THREAT OPS › Threat News
Threat Intelligence News
11896 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [Orova] Tat Fung Textile Co., Ltd. posted to leak siteransomware_live · 2026-08-04
- [Orova] Integrated Site Management posted to leak siteransomware_live · 2026-08-04
- [Orova] Conceptual Designs, Inc. posted to leak siteransomware_live · 2026-08-04
- [Orova] JK Capital Management Limited posted to leak siteransomware_live · 2026-08-04
- [Orova] Global Friction Products, Inc posted to leak siteransomware_live · 2026-08-04
- Travelers targeted when logging into hotel Wi-Fi networksmalwarebytes_blog · 2026-08-04
- How legitimate cloud platforms enable phishers to bypass MFAsecurelist · 2026-08-04
- Thermo Fisher Applied Biosystems Genetic Analyzerscisa_advisories · 2026-08-04
- CISA Adds Three Known Exploited Vulnerabilities to Catalogcisa_advisories · 2026-08-04
- Acrisure KARR BT and DR-100cisa_advisories · 2026-08-04
- Online backlash ends in Google rolling back Google Earth AI tool after a daymalwarebytes_blog · 2026-08-04
- When Vibe Hacking Turns AI into the Junior Hacker Every Adversary Always Wantedthehackernews · 2026-08-04
- [NVD] CVE-2026-10050 (CRITICAL 9.1) — In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. This was done because the initial specification for HTTP did not specify explicitly a charset, and it was assumed to be ISO-8859-1 for historical reasons. If tnvd · 2026-08-04
- Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agentthehackernews · 2026-08-04
- New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Rootthehackernews · 2026-08-04
- Some Claude Chats Are Searchable on Googleschneier · 2026-08-04
- “Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AItalos · 2026-08-04
- Why Was Telegram Removed From the App Store?socradar_blog · 2026-08-04
- [NVD] CVE-2026-64564 (CRITICAL 9.8) — In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the ASCONF chunk is processed against in asconf->transport (== chunk->transport, set once in sctp_rcv(nvd · 2026-08-04
- [NVD] CVE-2026-64563 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: rhashtable: clear stale iter->p on table restart rhashtable_walk_start_check() has two restart paths when resuming a walk. When iter->walker.tbl is valid, it re-validates iter->p against the table and sets iternvd · 2026-08-04
- [NVD] CVE-2026-64562 (HIGH 8.8) — In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Hide shadow VMCS right after VMCLEAR free_nested() frees the shadow VMCS while vmcs01 still points to it. But because it is asynchronous with respect to loaded_vmcs_clear(), the vCPU might migrate benvd · 2026-08-04
- [NVD] CVE-2026-64561 (HIGH 8.8) — In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available Check for a "stale" page fault, i.e. for an invalid and/or obsolete root, after making MMU pages available for the shadow MMU. If renvd · 2026-08-04
- CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromisesthehackernews · 2026-08-04
- WhatsApp account takeover scam asks you to “vote for my friend”malwarebytes_blog · 2026-08-04
- [aurora] GILDE Handwerk Macrander GmbH & Co. KG posted to leak siteransomware_live · 2026-08-04
- [NVD] CVE-2026-16881 — A code injection vulnerability exists in the LINE Android app prior to version 26.7.2. The profile rendering component does not adequately validate or sandbox externally supplied script content embedded in profile templates. As a result, an attacker who is able to place craftnvd · 2026-08-04
- [aurora] US Installation Group, Inc. posted to leak siteransomware_live · 2026-08-04
- Re: Some Changes to GNOME Security Trackingoss_sec · 2026-08-04
- [incransom] pushidrosal.id posted to leak siteransomware_live · 2026-08-04
- [incransom] lccgroup.com posted to leak siteransomware_live · 2026-08-04
- [incransom] https://geleximco.vn/ posted to leak siteransomware_live · 2026-08-04
- Re: Bouncy Castle 1.85 release fixes 32 CVEsoss_sec · 2026-08-04
- [incransom] clintonhealthaccess.org posted to leak siteransomware_live · 2026-08-04
- Bouncy Castle 1.85 release fixes 32 CVEsoss_sec · 2026-08-04
- SUSE Linux Kernel Multiple Vulnerabilitieshkcert · 2026-08-04
- [incransom] Oleoductos del Valle posted to leak siteransomware_live · 2026-08-04
- Re: Some Changes to GNOME Security Trackingoss_sec · 2026-08-04
- [CISA KEV] CVE-2026-34486 — Apache Tomcat: Apache Tomcat Missing Encryption of Sensitive Data Vulnerabilitycisa_kev · 2026-08-04
- [CISA KEV] CVE-2026-9198 — IBM Langflow: IBM Langflow Code Injection Vulnerabilitycisa_kev · 2026-08-04
- Agents vs. agents: how we triage HackerOne reports for $2 each, 85% as well as a humanelastic_security · 2026-08-04
- [NVD] CVE-2026-69249 — python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In versions 42.0.0 through 48.0.0, when resolving invalid certificate chains that include duplicate copies of self-signed certificates, the processing recursively invokenvd · 2026-08-03
- [NVD] CVE-2026-10849 (HIGH 8.2) — The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response from the update server into a heap buffer in response_json_cb() (subsys/mgmt/hawkbit/hawkbit.c). The buffer is sized to hold the received body bytes but reserves no space for a tenvd · 2026-08-03
- “Adult TikTok” searches lead to scamsmalwarebytes_blog · 2026-08-03
- OSSN-0104: Ironic-Python-Agent may fallback to mDNS unexpectedlyoss_sec · 2026-08-03
- [GHSA] GHSA-m2h6-j472-rp4c (medium) — python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtreesgithub_advisories · 2026-08-03
- [GHSA] GHSA-jwv3-5hgf-82ww (high) — python-cryptography: Duplicate self-signed intermediates can cause exponential path-buildinggithub_advisories · 2026-08-03
- [GHSA] GHSA-g6cj-pr64-35w5 (high) — cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timinggithub_advisories · 2026-08-03
- The AI Act kicks into action, forces companies to be clear about AI chatbotsmalwarebytes_blog · 2026-08-03
- [GHSA] GHSA-v5mv-p594-2x33 (high) — Guzzle: Noncanonical host can bypass host-based checksgithub_advisories · 2026-08-03
- [GHSA] GHSA-f7vp-7xgx-4w4r (medium) — Guzzle: Noncanonical cookie domain keeps subdomain scopegithub_advisories · 2026-08-03
- [GHSA] GHSA-cq5v-8q36-5273 (high) — AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)github_advisories · 2026-08-03
- Californians can tell data brokers to DROP their informationmalwarebytes_blog · 2026-08-03
- [GHSA] GHSA-mfx4-hv73-q22v (medium) — AIOHTTP: HTTP request smuggling via WebSocket upgradegithub_advisories · 2026-08-03
- [GHSA] GHSA-mq44-7p77-q5h7 (medium) — AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflategithub_advisories · 2026-08-03
- [GHSA] GHSA-v8fg-2rw7-q452 (critical) — Sequelize: SQL Injection (Oracle DB)github_advisories · 2026-08-03
- [GHSA] GHSA-8j4g-w8fx-2239 (medium) — Hono: ReDoS in CORS middleware via Access-Control-Request-Headersgithub_advisories · 2026-08-03
- [GHSA] GHSA-p538-c434-8v24 (medium) — GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.countgithub_advisories · 2026-08-03
- [GHSA] GHSA-539m-9xh6-q6rr (medium) — GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()github_advisories · 2026-08-03
- [GHSA] GHSA-3f7w-8rr8-f37f (high) — GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file readgithub_advisories · 2026-08-03
- [GHSA] GHSA-mwp4-54f8-5fhr (high) — ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypassgithub_advisories · 2026-08-03
- [GHSA] GHSA-4xrf-jv44-h6hh (medium) — ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checksgithub_advisories · 2026-08-03
- CVE-2026-68981: Apache NiFi: Uncontrolled Resource Consumption through Decompression of HTTP Requestsoss_sec · 2026-08-03
- CVE-2026-68980: Apache NiFi: Authorization Bypass for Parameter Context Asset Deletionoss_sec · 2026-08-03
- [qilin] Universitatea De Vest Vasile Goldi Din Arad posted to leak siteransomware_live · 2026-08-03
- CVE-2026-62354: Apache NiFi: Incorrect Authorization for Parameter Context Validation Requestsoss_sec · 2026-08-03
- [GHSA] GHSA-22jq-vg5j-6vgg (medium) — ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checksgithub_advisories · 2026-08-03
- CVE-2026-68979: Apache NiFi: Missing Authorization for Components Referenced by Parameter Context Updatesoss_sec · 2026-08-03
- Re: Some Changes to GNOME Security Trackingoss_sec · 2026-08-03
- Between Two Nerds: Hackers vs the stateriskybiz_news · 2026-08-03
- Inside the Cybercrime Ecosystemduo_decipher · 2026-08-03
- [GHSA] GHSA-m8rv-5g2x-5cg5 (medium) — undici vulnerable to CRLF Injection via blob-like body 'type' propertygithub_advisories · 2026-08-03
- [GHSA] GHSA-jr45-8vmc-qm54 (medium) — undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directivesgithub_advisories · 2026-08-03
- [GHSA] GHSA-v3r7-h72x-cjcm (medium) — undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fieldsgithub_advisories · 2026-08-03
- [GHSA] GHSA-8xcm-r25x-g524 (medium) — undici vulnerable to downstream response desynchronization via retry interceptorgithub_advisories · 2026-08-03
- [GHSA] GHSA-4cwx-7wf7-3272 (high) — undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directivesgithub_advisories · 2026-08-03
- [GHSA] GHSA-7p8r-x3mc-p8w7 (high) — fast-uri vulnerable to host confusion via backslash authority introducergithub_advisories · 2026-08-03
- [GHSA] GHSA-2m8v-j782-fhvr (high) — Socket.IO: Zero-attachment Memory Exhaustiongithub_advisories · 2026-08-03
- Targeted Attack on Government Entities in the Middle East | Part 2zscaler_threatlabz · 2026-08-03
- 18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Usersthehackernews · 2026-08-03
- Re: RefluXFS: LPE in the Linux kernel via XFS reflink race (CVE-2026-64600)oss_sec · 2026-08-03
- Re: Some Changes to GNOME Security Trackingoss_sec · 2026-08-03
- [safepay] pradotuylaw.com posted to leak siteransomware_live · 2026-08-03
- [safepay] naskdoorinc.com posted to leak siteransomware_live · 2026-08-03
- [safepay] new-point.it posted to leak siteransomware_live · 2026-08-03
- [safepay] simonrack.com posted to leak siteransomware_live · 2026-08-03
- [safepay] hanan-hov.co.il posted to leak siteransomware_live · 2026-08-03
- [anubis] BLACKBURN'S posted to leak siteransomware_live · 2026-08-03
- [anubis] Cameron Regional Medical Center posted to leak siteransomware_live · 2026-08-03
- Flashpoint EASM: Industry-Leading Vulnerability Intelligence, Mapped to Your Internet-Facing Assetsflashpoint · 2026-08-03
- [safepay] azn.co.jp posted to leak siteransomware_live · 2026-08-03
- [safepay] southshorerecycling.com posted to leak siteransomware_live · 2026-08-03
- [safepay] cpu-ag.com posted to leak siteransomware_live · 2026-08-03
- [safepay] multiaqua.com posted to leak siteransomware_live · 2026-08-03
- [anubis] Winn-Dixie posted to leak siteransomware_live · 2026-08-03
- [GHSA] GHSA-fxqj-rqcc-2cmp (medium) — PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unsetgithub_advisories · 2026-08-03
- Re: Some Changes to GNOME Security Trackingoss_sec · 2026-08-03
- More on the OpenAI Agent’s Attack on Hugging Faceschneier · 2026-08-03
- [GHSA] GHSA-rgw5-rvv9-x895 (high) — brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigationgithub_advisories · 2026-08-03
- Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accountsthehackernews · 2026-08-03
- [GHSA] GHSA-jj27-h5hq-8x99 (high) — Angular i18n: Cross-Site Scripting (XSS) via event-handler attributesgithub_advisories · 2026-08-03