THREAT OPS › Threat News
Threat Intelligence News
11919 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [thegentlemen] Bater posted to leak siteransomware_live · 2026-07-31
- [thegentlemen] Precision Concrete Pumping posted to leak siteransomware_live · 2026-07-31
- [thegentlemen] Clear Vision Signs posted to leak siteransomware_live · 2026-07-31
- [thegentlemen] Orsima posted to leak siteransomware_live · 2026-07-31
- Re: Some Changes to GNOME Security Trackingoss_sec · 2026-07-31
- [thegentlemen] The Municipal Chamber of Serra posted to leak siteransomware_live · 2026-07-31
- [thegentlemen] Efrata College of Education posted to leak siteransomware_live · 2026-07-31
- [thegentlemen] Amicell posted to leak siteransomware_live · 2026-07-31
- [thegentlemen] Paula Fish posted to leak siteransomware_live · 2026-07-31
- [thegentlemen] Known posted to leak siteransomware_live · 2026-07-31
- [thegentlemen] Peachtree Group posted to leak siteransomware_live · 2026-07-31
- [thegentlemen] Municipalidad de San Luis posted to leak siteransomware_live · 2026-07-31
- [thegentlemen] World Wide Fittings posted to leak siteransomware_live · 2026-07-31
- [thegentlemen] Chemco Systems posted to leak siteransomware_live · 2026-07-31
- [thegentlemen] Total Auto Business Solutions posted to leak siteransomware_live · 2026-07-31
- [thegentlemen] Okovolt Solartechnik posted to leak siteransomware_live · 2026-07-31
- [thegentlemen] Pertamina posted to leak siteransomware_live · 2026-07-31
- Re: Some Changes to GNOME Security Trackingoss_sec · 2026-07-31
- Re: Some Changes to GNOME Security Trackingoss_sec · 2026-07-31
- Re: Some Changes to GNOME Security Trackingoss_sec · 2026-07-31
- [GHSA] GHSA-mj3g-7xcc-x4vh (high) — @phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive Property Merginggithub_advisories · 2026-07-31
- [GHSA] GHSA-r2v3-8gwf-7ghm (critical) — vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest APIgithub_advisories · 2026-07-31
- Anthropic’s Opus 5 Is Better at Resisting Prompt Injectionschneier · 2026-07-31
- [GHSA] GHSA-g956-2f74-rmv7 (high) — hashi-vault-js has a path traversal and query parameter injectiongithub_advisories · 2026-07-31
- [GHSA] GHSA-5846-7qm3-r52j (high) — dssrf: any users using 1.1.1.1 DNS is impacted by SSRFgithub_advisories · 2026-07-31
- [GHSA] GHSA-jr6p-8pjj-mfx6 (medium) — Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation)github_advisories · 2026-07-31
- [GHSA] GHSA-68cj-mvg9-rgm2 (medium) — Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requestsgithub_advisories · 2026-07-31
- [GHSA] GHSA-ff84-5f28-78qj (medium) — re2: Out-of-bounds heap read in `exec`/`test`/`match` via attacker-influenced `lastIndex` on a non-ASCII subject → uncatchable process crash (DoS)github_advisories · 2026-07-31
- [GHSA] GHSA-6hxr-mr5r-9836 (medium) — re2: Global `String.prototype.match` with an empty-matchable pattern never advances → infinite loop with unbounded native memory growth (DoS)github_advisories · 2026-07-31
- [GHSA] GHSA-x83g-979r-f5fh (medium) — Sylius Mollie Plugin has unauthenticated IDOR that leaks order token and customer PIIgithub_advisories · 2026-07-31
- [GHSA] GHSA-rc52-c4hv-w89p (high) — Sylius Mollie Plugin vulnerable to payment status forgery via the payment webhookgithub_advisories · 2026-07-31
- [GHSA] GHSA-93wv-jw9v-4972 (high) — Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)github_advisories · 2026-07-31
- [GHSA] GHSA-qvv7-cg9c-w4x3 (high) — Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE modegithub_advisories · 2026-07-31
- Data Security Scanning Performance: Why Full Coverage Doesn't Mean Slow Scansvaronis_blog · 2026-07-31
- [GHSA] GHSA-fg7f-2386-8897 (high) — Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regexgithub_advisories · 2026-07-31
- [GHSA] GHSA-6hm5-jgcp-p838 (high) — Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)github_advisories · 2026-07-31
- [GHSA] GHSA-xh95-f55m-82fw (high) — Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)github_advisories · 2026-07-31
- [GHSA] GHSA-g2r8-wvmj-jf5w (medium) — `nx graph` dev server permissive CORS policygithub_advisories · 2026-07-31
- [GHSA] GHSA-88fw-v6x4-3f58 (high) — Spring Data: Unbounded property-path cache keyed by externally-supplied path stringgithub_advisories · 2026-07-31
- HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firmthehackernews · 2026-07-31
- [GHSA] GHSA-22p9-r2f5-22mf (medium) — OnionShare follows symlinks in shared directories, allowing unintended disclosure of local filesgithub_advisories · 2026-07-31
- [GHSA] GHSA-v833-3823-cmhp (medium) — OnionShare Receive mode writes uploaded files even when file uploads are disabledgithub_advisories · 2026-07-31
- [GHSA] GHSA-ghrq-5wpp-hxx5 (high) — Wings: Maliciously crafted packet during SFTP connection handshake causes denial of servicegithub_advisories · 2026-07-31
- [NVD] CVE-2026-17566 (CRITICAL 9.9) — pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to psql via --command. To stop an attacker from breaking out of the (...) wrapper, create_import_export_job() nvd · 2026-07-31
- [NVD] CVE-2026-17351 (CRITICAL 9.0) — The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TRANSACTION READ ONLY wrapper. sqlparse's strnvd · 2026-07-31
- [NVD] CVE-2026-17349 (CRITICAL 9.6) — /misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones that server via Server.clone(), which copies every column from the source row, including user_id, shared, shared_username, and the stnvd · 2026-07-31
- [NVD] CVE-2026-17347 (HIGH 7.5) — The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that returns a per-user encryption key, with %u in the configured string replaced by the current user's name. The previous implementation substituted the username dinvd · 2026-07-31
- [NVD] CVE-2026-17346 (HIGH 8.8) — The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatindex templates to it, but missed several sinks that had been placed in test_sql_string_literal_lint.py's ALLOWLIST on the incorrect assumption that schema, tablenvd · 2026-07-31
- Fake Fortnite rewards are stealing players’ accountsmalwarebytes_blog · 2026-07-31
- [GHSA] GHSA-pfvc-3p5h-x7h6 (critical) — Wings exposes node configuration secrets through egg configuration-file templatinggithub_advisories · 2026-07-31
- [GHSA] GHSA-q6hh-gp44-4hcm (medium) — Wings: Maliciously or erroneously created parsed config files can cause wings process to OOMgithub_advisories · 2026-07-31
- [GHSA] GHSA-p7w7-4929-vpj5 (high) — `@dynatrace-oss/dynatrace-mcp-server` has Unauthenticated HTTP MCP Tool Invocationgithub_advisories · 2026-07-31
- [GHSA] GHSA-xrmj-5g4g-8987 (medium) — @dynatrace-oss/dynatrace-mcp-server has a workflow template injection via create_workflow_for_notificationgithub_advisories · 2026-07-31
- [GHSA] GHSA-pqh8-p93p-2rx7 (medium) — @dynatrace-oss/dynatrace-mcp-server has a DQL injection via parameters not documented as DQLgithub_advisories · 2026-07-31
- [dragonforce] Lamont Pridmore posted to leak siteransomware_live · 2026-07-31
- Re: Some Changes to GNOME Security Trackingoss_sec · 2026-07-31
- [genesis] **** posted to leak siteransomware_live · 2026-07-31
- Re: Some Changes to GNOME Security Trackingoss_sec · 2026-07-31
- Re: Some Changes to GNOME Security Trackingoss_sec · 2026-07-31
- [NVD] CVE-2026-18446 (HIGH 7.5) — fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a reference that uses a backslash based introducer in place of it (backslash backslash, forward slash backslash, or backslash forward slash) is parsed with no authoritnvd · 2026-07-31
- Re: Some Changes to GNOME Security Trackingoss_sec · 2026-07-31
- [interlock] Gardiner Family Chiropractic posted to leak siteransomware_live · 2026-07-31
- Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxiesthehackernews · 2026-07-31
- Google security advisory (AV26-768)cccs_ca · 2026-07-31
- ESET tracks rise in malicious AI skills and adaptable malwarebleepingcomputer · 2026-07-31
- [dragonforce] RUS Industrial posted to leak siteransomware_live · 2026-07-31
- [dragonforce] www.mbmlawsc.com posted to leak siteransomware_live · 2026-07-31
- Rails security advisory (AV26-767)cccs_ca · 2026-07-31
- SolarWinds security advisory (AV26-766)cccs_ca · 2026-07-31
- [clop] BLUEVISTALLC.COM posted to leak siteransomware_live · 2026-07-31
- Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combinedthehackernews · 2026-07-31
- [Booba Project] Betz Industries posted to leak siteransomware_live · 2026-07-31
- Security Governance: Essential Framework Guideorca_security · 2026-07-31
- SDLC: Core Phases and Best Practices Explainedorca_security · 2026-07-31
- AI-BOM: Understanding AI Bill of Materials Essentialsorca_security · 2026-07-31
- [qilin] The Dcoop posted to leak siteransomware_live · 2026-07-31
- Minnesota Water Cyberattack: FBI and EPA Warn of PLC Attacks Across Seven Statessocradar_blog · 2026-07-31
- Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flawthehackernews · 2026-07-31
- Rapid7 at Black Hat USA 2026: See preemptive security in actionrapid7 · 2026-07-31
- Top 10 MSSPs in Belgium (2026)socradar_blog · 2026-07-31
- Re: 33 Vulnerabilities in cJSONoss_sec · 2026-07-31
- Re: RefluXFS: LPE in the Linux kernel via XFS reflink race (CVE-2026-64600)oss_sec · 2026-07-31
- 6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026thehackernews · 2026-07-31
- Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacksthehackernews · 2026-07-31
- [NVD] CVE-2026-16843 (HIGH 7.2) — Some Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary comnvd · 2026-07-31
- CVE-2026-62391: Apache Kyuubi: kyuubi.session.local.dir.allow.list bypass via unprefixed Spark file-conf aliasesoss_sec · 2026-07-31
- Facial Recognition at Madison Square Gardenschneier · 2026-07-31
- Fake Flash Player installs AtlasRATmalwarebytes_blog · 2026-07-31
- [cmdorganization] Stewart Belland & Associates Inc. posted to leak siteransomware_live · 2026-07-31
- [NVD] CVE-2026-15722 (HIGH 7.5) — A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. A remote unauthenticated atnvd · 2026-07-31
- [NVD] CVE-2026-11770 (HIGH 7.5) — A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and nvd · 2026-07-31
- Network Anomaly Detection in KATAsecurelist · 2026-07-31
- The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Versionunit42 · 2026-07-31
- [NVD] CVE-2026-18218 (MEDIUM 4.2) — A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attempts to revoke tokens for a specific application (client) using a "not-before" policy, the revocation may be silently ignored if the overall security realm alreadnvd · 2026-07-31
- [NVD] CVE-2026-18215 (MEDIUM 6.8) — Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization (tenant). A flaw was discovered where this restriction is ignored when using the token exchange feature. This means an attacker with a valid Microsoft token frnvd · 2026-07-31
- [NVD] CVE-2026-18214 (MEDIUM 6.8) — Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Workspace domains. A flaw was found where the token exchange feature, which allows swapping a Google token for a Keycloak token, does not check these domain restrinvd · 2026-07-31
- [NVD] CVE-2026-18209 (LOW 3.4) — A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentication flows. The issue occurs because the security check designed to prevent HTTP parameter pollution only inspects the query portion of a redirect URL and ignores the frnvd · 2026-07-31
- [NVD] CVE-2026-18203 (MEDIUM 6.5) — A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution. When a group policy is set to extend permissions to child groups, the system incorrectly uses a simple text-based prefix check to verify group membership. This allows a nvd · 2026-07-31
- [NVD] CVE-2026-16105 (MEDIUM 4.9) — A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certain name-based endpoints in the admin REST API do not properly enforce authorization checks when managing composite roles. This allows a delegated administrator with manage-realm pernvd · 2026-07-31
- Defining Community Open Source Is Harder Than It Lookssonatype · 2026-07-31