THREAT OPS › Threat News
Threat Intelligence News
11800 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [xpl0itrs] BMW Group posted to leak siteransomware_live · 2026-08-17
- [incransom] Lansing Urgent Care posted to leak siteransomware_live · 2026-08-17
- [GHSA] GHSA-8c42-7qj2-3j46 (medium) — Netty Vulnerable to Cache Poisoning and Information Disclosure via CORS Vary Header Overwritegithub_advisories · 2026-08-17
- Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploadsthehackernews · 2026-08-17
- [Global Secret Group] The Rubber Group posted to leak siteransomware_live · 2026-08-17
- Progress security advisory (AV26-824)cccs_ca · 2026-08-17
- Call for Applications: Information Controls Research Program 2026citizenlab · 2026-08-17
- [GHSA] GHSA-2qj4-mmr9-4v2f (high) — Netty: Memory Exhaustion in SctpMessageCompletionHandlergithub_advisories · 2026-08-17
- [GHSA] GHSA-fhgh-wq4q-r37x (high) — uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is setgithub_advisories · 2026-08-17
- [GHSA] GHSA-prg7-hcfm-mfcr (high) — sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial of Service)github_advisories · 2026-08-17
- [GHSA] GHSA-pwgv-4x5q-6m9f (high) — sqlparse: TokenList.__init__ materializes O(subtree) value per group, causing CPU DoS before depth/token caps triggergithub_advisories · 2026-08-17
- [GHSA] GHSA-2jp7-wwpg-3p9w (high) — Etherpad has stored XSS in HTML export via unescaped attribute-pool valuesgithub_advisories · 2026-08-17
- [GHSA] GHSA-92hr-gmr6-h8cp (medium) — Etherpad addressed weak token RNG, login timing, plugin path handling, API request handlinggithub_advisories · 2026-08-17
- [GHSA] GHSA-m6jg-wr9m-cg2f (medium) — uniget CLI has Path Traversal in Hook Files - Directory Escape Vulnerabilitygithub_advisories · 2026-08-17
- [GHSA] GHSA-qmcq-xw74-w667 (medium) — uniget CLI has an EDITOR Command Injectiongithub_advisories · 2026-08-17
- Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Trafficthehackernews · 2026-08-17
- [GHSA] GHSA-v836-6xw4-9cx3 (high) — vm2 has Memory Exhaustion DoS via bufferAllocLimit Bypassgithub_advisories · 2026-08-17
- [GHSA] GHSA-m5w8-4gq2-6f8x (critical) — vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)github_advisories · 2026-08-17
- [GHSA] GHSA-cfcw-xp6x-25gj (critical) — vm2: Sandbox Breakout Using Dangerous Host Proto Mutatorsgithub_advisories · 2026-08-17
- [GHSA] GHSA-m283-3h24-438v (critical) — VM2 has Missing Error.cause Sanitization that Enables Sandbox Escape to RCEgithub_advisories · 2026-08-17
- [GHSA] GHSA-gmc2-2x9w-cgh9 (high) — vm2's bufferAllocLimit cap bypassed by Buffer.concat and Buffer.from arrayLikegithub_advisories · 2026-08-17
- [Panzer] DL E&C posted to leak siteransomware_live · 2026-08-17
- [Global Secret Group] 4M REALTY COMPANY posted to leak siteransomware_live · 2026-08-17
- [GHSA] GHSA-f2ff-p2ww-7p4p (high) — sqlparse: Quadratic O(n²) DoS in group_commentsgithub_advisories · 2026-08-17
- [GHSA] GHSA-4h34-v6r8-mmjc (medium) — Glances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/configgithub_advisories · 2026-08-17
- [GHSA] GHSA-59fj-m2j6-hcxh (high) — Glances: `--disable-config-exec` does not cover on-alert action commands (incomplete fix of CVE-2026-53925)github_advisories · 2026-08-17
- [GHSA] GHSA-73wf-9vmv-5pv9 (high) — Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdline') → OS command injectiongithub_advisories · 2026-08-17
- [GHSA] GHSA-3496-9g83-7v6x (medium) — sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashesgithub_advisories · 2026-08-17
- 600,000 WordPress Sites Affected by Arbitrary File Upload Vulnerability in Forminator Forms WordPress Pluginwordfence · 2026-08-17
- [GHSA] GHSA-fp27-88fp-2phg (medium) — Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin Allowlist Containing the Wildcardgithub_advisories · 2026-08-17
- [GHSA] GHSA-8394-6f8r-whxg (medium) — Terragrunt: Arbitrary File Deletion via Malicious Module Manifestgithub_advisories · 2026-08-17
- [GHSA] GHSA-qcpp-8x79-hhp3 (high) — Glances has a command injection bypass of action-template sanitizer via cross-field shell-operator reconstructiongithub_advisories · 2026-08-17
- [GHSA] GHSA-j6gc-4893-qwmp (medium) — New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypassgithub_advisories · 2026-08-17
- [GHSA] GHSA-8r8v-xf7q-rcpr (critical) — New API: Integer overflow in quota billing yields negative charges (self-crediting)github_advisories · 2026-08-17
- [GHSA] GHSA-p845-629j-rcj6 (medium) — New API: Admin can reset passkeys for same-level or higher-privileged usersgithub_advisories · 2026-08-17
- [GHSA] GHSA-v828-m3pf-vq9q (high) — New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logginggithub_advisories · 2026-08-17
- [GHSA] GHSA-6x2c-phff-wx57 (critical) — New API: User List API Leaks Root User Access Token Leading to Privilege Escalationgithub_advisories · 2026-08-17
- [aurora] Planungsgruppe M+M AG posted to leak siteransomware_live · 2026-08-17
- [NVD] CVE-2026-64866 — New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. From 0.9.1.3 until 1.0.0-rc.7, AdminResetPasskey in controller/passkey.go lacks the canManageTargetRole authorization check for DELETE /api/user/:id/reset_passkey, allowing a nvd · 2026-08-17
- [NVD] CVE-2026-64865 — New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.16, repeated PUT /api/user/self requests that update language or sidebar_modules can race relay billing because controller/user.go calls User.Update and updanvd · 2026-08-17
- [NVD] CVE-2026-64859 (CRITICAL 9.1) — New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.7, the admin user list and user lookup APIs, including GET /api/user/, return User.AccessToken as access_token because User model objects are serialized aftenvd · 2026-08-17
- [NVD] CVE-2026-59829 (MEDIUM 4.3) — Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.1, on sites with category group moderation enabled, the review queue could include an excerpt (and permalink) of the private message attached to a flag, even when the reviewing catenvd · 2026-08-17
- [NVD] CVE-2026-55704 (MEDIUM 4.3) — Discourse is an open-source discussion platform. Prior o 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, users who were allowed to view a group’s activity, but were not permitted to see shared drafts, could still receive shared-draft entries through the group posts and group mentionsnvd · 2026-08-17
- [NVD] CVE-2026-55674 (CRITICAL 9.3) — Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an unauthenticated attacker could send a single request with a crafted color_scheme_id (or dark_scheme_id) cookie to inject arbitrary HTML into a Discourse page. Because the cooknvd · 2026-08-17
- [NVD] CVE-2026-53960 (MEDIUM 5.3) — Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, hidden or otherwise unviewable first-post content was leaked as an excerpt in the publicly-served Q&A (QAPage) JSON-LD structured data, exposing it to any unauthenticated visitornvd · 2026-08-17
- [NVD] CVE-2025-27772 — UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the `/new_run` endpoint is vulnerable to remote code execution via the `checks` and `metadata` parameters. Any user that has access to UpTrain and a valid authenticanvd · 2026-08-17
- [NVD] CVE-2025-27771 — UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the `/add_prompts` endpoint is vulnerable to remote code execution via the `checks` and `metadata` parameters. Any user that has access to UpTrain and a valid authennvd · 2026-08-17
- [NVD] CVE-2025-27770 — UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the `/create_project` endpoint is vulnerable to remote code execution via the `checks` and `metadata` parameters. Any user that has access to UpTrain and a valid autnvd · 2026-08-17
- [NVD] CVE-2025-27621 — UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the UpTrain backend creates a new default user with a static username, where the username is also used as the default API key. The UpTrain backend also has an open Cnvd · 2026-08-17
- Apple security advisory (AV26-823)cccs_ca · 2026-08-17
- LyX security advisoryoss_sec · 2026-08-17
- [NVD] CVE-2026-73851 — Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.34.0, an attacker who controls or tampers with the OpenAPI description consumed by Kiota can supply a file reference that resolves outside the manifest package (e.g. ../../../../etc/passwd, an absolute panvd · 2026-08-17
- Detecting cloud ransomware in Azure with Tenable One’s cloud detection and response capabilitiestenable · 2026-08-17
- [direwolf] Arizona State University (ASU) posted to leak siteransomware_live · 2026-08-17
- [direwolf] Wishfully Studios posted to leak siteransomware_live · 2026-08-17
- Apple Screen Sharing Security, (Mon, Aug 17th)sans_isc · 2026-08-17
- Brand Impersonation Takedown: From Whack-a-Mole to Managed Responsecyble · 2026-08-17
- [direwolf] Mighty Kingdom posted to leak siteransomware_live · 2026-08-17
- [direwolf] Eva AI Limited posted to leak siteransomware_live · 2026-08-17
- [aurora] Natco Home Group posted to leak siteransomware_live · 2026-08-17
- Citrix security advisory (AV26-645) – Update 2cccs_ca · 2026-08-17
- C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2zscaler_threatlabz · 2026-08-17
- Microsoft Edge security advisory (AV26-822)cccs_ca · 2026-08-17
- Compromising the Developer: How Modern Dependency Culture Reshaped the Supply Chain Threat Landscapeeclecticiq · 2026-08-17
- 17th August – Threat Intelligence Reportcheckpoint_research · 2026-08-17
- [GHSA] GHSA-m44r-7c5h-m6mj (high) — Medplum: Improper Validation of Redirect URI in External Auth Callback allows Authorization Code Leakagegithub_advisories · 2026-08-17
- [GHSA] GHSA-2qvg-qr73-mqxp (critical) — conflibot vulnerable to command injection via crafted pull request branch names under pull_request_targetgithub_advisories · 2026-08-17
- ShieldBreak bypasses Microsoft’s patch for earlier Defender flawmalwarebytes_blog · 2026-08-17
- [GHSA] GHSA-ggr8-5vv4-36mx (high) — DeepmergeTS has stack exhaustion when merging recursive object graphsgithub_advisories · 2026-08-17
- ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and Morethehackernews · 2026-08-17
- Dell security advisory (AV26-821)cccs_ca · 2026-08-17
- Tenable, Inc. security advisory (AV26-820)cccs_ca · 2026-08-17
- IBM security advisory (AV26-819)cccs_ca · 2026-08-17
- CISA Adds One Known Exploited Vulnerability to Catalogcisa_advisories · 2026-08-17
- How MCP Servers Can Expose Enterprise Secretsthehackernews · 2026-08-17
- [Panzer] Castilla La Mancha posted to leak siteransomware_live · 2026-08-17
- Operation ASTERIX: Anatomy of a Crypto Fraud Pipelinerapid7 · 2026-08-17
- Hacking Public Wi-Fi DNS to Steal Credentialsschneier · 2026-08-17
- Fake TikTok rewards promise cash you’ll never getmalwarebytes_blog · 2026-08-17
- Update your Mac: Screen Sharing vulnerability exploited in the wildmalwarebytes_blog · 2026-08-17
- Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Accessthehackernews · 2026-08-17
- [Panzer] Doimo Cucine posted to leak siteransomware_live · 2026-08-17
- [aurora] Lloyd Coils Europe posted to leak siteransomware_live · 2026-08-17
- Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxiesthehackernews · 2026-08-17
- [dragonforce] Vermont XCenter posted to leak siteransomware_live · 2026-08-17
- Why Facebook’s war on ad blockers could help scammersmalwarebytes_blog · 2026-08-17
- Africa’s Cybersecurity Challenge Is Bigger Than Access to Technologyrapid7 · 2026-08-17
- Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomwarethehackernews · 2026-08-17
- Italy RDWeb Access, GBCSA Data Sale, SCHUFA Claim, and FLY Firebase Exposuresocradar_blog · 2026-08-17
- A week in security (August 10 – August 16)malwarebytes_blog · 2026-08-17
- Risky Bulletin: The EU publishes its upcoming cybersecurity standardsriskybiz_news · 2026-08-17
- [bravox] Moores posted to leak siteransomware_live · 2026-08-17
- Recovering Encrypted LLM Reasoning Tracesembracethered · 2026-08-17
- [emperador] Albania's Official National Teacher Training Portal posted to leak siteransomware_live · 2026-08-17
- Microsoft Edge Multiple Vulnerabilitieshkcert · 2026-08-17
- Re: Fwd: OpenZFS Linux open zpool manipulation and escapes via unprivileged usernsoss_sec · 2026-08-16
- [emperador] Albania's official national teacher training portal. posted to leak siteransomware_live · 2026-08-16
- Fwd: OpenZFS Linux open zpool manipulation and escapes via unprivileged usernsoss_sec · 2026-08-16
- Sponsored: What npm 12 fixes… and what it doesn’triskybiz_news · 2026-08-16
- [qilin] Teikoku USA posted to leak siteransomware_live · 2026-08-16