THREAT OPS › Threat News
Threat Intelligence News
12016 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [GHSA] GHSA-fm7p-gw32-828p (medium) — mathlive's Lack of Escaping of HTML allows for XSSgithub_advisories · 2026-07-29
- [GHSA] GHSA-rwqx-fvqh-6wm4 (medium) — OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwordsgithub_advisories · 2026-07-29
- [NVD] CVE-2026-18255 (HIGH 7.2) — A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repositories they are not a member of, allowing an attacker with read-only superuser privileges to impersonate any robot account.nvd · 2026-07-29
- [GHSA] GHSA-fq3f-m5qm-99f5 (medium) — OpenTelemetry Javaagent RMI context propagation allows resource exhaustiongithub_advisories · 2026-07-29
- Measuring the Tendency of AI Agents to Go Rogueschneier · 2026-07-29
- [GHSA] GHSA-pmwx-rm49-xv39 (low) — ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversalgithub_advisories · 2026-07-29
- [GHSA] GHSA-xvg2-cgv6-6h7v (high) — netfoil: Incorrect block responses could lead to localhost trafficgithub_advisories · 2026-07-29
- When AI Assistant Share Links Become Public Exposurevaronis_blog · 2026-07-29
- [GHSA] GHSA-mjqf-28ph-426h (critical) — Logging operator has Fluentd configuration injection that allows remote code executiongithub_advisories · 2026-07-29
- [GHSA] GHSA-jq8w-8q2f-ffm9 (high) — ZITADEL Users Can Self-Verify Email/Phone via APIgithub_advisories · 2026-07-29
- Buying TikTok views or followers? Here’s what you’re really gettingmalwarebytes_blog · 2026-07-29
- [GHSA] GHSA-7h3g-4w2f-fj2f (high) — proot-distro has a Container Isolation Bypass via Crafted Restore Archivegithub_advisories · 2026-07-29
- [GHSA] GHSA-9xq3-3fqg-4vg7 (high) — `proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archivegithub_advisories · 2026-07-29
- [GHSA] GHSA-996f-334j-67g7 (low) — Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSSgithub_advisories · 2026-07-29
- [GHSA] GHSA-8hm4-r66f-29wr (low) — Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google syncgithub_advisories · 2026-07-29
- [GHSA] GHSA-xgr6-pqjv-3pf8 (medium) — Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule pagegithub_advisories · 2026-07-29
- [GHSA] GHSA-w8xc-8g92-v77h (low) — Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypassgithub_advisories · 2026-07-29
- [incransom] harwal.net posted to leak siteransomware_live · 2026-07-29
- Fwd: Node.js security updates for all active release lines, June 2026oss_sec · 2026-07-29
- [GHSA] GHSA-pm5p-7w5h-jm5q (low) — Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal networkgithub_advisories · 2026-07-29
- [GHSA] GHSA-4vmm-5qvc-w5p7 (high) — Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposuregithub_advisories · 2026-07-29
- [NVD] CVE-2026-16463 (HIGH 7.8) — A maliciously crafted DXF file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.nvd · 2026-07-29
- CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCityrapid7 · 2026-07-29
- [GHSA] GHSA-wchh-9x6h-7f6p (medium) — olm dependency deprecation: CVE-2022-39255 and CVE-2024-45193github_advisories · 2026-07-29
- [GHSA] GHSA-m4x6-gwgp-4pm7 (high) — AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escapinggithub_advisories · 2026-07-29
- WP2Shell WordPress Exploit Technical Analysis and Real Attack Datawordfence · 2026-07-29
- [GHSA] GHSA-4p3g-4hcj-wpvx (critical) — prebid-server's request forgery vulnerability allows for possible host environment data extractiongithub_advisories · 2026-07-29
- Clustered Points of Failurespecterops · 2026-07-29
- Cisco Secure Firewall Management Center Software Static Credential Vulnerabilitycisco_psirt · 2026-07-29
- Cisco Advance Notification for Publication of August 5, 2026, Security Advisoriescisco_psirt · 2026-07-29
- Better security starts with better questionsmsstic · 2026-07-29
- Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerabilitycisco_psirt · 2026-07-29
- [GHSA] GHSA-qcxp-gm7m-4j5v (high) — Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilitiesgithub_advisories · 2026-07-29
- Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memorythehackernews · 2026-07-29
- [GHSA] GHSA-pc2w-4mq8-32qw (low) — @dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human-approval gategithub_advisories · 2026-07-29
- [GHSA] GHSA-f42x-p2mx-hm8r (medium) — Penelope unsafe tar extraction allows arbitrary local file write via crafted session archivegithub_advisories · 2026-07-29
- Caught in the Octopus Trap: Unauthenticated RCE in Argo CD with CodeQLsynacktiv · 2026-07-29
- Charting your way in: Helm template injectionsynacktiv · 2026-07-29
- Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escapethehackernews · 2026-07-29
- [GHSA] GHSA-px9f-whj3-246m (medium) — Req vulnerable to multipart form-data header injection via unescaped name/filename/content_typegithub_advisories · 2026-07-29
- [GHSA] GHSA-655f-mp8p-96gv (high) — Req vulnerable to unbounded archive/compression extraction triggered by response content-typegithub_advisories · 2026-07-29
- [GHSA] GHSA-7c26-995w-6f47 (medium) — veraPDF Parser DoS via PostScript Type 1 Font Programsgithub_advisories · 2026-07-29
- [GHSA] GHSA-jrmc-qg6p-94fp (medium) — veraPDF Parser DoS via PostScript CMap Streamsgithub_advisories · 2026-07-29
- AI robocalls: Why caller ID is still lying to youmalwarebytes_blog · 2026-07-29
- [GHSA] GHSA-cg9x-g3gm-h5h6 (medium) — veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When Processing Untrusted PDFsgithub_advisories · 2026-07-29
- [GHSA] GHSA-3jh7-wm29-q568 (high) — veraPDF Validation XXE via Rich Textgithub_advisories · 2026-07-29
- [OSSA-2026-032] OpenStack Neutron: Subnetpool onboarding cross-project subnet mutation (CVE-2026-55707)oss_sec · 2026-07-29
- [GHSA] GHSA-36mm-w85j-3q2j (high) — veraPDF Validation XXE via XFAgithub_advisories · 2026-07-29
- [Joint Cybersecurity Advisory] Operation Double Barrel (The Relationship Between a State-Sponsored Threat Actor and the Gunra Ransomware Group)ahnlab · 2026-07-29
- Ransom & Dark Web Issues Week 5, July 2026ahnlab · 2026-07-29
- [GHSA] GHSA-w284-33mx-6g9v (high) — swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodiesgithub_advisories · 2026-07-29
- Adobe security advisory (AV26-756)cccs_ca · 2026-07-29
- [GHSA] GHSA-5f94-x226-ccpm (high) — swagger-typescript-api vulnerable to code injection via unescaped enum string valuesgithub_advisories · 2026-07-29
- [GHSA] GHSA-38c3-wv3c-v3xj (high) — swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client templategithub_advisories · 2026-07-29
- [GHSA] GHSA-x36r-4347-pm5x (medium) — swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`github_advisories · 2026-07-29
- [GHSA] GHSA-hqj5-cw9f-rx67 (high) — swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client templategithub_advisories · 2026-07-29
- [GHSA] GHSA-h754-fxp7-88wx (high) — swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`github_advisories · 2026-07-29
- OpenAI explains how its AI agent breached Hugging Facemalwarebytes_blog · 2026-07-29
- [NotCVE-2026-0011] Nmap 7.99 and Earlier nselib/packet.lua Zero-Length TCP Option Infinite Loop Allows Remote Denial of Serviceoss_sec · 2026-07-29
- [akira] Northwood Country Club posted to leak siteransomware_live · 2026-07-29
- Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offlinethehackernews · 2026-07-29
- Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Paymentsthehackernews · 2026-07-29
- Millenium: A RAT Rewritten, A Threat Multipliedgroupib_blog · 2026-07-29
- [Section9] ****.com.pa posted to leak siteransomware_live · 2026-07-29
- Horizon3’s NodeZero® AI Hacker Extends Production-Safe Autonomous Pentesting to Web Applicationshorizon3 · 2026-07-29
- Security Validation Should Begin Where Attackers Beginhorizon3 · 2026-07-29
- How AI is Rewriting the Zero-Day Playbook for Preemptive Securityrapid7 · 2026-07-29
- KYC: Bypass age verification using generative video modelssynacktiv · 2026-07-29
- Mythos Asks the Right Question. It Doesn't Answer It.thehackernews · 2026-07-29
- Operationalize AI Governance Across Shadow GenAI, MCP, and Agentic Workloads with Qualys TotalAIqualys · 2026-07-29
- 2026 Minimum Elements for a Software Bill of Materials (SBOM)cisa_advisories · 2026-07-29
- CISA Adds One Known Exploited Vulnerability to Catalogcisa_advisories · 2026-07-29
- Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browserthehackernews · 2026-07-29
- The GHOST STADIUM Score: Billions At Stake At The World’s Largest Football Tournamentgroupib_blog · 2026-07-29
- Completing Compliance with Evidence : A Bottom-Up Approach to NIS2, DORA, and the Cyber Resilience Actsynacktiv · 2026-07-29
- OpenAI-Hugging Face Breach: Five New Things We Learnedduo_decipher · 2026-07-29
- 73% of Organizations Say They Are Not Fully Ready for a Major Cyberattackthehackernews · 2026-07-29
- These near-mint ASUS Chromebook refurbs are only $145bleepingcomputer · 2026-07-29
- [spacebears] StellarRAD Systems posted to leak siteransomware_live · 2026-07-29
- Long-Lived Vulnerability in Microsoft Secure Bootschneier · 2026-07-29
- Russia Charges Telegram Founder Pavel Durov With Aiding Terrorist Activitythehackernews · 2026-07-29
- We found 120 fake Walmart stores trying to steal your credit cardmalwarebytes_blog · 2026-07-29
- Exploiting Titan Questsynacktiv · 2026-07-29
- [NVD] CVE-2026-59243 (CRITICAL 9.8) — The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or unsigned (`alg:none`) ID token to the OAuth callback could bypass authentication and log in as an arbitrary user, including one honvd · 2026-07-29
- [NVD] CVE-2026-18201 (MEDIUM 5.5) — Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discovered where an administrator with permission to manage identity providers could link a new provider to an organization without having the required permissions tonvd · 2026-07-29
- Livewire: remote command execution through unmarshalingsynacktiv · 2026-07-29
- Exploiting Anno 1404synacktiv · 2026-07-29
- ActivID administrator account takeover : the story behind HID-PSA-2025-002synacktiv · 2026-07-29
- 2025 Winter Challenge: Quinindromesynacktiv · 2026-07-29
- Site Unseen: Enumerating and Attacking Active Directory Sitessynacktiv · 2026-07-29
- Creating a "Two-Face" Rust binary on Linuxsynacktiv · 2026-07-29
- Paint it blue: Attacking the bluetooth stacksynacktiv · 2026-07-29
- Bypassing Windows authentication reflection mitigations for SYSTEM shells - Part ②synacktiv · 2026-07-29
- Bypassing Windows authentication reflection mitigations for SYSTEM shells - Part 1synacktiv · 2026-07-29
- Say hi to Pike!synacktiv · 2026-07-29
- Hooking Windows Named Pipessynacktiv · 2026-07-29
- Kubernetes forensics 1/3: what the container ?synacktiv · 2026-07-29
- Exploring cross-domain & cross-forest RBCDsynacktiv · 2026-07-29
- Deep-dive into the deployment of an on-premise low-privileged LLM serversynacktiv · 2026-07-29
- mitmproxy for fun and profit: Interception and Analysis of Application Trafficsynacktiv · 2026-07-29