THREAT OPS › Threat News
Threat Intelligence News
11790 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shellsthehackernews · 2026-09-16
- Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokensthehackernews · 2026-09-16
- Securing AWS Private Lambda with Zscaler Zero Trust Cloudzscaler_threatlabz · 2026-09-16
- Re: Retrospective by 'gpg.fail' authorsoss_sec · 2026-09-16
- ZDI-26-706: (0Day) CrewAI crewAI Framework Agent Loading Unsafe Reflection Remote Code Execution Vulnerabilityzdi_published · 2026-09-16
- ZDI-26-705: (0Day) BusyBox libarchive Symlink Directory Traversal Arbitrary File Creation Vulnerabilityzdi_published · 2026-09-16
- ZDI-26-713: GIMP APNG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerabilityzdi_published · 2026-09-16
- ZDI-26-711: NoMachine Redis Improper Authentication Local Privilege Escalation Vulnerabilityzdi_published · 2026-09-16
- [qilin] Aarsleff posted to leak siteransomware_live · 2026-09-16
- [dragonforce] Community Property Management posted to leak siteransomware_live · 2026-09-16
- [dragonforce] Owen Leigh Optometry posted to leak siteransomware_live · 2026-09-16
- Extending Zero Trust to AI: What Federal Civilian Agencies Can Do Nowzscaler_threatlabz · 2026-09-16
- Google Chrome Multiple Vulnerabilitieshkcert · 2026-09-16
- Microsoft Edge Multiple Vulnerabilitieshkcert · 2026-09-16
- Oracle Products Multiple Vulnerabilitieshkcert · 2026-09-16
- Re: Retrospective by 'gpg.fail' authorsoss_sec · 2026-09-16
- [CISA KEV] CVE-2026-58704 — Google Pixel: Google Pixel Improper Authorization Vulnerabilitycisa_kev · 2026-09-16
- [CISA KEV] CVE-2026-76460 — Cisco Identity Services Engine: Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerabilitycisa_kev · 2026-09-16
- [CISA KEV] CVE-2026-87886 — Acronis Backup: Acronis Backup Incorrect Default Permissions Vulnerabilitycisa_kev · 2026-09-16
- Oracle September 2026 Critical Security Patch Update addresses 672 CVEstenable · 2026-09-15
- [GHSA] GHSA-2h44-8472-frjj (critical) — @zereight/mcp-gitlab Vulnerable to Server-Side Request Forgerygithub_advisories · 2026-09-15
- [GHSA] GHSA-vmp7-252j-cwp7 (critical) — @zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transportgithub_advisories · 2026-09-15
- [GHSA] GHSA-5648-rgj9-v224 (high) — @zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unauthenticated transports, session-exhaustion DoSgithub_advisories · 2026-09-15
- [GHSA] GHSA-4595-rvpx-4q34 (high) — emp3r0r has an unauthenticated HTTP Polling DoSgithub_advisories · 2026-09-15
- Countermeasures for AI-Enabled Attacks Start with Deceptionzscaler_threatlabz · 2026-09-15
- [NVD] CVE-2026-87194 (HIGH 7.5) — Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oraclnvd · 2026-09-15
- [NVD] CVE-2026-87192 (HIGH 7.1) — Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oraclenvd · 2026-09-15
- [NVD] CVE-2026-83318 (HIGH 7.5) — Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Administration). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to convd · 2026-09-15
- [NVD] CVE-2026-83315 (HIGH 8.8) — Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP tnvd · 2026-09-15
- CVE-2026-86792: Apache Airflow Apache Kafka provider: Connection-editor remote code execution on the Scheduler via Kafka connection callback configurationoss_sec · 2026-09-15
- CVE-2026-86465: Apache Airflow Akeyless provider: Akeyless secrets backend: team-scope guard bypass via user-controlled keyoss_sec · 2026-09-15
- [GHSA] GHSA-gq9p-f254-h286 (high) — Http4s: Ember HTTP/2 buffers a frame's declared payload before checking SETTINGS_MAX_FRAME_SIZEgithub_advisories · 2026-09-15
- CVE-2026-86466: Apache Airflow FAB provider: FAB Authentik provider: id_token issuer/audience not validatedoss_sec · 2026-09-15
- [GHSA] GHSA-5hq8-qhww-jm7q (high) — libp2p-quic: Remote panic via certificate expiry race during QUIC handshakegithub_advisories · 2026-09-15
- [GHSA] GHSA-crq5-92j2-j7wv (medium) — Http4s: ResourceService and Webjar Service path escape via percent-encoded separatorsgithub_advisories · 2026-09-15
- [GHSA] GHSA-cp4q-fqw9-4hf6 (high) — Http4s Ember HTTP/2: unbounded continuation frame accumulationgithub_advisories · 2026-09-15
- [GHSA] GHSA-jrpm-956j-96jg (medium) — Http4s: Ember chunk parser lenience (TE.TE request smuggling)github_advisories · 2026-09-15
- [GHSA] GHSA-grh8-3p95-f9rr (medium) — Http4s: CookieJar middleware matches by substring, leaking cookies cross-origingithub_advisories · 2026-09-15
- [GHSA] GHSA-wv64-j4fq-5f9x (medium) — Http4s: CookieJar middleware accepts arbitrary Set-Cookie domaingithub_advisories · 2026-09-15
- [GHSA] GHSA-8f3q-3jmv-7prw (high) — Http4s Ember HTTP/2 has an unbounded outbound frame queuegithub_advisories · 2026-09-15
- CVE-2026-86462: Apache Airflow FAB provider: FAB Admin password PATCH does not invalidate database-backed sessionsoss_sec · 2026-09-15
- [Vexy Ransomware] Hashimoto Jimuki posted to leak siteransomware_live · 2026-09-15
- CVE-2026-82311: Apache Airflow FAB provider: FAB password reset never invalidates sessions: string/int _user_id comparison is always falseoss_sec · 2026-09-15
- CVE-2026-82310: Apache Airflow FAB provider: FAB auth manager: deactivated users retain and renew Core API JWT accessoss_sec · 2026-09-15
- Boost Engagement with Free Passkeys by Wordfencewordfence · 2026-09-15
- [GHSA] GHSA-fm4g-76c9-7w69 (high) — Http4s: DigestAuth nonce map grows unboundedgithub_advisories · 2026-09-15
- [GHSA] GHSA-9xww-74xv-gjfp (medium) — Http4s: DigestAuth allows replay of captured requestsgithub_advisories · 2026-09-15
- [GHSA] GHSA-9998-894r-fwvr (high) — Http4s Ember Transfer-Encoding value parsing (TE.CL / TE.0 request smuggling)github_advisories · 2026-09-15
- CVE-2026-76187: Apache Airflow Keycloak provider: Any realm client's credentials mint an Airflow session JWToss_sec · 2026-09-15
- [GHSA] GHSA-8h4c-x2wg-6xp8 (critical) — Http4s Ember accepts Transfer-Encoding combined with Content-Length (CL.TE request smuggling)github_advisories · 2026-09-15
- [GHSA] GHSA-9vwc-pc8p-253q (high) — Http4s Ember HTTP/2 does not enforce SETTINGS_MAX_CONCURRENT_STREAMSgithub_advisories · 2026-09-15
- [GHSA] GHSA-6m4x-pp6q-5jmm (high) — Http4s Ember HTTP/2: unbounded inbound body bufferinggithub_advisories · 2026-09-15
- CVE-2026-76186: Apache Airflow Keycloak provider: Keycloak token cookies not bound to Airflow session identityoss_sec · 2026-09-15
- [GHSA] GHSA-rf68-8gjr-36q7 (low) — Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is emptygithub_advisories · 2026-09-15
- [GHSA] GHSA-r8cr-4f9w-7r75 (medium) — Netmaker has a boolean‑based SQL Injectiongithub_advisories · 2026-09-15
- [safepay] marlinhvac.com posted to leak siteransomware_live · 2026-09-15
- [safepay] neumerkel-gmbh.de posted to leak siteransomware_live · 2026-09-15
- [safepay] triniticaring.org posted to leak siteransomware_live · 2026-09-15
- [safepay] laconcepcion.com.mx posted to leak siteransomware_live · 2026-09-15
- [safepay] meterex.com posted to leak siteransomware_live · 2026-09-15
- [safepay] stoecklin-kuechen.ch posted to leak siteransomware_live · 2026-09-15
- [safepay] ryomo.co.jp posted to leak siteransomware_live · 2026-09-15
- [safepay] ara-lyss.ch posted to leak siteransomware_live · 2026-09-15
- [safepay] gob.pe posted to leak siteransomware_live · 2026-09-15
- [NVD] CVE-2026-84048 — Joomla Extension - joomgalleryfriends.net - Unauthenticated arbitrary file upload via the TUS endpoint in JoomGallery < 4.4.2 - The TUS endpoint allows arbitrary file uploads, however neither file name nor file extension are under attacker control. Code execution requires non-stanvd · 2026-09-15
- [NVD] CVE-2026-68532 — Concrete CMS 9.0.0 to dashboard group type controller did not validate a CSRF token on its delete action, resulting in cross-site request forgery. A remote unauthenticated attacker could cause an authenticated user with group type management permission to delete a custom group tynvd · 2026-09-15
- Docker security advisory (AV26-925)cccs_ca · 2026-09-15
- [interlock] Springfield Public Schools posted to leak siteransomware_live · 2026-09-15
- Mozilla security advisory (AV26-924)cccs_ca · 2026-09-15
- KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokensthehackernews · 2026-09-15
- CVE-2026-84501: Apache ZooKeeper: Operational log forgery via newline injection in EnsembleAuthenticationProvideross_sec · 2026-09-15
- CVE-2026-84439: Apache ZooKeeper: Audit log injection via unsanitized output from multiple sourcesoss_sec · 2026-09-15
- CVE-2026-79993: Apache ZooKeeper: Missing ACL check on deleteContainer opcode allows unauthorized deletion of any empty persistent/container znodeoss_sec · 2026-09-15
- CVE-2026-59969: Apache ZooKeeper: Improper validation of certificate with host mismatch in FIPS modeoss_sec · 2026-09-15
- CVE-2026-59739: Apache ZooKeeper: Information disclosure via SetWatches reconnect replayoss_sec · 2026-09-15
- [NVD] CVE-2026-82837 (MEDIUM 5.3) — GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that certain conditions could have allowed an authenticated user to access sensitive credentials and tokens without transiting the expected nvd · 2026-09-15
- [NVD] CVE-2026-81898 — In Concrete CMS below version 9.5.3, the Address attribute's country-less text formatter skipped HTML-escaping, enabling stored XSS in Express association views. A user able to submit an Address attribute could execute script in the session of any dashboard user who opened the afnvd · 2026-09-15
- [NVD] CVE-2026-18113 — In Concrete CMS 9.0 to 9.5.2, the Top Navigation Bar block did not HTML-escape dropdown child page names before writing them into the page, so a user who could create or rename pages could store a script through a child page name and have it run in the browser of any visitor, edinvd · 2026-09-15
- [NVD] CVE-2026-13210 (HIGH 7.7) — GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an authenticated user to access CI/CD variables outside their intended environment scope due nvd · 2026-09-15
- [NVD] CVE-2026-12910 (MEDIUM 5.4) — GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an authenticated user to bypass SAML SSO sign-in restrictions and authenticate without SSO dunvd · 2026-09-15
- [NVD] CVE-2026-12749 (MEDIUM 6.4) — IBM Cloud Pak for Business Automation is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trunvd · 2026-09-15
- Before You Patch. Why Patch Reliability Matters for Confident Deploymentqualys · 2026-09-15
- [insomnia] Wiggins, Childs, Pantazis, Fisher, & Goldfarb LLC posted to leak siteransomware_live · 2026-09-15
- Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journaliststhehackernews · 2026-09-15
- [NVD] CVE-2026-91966 (MEDIUM 5.8) — AVideo through 29.0 contains an unauthenticated server-side request forgery vulnerability in the check_site_availability function that accepts attacker-controlled HTTP Host headers. Attackers can send requests to submitIndex.php or ajax.php with arbitrary Host headers to probe innvd · 2026-09-15
- [NVD] CVE-2026-91959 (MEDIUM 6.5) — FreeRDP before 3.31.0 contains a buffer over-read vulnerability in the rts_read_result function within the RPC gateway transport parser. Attackers can send a malicious BIND_ACK PDU with a truncated result entry to trigger an out-of-bounds read causing process abort.nvd · 2026-09-15
- [NVD] CVE-2026-91951 (MEDIUM 6.5) — FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in the urbdrc client channel's urb_send_current_frame_number_result() function. A malicious RDP server can send a crafted 28-byte USB redirection message to trigger a 4-byte write past the allocated 16-bynvd · 2026-09-15
- [NVD] CVE-2026-91941 (HIGH 7.5) — Crawl4AI before 0.9.3 contains an uncontrolled resource consumption vulnerability in PDFContentScrapingStrategy that allows untrusted clients to cause denial of service. Attackers can select the PDF scraping strategy in POST requests to download large remote PDFs without size or nvd · 2026-09-15
- [NVD] CVE-2026-91935 (HIGH 8.3) — Flowise before 3.1.4 fails to validate baseURL parameters in chat-model nodes, allowing authenticated users to redirect requests to arbitrary hosts. Attackers with chatflows:create or chatflows:update permissions can exfiltrate LLM provider API keys by redirecting requests to clonvd · 2026-09-15
- [NVD] CVE-2026-91930 (HIGH 7.5) — Flowise before 3.1.4 fails to scope enterprise organization and workspace membership APIs to the caller's tenant, allowing authenticated users to supply arbitrary organization IDs. Attackers can add themselves as organization owners, create workspaces, and gain administrative accnvd · 2026-09-15
- Grow CRA Readiness: Find Your Path Through the European Union Cyber Resilience Actopenssf_blog · 2026-09-15
- Enhancing Application and Threat Detection in Zero Trust Firewallzscaler_threatlabz · 2026-09-15
- How to opt out of AI chatbot trainingmalwarebytes_blog · 2026-09-15
- [interlock] City of Fort Smith Arkansas posted to leak siteransomware_live · 2026-09-15
- Re: Retrospective by 'gpg.fail' authorsoss_sec · 2026-09-15
- BambooToken Malware Uses MQTT to Control Windows and Linux Systemsthehackernews · 2026-09-15
- [NVD] CVE-2026-91836 (LOW 2.8) — A flaw has been found in OpenClaw ClawScan up to 0.1.6. This affects an unknown function of the file internal/runner/static_scanner.go of the component Static Scanner. This manipulation causes incomplete comparison with missing factors. It is possible to launch the attack on the nvd · 2026-09-15
- [NVD] CVE-2026-39919 (CRITICAL 9.8) — Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG 2000 output adapter (base/sjpx_openjpeg.c) that allows attackers to cause memory corruption by supplying a crafted PDF containing a JPEG 2000 image with mismatched component subsampling facnvd · 2026-09-15
- GNU security advisory (AV26-923)cccs_ca · 2026-09-15
- [qilin] Taurus Ibérica posted to leak siteransomware_live · 2026-09-15