THREAT OPS › Threat News
Threat Intelligence News
11890 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [GHSA] GHSA-qgvm-j2hm-6m38 (critical) — Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables token theft for any connected servicegithub_advisories · 2026-08-04
- Re: Some Changes to GNOME Security Trackingoss_sec · 2026-08-04
- CVE-2026-67592: Apache Qpid ProtonJ2: Unable to govern the maximum number of transfer frames per incoming deliveryoss_sec · 2026-08-04
- [GHSA] GHSA-5xvg-pmgg-3mxr (critical) — Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerabilitygithub_advisories · 2026-08-04
- CVE-2026-67591: Apache Qpid ProtonJ2: Incoming session flow control window can be exceededoss_sec · 2026-08-04
- CVE-2026-67590: Apache Qpid ProtonJ2: Unbounded type nesting can lead to pre-authentication stackoverflowoss_sec · 2026-08-04
- [GHSA] GHSA-gmmw-qg98-6j6p (high) — Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billing Manipulationgithub_advisories · 2026-08-04
- CVE-2026-67589: Apache Qpid ProtonJ2: Type size/count handling can lead to excessive allocation pre-authenticationoss_sec · 2026-08-04
- CVE-2026-67588: Apache Qpid ProtonJ2: Unbounded symbol value caching can lead to pre-authentication resource exhaustionoss_sec · 2026-08-04
- [GHSA] GHSA-8gj2-2cvc-6xx7 (medium) — Flowise: Unauthenticated Credential Abuse via Text-to-Speech Endpoint Allows Unauthorized Use of Private Chatflow TTS Credentialsgithub_advisories · 2026-08-04
- [GHSA] GHSA-fm2f-4339-4p2f (high) — Flowise: Missing Authorization on Execution Update Endpointgithub_advisories · 2026-08-04
- CVE-2026-67555: Apache Qpid Proton Dotnet: Unable to govern the maximum number of transfer frames per incoming deliveryoss_sec · 2026-08-04
- [NVD] CVE-2026-70474 (HIGH 8.1) — Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise has three OAuth2 credential endpoints that look up credentials by id alone with no workspaceId filter. The authorize, callback, and refresh handlers query tnvd · 2026-08-04
- [NVD] CVE-2026-70473 (HIGH 8.5) — Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise GET /api/v1/upsert-history returns the entire server-wide upsert history instead of being scoped to the requesting user, tenant, or workspace. The response nvd · 2026-08-04
- CVE-2026-67554: Apache Qpid Proton Dotnet: Unbounded disposition range handling can lead to denial of serviceoss_sec · 2026-08-04
- CVE-2026-67553: Apache Qpid Proton Dotnet: Incoming session flow control window can be exceededoss_sec · 2026-08-04
- CVE-2026-67552: Apache Qpid Proton Dotnet: Unbounded type nesting can lead to pre-authentication stackoverflowoss_sec · 2026-08-04
- CVE-2026-67551: Apache Qpid Proton Dotnet: Type size/count handling can lead to excessive allocation pre-authenticationoss_sec · 2026-08-04
- CVE-2026-67465: Apache Qpid Proton Dotnet: Unbounded symbol value caching can lead to pre-authentication resource exhaustionoss_sec · 2026-08-04
- CVE-2026-68080: Apache Qpid Broker-J: Unbounded echo flow responses can lead to denial of serviceoss_sec · 2026-08-04
- CVE-2026-68078: Apache Qpid Broker-J: Unable to govern the maximum number of transfer frames per incoming deliveryoss_sec · 2026-08-04
- Iran Cyberattacks Against Minnesota Water Systemsschneier · 2026-08-04
- CVE-2026-68077: Apache Qpid Broker-J: Unbounded disposition range handling can lead to denial of serviceoss_sec · 2026-08-04
- CVE-2026-68075: Apache Qpid Broker-J: Incoming session flow control window can be exceededoss_sec · 2026-08-04
- Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOpsmsstic · 2026-08-04
- A Roadmap for Confronting the Chilling Effects of Censorship, Surveillance and New Technologycitizenlab · 2026-08-04
- CVE-2026-66277: Apache Qpid Proton-J: Unable to govern the maximum number of transfer frames per incoming deliveryoss_sec · 2026-08-04
- CVE-2026-66276: Apache Qpid Proton-J: Unbounded disposition range handling can lead to denial of serviceoss_sec · 2026-08-04
- CVE-2026-66275: Apache Qpid Proton-J: Incoming session flow control window can be exceededoss_sec · 2026-08-04
- CVE-2026-66274: Apache Qpid Proton-J: Unbounded type nesting can lead to pre-authentication stackoverflowoss_sec · 2026-08-04
- [GHSA] GHSA-wch5-xp77-fxg4 (high) — Flowise: Cross-Workspace OAuth2 Credential Metadata Leakgithub_advisories · 2026-08-04
- [qilin] Galvin Brothers posted to leak siteransomware_live · 2026-08-04
- [qilin] RUPP Spritzguss posted to leak siteransomware_live · 2026-08-04
- CVE-2026-66273: Apache Qpid Proton-J: Type size/count handling can lead to excessive allocation pre-authenticationoss_sec · 2026-08-04
- [krybit] cesmac.edu.br posted to leak siteransomware_live · 2026-08-04
- CVE-2026-66257: Apache Qpid Proton-J: Unbounded symbol value caching can lead to pre-authentication resource exhaustionoss_sec · 2026-08-04
- [GHSA] GHSA-rwrp-9823-p2xq (medium) — Flowise: Incomplete Credential Redaction Exposes Secrets via APIgithub_advisories · 2026-08-04
- [GHSA] GHSA-fr6g-7cq8-fg82 (high) — Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert historygithub_advisories · 2026-08-04
- [incransom] TRULITE GLASS & ALUMINUM SOLUTIONS posted to leak siteransomware_live · 2026-08-04
- 128 Seconds to disruption: Microsoft Defender stops ransomware at QNETmsstic · 2026-08-04
- [GHSA] GHSA-chm3-vqcf-52rx (high) — Flowise: Cross-workspace credential IDOR in openai-assistants-vector-storegithub_advisories · 2026-08-04
- [GHSA] GHSA-4j8x-x6v7-w9rq (critical) — Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validationgithub_advisories · 2026-08-04
- [GHSA] GHSA-8r8h-6vcc-xhrv (high) — Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosuregithub_advisories · 2026-08-04
- MISP security advisory (AV26-775)cccs_ca · 2026-08-04
- [GHSA] GHSA-52fh-8v99-63c2 (critical) — Flowise: Pyodide validator Unicode homoglyph bypass leads to RCEgithub_advisories · 2026-08-04
- Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokensthehackernews · 2026-08-04
- Re: Bouncy Castle 1.85 release fixes 32 CVEsoss_sec · 2026-08-04
- [GHSA] GHSA-xc48-889x-5qmw (high) — Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)github_advisories · 2026-08-04
- [GHSA] GHSA-p5w8-m249-4r4v (high) — Flowise: `DELETE /api/v1/chatflows/:id` does not validate resource type, allowing `agentflows:delete` and `chatflows:delete` to delete each other’s flow typegithub_advisories · 2026-08-04
- On-Prem Data Security in the AI Era: Why It’s Time to Modernize with DSPMzscaler_threatlabz · 2026-08-04
- [play] First Tek posted to leak siteransomware_live · 2026-08-04
- [play] Preferred Financial Group posted to leak siteransomware_live · 2026-08-04
- Django CVE-2026-15307, CVE-2026-15337, CVE-2026-15830, and CVE-2026-15920oss_sec · 2026-08-04
- [GHSA] GHSA-x3hf-7cj6-3r4m (critical) — Flowise RCE via SQLite Record Manager Nodegithub_advisories · 2026-08-04
- [thegentlemen] TopMark Funding posted to leak siteransomware_live · 2026-08-04
- [thegentlemen] Control Concepts Technology posted to leak siteransomware_live · 2026-08-04
- 5 Reasons Developers Still Download Malicious Packagessonatype · 2026-08-04
- [chaos] healthcarehighways.com posted to leak siteransomware_live · 2026-08-04
- [GHSA] GHSA-6vh2-wg4h-4vwj (high) — Flowise: Unauthenticated Property Injection into Flow Execution Context via Ungated `overrideConfig` Spread in Prediction APIgithub_advisories · 2026-08-04
- [GHSA] GHSA-c6xh-wv4j-ppv5 (high) — Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addressesgithub_advisories · 2026-08-04
- [GHSA] GHSA-x6vm-w76m-8j7g (critical) — Remote Code Execution Vulnerability in CSVAgentgithub_advisories · 2026-08-04
- Checkpoint security advisory (AV26-774)cccs_ca · 2026-08-04
- [GHSA] GHSA-vmv7-4m6c-3cg5 (critical) — Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verifiedgithub_advisories · 2026-08-04
- Tenable, Inc. security advisory (AV26-773)cccs_ca · 2026-08-04
- WebPros security advisory (AV26-772)cccs_ca · 2026-08-04
- [GHSA] GHSA-3769-jgqc-cxm7 (critical) — Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Overridegithub_advisories · 2026-08-04
- Dell security advisory (AV26-771)cccs_ca · 2026-08-04
- [NVD] CVE-2026-67618 (MEDIUM 6.5) — marimo before 0.23.15 contains a configuration injection vulnerability that allows notebook authors to exfiltrate operator API keys by embedding a malicious base_url in PEP-723 inline script metadata, which is merged into session configuration with higher precedence than the opernvd · 2026-08-04
- [NVD] CVE-2026-11368 (HIGH 7.1) — The Bluetooth host ATT layer (subsys/bluetooth/host/att.c) associates each in-flight ATT TX buffer with its owning channel via the static tx_meta_data_storage[] array (data->att_chan = chan). When a buffer's last reference is dropped, its net-buf destroy callback defers the complnvd · 2026-08-04
- [GHSA] GHSA-wg86-r78f-74mp (critical) — Flowise Sandbox Escape to RCEgithub_advisories · 2026-08-04
- Zscaler Named a Leader in the 2026 Gartner® Magic Quadrant™ Reports for SASE and SSEzscaler_threatlabz · 2026-08-04
- IBM security advisory (AV26-770)cccs_ca · 2026-08-04
- [GHSA] GHSA-wp74-f5hh-5f3r (high) — Flowise: Missing authorization on `/api/v1/files` allows low-privileged API keys to list and delete files across workspaces within the same organizationgithub_advisories · 2026-08-04
- [GHSA] GHSA-g32j-mmxr-gfq5 (critical) — Flowise RCE via TypeORM DataSourcegithub_advisories · 2026-08-04
- [GHSA] GHSA-r745-8hwv-h473 (high) — Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret Exfiltrationgithub_advisories · 2026-08-04
- Re: Some Changes to GNOME Security Trackingoss_sec · 2026-08-04
- [GHSA] GHSA-2364-jh4q-m9vm (medium) — Flowise: IDOR vulnerability exists at the GET /api/v1/organization/customer-default-source endpointgithub_advisories · 2026-08-04
- Russian businesses erase Durov-linked products after 'terrorist' designationthe_record · 2026-08-04
- Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooksthehackernews · 2026-08-04
- What’s in the SOSS? Podcast #67 – S3E19 Funding the Future: Community Collaboration and the Spirit of Open Source with Mila Zhouopenssf_blog · 2026-08-04
- [gunra] worldtube posted to leak siteransomware_live · 2026-08-04
- [NVD] CVE-2026-70373 (HIGH 8.8) — Koha's reports/issues_stats.pl (the circulation statistics report) builds its calculation query in sub calculate by concatenating several user-controlled request parameters directly into the SQL string. The PeriodTypeSel, PeriodDaySel, and PeriodMonthSel parameters are interpolatnvd · 2026-08-04
- [NVD] CVE-2026-70372 (HIGH 8.8) — Koha's reports/bor_issues_top.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request parameters directly into the query string. An authenticated staff user holding the reports module permission can inject arbitrary SQL and read any table reachablenvd · 2026-08-04
- [NVD] CVE-2026-70371 (HIGH 8.8) — Koha's reports/issues_avg_stats.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request parameters directly into the query string. The Line and Column parameters are not validated against any whitelist and land verbatim in identifier positions (SELnvd · 2026-08-04
- [NVD] CVE-2026-70370 (HIGH 8.8) — Koha's reports/catalogue_stats.pl builds dynamic SQL in sub calculate by interpolating the user-controlled Line and Column request parameters directly into identifier positions of the query (SELECT DISTINCTROW, GROUP BY, ORDER BY) with no whitelist validation.nvd · 2026-08-04
- [NVD] CVE-2026-70369 (HIGH 8.8) — Koha's reports/acquisitions_stats.pl builds its per-cell statistics query in sub calculate by interpolating the user-controlled Filter request parameters directly into WHERE fragments covering aqbasket.closedate, aqorders.datereceived, aqbooksellers.name, items.homebranch, items.nvd · 2026-08-04
- Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Accessthehackernews · 2026-08-04
- N-able security advisory (AV26-769)cccs_ca · 2026-08-04
- Dark Web Market: Vortex Marketsocradar_blog · 2026-08-04
- The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Softwareunit42 · 2026-08-04
- QuickFox Supply Chain Attack Used to Deploy FDMTP Implantfortinet_research · 2026-08-04
- [qilin] WD Masonry & Concrete posted to leak siteransomware_live · 2026-08-04
- [akira] University SprinklerSystems posted to leak siteransomware_live · 2026-08-04
- Almost Half of Malware Samples Communicate Direct to IPunit42 · 2026-08-04
- Reasoning-Driven Full Repository Code Security with Orca’s Code Security Auditororca_security · 2026-08-04
- [Orova] Tat Fung Textile Co., Ltd. posted to leak siteransomware_live · 2026-08-04
- [Orova] Integrated Site Management posted to leak siteransomware_live · 2026-08-04
- [Orova] Conceptual Designs, Inc. posted to leak siteransomware_live · 2026-08-04
- [Orova] JK Capital Management Limited posted to leak siteransomware_live · 2026-08-04
- [Orova] Global Friction Products, Inc posted to leak siteransomware_live · 2026-08-04