THREAT OPS › Threat News
Threat Intelligence News
11873 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tablesthehackernews · 2026-08-07
- Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Accessthehackernews · 2026-08-07
- Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secretsthehackernews · 2026-08-07
- [thegentlemen] DHC posted to leak siteransomware_live · 2026-08-07
- [thegentlemen] INKA Group GmbH Co posted to leak siteransomware_live · 2026-08-07
- [thegentlemen] Vitex Pharmaceuticals posted to leak siteransomware_live · 2026-08-07
- [thegentlemen] Mdj Management posted to leak siteransomware_live · 2026-08-07
- [thegentlemen] Hst posted to leak siteransomware_live · 2026-08-07
- [thegentlemen] Groupe BPCE posted to leak siteransomware_live · 2026-08-07
- [thegentlemen] Axson Teknik posted to leak siteransomware_live · 2026-08-07
- [thegentlemen] Ponti posted to leak siteransomware_live · 2026-08-07
- [thegentlemen] Godollo posted to leak siteransomware_live · 2026-08-07
- [thegentlemen] Hoang Chiropractic Center posted to leak siteransomware_live · 2026-08-07
- [thegentlemen] aZaaS posted to leak siteransomware_live · 2026-08-07
- [thegentlemen] HIWIN posted to leak siteransomware_live · 2026-08-07
- [thegentlemen] National Furniture Outlet posted to leak siteransomware_live · 2026-08-07
- [thegentlemen] TESI posted to leak siteransomware_live · 2026-08-07
- [thegentlemen] Intranet Gov Brasil posted to leak siteransomware_live · 2026-08-07
- [thegentlemen] Feraboli Zootech posted to leak siteransomware_live · 2026-08-07
- [thegentlemen] Nobema posted to leak siteransomware_live · 2026-08-07
- [thegentlemen] Vemec posted to leak siteransomware_live · 2026-08-07
- [thegentlemen] LensAss Architecten posted to leak siteransomware_live · 2026-08-07
- [thegentlemen] Phase Technologies posted to leak siteransomware_live · 2026-08-07
- [thegentlemen] Holborn European Marketing posted to leak siteransomware_live · 2026-08-07
- [thegentlemen] ZS Salovnova posted to leak siteransomware_live · 2026-08-07
- [thegentlemen] Halliday Watkins Mann posted to leak siteransomware_live · 2026-08-07
- [thegentlemen] YY Business Solutions posted to leak siteransomware_live · 2026-08-07
- [Storm] NCA Alarms posted to leak siteransomware_live · 2026-08-07
- [Storm] Nelson Manufacturing posted to leak siteransomware_live · 2026-08-07
- [Storm] Southern Indiana Radiological Associates posted to leak siteransomware_live · 2026-08-07
- Linux Shell Forensic: Let?s Dive Into Atuin!, (Fri, Aug 7th)sans_isc · 2026-08-07
- [Helix] Venture Logistics posted to leak siteransomware_live · 2026-08-07
- [Helix] Uber posted to leak siteransomware_live · 2026-08-07
- [Helix] Highwoods Properties posted to leak siteransomware_live · 2026-08-07
- [Helix] Morguard posted to leak siteransomware_live · 2026-08-07
- [Helix] Westland Insurance posted to leak siteransomware_live · 2026-08-07
- TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaignthehackernews · 2026-08-07
- [NVD] CVE-2026-19195 (HIGH 7.8) — A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39. The affected element is an unknown function in the library ZyArk.sys of the component Kernel Driver. The manipulation leads to improper access controls. The attack needs to be performed locally. The exploit hanvd · 2026-08-07
- [NVD] CVE-2026-19193 (HIGH 7.8) — A flaw has been found in Jiangmin Antivirus 21. Impacted is the function MessageNotifyCallback in the library kvcore.sys of the component Minifilter Port. Executing a manipulation can lead to improper access controls. The attack needs to be launched locally. The exploit has been nvd · 2026-08-07
- Risky Bulletin: A Meta AI model also escaped a testing sandboxriskybiz_news · 2026-08-07
- [krybit] reflet2000.fr posted to leak siteransomware_live · 2026-08-07
- [krybit] www.actini.com posted to leak siteransomware_live · 2026-08-07
- [krybit] www.ernat-bureau-etudes.fr posted to leak siteransomware_live · 2026-08-07
- [krybit] www.serengetiestates.co.za posted to leak siteransomware_live · 2026-08-07
- [krybit] www.hymiasa.com posted to leak siteransomware_live · 2026-08-07
- Google Chrome Multiple Vulnerabilitieshkcert · 2026-08-07
- Apple macOS Security Restriction Bypass Vulnerabilityhkcert · 2026-08-07
- [SilentRansomGroup] Mayer Brown posted to leak siteransomware_live · 2026-08-07
- The security signal log tailing can't see: tracking npm cooldown removals with Elastic Agentelastic_security · 2026-08-07
- [CISA KEV] CVE-2026-8037 — Progress LoadMaster: Progress LoadMaster Command Injection Vulnerabilitycisa_kev · 2026-08-07
- July 2026 CVE Landscaperecordedfuture · 2026-08-07
- [qilin] Crystal Pharmatech posted to leak siteransomware_live · 2026-08-06
- When Agentic Glue Melts: Exploiting Cloudflare Code Mode and Workerscheckpoint_research · 2026-08-06
- [NVD] CVE-2026-8325 (HIGH 7.8) — A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.nvd · 2026-08-06
- [NVD] CVE-2026-7406 (HIGH 7.8) — A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.nvd · 2026-08-06
- [NVD] CVE-2026-7405 (MEDIUM 5.5) — A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-Bounds Read in the image handling library. A malicious actor can leverage this vulnerability to cause a denial of servicenvd · 2026-08-06
- [NVD] CVE-2026-71554 (MEDIUM 5.3) — h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header blocks containing more than one Host header, and forward every Host header to the consuming application. Where the consumer downgrades HTTP/2 to HTTP/1.1, the rnvd · 2026-08-06
- [NVD] CVE-2026-71476 — Nx is a monorepo solution for TypeScript and polyglot codebases. From version 20.8.0 until 22.7.7 and 23.0.2, the Nx self-hosted HTTP remote cache extracts downloaded cache artifacts without constraining where files are written. A malicious or on-path (MITM) remote cache server cnvd · 2026-08-06
- [NVD] CVE-2026-70640 (HIGH 7.0) — llama.cpp builds b1886 through b7445 contain a race condition use-after-free vulnerability in the LLaMA-Android JNI wrapper where bench_1model() and free_1context() lack synchronization, allowing Thread A to operate on freed memory while Thread B concurrently frees the llama_contnvd · 2026-08-06
- [NVD] CVE-2026-70639 (MEDIUM 5.5) — llama.cpp builds b1886 through b7445 contain a null pointer dereference vulnerability in the LLaMA-Android JNI wrapper where the bench_1model() function fails to validate the model context pointer before dereferencing it. Attackers can supply a malicious, corrupt, or truncated monvd · 2026-08-06
- [NVD] CVE-2026-70638 (HIGH 7.8) — llama.cpp builds b1886 through b7445 contain an integer overflow vulnerability in the LLaMA-Android JNI wrapper where the new_1batch() function multiplies sizeof(llama_seq_id) by an attacker-controlled n_seq_max parameter without overflow validation, causing heap buffer allocationvd · 2026-08-06
- [NVD] CVE-2026-70636 (HIGH 7.5) — Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAuth2 credential refresh endpoint by exploiting prefix-based whitelist matching in the authentication middleware defined in packages/server/src/utils/constannvd · 2026-08-06
- [NVD] CVE-2026-68480 — In the Linux kernel, the following vulnerability has been resolved: x86/bugs: Make Safe-RET robust against interrupt injection An attacker injecting interrupts while the Safe-RET mitigation executes on machines affected by SRSO can neutralize the safe return sequence, potentialnvd · 2026-08-06
- [NVD] CVE-2026-67622 (CRITICAL 9.9) — Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attackers to access credentials belonging to other workspaces by supplying an arbitrary credential UUID to Assistants endpoints without nvd · 2026-08-06
- [NVD] CVE-2026-67621 (HIGH 7.6) — Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document store operations by accessing unprotected mutation endpoints. Attackers holding only view-level permissions can send direct HTTP requenvd · 2026-08-06
- [NVD] CVE-2026-64677 — Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, endpoints in Anki's local HTTP server do not adequately constrain requested media and built-in data paths, allowing scripts served from shared decks, or malicious websites combined with an origin-check bypnvd · 2026-08-06
- [NVD] CVE-2026-62857 — Fedify is a TypeScript library for building federated server apps powered by ActivityPub. From version 1.2.0 through the affected 1.9, 1.10, 2.0, 2.1, 2.2, and 2.3 maintenance lines, getNodeInfo() follows an attacker-controlled links[].href value from /.well-known/nodeinfo withounvd · 2026-08-06
- [NVD] CVE-2026-5857 (HIGH 8.1) — Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c sets topic_len_received=1 before checking topic_len against the 64-byte limit, so an over-length topic returns early but leaves the flag set. On the next TCP segment, tcp_input() re-invokes the parser wnvd · 2026-08-06
- [NVD] CVE-2026-48088 (CRITICAL 9.4) — OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.4, the route `POST /api/tenants/{tenantId}/staff/{staffId}/crypto` accepts and stores attacker-controlled ML-KEM-768 public keys against any tenant on nvd · 2026-08-06
- [NVD] CVE-2026-48083 (MEDIUM 6.5) — OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the `/api/log` endpoint accepts unauthenticated POST requests, applies no schema validation to the message body, writes attacker-controlled content nvd · 2026-08-06
- [NVD] CVE-2026-48078 (MEDIUM 5.3) — OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.5, the unauthenticated `/api/tenants/{id}/schedule` endpoint returns every non-archived channel for a tenant regardless of the channel's `isPublic` flanvd · 2026-08-06
- [NVD] CVE-2026-48071 (MEDIUM 5.8) — OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.4, the PIN-type challenge throttle uses `emailHash` as the only key. The throttle rows live in the central `challenge_throttle` table, which is shared nvd · 2026-08-06
- [NVD] CVE-2026-45573 (MEDIUM 6.4) — Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, when VAPID delivery is enabled, the notification subscription flow stores a client-supplied push endpoint without validating that it belongs to an apprnvd · 2026-08-06
- [NVD] CVE-2026-43632 (HIGH 8.1) — llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in llama-server affecting six tokenization endpoints (/tokenize, /detokenize, /infill, /apply-template, /rerank, and /anthropic/count_tokens) that bypass the task queue and access ctx_server.vnvd · 2026-08-06
- [NVD] CVE-2026-43631 (HIGH 8.1) — llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in the vocab pointer of llama-server when the --sleep-idle-seconds feature is enabled, allowing unauthenticated remote attackers to execute arbitrary code. Attackers can trigger the vulnerabilnvd · 2026-08-06
- [NVD] CVE-2026-43630 (MEDIUM 6.5) — llama.cpp builds b5702 through b7653 contain an out-of-bounds read vulnerability in the recurrent memory state restore path that allows attackers with write access to the slot save directory to read memory past the end of the allocated cells array. Attackers can craft a maliciousnvd · 2026-08-06
- [NVD] CVE-2026-43629 (HIGH 8.1) — llama.cpp builds b4882 through b9058 contain a heap buffer overflow vulnerability in the KV cache state restore path where the state_read_data() function computes write size without overflow checking, allowing attackers with write access to the slot_save_path directory to corruptnvd · 2026-08-06
- [NVD] CVE-2026-43628 (HIGH 7.8) — llama.cpp builds b3978 through b9058 contain an integer underflow and out-of-bounds read vulnerability in the DRY sampler that allows unauthenticated attackers to trigger a heap buffer underflow by sending a crafted HTTP request with dry_allowed_length set to INT32_MIN to the /v1nvd · 2026-08-06
- [NVD] CVE-2026-43627 (HIGH 7.8) — llama.cpp builds b1283 through b9058 contain an integer overflow vulnerability in the llama_batch_init() function where unchecked multiplications in malloc() calls can wrap past INT32_MAX when computing allocation sizes. Attackers can pass specially crafted parameters to trigger nvd · 2026-08-06
- [NVD] CVE-2026-1289 (HIGH 7.8) — A maliciously crafted PDF file, when parsed through Autodesk Revit, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, disclose sensitive data, or execute arbitrary code in the context of the current process.nvd · 2026-08-06
- [NVD] CVE-2026-19173 (HIGH 8.3) — Out of bounds write in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)nvd · 2026-08-06
- [NVD] CVE-2026-19159 (HIGH 7.5) — Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)nvd · 2026-08-06
- [NVD] CVE-2026-19158 (HIGH 7.5) — Use after free in Views in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)nvd · 2026-08-06
- [NVD] CVE-2026-19156 (HIGH 7.5) — Heap buffer overflow in Base in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)nvd · 2026-08-06
- [NVD] CVE-2026-19152 (HIGH 8.3) — Insufficient policy enforcement in Navigation in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)nvd · 2026-08-06
- [NVD] CVE-2026-19148 (HIGH 8.3) — Out of bounds write in GPU in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)nvd · 2026-08-06
- [NVD] CVE-2026-19147 (HIGH 8.3) — Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)nvd · 2026-08-06
- [NVD] CVE-2026-19142 (HIGH 7.5) — Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)nvd · 2026-08-06
- [NVD] CVE-2026-19141 (HIGH 8.3) — Use after free in Resources in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)nvd · 2026-08-06
- [NVD] CVE-2026-19108 (MEDIUM 5.3) — A vulnerability was found in MZ Automation libiec61850 up to 1.6.1. The affected element is the function deleteDataSetValuesShadowBuffer of the file src/iec61850/server/mms_mapping/reporting.c of the component URCB Revalidation. The manipulation results in use after free. The attnvd · 2026-08-06
- [NVD] CVE-2026-19067 (MEDIUM 6.3) — A security flaw has been discovered in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /treatment.php. Performing a manipulation of the argument editid results in sql injection. Remote exploitation of the attack is possible. Thnvd · 2026-08-06
- [NVD] CVE-2026-19061 (LOW 3.7) — A flaw has been found in Insta InstaKNXServiceApp 1.2.3.1469. Affected by this issue is the function CreateWebClientAndDownloadFileList of the component Firmware Update Handler. Executing a manipulation can lead to insufficient verification of data authenticity. It is possible tonvd · 2026-08-06
- [NVD] CVE-2026-11803 (HIGH 7.8) — A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.nvd · 2026-08-06
- [GHSA] GHSA-957r-qf9p-67xw (medium) — Craft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contextsgithub_advisories · 2026-08-06
- [GHSA] GHSA-6hr6-w5qg-qmwg (medium) — h2: Duplicate Host header could facilitate request smugglinggithub_advisories · 2026-08-06
- [GHSA] GHSA-596p-6jv8-775v (medium) — Craft CMS: Authenticated leak of secret environment variablesgithub_advisories · 2026-08-06
- [GHSA] GHSA-xxpx-f366-4xpq (medium) — Craft CMS:Authorization bypass: view-only Categories user can modify category structure via structures/move-elementgithub_advisories · 2026-08-06
- [GHSA] GHSA-rvmm-v933-jgxq (medium) — Craft CMS: Missing authorization check allows non-admin control panel users access to user registration metricsgithub_advisories · 2026-08-06
- [GHSA] GHSA-7hxc-f267-h5q7 (low) — Craft CMS: Incorrect path validation could potentially lead to path traversalgithub_advisories · 2026-08-06
- [GHSA] GHSA-2rp4-x2j7-qmcc (medium) — Craft CMS: Stored XSS in the control panel via unescaped draft namegithub_advisories · 2026-08-06