THREAT OPS › Threat News
Threat Intelligence News
11872 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- Wordfence Intelligence Weekly WordPress Vulnerability Report (July 27, 2026 to August 2, 2026)wordfence · 2026-08-08
- Living off the coding agent: Two tales of tunnels and LaunchAgentselastic_security · 2026-08-07
- Varonis Atlas Now Integrates with Claude Inference Hooks to Extend Real-Time AI Data Protectionvaronis_blog · 2026-08-07
- [NVD] CVE-2026-48122 — Ruby LSP is an implementation of the language server protocol for Ruby. Several workspace-level settings in the Ruby LSP VS Code extension prior to version 0.10.4 could override the path to the Ruby executable, the version manager executables, or the Bundler `Gemfile` used at stanvd · 2026-08-07
- [NVD] CVE-2026-48047 — XWiki Platform WebJars API is a package for XWiki, a generic wiki platform. Starting with version 9.6-rc-1 and prior to versions 16.10.17, 17.4.9, and 17.10.3, a potential path traversal vulnerability allow an attacker who manages to get a malicious WebJar extension installed on nvd · 2026-08-07
- [NVD] CVE-2026-46409 (CRITICAL 9.6) — OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to version 1.1.3, the OpenYak desktop backend binds an HTTP API to `127.0.0.1:<random port>` (commonly 19141) without server-side Origin validation, loopback authennvd · 2026-08-07
- Inside the Modern SOC: The Identity Front Doorunit42 · 2026-08-07
- [bravox] MEDICOS posted to leak siteransomware_live · 2026-08-07
- [NVD] CVE-2026-48170 (CRITICAL 9.1) — `scim-patch`, a library to perform SCIM patch, prior to version 0.9.1 performs prototype pollution when applying a SCIM PATCH operation whose `value` object contains a key like `"__proto__.someProp"`. After one such patch, `Object.prototype.someProp` is set process-wide, affectinnvd · 2026-08-07
- [NVD] CVE-2026-48169 (HIGH 8.8) — PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization failures that together break workspace isolation. The service layer for issues and projects performs global primary-key lookups without checking workspace ownershnvd · 2026-08-07
- RovoBlast: How One Click Triggered Atlassian’s AI Assistant to Leak Datavaronis_blog · 2026-08-07
- AI chat bots are sliding into League of Legends friend requestsmalwarebytes_blog · 2026-08-07
- [NVD] CVE-2026-50540 (CRITICAL 9.6) — Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to version 4.0.0, kata-runtime is vulnerable to host code execution via an unvalidated configuration path annotation. The runtnvd · 2026-08-07
- Friday Squid Blogging: Arctic Bobtail Squid Videoschneier · 2026-08-07
- Meta ordered to pay $942 million over harm to childrenmalwarebytes_blog · 2026-08-07
- Meta ordered to pay $942 million over harm to childrenmalwarebytes_blog · 2026-08-07
- [GHSA] GHSA-fp3f-mc75-235c (medium) — pypdf: Possible large memory usage for large /ToUnicode streamsgithub_advisories · 2026-08-07
- [NVD] CVE-2026-71851 (CRITICAL 9.0) — crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in CryptoJS.lib.WordArray.random() using a custom variation of the Multiply-With-Carry pseudorandom number generator, seeded from Math.random(), instead of a cryptograpnvd · 2026-08-07
- [NVD] CVE-2026-71848 (MEDIUM 5.3) — Hono is a Web application framework that provides support for any JavaScript runtime. From 4.12.0 to 4.12.33, the languageDetector middleware is vulnerable to algorithmic complexity denial of service when processing a crafted language tag containing a large number of hyphen separnvd · 2026-08-07
- [NVD] CVE-2026-71847 — Ruby JSON is a JSON implementation for Ruby. From 2.20.0 until 2.21.2, Ruby's JSON native C extension clears the consumed JSON::ResumableParser input buffer but leaves state.start, state.cursor, and state.end pointing into released storage. When partial_value reconstructs an inconvd · 2026-08-07
- [NVD] CVE-2026-69127 — Kirby is an open-source content management system. Prior to 4.9.5 and from 5.0.0 through 5.5.1, the REST API error handler can return unsanitized PHP error messages that expose the full filesystem path of the Kirby installation to unauthenticated API users. This vulnerability affnvd · 2026-08-07
- [GHSA] GHSA-fwg2-594c-jp42 (medium) — pypdf: Possible long runtimes/large memory usage for large CID font width rangesgithub_advisories · 2026-08-07
- [GHSA] GHSA-rg76-677x-56q9 (critical) — crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chaingithub_advisories · 2026-08-07
- Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealerthehackernews · 2026-08-07
- Upgrading How You Sign In to Your Sucuri Accountsucuri_blog · 2026-08-07
- [GHSA] GHSA-f23p-vx2j-j53r (medium) — Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosuregithub_advisories · 2026-08-07
- [GHSA] GHSA-79qm-7rj5-m7r9 (low) — Hono: Proxy Helper does not remove response headers listed in the `Connection` headergithub_advisories · 2026-08-07
- [GHSA] GHSA-54fx-42gc-7vw4 (medium) — Hono: Algorithmic Complexity DoS in Language Middlewaregithub_advisories · 2026-08-07
- [GHSA] GHSA-9hj4-r449-hfvc (low) — Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streamsgithub_advisories · 2026-08-07
- ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Walletsthehackernews · 2026-08-07
- [GHSA] GHSA-gm37-52c6-37mw (high) — pymdown-extensions: exponential-backtracking ReDoS in caret, tilde, betterem, and magiclink inline processorsgithub_advisories · 2026-08-07
- [GHSA] GHSA-mmj4-63m4-r6h5 (critical) — CodeIgniter: Uploaded file extension validation bypass in `is_image` and `mime_in` rulesgithub_advisories · 2026-08-07
- [GHSA] GHSA-hhmc-q9hp-r662 (high) — CodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenamesgithub_advisories · 2026-08-07
- [GHSA] GHSA-c9w5-rwh3-7pm9 (critical) — CodeIgniter: SQL injection in Query Builder deleteBatch() when used with where() conditionsgithub_advisories · 2026-08-07
- [GHSA] GHSA-7wmf-pw8j-mc78 (medium) — CodeIgniter: Spoofable forwarded HTTPS headers in IncomingRequest::isSecure()github_advisories · 2026-08-07
- [NVD] CVE-2026-56818 (MEDIUM 6.5) — Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, the RedisArrayAggregator Redis codec clears retained partial aggregate state when the maxNestedArrayDepth limit is exceeded, but it does not clear the same state when thnvd · 2026-08-07
- UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Datathehackernews · 2026-08-07
- [GHSA] GHSA-wcx4-wpfv-mc5c (high) — jsii-diff: Command Injection via npm: package argumentgithub_advisories · 2026-08-07
- [NVD] CVE-2026-68772 (HIGH 8.0) — ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMaterializer component that allows attackers with write access to a shared artifact store to execute arbitrary code by planting a malicious pickle file. Attackers can replace a stored artifact.pkl file nvd · 2026-08-07
- [NVD] CVE-2026-19212 (MEDIUM 4.3) — A vulnerability was determined in WonderTrader up to 0.9.9. This impacts an unknown function of the file src/Includes/WTSTradeDef.hpp of the component TraderATP Cash Trade Conversion. Executing a manipulation of the argument m_offsetType can lead to use of uninitialized variable.nvd · 2026-08-07
- [NVD] CVE-2026-17595 — Nexus Repository 3 did not fully sandbox JEXL expressions used in Content Selectors. An account holding the nexus:selectors:create permission could construct an expression that read Java object properties not intended to be exposed to the expression engine, disclosing internal JVnvd · 2026-08-07
- [NVD] CVE-2026-17593 — An account holding the nexus:settings:update permission in Nexus Repository 3 (or the equivalent nexus:settings permission in the legacy Nexus Repository 2) could submit arbitrary values as realm identifiers through an internal configuration API that did not validate them againstnvd · 2026-08-07
- [NVD] CVE-2026-14644 — Nexus Repository 3 contained a privilege escalation vulnerability in the REST privileges API. An authenticated user with permission to manage privileges could, under certain role configurations, escalate their own access to full administrator by exploiting a type-confusion flaw invd · 2026-08-07
- [GHSA] GHSA-p9jm-q85p-7mcp (medium) — Netty: RedisArrayAggregator max-elements failure leaves retained partial aggregate stategithub_advisories · 2026-08-07
- Progress security advisory (AV26-552) – Update 2cccs_ca · 2026-08-07
- [GHSA] GHSA-9rjg-x2p2-h68h (medium) — API Platform Core: Relation IRIs are not type-checked: a related resource can be denormalised as the wrong resource type (type confusion)github_advisories · 2026-08-07
- [GHSA] GHSA-29g2-3rmr-qm68 (medium) — SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept headergithub_advisories · 2026-08-07
- [GHSA] GHSA-7c4v-fwgw-9rf7 (medium) — Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpointgithub_advisories · 2026-08-07
- [GHSA] GHSA-qgq7-7hm3-q39j (medium) — go-git: Malicious reference names may modify files outside the reference storagegithub_advisories · 2026-08-07
- [GHSA] GHSA-hc8v-wwc9-vgxm (high) — go-git: Worktree operations may follow symlinksgithub_advisories · 2026-08-07
- [spacebears] Hitech Distribuzione Informatica S.r.l. (HTDI) posted to leak siteransomware_live · 2026-08-07
- ClamAV Vulnerabilities Affecting Cisco Products: August 2026cisco_psirt · 2026-08-07
- [GHSA] GHSA-wvpp-8hx9-p66j (high) — GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command executiongithub_advisories · 2026-08-07
- [GHSA] GHSA-jm78-9fvv-mhgr (high) — GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE)github_advisories · 2026-08-07
- [GHSA] GHSA-hmq2-w58f-27jc (high) — GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPythongithub_advisories · 2026-08-07
- [GHSA] GHSA-hh9p-6wh2-4mfc (medium) — GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()github_advisories · 2026-08-07
- [GHSA] GHSA-9rj7-rf2p-w77r (high) — GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooksgithub_advisories · 2026-08-07
- [GHSA] GHSA-4gmw-gg2m-w46p (high) — GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwritegithub_advisories · 2026-08-07
- [GHSA] GHSA-55q2-fjhq-7xh7 (medium) — DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSSgithub_advisories · 2026-08-07
- Inside the Fake Copyright Racket Silencing News Outletscitizenlab · 2026-08-07
- [NVD] CVE-2026-19264 (CRITICAL 9.8) — Postiz is an open-source social media scheduling tool. The route that serves locally stored media joins URL-supplied path segments onto the upload directory and streams the file without normalising the path or confining it to that directory, and the route requires no authenticatinvd · 2026-08-07
- [NVD] CVE-2026-19207 (LOW 2.4) — A security vulnerability has been detected in PHPGurukul Company Visitor Management System 1.0. This issue affects some unknown processing of the file /manage-newvisitors.php. The manipulation of the argument fullname leads to cross site scripting. The attack can be initiated remnvd · 2026-08-07
- [GHSA] GHSA-rjhh-76wf-8xmw (medium) — Smarty Security stream restriction bypass through stream: resourcegithub_advisories · 2026-08-07
- [GHSA] GHSA-f6wf-28g6-769x (medium) — Smarty: Symlink path traversal out of trusted directoriesgithub_advisories · 2026-08-07
- Google security advisory (AV26-787)cccs_ca · 2026-08-07
- [GHSA] GHSA-wg23-69c2-gjc8 (critical) — Craft CMS: Passkey login accepts replayed WebAuthn assertionsgithub_advisories · 2026-08-07
- [NVD] CVE-2026-15570 — An improper restriction of URL schemes and destinations in the SmartCenter browserseturl command in the Telefunken TE24553B45V2DZ Smart TV running on the Vestel MB181 / Voltron181 / TiVo OS platform allows an attacker with access to the same local network to cause the embedded brnvd · 2026-08-07
- ThreatLabz 2026 Report: Frontier AI and Enterprise Readinesszscaler_threatlabz · 2026-08-07
- XSS2Shell (CVE-2026-64638): Patch WordPress Nowsocradar_blog · 2026-08-07
- [Storm] Pioneer Bank posted to leak siteransomware_live · 2026-08-07
- [thegentlemen] Hartfiel Automation posted to leak siteransomware_live · 2026-08-07
- [qilin] Astro Electroplating posted to leak siteransomware_live · 2026-08-07
- [qilin] Filtronic posted to leak siteransomware_live · 2026-08-07
- [qilin] EISNER ZT GMBH posted to leak siteransomware_live · 2026-08-07
- [qilin] John C Saunders, CPA posted to leak siteransomware_live · 2026-08-07
- [qilin] Nikan Awasisak Agency posted to leak siteransomware_live · 2026-08-07
- [qilin] Depona posted to leak siteransomware_live · 2026-08-07
- [NVD] CVE-2026-66494 — Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0 - An unauthenticated attacker can store malicious JavaScript in a Joomla site's database via a single HTTP request. When an administrator opens the SP Page Builder editornvd · 2026-08-07
- [NVD] CVE-2026-56793 (HIGH 7.7) — Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.nvd · 2026-08-07
- Meeting Canada’s Bill C-8 Cybersecurity Requirements with NodeZero®horizon3 · 2026-08-07
- New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAPthehackernews · 2026-08-07
- [clop] CONTINENTAL.AERO posted to leak siteransomware_live · 2026-08-07
- [clop] MINDRAY.COM posted to leak siteransomware_live · 2026-08-07
- Vulnerability Management Lifecycle: Core Phasesorca_security · 2026-08-07
- Application Security Framework: Complete Guideorca_security · 2026-08-07
- What is AI AppGen Security?orca_security · 2026-08-07
- [incransom] ATMS posted to leak siteransomware_live · 2026-08-07
- Agentic AI for Cyber Defenders: What Security Teams Built at Black Hat USA 2026tenable · 2026-08-07
- CISA Adds One Known Exploited Vulnerability to Catalogcisa_advisories · 2026-08-07
- CPDLC over ATN-B1 Vulnerabilitiescisa_advisories · 2026-08-07
- Growing Up The Hard Waythehackernews · 2026-08-07
- Cracking Kynx: The Stealer Hunting for Your Wallets, Games, and AI Toolssocradar_blog · 2026-08-07
- [NVD] CVE-2026-15816 (HIGH 7.5) — A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH option, an attacker on the adjacent nvd · 2026-08-07
- 18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containersthehackernews · 2026-08-07
- Cisco Catalyst SD-WAN and IOS XE: Critical Flaws Fixedsocradar_blog · 2026-08-07
- Ransomware Threats in Europe H1 2026: A Deep Dive into Regional Attack Patterns and Dominant Threat Actorscyble · 2026-08-07
- Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emailsthehackernews · 2026-08-07
- ICE Is Buying Access to Credit Card Recordsschneier · 2026-08-07
- AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Daythehackernews · 2026-08-07
- New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tablesthehackernews · 2026-08-07