THREAT OPS › Threat News
Threat Intelligence News
11857 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [NVD] CVE-2026-18706 (MEDIUM 6.6) — An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user able to issue aggregation and memory-management commands to cause an internal reference to be used after the underlying memory has been freed. This could result in a server crash or, potnvd · 2026-08-11
- [NVD] CVE-2026-18705 (MEDIUM 6.5) — An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to one view to retrieve documents from a different, protected view over the same underlying collection. This is due to insufficient handling of certain user-supplied fieldsnvd · 2026-08-11
- [NVD] CVE-2026-18704 (MEDIUM 6.5) — An issue in MongoDB Server's aggregation framework could allow an authenticated user with only read privileges to perform write operations against collections they should not be able to modify. This is due to an internal-use aggregation stage being reachable by external clients wnvd · 2026-08-11
- [NVD] CVE-2026-18703 (MEDIUM 4.2) — An issue in MongoDB Server could allow a party with a valid client certificate and a corresponding user account to authenticate using a certificate-based authentication method, even when an administrator has configured the server to restrict authentication to other mechanisms. Thnvd · 2026-08-11
- [NVD] CVE-2026-18702 (MEDIUM 6.4) — An issue in MongoDB Server could allow an authenticated user with limited, database-scoped privileges to modify diagnostic logging settings that affect the entire server rather than just the intended database. This could allow suppression of diagnostic logging server-wide, potentnvd · 2026-08-11
- [NVD] CVE-2026-18701 (MEDIUM 6.5) — An issue in MongoDB Server's query subsystem could allow an authenticated user with read privileges to cause the server process to terminate unexpectedly by submitting a specially formed query filter. This could result in a denial of service.nvd · 2026-08-11
- [NVD] CVE-2026-18700 (MEDIUM 6.5) — An issue in MongoDB Server's geospatial validation could allow an authenticated user with write privileges to cause an internal reference to be used after the underlying memory has been freed, through concurrent operations against a collection using a certain type of validator. Tnvd · 2026-08-11
- [NVD] CVE-2026-18699 (MEDIUM 6.5) — An issue in MongoDB Server's query planner could allow an authenticated user with read-level privileges to cause the server process to terminate unexpectedly by submitting a specially formed query against a collection with a text index. This could result in a denial of service, anvd · 2026-08-11
- [NVD] CVE-2026-18698 (MEDIUM 5.4) — An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collections that should require more specific privileges. This could result in exposure of collection metadata and, on certain deploymentnvd · 2026-08-11
- [NVD] CVE-2026-18697 (HIGH 7.5) — An issue in MongoDB Server's aggregation framework could allow an unauthenticated party to cause a mongos (router) process to terminate unexpectedly by submitting a specially formed aggregation command. This could result in a denial of service, disrupting client connections routenvd · 2026-08-11
- [NVD] CVE-2026-18696 (MEDIUM 6.5) — An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to perform certain data-definition operations, such as dropping or modifying collections, against collections they do not have permission to manipulate. This is dunvd · 2026-08-11
- [NVD] CVE-2026-18695 (MEDIUM 6.5) — An issue in MongoDB Server's handling of certain query predicates against time-series collections with a metaField could allow an authenticated user with write access to cause the server process to terminate unexpectedly, resulting in a denial of service.nvd · 2026-08-11
- [NVD] CVE-2026-18694 (HIGH 7.1) — An issue in MongoDB Server's geospatial query processing could allow an authenticated user with write privileges to cause certain malformed geometry data to be stored and later processed without proper validation. Subsequent queries against this data could then result in the servnvd · 2026-08-11
- [NVD] CVE-2026-18693 (HIGH 7.6) — An issue in MongoDB Server's handling of timeseries collections could allow an authenticated user with write privileges to cause an internal data structure to become inconsistent through certain document insertions. A subsequent insert into the affected bucket could then result invd · 2026-08-11
- [NVD] CVE-2026-18692 (HIGH 8.8) — An issue in MongoDB Server's handling of timeseries bucket lifecycle could allow an authenticated user with write privileges to cause an internal reference to be used after the underlying memory has been freed. Subsequent operations could then result in a server crash or, potentinvd · 2026-08-11
- [NVD] CVE-2026-18691 (HIGH 8.8) — An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to influence which authentication mechanism is used when one replica set member connects to another. Under certain conditions, this could cause the cluster's shared internnvd · 2026-08-11
- [NVD] CVE-2026-18690 (HIGH 8.1) — An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collections that their assigned privileges should not permit. This could result in critical system collections being dropped and recreatenvd · 2026-08-11
- [NVD] CVE-2026-18688 (HIGH 7.1) — An issue in MongoDB Server's aggregation framework could allow an authenticated user to trigger an out-of-bounds memory read by providing a specially formed numeric parameter in a certain aggregation pipeline stage. This could result in a server crash (denial of service) and may nvd · 2026-08-11
- [NVD] CVE-2026-18687 (HIGH 7.1) — MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request parameters against the collection's encrypted field configuration before use. An authenticated user with readWrite privileges could submit a specially formed requesnvd · 2026-08-11
- Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Clientthehackernews · 2026-08-11
- [GHSA] GHSA-9mr8-pwpw-3j2w (medium) — Microsoft Security Advisory CVE-2026-62909 – .NET Elevation of Privilege Vulnerabilitygithub_advisories · 2026-08-11
- [GHSA] GHSA-jqhp-238x-qhgf (high) — Microsoft Security Advisory CVE-2026-62886 – .NET Elevation of Privilege Vulnerabilitygithub_advisories · 2026-08-11
- [GHSA] GHSA-m93f-wj8c-rp8p (high) — Microsoft Security Advisory CVE-2026-62901 – .NET Denial of Service Vulnerabilitygithub_advisories · 2026-08-11
- [Orova] Ganzhou Xinye Craft Co., Ltd. posted to leak siteransomware_live · 2026-08-11
- [GHSA] GHSA-r6mh-95jw-g7qg (medium) — Microsoft Security Advisory CVE-2026-62899 – .NET Security Feature Bypass Vulnerabilitygithub_advisories · 2026-08-11
- Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commandsthehackernews · 2026-08-11
- [GHSA] GHSA-c494-m2fq-59mx (high) — Microsoft Security Advisory CVE-2026-62898 – .NET Information Disclosure Vulnerabilitygithub_advisories · 2026-08-11
- [Panzer] Xpress Tech posted to leak siteransomware_live · 2026-08-11
- [NVD] CVE-2026-71362 (CRITICAL 9.1) — Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.nvd · 2026-08-11
- Microsoft's August 2026 Patch Tuesday Addresses 398 CVEs (CVE-2026-68820)tenable · 2026-08-11
- [Control systems] Siemens security advisory (AV26-802)cccs_ca · 2026-08-11
- The August 2026 Security Update Reviewzdi_blog · 2026-08-11
- CRA Readiness: A Practitioner’s Guide to Complianceopenssf_blog · 2026-08-11
- Rapid7 security advisory (AV26-801)cccs_ca · 2026-08-11
- Shattering the Dream – When a Job Offer Becomes a Zero-Day Attackcheckpoint_research · 2026-08-11
- How Trail of Bits helps verify the integrity of your Signal chatstrailofbits · 2026-08-11
- [qilin] G.M.A. GRANDI MARCHE AUTOMOBILI - S.R.L posted to leak siteransomware_live · 2026-08-11
- [qilin] Crown Group posted to leak siteransomware_live · 2026-08-11
- [NVD] CVE-2026-39452 (HIGH 7.3) — Protection mechanism failure for some Intel(R) Transfer Learning Tool before version v0.7 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable escalationvd · 2026-08-11
- [NVD] CVE-2025-31936 (MEDIUM 5.7) — Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processors when using Intel(R) TDX within SMM may allow an escalation of privilege. SMM adversary with a privileged user combined with a high complexity attack may enable escalation of privilnvd · 2026-08-11
- From Scanner Findings to Verifiable Web Application Riskhorizon3 · 2026-08-11
- Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCEthehackernews · 2026-08-11
- Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerabilitycisco_psirt · 2026-08-11
- DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disruptthehackernews · 2026-08-11
- Valve warns Steam hardware buyers: Expect fake delivery scamsmalwarebytes_blog · 2026-08-11
- How to Create a Secure WordPress Staging Site: Beginner’s Guidesucuri_blog · 2026-08-11
- When "Prepare to Disconnect" Becomes Official Guidance: What CI Fortify Means for OT Securityzscaler_threatlabz · 2026-08-11
- [NVD] CVE-2026-73070 (MEDIUM 5.5) — Vim is an open source, command line text editor. Prior to 9.2.0842, the socket server backend in src/socketserver.c accepts unbounded client connections in socketserver_accept(), causing descriptors to overflow fd_set structures in src/channel.c and fixed-size struct pollfd arraynvd · 2026-08-11
- [NVD] CVE-2026-18640 (HIGH 7.1) — The NewNotebook API does not sufficiently sanitize its parameters allowing an authenticated user with NOTEBOOK_EDIT permission to write the notebook record outside the org's data store directory. The file written must have an extension of ".json.db" but can otherwise overwrite otnvd · 2026-08-11
- [NVD] CVE-2026-18639 (HIGH 7.3) — When Velociraptor is configured to use an OIDC IdP for authentication, it uses the email claim as a username. However, some IdP allow users to change the email claim without verification. Some IdPs do not set the "email_verified" claim and do not actually verify the email. This nvd · 2026-08-11
- [NVD] CVE-2026-11814 — A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of the affected device. This issue is limited nvd · 2026-08-11
- [NVD] CVE-2026-11739 — A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker in the middle) to compromise the confidentiality and integrity of the affected device.nvd · 2026-08-11
- 5 Key Takeaways from Black Hat USA 2026orca_security · 2026-08-11
- Social media platforms crack down on drone factory recruiting gamemalwarebytes_blog · 2026-08-11
- [GHSA] GHSA-87fv-vqqr-m4jr (critical) — SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedlegithub_advisories · 2026-08-11
- AI Genie in the Wildschneier · 2026-08-11
- [dragonforce] QPC Global posted to leak siteransomware_live · 2026-08-11
- AMD security advisory (AV26-800)cccs_ca · 2026-08-11
- [interlock] AngMar Companies posted to leak siteransomware_live · 2026-08-11
- [NVD] CVE-2026-72925 (MEDIUM 6.1) — SWC is a TypeScript / JavaScript compiler written in Rust. Prior to @swc/html 1.15.47-nightly-20260729.1 and swc_html_minifier 59.0.0, the minifyJson processing in crates/swc_html_minifier/src/lib.rs parsed and serialized attacker-controlled JSON in application/json and applicatinvd · 2026-08-11
- [NVD] CVE-2026-18860 (HIGH 8.7) — Velociraptor allows multi-tenant deployments named "Orgs". By default Velociraptor, uses the ROOT org, but users can create child orgs for other tenants within the same deployment. Users can have different permissions in each org. To manage Orgs, Velociraptor usually examines tnvd · 2026-08-11
- [NVD] CVE-2026-18636 (MEDIUM 6.8) — The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows reading files from the datastore. To prevent users from reading sensitive files or accessing other orgs, the requested path is prefix checked against a list of denied prefixes. This prefix check can be bypassed alnvd · 2026-08-11
- [NVD] CVE-2026-18635 (HIGH 7.2) — Velociraptor's VQL has a query() plugin which allows running a VQL query in a different org or user context. To be able to run as a different user, the calling user needs to have the IMPERSONATE permission (usually only given to administrators). Velociraptor versions prior to 0.7nvd · 2026-08-11
- [NVD] CVE-2026-17535 (MEDIUM 6.2) — Velociraptor's NTFS parsing library mishandles several out of bound and memory exhaustion bugs which may be triggered by maliciously crafted NTFS images. Typically Velociraptor's NTFS parser is used on live NTFS filesystems, limiting the opportunity of attackers corrupting the fnvd · 2026-08-11
- Commvault security advisory (AV26-799)cccs_ca · 2026-08-11
- Beware of phishing emails disguised as requests to review quotes (PhantomStealer)ahnlab · 2026-08-11
- July 2026 Infostealer Trend Reportahnlab · 2026-08-11
- Enriched URL Reports: VirusTotal URL Scanning 2.0virustotal_blog · 2026-08-11
- [payload] B&B Hydraulik posted to leak siteransomware_live · 2026-08-11
- [payload] Stücheli Architekten posted to leak siteransomware_live · 2026-08-11
- [payload] Baya Technologies posted to leak siteransomware_live · 2026-08-11
- [krybit] www.kilpi-koskinen.fi posted to leak siteransomware_live · 2026-08-11
- [krybit] www.apsanet.com.ar posted to leak siteransomware_live · 2026-08-11
- SAP security advisory – August 2026 monthly rollup (AV26-798)cccs_ca · 2026-08-11
- HashiCorp security advisory (AV26-797)cccs_ca · 2026-08-11
- Top 10 Phishing Kits Used by Cybercriminalssocradar_blog · 2026-08-11
- Sexual predators targeting online accounts for intimate images, FBI warnsmalwarebytes_blog · 2026-08-11
- [qilin] Service Evaluation Concepts posted to leak siteransomware_live · 2026-08-11
- [NVD] CVE-2026-72774 (MEDIUM 6.5) — n8n before 1.123.67, 2.31.5, and 2.32.1 contains a credential authorization bypass in the HTTP Request node. An authenticated member with edit access to a shared workflow can reference another user's credential while specifying the credential type via an expression. Because the pnvd · 2026-08-11
- [NVD] CVE-2026-72772 (HIGH 8.8) — n8n before 2.32.1 (and before 2.31.5) is vulnerable to account takeover via the Token Exchange Embed Login feature. When a validly-signed incoming token was matched to a local account by its email claim, the service did not verify that the email claim was verified, nor that the tnvd · 2026-08-11
- [NVD] CVE-2026-72769 (HIGH 8.1) — n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the VM expression engine. An authenticated user able to create or edit a workflow expression can abuse the engine's array-element access to obtain a reference to a host built-in and pollute itnvd · 2026-08-11
- [NVD] CVE-2026-72767 (HIGH 8.8) — n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a remote code execution vulnerability in the Git node. Authenticated users with rights to create and execute workflows can stage a crafted local repository that causes git to run hooks under default git secunvd · 2026-08-11
- [NVD] CVE-2026-72764 (HIGH 8.8) — n8n's JavaScript task runner shared a single module cache across all users' Code-node executions. In affected versions (before 1.123.67, 2.31.5, and 2.32.1), a user able to run a Code node could poison a cached module and thereby alter other users' Code-node executions on the samnvd · 2026-08-11
- [NVD] CVE-2026-72762 (HIGH 8.8) — n8n versions before 1.123.67, 2.31.5, and 2.32.1 contain an arbitrary file write vulnerability in the Edit Image node, which passes its output format parameter to the underlying image library without validation. An authenticated user able to run workflows can supply a crafted fornvd · 2026-08-11
- Grafana security advisory (AV26-796)cccs_ca · 2026-08-11
- OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Developmentthehackernews · 2026-08-11
- What’s in the SOSS? Podcast #68 – S3E20 CRA Readiness: Practical Strategies for Open Source Communities with Megan Knightopenssf_blog · 2026-08-11
- Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)rapid7 · 2026-08-11
- CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)rapid7 · 2026-08-11
- [qilin] tommer construction posted to leak siteransomware_live · 2026-08-11
- Love/hate relationship: The AI affair. Young people love AI, but it’s breaking their trustmalwarebytes_blog · 2026-08-11
- [NVD] CVE-2026-50237 (HIGH 7.4) — A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A namespace tenant can plant a ProjectHelmChartRepository with an arbitrary URL that the console pod fetches server-side, bypassing tenant egress restrictions. Combined withnvd · 2026-08-11
- [NVD] CVE-2026-50236 (HIGH 7.4) — An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without validation, with path neutralization enabling arbitrary endpoint targeting and full response reflection from the console pod's privnvd · 2026-08-11
- [NVD] CVE-2026-13738 (CRITICAL 9.8) — CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Cliennvd · 2026-08-11
- A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devicesthehackernews · 2026-08-11
- Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repothehackernews · 2026-08-11
- INC Ransom Targeted 24 Law Firms, but Only 10 are Listedsocradar_blog · 2026-08-11
- Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participantssecurelist · 2026-08-11
- Mira Hormone Monitor, Mira Android Appcisa_advisories · 2026-08-11
- Pulsetto Vagus Nerve Stimulatorcisa_advisories · 2026-08-11