THREAT OPS › Threat News
Threat Intelligence News
11576 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- Cpython: [CVE-2026-82049] tarfile extraction filters allow file modification and content disclosure via hard link to symlinkoss_sec · 2026-09-14
- Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exportsthehackernews · 2026-09-14
- graphql-go/graphql <= 0.8.1: quadratic CPU-exhaustion DoS via OverlappingFieldsCanBeMergedRuleoss_sec · 2026-09-14
- Android security advisory – September 2026 monthly rollup (AV26-920)cccs_ca · 2026-09-14
- [GHSA] GHSA-2xmm-m4wv-3fjh (low) — October CMS: Incomplete Scheme Validation in Image Resizergithub_advisories · 2026-09-14
- [GHSA] GHSA-2ff2-mx52-q8wp (low) — October CMS: PHP Object Injection via Backend Widget Session Storagegithub_advisories · 2026-09-14
- New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computingthehackernews · 2026-09-14
- Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countriesthehackernews · 2026-09-14
- Wordfence Argus Identifies Two Critical Unauthenticated Vulnerability Chains Leading to Remote Code Execution in The Events Calendar Pluginwordfence · 2026-09-14
- [Eclipse] Dublin City Schools GA posted to leak siteransomware_live · 2026-09-14
- Using AI for Weapons Developmentschneier · 2026-09-14
- [GHSA] GHSA-xv9m-fm3w-8w5x (low) — October CMS: Safe Mode Sandbox Bypass via Session Store and Forwarded Builder Callsgithub_advisories · 2026-09-14
- CVE-2026-87802: Apache Syncope: SRA OAuth2 JWT signature verification bypassoss_sec · 2026-09-14
- WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distributionthehackernews · 2026-09-14
- Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026cisco_psirt · 2026-09-14
- Cisco Secure Email Gateway SQL Injection Vulnerabilitycisco_psirt · 2026-09-14
- [Security Blog] Internet-edge Devices Remain Targets for Hackers: Patching Alone Cannot Stop Credential Theft or Persistent Accesshkcert · 2026-09-14
- CVE-2026-87785: Apache Syncope: JWT subject spoofingoss_sec · 2026-09-14
- CVE-2026-87779: Apache Syncope: AES Secret Key disclosure via log outputoss_sec · 2026-09-14
- CVE-2026-86460: Apache Syncope: Cypher Injection via FIQL Search on Neo4j Persistenceoss_sec · 2026-09-14
- CVE-2026-82232: Apache Syncope: SQL injection via sort parameter in Task searchoss_sec · 2026-09-14
- CVE-2026-78336: Apache Syncope: OIDCC4UI provider list discloses client secrets to any authenticated useross_sec · 2026-09-14
- CVE-2026-78330: Apache Syncope: Privilege escalation for admin user via JWT authenticationoss_sec · 2026-09-14
- CVE-2026-78318: Apache Syncope: Unauthenticated reflected XSS in Console and Enduseross_sec · 2026-09-14
- CVE-2026-77883: Apache Syncope: Information disclosure via one-hop JEXL navigation past the JexlContextBuilder name denylistoss_sec · 2026-09-14
- CVE-2026-77181: Apache Syncope: ClientApp update entitlement not effectiveoss_sec · 2026-09-14
- CVE-2026-77147: Apache Syncope: Groovy Sandbox escape for empty CommandArgsoss_sec · 2026-09-14
- CVE-2026-77051: Apache Syncope: SQL injection via unsanitized entityKey and opEvent in Audit Events searchoss_sec · 2026-09-14
- CVE-2026-75030: Apache Syncope: Incomplete authorization checks for Group members deprovisioningoss_sec · 2026-09-14
- CVE-2026-75015: Apache Syncope: Nested secrets leak cleartext into audit records readableoss_sec · 2026-09-14
- CVE-2026-73668: Apache Syncope: Cross-realm disclosure of confidential ConnId bundles configuration valuesoss_sec · 2026-09-14
- CVE-2026-73579: Apache Syncope: Non-recursive Any search could skip Realms restrictionsoss_sec · 2026-09-14
- [Eclipse] Rosello et Fils posted to leak siteransomware_live · 2026-09-14
- Samsung mobile security advisory (AV26-919)cccs_ca · 2026-09-14
- Rapid7 Named Among Notable Vendors in Forrester MDR Landscape: Why the Future is Exposure-informed, Preemptive MDRrapid7 · 2026-09-14
- Breaking: GitLab Critical Path Traversal Flaw Exploited in the Wild — Patch Immediatelyorca_security · 2026-09-14
- ⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkitsthehackernews · 2026-09-14
- Emacs arbitrary code execution: incomplete fix for CVE-2024-53920oss_sec · 2026-09-14
- MongoDB security advisory (AV26-918)cccs_ca · 2026-09-14
- What's New in ZDX: Broader Reach, Smarter Remediationzscaler_threatlabz · 2026-09-14
- Google’s new search redirects make links harder to check before you clickmalwarebytes_blog · 2026-09-14
- [NVD] CVE-2026-90940 (MEDIUM 5.3) — novel-plus through 5.3.3 contains an insecure default cache-management password in the CacheController.refreshCache endpoint that allows anonymous attackers to invalidate portal caches by supplying the hardcoded default value in the URL path. Attackers can trigger unauthorized canvd · 2026-09-14
- [lockbit5] tpi.tw posted to leak siteransomware_live · 2026-09-14
- [lockbit5] comune.robeccosulnaviglio.mi.it posted to leak siteransomware_live · 2026-09-14
- [lockbit5] httoy.fi posted to leak siteransomware_live · 2026-09-14
- [insomnia] Massey, Stotser & Nichols posted to leak siteransomware_live · 2026-09-14
- Wordfence Bug Bounty Program Monthly Report – May 2026wordfence · 2026-09-14
- [chaos] glasfloss.com posted to leak siteransomware_live · 2026-09-14
- [chaos] steelhausinc.com posted to leak siteransomware_live · 2026-09-14
- [NVD] CVE-2024-58383 (HIGH 7.3) — Froxlor before 2.2.0 (affected up to and including 2.2.0-rc3) generates /etc/pure-ftpd/db/mysql.conf with mode 0644 via the XML configuration templates in lib/configfiles/, even though the file contains the Froxlor SQL user's password. On systems where the parent directories are nvd · 2026-09-14
- Here Come the AI-Generated BEC Scamsduo_decipher · 2026-09-14
- [qilin] Vitar Group posted to leak siteransomware_live · 2026-09-14
- [Booba Project] Mestechkin Law Group P.C. posted to leak siteransomware_live · 2026-09-14
- VectraRAT: An Undocumented Full-Stack MaaS Built From Scratchsocradar_blog · 2026-09-14
- Operate Zscaler Zero Trust Exchange with the Agentic AI tool of Your Choicezscaler_threatlabz · 2026-09-14
- 14th September – Threat Intelligence Reportcheckpoint_research · 2026-09-14
- [Booba Project] Atlas Ocean Voyages posted to leak siteransomware_live · 2026-09-14
- CISA Adds One Known Exploited Vulnerability to Catalogcisa_advisories · 2026-09-14
- AI Changed the Exposure Problem. Validation Needs to Change With It.thehackernews · 2026-09-14
- [AuditTeam] Ne***ox posted to leak siteransomware_live · 2026-09-14
- Revolut gave customer IDs and financial data to a government impostormalwarebytes_blog · 2026-09-14
- Microsoft’s Patchingschneier · 2026-09-14
- Unmasking Cloud Identities: From Behavioral Clustering to Automated Detectionunit42 · 2026-09-14
- UCQ Leak, Israeli GlobalProtect Access, Digital Nirvana Dump, 32baar, and Ghorer Bazarsocradar_blog · 2026-09-14
- [qilin] Alicotrans posted to leak siteransomware_live · 2026-09-14
- Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Usersthehackernews · 2026-09-14
- A week in security (September 7 – September 13)malwarebytes_blog · 2026-09-14
- ZDI-26-701: Linux Kernel TLS Protocol Out-Of-Bounds Read Information Disclosure Vulnerabilityzdi_published · 2026-09-14
- ZDI-26-700: Linux Kernel QFQ Plus Scheduler Use-After-Free Local Privilege Escalation Vulnerabilityzdi_published · 2026-09-14
- ZDI-26-696: Linux Kernel NTFS3 Journal Heap-based Buffer Overflow Code Execution Vulnerabilityzdi_published · 2026-09-14
- ZDI-26-695: Linux Kernel NFSv4 Server Race Condition Remote Code Execution Vulnerabilityzdi_published · 2026-09-14
- ZDI-26-694: Linux Kernel Net Scheduler Clsact Qdisc Use-After-Free Local Privilege Escalation Vulnerabilityzdi_published · 2026-09-14
- ZDI-26-691: Linux Kernel Netlink-based Wireless Configuration Integer Overflow Local Privilege Escalation Vulnerabilityzdi_published · 2026-09-14
- ZDI-26-690: Linux Kernel MCTP Routing Uninitialized Memory Information Disclosure Vulnerabilityzdi_published · 2026-09-14
- ZDI-26-689: Linux Kernel SCTP Subsystem Race Condition Information Disclosure Vulnerabilityzdi_published · 2026-09-14
- ZDI-26-688: Linux Kernel OpenvSwitch Race Condition Local Privilege Escalation Vulnerabilityzdi_published · 2026-09-14
- ZDI-26-687: Linux Kernel Open vSwitch Flow Delete Use-After-Free Information Disclosure Vulnerabilityzdi_published · 2026-09-14
- ZDI-26-686: Linux Kernel nftables Race Condition Local Privilege Escalation Vulnerabilityzdi_published · 2026-09-14
- ZDI-26-685: Linux Kernel NFC NCI UART Driver Race Condition Local Privilege Escalation Vulnerabilityzdi_published · 2026-09-14
- ZDI-26-684: Linux Kernel KSMBD Query Directory Request Race Condition Remote Code Execution Vulnerabilityzdi_published · 2026-09-14
- ZDI-26-683: Linux Kernel IPv6 VTI Subsystem Use-After-Free Local Privilege Escalation Vulnerabilityzdi_published · 2026-09-14
- ZDI-26-682: Linux Kernel IPv6 Neighbour Discovery Uninitialized Memory Information Disclosure Vulnerabilityzdi_published · 2026-09-14
- ZDI-26-681: Linux Kernel FUSE Subsystem Race Condition Local Privilege Escalation Vulnerabilityzdi_published · 2026-09-14
- ZDI-26-680: Linux Kernel Crypto Subsystem Use-After-Free Local Privilege Escalation Vulnerabilityzdi_published · 2026-09-14
- GitLab Multiple Vulnerabilitieshkcert · 2026-09-14
- Phishing Alert - Beware of Phishing Activities Leading to Unauthorised Credit Card Transactionshkcert · 2026-09-14
- What is Proactive Threat Intelligence? | Recorded Futurerecordedfuture · 2026-09-14
- [CISA KEV] CVE-2026-76461 — Cisco Secure Email Gateway: Cisco Secure Email Gateway SQL Injection Vulnerabilitycisa_kev · 2026-09-14
- [Panzer] Cerámicas Kantu posted to leak siteransomware_live · 2026-09-13
- [NVD] CVE-2026-85129 (HIGH 8.8) — The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its import features, and does not sanitise the data submitted to it before storing it as the active theme's settings, allowing unauthenticated attackers to inject arbitrary webnvd · 2026-09-13
- [NVD] CVE-2026-81648 (CRITICAL 10.0) — The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on the server, overwriting the payment gatewaynvd · 2026-09-13
- [NVD] CVE-2026-74933 (HIGH 8.8) — The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its REST API and AJAX actions, and decodes stored values before printing them, allowing unauthenticated users to overwrite its configuration and inject arbitrary web scripts that envd · 2026-09-13
- [NVD] CVE-2026-37008 (HIGH 8.1) — CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275. Import-time blocking of module names does not address the availability of Python's complete object graph. For example, calling cnvd · 2026-09-13
- [NVD] CVE-2026-90583 (MEDIUM 4.3) — A security flaw has been discovered in kagisearch smallweb up to 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf. The affected element is the function index of the file app/sw.py of the component Query String Rendering. Performing a manipulation of the argument qs results in cross site nvd · 2026-09-13
- [NVD] CVE-2026-90582 (MEDIUM 5.3) — A vulnerability was identified in evanchiu serverless-todo 1.0.3/2.0.0. Impacted is the function saveTodos of the file src/index.js of the component API Todo Endpoint. Such manipulation of the argument event.body leads to resource consumption. The attack can be executed remotely.nvd · 2026-09-13
- [NVD] CVE-2026-90581 (MEDIUM 6.3) — A vulnerability was determined in cym1102 nginxWebUI up to 4.4.2. This issue affects the function MainController.autoUpdate of the file /adminPage/main/autoUpdate. This manipulation of the argument url causes code injection. Remote exploitation of the attack is possible. The explnvd · 2026-09-13
- [NVD] CVE-2026-90580 (MEDIUM 6.3) — A vulnerability was found in FlowiseAI Flowise up to 3.0.2. This vulnerability affects the function axios.post of the file packages/server/src/controllers/evaluations/index.ts of the component Evaluations Endpoint. The manipulation of the argument Host/X-Forwarded-Proto results invd · 2026-09-13
- [NVD] CVE-2026-90579 (HIGH 7.3) — A vulnerability has been found in cheshire-cat-ai Cheshire Cat AI up to 1.9.2. This affects the function _authorize_http_key of the file core/cat/factory/custom_auth_handler.py. The manipulation of the argument user_id leads to missing authentication. The attack may be initiated nvd · 2026-09-13
- [NVD] CVE-2026-90578 (MEDIUM 5.3) — A flaw has been found in GPAC up to f1219cde. Affected by this issue is the function gf_list_count of the file utils/list.c of the component MP4Box. Executing a manipulation can lead to use after free. The attack is restricted to local execution. The exploit has been published annvd · 2026-09-13
- [NVD] CVE-2026-90577 (MEDIUM 5.3) — A vulnerability was detected in GPAC up to f1219cde. Affected by this vulnerability is the function gf_node_get_field of the file scenegraph/base_scenegraph.c of the component MP4Box. Performing a manipulation results in heap-based buffer overflow. The attack is only possible witnvd · 2026-09-13