THREAT OPS › Threat News
Threat Intelligence News
11855 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [NVD] CVE-2026-19002 (HIGH 8.1) — A missing bounds check when parsing stored procedure parameter metadata in the MongoDB BI Connector ODBC Driver can result in an out-of-bounds write in the client application process. Triggering this issue requires control over the server the driver connects to, or the ability tonvd · 2026-08-12
- [NVD] CVE-2026-19001 (CRITICAL 9.8) — The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application supplies an unusually long catalog, schema, or object name to a metadata retrieval function. This may result in memory corruption within the calling application's process,nvd · 2026-08-12
- [NVD] CVE-2026-18888 (MEDIUM 6.5) — The MongoDB BI Connector ODBC Driver converts floating point column values into text without checking that the result fits within the destination buffer. When an application reads a sufficiently large floating point value as text, the driver may write beyond the end of that buffenvd · 2026-08-12
- [NVD] CVE-2026-16033 (HIGH 8.5) — A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation. When processing image metadata templates, LXD fails to properly sanitize or restrict template file paths from escaping the instance templates directory (spnvd · 2026-08-12
- [NVD] CVE-2026-13622 (HIGH 8.8) — A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside the target virt-launcher pod via /proc/<pid>/root/ paths using net.Dial() without symlink protection. These socket paths reside innvd · 2026-08-12
- [kairos] Hightech Signs posted to leak siteransomware_live · 2026-08-12
- [NVD] CVE-2026-73434 (MEDIUM 6.1) — A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff_parse_vprp(), the number of available gst_riff_vprp_video_field_desc entries is calculated by dividing the remaining buffer size by the attacker-controlled vprp->fields value, rather than by sizeof(gnvd · 2026-08-12
- [NVD] CVE-2026-73433 (MEDIUM 6.6) — A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM metadata in an AVI strd chunk, gst_avi_demux_parse_strd() decrements a remaining-length counter by fixed offsets (98 and 10 bytes) without verifying sufficient data remains. For crafted strd payloadsnvd · 2026-08-12
- [NVD] CVE-2026-73269 (CRITICAL 9.9) — A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, can trigger the creation of a cluster-scoped ClusterRoleBinding. This allows the user to escalate their privileges from namespace-lnvd · 2026-08-12
- [NVD] CVE-2026-73268 (CRITICAL 9.9) — A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurator resources can inject an arbitrary Job specification. This is possible because the CreateJob() function does not validate user-convd · 2026-08-12
- [NVD] CVE-2026-63300 (CRITICAL 9.9) — An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_create_instances permissions on a restricted project to bypass project-level security restrictions. When migrating an instance betwenvd · 2026-08-12
- [NVD] CVE-2026-63299 (CRITICAL 9.9) — An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits. Two related code paths fail to verify resource limits during volume operations: the storagePoolVolumeTypePostMove function omits the limits.AllowVolumeCreationvd · 2026-08-12
- [NVD] CVE-2026-63298 (CRITICAL 9.9) — An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inject arbitrary configuration directives. By supplying newline characters within the 'nvidia.driver.capabilities' or 'nvidia.require.*nvd · 2026-08-12
- [NVD] CVE-2026-63297 (CRITICAL 9.9) — An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copies. When copying an instance to a target project, LXD performs restriction checknvd · 2026-08-12
- [NVD] CVE-2026-63296 (CRITICAL 9.9) — An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to a target project, LXD accepts configuration overrides without validating the new configuration against the nvd · 2026-08-12
- [NVD] CVE-2026-63295 (MEDIUM 4.3) — An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass project-level container isolation restrictions. When a project is configured with restrictions on container privileges (such as enforcing restricted.containers.privilege=isolated), LXD fails tnvd · 2026-08-12
- [NVD] CVE-2026-63294 (CRITICAL 9.9) — A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of crafted image or backup archives, LXD fails to properly validate and confine the backup.yaml file when it exists as a symbolic link. Annvd · 2026-08-12
- [NVD] CVE-2026-62420 (CRITICAL 9.9) — An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations. When moving an instance cross-project to a different cluster member via POST /1.0/instances/{name} with migrationnvd · 2026-08-12
- [SilentRansomGroup] Riker Danzig LLP posted to leak siteransomware_live · 2026-08-12
- Zoom Zero-Click RCE Flaws Allow Any Meeting Attendee to Compromise All Participantsorca_security · 2026-08-12
- Qualys Introduces Real-Time Cloud Security Posture Management (CSPM) for Faster Risk Detection and Remediationqualys · 2026-08-12
- [GHSA] GHSA-pfvm-w89x-94jw (high) — SIPSorcery: Malformed UDP datagram crashes TurnServer receive loop with no restart, disabling TURN UDP relay for all clients (DoS)github_advisories · 2026-08-12
- [GHSA] GHSA-jwjp-4649-v8jp (high) — SIPSorcery vulnerable to Denial of Service via out-of-bounds read in SCTP SACK chunk parsinggithub_advisories · 2026-08-12
- [incransom] gamaus.com posted to leak siteransomware_live · 2026-08-12
- [GHSA] GHSA-49m4-vp58-wgc9 (high) — MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`github_advisories · 2026-08-12
- [GHSA] GHSA-w62w-66v9-vvgv (high) — SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket accessgithub_advisories · 2026-08-12
- [NVD] CVE-2026-18952 (HIGH 8.1) — Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics plugin might allow an authenticated remote user to perform server-side request forgery and read local files via a crafted URL parameter to the threat intel source configuration ennvd · 2026-08-12
- [NVD] CVE-2026-73298 — The Microsoft Container Migration Solution Accelerator is a multi-service application that provides a multi-agent, AI-driven migration solution for moving container service configurations to Azure Kubernetes Service. In version 2.1.2 and earlier, a security vulnerability was idennvd · 2026-08-12
- [NVD] CVE-2026-44741 (HIGH 8.8) — Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Versions prior to 2.3.6 and 1.7.18 have a SQL injection vulnerability in Pimcore's translation grid date filter — the user-supplied `property` field from the filter JSON is interpolated directly into a `UNIX_TIMESTnvd · 2026-08-12
- Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoorthehackernews · 2026-08-12
- Fortinet security advisory (AV26-812)cccs_ca · 2026-08-12
- Major Themes at Black Hat 2026sonatype · 2026-08-12
- How Eaton Secured 100+ Manufacturing Facilities with Zscalerzscaler_threatlabz · 2026-08-12
- From Patch Tuesday to Pentest Wednesday®: How a Major Transportation Company Turned AWS Attack Paths Into Actionhorizon3 · 2026-08-12
- [NVD] CVE-2026-73297 — Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, _is_blocked_ip in ufo/utils/url_security.py did not block NAT64 prefixes 64:ff9b::/96 and 64:ff9b:1::/48, the 6to4 prefix 2002::/16, or the Teredo prefix 2001::/32 and didnvd · 2026-08-12
- [NVD] CVE-2026-73296 (CRITICAL 9.4) — Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, create_mobile_data_collection_server and create_mobile_action_server in ufo/client/mcp/http_servers/mobile_mcp_server.py exposed Streamable HTTP MCP services on TCP ports nvd · 2026-08-12
- [blacknevas] Westbrook Greenhouse Systems www.westbrooksystems.com serviced by an IT company Computer C... posted to leak siteransomware_live · 2026-08-12
- [blacknevas] Enteroptyx Ophthalmology Products www.enteroptyx.com serviced by an IT company Computer Co... posted to leak siteransomware_live · 2026-08-12
- [blacknevas] Jack Rutherford Customs Brokers Ltd / The Rutherford Group www.therg.ca serviced by an IT ... posted to leak siteransomware_live · 2026-08-12
- [NVD] CVE-2026-58076 (HIGH 8.8) — Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and instantiating it with arguments from the same blob, with no restriction on what could be imported. An operator's `executor_config` renvd · 2026-08-12
- [NVD] CVE-2026-54183 (MEDIUM 4.3) — Apache Airflow's secrets masker hides values stored under sensitive key names when they are displayed in the UI. The masker's recursion-depth limit did not descend into values nested inside a list, tuple, or set beyond that limit, so an Airflow Variable holding such a deeply-nestnvd · 2026-08-12
- [Control Systems] Phoenix Contact security advisory (AV26-811)cccs_ca · 2026-08-12
- Blacklight: Illuminating AI Agent Artifacts for Attackers and Defendersspecterops · 2026-08-12
- Cisco Advance Notification for Publication of August 19, 2026, Security Advisoriescisco_psirt · 2026-08-12
- [qilin] United Association Local Union 345 posted to leak siteransomware_live · 2026-08-12
- How an Unexpected Pivot Led to a Career at Zscalerzscaler_threatlabz · 2026-08-12
- [incransom] BEDC.COM.AU posted to leak siteransomware_live · 2026-08-12
- [incransom] diabetesandmetabolism.com posted to leak siteransomware_live · 2026-08-12
- [clop] AOL.COM posted to leak siteransomware_live · 2026-08-12
- [clop] GATE7LLC.COMGBBEV.COM posted to leak siteransomware_live · 2026-08-12
- [clop] ENTERATEK.MXESBERBEVERAGE.COM posted to leak siteransomware_live · 2026-08-12
- [clop] NUVITIA.COM posted to leak siteransomware_live · 2026-08-12
- [clop] IPMSOLUTIONS.SK posted to leak siteransomware_live · 2026-08-12
- [clop] ECCELLENT.COM posted to leak siteransomware_live · 2026-08-12
- [clop] STNET.IT posted to leak siteransomware_live · 2026-08-12
- [clop] QCPL.IN posted to leak siteransomware_live · 2026-08-12
- [clop] FLUIDLOGIC.COM posted to leak siteransomware_live · 2026-08-12
- [clop] MIDLANDIND.COM.AU posted to leak siteransomware_live · 2026-08-12
- [clop] ITKHOLDING.HU posted to leak siteransomware_live · 2026-08-12
- [clop] G3AEROSPACE.COM posted to leak siteransomware_live · 2026-08-12
- [clop] ARCHERGREY.COM posted to leak siteransomware_live · 2026-08-12
- [clop] OMNITANKER.COM posted to leak siteransomware_live · 2026-08-12
- [clop] LIFESTRAW.COM posted to leak siteransomware_live · 2026-08-12
- [clop] SPKAA.COM posted to leak siteransomware_live · 2026-08-12
- [clop] IVALUESYS.COM posted to leak siteransomware_live · 2026-08-12
- [clop] NUOVACMM.COM posted to leak siteransomware_live · 2026-08-12
- MongoDB security advisory (AV26-810)cccs_ca · 2026-08-12
- [clop] THERMOS.COM posted to leak siteransomware_live · 2026-08-12
- [clop] WATERLANDPE.COM posted to leak siteransomware_live · 2026-08-12
- [clop] 9ALTITUDES.COM posted to leak siteransomware_live · 2026-08-12
- [clop] INTELLIHOT.COM posted to leak siteransomware_live · 2026-08-12
- [clop] INTELLIGENTGROWTHSOLUTIONS.COM posted to leak siteransomware_live · 2026-08-12
- [clop] HONGHE-TECH.COM posted to leak siteransomware_live · 2026-08-12
- [clop] ATOMBERG.COM posted to leak siteransomware_live · 2026-08-12
- [clop] CLOVER.COM posted to leak siteransomware_live · 2026-08-12
- [clop] JPMGROUP.CO.IN posted to leak siteransomware_live · 2026-08-12
- [clop] BRILLONCONSUMER.COM (BRILLONCONSUMER.COM) posted to leak siteransomware_live · 2026-08-12
- [clop] SUUNTO.CN (SUUNTO.COM) posted to leak siteransomware_live · 2026-08-12
- [clop] SMAPCENTER.UAH.EDU posted to leak siteransomware_live · 2026-08-12
- [clop] TRISTAR.COM posted to leak siteransomware_live · 2026-08-12
- [clop] MAMASANDPAPAS.COM posted to leak siteransomware_live · 2026-08-12
- [clop] CORNELIUS.COM posted to leak siteransomware_live · 2026-08-12
- [clop] MAMMUT.COM posted to leak siteransomware_live · 2026-08-12
- [clop] PARTECH.COM posted to leak siteransomware_live · 2026-08-12
- [clop] STARKEY.COM posted to leak siteransomware_live · 2026-08-12
- [clop] LARGAN.COM.TW posted to leak siteransomware_live · 2026-08-12
- [clop] TOASTTAB.COM posted to leak siteransomware_live · 2026-08-12
- [clop] IRCO.COM posted to leak siteransomware_live · 2026-08-12
- [clop] ALDOGROUP.COM (ALDOSHOES.COM) posted to leak siteransomware_live · 2026-08-12
- [clop] PHILIPS.COM posted to leak siteransomware_live · 2026-08-12
- [clop] FISERV.COM posted to leak siteransomware_live · 2026-08-12
- [clop] GE.COM posted to leak siteransomware_live · 2026-08-12
- [clop] NETPOWER.COM posted to leak siteransomware_live · 2026-08-12
- [clop] SHELL.COM (August 2026) posted to leak siteransomware_live · 2026-08-12
- [blacknevas] COMPUTER COUNTRY AND NETWORKS posted to leak siteransomware_live · 2026-08-12
- [GHSA] GHSA-h47f-gmjp-m7rr (high) — compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0github_advisories · 2026-08-12
- [GHSA] GHSA-q939-rpr3-3284 (high) — SSH.NET: ScpClient Recursive Download Allows Arbitrary File Write via Server-Controlled SCP Filenamesgithub_advisories · 2026-08-12
- [NVD] CVE-2026-73291 (HIGH 7.1) — Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.4.0, Seerr's ImageProxy in server/lib/imageproxy.ts uses the upstream ETag and Content-Type response headers to build a cache filename for the unauthenticated GET /avatarpnvd · 2026-08-12
- [GHSA] GHSA-88p2-jj8w-j8qg (medium) — Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpointgithub_advisories · 2026-08-12
- [GHSA] GHSA-6pvm-2vjj-rx4w (medium) — phpMyFAQ: SQL LIKE Wildcard Injection in Chat User Search Allows Authenticated User Enumerationgithub_advisories · 2026-08-12