THREAT OPS › Threat News
Threat Intelligence News
11883 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [NVD] CVE-2026-9192 (CRITICAL 9.8) — An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the privileges of any named user known to the server, including anvd · 2026-08-05
- [NVD] CVE-2026-9190 (CRITICAL 9.1) — An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker to bypass authentication and authorization checks, hijack a legitimate user's session, or capture credentials. The vulnerability occurs whnvd · 2026-08-05
- [NVD] CVE-2026-8709 (CRITICAL 9.9) — An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges and execute privileged operations against the Securitynvd · 2026-08-05
- [NVD] CVE-2026-7557 (CRITICAL 9.1) — An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This vunvd · 2026-08-05
- [NVD] CVE-2026-7329 (CRITICAL 9.9) — An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges to administrator. This enables execution ofnvd · 2026-08-05
- [NVD] CVE-2026-7327 (HIGH 8.1) — An improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with an administrative REST role to escalate privileges. This can result in unauthorized disclosure of senvd · 2026-08-05
- [NVD] CVE-2026-7326 (HIGH 7.5) — A cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a malicious web page to perform administrative actions on the administrator's behalf. This can resnvd · 2026-08-05
- [OSSA-2026-033] Ironic Portgroup shard filter bypasses project scope (CVE-2026-71201)oss_sec · 2026-08-05
- [GHSA] GHSA-r4w5-6pfg-jxp5 (medium) — Electron: ProtocolResponse.url reuses the default session cache instead of the registering sessiongithub_advisories · 2026-08-05
- [GHSA] GHSA-v64r-4m7r-3mvq (medium) — Electron: HTTP redirect followed into local file loadergithub_advisories · 2026-08-05
- Cisco IOS XE Software Web-Based Management Interface Denial of Service Vulnerabilitycisco_psirt · 2026-08-05
- Cisco Integrated Management Controller Cross-Site Scripting Vulnerabilitycisco_psirt · 2026-08-05
- Cisco RoomOS Logging Subsystem Information Disclosure Vulnerabilitycisco_psirt · 2026-08-05
- Cisco IOS XE Software Blocks Extensible Exchange Protocol Denial of Service Vulnerabilitycisco_psirt · 2026-08-05
- Cisco IOS XE Software SNMP Denial of Service Vulnerabilitycisco_psirt · 2026-08-05
- Cisco IOS Software and IOS XE Software Extensible Messaging Client Protocol Denial of Service Vulnerabilitycisco_psirt · 2026-08-05
- Cisco Catalyst SD-WAN Manager Information Disclosure Vulnerabilitycisco_psirt · 2026-08-05
- Cisco IOS XE Software Security Hardening Release: August 2026cisco_psirt · 2026-08-05
- Cisco Integrated Management Controller Argument Injection Vulnerabilitiescisco_psirt · 2026-08-05
- Cisco Terminal Services Agent Firewall Rules Bypass Vulnerabilitycisco_psirt · 2026-08-05
- Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026cisco_psirt · 2026-08-05
- Cisco IOS XE Software Web-Based Management Interface Denial of Service Vulnerabilitycisco_psirt · 2026-08-05
- [GHSA] GHSA-v3j7-r9gq-3gjw (high) — Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin readsgithub_advisories · 2026-08-05
- ejabberd 26.07 released with several security fixesoss_sec · 2026-08-05
- [GHSA] GHSA-m55f-7gqj-fr98 (medium) — Electron: Extension tab APIs operate across session boundariesgithub_advisories · 2026-08-05
- [GHSA] GHSA-5c9j-mhmv-5xgx (medium) — Electron: shell.openPath path validation bypass via embedded null bytegithub_advisories · 2026-08-05
- From open lures to cloaked gates: How a macOS ClickFix campaign learned to hidemsstic · 2026-08-05
- [GHSA] GHSA-h7rp-cf8h-j98x (high) — Electron: Context isolation bypass via Function.prototype.bind hijackgithub_advisories · 2026-08-05
- [GHSA] GHSA-x8rc-wpg4-grpf (low) — Electron: Cross-origin iframe can position native autofill popupgithub_advisories · 2026-08-05
- [GHSA] GHSA-9pf5-hg6p-4pwp (medium) — Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origingithub_advisories · 2026-08-05
- Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Promptthehackernews · 2026-08-05
- [GHSA] GHSA-pfmc-3mgc-p6fp (low) — Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory sizegithub_advisories · 2026-08-05
- [GHSA] GHSA-jm7p-cc5g-qwxx (medium) — Electron: Parent process code-sign check is spoofablegithub_advisories · 2026-08-05
- [NVD] CVE-2026-16102 (HIGH 8.1) — A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User Property mappers, allowing them to write values to sensitive internal claim locatnvd · 2026-08-05
- [NVD] CVE-2026-16100 (MEDIUM 6.5) — A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error messages from failed account operations as Prometheus metric labels. Because these error messages can include user-supplied input like nonexistent client IDs, nvd · 2026-08-05
- [NVD] CVE-2026-16071 (MEDIUM 5.4) — A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external directories. The issue occurs when a delegated administrator performs a search using a specific LDAP entry Distinguished Name (DN). Due to missing validation, the synvd · 2026-08-05
- [NVD] CVE-2026-15573 (HIGH 8.1) — A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing slash or matrix parameters to a URL, an atnvd · 2026-08-05
- Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Importsthehackernews · 2026-08-05
- CVE-2026-60053: Apache Answer: Residual Administrative API Key Access After Role or Account Revocationoss_sec · 2026-08-05
- CVE-2026-60023: Apache Answer: Unauthorized disclosure of deleted or pending answer contentoss_sec · 2026-08-05
- Ransom & Dark Web Issues Week 1, August 2026ahnlab · 2026-08-05
- CVE-2026-50749: Apache Answer: Missing authorization in revision audit reject allows authenticated users to reject pending revisionsoss_sec · 2026-08-05
- CVE-2026-48912: Apache Answer: Improper authorization in avatar update cleanup allows authenticated users to delete arbitrary uploaded files by URLoss_sec · 2026-08-05
- CVE-2026-48911: Apache Answer: Unauthenticated OAuth Email-Binding Account Takeover via Existing User Confirmation Flowoss_sec · 2026-08-05
- CVE-2026-48834: Apache Answer: Denial of service via crafted Accept-Language header parsingoss_sec · 2026-08-05
- [Triple X] Henshaw Law posted to leak siteransomware_live · 2026-08-05
- CVE-2026-54876: OpenSSL: Client-Side Memory Leak in OCSP Response Checkingoss_sec · 2026-08-05
- [GHSA] GHSA-jx35-x7fj-vgpr (medium) — Ghost Content API filter bypass reveals private fieldsgithub_advisories · 2026-08-05
- [GHSA] GHSA-pr22-p9rp-2cqv (medium) — Ghost: Cross-Site Scripting in Feature Image Captionsgithub_advisories · 2026-08-05
- [GHSA] GHSA-x5mm-wm4g-j5xv (medium) — Ghost: Server-Side Request Forgery Mitigation Issuegithub_advisories · 2026-08-05
- Zscaler Wins 3 CRN Tech Innovator Awardszscaler_threatlabz · 2026-08-05
- Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bugthehackernews · 2026-08-05
- From Stolen Credentials to Full Breach: The 72-Hour Timelinecyble · 2026-08-05
- Compromised keyv Maintainer Account Triggers Massive npm Supply Chain Attackorca_security · 2026-08-05
- CVE-2026-61486: Apache Lucy: stack-buffer-overflow in JSON parser error reporter on malformed inputoss_sec · 2026-08-05
- CVE-2026-61485: Apache Lucy: Freezer/InStream deserialization bomb - unbounded allocation reading an indexoss_sec · 2026-08-05
- CVE-2026-61484: Apache Lucy: LucyX::Remote::SearchServer unauthenticated remote Storable::thaw -> RCE/DoSoss_sec · 2026-08-05
- CVE-2026-61483: Apache Lucy: QueryParser unbounded recursion on deeply-nested query -> C-stack-overflow DoSoss_sec · 2026-08-05
- Multiple vulnerabilities in Jenkins and Jenkins pluginsoss_sec · 2026-08-05
- How AI-powered phishing killed blocklists for goodbleepingcomputer · 2026-08-05
- Re: Bouncy Castle 1.85 release fixes 32 CVEsoss_sec · 2026-08-05
- [qilin] Stade Francais posted to leak siteransomware_live · 2026-08-05
- Immigration Policy: The Backdoor to Transnational Repressioncitizenlab · 2026-08-05
- OpenAI, Anthropic AI Agents Performed ‘Unsanctioned’ Actions During Cyber Testsduo_decipher · 2026-08-05
- Trojanized npm Packages Decode C2 IP From Ethereum Recipient Addressesthehackernews · 2026-08-05
- [NVD] CVE-2026-71227 (MEDIUM 5.1) — A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the _kcapi_aio_read_all() function can enter a non-terminating wait loop. This cannvd · 2026-08-05
- [NVD] CVE-2026-71225 (MEDIUM 6.5) — A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stateful modes such as Counter (CTR) or Cipher Block Chaining (CBC), the library improperly reuses the Initialization Vector (IV) for each internal data chunk. A renvd · 2026-08-05
- Horizon3 Accelerates Partner-Led Growth with $20 Million Investmenthorizon3 · 2026-08-05
- [Dark Project] Brainhunter Companies LLC. and Brainhunter Systems Ltd. posted to leak siteransomware_live · 2026-08-05
- [Dark Project] The Miller Group posted to leak siteransomware_live · 2026-08-05
- [Dark Project] TSC Logistics posted to leak siteransomware_live · 2026-08-05
- [everest] Keysight posted to leak siteransomware_live · 2026-08-05
- [Dark Project] Reid Electric Service, Inc posted to leak siteransomware_live · 2026-08-05
- Hewlett Packard Enterprise (HPE) security advisory (AV26-778)cccs_ca · 2026-08-05
- 10 Best Tenable Alternatives in 2026orca_security · 2026-08-05
- 7 Best Rapid7 Alternatives for Cloud Security and Exposure Management in 2026orca_security · 2026-08-05
- 9 Best CrowdStrike Alternatives in 2026orca_security · 2026-08-05
- Context-Backed Attacker’s-Eye Testing with Orca’s Attack Surface Red Agentorca_security · 2026-08-05
- 10 Best Qualys Alternatives for Cloud Security and Vulnerability Management in 2026orca_security · 2026-08-05
- Tenable Hexa AI: Automating exposure remediation with agentic routinestenable · 2026-08-05
- Researchers Find Persistent Backdoor in Zbtlink Routersduo_decipher · 2026-08-05
- Health360: The Answer to the Question, "Is My Zscaler Deployment Healthy?"zscaler_threatlabz · 2026-08-05
- [NVD] CVE-2026-64582 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix a use-after-free problem in rxe_mmap rxe_mmap() removes a rxe_mmap_info struct from the pending_mmaps list and releases pending_lock while the struct's kref is still at 1: list_del_init(&ip->pnvd · 2026-08-05
- CISA Adds One Known Exploited Vulnerability to Catalogcisa_advisories · 2026-08-05
- New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitchthehackernews · 2026-08-05
- Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Riskthehackernews · 2026-08-05
- Google’s synchronized passkeys can be stolen in ‘Pass‑ta‑key’ attacksmalwarebytes_blog · 2026-08-05
- Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markupthehackernews · 2026-08-05
- A few notes on AWS Nitro Enclaves: KMS integrationtrailofbits · 2026-08-05
- OpenAI, Anthropic AI Agents Performed ‘Unsanctioned’ Actions During Cyber Testsduo_decipher · 2026-08-05
- Leaked n8n API Tokens Exposed Live Instances to Credential Theftthehackernews · 2026-08-05
- Vulnerabilities in Car Anti-Theft Deviceschneier · 2026-08-05
- From Air Gaps to Always Connected: The Uptime Challenge Security Must Solvezscaler_threatlabz · 2026-08-05
- Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Datathehackernews · 2026-08-05
- [NVD] CVE-2026-10090 (CRITICAL 9.0) — A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with namespace-scoped "edit" privileges in an ACM hub namespace can create a Channel resource pointing to a Helm rnvd · 2026-08-05
- [NVD] CVE-2026-10059 (CRITICAL 9.1) — A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator. This action inadvertently grants the tenant administrator the abilnvd · 2026-08-05
- Junk Cleaner clears the clutter from your Androidmalwarebytes_blog · 2026-08-05
- [NVD] CVE-2026-71203 (MEDIUM 5.3) — changedetection.io's REST API resources are protected by an @auth.check_token decorator validating the caller's x-api-key header, except the Spec resource registered at /api/v1/full-spec (changedetectionio/api/Spec.py), whose get method carries neither @auth.check_token nor @valinvd · 2026-08-05
- [NVD] CVE-2026-70378 (HIGH 7.5) — imagecli's pipeline operation (Carve::apply in src/image_ops.rs) only asserts , never validating that the ratio is positive. A negative ratio (e.g. -5) causes the computed target width to saturate to 0 via Rust's defined float-to-uint cast, which is then passed to imageproc::seamnvd · 2026-08-05
- [NVD] CVE-2026-70377 (HIGH 7.5) — imagecli's pipeline operation (Scale::apply in src/image_ops.rs) computes output width/height as (dimension as f32 * ratio) as u32 with no upper-bound validation on the CLI-supplied ratio, which is parsed via nom::number::complete::float with no range check. Any application embednvd · 2026-08-05