THREAT OPS › Threat News
Threat Intelligence News
11817 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- Why Facebook’s war on ad blockers could help scammersmalwarebytes_blog · 2026-08-17
- Africa’s Cybersecurity Challenge Is Bigger Than Access to Technologyrapid7 · 2026-08-17
- Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomwarethehackernews · 2026-08-17
- Italy RDWeb Access, GBCSA Data Sale, SCHUFA Claim, and FLY Firebase Exposuresocradar_blog · 2026-08-17
- A week in security (August 10 – August 16)malwarebytes_blog · 2026-08-17
- Risky Bulletin: The EU publishes its upcoming cybersecurity standardsriskybiz_news · 2026-08-17
- [bravox] Moores posted to leak siteransomware_live · 2026-08-17
- Recovering Encrypted LLM Reasoning Tracesembracethered · 2026-08-17
- [emperador] Albania's Official National Teacher Training Portal posted to leak siteransomware_live · 2026-08-17
- Microsoft Edge Multiple Vulnerabilitieshkcert · 2026-08-17
- Re: Fwd: OpenZFS Linux open zpool manipulation and escapes via unprivileged usernsoss_sec · 2026-08-16
- [emperador] Albania's official national teacher training portal. posted to leak siteransomware_live · 2026-08-16
- Fwd: OpenZFS Linux open zpool manipulation and escapes via unprivileged usernsoss_sec · 2026-08-16
- Sponsored: What npm 12 fixes… and what it doesn’triskybiz_news · 2026-08-16
- [qilin] Teikoku USA posted to leak siteransomware_live · 2026-08-16
- [qilin] AGUNSA posted to leak siteransomware_live · 2026-08-16
- [qilin] Coface posted to leak siteransomware_live · 2026-08-16
- [qilin] Spoonful of Comfort posted to leak siteransomware_live · 2026-08-16
- [Panzer] SAGASTA sro posted to leak siteransomware_live · 2026-08-16
- [Eclipse] Moscord posted to leak siteransomware_live · 2026-08-16
- [qilin] Mulino Padano posted to leak siteransomware_live · 2026-08-16
- [qilin] WEBA Meubelen posted to leak siteransomware_live · 2026-08-16
- [medusalocker] Twal Family IT Lab posted to leak siteransomware_live · 2026-08-16
- [medusalocker] All Parts Dry Cleaning posted to leak siteransomware_live · 2026-08-16
- [medusalocker] Idex Group posted to leak siteransomware_live · 2026-08-16
- [medusalocker] Bija Industrie posted to leak siteransomware_live · 2026-08-16
- [medusalocker] Thecourierguy posted to leak siteransomware_live · 2026-08-16
- CVE-2026-72888: Net::OAuth versions before 0.32 for Perl allow memory exhaustion via unbounded caching of failed module loads in smart_requireoss_sec · 2026-08-16
- CVE-2026-72887: Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OAuth 1.0a to OAuth 1.0 in get_request_tokenoss_sec · 2026-08-16
- CVE-2026-19349: Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl allow authentication bypass via an OAuth2 state parameter stored as an SSO session in the GitHub and LinkedIn backendsoss_sec · 2026-08-16
- libmspack: heap buffer overflow in make_decode_table() (Huffman decode table construction) -- CVE requestedoss_sec · 2026-08-16
- [Helix] Kennedy Jenks posted to leak siteransomware_live · 2026-08-16
- [lockbit5] actua.fr posted to leak siteransomware_live · 2026-08-16
- [lockbit5] dupouy-associes.fr posted to leak siteransomware_live · 2026-08-16
- [lockbit5] agricolagalbusera.it posted to leak siteransomware_live · 2026-08-16
- [lockbit5] tecosim.com posted to leak siteransomware_live · 2026-08-16
- [lockbit5] vgrn.de posted to leak siteransomware_live · 2026-08-16
- [qilin] MOSAID Technologies posted to leak siteransomware_live · 2026-08-16
- [qilin] INVENSITY posted to leak siteransomware_live · 2026-08-16
- [qilin] Megawide posted to leak siteransomware_live · 2026-08-16
- [Panzer] Infosat posted to leak siteransomware_live · 2026-08-16
- [qilin] Desatera Sdn Bhd posted to leak siteransomware_live · 2026-08-16
- [qilin] Loescher editore Torino posted to leak siteransomware_live · 2026-08-16
- [qilin] Botek posted to leak siteransomware_live · 2026-08-16
- [qilin] Zanichelli posted to leak siteransomware_live · 2026-08-16
- [qilin] Jone Précision posted to leak siteransomware_live · 2026-08-16
- [qilin] Arnall Golden Gregory posted to leak siteransomware_live · 2026-08-16
- [qilin] ASCII Group posted to leak siteransomware_live · 2026-08-16
- [qilin] DELTA WAYS posted to leak siteransomware_live · 2026-08-16
- [qilin] motorenmaier gmbh posted to leak siteransomware_live · 2026-08-16
- [qilin] Double H Equipment posted to leak siteransomware_live · 2026-08-16
- [Orova] Smartsoft posted to leak siteransomware_live · 2026-08-16
- [NVD] CVE-2026-14524 (CRITICAL 9.1) — The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the proSol_fileDeleteProcess function in all versions up to, and including, 2.0.8. This makes it possible for unauthenticated attackers to delete arnvd · 2026-08-16
- [NVD] CVE-2026-14498 (HIGH 8.8) — The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.57 via the 'options' parameter parameter. This is due to missing capability check and nonce verification on the wp_ajax_qw_form_ajax handler, combined with unsnvd · 2026-08-16
- [NVD] CVE-2026-13358 (MEDIUM 6.5) — The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.12.10 via the ssa_past_appointments due to missing validation on a user controlled key. nvd · 2026-08-16
- [NVD] CVE-2026-13167 (MEDIUM 4.3) — The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.5.2. This is due to the plugin not properly verifying that a user is authorized to performnvd · 2026-08-16
- [NVD] CVE-2026-12905 (MEDIUM 4.3) — The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 27.7 via the appointment() method of the Mobile Staff Cabinet API (resource=appointment, action=bookly_mobile_staff_cabinet) in frontend/modules/mobile_staff_cabinenvd · 2026-08-16
- [NVD] CVE-2026-12477 (MEDIUM 4.4) — The Gravity Booster – Styles & Layouts for Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.26 due to insufficient input sanitization and output escaping. This makes it possible for authentinvd · 2026-08-16
- [NVD] CVE-2026-11780 (MEDIUM 6.4) — The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'question_title' parameter in all versions up to, and including, 11.2.1 due to insufficient input sanitization and output escaping. This makes invd · 2026-08-16
- [NVD] CVE-2025-10005 (MEDIUM 4.3) — The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.9.20 via the ppw_free_set_password AJAX action due to missing validation on a user controlled kenvd · 2026-08-16
- [NVD] CVE-2026-2487 (MEDIUM 4.4) — The Admin Custom Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administratnvd · 2026-08-16
- [NVD] CVE-2026-19930 (MEDIUM 6.3) — A security flaw has been discovered in Dolibarr up to 23.0.3. Affected is an unknown function of the file htdocs/user/card.php of the component User Cloning. The manipulation of the argument ID results in ldap injection. It is possible to launch the attack remotely. The exploit hnvd · 2026-08-16
- [NVD] CVE-2026-19929 (MEDIUM 6.3) — A vulnerability was identified in OpenBoxes up to 0.9.6. This impacts the function buildZebraTemplate of the file grails-app/controllers/org/pih/warehouse/core/DocumentController.groovy of the component Template Processing. The manipulation leads to improper neutralization of spenvd · 2026-08-16
- [NVD] CVE-2026-19928 (MEDIUM 6.3) — A vulnerability was determined in OpenBoxes up to 0.9.7. This affects the function needManager of the file grails-app/controllers/org/pih/warehouse/RoleInterceptor.groovy of the component Role Interceptor. Executing a manipulation can lead to improper privilege management. The atnvd · 2026-08-16
- [NVD] CVE-2026-19927 (MEDIUM 6.3) — A vulnerability was found in OpenBoxes up to 0.9.7. The impacted element is the function Upload of the file grails-app/controllers/org/pih/warehouse/product/ProductController.groovy of the component Product Upload Endpoint. Performing a manipulation of the argument params.url resnvd · 2026-08-16
- [NVD] CVE-2026-19926 (HIGH 7.3) — A vulnerability has been found in Evergreen up to 3.14.11/3.15.11/3.16.5/3.17-beta1. The affected element is an unknown function of the file /osrf-gateway-v1 of the component open-ils.fielder OpenSRF Service. Such manipulation leads to sql injection. The attack can be executed renvd · 2026-08-16
- [NVD] CVE-2026-19925 (MEDIUM 4.7) — A vulnerability was detected in SourceCodester Stock Management System 1.0. This issue affects some unknown processing of the file /classes/Master.php?f=delete_supplier. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploitnvd · 2026-08-16
- [NVD] CVE-2026-19924 (CRITICAL 9.8) — A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability affects the function R7WebsSecurityHandler of the component httpd. The manipulation leads to improper authentication. The attack may be initiated remotely. The exploit has been dinvd · 2026-08-16
- [NVD] CVE-2026-19923 (MEDIUM 6.3) — A weakness has been identified in code-projects Online Shopping System 1.0. This affects an unknown part of the file /checkout_process.php. Executing a manipulation of the argument total_count can lead to sql injection. The attack can be launched remotely. The exploit has been manvd · 2026-08-16
- [NVD] CVE-2026-19922 (LOW 3.5) — A security flaw has been discovered in code-projects Online Shopping System 1.0. Affected by this issue is some unknown functionality of the file /checkout.php. Performing a manipulation of the argument amount_1 results in cross site scripting. The attack can be initiated remotelnvd · 2026-08-16
- [NVD] CVE-2026-19921 (MEDIUM 6.3) — A vulnerability was identified in code-projects Online Shopping System 1.0. Affected by this vulnerability is an unknown functionality of the file /homeaction.php. Such manipulation of the argument cat_id leads to sql injection. It is possible to launch the attack remotely. The envd · 2026-08-16
- [NVD] CVE-2026-19920 (MEDIUM 6.3) — A vulnerability was determined in code-projects Online Shopping System 1.0. Affected is an unknown function of the file /action.php. This manipulation of the argument proId causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosnvd · 2026-08-16
- [NVD] CVE-2026-19919 (HIGH 7.3) — A vulnerability was found in code-projects Online Shopping System 1.0. This impacts an unknown function of the file /login.php of the component Login. The manipulation of the argument email results in sql injection. The attack may be performed from remote. The exploit has been manvd · 2026-08-16
- [NVD] CVE-2026-19918 (MEDIUM 6.3) — A vulnerability has been found in SpaceX Starlink Router Gen 3 2025.11.14.mr64708.3. This affects the function get_status of the component gRPC Management Interface. The manipulation leads to improper access controls. The attack can only be initiated within the local network. Thenvd · 2026-08-16
- [NVD] CVE-2026-19917 (MEDIUM 6.3) — A flaw has been found in code-projects Online Food Order System 1.0. The impacted element is an unknown function of the file delete_food_items1.php. Executing a manipulation of the argument checkbox can lead to sql injection. The attack can be executed remotely. The exploit has bnvd · 2026-08-15
- [NVD] CVE-2026-74767 — Pandora contains a denial-of-service vulnerability in its handling of DAA (Direct Access Archive) files. When extracting the internal ISO image from a DAA archive, compressed chunks were decompressed using zlib.decompress() without enforcing a limit on the resulting uncompressed nvd · 2026-08-15
- [NVD] CVE-2026-74764 — Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a submitted TAR archive, the extractor passed archive member names directly to Python's tarfile.TarFile.extract() without applying an extraction filter. An attacker ablenvd · 2026-08-15
- [NVD] CVE-2026-73055 (MEDIUM 4.8) — Shescape before 2.1.15 (and 3.0.0 before 3.0.2) fails to properly escape tilde (~) characters in assignment contexts on Unix systems where the shell is explicitly configured to "sh" or true and /bin/sh points to BusyBox. Using the escape and escapeAll APIs with untrusted input innvd · 2026-08-15
- [NVD] CVE-2026-73054 (HIGH 7.5) — SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the WebSocket endpoint caused by differential parsing of query parameters between authentication exemption and session quarantine checks. Unauthenticated attackers can craft a malicious WebSocket URI nvd · 2026-08-15
- [NVD] CVE-2026-73053 (CRITICAL 9.0) — SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to sanitize codepoint branch output. Attackers can craft document icons with hex-encoded markup that executes in the renderer with Node integration enabled, achievinvd · 2026-08-15
- [NVD] CVE-2026-73052 (CRITICAL 9.0) — SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the sort menu. Attackers can inject markup by renaming a database field to execute arbitrary JavaScript when users open the sort menu,nvd · 2026-08-15
- [NVD] CVE-2026-73050 (CRITICAL 9.0) — SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing stored cross-site scripting through eight unescaped render sites. Attackers can inject event-handler attributes by including quotation marks in the color value, exenvd · 2026-08-15
- [NVD] CVE-2026-73047 (MEDIUM 6.2) — siyuan versions <= 3.7.3 (fixed in v3.7.4) contain a server-side template injection vulnerability in the attribute-view Template calculation feature (introduced in v3.7.0-beta.1). The feature's template engine uses Sprig's unmodified function map, which still exposes the env, expnvd · 2026-08-15
- [NVD] CVE-2026-73046 (CRITICAL 9.8) — SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middleware. The HTTP Basic Authentication branch, which guards nearly the entire /api/* surface, accepts the workspace access code (Conf.AccessAuthCode) as the Basic Auth password but nnvd · 2026-08-15
- [NVD] CVE-2026-73045 (HIGH 7.5) — SiYuan before 3.7.4 contains an improper restriction of excessive authentication attempts vulnerability in the authFilePublishAccess endpoint that allows unauthenticated attackers to brute-force per-notebook publish passwords. Attackers can submit unbounded password guesses withonvd · 2026-08-15
- [NVD] CVE-2026-73044 (CRITICAL 9.0) — SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored cross-site scripting injection into style attributes. Attackers can inject malicious payloads through the setAttrViewColWidth API that break out of style attributes and inject evennvd · 2026-08-15
- [NVD] CVE-2026-73043 (CRITICAL 9.0) — SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which renders user-authored Go templates and stores output verbatim without sanitization. Attackers can inject malicious HTML and JavaScript into template calculationnvd · 2026-08-15
- [NVD] CVE-2026-73042 (CRITICAL 9.0) — SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to execute script when users open group, view, or field-edit menus. Attackers can inject markup through field descriptions or names that close containing elements annvd · 2026-08-15
- [NVD] CVE-2026-73041 (CRITICAL 9.0) — SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endpoint. Attackers can inject malicious markup into annotation fields that execute as script in the PDF renderer with full Node.js access when a user opens an annonvd · 2026-08-15
- [NVD] CVE-2026-19916 (LOW 3.5) — A vulnerability was detected in code-projects Online Food Order System 1.0. The affected element is an unknown function of the file edit_food_items.php. Performing a manipulation of the argument dname results in cross site scripting. Remote exploitation of the attack is possible.nvd · 2026-08-15
- [xpl0itrs] Oz Hair & Beauty posted to leak siteransomware_live · 2026-08-15
- [xpl0itrs] ********* posted to leak siteransomware_live · 2026-08-15
- [xpl0itrs] RapidFort posted to leak siteransomware_live · 2026-08-15
- [direwolf] DodoPayments posted to leak siteransomware_live · 2026-08-15
- [direwolf] AAM:HOA Management posted to leak siteransomware_live · 2026-08-15
- [direwolf] TOTVS posted to leak siteransomware_live · 2026-08-15
- [direwolf] Colla Health posted to leak siteransomware_live · 2026-08-15
- [direwolf] PayrHealth posted to leak siteransomware_live · 2026-08-15
- [direwolf] DXS International posted to leak siteransomware_live · 2026-08-15
- [NVD] CVE-2026-19906 (LOW 3.7) — A weakness has been identified in pkp pkp-lib 3.3.0/3.4.0/3.5.0. This vulnerability affects the function setData of the file classes/user/form/APIProfileForm.php of the component API Key Generation. Executing a manipulation of the argument apiKey can lead to insufficient entropy.nvd · 2026-08-15