THREAT OPS › Threat News
Threat Intelligence News
11865 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [thegentlemen] AIMS Group posted to leak siteransomware_live · 2026-08-10
- [thegentlemen] AnMed posted to leak siteransomware_live · 2026-08-10
- [thegentlemen] NTU Alumni Club posted to leak siteransomware_live · 2026-08-10
- [thegentlemen] Canopy Support Services posted to leak siteransomware_live · 2026-08-10
- [thegentlemen] Mikel Coffee posted to leak siteransomware_live · 2026-08-10
- [thegentlemen] Hong Kong Baptist University posted to leak siteransomware_live · 2026-08-10
- [thegentlemen] Eva Care posted to leak siteransomware_live · 2026-08-10
- [thegentlemen] Premier Pigs posted to leak siteransomware_live · 2026-08-10
- [thegentlemen] Zion Contracting posted to leak siteransomware_live · 2026-08-10
- Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentialsthehackernews · 2026-08-10
- [NVD] CVE-2026-13133 — A vulnerability has been identified in LineInst.exe (LINE for Windows) prior to version 26.4.0, where Msftedit.dll is loaded via a relative path without a secure DLL search path, allowing a malicious DLL placed in the installer's directory to be loaded ahead of the legitimate Sysnvd · 2026-08-10
- A week in security (August 3 – August 9)malwarebytes_blog · 2026-08-10
- Brazil Fiscal Leak, US Fullz, Telecom Access, Endesa IBANs, and Mexico Fortinet Accesssocradar_blog · 2026-08-10
- OpenAI's Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pausethehackernews · 2026-08-10
- [NVD] CVE-2026-19389 (HIGH 7.1) — Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation of attacker-controlled length and size values can bypass bounds chenvd · 2026-08-10
- [NVD] CVE-2026-19387 (HIGH 7.6) — A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a crafted WAV file to cause writes beyond the allocated onvd · 2026-08-10
- [NVD] CVE-2026-19384 (HIGH 7.3) — A weakness has been identified in SourceCodester Simple Doctors Appointment System 1.0. The affected element is an unknown function of the file /admin/ajax.php?action=set_appointment. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely.nvd · 2026-08-10
- Risky Bulletin: Two law firms pay giant ransomsriskybiz_news · 2026-08-10
- [NVD] CVE-2026-19383 (MEDIUM 4.7) — A security vulnerability has been detected in saithink/saigroup SaiAdmin up to 5.0.1. This impacts the function shell_exec of the file /app/saipackage/install/upload of the component Plugin Upload Endpoint. The manipulation leads to unrestricted upload. Remote exploitation of thenvd · 2026-08-10
- [NVD] CVE-2026-19382 (LOW 2.3) — A weakness has been identified in Almico Speedfan 4.52. This affects the function KiSystemCall64 in the library speedfan.sys of the component MSR Index Handler. Executing a manipulation can lead to memory leak. The attack can only be executed locally. The exploit has been made avnvd · 2026-08-10
- [NVD] CVE-2026-19381 (HIGH 7.8) — A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0. The impacted element is an unknown function in the library NTIOLib_KSFX.sys of the component Driver. Performing a manipulation results in improper privilege management. The attack needs to benvd · 2026-08-10
- [NVD] CVE-2026-19380 (LOW 2.3) — A vulnerability was identified in Mullvad wireguard.sys 0.10.1. The affected element is the function AdapterState of the component IOCTL Handler. Such manipulation leads to improper update of reference count. Local access is required to approach this attack. The exploit is publicnvd · 2026-08-10
- [NVD] CVE-2026-19379 (HIGH 7.3) — A vulnerability was determined in EFM ipTIME AX8004M 15.09.0. Impacted is the function popen of the file /cgi/d.cgi of the component CGI Endpoint. This manipulation of the argument fname causes os command injection. The attack can be initiated remotely. The exploit has been publinvd · 2026-08-10
- PostgreSQL Multiple Vulnerabilitieshkcert · 2026-08-10
- [NVD] CVE-2026-19378 (MEDIUM 4.3) — A vulnerability was found in code-projects Task Management System 1.0. This issue affects some unknown processing of the file /user/CommentSave.php. The manipulation of the argument comment/task_id/mineId/recId/myName/myImage results in cross site scripting. It is possible to launvd · 2026-08-10
- [NVD] CVE-2026-19376 (HIGH 7.3) — A vulnerability has been found in Uasoft Badaso 3.0.0-alpha. This vulnerability affects the function ApiRequest::class of the file src/Routes/api.php of the component File API. The manipulation leads to permission issues. It is possible to initiate the attack remotely. The exploinvd · 2026-08-10
- [NVD] CVE-2026-19375 (MEDIUM 6.3) — A vulnerability was detected in dmitriiweb article-scraper-mcp 1.0.0. This vulnerability affects the function fetch_article of the file news_scraper_mcp/server.py. The manipulation of the argument url results in server-side request forgery. The attack may be performed from remotenvd · 2026-08-10
- The Hugging Face Hack Was Cheap Persistence at Workrecordedfuture · 2026-08-10
- [NVD] CVE-2026-19374 (HIGH 7.3) — A security vulnerability has been detected in adafap api-mcp up to 92b9a5d04acfec165c7d4ef852496593aa87be06. This affects the function customAxios of the file app/api/proxy/route.ts of the component Proxy API Endpoint. The manipulation of the argument url leads to server-side reqnvd · 2026-08-09
- [NVD] CVE-2026-19373 (MEDIUM 5.3) — A weakness has been identified in PhialsBasement KoboldCPP-MCP-Server 1.0.0. Affected by this issue is the function makeRequest of the file src/index.ts of the component BaseConfigSchema. Executing a manipulation of the argument apiUrl can lead to server-side request forgery. It nvd · 2026-08-09
- [NVD] CVE-2026-19372 (MEDIUM 5.3) — A security flaw has been discovered in Handwriting-OCR handwriting-ocr-mcp-server 0.1.0. Affected by this vulnerability is the function fs.readFileSync of the file src/index.ts of the component upload_document. Performing a manipulation of the argument File results in path travernvd · 2026-08-09
- [NVD] CVE-2026-19371 (MEDIUM 5.3) — A vulnerability was identified in Nikolaibibo claude-comfyui-mcp 1.0.0. Affected is the function copyFileSync of the file src/tools/utils.ts of the component comfy_upload_image. Such manipulation of the argument image_path leads to path traversal. An attack has to be approached lnvd · 2026-08-09
- [NVD] CVE-2026-12372 (LOW 3.7) — A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. The `nltk.pathsec.validate_network_url()` function, intended to prevent SSRF by rejecting internal network addresses, fails to reject IPs in the RFC 6598 shared anvd · 2026-08-09
- [NVD] CVE-2026-19370 (MEDIUM 5.3) — A vulnerability was determined in bartekke8it56w2 new-mcp 0.1.0. This impacts the function fs.writeFileSync/fs.existsSync/fs.readFileSync of the file index.ts of the component geminithinking. This manipulation of the argument sessionCommand/sessionPath causes path traversal. The nvd · 2026-08-09
- [NVD] CVE-2026-19369 (MEDIUM 5.3) — A vulnerability was found in KS-GEN-AI jira-mcp-server 0.2.0. This affects the function axios.get of the file src/index.ts of the component add_attachment_from_public_url. The manipulation of the argument imageUrl results in server-side request forgery. The attack requires a locanvd · 2026-08-09
- [NVD] CVE-2026-19368 (LOW 3.3) — A vulnerability was found in PV-Bhat gemsuite-mcp 1.0.0. Affected by this issue is some unknown functionality of the file src/handlers/unified-gemini.ts of the component gemini_search/gemini_reason/gemini_process/gemini_analyze. The manipulation of the argument file_path/file_patnvd · 2026-08-09
- [NVD] CVE-2026-19367 (MEDIUM 6.3) — A vulnerability has been found in NocteDefensor LudusMCP 1.0.24. Affected by this vulnerability is an unknown functionality of the file src/tools/rangeConfig.ts of the component read_range_config. The manipulation of the argument Source leads to server-side request forgery. The anvd · 2026-08-09
- Sponsored: Island's expansion to SASE and enterprise AIriskybiz_news · 2026-08-09
- [play] MIE Solutions posted to leak siteransomware_live · 2026-08-09
- [play] Rilpa Enterprises posted to leak siteransomware_live · 2026-08-09
- [NVD] CVE-2026-70395 — Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash allows an attacker to forge a relationship to a record they cannot name, and to recover the secret value used to look it up. When manage_relationship is used with on_lookup: :relate nvd · 2026-08-09
- [NVD] CVE-2026-19366 (MEDIUM 5.3) — A flaw has been found in NocteDefensor LudusMCP up to 1.0.24. Affected is an unknown function of the file src/tools/insertCredsRangeConfig.ts of the component insert_creds_range_config. Executing a manipulation of the argument configPath/outputPath can lead to path traversal. Thenvd · 2026-08-09
- [NVD] CVE-2026-19365 (MEDIUM 5.3) — A vulnerability was identified in Ichigo3766 image-gen-mcp 0.1.0. The impacted element is an unknown function of the file src/index.ts of the component upscale_images. Such manipulation of the argument output_path leads to path traversal. The attack must be carried out locally. Tnvd · 2026-08-09
- [play] Marconi Industrial Services posted to leak siteransomware_live · 2026-08-09
- [qilin] Synergy Interactive posted to leak siteransomware_live · 2026-08-09
- [NVD] CVE-2026-69659 — Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to exhaust the memory of the node via a crafted keyset pagination cursor. Read actions with keyset pagination deserialize the client-supplied page[:after] or page[:before] cursor in decode_valunvd · 2026-08-09
- [NVD] CVE-2026-19364 (MEDIUM 6.3) — A vulnerability was determined in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /viewdoctorconsultancycharge.php. This manipulation of the argument delid causes sql injection. The attack is possible to be carried out remotelynvd · 2026-08-09
- [NVD] CVE-2026-19363 (MEDIUM 5.3) — A vulnerability was found in lmammino oidc-authorizer up to 0.4.0. Impacted is the function unwrap of the file src/handler.rs of the component Fixed Message Handler. The manipulation of the argument jwtClaims results in deserialization. The attack can be executed remotely. The exnvd · 2026-08-09
- [NVD] CVE-2026-19362 (MEDIUM 5.3) — A vulnerability has been found in lmammino oidc-authorizer 0.4.0. This issue affects the function parse_token_from_header of the file src/parse_token_from_header.rs of the component Authorization Header Parsing. The manipulation of the argument authorization_token leads to denialnvd · 2026-08-09
- [NVD] CVE-2026-19361 (LOW 3.7) — A flaw has been found in macrozheng mall 0504e86. This vulnerability affects unknown code of the file /sso/getAuthCode of the component mall-portal Module. Executing a manipulation can lead to weak password recovery. The attack may be launched remotely. This attack is characteriznvd · 2026-08-09
- [NVD] CVE-2026-15534 — Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch. The regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit counnvd · 2026-08-09
- [NVD] CVE-2026-19360 (MEDIUM 4.7) — A vulnerability was detected in wongcyrus ExcelLexBot up to 0.0.3. This affects the function ExcelLexBotS3TriggerFunction of the component Lambda Function Handler. Performing a manipulation results in improper privilege management. The attack may be initiated remotely. The vendornvd · 2026-08-09
- [NVD] CVE-2026-19359 (MEDIUM 4.7) — A security vulnerability has been detected in nxp-auto-goldvip gvip up to 1.4.0. Affected by this issue is the function SitewiseCustomFunction of the component Lambda Function Handler. Such manipulation leads to improper access controls. The attack can be launched remotely. Upgranvd · 2026-08-09
- [qilin] Energetic Development Corp posted to leak siteransomware_live · 2026-08-09
- [qilin] Panda Logistics Taichung Branch posted to leak siteransomware_live · 2026-08-09
- [qilin] East Field Corporation posted to leak siteransomware_live · 2026-08-09
- [qilin] Chun Tai Sing Chemical Industry posted to leak siteransomware_live · 2026-08-09
- [NVD] CVE-2026-19358 (MEDIUM 6.3) — A weakness has been identified in 3CORESec Trapdoor up to 1.2.2. Affected by this vulnerability is the function DefaultFunction. This manipulation causes improper access controls. The attack can be initiated remotely. The vendor was contacted early about this disclosure.nvd · 2026-08-09
- [NVD] CVE-2026-19357 (MEDIUM 5.3) — A security flaw has been discovered in MingSoft MCMS up to 3.0.6. Affected is an unknown function of the file /mdiy/form/get of the component ms-mdiy. The manipulation results in information disclosure. It is possible to launch the attack remotely. The exploit has been released tnvd · 2026-08-09
- Beware of Phishing Emails Disguised as Transaction Receiptsahnlab · 2026-08-09
- Security Issues in the Korean & Global Financial Sector in July 2026ahnlab · 2026-08-09
- [qilin] pm-energy Die Solarexperten posted to leak siteransomware_live · 2026-08-09
- [unsafe] Constellation HomeBuilder Systems posted to leak siteransomware_live · 2026-08-09
- [qilin] Harplast SRL posted to leak siteransomware_live · 2026-08-09
- [NVD] CVE-2026-19356 (MEDIUM 5.3) — A vulnerability was identified in MingSoft MCMS up to 3.0.6. This impacts an unknown function of the file /mdiy/form/data/list of the component ms-mdiy. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The exploit is publicly availnvd · 2026-08-09
- [NVD] CVE-2026-19355 (HIGH 7.3) — A vulnerability was determined in MingSoft MCMS up to 3.0.6. This affects the function ModelDataImpl.queryDiyFormData of the file /mdiy/form/data/list.do of the component ms-mdiy. Executing a manipulation of the argument formFields can lead to sql injection. The attack may be pernvd · 2026-08-09
- [NVD] CVE-2026-19354 (MEDIUM 6.3) — A vulnerability was found in lock-upme OPMS up to 831440f37a92c1568f2e071d5233bc873a9d8b09. The impacted element is an unknown function of the file controllers/messages/message.go of the component IN Clause Handler. Performing a manipulation of the argument ids results in sql injnvd · 2026-08-09
- [qilin] Price Shoes posted to leak siteransomware_live · 2026-08-09
- [qilin] Naval Interior Team posted to leak siteransomware_live · 2026-08-09
- [NVD] CVE-2026-19353 (MEDIUM 5.0) — A vulnerability has been found in DedeCMS up to 5.7.118 UTF8SP2. The affected element is the function _4_Setup of the file install/index.php of the component Installation Wizard. Such manipulation leads to file inclusion. The attack can be executed remotely. This attack is characnvd · 2026-08-09
- [NVD] CVE-2026-19352 (LOW 3.1) — A vulnerability was determined in mifi lossless-cut up to 3.69.0. Affected by this issue is some unknown functionality of the file src/main/httpServer.ts of the component Built-in HTTP API Service. Executing a manipulation can lead to server-side request forgery. The attack requinvd · 2026-08-09
- [NVD] CVE-2026-19351 (HIGH 7.3) — A vulnerability was found in dresende node-sql-query 0.1.25/0.1.26/0.1.27/0.1.28. Affected by this vulnerability is the function SelectQuery.from/SelectQuery.build in the library lib/Select.js of the component Request Parameter Handler. Performing a manipulation results in sql innvd · 2026-08-09
- [NVD] CVE-2026-19350 (MEDIUM 6.3) — A vulnerability has been found in Dolibarr ERP up to 23.0.3. Affected is the function fail of the file htdocs/takepos/invoice.php of the component TakePOS Module. Such manipulation leads to missing authorization. The attack may be performed from remote. The name of the patch is 8nvd · 2026-08-09
- [NVD] CVE-2026-19348 (CRITICAL 9.8) — A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf of the file /protocol.csp?fname=net&opt=smacfilter_conf&function=set&act=add&name=test&enable=1. Performing a manipulation of the argument enable/name/mac resulnvd · 2026-08-09
- [NVD] CVE-2026-19347 (MEDIUM 6.3) — A vulnerability was identified in itsourcecode Hospital Management System 1.0. This issue affects some unknown processing of the file /viewdoctor.php. Such manipulation of the argument delid leads to sql injection. The attack can be launched remotely. The exploit is publicly avainvd · 2026-08-09
- [qilin] Phithan Phanich posted to leak siteransomware_live · 2026-08-09
- [qilin] Grupo Diestra posted to leak siteransomware_live · 2026-08-09
- [qilin] Université Libre de Bruxelles posted to leak siteransomware_live · 2026-08-09
- [NVD] CVE-2026-19346 (HIGH 8.8) — A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formCertListInfo of the file /goform/CertListInfo. This manipulation of the argument Name causes command injection. The attack can be initiated remotely. The exploit has been publicly dinvd · 2026-08-09
- [NVD] CVE-2026-19345 (MEDIUM 6.5) — A vulnerability was found in code-projects Task Management System 1.0. This affects an unknown part of the file /user/UpdateTaskStatus.php. The manipulation of the argument task_id/val results in missing authorization. It is possible to launch the attack remotely. The exploit hasnvd · 2026-08-09
- [NVD] CVE-2026-19344 (HIGH 7.3) — A vulnerability has been found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /user/comment_count_user.php. The manipulation of the argument task_id leads to sql injection. It is possible to initiate the attack remotenvd · 2026-08-09
- [shinyhunters] Ali** ********** posted to leak siteransomware_live · 2026-08-09
- [qilin] Service d'usinage 9002 posted to leak siteransomware_live · 2026-08-09
- [NVD] CVE-2026-19343 (HIGH 7.3) — A flaw has been found in code-projects Task Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/AdminLogin.php. Executing a manipulation of the argument email/password can lead to sql injection. The attack may be performed from remnvd · 2026-08-09
- [NVD] CVE-2026-19342 (HIGH 7.3) — A vulnerability was detected in code-projects Task Management System 1.0. Affected is an unknown function of the file /index.php of the component Login. Performing a manipulation of the argument Password results in improper authentication. The attack is possible to be carried outnvd · 2026-08-09
- [NVD] CVE-2026-19341 (HIGH 8.8) — A security vulnerability has been detected in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/pptpSrvGlobalConfig. Such manipulation of the argument EncryptionMode leads to stack-based buffer overflow. The attack can be executed remotely.nvd · 2026-08-09
- [NVD] CVE-2026-19340 (MEDIUM 6.3) — A weakness has been identified in anubissbe ProjectHub-Mcp up to 5.0.0. This affects an unknown function of the file backend-fix/complete_backend.js of the component Webhooks API. This manipulation of the argument url causes server-side request forgery. Remote exploitation of thenvd · 2026-08-09
- [NVD] CVE-2026-19339 (MEDIUM 6.3) — A security flaw has been discovered in aliyun alibabacloud-dataworks-mcp-server up to 1.0.43. The impacted element is the function ReadResourceRequestSchema of the file src/resources/initResources.ts. The manipulation of the argument request.params.uri results in server-side requnvd · 2026-08-09
- [NVD] CVE-2026-19338 (MEDIUM 5.3) — A vulnerability was identified in automateyournetwork MCPyATS up to 0.1.4. The affected element is the function processGenerateRequest of the file mcp_servers/mermaid/index.ts of the component generate_mermaid_markdown. The manipulation of the argument folder/name leads to path tnvd · 2026-08-09
- [NVD] CVE-2026-19337 (MEDIUM 5.3) — A vulnerability was determined in adenot mcp-google-search up to 0.3.1. Impacted is an unknown function of the file src/index.ts of the component read_webpage. Executing a manipulation of the argument url can lead to server-side request forgery. The attack is restricted to local nvd · 2026-08-09
- [NVD] CVE-2026-19336 (MEDIUM 5.3) — A vulnerability was found in Pimzino spec-workflow-mcp up to 2.2.6. This issue affects the function ApprovalStorage.createApproval of the file src/tools/approvals.ts. Performing a manipulation of the argument categoryName results in path traversal. The attack is only possible witnvd · 2026-08-09
- [NVD] CVE-2026-19335 (MEDIUM 5.3) — A vulnerability has been found in Jane-xiaoer skill-vision-control up to 1.3.0. This vulnerability affects the function getSkillVersionsDir of the file src/svc/utils/config.ts. Such manipulation of the argument skillName leads to path traversal. The attack can only be performed fnvd · 2026-08-09
- [NVD] CVE-2026-18603 — The PiWeb Cancel order / Refund request for WooCommerce WordPress plugin before 1.3.4.34 does not have authorization or ownership checks when adding the contents of a previous order to the cart, allowing unauthenticated users to disclose the contents of other customers' orders, anvd · 2026-08-09
- [NVD] CVE-2026-18465 — The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and does not properly validate a user-controlled path before using it in a file inclusion, allowing unauthenticated attanvd · 2026-08-09
- [NVD] CVE-2026-18464 — The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and does not restrict the operation it dispatches, allowing unauthenticated attackers to trigger uncontrolled recursion nvd · 2026-08-09
- [NVD] CVE-2026-18357 — The WPC Order Tip for WooCommerce WordPress plugin before 3.3.1 does not perform authorisation or nonce checks in one of its reporting features, allowing unauthenticated attackers to retrieve sensitive order data belonging to any customer of the store, such as billing names, ordenvd · 2026-08-09
- [NVD] CVE-2026-18037 — The Create WordPress plugin before 2.5.4 does not perform an authorization check before rendering content over one of its public REST API routes, and that route additionally publishes the requested content as a side effect, allowing unauthenticated attackers to read unpublished cnvd · 2026-08-09
- [NVD] CVE-2026-18032 — The WP Data Access WordPress plugin before 5.5.79 does not validate the column names it accepts on one of its unauthenticated AJAX actions, and the nonce guarding that action does not cover them, allowing unauthenticated attackers to read arbitrary columns of the database table nvd · 2026-08-09
- [NVD] CVE-2026-17017 — The CubeWP Framework WordPress plugin before 1.1.31 does not properly sanitize and escape a parameter before using it in a SQL statement through an AJAX action, and does not include a capability check on that action, allowing users with Subscriber-level access and above to perfornvd · 2026-08-09
- [NVD] CVE-2026-17014 — The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public REST endpoint actions, allowing unauthenticated users to delete the generated album export ZIP archives it stores.nvd · 2026-08-09