THREAT OPS › Threat News
Threat Intelligence News
12066 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [NVD] CVE-2026-56821 (HIGH 7.4) — Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator flags an out-of-date OCSP response but does not stop processing it, so an expired GOOD response is still reported as VALID, lnvd · 2026-07-29
- Stop rewriting detection rules by hand: automatic Sentinel-to-Elastic migration is hereelastic_security · 2026-07-29
- [CISA KEV] CVE-2026-20316 — Cisco Secure Firewall Management Center (FMC): Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerabilitycisa_kev · 2026-07-29
- [Deadlock] AHENK lab posted to leak siteransomware_live · 2026-07-28
- [NVD] CVE-2026-59921 (MEDIUM 5.7) — Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, HttpPostRequestEncoder constructs multipart HTTP request bodies by directly concatenating user-supplied filenames and field names into Content-Disposition MIME nvd · 2026-07-28
- Secure Agentic AI at Machine Speed: Meet Zscaler at Black Hat 2026zscaler_threatlabz · 2026-07-28
- [qilin] Hoc posted to leak siteransomware_live · 2026-07-28
- [blacknevas] Speed Group posted to leak siteransomware_live · 2026-07-28
- [thegentlemen] Buck Knives posted to leak siteransomware_live · 2026-07-28
- What Is a Dependency Firewall?openssf_blog · 2026-07-28
- [coinbasecartel] Accesso posted to leak siteransomware_live · 2026-07-28
- Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attackthehackernews · 2026-07-28
- Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)rapid7 · 2026-07-28
- Progress security advisory (AV26-755)cccs_ca · 2026-07-28
- Co-Founder of Controversial Spyware Firm Had Israeli Diplomatic Passportcitizenlab · 2026-07-28
- [NVD] CVE-2026-16313 (HIGH 7.6) — A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary propernvd · 2026-07-28
- [chaos] thecranewaregroup.com posted to leak siteransomware_live · 2026-07-28
- [cmdorganization] B-K Tool & Design posted to leak siteransomware_live · 2026-07-28
- [NVD] CVE-2026-47427 (HIGH 7.5) — GitHub MCP Server is GitHub's official MCP Server. Prior to 1.1.0, the CompletionsHandler function in pkg/github/server.go accesses params.Ref without first checking whether it is nil, so a completion/complete request with a missing or empty ref field triggers a nil pointer derefnvd · 2026-07-28
- Wordfence PRISM Detected Backdoored WordPress Plugin within Two Hours of it Being Introducedwordfence · 2026-07-28
- ColdFusion Under Fire: Breaking Down CVE-2026-48283 and CVE-2026-48313horizon3 · 2026-07-28
- Different Attack Surface. Same Outcome: Security You Can Prove.horizon3 · 2026-07-28
- Disrupting supply chain attacks on npm and GitHub Actionsgithub_security_lab · 2026-07-28
- Escaping Linux Sandboxes via PipeWire (CVE-2026-5674)embracethered · 2026-07-28
- [OSSA-2026-031] OpenStack Swift: Proxy denial of service via Accept header (CVE-2026-pending)oss_sec · 2026-07-28
- [OSSA-2026-030] OpenStack Swift: S3API header authorization bypass (CVE-2026-pending)oss_sec · 2026-07-28
- CVE-2026-66299: Apache Tomcat: DoS via WebSocket chat exampleoss_sec · 2026-07-28
- Xen Security Advisory 508 v2 - pygrub is only supported in de-privileged modeoss_sec · 2026-07-28
- Demystifying The Com and Nihilistic Violent Extremism: What You Need To Knowflashpoint · 2026-07-28
- Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Processthehackernews · 2026-07-28
- Xen Security Advisory 507 v2 (CVE-2026-62434) - PoD: Don't try to reclaim special pagesoss_sec · 2026-07-28
- Xen Security Advisory 506 v2 (CVE-2026-62433) - correct buffer checks for DM_OP hypercallsoss_sec · 2026-07-28
- Xen Security Advisory 505 v2 (CVE-2026-62432) - evtchn: Race between FIFO expand and resetoss_sec · 2026-07-28
- Xen Security Advisory 504 v2 (CVE-2026-62431) - Viridian STIMER division by zerooss_sec · 2026-07-28
- [Deadlock] DIATER posted to leak siteransomware_live · 2026-07-28
- [Deadlock] Pasello posted to leak siteransomware_live · 2026-07-28
- [Booba Project] Oklahoma Manufacturing Alliance posted to leak siteransomware_live · 2026-07-28
- Xen Security Advisory 503 v2 (CVE-2026-62430) - x86: Out-of-bounds read in vRTC emulationoss_sec · 2026-07-28
- 24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Loginthehackernews · 2026-07-28
- Vercel security advisory (AV26-754)cccs_ca · 2026-07-28
- Apple security advisory (AV26-753)cccs_ca · 2026-07-28
- JetBrains security advisory (AV26-752)cccs_ca · 2026-07-28
- Arista Networks security advisory (AV26-751)cccs_ca · 2026-07-28
- Apache security advisory (AV26-749)cccs_ca · 2026-07-28
- [akira] Franz Krause artworksgroup posted to leak siteransomware_live · 2026-07-28
- JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breachthehackernews · 2026-07-28
- [incransom] https://eclmn.com/ posted to leak siteransomware_live · 2026-07-28
- Cloud Security for Payment Data: A PCI DSS Compliance Guideorca_security · 2026-07-28
- [NVD] CVE-2026-49332 (HIGH 8.5) — A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forwarded-User) but does not strip underscore-variant keys (X_Forwarded_User) from incoming requests. WSGI and PHP frameworks normalize both variants to the sanvd · 2026-07-28
- AI Changes the Software Supply Chain and How We Secure Itsonatype · 2026-07-28
- Rapid7 Cyber GRC is now available: Turn security action into compliance proofrapid7 · 2026-07-28
- The Next Evolution of MDR: Preemptive Defense and Agentic Investigationrapid7 · 2026-07-28
- Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Rootthehackernews · 2026-07-28
- [Deadlock] Takis srl posted to leak siteransomware_live · 2026-07-28
- What’s in the SOSS? Podcast #66 – S3E18 Turning AI into the Ultimate Open Source Maintainer Power Tool with Michael Winseropenssf_blog · 2026-07-28
- [Booba Project] Incredible Technologies posted to leak siteransomware_live · 2026-07-28
- We rebuilt Malwarebytes Mobile Security for the scams of todaymalwarebytes_blog · 2026-07-28
- Shared Claude chats were searchable on Googlemalwarebytes_blog · 2026-07-28
- [incransom] Della Casa Group AG posted to leak siteransomware_live · 2026-07-28
- CI Fortify – Advice for isolating vital systemscisa_advisories · 2026-07-28
- Siemens Mendix Runtimecisa_advisories · 2026-07-28
- MikroTik RouterOS and Cloud Hosted Routercisa_advisories · 2026-07-28
- Siemens SIMATIC S7-PLCSIM Advancedcisa_advisories · 2026-07-28
- Siemens Desigo CCcisa_advisories · 2026-07-28
- Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFPcisa_advisories · 2026-07-28
- ABB KNX Update Toolcisa_advisories · 2026-07-28
- igloohome Smart Lock Mobile Applicationcisa_advisories · 2026-07-28
- Introducing Attack Path Management for Entra Agents in BloodHound Enterprisespecterops · 2026-07-28
- Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relaysthehackernews · 2026-07-28
- Designing an MCP Server for AI Agents: Why Wrapping Your API Is the Wrong Abstractionspecterops · 2026-07-28
- Attack Path Management Comes to AWSspecterops · 2026-07-28
- Expanding attack path management to the AI frontierspecterops · 2026-07-28
- Update your iPhone, iPad and Mac to fix Apple security holesmalwarebytes_blog · 2026-07-28
- Vatican’s Click To Pray app exposed personal data from 700,000 usersmalwarebytes_blog · 2026-07-28
- Axon Is Another License Plate Surveillance Companyschneier · 2026-07-28
- How we use /goal to find bugs in Patch the Planettrailofbits · 2026-07-28
- [qilin] Gran valle negocios posted to leak siteransomware_live · 2026-07-28
- IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chainstalos · 2026-07-28
- Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging Inthehackernews · 2026-07-28
- Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploitthehackernews · 2026-07-28
- Mirage Kitten targets Middle East and Africa region with new malwaresecurelist · 2026-07-28
- Rapid7 and Exclusive Networks expand partnership to modernize security operations and accelerate customer successrapid7 · 2026-07-28
- Microsoft Says New Cybersecurity AI Model Helps MDASH Score 95.95% at Half the Costthehackernews · 2026-07-28
- Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flawthehackernews · 2026-07-28
- [termite] Affinia Healthcare posted to leak siteransomware_live · 2026-07-28
- [incransom] minigrip.com.mx posted to leak siteransomware_live · 2026-07-28
- [incransom] DUCON posted to leak siteransomware_live · 2026-07-28
- [incransom] greenecountyga.gov posted to leak siteransomware_live · 2026-07-28
- [incransom] foundationstofreedom.org posted to leak siteransomware_live · 2026-07-28
- Apple Products Multiple Vulnerabilitieshkcert · 2026-07-28
- [anubis] Prelys Courtage posted to leak siteransomware_live · 2026-07-28
- Not Every Fox is Silver: Inside an AtlasRAT loader chainahnlab · 2026-07-27
- [termite] JD Young posted to leak siteransomware_live · 2026-07-27
- [NVD] CVE-2026-64542 — In the Linux kernel, the following vulnerability has been resolved: ipv6: ndisc: fix NULL deref in accept_untracked_na() accept_untracked_na() re-fetches the inet6_dev with __in6_dev_get(dev) and dereferences idev->cnf.accept_untracked_na without a NULL check, even though its onvd · 2026-07-27
- The Lethal Trifecta Is Everything Zero Trust Was Built to Stopzscaler_threatlabz · 2026-07-27
- Between Two Nerds: Cyber is peopleriskybiz_news · 2026-07-27
- Erlang security advisory (AV26-750)cccs_ca · 2026-07-27
- [safepay] zinorm.de posted to leak siteransomware_live · 2026-07-27
- [safepay] moebelmayer.de posted to leak siteransomware_live · 2026-07-27
- [safepay] paritaet-nrw.org posted to leak siteransomware_live · 2026-07-27