THREAT OPS › Threat News
Threat Intelligence News
11883 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [GHSA] GHSA-42cj-m3vj-89wv (medium) — Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypassgithub_advisories · 2026-08-05
- [GHSA] GHSA-qq9q-x9w4-chhj (medium) — Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusiongithub_advisories · 2026-08-05
- [GHSA] GHSA-9pgf-384g-p7mv (high) — Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validationgithub_advisories · 2026-08-05
- [GHSA] GHSA-9473-5f9j-94wq (high) — Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Propsgithub_advisories · 2026-08-05
- [Panzer] Surakarta University posted to leak siteransomware_live · 2026-08-05
- [Panzer] Festina Group posted to leak siteransomware_live · 2026-08-05
- [GHSA] GHSA-279x-mwfv-vcqv (critical) — Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's hostgithub_advisories · 2026-08-05
- [GHSA] GHSA-48hr-524c-v5w3 (medium) — Nuxt: Unauthorized Component Instantiation via Server Island Propsgithub_advisories · 2026-08-05
- [GHSA] GHSA-wm8w-6qjm-cv43 (high) — Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clientsgithub_advisories · 2026-08-05
- [GHSA] GHSA-hxvh-4h3w-prp9 (high) — Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721)github_advisories · 2026-08-05
- [clop] nuv******* posted to leak siteransomware_live · 2026-08-05
- [clop] ipm******* posted to leak siteransomware_live · 2026-08-05
- [clop] ecc******* posted to leak siteransomware_live · 2026-08-05
- [clop] st******* posted to leak siteransomware_live · 2026-08-05
- [GHSA] GHSA-hxcr-hm88-mpq6 (high) — Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island renderinggithub_advisories · 2026-08-05
- [clop] qc******* posted to leak siteransomware_live · 2026-08-05
- [clop] flu******* posted to leak siteransomware_live · 2026-08-05
- [clop] mid******* posted to leak siteransomware_live · 2026-08-05
- [clop] itk******* posted to leak siteransomware_live · 2026-08-05
- [clop] G3A******* posted to leak siteransomware_live · 2026-08-05
- [clop] arc******* posted to leak siteransomware_live · 2026-08-05
- [clop] omn******* posted to leak siteransomware_live · 2026-08-05
- [clop] lif******* posted to leak siteransomware_live · 2026-08-05
- [clop] sp******* posted to leak siteransomware_live · 2026-08-05
- [clop] iva******* posted to leak siteransomware_live · 2026-08-05
- [clop] nuo******* posted to leak siteransomware_live · 2026-08-05
- [clop] the******* posted to leak siteransomware_live · 2026-08-05
- [clop] wat******* posted to leak siteransomware_live · 2026-08-05
- [clop] 9al******* posted to leak siteransomware_live · 2026-08-05
- [clop] int******* posted to leak siteransomware_live · 2026-08-05
- [clop] hon******* posted to leak siteransomware_live · 2026-08-05
- [clop] ato******* posted to leak siteransomware_live · 2026-08-05
- [clop] clo******* posted to leak siteransomware_live · 2026-08-05
- [clop] jpm******* posted to leak siteransomware_live · 2026-08-05
- [GHSA] GHSA-7p4m-qxvv-g567 (medium) — rclone: Local Encoding Path Traversalgithub_advisories · 2026-08-05
- [clop] bri******* posted to leak siteransomware_live · 2026-08-05
- [clop] suu******* posted to leak siteransomware_live · 2026-08-05
- [clop] sma******* posted to leak siteransomware_live · 2026-08-05
- [clop] tri******* posted to leak siteransomware_live · 2026-08-05
- [clop] cor******* posted to leak siteransomware_live · 2026-08-05
- [clop] mam******* posted to leak siteransomware_live · 2026-08-05
- [clop] par******* posted to leak siteransomware_live · 2026-08-05
- [clop] sta******* posted to leak siteransomware_live · 2026-08-05
- [clop] lar******* posted to leak siteransomware_live · 2026-08-05
- [clop] toa******* posted to leak siteransomware_live · 2026-08-05
- [GHSA] GHSA-4vr5-p2gc-h23p (medium) — rclone archive extract allows S3 destination prefix escape via crafted archive pathsgithub_advisories · 2026-08-05
- [clop] ir****** posted to leak siteransomware_live · 2026-08-05
- Flooding Dropper Hits npm With 850 Malicious Packagessonatype · 2026-08-05
- [GHSA] GHSA-gx4c-2hqx-cw2r (low) — rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirectgithub_advisories · 2026-08-05
- [clop] ald******* posted to leak siteransomware_live · 2026-08-05
- [clop] phi******* posted to leak siteransomware_live · 2026-08-05
- [clop] fis******* posted to leak siteransomware_live · 2026-08-05
- [GHSA] GHSA-fqj9-69pf-6pjg (high) — rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositoriesgithub_advisories · 2026-08-05
- [clop] g******* posted to leak siteransomware_live · 2026-08-05
- [clop] sh******* posted to leak siteransomware_live · 2026-08-05
- [clop] net******* posted to leak siteransomware_live · 2026-08-05
- [GHSA] GHSA-2m8m-jhrm-w6j2 (high) — rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Executiongithub_advisories · 2026-08-05
- [GHSA] GHSA-h4mf-4v27-hggj (medium) — rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirectgithub_advisories · 2026-08-05
- [GHSA] GHSA-8c48-q9wj-3w37 (medium) — rclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Preserves Newlinesgithub_advisories · 2026-08-05
- [GHSA] GHSA-8mxv-9xhp-86h4 (medium) — rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keysgithub_advisories · 2026-08-05
- [GHSA] GHSA-8v25-v8p6-qf7v (medium) — rclone: Path traversal in serve s3 allows reading and overwriting root-level filesgithub_advisories · 2026-08-05
- [GHSA] GHSA-3x6r-wxxg-53vv (medium) — rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panicgithub_advisories · 2026-08-05
- [GHSA] GHSA-xhf4-832v-7xcr (medium) — rclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone Memorygithub_advisories · 2026-08-05
- [GHSA] GHSA-cf44-9pgv-m4xc (high) — rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remotegithub_advisories · 2026-08-05
- [GHSA] GHSA-45pq-889g-fcgh (high) — rclone: Incomplete path validation allows backend root escape in serve resticgithub_advisories · 2026-08-05
- [lockbit5] briggsplc.com posted to leak siteransomware_live · 2026-08-05
- [GHSA] GHSA-945v-v9p3-v5xw (low) — rclone local `--metadata` applies attacker-controlled mode/uid - setuid binary planted from an untrusted remotegithub_advisories · 2026-08-05
- [GHSA] GHSA-gwfq-86j8-7qhv (low) — rclone: Verbose Stack Trace Disclosure in RC API Error Responsesgithub_advisories · 2026-08-05
- [NVD] CVE-2026-18485 (HIGH 7.8) — There is a local privilege escalation vulnerability recently discovered in the NI-PAL kernel driver. This may allow a local, authenticated user to escalate privileges and execute arbitrary code. This vulnerability affects NI-PAL 26.3.1 and prior versions running on Microsoft Winvd · 2026-08-05
- Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Luresthehackernews · 2026-08-05
- OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemesthehackernews · 2026-08-05
- [qilin] Mera Metal posted to leak siteransomware_live · 2026-08-05
- [Global Secret Group] Pavillon posted to leak siteransomware_live · 2026-08-05
- [GHSA] GHSA-p2rr-rvmm-c5fp (medium) — Electron: Sandboxed iframes can launch external protocol handlersgithub_advisories · 2026-08-05
- Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th)sans_isc · 2026-08-05
- Zbtlink security advisory (AV26-779)cccs_ca · 2026-08-05
- [dragonforce] P. A. Inc. (Performance Alloys) posted to leak siteransomware_live · 2026-08-05
- [dragonforce] Mike Graham Heating And Air Conditioning posted to leak siteransomware_live · 2026-08-05
- [GHSA] GHSA-f2r8-jv7c-xqmp (medium) — Electron: DevTools embedder handler executes arbitrary files via shell opengithub_advisories · 2026-08-05
- [GHSA] GHSA-ff2p-hmqr-hxm4 (medium) — Electron: contextBridge object copy honors prototype settersgithub_advisories · 2026-08-05
- [GHSA] GHSA-4f78-qhmw-8j8m (medium) — Electron: DevTools JavaScript Injection via Unsanitized Dock State Parametergithub_advisories · 2026-08-05
- [GHSA] GHSA-9f4c-93c8-jc8g (high) — Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation pathgithub_advisories · 2026-08-05
- Mini Shai-Hulud npm Attack: More Than 2,200 Components Impactedsonatype · 2026-08-05
- [NVD] CVE-2026-20288 (MEDIUM 6.5) — A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with Admin privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root. This vulneranvd · 2026-08-05
- Turning Enterprise Update Servers Into Backdoor Factories (0_o) – Part 1specterops · 2026-08-05
- Turning Enterprise Update Servers Into Backdoor Factories (0_o) – Part 2specterops · 2026-08-05
- Of Course We Built a WSUS Ludus Labspecterops · 2026-08-05
- Weaponizing Windows Updates with NotWSUSpiciousspecterops · 2026-08-05
- Re: [OSSA-2026-031] OpenStack Swift: Proxy denial of service via Accept header (CVE-2026-71190)oss_sec · 2026-08-05
- Re: [OSSA-2026-030] OpenStack Swift: S3API header authorization bypass (CVE-2026-71191, CVE-2026-71192)oss_sec · 2026-08-05
- Re: [OSSA-2026-007] OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean (CVE-2026-40683)oss_sec · 2026-08-05
- Zscaler Integrates With Claude Inference Hooks to Scale AI While Addressing Riskszscaler_threatlabz · 2026-08-05
- [qilin] STADLER Sensorik CNC-Technik posted to leak siteransomware_live · 2026-08-05
- Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP)msstic · 2026-08-05
- [GHSA] GHSA-v93f-fgjr-hjrj (medium) — Electron: window.open features string controls some window options considered privilegedgithub_advisories · 2026-08-05
- [chaos] tomorrowsoffice.com posted to leak siteransomware_live · 2026-08-05
- [Dark Project] Long-Lewis Automotive Group posted to leak siteransomware_live · 2026-08-05
- [NVD] CVE-2026-9203 (HIGH 8.5) — A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with low-privileged roles to bypass protections for cloud instance metadata endpoints. Successful exploitation can disclose cloud credentials and compromnvd · 2026-08-05
- [NVD] CVE-2026-9195 (CRITICAL 9.3) — A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a crafted URL to execute arbitrary JavaScript in the administrator's browser session, capture credenvd · 2026-08-05
- [NVD] CVE-2026-9193 (CRITICAL 9.9) — An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Hadoop role to escalate privileges and execute privileged operations against the Security database.nvd · 2026-08-05