News
11790 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- HPE security advisory (AV26-928)cccs_ca · 2026-09-16
- House passes bill to equip local law enforcement with scam-fighting toolsthe_record · 2026-09-16
- Data Broker Radaris Loses Domains in Privacy Fightkrebs · 2026-09-16
- [Control Systems] Phoenix Contact security advisory (AV26-927)cccs_ca · 2026-09-16
- [kairos] Leisure Coast Kitchens posted to leak siteransomware_live · 2026-09-16
- Google security advisory (AV26-926)cccs_ca · 2026-09-16
- [qilin] Reddrop Group posted to leak siteransomware_live · 2026-09-16
- [qilin] In The Company of Huskies posted to leak siteransomware_live · 2026-09-16
- CTEM Technology Evaluation Scorecardhorizon3 · 2026-09-16
- CISO’s CTEM Evaluation Checklisthorizon3 · 2026-09-16
- [Wallstreet] Odyssey Charter School, Inc. posted to leak siteransomware_live · 2026-09-16
- [Wallstreet] Roshd Sanat posted to leak siteransomware_live · 2026-09-16
- [GHSA] GHSA-r2pf-9cw4-5j65 (high) — node-opcua: TCP Socket Leak (FIN-WAIT-2) via keepalive reconnection cycle - Resource Exhaustiongithub_advisories · 2026-09-16
- CVE-2026-86218 | N-able N-central Pre-Authentication Remote Code Execution Vulnerabilityhorizon3 · 2026-09-16
- Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software SSL VPN Denial of Service Vulnerabilitycisco_psirt · 2026-09-16
- CVE-2026-89775: Guest-to-Host Escape in KVM/arm64oss_sec · 2026-09-16
- Ghostwriter v7.3.0: A Fresh New Lookspecterops · 2026-09-16
- Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software for Secure Firewall 3100 and 4200 Series DTLS Denial of Service Vulnerabilitycisco_psirt · 2026-09-16
- Cisco Secure Firewall Management Center Software Java Deserialization Remote Code Execution Vulnerabilitycisco_psirt · 2026-09-16
- Cisco Identity Services Engine Remote Code Execution Vulnerabilitiescisco_psirt · 2026-09-16
- Cisco Identity Services Engine Authenticated Remote Code Execution and API Vulnerabilitiescisco_psirt · 2026-09-16
- Cisco Identity Services Engine Vulnerabilitiescisco_psirt · 2026-09-16
- Cisco Identity Services Engine RADIUS Denial of Service Vulnerabilitycisco_psirt · 2026-09-16
- Cisco Secure Firewall Management Center and Secure Firewall Threat Defense Software sftunnel Vulnerabilitiescisco_psirt · 2026-09-16
- Cisco Secure Firewall Threat Defense Software TLS 1.3 Denial of Service Vulnerabilitycisco_psirt · 2026-09-16
- Cisco Identity Services Engine 802.1X Session Hijack and Information Disclosure Vulnerabilitiescisco_psirt · 2026-09-16
- Cisco Secure Firewall Management Center Software Vulnerabilitiescisco_psirt · 2026-09-16
- Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026cisco_psirt · 2026-09-16
- Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software TCP DNS Denial of Service Vulnerabilitycisco_psirt · 2026-09-16
- Cisco ThousandEyes Virtual Appliance Authenticated Web Interface Command Injection Vulnerabilitycisco_psirt · 2026-09-16
- Cisco Secure Firewall Threat Defense Software Snort 2 SSL/TLS Denial of Service Vulnerabilitycisco_psirt · 2026-09-16
- Cisco Identity Services Engine Hardening Release: September 2026cisco_psirt · 2026-09-16
- Cisco Identity Services Engine Multiple Path Traversal Vulnerabilitiescisco_psirt · 2026-09-16
- Cisco Identity Services Engine Cross-Site Scripting Vulnerabilitycisco_psirt · 2026-09-16
- Cisco Identity Services Engine Command Injection Vulnerabilitiescisco_psirt · 2026-09-16
- Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Object Group Access Control List Bypass Vulnerabilitiescisco_psirt · 2026-09-16
- Cisco Identity Services Engine Authentication Bypass Vulnerabilitycisco_psirt · 2026-09-16
- Cisco Identity Services Engine Authorization Bypass Vulnerabilitiescisco_psirt · 2026-09-16
- Cisco Secure Firewall Management Center Software Vulnerabilitiescisco_psirt · 2026-09-16
- Cisco Nexus Dashboard Software Security Hardening Release: September 2026cisco_psirt · 2026-09-16
- Cisco BroadWorks CommPilot Application Software Authorization Bypass Vulnerabilitycisco_psirt · 2026-09-16
- Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software EIGRP Denial of Service Vulnerabilitycisco_psirt · 2026-09-16
- Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Logging Denial of Service Vulnerabilitycisco_psirt · 2026-09-16
- Cisco Identity Services Engine Authentication Bypass Vulnerabilitiescisco_psirt · 2026-09-16
- Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IKEv2 Certificate Authentication Denial of Service Vulnerabilitycisco_psirt · 2026-09-16
- Cisco Identity Services Engine SQL and HQL Injection Vulnerabilitiescisco_psirt · 2026-09-16
- Cisco Identity Services Engine SQL Injection Vulnerabilitiescisco_psirt · 2026-09-16
- Cisco Secure Firewall Management Center Software sftunnel Root Arbitrary Code Execution Vulnerabilitycisco_psirt · 2026-09-16
- Cisco Identity Services Engine Information Disclosure Vulnerabilitycisco_psirt · 2026-09-16
- Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Executionthehackernews · 2026-09-16
- [GHSA] GHSA-pg97-jvmf-qfvc (high) — djust has Cross-Site Request Forgery on the Server-Sent-Events transport: a cross-origin page can drive a victim-authenticated SSE sessiongithub_advisories · 2026-09-16
- CVE-2026-68536: Apache MyFaces: Server-Side Request Forgery / Local File Inclusion Vulnerabilityoss_sec · 2026-09-16
- CVE-2026-76646: Apache MyFaces: Denial of Service via Unbounded Request Parsingoss_sec · 2026-09-16
- [GHSA] GHSA-5h8j-6crg-7rmw (critical) — LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploygithub_advisories · 2026-09-16
- [GHSA] GHSA-3492-cvg7-9mr2 (high) — djust: Multi-tenant isolation fails open on the WebSocket/SSE path, disclosing other tenants' datagithub_advisories · 2026-09-16
- Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipersthehackernews · 2026-09-16
- CVE-2026-87976: Apache NiFi Registry: Improper Limitation of Pathname in Persisted Extension Bundlesoss_sec · 2026-09-16
- CVE-2026-86089: Apache NiFi: Missing Process Group Authorization for Connector Migrationoss_sec · 2026-09-16
- CVE-2026-82561: Apache NiFi: Missing Authorization for Components Referenced in Flow Update Methodsoss_sec · 2026-09-16
- CVE-2026-81866: Apache NiFi: Missing Authorization for Assets and Secrets Referenced by Connector Configurationoss_sec · 2026-09-16
- CVE-2026-70469: Apache NiFi: Improper Handling of Case Sensitivity for Content-Encoding in HTTP Requestsoss_sec · 2026-09-16
- Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCHzscaler_threatlabz · 2026-09-16
- Re: Retrospective by 'gpg.fail' authorsoss_sec · 2026-09-16
- Multiple vulnerabilities in Jenkins pluginsoss_sec · 2026-09-16
- ISC has disclosed fourteen vulnerabilities in BIND 9 (CVE-2026-19033, CVE-2026-19662, CVE-2026-19666, CVE-2026-19667, CVE-2026-19668, CVE-2026-19941, CVE-2026-75029, CVE-2026-76163, CVE-2026-77119, CVE-2026-77692, CVE-2026-78301, CVE-2026-80274, CVE-2026-81563, CVE-2026-81736)oss_sec · 2026-09-16
- [qilin] Thorndale Foundation posted to leak siteransomware_live · 2026-09-16
- [qilin] Thema Foundries posted to leak siteransomware_live · 2026-09-16
- Unbound: 1.26.1 addresses multiple CVE itemsoss_sec · 2026-09-16
- Ransom & Dark Web Issues Week 3, September 2026ahnlab · 2026-09-16
- [akira] Blossomland Accounting posted to leak siteransomware_live · 2026-09-16
- [akira] Bee Maid Honey posted to leak siteransomware_live · 2026-09-16
- One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claudethehackernews · 2026-09-16
- [akira] Manders posted to leak siteransomware_live · 2026-09-16
- Oracle Critical Security Patch Update, September 2026 Reviewqualys · 2026-09-16
- CVE-2026-76461: Cisco Email Gateway Flaw Exploitedsocradar_blog · 2026-09-16
- [GHSA] GHSA-cc7c-9jff-58wj (high) — djust: Client mass-assignment of arbitrary view attributes via the default dj-model update_model handlergithub_advisories · 2026-09-16
- [GHSA] GHSA-v8pv-4842-x354 (high) — OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOSgithub_advisories · 2026-09-16
- [arcusmedia] ARDA posted to leak siteransomware_live · 2026-09-16
- [GHSA] GHSA-8g2f-g3gq-5rjv (high) — djust's observability endpoints are network-exposed: the localhost gate is an opt-in middleware the docs omit, and the views enforce only DEBUGgithub_advisories · 2026-09-16
- [GHSA] GHSA-cv3r-c5h8-f4g5 (critical) — @zereight/mcp-gitlab: Unauthenticated arbitrary file read via `upload_markdown` enables PAT exfiltration and full account takeovergithub_advisories · 2026-09-16
- Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositoriesthehackernews · 2026-09-16
- [Panzer] Nielsen Design posted to leak siteransomware_live · 2026-09-16
- Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fixthehackernews · 2026-09-16
- TrustSink: How a Rogue External MFA Provider Steals Passwordsvaronis_blog · 2026-09-16
- CISA Adds One Known Exploited Vulnerability to Catalogcisa_advisories · 2026-09-16
- Using Cyber Decoys to Strengthen Detection and Responsecisa_advisories · 2026-09-16
- CISA Adds Two Known Exploited Vulnerabilities to Catalogcisa_advisories · 2026-09-16
- N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Securitythehackernews · 2026-09-16
- CVE-2026-27540 WooCommerce Flaw Exploitedsocradar_blog · 2026-09-16
- Discernment Deleted: Inside the Operation Server of BlackHatSect0r && DXQRTXXsocradar_blog · 2026-09-16
- Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitationthehackernews · 2026-09-16
- Threat Intelligence Alone Won't Close the Exploitation Gapthehackernews · 2026-09-16
- Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacksthehackernews · 2026-09-16
- Google Pixel owners urged to patch actively exploited modem flawmalwarebytes_blog · 2026-09-16
- Securing the unpatchable in an age of AI-driven vulnerabilitiestalos · 2026-09-16
- Agents at Large | Tracing Illicit OpenAI Agent Activity on Hugging Facesentinelone · 2026-09-16
- NightEagle targets Russian companiessecurelist · 2026-09-16
- Atomic macOS (AMOS) Stealer Activityunit42 · 2026-09-16
- AI helps scammers build convincing antivirus renewal pagesmalwarebytes_blog · 2026-09-16
- We’re In: Enterprise Commitment to Sustainable Package Registriesopenssf_blog · 2026-09-16