THREAT OPS › Threat News
Threat Intelligence News
11837 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [NVD] CVE-2026-46380 (MEDIUM 6.7) — compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the HTTPSFetcher._do_fetch() method passes a user-supplied URL directly to requests.get() without validation. This allows an attacker to perform Server-Side Request Forgenvd · 2026-08-14
- [Global Secret Group] Columbia University Information (Dental) posted to leak siteransomware_live · 2026-08-14
- FreePBX security advisory (AV26-818)cccs_ca · 2026-08-14
- Upcoming Speaking Engagementsschneier · 2026-08-14
- HashiCorp security advisory (AV26-817)cccs_ca · 2026-08-14
- [GHSA] GHSA-29rf-f4vv-pvq6 (high) — Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accountsgithub_advisories · 2026-08-14
- croc: Arbitrary File Deletion via received filename, chainable to RCE (fixed in 11.0.3)oss_sec · 2026-08-14
- [NVD] CVE-2026-58224 (MEDIUM 6.5) — A flaw was found in Samba's CTDB, the clustered database service used by Samba. Insufficient integrity validation of received CTDB protocol packets allows malformed packets containing invalid field lengths, improperly terminated strings, or inconsistent packet sizes to be processnvd · 2026-08-14
- croc: Arbitrary File Deletion via received filename, chainable to RCE (fixed in 11.0.3)oss_sec · 2026-08-14
- [qilin] Connections posted to leak siteransomware_live · 2026-08-14
- [interlock] Connell Enterprises LLC posted to leak siteransomware_live · 2026-08-14
- IXP Manager: Authenticated IDOR / BOLA + Mass Assignment in API Key Update Allows Overwrite of Other Users’ API Keys (incl. Superuser)oss_sec · 2026-08-14
- Wordfence Intelligence Weekly WordPress Vulnerability Report (August 3, 2026 to August 9, 2026)wordfence · 2026-08-14
- Info-ZIP test option (-T) command injectionoss_sec · 2026-08-14
- Ransomware Threats in the Americas H1 2026: Dissecting the Regional Attack Patterns and Dominant Actorscyble · 2026-08-14
- From Blackwater to Cyber-Privateers: When States Outsource Forcesocradar_blog · 2026-08-14
- [coinbasecartel] Turner and Townsend posted to leak siteransomware_live · 2026-08-14
- [coinbasecartel] Serruya private equity posted to leak siteransomware_live · 2026-08-14
- [coinbasecartel] Sweet Water Holdings posted to leak siteransomware_live · 2026-08-14
- [akira] Keystops posted to leak siteransomware_live · 2026-08-14
- [akira] Cozad Asset Management posted to leak siteransomware_live · 2026-08-14
- Zimbra security advisory (AV26-816)cccs_ca · 2026-08-14
- Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealththehackernews · 2026-08-14
- Apple now uses iPhone alerts for targets of mercenary spywaremalwarebytes_blog · 2026-08-14
- WhatsApp is testing a new warning for scam messagesmalwarebytes_blog · 2026-08-14
- Who’s Tracking You? Use This New Service to Find Outkrebs · 2026-08-14
- Chrome DevTools Technique Enables Authenticated Session Hijacking in Live Windows Browsersthehackernews · 2026-08-14
- If the Markets Reject OpenAI and Anthropic, the US Should Nationalize Themschneier · 2026-08-14
- CTM360 Uncovers Over 3,000 Recruitment Phishing URLs Using Browser-in-the-Browser (BitB) Credential Trapsthehackernews · 2026-08-14
- Apple Warns Users in 110 Countries They May Be Targets of Mercenary Spywarethehackernews · 2026-08-14
- [qilin] Aletex Group posted to leak siteransomware_live · 2026-08-14
- [rhysida] Pierce Township posted to leak siteransomware_live · 2026-08-14
- [qilin] Radiant posted to leak siteransomware_live · 2026-08-14
- Trump Memo Paves Way for U.S. Firms to Hack and Disrupt Foreign Crime Groupsthehackernews · 2026-08-14
- [clop] ZEBRA.COM posted to leak siteransomware_live · 2026-08-14
- APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkitsecurelist · 2026-08-14
- [qilin] Lercher Werkzeugbau posted to leak siteransomware_live · 2026-08-14
- [qilin] 3f posted to leak siteransomware_live · 2026-08-14
- [qilin] PenLink posted to leak siteransomware_live · 2026-08-14
- [qilin] Urban Worldwide posted to leak siteransomware_live · 2026-08-14
- [m3rx] tecnoabi.com posted to leak siteransomware_live · 2026-08-14
- China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraudthehackernews · 2026-08-14
- [Storm] Hinman Straub posted to leak siteransomware_live · 2026-08-14
- [Storm] 3-point Australia posted to leak siteransomware_live · 2026-08-14
- [Storm] Rood & Riddle Equine Hospital posted to leak siteransomware_live · 2026-08-14
- [Storm] Canadian Mental Health Association posted to leak siteransomware_live · 2026-08-14
- [Storm] Tapper Cuddy LLP posted to leak siteransomware_live · 2026-08-14
- [Storm] Integra Castings posted to leak siteransomware_live · 2026-08-14
- You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?))watchtowr · 2026-08-14
- [NVD] CVE-2026-16739 (MEDIUM 5.9) — The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.4 does not verify that a payment-confirmation request originates from the owner of the targeted order, nor that any payment actually occurred, allowing unauthenticated attackers to mark arbitrary orders as confirmenvd · 2026-08-14
- [shinyhunters] Metabase posted to leak siteransomware_live · 2026-08-14
- [shinyhunters] Sharecare, Inc. posted to leak siteransomware_live · 2026-08-14
- [thegentlemen] IPS posted to leak siteransomware_live · 2026-08-14
- [shinyhunters] Carhartt, Inc. posted to leak siteransomware_live · 2026-08-14
- [thegentlemen] Gfeller Treuhand und Verwaltungs posted to leak siteransomware_live · 2026-08-14
- [shinyhunters] Cook Medical LLC posted to leak siteransomware_live · 2026-08-14
- [thegentlemen] Gravity Coffee posted to leak siteransomware_live · 2026-08-14
- [shinyhunters] Baxter International, Inc. posted to leak siteransomware_live · 2026-08-14
- [thegentlemen] Ollies Place Kidswear posted to leak siteransomware_live · 2026-08-14
- [thegentlemen] The Coffee Bean posted to leak siteransomware_live · 2026-08-14
- [thegentlemen] KFC Kosova posted to leak siteransomware_live · 2026-08-14
- [thegentlemen] First Coast Heart Vascular Center posted to leak siteransomware_live · 2026-08-14
- [thegentlemen] Cityside Homes posted to leak siteransomware_live · 2026-08-14
- [thegentlemen] Retail Business Management Systems posted to leak siteransomware_live · 2026-08-14
- [thegentlemen] TOA posted to leak siteransomware_live · 2026-08-14
- [thegentlemen] Tempel posted to leak siteransomware_live · 2026-08-14
- [thegentlemen] Plaza Auto Mall posted to leak siteransomware_live · 2026-08-14
- [thegentlemen] Avanta Maroc Ex Adecco posted to leak siteransomware_live · 2026-08-14
- [thegentlemen] EKEPIS posted to leak siteransomware_live · 2026-08-14
- [thegentlemen] Megalaser Industria Metalurgica LTDA posted to leak siteransomware_live · 2026-08-14
- [thegentlemen] Community Connections posted to leak siteransomware_live · 2026-08-14
- [thegentlemen] Acli posted to leak siteransomware_live · 2026-08-14
- [thegentlemen] Vector Two Technology posted to leak siteransomware_live · 2026-08-14
- Risky Bulletin: US will let private companies carry out offensive cyber opsriskybiz_news · 2026-08-14
- VMWare Products Multiple Vulnerabilitieshkcert · 2026-08-14
- Microsoft Edge Multiple Vulnerabilitieshkcert · 2026-08-14
- Palo Alto Products Multiple Vulnerabilitieshkcert · 2026-08-14
- [SilentRansomGroup] Reminger posted to leak siteransomware_live · 2026-08-13
- [incransom] https://pacific-construction.com/ posted to leak siteransomware_live · 2026-08-13
- [incransom] cambrialawfirm.com posted to leak siteransomware_live · 2026-08-13
- CVE-2026-17431: PDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() of the output path in to_pdf and of stylesheet paths in _style_tag_foross_sec · 2026-08-13
- CVE-2026-16770: PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source documentoss_sec · 2026-08-13
- [NVD] CVE-2026-73661 — FreePBX is an open source IP PBX. Prior to 16.0.47 and 17.0.30, the FreePBX Framework module permits a crafted backup to restore the hidden AUTHTYPE setting with the value none through runRestore() in amp_conf/htdocs/admin/libraries/Builtin/Restore.php. An authenticated user withnvd · 2026-08-13
- [NVD] CVE-2026-73660 — FreePBX is an open source IP PBX. Prior to 16.0.6 and 17.0.5.4, the FreePBX Text-To-Speech module allows an authenticated administrator to save a TTS destination name that is HTML-encoded for storage, decoded during dialplan generation, passed as an AGI argument, and used to builnvd · 2026-08-13
- [NVD] CVE-2026-73489 (MEDIUM 4.3) — Russh is a Rust SSH client & server library. Prior to 0.62.4, an authenticated SSH client can cause a denial of service by sending a pty-req channel request with more than 130 terminal-mode records. The parser in russh/src/server/encrypted.rs stores terminal modes in a fixed 130-nvd · 2026-08-13
- [NVD] CVE-2026-73428 (MEDIUM 4.6) — Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.18, Trix is vulnerable to stored cross-site scripting when crafted HTML is pasted into the editor. HTMLParser processes a mock attachment in a `<span>` with an empty `data-trix-attachment="nvd · 2026-08-13
- [NVD] CVE-2026-73421 — NextAuth.js provides authentication for Next.js. From next-auth 5.0.0-beta.0 until 5.0.0-beta.32, applications that gate access by checking only for the existence of the auth object returned by the auth() wrapper can fail open when Auth.js has a server configuration error. In midnvd · 2026-08-13
- [NVD] CVE-2026-73420 — NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the defaultNormalizer used by the email and magic-link sign-in flow validates an address before applying Unicode normalization. An address can contain a Unicode chnvd · 2026-08-13
- [NVD] CVE-2026-73417 — jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 3.3.0 until 4.5.10 and 4.6.2, JupyterLab allows notebook settings to be shared and applied through an overrides.json file using the Import button invd · 2026-08-13
- [NVD] CVE-2026-73416 — jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.5.0 until 4.5.10 and 4.6.2, in jupyterlab/extensions/manager.py and jupyterlab/extensions/pypi.py, JupyterLab's PyPI extension manager enforces bnvd · 2026-08-13
- rsync 3.5.0 released with fixes for 33 CVEsoss_sec · 2026-08-13
- APPLE-SA-08-06-2026-2 macOS Sequoia 15.7.9fulldisclosure · 2026-08-13
- APPLE-SA-08-06-2026-3 macOS Sonoma 14.8.9fulldisclosure · 2026-08-13
- CVE-2026-64607: Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoSoss_sec · 2026-08-13
- OpenSSL Security Advisoryoss_sec · 2026-08-13
- [NVD] CVE-2026-8715 (CRITICAL 9.6) — Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissions to read files from the operator pod's filesystem and tranvd · 2026-08-13
- [GHSA] GHSA-p28v-f755-9qrg (high) — Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoSgithub_advisories · 2026-08-13
- [coinbasecartel] Hitachi High-Tech posted to leak siteransomware_live · 2026-08-13
- [OSSN-0107] Ironic-Python-Agent: Container HardwareManager Security Model Misimplementedoss_sec · 2026-08-13
- [GHSA] GHSA-m42h-3232-vpv3 (high) — nltk: Arbitrary File Read via Path Traversal in nltk.data.load() through Percent-Encoded Sequencesgithub_advisories · 2026-08-13