THREAT OPS › Threat News
Threat Intelligence News
11964 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [Control Systems] Phoenix Contact security advisory (AV26-762)cccs_ca · 2026-07-30
- [GHSA] GHSA-c9hr-64h3-gxpc (high) — Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidationgithub_advisories · 2026-07-30
- [GHSA] GHSA-pgwh-4jj4-qm8v (high) — Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)github_advisories · 2026-07-30
- [GHSA] GHSA-jx74-cqjv-2c67 (critical) — Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltrationgithub_advisories · 2026-07-30
- [GHSA] GHSA-qq9q-xgm3-xv9g (high) — Flyto2 Core: LLM/API keys leak to an attacker-controlled base_urlgithub_advisories · 2026-07-30
- [GHSA] GHSA-hr7p-wg7r-hg9m (high) — Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylistedgithub_advisories · 2026-07-30
- [GHSA] GHSA-2956-977x-2w3r (critical) — Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)github_advisories · 2026-07-30
- [GHSA] GHSA-4jc5-g844-4x33 (medium) — linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirectgithub_advisories · 2026-07-30
- [GHSA] GHSA-5p9g-j988-pcwv (high) — MCP Ruby SDK: Ruby SSE Session Poisoninggithub_advisories · 2026-07-30
- [GHSA] GHSA-h669-8m4g-r2hc (high) — MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransportgithub_advisories · 2026-07-30
- [GHSA] GHSA-52jp-gj8w-j6xh (medium) — MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize floodgithub_advisories · 2026-07-30
- [GHSA] GHSA-7683-3w9x-ch42 (medium) — MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)github_advisories · 2026-07-30
- [GHSA] GHSA-rjr6-rcgv-9m7m (medium) — MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protectiongithub_advisories · 2026-07-30
- WebPros security advisory (AV26-761)cccs_ca · 2026-07-30
- [GHSA] GHSA-xc5w-4v5w-7x65 (medium) — OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Checkgithub_advisories · 2026-07-30
- Metasploit Framework 6.5 Releasedrapid7 · 2026-07-30
- [GHSA] GHSA-jm28-2wcr-qf3h (medium) — OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Outputgithub_advisories · 2026-07-30
- [GHSA] GHSA-xpxj-f2fm-rqch (high) — OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)github_advisories · 2026-07-30
- CVE-2026-60075: Date::Manip versions through 6.99 for Perl allow CPU exhaustion via quadratic backtracking in the unanchored time substitution in _parse_timeoss_sec · 2026-07-30
- CVE-2026-60074: Date::Manip versions through 6.99 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric range tests in checkoss_sec · 2026-07-30
- [cmdorganization] Contact Group posted to leak siteransomware_live · 2026-07-30
- Adobe security advisory (AV26-760)cccs_ca · 2026-07-30
- The July 2026 Apple Security Update Reviewzdi_blog · 2026-07-30
- Batten Down Your Packages: Mitigation Guidance for Supply Chain Compromisemandiant_gti · 2026-07-30
- Expanded Risk360 Availability Brings Foundational Risk Insights to More Zscaler Customerszscaler_threatlabz · 2026-07-30
- Hims & Hers sued over alleged health data privacy failuresmalwarebytes_blog · 2026-07-30
- CVE-2026-48910: Apache JSPWiki: Markdown parser allows XSS injection in Markdown error processingoss_sec · 2026-07-30
- CVE-2026-28814: Apache JSPWiki: Arbitrary Wiki Markup rendering due to lack of authenticationoss_sec · 2026-07-30
- CVE-2026-28813: Apache JSPWiki: JSON hijackingoss_sec · 2026-07-30
- Spring security advisory (AV26-759)cccs_ca · 2026-07-30
- CVE-2026-28812: Apache JSPWiki: UserManager does not sanity-check user database at startuposs_sec · 2026-07-30
- CVE-2026-28811: Apache JSPWiki: Error Handling Reveals Error Detailsoss_sec · 2026-07-30
- CVE-2026-22068+more: multiple vulnerabilities in Apache Traffic Server prior to 9.2.15/10.1.4oss_sec · 2026-07-30
- [SBA-ADV-20260128-04] CVE-2026-16970: DFIR-IRIS 2.4.26 and possibly others Insufficient Logout Implementationoss_sec · 2026-07-30
- [SBA-ADV-20260128-02] CVE-2026-16971 CVE-2026-18362: DFIR-IRIS 2.4.26 and possibly others Missing Brute Force Protectionoss_sec · 2026-07-30
- Adform compromised to serve crypto stealer via supply chain attackdoublepulsar · 2026-07-30
- [SBA-ADV-20260126-01] CVE-2026-16969 CVE-2026-18360 CVE-2026-18361: DFIR-IRIS 2.4.26 and possibly others Stored XSSoss_sec · 2026-07-30
- Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Databasethehackernews · 2026-07-30
- Re: Backports available - cBPF JIT spray hardeningoss_sec · 2026-07-30
- [NVD] CVE-2026-54365 (HIGH 7.5) — CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unauthenticated attackers to create arbitrary local OS user accounts by supplying a crafted base64-encoded XML string to exposed API endpoints. Attackers can send a manvd · 2026-07-30
- GitLab security advisory (AV26-758)cccs_ca · 2026-07-30
- Walking the Walk on Package Registry Sustainabilitysonatype · 2026-07-30
- Hidden prompt can make Microsoft Copilot spread itself through your Word docsmalwarebytes_blog · 2026-07-30
- [incransom] sslf.local posted to leak siteransomware_live · 2026-07-30
- What Orca is Building at Black Hat 2026orca_security · 2026-07-30
- Cisco security advisory (AV26-757)cccs_ca · 2026-07-30
- [NVD] CVE-2026-5582 (MEDIUM 4.3) — The FuseWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.24.2. This is due to missing nonce verification on the toggle_sync_status() function. This makes it possible for unauthenticated attackers to toggle the status ofnvd · 2026-07-30
- [NVD] CVE-2026-18378 (HIGH 7.6) — A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows user able to edit the CR to specify an arbitrary upload URL. When authentication.type is set to token (the default), the cluster-global Red Hat Cloud pull-secret bearer tonvd · 2026-07-30
- Open Source Software: Security Principles and Practicescisa_advisories · 2026-07-30
- CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCscisa_advisories · 2026-07-30
- NASA Core Flight System (cFS) Health & Safety (HS) Applicationcisa_advisories · 2026-07-30
- Mitsubishi Electric CC-Link IE TSN Communication Protocolcisa_advisories · 2026-07-30
- Schneider Electric IGSScisa_advisories · 2026-07-30
- MikroTik RouterOScisa_advisories · 2026-07-30
- Toptech Systems RCU II+ and Multiload II+cisa_advisories · 2026-07-30
- Watchfire Controller Softwarecisa_advisories · 2026-07-30
- Johnson Controls OpenBlue Employeecisa_advisories · 2026-07-30
- MZ Automation GmbH libiec61850cisa_advisories · 2026-07-30
- MZ Automation lib60870cisa_advisories · 2026-07-30
- Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Modulecisa_advisories · 2026-07-30
- o6 Automation open62541cisa_advisories · 2026-07-30
- The Network Has Become the Control Plane for AI Securitythehackernews · 2026-07-30
- CVE-2026-23985: Apache Superset: Regular Expression Denial of Service (ReDoS) in SQL Parseross_sec · 2026-07-30
- CVE-2026-23981: Apache Superset: Improper Authorization in Chart Update allowing Dashboard Modificationoss_sec · 2026-07-30
- [NVD] CVE-2026-18369 (MEDIUM 5.8) — A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP address literals as dns identifiers and follows HTTP redirects without validating that the target is a public address. An unauthenticated ACME account holder can exploit this to perfonvd · 2026-07-30
- CVE-2026-52680: Apache Kyuubi: REST batch multipart upload path traversal allows controlled file writeoss_sec · 2026-07-30
- CVE-2026-44617: Apache Zeppelin: LDAP filter injection in LdapRealm — incomplete fix of CVE-2024-31867oss_sec · 2026-07-30
- CVE-2026-44616: Apache Zeppelin: LDAP injection in ActiveDirectoryGroupRealm filter constructionoss_sec · 2026-07-30
- CVE-2026-44615: Apache Zeppelin: Path traversal in NotebookRepo note and folder path compositionoss_sec · 2026-07-30
- CVE-2026-44613: Apache Zeppelin: Cross-site request forgery in REST and WebSocket request handlingoss_sec · 2026-07-30
- Should You Use AI for a Task? Here’s a Simple Way to Decideschneier · 2026-07-30
- OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asiasecurelist · 2026-07-30
- Building secure Uniswap v4 hookstrailofbits · 2026-07-30
- [qilin] TenSparrows posted to leak siteransomware_live · 2026-07-30
- Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)rapid7 · 2026-07-30
- Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Promptsthehackernews · 2026-07-30
- SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRATthehackernews · 2026-07-30
- [cmdorganization] Collge Mont Notre-Dame de Sherbrooke posted to leak siteransomware_live · 2026-07-30
- Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacksunit42 · 2026-07-30
- Black Hat special: Rewind and revisittalos · 2026-07-30
- [qilin] Db Tarimsal Enerji posted to leak siteransomware_live · 2026-07-30
- [cmdorganization] Rondout Electric posted to leak siteransomware_live · 2026-07-30
- [qilin] Byonyks posted to leak siteransomware_live · 2026-07-30
- [qilin] Prenisac posted to leak siteransomware_live · 2026-07-30
- [qilin] Excel Consultores posted to leak siteransomware_live · 2026-07-30
- [qilin] Affinity Capital posted to leak siteransomware_live · 2026-07-30
- [kairos] Warwick Fabrics posted to leak siteransomware_live · 2026-07-30
- [gunra] Siam Stabilizers and Chemicals Co., Ltd. / SSC posted to leak siteransomware_live · 2026-07-30
- Toy Ghouls’ new toy: the GenieLocker ransomwaresecurelist · 2026-07-30
- [qilin] Adpo posted to leak siteransomware_live · 2026-07-30
- [qilin] servitelco posted to leak siteransomware_live · 2026-07-30
- [qilin] Orimar posted to leak siteransomware_live · 2026-07-30
- [qilin] Indian Motos Inmot posted to leak siteransomware_live · 2026-07-30
- Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotationthehackernews · 2026-07-30
- FCC Blocks New Foreign-Produced Robots and Power Inverters Over Cyber Risksthehackernews · 2026-07-30
- [aurora] Van Eijck International Car Rescue posted to leak siteransomware_live · 2026-07-30
- [aurora] Evosys Laser GmbH posted to leak siteransomware_live · 2026-07-30
- [aurora] Pyramid Analytics B.V. posted to leak siteransomware_live · 2026-07-30
- [thegentlemen] Promatrix posted to leak siteransomware_live · 2026-07-30
- [thegentlemen] Malaysian Nuclear Agency posted to leak siteransomware_live · 2026-07-30