THREAT OPS › Threat News
Threat Intelligence News
12035 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- We found 120 fake Walmart stores trying to steal your credit cardmalwarebytes_blog · 2026-07-29
- Exploiting Titan Questsynacktiv · 2026-07-29
- [NVD] CVE-2026-59243 (CRITICAL 9.8) — The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or unsigned (`alg:none`) ID token to the OAuth callback could bypass authentication and log in as an arbitrary user, including one honvd · 2026-07-29
- [NVD] CVE-2026-18201 (MEDIUM 5.5) — Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discovered where an administrator with permission to manage identity providers could link a new provider to an organization without having the required permissions tonvd · 2026-07-29
- Livewire: remote command execution through unmarshalingsynacktiv · 2026-07-29
- Exploiting Anno 1404synacktiv · 2026-07-29
- ActivID administrator account takeover : the story behind HID-PSA-2025-002synacktiv · 2026-07-29
- 2025 Winter Challenge: Quinindromesynacktiv · 2026-07-29
- Site Unseen: Enumerating and Attacking Active Directory Sitessynacktiv · 2026-07-29
- Creating a "Two-Face" Rust binary on Linuxsynacktiv · 2026-07-29
- Paint it blue: Attacking the bluetooth stacksynacktiv · 2026-07-29
- Bypassing Windows authentication reflection mitigations for SYSTEM shells - Part ②synacktiv · 2026-07-29
- Bypassing Windows authentication reflection mitigations for SYSTEM shells - Part 1synacktiv · 2026-07-29
- Say hi to Pike!synacktiv · 2026-07-29
- Hooking Windows Named Pipessynacktiv · 2026-07-29
- Kubernetes forensics 1/3: what the container ?synacktiv · 2026-07-29
- Exploring cross-domain & cross-forest RBCDsynacktiv · 2026-07-29
- Deep-dive into the deployment of an on-premise low-privileged LLM serversynacktiv · 2026-07-29
- mitmproxy for fun and profit: Interception and Analysis of Application Trafficsynacktiv · 2026-07-29
- 2025 winter challenge writeupsynacktiv · 2026-07-29
- Beyond ACLs: Mapping Windows Privilege Escalation Paths with BloodHoundsynacktiv · 2026-07-29
- On the clock: Escaping VMware Workstation at Pwn2Own Berlin 2025synacktiv · 2026-07-29
- Wireless-(in)Fidelity: Pentesting Wi-Fi in 2025synacktiv · 2026-07-29
- Exploring cross-domain & cross-forest RBCD: part 2synacktiv · 2026-07-29
- Surviving the surge of new Linux LPE : Defense in Depth not deadsynacktiv · 2026-07-29
- Exploiting the Tesla Wall Connector from its charge port connector - Part 2: bypassing the anti-downgradesynacktiv · 2026-07-29
- Make it Blink: Over-the-Air Exploitation of the Philips Hue Bridgesynacktiv · 2026-07-29
- [NVD] CVE-2026-11973 (MEDIUM 4.9) — The WP-Lister Lite for eBay plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 3.8.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL querynvd · 2026-07-29
- Public PoC Released for Exploited Check Point SmartConsole Authentication Bypassthehackernews · 2026-07-29
- New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commandsthehackernews · 2026-07-29
- Apple Patches Everything (July 2026), (Wed, Jul 29th)sans_isc · 2026-07-29
- Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulatesthehackernews · 2026-07-29
- CVE-2026-23904: Apache Kyuubi: Unrestricted access via Kyuubi engine-ui proxyoss_sec · 2026-07-29
- Re: Fwd: Heads-up: Upcoming important Samba security releases on 2026-07-28oss_sec · 2026-07-29
- CVE-2026-50622: Apache Atlas: Missing Authorization on Admin Endpointsoss_sec · 2026-07-29
- [aurora] Bretford Manufacturing posted to leak siteransomware_live · 2026-07-29
- OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breachthehackernews · 2026-07-29
- Risky Bulletin: Cyberattack disrupts Minnesota water utilitiesriskybiz_news · 2026-07-29
- ZDI-26-467: GStreamer rtpsbcdepay Use-After-Free Remote Code Execution Vulnerabilityzdi_published · 2026-07-29
- ZDI-26-466: GStreamer PNG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerabilityzdi_published · 2026-07-29
- ZDI-26-465: GStreamer OGG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerabilityzdi_published · 2026-07-29
- ZDI-26-464: GStreamer MRF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerabilityzdi_published · 2026-07-29
- ZDI-26-463: GStreamer MRF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerabilityzdi_published · 2026-07-29
- ZDI-26-462: GIMP APNG File Parsing Integer Overflow Remote Code Execution Vulnerabilityzdi_published · 2026-07-29
- ZDI-26-461: GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerabilityzdi_published · 2026-07-29
- ZDI-26-460: GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerabilityzdi_published · 2026-07-29
- ZDI-26-459: GIMP SGI File Parsing Integer Overflow Remote Code Execution Vulnerabilityzdi_published · 2026-07-29
- ZDI-26-458: GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerabilityzdi_published · 2026-07-29
- ZDI-26-457: GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerabilityzdi_published · 2026-07-29
- ZDI-26-456: GIMP TIF File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerabilityzdi_published · 2026-07-29
- ZDI-26-455: GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerabilityzdi_published · 2026-07-29
- ZDI-26-454: GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerabilityzdi_published · 2026-07-29
- ZDI-26-453: GIMP HDR File Parsing Integer Overflow Remote Code Execution Vulnerabilityzdi_published · 2026-07-29
- ZDI-26-496: Trend AI Cleaner One Pro Link Following Arbitrary File Deletion Vulnerabilityzdi_published · 2026-07-29
- ZDI-26-495: (Pwn2Own) VMware ESXi VMXNET3 espQueueMask Out-Of-Bounds Write Local Privilege Escalation Vulnerabilityzdi_published · 2026-07-29
- ZDI-26-494: Apple macOS USD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerabilityzdi_published · 2026-07-29
- ZDI-26-493: Apple macOS USD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerabilityzdi_published · 2026-07-29
- ZDI-26-492: Apple macOS ImageIO Numeric Truncation Remote Code Execution Vulnerabilityzdi_published · 2026-07-29
- ZDI-26-491: Apple macOS CoreAudio Out-Of-Bounds Write Remote Code Execution Vulnerabilityzdi_published · 2026-07-29
- ZDI-26-490: (Pwn2Own) Kenwood DNR1007XR USB Incorrect Default Permissions Local Privilege Escalation Vulnerabilityzdi_published · 2026-07-29
- ZDI-26-487: (Pwn2Own) Kenwood DNR1007XR udhcpd Incorrect Permission Assignment Local Privilege Escalation Vulnerabilityzdi_published · 2026-07-29
- ZDI-26-485: (Pwn2Own) Kenwood DNR1007XR JKGenService Command Injection Local Privilege Escalation Vulnerabilityzdi_published · 2026-07-29
- ZDI-26-477: (Pwn2Own) Sony XAV-9500ES Crash Dump Handler Command Injection Local Privilege Escalation Vulnerabilityzdi_published · 2026-07-29
- ZDI-26-475: (Pwn2Own) Sony XAV-9500ES AVRCP_Br_Response_Parser Heap-based Buffer Overflow Remote Code Execution Vulnerabilityzdi_published · 2026-07-29
- ZDI-26-474: (Pwn2Own) Sony XAV-9500ES l2_reassemble_sdu Heap-based Buffer Overflow Remote Code Execution Vulnerabilityzdi_published · 2026-07-29
- ZDI-26-471: (Pwn2Own) Sony XAV-9500ES prh_l2_decode_packet Out-Of-Bounds Read Information Disclosure Vulnerabilityzdi_published · 2026-07-29
- ZDI-26-470: Aeon load_time_series_segmentation_benchmark Code Injection Remote Code Execution Vulnerabilityzdi_published · 2026-07-29
- ZDI-26-469: Aeon load_human_activity_segmentation_datasets Code Injection Remote Code Execution Vulnerabilityzdi_published · 2026-07-29
- ZDI-26-468: Aeon load_rehab_pile_dataset Deserialization of Untrusted Data Remote Code Execution Vulnerabilityzdi_published · 2026-07-29
- Two Compromised joyfill npm Packages Run RAT When Imported Into Node.jsthehackernews · 2026-07-29
- Coordinated “cyberattack” on Minnesota water utilities: What you need to knowtenable · 2026-07-29
- Measuring LLMs’ Ability to Perform Cryptanalysisschneier · 2026-07-29
- F5 Products Multiple Vulnerabilitieshkcert · 2026-07-29
- [NVD] CVE-2026-56822 (HIGH 7.4) — Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator forwards the SslHandshakeCompletionEvent before the asynchronous OCSP validation completes. This allows the client's downstrenvd · 2026-07-29
- [NVD] CVE-2026-56821 (HIGH 7.4) — Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator flags an out-of-date OCSP response but does not stop processing it, so an expired GOOD response is still reported as VALID, lnvd · 2026-07-29
- Stop rewriting detection rules by hand: automatic Sentinel-to-Elastic migration is hereelastic_security · 2026-07-29
- [CISA KEV] CVE-2026-20316 — Cisco Secure Firewall Management Center (FMC): Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerabilitycisa_kev · 2026-07-29
- [Deadlock] AHENK lab posted to leak siteransomware_live · 2026-07-28
- [NVD] CVE-2026-59921 (MEDIUM 5.7) — Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, HttpPostRequestEncoder constructs multipart HTTP request bodies by directly concatenating user-supplied filenames and field names into Content-Disposition MIME nvd · 2026-07-28
- Secure Agentic AI at Machine Speed: Meet Zscaler at Black Hat 2026zscaler_threatlabz · 2026-07-28
- [qilin] Hoc posted to leak siteransomware_live · 2026-07-28
- [blacknevas] Speed Group posted to leak siteransomware_live · 2026-07-28
- [thegentlemen] Buck Knives posted to leak siteransomware_live · 2026-07-28
- What Is a Dependency Firewall?openssf_blog · 2026-07-28
- [coinbasecartel] Accesso posted to leak siteransomware_live · 2026-07-28
- Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attackthehackernews · 2026-07-28
- Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)rapid7 · 2026-07-28
- Progress security advisory (AV26-755)cccs_ca · 2026-07-28
- Co-Founder of Controversial Spyware Firm Had Israeli Diplomatic Passportcitizenlab · 2026-07-28
- [NVD] CVE-2026-16313 (HIGH 7.6) — A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary propernvd · 2026-07-28
- [chaos] thecranewaregroup.com posted to leak siteransomware_live · 2026-07-28
- [cmdorganization] B-K Tool & Design posted to leak siteransomware_live · 2026-07-28
- [NVD] CVE-2026-47427 (HIGH 7.5) — GitHub MCP Server is GitHub's official MCP Server. Prior to 1.1.0, the CompletionsHandler function in pkg/github/server.go accesses params.Ref without first checking whether it is nil, so a completion/complete request with a missing or empty ref field triggers a nil pointer derefnvd · 2026-07-28
- Wordfence PRISM Detected Backdoored WordPress Plugin within Two Hours of it Being Introducedwordfence · 2026-07-28
- ColdFusion Under Fire: Breaking Down CVE-2026-48283 and CVE-2026-48313horizon3 · 2026-07-28
- Different Attack Surface. Same Outcome: Security You Can Prove.horizon3 · 2026-07-28
- Disrupting supply chain attacks on npm and GitHub Actionsgithub_security_lab · 2026-07-28
- Escaping Linux Sandboxes via PipeWire (CVE-2026-5674)embracethered · 2026-07-28
- [OSSA-2026-031] OpenStack Swift: Proxy denial of service via Accept header (CVE-2026-pending)oss_sec · 2026-07-28
- [OSSA-2026-030] OpenStack Swift: S3API header authorization bypass (CVE-2026-pending)oss_sec · 2026-07-28