THREAT OPS › Threat News
Threat Intelligence News
11941 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- Re: RefluXFS: LPE in the Linux kernel via XFS reflink race (CVE-2026-64600)oss_sec · 2026-07-31
- 6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026thehackernews · 2026-07-31
- Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacksthehackernews · 2026-07-31
- [NVD] CVE-2026-16843 (HIGH 7.2) — Some Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary comnvd · 2026-07-31
- CVE-2026-62391: Apache Kyuubi: kyuubi.session.local.dir.allow.list bypass via unprefixed Spark file-conf aliasesoss_sec · 2026-07-31
- Facial Recognition at Madison Square Gardenschneier · 2026-07-31
- Fake Flash Player installs AtlasRATmalwarebytes_blog · 2026-07-31
- [cmdorganization] Stewart Belland & Associates Inc. posted to leak siteransomware_live · 2026-07-31
- [NVD] CVE-2026-15722 (HIGH 7.5) — A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. A remote unauthenticated atnvd · 2026-07-31
- [NVD] CVE-2026-11770 (HIGH 7.5) — A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and nvd · 2026-07-31
- Network Anomaly Detection in KATAsecurelist · 2026-07-31
- The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Versionunit42 · 2026-07-31
- [NVD] CVE-2026-18218 (MEDIUM 4.2) — A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attempts to revoke tokens for a specific application (client) using a "not-before" policy, the revocation may be silently ignored if the overall security realm alreadnvd · 2026-07-31
- [NVD] CVE-2026-18215 (MEDIUM 6.8) — Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization (tenant). A flaw was discovered where this restriction is ignored when using the token exchange feature. This means an attacker with a valid Microsoft token frnvd · 2026-07-31
- [NVD] CVE-2026-18214 (MEDIUM 6.8) — Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Workspace domains. A flaw was found where the token exchange feature, which allows swapping a Google token for a Keycloak token, does not check these domain restrinvd · 2026-07-31
- [NVD] CVE-2026-18209 (LOW 3.4) — A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentication flows. The issue occurs because the security check designed to prevent HTTP parameter pollution only inspects the query portion of a redirect URL and ignores the frnvd · 2026-07-31
- [NVD] CVE-2026-18203 (MEDIUM 6.5) — A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution. When a group policy is set to extend permissions to child groups, the system incorrectly uses a simple text-based prefix check to verify group membership. This allows a nvd · 2026-07-31
- [NVD] CVE-2026-16105 (MEDIUM 4.9) — A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certain name-based endpoints in the admin REST API do not properly enforce authorization checks when managing composite roles. This allows a delegated administrator with manage-realm pernvd · 2026-07-31
- Defining Community Open Source Is Harder Than It Lookssonatype · 2026-07-31
- Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizationsthehackernews · 2026-07-31
- [NVD] CVE-2026-63223 (CRITICAL 9.8) — CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename extension, allowing a remote attacker to upload executable content when an application preserves the client filenamenvd · 2026-07-31
- [NVD] CVE-2026-56671 (HIGH 7.5) — ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, get_model_preview in app/model_manager.py joins an unrestricted filename route capture to a selected model directory without a containment check, allowing an unauthenticated rnvd · 2026-07-31
- Risky Bulletin: Crime Stoppers puts bounty on INC ransomware groupriskybiz_news · 2026-07-31
- No Hacker Required: How the World's First Autonomous AI Breach Makes the Case for Deceptionzscaler_threatlabz · 2026-07-31
- [NVD] CVE-2026-55499 (MEDIUM 4.3) — Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, a single-file share event-stream subscription resolves the share root to the owner’s parent folder and subscribes to that folder topic, allowing an authenticated share recipient to receive names, pathnvd · 2026-07-31
- [qilin] Hawaii Family Dental posted to leak siteransomware_live · 2026-07-31
- [NVD] CVE-2026-14541 (HIGH 7.5) — An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mcp-toolbox version 1.4.0. When a Google authService is initialized with mcpEnabled: true but lacks an explicitly defined audience or clientId, the ValidateMCPAutnvd · 2026-07-31
- Re: Some Changes to GNOME Security Trackingoss_sec · 2026-07-31
- [NVD] CVE-2026-14540 (MEDIUM 6.1) — A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-toolbox versions 0.3.0 through 1.4.0. While the toolbox implements baseline input sanitization for user-controlled parameters, the underlying HTTP client (internnvd · 2026-07-31
- [NVD] CVE-2026-14539 (HIGH 7.5) — An allocation of resources without limits vulnerability in the HTTP handler component of Google mcp-toolbox versions up to and including 1.4.0 allows an unauthenticated attacker to cause a denial of service (DoS). The /mcp endpoint handler reads incoming payloads directly into synvd · 2026-07-31
- [NVD] CVE-2026-14538 (HIGH 7.7) — An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Google mcp-toolbox versions 0.16.1 through 1.4.0 allows an authenticated attacker to bypass allowedDatasets validation checks. The toolbox relies on the BigQuery drynvd · 2026-07-31
- [NVD] CVE-2026-14537 (CRITICAL 9.8) — Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0 allows an unauthenticated attacker to invoke tools protected by the scopeRequired feature via sending tool invocation requests through legacy HTTP endpoints whnvd · 2026-07-31
- Exploring the Hugging Face Breach: mapping AI agent tactics to Elastic Defendelastic_security · 2026-07-31
- Alert Zero: AI-driven alert triage and attack investigation for the agentic SOCelastic_security · 2026-07-31
- What's new in Elastic Defend: 800+ vulnerable driver rules, automated troubleshooting, and ARM supportelastic_security · 2026-07-31
- Elastic goes all-in on Hacker Summer Camp at Black Hat and DEF CON in Las Vegaselastic_security · 2026-07-31
- PHP 30 July 2026 security releasesoss_sec · 2026-07-30
- [NVD] CVE-2026-62246 (HIGH 8.5) — Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane datastore schema, database user, and etcd key prefix from a lossy namespace-and-name normalization in GetDefaultDatastoreSchema() and GetDefaultDatastoreUsername()nvd · 2026-07-30
- Some Changes to GNOME Security Trackingoss_sec · 2026-07-30
- [genesis] Boyum IT Solutions (HOT!) posted to leak siteransomware_live · 2026-07-30
- [genesis] C.A. Walker Construction posted to leak siteransomware_live · 2026-07-30
- What’s New in GovCloud: July 2026 Zscaler Product Updateszscaler_threatlabz · 2026-07-30
- [GHSA] GHSA-hf3j-86p7-mfw8 (critical) — AWS Amplify Studio UI Component Properties Has an Input Validation Issuegithub_advisories · 2026-07-30
- [qilin] Audio Precision, Inc posted to leak siteransomware_live · 2026-07-30
- What water utilities need to know about cybersecurity compliancetenable · 2026-07-30
- [Gammax] AguAseo posted to leak siteransomware_live · 2026-07-30
- OpenSSF Newsletter – July 2026openssf_blog · 2026-07-30
- Re: 33 Vulnerabilities in cJSONoss_sec · 2026-07-30
- o6 Automation open62541: multiple CISA-coordinated OPC UA vulnerabilitiesoss_sec · 2026-07-30
- [securotrop] MAG USA Inc posted to leak siteransomware_live · 2026-07-30
- Wordfence Intelligence Weekly WordPress Vulnerability Report (July 20, 2026 to July 26, 2026)wordfence · 2026-07-30
- Gladinet security advisory (AV26-765)cccs_ca · 2026-07-30
- [GHSA] GHSA-xr9x-r78c-5hrm (critical) — Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processinggithub_advisories · 2026-07-30
- DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malwarethehackernews · 2026-07-30
- PHP Group security advisory (AV26-764)cccs_ca · 2026-07-30
- You were onto something with “It’s the Climb,” Mileytalos · 2026-07-30
- CVE-2026-66756: Apache Tika: unpack endpoint in tika-server allows configuration with unsecureFeatures=falseoss_sec · 2026-07-30
- CVE-2026-66755: Apache Tika: Arbitrary Local File Read in ISArchiveParseross_sec · 2026-07-30
- VMware security advisory (AV26-763)cccs_ca · 2026-07-30
- 33 Vulnerabilities in cJSONoss_sec · 2026-07-30
- Read This Before You Buy That TV Streaming Stickkrebs · 2026-07-30
- [GHSA] GHSA-4mrv-5p47-p938 (low) — MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosuregithub_advisories · 2026-07-30
- [incransom] PARTNERED HEALTH GROUP posted to leak siteransomware_live · 2026-07-30
- [GHSA] GHSA-cg4g-m8jx-vjv2 (high) — dssrf has an SSRF bypass with remove_at_symbol_in_stringgithub_advisories · 2026-07-30
- American Being Prosecuted for Wiping His Phone Before Handing It Over to Border Officialsschneier · 2026-07-30
- Incident Response Tools: Top 12 Platforms Comparedorca_security · 2026-07-30
- KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Railsrapid7 · 2026-07-30
- Canada’s Bill C-8 is here: Why the 72-hour reporting rule will redefine critical infrastructure securitytenable · 2026-07-30
- Malwarebytes for Windows, now available on the Microsoft Storemalwarebytes_blog · 2026-07-30
- What’s new in Microsoft Security: July 2026msstic · 2026-07-30
- AI Threat Detection: A Complete Guide to Modern Securityorca_security · 2026-07-30
- ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Storiesthehackernews · 2026-07-30
- Data Risk Management: Essential Strategies & Solutionsorca_security · 2026-07-30
- [NVD] CVE-2026-6540 (HIGH 7.5) — Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform URL path normalization. As a result, HTTP requests using path-traversal segments, encoded slashes, or repeated slashes are not correctly evaluated by Prefix path nvd · 2026-07-30
- [NVD] CVE-2026-41187 (MEDIUM 6.5) — Calico's apiserver wraps tier-scoped resources so that every operation runs through AuthorizeTierOperation, but the Delete override on NetworkPolicy, GlobalNetworkPolicy, and their staged variants is not invoked for DeleteCollection requests. A user holding the deletecollection vnvd · 2026-07-30
- [NVD] CVE-2026-41186 (HIGH 7.5) — When Calico's shared debug server is enabled (disabled by default), the Calico kube-controllers and Goldmane components bind their Go pprof debug listener to 0.0.0.0 without authentication. Any pod with network reachability to the listener can retrieve the process heap, goroutinenvd · 2026-07-30
- Rapid7 named a Leader in the IDC MarketScape: Worldwide MDR Service for Midmarket 2026 Vendor Assessmentrapid7 · 2026-07-30
- [Control Systems] Phoenix Contact security advisory (AV26-762)cccs_ca · 2026-07-30
- [GHSA] GHSA-c9hr-64h3-gxpc (high) — Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidationgithub_advisories · 2026-07-30
- [GHSA] GHSA-pgwh-4jj4-qm8v (high) — Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)github_advisories · 2026-07-30
- [GHSA] GHSA-jx74-cqjv-2c67 (critical) — Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltrationgithub_advisories · 2026-07-30
- [GHSA] GHSA-qq9q-xgm3-xv9g (high) — Flyto2 Core: LLM/API keys leak to an attacker-controlled base_urlgithub_advisories · 2026-07-30
- [GHSA] GHSA-hr7p-wg7r-hg9m (high) — Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylistedgithub_advisories · 2026-07-30
- [GHSA] GHSA-2956-977x-2w3r (critical) — Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)github_advisories · 2026-07-30
- [GHSA] GHSA-4jc5-g844-4x33 (medium) — linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirectgithub_advisories · 2026-07-30
- [GHSA] GHSA-5p9g-j988-pcwv (high) — MCP Ruby SDK: Ruby SSE Session Poisoninggithub_advisories · 2026-07-30
- [GHSA] GHSA-h669-8m4g-r2hc (high) — MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransportgithub_advisories · 2026-07-30
- [GHSA] GHSA-52jp-gj8w-j6xh (medium) — MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize floodgithub_advisories · 2026-07-30
- [GHSA] GHSA-7683-3w9x-ch42 (medium) — MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)github_advisories · 2026-07-30
- [GHSA] GHSA-rjr6-rcgv-9m7m (medium) — MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protectiongithub_advisories · 2026-07-30
- WebPros security advisory (AV26-761)cccs_ca · 2026-07-30
- [GHSA] GHSA-xc5w-4v5w-7x65 (medium) — OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Checkgithub_advisories · 2026-07-30
- Metasploit Framework 6.5 Releasedrapid7 · 2026-07-30
- [GHSA] GHSA-jm28-2wcr-qf3h (medium) — OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Outputgithub_advisories · 2026-07-30
- [GHSA] GHSA-xpxj-f2fm-rqch (high) — OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)github_advisories · 2026-07-30
- CVE-2026-60075: Date::Manip versions through 6.99 for Perl allow CPU exhaustion via quadratic backtracking in the unanchored time substitution in _parse_timeoss_sec · 2026-07-30
- CVE-2026-60074: Date::Manip versions through 6.99 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric range tests in checkoss_sec · 2026-07-30
- [cmdorganization] Contact Group posted to leak siteransomware_live · 2026-07-30
- Adobe security advisory (AV26-760)cccs_ca · 2026-07-30
- The July 2026 Apple Security Update Reviewzdi_blog · 2026-07-30