THREAT OPS › Threat News
Threat Intelligence News
11862 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [bravox] Verona 83 posted to leak siteransomware_live · 2026-08-10
- China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flawthehackernews · 2026-08-10
- Zero Trust Connectivity for Private AI Apps/Models: Who Can Actually Reach Them?zscaler_threatlabz · 2026-08-10
- Scans for Solana (Surfpool?) Endpoints, (Mon, Aug 10th)sans_isc · 2026-08-10
- [NVD] CVE-2026-48048 (HIGH 7.5) — XWiki Platform is a generic wiki platform. XWiki discovered that the patch for GHSA-5cf8-vrr8-8hjm was insufficient. Starting with version 6.2.1 and prior to versions 18.0.0RC1, 17.10.13, 17.4.9 and 16.10.17, with slightly modified parameters to the `LiveTableResults`, it is stilnvd · 2026-08-10
- Six npm Packages Use Ethereum Transactions to Retrieve Malicious Payloadssonatype · 2026-08-10
- Cisco security advisory (AV26-794)cccs_ca · 2026-08-10
- Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprisemsstic · 2026-08-10
- Abyssos: Technical Analysis of a New Modular RATzscaler_threatlabz · 2026-08-10
- New turnkey kit makes it easy for anyone to become a scammermalwarebytes_blog · 2026-08-10
- Roundcube security advisory (AV26-793)cccs_ca · 2026-08-10
- ⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoorsthehackernews · 2026-08-10
- DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructuremsstic · 2026-08-10
- July 2026 Dark Web Breach Incident Trend Reportahnlab · 2026-08-10
- July 2026 Dark Web Threat Actor Trend Reportahnlab · 2026-08-10
- July 2026 Dark Web Issue Trend Reportahnlab · 2026-08-10
- Attack Cases for Domestic Web Servers Running SoftEther VPN in Koreaahnlab · 2026-08-10
- [unsafe] Presentations.AI posted to leak siteransomware_live · 2026-08-10
- [akira] Alcast posted to leak siteransomware_live · 2026-08-10
- WordPress security advisory (AV26-792)cccs_ca · 2026-08-10
- HashiCorp security advisory (AV26-791)cccs_ca · 2026-08-10
- WebPros security advisory (AV26-790)cccs_ca · 2026-08-10
- When Credentials Are No Longer Enough: Device Trust in the AI Erableepingcomputer · 2026-08-10
- IBM security advisory (AV26-789)cccs_ca · 2026-08-10
- 10th August – Threat Intelligence Reportcheckpoint_research · 2026-08-10
- [Panzer] The Minor Food Group posted to leak siteransomware_live · 2026-08-10
- Critical Metabase Zero-Day Exploitedsocradar_blog · 2026-08-10
- [akira] One Vision Imaging posted to leak siteransomware_live · 2026-08-10
- [akira] i4 Solutions posted to leak siteransomware_live · 2026-08-10
- [NVD] CVE-2026-68392 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync Dereferencing RCU-protected pointers outside critical sections is invalid and may lead to UAF. Take hdev->lock for hci_conn lookup and hci_abort_convd · 2026-08-10
- [NVD] CVE-2026-68371 (HIGH 8.4) — In the Linux kernel, the following vulnerability has been resolved: usb: musb: omap2430: Do not put borrowed of_node in probe omap2430_probe() stores pdev->dev.of_node in a local np variable. This is a borrowed pointer and the probe function does not take a reference to it. Thnvd · 2026-08-10
- [NVD] CVE-2026-68367 — In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_tcm: synchronize delayed set_alt with teardown The f_tcm set_alt() path defers endpoint setup to a work item and completes the delayed status response from process context. The delayed work uses nvd · 2026-08-10
- [NVD] CVE-2026-68337 — In the Linux kernel, the following vulnerability has been resolved: bpf: Reject redirect helpers without a bpf_net_context The bpf_redirect*() helpers and skb_do_redirect() obtain the per-task bpf_redirect_info via bpf_net_ctx_get_ri(), which dereferences the current->bpf_net_cnvd · 2026-08-10
- [NVD] CVE-2026-68303 — In the Linux kernel, the following vulnerability has been resolved: drm/vc4: hvs/v3d: Fix null dereference in unbind The hvs and v3d drivers use dev_get_drvdata(master) in their unbind functions. Since the vc4-drm gets removed before its dependent drivers (vc4_hvs/vc4_v3d) the nvd · 2026-08-10
- [NVD] CVE-2026-68289 — In the Linux kernel, the following vulnerability has been resolved: tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream() In tipc_recvmsg(), the copy length is computed as: copy = min_t(int, dlen - offset, buflen); buflen is size_t but min_t(int, ...) casts it nvd · 2026-08-10
- [NVD] CVE-2026-68288 — In the Linux kernel, the following vulnerability has been resolved: net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD net_dm_packet_report_fill() and net_dm_hw_packet_report_fill() open code the NET_DM_ATTR_PAYLOAD attribute to avoid zeroing the packet payload before overnvd · 2026-08-10
- [NVD] CVE-2026-68287 (HIGH 7.5) — In the Linux kernel, the following vulnerability has been resolved: drop_monitor: fix size calculations for 64-bit attributes net_dm_packet_report_fill() and net_dm_hw_packet_report_fill() use nla_put_u64_64bit() to append 64-bit attributes (NET_DM_ATTR_PC and NET_DM_ATTR_TIMESnvd · 2026-08-10
- [NVD] CVE-2026-68286 — In the Linux kernel, the following vulnerability has been resolved: drop_monitor: perform u64_stats updates under IRQ-disabled section In net_dm_packet_trace_kfree_skb_hit() and net_dm_hw_trap_packet_probe(), u64_stats_update_begin() / u64_stats_inc() / u64_stats_update_end() wnvd · 2026-08-10
- [NVD] CVE-2026-68280 — In the Linux kernel, the following vulnerability has been resolved: drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() The deprecated UNIVERSAL_DEV_PM_OPS() macro uses the provided callbacks for both runtime PM and system sleep. This causes the DSI clocks to be disnvd · 2026-08-10
- [NVD] CVE-2026-68279 — In the Linux kernel, the following vulnerability has been resolved: drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers drm_dp_sideband_parse_remote_dpcd_read() reads num_bytes from the raw message and then unconditionally does: memcpy(bytes, &raw->msg[idx], nvd · 2026-08-10
- [NVD] CVE-2026-68278 — In the Linux kernel, the following vulnerability has been resolved: drm/dp/mst: fix buffer overflows in sideband chunk accumulation drm_dp_sideband_append_payload() has three related bugs when processing device-provided sideband reply data: 1. Zero-length curchunk_len underflonvd · 2026-08-10
- [NVD] CVE-2026-68277 — In the Linux kernel, the following vulnerability has been resolved: drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers Three sideband reply parsers read 16-bit fields as: val = (raw->msg[idx] << 8) | (raw->msg[idx+1]); and check bounds only after the fact.nvd · 2026-08-10
- [NVD] CVE-2026-68255 (HIGH 7.7) — In the Linux kernel, the following vulnerability has been resolved: drm/virtio: bound EDID block reads to the response buffer virtio_get_edid_block() validates the read offset only against the device-supplied resp->size field, never against the fixed-size resp->edid array. The nvd · 2026-08-10
- [NVD] CVE-2026-68254 — In the Linux kernel, the following vulnerability has been resolved: drm/i915/vrr: require valid min/max vfreq for VRR Ensure the EDID provided min/max vfreq are valid. Most scenarios are already covered (by coincidence) through the checks in intel_vrr_is_capable() and intel_vrrnvd · 2026-08-10
- [NVD] CVE-2026-68253 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: drm/i915/hdcp: check streams[] bounds before overflow The data->streams[] overflow check is done after the buffer overflow has already happened. Move the overflow check before the write. Side note, emitting a nvd · 2026-08-10
- [NVD] CVE-2026-68205 — In the Linux kernel, the following vulnerability has been resolved: media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor() The v4l2 helper v4l2_async_register_subdev_sensor() calls v4l2_async_register_subdev(), which is a macro that expands to _nvd · 2026-08-10
- [NVD] CVE-2026-68202 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: ALSA: seq: close a re-opened queue timer in the destructor queue_delete() closes the queue timer, then frees it. snd_seq_timer_close() clears q->timer->timeri. snd_use_lock_sync() then drains borrowers, and sndnvd · 2026-08-10
- [NVD] CVE-2026-68198 (HIGH 8.8) — In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: fix use-after-free in aggr_reset_state() The aggr_reset_state() function uses timer_delete() (non-synchronous) for the aggregation timer before proceeding to delete TID state and before the structnvd · 2026-08-10
- [NVD] CVE-2026-68181 — In the Linux kernel, the following vulnerability has been resolved: mei: bus: access mei_device under device_lock on cleanup Fix couple of problems in mei_cl_bus_dev_release(): mei_cl_flush_queues() is running without lock. bus->file_list access after mei_dev_bus_put(bus) can nvd · 2026-08-10
- [NVD] CVE-2026-68169 — In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: userspace: fix use-after-free in get_local_id In mptcp_pm_userspace_get_local_id(), the address entry is looked up under spinlock, but its id is read after dropping the lock. A concurrent deletion canvd · 2026-08-10
- [NVD] CVE-2026-68166 — In the Linux kernel, the following vulnerability has been resolved: userfaultfd: prevent registration of special VMAs Vova Tokarev says: userfaultfd allows registration on shadow stack VMAs. With userfaultfd access, you can register on the shadow stack, discard a page ...nvd · 2026-08-10
- [NVD] CVE-2026-68162 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: sctp: avoid auth_enable sysctl UAF during netns teardown proc_sctp_do_auth() updates the SCTP control socket after changing net.sctp.auth_enable. The handler gets the per-net SCTP state from ctl->data, so an alnvd · 2026-08-10
- [NVD] CVE-2026-68159 (CRITICAL 9.8) — In the Linux kernel, the following vulnerability has been resolved: libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE __decode_pg_temp() decodes an user-controlled length but only rejects values large enough to overflow the allocation; it does not bound it tnvd · 2026-08-10
- [NVD] CVE-2026-68150 — In the Linux kernel, the following vulnerability has been resolved: fs/super: fix emergency thaw double-unlock of s_umount do_thaw_all() iterates over all superblocks via __iterate_supers() with SUPER_ITER_EXCL, which acquires s_umount exclusively before calling the callback annvd · 2026-08-10
- [NVD] CVE-2026-68146 — In the Linux kernel, the following vulnerability has been resolved: ftrace: Add global mutex to serialize trace_parser access In ftrace, the trace_parser structure is allocated and initialized when a trace file is opened, and is subsequently used across write and release handlenvd · 2026-08-10
- [NVD] CVE-2026-68145 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: iomap: fix out-of-bounds bitmap_set() with zero-length range ifs_set_range_dirty() and ifs_set_range_uptodate() compute last_blk as (off + len - 1) >> i_blkbits. When off is 0 and len is 0, the unsigned subtranvd · 2026-08-10
- [NVD] CVE-2026-68138 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: net/sched: serialize qdisc_rtab_list against concurrent get/put qdisc_get_rtab() and qdisc_put_rtab() mutate the process-global singly linked list qdisc_rtab_list and a plain non-atomic 'int refcnt' with no locnvd · 2026-08-10
- [NVD] CVE-2026-68136 (CRITICAL 9.8) — In the Linux kernel, the following vulnerability has been resolved: net: gro: fix double aggregation of flush-marked skbs Commit 0ab03f353d36 ("net-gro: Fix GRO flush when receiving a GSO packet.") added a flush check to skb_gro_receive(), but skb_gro_receive_list() lacks the snvd · 2026-08-10
- [NVD] CVE-2026-68132 — In the Linux kernel, the following vulnerability has been resolved: super: fix emergency thaw deadlock on frozen block devices do_thaw_all_callback() calls bdev_thaw() while holding sb->s_umount exclusively. If the block device was frozen via bdev_freeze() dropping the last blonvd · 2026-08-10
- [NVD] CVE-2026-68130 — In the Linux kernel, the following vulnerability has been resolved: ksmbd: defer destroy_previous_session() until after NTLM authentication In ntlm_authenticate(), destroy_previous_session() is called using a user pointer resolved from the client-supplied NTLM blob username fienvd · 2026-08-10
- Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Developmentthehackernews · 2026-08-10
- [NVD] CVE-2026-68118 (HIGH 8.2) — In the Linux kernel, the following vulnerability has been resolved: tcp: challenge ACK for non-exact RST in SYN-RECEIVED The SYN-RECEIVED request-socket path in tcp_check_req() accepts an in-window RST without requiring SEG.SEQ to exactly match RCV.NXT. A non-exact RST therefonvd · 2026-08-10
- [NVD] CVE-2026-68100 (HIGH 8.1) — In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl set_ntacl_dacl() copies each ACE from the attacker-controlled stored security descriptor verbatim into the response DACL without checking sid.num_snvd · 2026-08-10
- [NVD] CVE-2026-68099 — In the Linux kernel, the following vulnerability has been resolved: ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL check_add_overflow() unconditionally writes the truncated sum into *d even on overflow, per its contract in include/linux/overflow.h. The nvd · 2026-08-10
- [NVD] CVE-2026-68096 (HIGH 7.5) — In the Linux kernel, the following vulnerability has been resolved: audit: fix recursive locking deadlock in audit_dupe_exe() A deadlock occurs in the audit subsystem when duplicating executable-related rules. When a file is moved (e.g., via do_renameat2()), the VFS layer locknvd · 2026-08-10
- Steam Customer Data Exposed in CEVA Logistics Cyberattacksocradar_blog · 2026-08-10
- Edge is dropping older extensions, affecting popular privacy toolsmalwarebytes_blog · 2026-08-10
- Ransomware Now Shows Up in Nearly Half of All Breaches: A Survival Playbook for Lean Security Teamscyble · 2026-08-10
- Dell security advisory (AV26-788)cccs_ca · 2026-08-10
- Audit Fix: Audit Readiness for the Post-Mythos Eraqualys · 2026-08-10
- New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFAthehackernews · 2026-08-10
- [Global Secret Group] MACOFIN HELLAS S.A. posted to leak siteransomware_live · 2026-08-10
- [qilin] City of Winchester posted to leak siteransomware_live · 2026-08-10
- [qilin] B Wright Drywall posted to leak siteransomware_live · 2026-08-10
- #StopRansomware: Gunra Ransomwarecisa_advisories · 2026-08-10
- Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Developmentthehackernews · 2026-08-10
- [Global Secret Group] Cook Remodeling posted to leak siteransomware_live · 2026-08-10
- TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCorethehackernews · 2026-08-10
- [Storm] Southern Metals posted to leak siteransomware_live · 2026-08-10
- [Storm] TRP International posted to leak siteransomware_live · 2026-08-10
- [Storm] Supportive Insurance Services posted to leak siteransomware_live · 2026-08-10
- [NVD] CVE-2026-72577 (CRITICAL 9.8) — Multiple vulnerabilities in NASA fprime-gds through 3.4.3 allow an unauthenticated remote attacker to achieve arbitrary code execution on the ground station host and inject arbitrary commands to connected spacecraft. The Flask application in src/fprime_gds/flask/app.py applies nonvd · 2026-08-10
- [NVD] CVE-2026-72576 (MEDIUM 5.4) — A stored cross-site scripting (XSS) vulnerability in Bludit 4.0.0-beta allows a low-privileged authenticated user (Author role) to inject arbitrary JavaScript by uploading a crafted SVG file as the site logo. A stored script tag in the SVG executes in the browser of any user who nvd · 2026-08-10
- [NVD] CVE-2026-72569 (CRITICAL 9.1) — A path traversal vulnerability in cube-root/directory-serve through 1.3.7 allows an unauthenticated remote attacker to delete arbitrary files outside the intended served directory when the application is run with the --delete option.nvd · 2026-08-10
- [NVD] CVE-2026-72567 (CRITICAL 9.8) — An improper path validation vulnerability in AsyncFuncAI/deepwiki-open through commit 16f35a0 allows unauthenticated remote attackers to write to or delete arbitrary files with root privileges. The api/api.py wiki-cache endpoint constructs file paths from user-controlled owner, rnvd · 2026-08-10
- [NVD] CVE-2026-72566 (HIGH 7.7) — A server-side request forgery (SSRF) vulnerability in automatisch through commit 41f3c56 allows a low-privileged authenticated user with 'manage Flow' permission to make the server fetch arbitrary URLs and retrieve the full response body via the HTTP Request app's Custom Request nvd · 2026-08-10
- Python Now Has a Post-Quantum Encryption Libraryschneier · 2026-08-10
- [Wallstreet] T.RAD North America posted to leak siteransomware_live · 2026-08-10
- [Wallstreet] Black Hills Bentonite posted to leak siteransomware_live · 2026-08-10
- [spacebears] Elixi International SA posted to leak siteransomware_live · 2026-08-10
- IT threat evolution in Q2 2026. Non-mobile statisticssecurelist · 2026-08-10
- IT threat evolution in Q2 2026. Mobile statisticssecurelist · 2026-08-10
- [unsafe] DECK APP TECHNOLOGIES PTE. LTD posted to leak siteransomware_live · 2026-08-10
- [thegentlemen] PharmaEssentia posted to leak siteransomware_live · 2026-08-10
- [thegentlemen] CONTAC Ingenieros posted to leak siteransomware_live · 2026-08-10
- [thegentlemen] RAK Construction posted to leak siteransomware_live · 2026-08-10
- [thegentlemen] Lancesoft India posted to leak siteransomware_live · 2026-08-10
- [thegentlemen] AIMS Group posted to leak siteransomware_live · 2026-08-10
- [thegentlemen] AnMed posted to leak siteransomware_live · 2026-08-10
- [thegentlemen] NTU Alumni Club posted to leak siteransomware_live · 2026-08-10