THREAT OPS › Threat News
Threat Intelligence News
11990 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- Black Hat special: Rewind and revisittalos · 2026-07-30
- [qilin] Db Tarimsal Enerji posted to leak siteransomware_live · 2026-07-30
- [cmdorganization] Rondout Electric posted to leak siteransomware_live · 2026-07-30
- [qilin] Byonyks posted to leak siteransomware_live · 2026-07-30
- [qilin] Prenisac posted to leak siteransomware_live · 2026-07-30
- [qilin] Excel Consultores posted to leak siteransomware_live · 2026-07-30
- [qilin] Affinity Capital posted to leak siteransomware_live · 2026-07-30
- [kairos] Warwick Fabrics posted to leak siteransomware_live · 2026-07-30
- [gunra] Siam Stabilizers and Chemicals Co., Ltd. / SSC posted to leak siteransomware_live · 2026-07-30
- Toy Ghouls’ new toy: the GenieLocker ransomwaresecurelist · 2026-07-30
- [qilin] Adpo posted to leak siteransomware_live · 2026-07-30
- [qilin] servitelco posted to leak siteransomware_live · 2026-07-30
- [qilin] Orimar posted to leak siteransomware_live · 2026-07-30
- [qilin] Indian Motos Inmot posted to leak siteransomware_live · 2026-07-30
- Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotationthehackernews · 2026-07-30
- FCC Blocks New Foreign-Produced Robots and Power Inverters Over Cyber Risksthehackernews · 2026-07-30
- [aurora] Van Eijck International Car Rescue posted to leak siteransomware_live · 2026-07-30
- [aurora] Evosys Laser GmbH posted to leak siteransomware_live · 2026-07-30
- [aurora] Pyramid Analytics B.V. posted to leak siteransomware_live · 2026-07-30
- [thegentlemen] Promatrix posted to leak siteransomware_live · 2026-07-30
- [thegentlemen] Malaysian Nuclear Agency posted to leak siteransomware_live · 2026-07-30
- [thegentlemen] Delkart Industries Pvt posted to leak siteransomware_live · 2026-07-30
- [thegentlemen] ETA Technology Pvt posted to leak siteransomware_live · 2026-07-30
- [thegentlemen] Kontact Consortium India Pvt posted to leak siteransomware_live · 2026-07-30
- [thegentlemen] Upanal CNC Solutions posted to leak siteransomware_live · 2026-07-30
- [thegentlemen] Indus Protech Solutions posted to leak siteransomware_live · 2026-07-30
- [thegentlemen] Angel Hotel posted to leak siteransomware_live · 2026-07-30
- [thegentlemen] The Garfield County Sheriff Office posted to leak siteransomware_live · 2026-07-30
- [morpheus] Yue Ki Industrial posted to leak siteransomware_live · 2026-07-30
- [NVD] CVE-2026-47882 (HIGH 8.3) — When enabling Spring Boot DevTools support for a remote application target (for example a Docker container or Cloud Foundry app) from the Spring Tools Boot Dashboard, Spring Tools generates a shared secret that authenticates DevTools remote-restart uploads to the deployed applicanvd · 2026-07-30
- [NVD] CVE-2026-47873 (HIGH 8.0) — The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of the host's network interfaces (0.0.0.0) rather than restricting them to loopback. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earliernvd · 2026-07-30
- [NVD] CVE-2026-47858 (HIGH 8.0) — Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier Spring Tools for VSCodnvd · 2026-07-30
- [NVD] CVE-2026-16527 (HIGH 7.3) — An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.nvd · 2026-07-30
- [NVD] CVE-2026-14226 (MEDIUM 4.3) — The Easy Appointments WordPress plugin before 3.12.28 does not require a sufficient capability on one of its appointment-listing REST endpoints, restricting it only to a capability that every authenticated user holds, allowing users with subscriber-level access to read all bookinnvd · 2026-07-30
- Srsly Risky Biz: Chipping away at Chinese AI risksriskybiz_news · 2026-07-30
- Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleetthehackernews · 2026-07-30
- ZDI-26-523: Hugging Face PyTorch Image Models checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerabilityzdi_published · 2026-07-30
- ZDI-26-522: Phoenix Contact CHARX SEC-3000 Insertion of Sensitive Information into Log File Information Disclosure Vulnerabilityzdi_published · 2026-07-30
- ZDI-26-520: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Jupicore External Control of Path Remote Code Execution Vulnerabilityzdi_published · 2026-07-30
- ZDI-26-519: (Pwn2Own) Phoenix Contact CHARX SEC-3150 CharxSystemConfigManager Configuration Injection Remote Code Execution Vulnerabilityzdi_published · 2026-07-30
- ZDI-26-518: (Pwn2Own) Phoenix Contact CHARX SEC-3150 MQTT Service Server-Side Request Forgery Remote Code Execution Vulnerabilityzdi_published · 2026-07-30
- ZDI-26-517: (Pwn2Own) Phoenix Contact CHARX SEC-3150 BackendURL WebSocket Command Injection Remote Code Execution Vulnerabilityzdi_published · 2026-07-30
- ZDI-26-516: (Pwn2Own) Phoenix Contact CHARX SEC-3150 ModBus Server Exposed Dangerous Function Denial-of-Service Vulnerabilityzdi_published · 2026-07-30
- ZDI-26-514: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Failing Open Authentication Bypass Vulnerabilityzdi_published · 2026-07-30
- ZDI-26-512: (Pwn2Own) Phoenix Contact CHARX SEC-3150 ModBus Server Exposed Dangerous Function Denial-of-Service Vulnerabilityzdi_published · 2026-07-30
- ZDI-26-511: (Pwn2Own) Phoenix Contact CHARX SEC-3150 user-applications Symlink Following Local Privilege Escalation Vulnerabilityzdi_published · 2026-07-30
- ZDI-26-510: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Missing Cryptographic Signature Remote Code Execution Vulnerabilityzdi_published · 2026-07-30
- ZDI-26-508: (Pwn2Own) Phoenix Contact CHARX SEC-3150 charx_set_ip_address Improper Input Validation Local Privilege Escalation Vulnerabilityzdi_published · 2026-07-30
- ZDI-26-507: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Privilege Defined With Unsafe Actions Local Privilege Escalation Vulnerabilityzdi_published · 2026-07-30
- ZDI-26-506: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Insertion of Sensitive Information into Log File Authentication Bypass Vulnerabilityzdi_published · 2026-07-30
- ZDI-26-505: (Pwn2Own) Phoenix Contact CHARX SEC-3150 charx-system-config-manager Service CRLF Injection Firewall Bypass Vulnerabilityzdi_published · 2026-07-30
- ZDI-26-504: (Pwn2Own) Phoenix Contact CHARX SEC-3150 CharxSystemConfigManager Configuration Injection Remote Code Execution Vulnerabilityzdi_published · 2026-07-30
- ZDI-26-503: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Race Condition Firewall Bypass Vulnerabilityzdi_published · 2026-07-30
- ZDI-26-502: (Pwn2Own) Phoenix Contact CHARX SEC-3150 user-applications Link Following Local Privilege Escalation Vulnerabilityzdi_published · 2026-07-30
- AWS Forensics : What you need to knowsynacktiv · 2026-07-30
- What Is an Incident Response Retainer? (And Why Waiting Until a Breach Is Too Late)groupib_blog · 2026-07-30
- Google Chrome Multiple Vulnerabilitieshkcert · 2026-07-30
- IBM WebSphere Products Multiple Vulnerabilitieshkcert · 2026-07-30
- Cisco Secure Firewall Management Center Software Information Disclosure Vulnerabilityhkcert · 2026-07-30
- Node.js Multiple Vulnerabilitieshkcert · 2026-07-30
- SilabRAT, What’s Your Power?groupib_blog · 2026-07-30
- [NVD] CVE-2026-17791 (MEDIUM 6.5) — Insufficient validation of untrusted input in Payments in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)nvd · 2026-07-30
- [NVD] CVE-2026-17789 (MEDIUM 6.5) — Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via malicious network traffic. (Chromium security severity: Medium)nvd · 2026-07-30
- [NVD] CVE-2026-17784 (HIGH 8.8) — Use after free in Audio in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)nvd · 2026-07-30
- [NVD] CVE-2026-17768 (CRITICAL 9.6) — Insufficient validation of untrusted input in WebSockets in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)nvd · 2026-07-30
- [NVD] CVE-2026-17761 (MEDIUM 5.4) — Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via malicious network traffic. (Chromium security severity: Medium)nvd · 2026-07-30
- [NVD] CVE-2026-17679 (MEDIUM 6.5) — Insufficient validation of untrusted input in Print Preview in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)nvd · 2026-07-30
- [NVD] CVE-2026-17678 (HIGH 8.8) — Out of bounds read in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)nvd · 2026-07-30
- [NVD] CVE-2026-17676 (CRITICAL 9.6) — Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)nvd · 2026-07-30
- [NVD] CVE-2026-17675 (CRITICAL 9.6) — Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)nvd · 2026-07-30
- [NVD] CVE-2026-17673 (CRITICAL 9.6) — Integer overflow in QUIC in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)nvd · 2026-07-30
- [NVD] CVE-2026-17672 (CRITICAL 9.6) — Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)nvd · 2026-07-30
- [NVD] CVE-2026-17671 (CRITICAL 9.6) — Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)nvd · 2026-07-30
- [NVD] CVE-2026-17670 (CRITICAL 9.6) — Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)nvd · 2026-07-30
- [NVD] CVE-2026-17666 (CRITICAL 9.1) — Cryptographic Flaw in Enterprise in Google Chrome prior to 151.0.7922.72 allowed an attacker in a privileged network position to bypass discretionary access control via malicious network traffic. (Chromium security severity: High)nvd · 2026-07-30
- [NVD] CVE-2026-17663 (HIGH 8.3) — Insufficient validation of untrusted input in GPU in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)nvd · 2026-07-30
- [NVD] CVE-2026-17651 (CRITICAL 9.6) — Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)nvd · 2026-07-30
- Citrix XenServer Multiple Vulnerabilitieshkcert · 2026-07-30
- GitLab Multiple Vulnerabilitieshkcert · 2026-07-30
- Xen Multiple Vulnerabilitieshkcert · 2026-07-30
- Dealing with AI-Generated Extortionrecordedfuture · 2026-07-30
- Iran War’s Secondary Effects Shape 2026 US Violent Extremismrecordedfuture · 2026-07-30
- Apple accused of letting fake crypto app steal $1.8 millionmalwarebytes_blog · 2026-07-29
- [NVD] CVE-2026-15831 (MEDIUM 4.3) — GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.3 and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to bypass administrator-configured tool governance policies due to improper authorization enfornvd · 2026-07-29
- Backports available - cBPF JIT spray hardeningoss_sec · 2026-07-29
- OpenSSF Community Day Europe 2026: Schedule Highlights & What to Expectopenssf_blog · 2026-07-29
- Fwd: [CVE-2026-13346] pip absolute path traversal during download from malicious package indexesoss_sec · 2026-07-29
- Operation Olalampo: Inside MuddyWater’s Latest Campaigngroupib_blog · 2026-07-29
- Phoenix Rising: Exposing the PhaaS Kit Behind Global Mass Phishing Campaignsgroupib_blog · 2026-07-29
- Hooking the Archipelago: Dissecting a Phishing Campaign Targeting Philippine Banking Usersgroupib_blog · 2026-07-29
- [NVD] CVE-2026-8497 (HIGH 7.4) — Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and earlier on Android, iOS, and macOS allows an adjacent-network attacker to intercept and modify sensitive information via a forged TLS certificate.nvd · 2026-07-29
- [NVD] CVE-2026-14266 (HIGH 7.8) — 7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visitnvd · 2026-07-29
- Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploadsthehackernews · 2026-07-29
- CVE-2026-6516 | ManageEngine ADAudit Plus Pre-Authentication Remote Code Execution Vulnerabilityhorizon3 · 2026-07-29
- GitBait: Phishing dirigido al sector financiero mexicanogroupib_blog · 2026-07-29
- [GHSA] GHSA-fm7p-gw32-828p (medium) — mathlive's Lack of Escaping of HTML allows for XSSgithub_advisories · 2026-07-29
- [GHSA] GHSA-rwqx-fvqh-6wm4 (medium) — OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwordsgithub_advisories · 2026-07-29
- [NVD] CVE-2026-18255 (HIGH 7.2) — A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repositories they are not a member of, allowing an attacker with read-only superuser privileges to impersonate any robot account.nvd · 2026-07-29
- [GHSA] GHSA-fq3f-m5qm-99f5 (medium) — OpenTelemetry Javaagent RMI context propagation allows resource exhaustiongithub_advisories · 2026-07-29
- Measuring the Tendency of AI Agents to Go Rogueschneier · 2026-07-29