THREAT OPS › Threat News
Threat Intelligence News
11883 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [GHSA] GHSA-cxjq-mrr5-89rv (critical) — Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middlewaregithub_advisories · 2026-08-06
- [Gammax] King International LLC posted to leak siteransomware_live · 2026-08-06
- [GHSA] GHSA-8rxv-jg7p-wvg3 (high) — Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypassgithub_advisories · 2026-08-06
- [GHSA] GHSA-6p8f-p8j2-rqmv (medium) — Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:portgithub_advisories · 2026-08-06
- [GHSA] GHSA-62fc-8686-hfmq (medium) — Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRefgithub_advisories · 2026-08-06
- [GHSA] GHSA-3q9r-p662-5j8m (medium) — Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=falsegithub_advisories · 2026-08-06
- [GHSA] GHSA-fgjj-px3w-67xx (high) — Traefik: Gateway API route identity collision allows cross-namespace backend hijackinggithub_advisories · 2026-08-06
- [GHSA] GHSA-6765-c87h-8mrf (low) — Traefik: BasicAuth singleflight key collision allows authenticated identity spoofinggithub_advisories · 2026-08-06
- Zscaler Integrates With OpenAI Cyber Models to Secure the AI-Enabled Endpointzscaler_threatlabz · 2026-08-06
- New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUsthehackernews · 2026-08-06
- [NVD] CVE-2026-43622 (HIGH 7.8) — llama.cpp builds b1886 through b7445 contain a double free vulnerability in the LLaMA-Android JNI wrapper where new_1batch() allocates memory using malloc() while free_1batch() deallocates it using the C++ delete operator, causing heap metadata corruption. Attackers can trigger tnvd · 2026-08-06
- [NVD] CVE-2026-19047 (MEDIUM 5.3) — A vulnerability was detected in NocteDefensor LudusMCP up to 1.0.24. This affects the function executeArbitraryCommand/executeCommand of the file src/ludusMCP/cliWrapper.ts of the component ludus_cli_execute. Performing a manipulation of the argument command/args results in commanvd · 2026-08-06
- [NVD] CVE-2026-18427 (HIGH 7.5) — @fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass. The static file handler rejected only parent directory segments, but it did not canonicalize dot segments, duplicate slashes, encoded dots, or backslashes before route matching andnvd · 2026-08-06
- [GHSA] GHSA-3ccp-42pg-hgv6 (high) — Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive poolgithub_advisories · 2026-08-06
- Re: Some Changes to GNOME Security Trackingoss_sec · 2026-08-06
- Django security advisory (AV26-786)cccs_ca · 2026-08-06
- [qilin] AmSpec posted to leak siteransomware_live · 2026-08-06
- [qilin] ALIZE (alize-sud.fr) posted to leak siteransomware_live · 2026-08-06
- [qilin] Jakle & Alexander posted to leak siteransomware_live · 2026-08-06
- ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Storiesthehackernews · 2026-08-06
- [NVD] CVE-2026-70646 (HIGH 7.5) — aiosend is a synchronous and asynchronous Crypto Pay API client. Pror to version 3.0.7, `WebhookHandler.feed_update()` deserializes the entire request body before verifying the HMAC signature. This allows an unauthenticated attacker to force expensive parsing of arbitrary JSON panvd · 2026-08-06
- Apple WebKit vulnerabilities reveal your IP address, despite Private Relaymalwarebytes_blog · 2026-08-06
- [qilin] Akuur Law Firm posted to leak siteransomware_live · 2026-08-06
- [qilin] J&T Bank and Trust posted to leak siteransomware_live · 2026-08-06
- PowerDNS Security Advisory 2026-11 for PowerDNS Authoritative Server, Recursor and dnsdist: A crafted DNS packet can cause increased memory and CPU consumptionoss_sec · 2026-08-06
- rust-in-peace: results from agent-assisted Rust OSS vulnerability researchoss_sec · 2026-08-06
- [bravox] MITC AG posted to leak siteransomware_live · 2026-08-06
- Cisco security advisory (AV26-785)cccs_ca · 2026-08-06
- UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environmentsmandiant_gti · 2026-08-06
- Ransomware Moves up the Org Chart: Managers Are Prime Targetszscaler_threatlabz · 2026-08-06
- Foxit security advisory (AV26-784)cccs_ca · 2026-08-06
- Vulnerability Scanning Tools: Top 10 Compared for 2026orca_security · 2026-08-06
- Cloud Security Controls: Types, Frameworks & Checklistorca_security · 2026-08-06
- AI Guardrails: Essential Safety Controls Explainedorca_security · 2026-08-06
- An Inside Look at Orca AI Agent Podsorca_security · 2026-08-06
- GitHub security advisory (AV26-783)cccs_ca · 2026-08-06
- Jenkins security advisory (AV26-782)cccs_ca · 2026-08-06
- [akira] Basic Grain Products posted to leak siteransomware_live · 2026-08-06
- Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Citiesthehackernews · 2026-08-06
- Progress security advisory (AV26-781)cccs_ca · 2026-08-06
- AI code security with Claude Mythos Preview: Inside Tenable’s 500+ hours of testing for Project Glasswingtenable · 2026-08-06
- Medixant RadiAnt DICOMcisa_advisories · 2026-08-06
- Johnson Controls Inc. TL280cisa_advisories · 2026-08-06
- ABB Ability Zenoncisa_advisories · 2026-08-06
- Zyxel security advisory (AV26-780)cccs_ca · 2026-08-06
- [akira] Pharma Test Apparatebau AG posted to leak siteransomware_live · 2026-08-06
- CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Appsthehackernews · 2026-08-06
- Scammers target OnlyFans users with deepfakesmalwarebytes_blog · 2026-08-06
- Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypassesthehackernews · 2026-08-06
- AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memorythehackernews · 2026-08-06
- [Orova] First Baptist Church of Belleview posted to leak siteransomware_live · 2026-08-06
- Adversarial Clothing Designed to Fool Facial Recognition Systemsschneier · 2026-08-06
- Snowflake Hacker Pleads Guilty, Faces 32 Yearssocradar_blog · 2026-08-06
- Amazon and Apple impersonated in “$149.99 unauthorized charge” scammalwarebytes_blog · 2026-08-06
- [Orova] Hilliard's Air Conditioning & Heating Inc posted to leak siteransomware_live · 2026-08-06
- [Orova] Gemstone UK posted to leak siteransomware_live · 2026-08-06
- Anthropic’s Mythos AI used social engineering to target real peoplemalwarebytes_blog · 2026-08-06
- [dragonforce] EduSpa posted to leak siteransomware_live · 2026-08-06
- Token Jacking: Cybercriminals Could Be Stealing Your AI Resourcesunit42 · 2026-08-06
- [dragonforce] Primary Eye Care posted to leak siteransomware_live · 2026-08-06
- [Orova] St Theresa Catholic Church posted to leak siteransomware_live · 2026-08-06
- [Orova] Stoneybrook West Master Association, Inc posted to leak siteransomware_live · 2026-08-06
- [Orova] Stonecrest POA posted to leak siteransomware_live · 2026-08-06
- [Orova] Magnolia Dental posted to leak siteransomware_live · 2026-08-06
- [Orova] Country Oaks Veterinary Clinic posted to leak siteransomware_live · 2026-08-06
- [Orova] David King Architect posted to leak siteransomware_live · 2026-08-06
- [Orova] Woodside Ranch posted to leak siteransomware_live · 2026-08-06
- Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Accessthehackernews · 2026-08-06
- [Barracuda] Ferrell \ Skyline Implants & Periodontics \ Dr. Scott Ferguson posted to leak siteransomware_live · 2026-08-06
- AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Modelthehackernews · 2026-08-06
- [Barracuda] Micro-Comm Inc. posted to leak siteransomware_live · 2026-08-06
- [Barracuda] Namyang Industrial Co., Ltd. \ NAMYANG NEXMO posted to leak siteransomware_live · 2026-08-06
- [Barracuda] RS Automation Co., Ltd. posted to leak siteransomware_live · 2026-08-06
- [threeam] clubonecasino.com posted to leak siteransomware_live · 2026-08-06
- [NVD] CVE-2026-64601 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on each resubmission In capture_urb_complete(), usb_anchor_urb() is called on every completion callback, but the URB is alreanvd · 2026-08-06
- [NVD] CVE-2026-64599 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: crypto: amlogic - avoid double cleanup in meson_crypto_probe() When meson_allocate_chanlist() fails after a partial allocation, it already unwinds the allocated chanlist state through its local error path. mesonvd · 2026-08-06
- [NVD] CVE-2026-64598 (HIGH 8.8) — In the Linux kernel, the following vulnerability has been resolved: smb/client: Fix error code in smb2_aead_req_alloc() The "*num_sgs" variable is a u32 so "ERR_PTR(*num_sgs)" doesn't work. We would have to do something similar to the previous line where it's cast to int and thnvd · 2026-08-06
- [NVD] CVE-2026-64597 (CRITICAL 9.8) — In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_close() replay A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_close_init() fails before the next send, cleanup retains the prnvd · 2026-08-06
- [NVD] CVE-2026-64590 — In the Linux kernel, the following vulnerability has been resolved: dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning When CONFIG_DMA_API_DEBUG_SG is enabled, importing a udmabuf into a DRM driver (e.g. amdgpu for video playback in GNOME Videos / Showtimenvd · 2026-08-06
- [NVD] CVE-2026-64588 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: fuse-uring: fix data races on ring->ready On weakly-ordered architectures, the store to fiq->ops can be reordered past the store to ring->ready, allowing a CPU that sees ring->ready == true via fuse_uring_readynvd · 2026-08-06
- [NVD] CVE-2026-64587 (HIGH 7.0) — In the Linux kernel, the following vulnerability has been resolved: net: ethernet: arc: emac: quiesce interrupts before requesting IRQ Normal RX/TX interrupts are enabled later, in arc_emac_open(), so probe should not see interrupt delivery in the usual case. However, hardware nvd · 2026-08-06
- [NVD] CVE-2026-64586 (HIGH 8.8) — In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: drain bus_reset work on device removal brcmf_fw_crashed() and the debugfs "reset" entry both schedule drvr->bus_reset, whose callback recovers drvr through container_of() and dereferences it. Tnvd · 2026-08-06
- [NVD] CVE-2026-64585 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: can: esd_usb: kill anchored URBs before freeing netdevs esd_usb_disconnect() frees each CAN netdev with free_candev() inside its per-netdev loop and only calls unlink_all_urbs(dev) afterwards. The per-netdev prnvd · 2026-08-06
- [NVD] CVE-2026-64584 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_midi: cancel pending IN work before freeing the midi object The f_midi driver embeds a work item (midi->work) whose handler, f_midi_in_work(), dereferences the enclosing struct f_midi through connvd · 2026-08-06
- [NVD] CVE-2026-64583 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown The Broadcom BDC UDC driver registers its IRQ handler with devm_request_irq() in bdc_udc_init(), so the IRQ is released by devm only afnvd · 2026-08-06
- [NVD] CVE-2026-18649 (HIGH 7.5) — A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size limit on the reassembly buffer used during fragmented RTP packet processing. A remote, unauthenticated attacker can send a continuonvd · 2026-08-06
- [NVD] CVE-2024-6832 (MEDIUM 5.9) — The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not maintain a consistent state for account locking if it cannot reach all configured user stores, allowing an attacker to repeatedly attempt authentication with invalid nvd · 2026-08-06
- [NVD] CVE-2024-10302 (MEDIUM 4.0) — The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input. This weakness allows arbitrary unvalidated data to be included within user claims, which are then used by downstream processes. Allowing unvalidated input into user claims can lnvd · 2026-08-06
- Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shellsthehackernews · 2026-08-06
- EclecticIQ Intelligence Center 3.8: Built for the way security teams are actually working noweclecticiq · 2026-08-06
- Day 2 at Black Hat: Check Point Research Takes the Stagecheckpoint_research · 2026-08-06
- Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million Peoplethehackernews · 2026-08-06
- Srsly Risky Biz: Being a North Korean hacker is about to be less funriskybiz_news · 2026-08-06
- Debian Linux Kernel Multiple Vulnerabilitieshkcert · 2026-08-06
- Cisco Products Multiple Vulnerabilitieshkcert · 2026-08-06
- Jenkins Multiple Vulnerabilitieshkcert · 2026-08-06
- Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packageselastic_security · 2026-08-06
- Emerging Threats to Neurotechnologyrecordedfuture · 2026-08-06
- [Breach] Fanlore — 144,520 accounts exposedhibp_breaches · 2026-08-06
- [incransom] vprj.org posted to leak siteransomware_live · 2026-08-05