THREAT OPS › Threat News
Threat Intelligence News
11857 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- CISA Adds Three Known Exploited Vulnerabilities to Catalogcisa_advisories · 2026-08-11
- Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workersthehackernews · 2026-08-11
- AI for Military Supportschneier · 2026-08-11
- Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11thehackernews · 2026-08-11
- Cloud Compliance Solutions for Enterprises: The Automation Checklistorca_security · 2026-08-11
- Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secretsthehackernews · 2026-08-11
- [NVD] CVE-2026-33922 (MEDIUM 6.0) — A path traversal vulnerability was discovered in the Offline archives functionality of the local web interface due to insufficient validation of an input parameter. A local user with administrative credentials for the web interface could submit an archive name containing traversanvd · 2026-08-11
- [NVD] CVE-2026-33921 (MEDIUM 5.2) — The Windows installer deployed Npcap leaving its access restriction option at the insecure default value, so the driver was accessible to every local user of the host instead of being restricted to administrators only. A local user without administrative privileges could use the nvd · 2026-08-11
- Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selectionsecurelist · 2026-08-11
- Kimwolf v7: An Evolution of the Kimwolf Botnetunit42 · 2026-08-11
- [NVD] CVE-2026-72693 (HIGH 7.8) — `openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged context. In the documented `kbrequest`/init usage, the ownership test in `authenticate_user()` relies on `stat("/proc/<pid>/fd/0")`. `stat()` on `/proc/<pid>/fdnvd · 2026-08-11
- [NVD] CVE-2026-71217 (HIGH 7.5) — A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON with oversized numeric parameters, such as `parallel` and `len`, which are not properly validated by the server. This improper input validation can lead to excessinvd · 2026-08-11
- Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networksthehackernews · 2026-08-11
- Watch out for fake TikTok Shops trying to steal your moneymalwarebytes_blog · 2026-08-11
- Fake popular sites offer a free app, instead take over PCsmalwarebytes_blog · 2026-08-11
- The Hidden Threat in Your Software Development Lifecycle: Why Self-Hosted Runners Need Zero Trustzscaler_threatlabz · 2026-08-11
- Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbinethehackernews · 2026-08-11
- [NVD] CVE-2026-18348 (MEDIUM 4.1) — Missing authorization check in the upload_azure, upload_sftp, and upload_smb VQL plugins allows an authenticated analyst-role user can initiate attacker-controlled outbound network connections from the Velociraptor server, bypassing the NETWORK ACL permission boundary. This enablnvd · 2026-08-11
- [direwolf] Leafwell posted to leak siteransomware_live · 2026-08-11
- [aurora] FREYWILLE posted to leak siteransomware_live · 2026-08-11
- BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Adminsthehackernews · 2026-08-11
- ZDI-26-556: Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerabilityzdi_published · 2026-08-11
- ZDI-26-555: Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerabilityzdi_published · 2026-08-11
- ZDI-26-554: Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerabilityzdi_published · 2026-08-11
- ZDI-26-553: OriginLab Origin Viewer OGW File Parsing Memory Corruption Remote Code Execution Vulnerabilityzdi_published · 2026-08-11
- ZDI-26-552: OriginLab Origin Viewer OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerabilityzdi_published · 2026-08-11
- ZDI-26-551: OriginLab OriginPro OGG File Parsing Memory Corruption Remote Code Execution Vulnerabilityzdi_published · 2026-08-11
- ZDI-26-550: OriginLab OriginPro OGW File Parsing Memory Corruption Remote Code Execution Vulnerabilityzdi_published · 2026-08-11
- ZDI-26-549: OriginLab OriginPro OGG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerabilityzdi_published · 2026-08-11
- ZDI-26-548: OriginLab OriginPro OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerabilityzdi_published · 2026-08-11
- ZDI-26-547: OriginLab OriginPro OPJU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerabilityzdi_published · 2026-08-11
- ZDI-26-544: Microsoft Windows Deployment Services Use-After-Free Remote Code Execution Vulnerabilityzdi_published · 2026-08-11
- ZDI-26-543: Microsoft Windows ICC File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerabilityzdi_published · 2026-08-11
- ZDI-26-542: Microsoft Windows UMPDDrvBitBlt Improper Object Management Local Privilege Escalation Vulnerabilityzdi_published · 2026-08-11
- ZDI-26-541: (Pwn2Own) Microsoft Windows win32kfull Use-After-Free Local Privilege Escalation Vulnerabilityzdi_published · 2026-08-11
- ZDI-26-540: (Pwn2Own) Microsoft Windows win32kfull Use-After-Free Information Disclosure Vulnerabilityzdi_published · 2026-08-11
- ZDI-26-539: (Pwn2Own) Microsoft Windows ipt.sys Incorrect Permission Assignment Local Privilege Escalation Vulnerabilityzdi_published · 2026-08-11
- ZDI-26-538: (Pwn2Own) Microsoft Exchange Improper Authorization Privilege Escalation Vulnerabilityzdi_published · 2026-08-11
- ZDI-26-537: (Pwn2Own) Microsoft Windows storport Integer Overflow Local Privilege Escalation Vulnerabilityzdi_published · 2026-08-11
- ZDI-26-536: (Pwn2Own) Microsoft Windows http.sys Integer Overflow Local Privilege Escalation Vulnerabilityzdi_published · 2026-08-11
- ZDI-26-535: (Pwn2Own) Microsoft Exchange External Control of File Path Remote Code Execution Vulnerabilityzdi_published · 2026-08-11
- ZDI-26-532: SonicWall Email Security updateNetIf Command Injection Local Privilege Escalation Vulnerabilityzdi_published · 2026-08-11
- ZDI-26-531: SonicWall GMS Virtual Appliance interface Command Injection Local Privilege Escalation Vulnerabilityzdi_published · 2026-08-11
- ZDI-26-530: SonicWall Email Security snmp Command Injection Local Privilege Escalation Vulnerabilityzdi_published · 2026-08-11
- ZDI-26-529: Samsung Galaxy S25 TIFF File Processing Heap-based Buffer Overflow Remote Code Execution Vulnerabilityzdi_published · 2026-08-11
- ZDI-26-528: Wazuh Cluster DAPI Protocol Deserialization of Untrusted Data Remote Code Execution Vulnerabilityzdi_published · 2026-08-11
- ZDI-26-527: Wazuh Cluster DAPI Protocol Deserialization of Untrusted Data Remote Code Execution Vulnerabilityzdi_published · 2026-08-11
- F5 Products Denial of Service Vulnerabilityhkcert · 2026-08-11
- [genesis] Interim HealthCare posted to leak siteransomware_live · 2026-08-11
- Mines, Minds, and Machines: The Journey of AIrecordedfuture · 2026-08-11
- [CISA KEV] CVE-2026-68820 — Microsoft Windows Ancillary Function Driver for WinSock : Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerabilitycisa_kev · 2026-08-11
- 13 million tool calls: auditing every AI coding agent action with Elastic Agentelastic_security · 2026-08-11
- [CISA KEV] CVE-2026-20349 — Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) : Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerabilitycisa_kev · 2026-08-11
- [CISA KEV] CVE-2026-72898 — Metabase Metabase: Metabase SQL Injection Vulnerabilitycisa_kev · 2026-08-11
- [NVD] CVE-2026-48161 — react18-use is a React 19 use hook shim. Between 2026-05-19 01:07:01 and 2026-05-19 15:20:43, the default branch contained malicious commits 7b79148d1495a2505f9277da295a98cf176f4496 through 7b79148d1495a2505f9277da295a98cf176f4496 that executed remote attacker-controlled code on nvd · 2026-08-10
- [direwolf] BigSpark posted to leak siteransomware_live · 2026-08-10
- [anubis] Cleaver-Brooks posted to leak siteransomware_live · 2026-08-10
- [Deadlock] LT Group / Fortune Tobacco Corp posted to leak siteransomware_live · 2026-08-10
- [NVD] CVE-2026-72917 (MEDIUM 5.9) — AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. From 1.0.0 to 1.15.0, AnythingLLM's unauthenticated account-recovery flow in server/utils/PasswordRecovery/index.js uses recoverAccount() to deduplicate thenvd · 2026-08-10
- [NVD] CVE-2025-32736 — Cross-Site Request Forgery weaknesses in the Administrative Console of PingFederate versions before version 13.1 may allow actors to perform unauthorized actions via specially-crafted links triggered by administrators with active sessions.nvd · 2026-08-10
- The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communicationsunit42 · 2026-08-10
- [genesis] Consolidated Medical Practices of Memphis posted to leak siteransomware_live · 2026-08-10
- [genesis] Interim HealthCare (Oklahoma and Tulsa) posted to leak siteransomware_live · 2026-08-10
- [direwolf] Chat Jurídico posted to leak siteransomware_live · 2026-08-10
- [direwolf] Merge posted to leak siteransomware_live · 2026-08-10
- [NVD] CVE-2026-72904 — Firecrawl turns entire websites into LLM-ready markdown or structured data. Prior to 2.11.32, a critical arbitrary file read vulnerability exists in Firecrawl's extraction functionality due to unsafe schema dereferencing of user-supplied JSON schemas in apps/api/src/lib/extract/hnvd · 2026-08-10
- [NVD] CVE-2026-63622 (HIGH 7.8) — A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnerability in the `virFileChownFiles()` function. By planting a symbolic link within the `swtpm` state directory, the attacker could trnvd · 2026-08-10
- [NVD] CVE-2026-18982 (HIGH 8.8) — A flaw was found in the RHOAI training-operator. This vulnerability allows a user with standard edit or admin roles in any Kubernetes namespace to escalate their privileges. Through the creation of training jobs, an attacker can impersonate service accounts, access the host filesnvd · 2026-08-10
- [NVD] CVE-2026-18951 (HIGH 8.8) — A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay incorrectly aggregates `trainjobs` management permissions into the native Kubernetes `edit ClusterRole`. This allows any user with `edit ClusterRole` permissions in a namespanvd · 2026-08-10
- [NVD] CVE-2026-18620 (HIGH 7.1) — A flaw was found in Data Science Pipelines. A restricted user, or tenant, can exploit an improper authorization vulnerability in the setDefaultServiceAccount function. By specifying a more privileged ServiceAccount (SA) during a CreateRun request, an attacker can bypass authorizanvd · 2026-08-10
- [NVD] CVE-2026-18618 (HIGH 7.5) — A flaw was found in ml-metadata. The statically-linked gRPC stack in ml-metadata is outdated, making it vulnerable to known HTTP/2 denial of service (DoS) issues. An in-cluster attacker, with network access to the MLMD pod, could exploit these vulnerabilities by sending speciallynvd · 2026-08-10
- [NVD] CVE-2026-18617 (HIGH 8.8) — A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exploit a vulnerability in the spec.database.customExtraParams field, which allows for the injection of dangerous parameters into the MySQL Data Source Name (DSN) string. By manipulating these nvd · 2026-08-10
- [NVD] CVE-2026-18611 (HIGH 7.5) — A flaw was found in the Data Science Pipelines Operator. This vulnerability allows an unauthenticated attacker to derive sensitive credentials, such as MariaDB root/user passwords and MinIO access/secret keys, if they can access the MinIO Route or MariaDB Service. The flaw occursnvd · 2026-08-10
- [NVD] CVE-2026-18608 (HIGH 8.7) — A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which defines its permissions, includes extensive privileges beyond what is necessary for its operation. These excessive permissions, such as the ability to execute commands within pods annvd · 2026-08-10
- [NVD] CVE-2026-15581 (HIGH 8.0) — A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to bypass authentication and directly access the TAS backend API. An attacker can exploit this to read, tamper with, or delete monitoring data and configurations, anvd · 2026-08-10
- [NVD] CVE-2026-15467 (HIGH 8.1) — A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the cluster can exploit this vulnerability by configuring a sidecar container to bypass existing security policies. This allows the user to enable and execute untrusted remote cnvd · 2026-08-10
- Between Two Nerds: The cyber resistance!riskybiz_news · 2026-08-10
- [qilin] HIGEN MOTOR(critical data) posted to leak siteransomware_live · 2026-08-10
- [direwolf] Swyft Inc. posted to leak siteransomware_live · 2026-08-10
- [NVD] CVE-2026-68872 (MEDIUM 6.5) — The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backenvd · 2026-08-10
- [NVD] CVE-2026-68871 (MEDIUM 6.5) — The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with this backend, a caller in one team could resolnvd · 2026-08-10
- [NVD] CVE-2026-68870 (MEDIUM 5.3) — The Azure Key Vault secrets backend in Apache Airflow's Microsoft Azure provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with this backend, a caller in one team cnvd · 2026-08-10
- Data Center Physical Security: Mitigating FPV Drone Threatsflashpoint · 2026-08-10
- [direwolf] AliveCor, Inc. posted to leak siteransomware_live · 2026-08-10
- [direwolf] Statista GmbH posted to leak siteransomware_live · 2026-08-10
- [direwolf] Quironsalud posted to leak siteransomware_live · 2026-08-10
- [direwolf] Health Carousel posted to leak siteransomware_live · 2026-08-10
- [direwolf] Fondo posted to leak siteransomware_live · 2026-08-10
- [direwolf] Osmo Wallet posted to leak siteransomware_live · 2026-08-10
- [bravox] Elettrica System posted to leak siteransomware_live · 2026-08-10
- Qualcomm security advisory (AV26-795)cccs_ca · 2026-08-10
- [Global Secret Group] Coggins Insurance Agency posted to leak siteransomware_live · 2026-08-10
- [NVD] CVE-2026-71577 (MEDIUM 6.3) — A flaw was found in multicluster-global-hub. During a ManagedClusterMigration, the system incorrectly grants all managed hubs read access to a shared communication topic. This allows a compromised managed hub to intercept and collect sensitive bootstrap kubeconfigs, which containnvd · 2026-08-10
- [NVD] CVE-2026-71576 (HIGH 8.5) — A flaw was found in multicluster-global-hub. The manager component improperly validates the source identity of incoming CloudEvents on Kafka status topics. A remote attacker, after compromising a managed hub and obtaining its Kafka client certificate, can manipulate the self-assenvd · 2026-08-10
- How to fake a data trail (and maybe lower prices) (Lock and Code S07E16)malwarebytes_blog · 2026-08-10
- [bravox] Verona 83 posted to leak siteransomware_live · 2026-08-10
- China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flawthehackernews · 2026-08-10
- Zero Trust Connectivity for Private AI Apps/Models: Who Can Actually Reach Them?zscaler_threatlabz · 2026-08-10
- Scans for Solana (Surfpool?) Endpoints, (Mon, Aug 10th)sans_isc · 2026-08-10
- [NVD] CVE-2026-48048 (HIGH 7.5) — XWiki Platform is a generic wiki platform. XWiki discovered that the patch for GHSA-5cf8-vrr8-8hjm was insufficient. Starting with version 6.2.1 and prior to versions 18.0.0RC1, 17.10.13, 17.4.9 and 16.10.17, with slightly modified parameters to the `LiveTableResults`, it is stilnvd · 2026-08-10