THREAT OPS › Threat News
Threat Intelligence News
11856 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [GHSA] GHSA-6pvm-2vjj-rx4w (medium) — phpMyFAQ: SQL LIKE Wildcard Injection in Chat User Search Allows Authenticated User Enumerationgithub_advisories · 2026-08-12
- [NVD] CVE-2026-14479 (MEDIUM 5.5) — A maliciously crafted input, when processed by the Autodesk Installer IPC frame parser, may trigger improper validation of an input-specified position or offset, resulting in an out-of-range substring operation. A malicious actor may leverage this vulnerability to cause the NT AUnvd · 2026-08-12
- [NVD] CVE-2026-14478 (HIGH 7.8) — A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to inject unauthenticated IPC messages into named pipes, modify pipe permissions or ownership, and potentially impact confidentiality, integrity, and availability.nvd · 2026-08-12
- [GHSA] GHSA-3763-qp59-59vf (high) — nimiq-blockchain: Validity store off by one errorgithub_advisories · 2026-08-12
- [GHSA] GHSA-jmqm-f8q4-v7wx (medium) — LibreNMS: Reflected XSS via Proxmox instance/vmid GET parameters injected into document.title JavaScript assignmentgithub_advisories · 2026-08-12
- [GHSA] GHSA-j5jq-cr68-v2xx (high) — Winter: Authenticated backend users can bypass Users controller permission checksgithub_advisories · 2026-08-12
- [GHSA] GHSA-5c4f-9pq9-6c77 (medium) — Winter: Broken access control in `Cms\Controllers\Index` allows cross-template actions and unauthorized asset uploadsgithub_advisories · 2026-08-12
- SonicWall security advisory (AV26-809)cccs_ca · 2026-08-12
- [incransom] stuartandassociates.com posted to leak siteransomware_live · 2026-08-12
- Ransom & Dark Web Issues Week 2, August 2026ahnlab · 2026-08-12
- [majinahanashi] SCHMITZ & NITTENWILM posted to leak siteransomware_live · 2026-08-12
- [majinahanashi] Goccia S.p.A. posted to leak siteransomware_live · 2026-08-12
- [majinahanashi] Camandona SA posted to leak siteransomware_live · 2026-08-12
- “Zoomsday” flaws could let one Zoom participant attack anothermalwarebytes_blog · 2026-08-12
- [GHSA] GHSA-m7jc-g4rc-jmvh (medium) — Winter: SQL Injection in Backend Filter Widget numberrange Scope via numbersFromAjaxgithub_advisories · 2026-08-12
- [GHSA] GHSA-vgp4-2fc4-qff2 (high) — Winter: Stored XSS through Editor Settings custom stylesgithub_advisories · 2026-08-12
- [GHSA] GHSA-v7cf-8gh9-gxmj (high) — Winter: Stored XSS through Brand Settings custom stylesgithub_advisories · 2026-08-12
- [emperador] City Government of Baguio posted to leak siteransomware_live · 2026-08-12
- Adobe security advisory (AV26-808)cccs_ca · 2026-08-12
- Linux Kernel Process Accounting, (Wed, Aug 12th)sans_isc · 2026-08-12
- 737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have Onethehackernews · 2026-08-12
- The Threat Hiding in Your Hiring Process: How Fake Remote Workers Get Inbleepingcomputer · 2026-08-12
- Patch Tuesday: Update now to fix 421 flaws, including three zero-daysmalwarebytes_blog · 2026-08-12
- WS-Trust Autologon Endpoint: Password Spray Without Smart Lockout Blockingvaronis_blog · 2026-08-12
- AI is Working in the SOC. So Why are Security Executives More Worried Than Ever?rapid7 · 2026-08-12
- Cisco security advisory (AV26-807)cccs_ca · 2026-08-12
- Google security advisory (AV26-806)cccs_ca · 2026-08-12
- [krybit] hisstw.com posted to leak siteransomware_live · 2026-08-12
- August 2026 Patch Tuesday: 421 Flaws, 3 Zero-Dayssocradar_blog · 2026-08-12
- [krybit] labindia.com posted to leak siteransomware_live · 2026-08-12
- [krybit] lhyk.com.sg posted to leak siteransomware_live · 2026-08-12
- Siemens RUGGEDCOM APE1808cisa_advisories · 2026-08-12
- OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoningthehackernews · 2026-08-12
- SAP Commerce Cloud CVE-2026-58231 Requires Urgent Patchingsocradar_blog · 2026-08-12
- Enterprise Defenses Recovered at the Edge and Collapsed Insidethehackernews · 2026-08-12
- [NVD] CVE-2026-68868 (MEDIUM 6.5) — The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections and Variables: the caller's `team_name` was accepted by the backend but dropped at the internal call boundary, so every lookup resolved againvd · 2026-08-12
- Tools to Scan Workloads and Containers: Detecting Threats Agents Missorca_security · 2026-08-12
- Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flawsthehackernews · 2026-08-12
- [NVD] CVE-2026-64955 (MEDIUM 6.1) — When Microsoft Excel imports a CSV file, it executes cells beginning with certain characters as formulas, giving such CSV files arbitrary execution. Velociraptor fails to sanitize such cells when exporting to CSV from various places such as the GUI, offline collector or data exnvd · 2026-08-12
- [NVD] CVE-2026-64952 (MEDIUM 6.5) — The hunt_delete() VQL function allows deleting hunts. Velociraptor misapplied the permission check requiring only COLLECT_CLIENT (usually assigned to the "investigator" role) instead of the "DELETE_RESULTS" permission (usually only assigned to "administrators").nvd · 2026-08-12
- [NVD] CVE-2026-18652 (MEDIUM 6.5) — Velociraptor allows reading Stacked result sets from the GUI. Velociraptor's multi-tenant design stores sub orgs within the datastore directory. The path requested by the GUI is not correctly checked against the prefix deny list, allowing result sets to read from denied prefixesnvd · 2026-08-12
- Prompt Injections for Defenseschneier · 2026-08-12
- Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Accessthehackernews · 2026-08-12
- [qilin] Wanted posted to leak siteransomware_live · 2026-08-12
- Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizationsthehackernews · 2026-08-12
- SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Codethehackernews · 2026-08-12
- [SilentRansomGroup] R...er posted to leak siteransomware_live · 2026-08-12
- [SilentRansomGroup] R... D... posted to leak siteransomware_live · 2026-08-12
- ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Accessthehackernews · 2026-08-12
- Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoSthehackernews · 2026-08-12
- [NVD] CVE-2026-64954 (HIGH 8.2) — Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLLECT_CLIENT permission. However, this is not enforced when the user can run a VQL query which resets the authorization provider. This allows nvd · 2026-08-12
- [GHSA] GHSA-gqgw-jghv-mxwx (medium) — tablib: Stored XSS in the HTML export via unescaped dataset titlegithub_advisories · 2026-08-12
- Risky Bulletin: Russian hackers jump on the fake job interview trainriskybiz_news · 2026-08-12
- Cisco Products Multiple Vulnerabilitieshkcert · 2026-08-12
- Docker Desktop Security Restriction Bypass Vulnerabilityhkcert · 2026-08-12
- Google Chrome Multiple Vulnerabilitieshkcert · 2026-08-12
- Microsoft Monthly Security Update (August 2026)hkcert · 2026-08-12
- Zoom Products Multiple Vulnerabilitieshkcert · 2026-08-12
- [spacebears] Basso Fedele & Figli S.r.l. (Olio Basso) / Villa Raiano posted to leak siteransomware_live · 2026-08-12
- [NVD] CVE-2026-64927 (MEDIUM 6.4) — A flaw was found in the multicloud-operators-channel component. This vulnerability allows a user with specific permissions to manipulate how the system handles sensitive information, known as Secrets, across different parts of the system (namespaces). By exploiting this, an attacnvd · 2026-08-12
- Adobe Monthly Security Update (August 2026)hkcert · 2026-08-12
- [genesis] **E*** posted to leak siteransomware_live · 2026-08-11
- Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilitiestalos · 2026-08-11
- [NVD] CVE-2026-18710 (MEDIUM 6.5) — A MongoDB driver component could write sensitive configuration information, including a credential used for outbound network connectivity, to application log output in cleartext during routine client initialization. This occurs automatically as part of normal operation and requirnvd · 2026-08-11
- CaptiveCrunch: Midnight Blizzard Weaponizes Hotel Wi-Fi Captive Portals to Steal Microsoft 365 Credentialszscaler_threatlabz · 2026-08-11
- Microsoft Patch Tuesday, August 2026 Security Update Reviewqualys · 2026-08-11
- Microsoft Plugs Nearly 400 Security Holeskrebs · 2026-08-11
- Tracking Shai-Hulud: Inside the ChainDrop NPM Wormzscaler_threatlabz · 2026-08-11
- [NVD] CVE-2026-19579 (MEDIUM 5.4) — Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request cancellation endpoint. The cancel_by_admin and requestingUser values are read from user-controlled URL path segments and used without a server-side authorizationvd · 2026-08-11
- [NVD] CVE-2026-14863 (HIGH 8.8) — FileRun up to and including version 2026.2.0 contains an OS command injection vulnerability that allows authenticated attackers to achieve remote code execution by uploading a file with a malicious filename containing shell command substitution sequences. The thumbnail generationnvd · 2026-08-11
- Introducing Zscaler Zero Trust Gateway for Google Cloudzscaler_threatlabz · 2026-08-11
- Patch Tuesday - August 2026rapid7 · 2026-08-11
- Fake CCleaner installs GhostDesk Chrome spywaremalwarebytes_blog · 2026-08-11
- [NVD] CVE-2026-73232 (HIGH 7.5) — ffuf is a fast web fuzzer written in Go. Prior to 2.2.0, ffuf allows a malicious target server to cause an out-of-memory denial of service because the response size guard in pkg/runner/simple.go checks only the compressed Content-Length while io.ReadAll reads gzip, brotli, deflatnvd · 2026-08-11
- [NVD] CVE-2026-73230 — Ente provides end-to-end encrypted cloud services and security tools. Prior to 2026.07.28, Ente 2of3 card format version 1 stored the secret byte length and 32-bit FNV-1a checksum in cleartext on every card, allowing someone with one card to test candidate secrets offline and recnvd · 2026-08-11
- [NVD] CVE-2026-73229 (MEDIUM 4.3) — Django REST framework is a powerful and flexible toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's rest_framework/renderers.py AdminRenderer.render() uses override_method() to simulate GET and directly invokes view.get() without view.check_permissions() whilnvd · 2026-08-11
- [NVD] CVE-2026-71845 (MEDIUM 6.3) — A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes, including CCX_TOKEN, a bearer credential used in disconnected cluster deployments. When glog verbosity is set to level 2 or higher, the token is written in clnvd · 2026-08-11
- [NVD] CVE-2026-71475 (MEDIUM 6.8) — A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unencoded data into the Insights API URL path. This occurs because the ClusterID, which is controlled by the spoke, is used directly in the request path without proper validatnvd · 2026-08-11
- [NVD] CVE-2026-71474 (HIGH 7.1) — A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can include the cloud.openshift.com pull-secret token. A local user with access to pod logs on the hub could read this long-lived credential. This informationnvd · 2026-08-11
- [NVD] CVE-2026-71468 (MEDIUM 5.3) — A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes its cache, it improperly reuses a user's bearer token for all subsequent federated requests until the cache expires. This allows other authenticated users to gain unauthorized access tonvd · 2026-08-11
- Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attackthehackernews · 2026-08-11
- Ivanti security advisory (AV26-805)cccs_ca · 2026-08-11
- Microsoft security advisory – August 2026 monthly rollup (AV26-804)cccs_ca · 2026-08-11
- [GHSA] GHSA-9mrh-pw7c-9mqm (medium) — Microsoft Security Advisory CVE-2026-62902 – .NET Information Disclosure Vulnerabilitygithub_advisories · 2026-08-11
- [GHSA] GHSA-vg44-h755-9hw7 (high) — Microsoft Security Advisory CVE-2026-62871 – .NET Elevation of Privilege Vulnerabilitygithub_advisories · 2026-08-11
- Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsingthehackernews · 2026-08-11
- [GHSA] GHSA-fx4q-gjrx-2jw6 (high) — Microsoft Security Advisory CVE-2026-62897 – .NET Remote Code Execution Vulnerabilitygithub_advisories · 2026-08-11
- [GHSA] GHSA-gg8c-3338-xw2f (high) — Microsoft Security Advisory CVE-2026-70354 – .NET Core Remote Code Execution Vulnerabilitygithub_advisories · 2026-08-11
- Red Hat security advisory (AV26-803)cccs_ca · 2026-08-11
- Bulletin de sécurité Red Hat (AV26-803)cccs_ca · 2026-08-11
- Red Hat security advisory (AV26-803)cccs_ca · 2026-08-11
- [NVD] CVE-2026-73228 (MEDIUM 5.3) — Django REST framework is a toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's request.data parsing in rest_framework/request.py Request._parse() passes the underlying HttpRequest stream to JSONParser and FormParser for application/json and application/x-www-fnvd · 2026-08-11
- [NVD] CVE-2026-48809 (HIGH 7.5) — python-engineio is a Python implementation of the Engine.IO realtime client and server. Versions prior to 4.13.2 have two specific configurations of the python-engineio server in which the size of incoming messages is not checked before the messages are loaded into memory. An attnvd · 2026-08-11
- [NVD] CVE-2026-48802 (HIGH 7.5) — python-engineio is a Python implementation of the Engine.IO realtime client and server. Prior to version 4.13.2, an attacker can cause the creation of unnecessary background threads in the python-engineio server by exploiting the heartbeat mechanism, which launches a thread when nvd · 2026-08-11
- [NVD] CVE-2026-18712 (HIGH 8.1) — An issue in MongoDB Server's Queryable Encryption maintenance operations could allow an authenticated user with privileges on one encrypted collection to cause unauthorized modification or destruction of data belonging to a different collection. This is due to insufficient validanvd · 2026-08-11
- [NVD] CVE-2026-18711 (HIGH 7.1) — An issue in MongoDB Server's query execution engine could allow an authenticated user with read and write privileges to cause an internal reference to be used after the underlying memory has been freed, when running certain queries against time-series collections. This could resunvd · 2026-08-11
- [NVD] CVE-2026-18709 (MEDIUM 6.4) — An issue in MongoDB Server could allow an authenticated user with direct network access to a shard to improperly commit or abort an in-progress prepared transaction, bypassing the intended transaction coordination process. This could result in cross-shard data inconsistency, clusnvd · 2026-08-11
- [NVD] CVE-2026-18708 (MEDIUM 6.4) — An issue in MongoDB Server's JavaScript scripting engine could allow an authenticated user with write privileges to cause code they control to be executed within the query scope of other users, through a specially crafted stored value processed during an internal maintenance cyclnvd · 2026-08-11
- [NVD] CVE-2026-18707 (MEDIUM 4.3) — An issue in MongoDB Server could allow an authenticated user, including one with no assigned privileges, to cause the server process to terminate unexpectedly by submitting a specially formed aggregation command. This could result in a denial of service.nvd · 2026-08-11
- [NVD] CVE-2026-18706 (MEDIUM 6.6) — An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user able to issue aggregation and memory-management commands to cause an internal reference to be used after the underlying memory has been freed. This could result in a server crash or, potnvd · 2026-08-11