THREAT OPS › Threat News
Threat Intelligence News
11876 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [GHSA] GHSA-rvmm-v933-jgxq (medium) — Craft CMS: Missing authorization check allows non-admin control panel users access to user registration metricsgithub_advisories · 2026-08-06
- [GHSA] GHSA-7hxc-f267-h5q7 (low) — Craft CMS: Incorrect path validation could potentially lead to path traversalgithub_advisories · 2026-08-06
- [GHSA] GHSA-2rp4-x2j7-qmcc (medium) — Craft CMS: Stored XSS in the control panel via unescaped draft namegithub_advisories · 2026-08-06
- [GHSA] GHSA-hmqg-cxww-wqhq (high) — PHP_CodeSniffer gitblame report command injection via crafted filenamegithub_advisories · 2026-08-06
- [GHSA] GHSA-j4r3-hg7j-8chg (medium) — node-re2: Out-of-bounds heap read in `replace`/`split` via a `Buffer` ending in a truncated multi-byte UTF-8 character → adjacent heap memory disclosed to JavaScriptgithub_advisories · 2026-08-06
- [GHSA] GHSA-8hcv-x26h-mcgp (medium) — node-re2: String.prototype.replace(re2, template) aborts the Node process (uncatchable ToLocalChecked on empty MaybeLocal) when the result exceeds V8's max string lengthgithub_advisories · 2026-08-06
- [GHSA] GHSA-w9hm-4m3m-fxmm (high) — ngx-extended-pdf-viewer bundles a version of pdf.js vulnerable to CVE-2026-16633github_advisories · 2026-08-06
- [GHSA] GHSA-hq66-cqwq-w95j (high) — PDF.js: Arbitrary JavaScript execution upon opening a malicious PDF github_advisories · 2026-08-06
- [GHSA] GHSA-pmhh-3w7g-xqp8 (medium) — jsoup: Cleaner may expose markup with custom raw-text elementsgithub_advisories · 2026-08-06
- [GHSA] GHSA-p8x7-9vfw-p7vc (high) — Craft CMS: Arbitrary user password reset leading to administrator account takeovergithub_advisories · 2026-08-06
- [GHSA] GHSA-f5wm-88jv-g5hx (high) — Craft CMS: Authenticated RCE through Twig sandbox escapegithub_advisories · 2026-08-06
- [GHSA] GHSA-9p7c-v5x3-rfx8 (medium) — Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Setsgithub_advisories · 2026-08-06
- [GHSA] GHSA-265m-7826-wjqm (high) — Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypassgithub_advisories · 2026-08-06
- [GHSA] GHSA-mj63-m3rc-8ppr (medium) — league/commonmark: Denial of service via deeply nested XML outputgithub_advisories · 2026-08-06
- [GHSA] GHSA-mh25-x5hq-wrqp (high) — league/commonmark: Denial of service via colliding heading slugsgithub_advisories · 2026-08-06
- [GHSA] GHSA-jfm3-95jq-q3rf (high) — league/commonmark: Denial of service via duplicate footnote definitionsgithub_advisories · 2026-08-06
- CVE-2026-68481: Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvideross_sec · 2026-08-06
- [GHSA] GHSA-g2gp-3wwq-f4ph (high) — league/commonmark: Denial of service via adjacent inline attribute blocksgithub_advisories · 2026-08-06
- CVE-2026-68079: Apache CXF: DefaultEncryptingCodeDataProvider allows unlimited authorization code replayoss_sec · 2026-08-06
- [GHSA] GHSA-2q4p-g7hv-5rgv (high) — league/commonmark: Quadratic-time denial of service when parsing crafted Markdowngithub_advisories · 2026-08-06
- CVE-2026-65583: Apache CXF: Self-issued ID token claims validation skippedoss_sec · 2026-08-06
- CVE-2026-63687: Apache CXF: JwtRequestCodeFilter silently overrides outer PKCE and nonce parametersoss_sec · 2026-08-06
- CVE-2026-61466: Apache CXF: OAuth2 Dynamic Client Registration Scope Self-Escalationoss_sec · 2026-08-06
- [GHSA] GHSA-29pj-957v-52mc (medium) — league/commonmark: AttributesExtension href/src unsafe-link filter bypass via embedded control bytesgithub_advisories · 2026-08-06
- Beyond Cyber: How CTI Teams Are Solving Converged Threat Use Casesflashpoint · 2026-08-06
- CVE-2026-57818: Apache CXF: OAuth2 Authorization Code Replay via TOCTOU in JCacheCodeDataProvideross_sec · 2026-08-06
- [GHSA] GHSA-5p4m-2wfm-xmqj (high) — JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backportedgithub_advisories · 2026-08-06
- CVE-2026-57817: Apache CXF: The authorization code hash (c_hash) is not enforced for the hybrid OIDC flowoss_sec · 2026-08-06
- CVE-2026-66909: Apache CXF: Unsafe deserialization of inbound JMS ObjectMessageoss_sec · 2026-08-06
- CVE-2026-65432: Apache CXF: XXE via WSDL/XSD import parsingoss_sec · 2026-08-06
- CVE-2026-64958: Apache CXF: Denial of service via message header attachmentsoss_sec · 2026-08-06
- CVE-2026-57819: Apache CXF: No default restriction on the amount of form parameters per messageoss_sec · 2026-08-06
- CVE-2026-54225: Apache CXF: Denial of Service attack via large attachmentsoss_sec · 2026-08-06
- [GHSA] GHSA-hqvf-45jj-mccq (medium) — AWS CLI: Disabled SSH host key verification in Amazon AWS CLI EMR helper commandsgithub_advisories · 2026-08-06
- [GHSA] GHSA-vp3h-ghgh-jr7g (high) — Nx: Zip-Slip in the self-hosted remote cachegithub_advisories · 2026-08-06
- [GHSA] GHSA-rhh3-jpg6-66xh (medium) — Mermaid radar diagrams are vulnerable to DoSgithub_advisories · 2026-08-06
- [GHSA] GHSA-c4c3-pg64-4m4v (low) — Mermaid configuration APIs allow prototype pollutiongithub_advisories · 2026-08-06
- [play] Signature Services posted to leak siteransomware_live · 2026-08-06
- [play] GCATS Investments posted to leak siteransomware_live · 2026-08-06
- [play] Platinum Group posted to leak siteransomware_live · 2026-08-06
- [GHSA] GHSA-6x64-9x62-f2gx (medium) — Mermaid allows CSS injection applying to sibling elements of the diagramgithub_advisories · 2026-08-06
- [GHSA] GHSA-3rrr-jr9j-h3q3 (medium) — Mermaid Architecture diagrams are vulnerable to prototype pollutiongithub_advisories · 2026-08-06
- [GHSA] GHSA-grm4-wm43-9jh5 (low) — Contao: Possible path traversal in job download URIsgithub_advisories · 2026-08-06
- [GHSA] GHSA-2v8p-3f2j-5mp7 (medium) — Mermaid XY Charts are vulnerable to an infinite loop DoSgithub_advisories · 2026-08-06
- CVE-2026-34502: Apache Portable Runtime Utility: Heap buffer overflow in APR memcached clientoss_sec · 2026-08-06
- CVE-2026-34501: Apache Portable Runtime Utility: Heap buffer overflow in APR redis clientoss_sec · 2026-08-06
- [GHSA] GHSA-3mr9-p497-58f6 (low) — Contao crawler leaks auth credentials to external hostsgithub_advisories · 2026-08-06
- CVE-2026-34191: Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracleoss_sec · 2026-08-06
- Dangling DNS record for bastion.certb.cdp.bethesda.netfulldisclosure · 2026-08-06
- CL.0 desync in www.microsoft.comfulldisclosure · 2026-08-06
- CVE-2026-32327: Apache Portable Runtime Utility: apr-util XML stack recursion crashoss_sec · 2026-08-06
- [GHSA] GHSA-vx89-p3j7-8xqc (medium) — Statamic: Stored Cross-Site Scripting in Automagic Form Notification Email Templategithub_advisories · 2026-08-06
- CVE-2025-49506: Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attackoss_sec · 2026-08-06
- CVE-2026-15013 – miniOrange SAML SSO <= 5.4.3 Unauthenticated Authentication Bypass (PoC)fulldisclosure · 2026-08-06
- [GHSA] GHSA-qhr7-v3xp-vw9m (medium) — Statamic: Missing file upload validation on frontend forms allows uploading disallowed file typesgithub_advisories · 2026-08-06
- [KIS-2026-16] Telenia Software TVox <= 26.5.3 (nice) Local Privilege Escalation Vulnerabilityfulldisclosure · 2026-08-06
- [KIS-2026-15] Telenia Software TVox <= 26.5.3 (action_audio.php) OS Command Injection Vulnerabilityfulldisclosure · 2026-08-06
- [KIS-2026-14] Telenia Software TVox <= 26.5.3 (set_env.php) Authentication Bypass Vulnerabilityfulldisclosure · 2026-08-06
- [KIS-2026-13] vBulletin <= 6.2.1 (runMaths) Remote Code Execution Vulnerabilityfulldisclosure · 2026-08-06
- CVE-2026-64640: Apache Polaris: register endpoint reads attacker-controlled storage location before allowed-locations validationoss_sec · 2026-08-06
- [SYSS-2026-050]: DICOM Toolkit (DCMTK) - Integer Overflow or Wraparound (CWE-190)fulldisclosure · 2026-08-06
- [SYSS-2026-049]: DICOM Toolkit (DCMTK) - Integer Overflow or Wraparound (CWE-190)fulldisclosure · 2026-08-06
- [SYSS-2026-048]: DICOM Toolkit (DCMTK) - Integer Overflow or Wraparound (CWE-190)fulldisclosure · 2026-08-06
- [SYSS-2026-047]: DICOM Toolkit (DCMTK) - Path traversal (CWE-22)fulldisclosure · 2026-08-06
- [SYSS-2026-046]: DICOM Toolkit (DCMTK) - Integer Overflow or Wraparound (CWE-190)fulldisclosure · 2026-08-06
- [GHSA] GHSA-qh8c-7588-qfrv (medium) — Statamic: Missing authorization on navigation endpoint allows disclosure of restricted entriesgithub_advisories · 2026-08-06
- [GHSA] GHSA-j2vp-f2pv-5rj4 (medium) — Statamic: Unsafe method invocation via Antlers template resolution allows data destructiongithub_advisories · 2026-08-06
- APPLE-SA-07-27-2026-8 Safari 26.6fulldisclosure · 2026-08-06
- APPLE-SA-07-27-2026-7 visionOS 26.6fulldisclosure · 2026-08-06
- APPLE-SA-07-27-2026-6 watchOS 26.6fulldisclosure · 2026-08-06
- APPLE-SA-07-27-2026-5 tvOS 26.6fulldisclosure · 2026-08-06
- APPLE-SA-07-27-2026-4 macOS Sonoma 14.8.8fulldisclosure · 2026-08-06
- APPLE-SA-07-27-2026-3 macOS Sequoia 15.7.8fulldisclosure · 2026-08-06
- Skullcandy Dime 3 unauthorized Bluetooth pairing behaviorfulldisclosure · 2026-08-06
- [GHSA] GHSA-93qh-5269-9wcf (high) — Statamic: Account takeover via OAuth email matching without email-verification checkgithub_advisories · 2026-08-06
- Security advisory: multiple vulnerabilities including Authenticated RCE (property injection), Hardcoded credentials, Pre-authentication root RCE in CatDV Server 10.7.8 (Square Box Systems)fulldisclosure · 2026-08-06
- Security advisory: multiple vulnerabilities including Default-credential RCE, Pre-authentication root RCE in atvise SCADA 3.13.0 (atvise GmbH / Bachmann Visutec)fulldisclosure · 2026-08-06
- Security advisory: Pre-authentication RCE in Apache Struts 2 2.6.11.0 (Apache Software Foundation)fulldisclosure · 2026-08-06
- Security advisory: Pre-authentication RCE in AOMEI Cyber Backup v2.3.0 (AOMEI)fulldisclosure · 2026-08-06
- [0day-Rubbish] SonicWall SMA 1000 — Pre-Auth Deserialization RCE (CVSS 9.8) via Struts 1 Property Injection and Auth-Filter Rewritefulldisclosure · 2026-08-06
- [GHSA] GHSA-225x-3jhx-wh4q (medium) — Statamic: Missing authorization on Control Panel endpoint allows disclosure of user existencegithub_advisories · 2026-08-06
- The DCHECK Illusion: Chrome's "Trusted Path" Policy Creates Vulnerabilitiesfulldisclosure · 2026-08-06
- Silent;Call — Pre-Authentication Remote Root in Cisco CUCM 15.x (SKYLINE-2026-001/002/003)fulldisclosure · 2026-08-06
- [GHSA] GHSA-47pj-3jcm-6whg (medium) — LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite storesgithub_advisories · 2026-08-06
- Private Access That Scales With Your App Catalogzscaler_threatlabz · 2026-08-06
- Why metaphor may dictate your security strategytalos · 2026-08-06
- New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hoststhehackernews · 2026-08-06
- Announcing OpenBao v2.6!openssf_blog · 2026-08-06
- [lynx] www.jerryleigh.com posted to leak siteransomware_live · 2026-08-06
- [lynx] www.talbotdes.org posted to leak siteransomware_live · 2026-08-06
- Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugsthehackernews · 2026-08-06
- Canadian Man Pleads Guilty in Snowflake Extortionskrebs · 2026-08-06
- [GHSA] GHSA-x677-9fxg-v5c5 (high) — Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuthgithub_advisories · 2026-08-06
- [GHSA] GHSA-cxjq-mrr5-89rv (critical) — Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middlewaregithub_advisories · 2026-08-06
- [Gammax] King International LLC posted to leak siteransomware_live · 2026-08-06
- [GHSA] GHSA-8rxv-jg7p-wvg3 (high) — Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypassgithub_advisories · 2026-08-06
- [GHSA] GHSA-6p8f-p8j2-rqmv (medium) — Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:portgithub_advisories · 2026-08-06
- [GHSA] GHSA-62fc-8686-hfmq (medium) — Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRefgithub_advisories · 2026-08-06
- [GHSA] GHSA-3q9r-p662-5j8m (medium) — Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=falsegithub_advisories · 2026-08-06
- [GHSA] GHSA-fgjj-px3w-67xx (high) — Traefik: Gateway API route identity collision allows cross-namespace backend hijackinggithub_advisories · 2026-08-06