THREAT OPS › Threat News
Threat Intelligence News
12099 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- Introducing Attack Path Management for Entra Agents in BloodHound Enterprisespecterops · 2026-07-28
- Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relaysthehackernews · 2026-07-28
- Designing an MCP Server for AI Agents: Why Wrapping Your API Is the Wrong Abstractionspecterops · 2026-07-28
- Attack Path Management Comes to AWSspecterops · 2026-07-28
- Expanding attack path management to the AI frontierspecterops · 2026-07-28
- Update your iPhone, iPad and Mac to fix Apple security holesmalwarebytes_blog · 2026-07-28
- Vatican’s Click To Pray app exposed personal data from 700,000 usersmalwarebytes_blog · 2026-07-28
- Axon Is Another License Plate Surveillance Companyschneier · 2026-07-28
- How we use /goal to find bugs in Patch the Planettrailofbits · 2026-07-28
- [qilin] Gran valle negocios posted to leak siteransomware_live · 2026-07-28
- IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chainstalos · 2026-07-28
- Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging Inthehackernews · 2026-07-28
- Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploitthehackernews · 2026-07-28
- Mirage Kitten targets Middle East and Africa region with new malwaresecurelist · 2026-07-28
- Rapid7 and Exclusive Networks expand partnership to modernize security operations and accelerate customer successrapid7 · 2026-07-28
- Microsoft Says New Cybersecurity AI Model Helps MDASH Score 95.95% at Half the Costthehackernews · 2026-07-28
- Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flawthehackernews · 2026-07-28
- [termite] Affinia Healthcare posted to leak siteransomware_live · 2026-07-28
- [incransom] minigrip.com.mx posted to leak siteransomware_live · 2026-07-28
- [incransom] DUCON posted to leak siteransomware_live · 2026-07-28
- [incransom] greenecountyga.gov posted to leak siteransomware_live · 2026-07-28
- [incransom] foundationstofreedom.org posted to leak siteransomware_live · 2026-07-28
- Apple Products Multiple Vulnerabilitieshkcert · 2026-07-28
- [anubis] Prelys Courtage posted to leak siteransomware_live · 2026-07-28
- Not Every Fox is Silver: Inside an AtlasRAT loader chainahnlab · 2026-07-27
- [termite] JD Young posted to leak siteransomware_live · 2026-07-27
- [NVD] CVE-2026-64542 — In the Linux kernel, the following vulnerability has been resolved: ipv6: ndisc: fix NULL deref in accept_untracked_na() accept_untracked_na() re-fetches the inet6_dev with __in6_dev_get(dev) and dereferences idev->cnf.accept_untracked_na without a NULL check, even though its onvd · 2026-07-27
- The Lethal Trifecta Is Everything Zero Trust Was Built to Stopzscaler_threatlabz · 2026-07-27
- Between Two Nerds: Cyber is peopleriskybiz_news · 2026-07-27
- Erlang security advisory (AV26-750)cccs_ca · 2026-07-27
- [safepay] zinorm.de posted to leak siteransomware_live · 2026-07-27
- [safepay] moebelmayer.de posted to leak siteransomware_live · 2026-07-27
- [safepay] paritaet-nrw.org posted to leak siteransomware_live · 2026-07-27
- [safepay] haugbuersten.de posted to leak siteransomware_live · 2026-07-27
- [safepay] landesmuseum.de posted to leak siteransomware_live · 2026-07-27
- [safepay] hst.eu posted to leak siteransomware_live · 2026-07-27
- [safepay] braywoodschool.co.uk posted to leak siteransomware_live · 2026-07-27
- Aftercall ads are driving Android users crazymalwarebytes_blog · 2026-07-27
- [safepay] weier.org posted to leak siteransomware_live · 2026-07-27
- [safepay] bnpdist.com posted to leak siteransomware_live · 2026-07-27
- [chaos] vit-best.com posted to leak siteransomware_live · 2026-07-27
- [NVD] CVE-2026-17570 (MEDIUM 4.3) — Improper access control in the PAM password history endpoints in Devolutions Server allows an authenticated low-privileged user to disclose plaintext credential secrets via crafted API requests. This issue affects : * Devolutions Server 2026.2.4.0 through 2026.2.12.0 * Denvd · 2026-07-27
- [NVD] CVE-2026-17569 (MEDIUM 4.3) — Improper access control in the NetBox synchronizer in Devolutions Server allows an authenticated user with view-only permission on an entry to obtain a stored API token via the partial connection endpoint. This issue affects : * Devolutions Server 2026.2.4.0 through 2026.2.1nvd · 2026-07-27
- [NVD] CVE-2026-17568 (HIGH 8.8) — Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-administrative user holding the user-group membership management permission to escalate privileges to administrator via a crafted API request. This issue affects nvd · 2026-07-27
- Fortinet security advisory (AV26-109) – Update 1cccs_ca · 2026-07-27
- Redis security advisory (AV26-748)cccs_ca · 2026-07-27
- NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Frameworkthehackernews · 2026-07-27
- Microsoft security advisory (AV26-747)cccs_ca · 2026-07-27
- [NVD] CVE-2026-24252 (HIGH 7.8) — NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection. A successful exploit of this vulnerability may lead to code execution, data tampering, escalation of privileges and information disclosure.nvd · 2026-07-27
- Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruptionthehackernews · 2026-07-27
- Qualys Expands Serverless Security with Vulnerability Scanning for AWS Lambdaqualys · 2026-07-27
- Rethinking security for the age of AImsstic · 2026-07-27
- Enhancing AI security through global AI red teamingmsstic · 2026-07-27
- 27th July – Threat Intelligence Reportcheckpoint_research · 2026-07-27
- Sextortion scammers are exploiting ShinyHunters data leaksmalwarebytes_blog · 2026-07-27
- The Sub-10-Minute Cloud Takeover: How Exposed IAM Keys, Misconfiguration and AI Are Rewriting the Rules of Cloud Breachesqualys · 2026-07-27
- Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoorzscaler_threatlabz · 2026-07-27
- Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flawthehackernews · 2026-07-27
- What’s your data worth on the dark web? (Lock and Code S07E15)malwarebytes_blog · 2026-07-27
- World Wide Technology and Horizon3 Launch Strategic Partnership to Rewrite the Cybersecurity Playbook for the AI Erahorizon3 · 2026-07-27
- The New Measure of Infrastructure Readinesshorizon3 · 2026-07-27
- ⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and Morethehackernews · 2026-07-27
- n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Processthehackernews · 2026-07-27
- [shinyhunters] BH Security, LLC. (brinkshome.com) posted to leak siteransomware_live · 2026-07-27
- [shinyhunters] RingCentral, Inc. posted to leak siteransomware_live · 2026-07-27
- [shinyhunters] Ernst & Young posted to leak siteransomware_live · 2026-07-27
- APTs Top the List of Most Active Threat Actors in H1 2026cyble · 2026-07-27
- Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Updatethehackernews · 2026-07-27
- CISA Adds Two Known Exploited Vulnerabilities to Catalogcisa_advisories · 2026-07-27
- [qilin] Savills France posted to leak siteransomware_live · 2026-07-27
- [qilin] Wilbert's posted to leak siteransomware_live · 2026-07-27
- Cognyte Sells a Mobile Cell Surveillance Vanschneier · 2026-07-27
- Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malwarethehackernews · 2026-07-27
- [NVD] CVE-2026-17527 (HIGH 7.7) — In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to provide read-only access to CDI resources, includes a rule granting create on the datavolumes/source subresource. CDI's DataVolume clone authorization accepts this permission as sufnvd · 2026-07-27
- Java Spring Boot "heapdump" scans, (Mon, Jul 27th)sans_isc · 2026-07-27
- TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governmentsthehackernews · 2026-07-27
- [NVD] CVE-2026-64531 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: reject oversized nested action attrs Open vSwitch stores generated flow actions as nlattrs, whose nla_len field is u16. Commit a1e64addf3ff ("net: openvswitch: remove misbehaving actions lengtnvd · 2026-07-27
- GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoptionthehackernews · 2026-07-27
- A week in security (July 20 – July 26)malwarebytes_blog · 2026-07-27
- Risky Bulletin: A JSON RCE bug is about to rock the Java worldriskybiz_news · 2026-07-27
- [dragonforce] Katathani Phuket Beach Resort posted to leak siteransomware_live · 2026-07-27
- [CRPxO] IPTV Platform posted to leak siteransomware_live · 2026-07-27
- [CRPxO] Marketech posted to leak siteransomware_live · 2026-07-27
- [CRPxO] American Hospice & Home Health Services (Ahhh Care) posted to leak siteransomware_live · 2026-07-27
- [CRPxO] Bright Star Partners Insurance posted to leak siteransomware_live · 2026-07-27
- [CRPxO] eCare Platform posted to leak siteransomware_live · 2026-07-27
- [CRPxO] Dignity Phoenix posted to leak siteransomware_live · 2026-07-27
- [CRPxO] Schorr Law posted to leak siteransomware_live · 2026-07-27
- [CRPxO] Simpkins Law Firm posted to leak siteransomware_live · 2026-07-27
- [CRPxO] Leah Walker Orthodontics posted to leak siteransomware_live · 2026-07-27
- [CRPxO] Elko Dental Specialists posted to leak siteransomware_live · 2026-07-27
- [Deadlock] Hardware Asesorias Software Ltda posted to leak siteransomware_live · 2026-07-27
- [Deadlock] Tesco Engineer posted to leak siteransomware_live · 2026-07-27
- [Global Secret Group] Louisiana Coalition Against | Domestic Violence posted to leak siteransomware_live · 2026-07-27
- [CRPxO] ProSmile Family Dental Care posted to leak siteransomware_live · 2026-07-27
- [CRPxO] Qube Aviation Catering posted to leak siteransomware_live · 2026-07-27
- [CRPxO] Performance Data Solutions posted to leak siteransomware_live · 2026-07-27
- [CRPxO] Host & Protect (RedBlink) posted to leak siteransomware_live · 2026-07-27
- [CRPxO] RnnR Cloud posted to leak siteransomware_live · 2026-07-27
- [CRPxO] CodeConductor.ai posted to leak siteransomware_live · 2026-07-27