THREAT OPS › Threat News
Threat Intelligence News
12107 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCEthehackernews · 2026-07-25
- DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payoutsthehackernews · 2026-07-25
- [NVD] CVE-2026-61884 (CRITICAL 9.8) — The Tycon Systems TPDIN-Monitor-WEB2 ships without HTTP credentials configured, intended for an installer to set them on first use. On firmware 2.4.4 and earlier, a unit left in this unconfigured state serves the web management interface without requiring any login. An attacker wnvd · 2026-07-24
- [NVD] CVE-2026-55985 (MEDIUM 4.3) — The web management interface in Tycon Systems TPDIN-Monitor-WEB2 stores and displays system credentials in cleartext on a certain configuration page accessible to authenticated users. Any party with access to the administrative dashboard can immediately read these credentials, wnvd · 2026-07-24
- Friday Squid Blogging: Illex Squid Catch in the Falklandsschneier · 2026-07-24
- Progress security advisory (AV26-746)cccs_ca · 2026-07-24
- [NVD] CVE-2026-17107 (HIGH 8.5) — A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first removing caller-supplied values,nvd · 2026-07-24
- HPE security advisory (AV26-745)cccs_ca · 2026-07-24
- MongoDB security advisory (AV26-744)cccs_ca · 2026-07-24
- Ericsson security advisory (AV26-743)cccs_ca · 2026-07-24
- [NVD] CVE-2026-64210 (HIGH 7.5) — In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: xsk: Fix unlocked writing to ICOSQ During napi poll, when the affinity changes and there's still XSK work to be done, we trigger an ICOSQ interrupt on the new CPU. However, this triggering on the ICOnvd · 2026-07-24
- [NVD] CVE-2026-17059 (MEDIUM 6.5) — A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access management solution. The issue occurs because the system fails to check if an administrator has permission to view individual users when lnvd · 2026-07-24
- BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Deliverythehackernews · 2026-07-24
- Case Study: Targeted Attack Case on an MS-SQL Server Involving the Installation of GotoHTTP and SoftEther VPNahnlab · 2026-07-24
- Don’t get fooled by TikTok resin art scamsmalwarebytes_blog · 2026-07-24
- Call of Duty Mobile scam uses fake free points to steal player accountsmalwarebytes_blog · 2026-07-24
- 5 AI Security Challenges in 2026 and Why They Mattervaronis_blog · 2026-07-24
- OpenAI’s agent escaped its sandbox during a security testmalwarebytes_blog · 2026-07-24
- How Iran Uses Cellular Infrastructure to Target US Military Phonescitizenlab · 2026-07-24
- [Control Systems] Moxa security advisory (AV26-742)cccs_ca · 2026-07-24
- Google Chrome security advisory (AV26-741)cccs_ca · 2026-07-24
- [NVD] CVE-2026-17048 (MEDIUM 5.5) — A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs when the system processes requests for rotated client secrets that are stored in a secure vault. Due to improper boundary enforcement, a delegated administrator nvd · 2026-07-24
- Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controllerthehackernews · 2026-07-24
- Updated Cyber Threat Actor Naming Systemmandiant_gti · 2026-07-24
- Microsoft Edge security advisory (AV26-740)cccs_ca · 2026-07-24
- Autonomously Hide, Segment, and Shield: Private App Defense for the AI Erazscaler_threatlabz · 2026-07-24
- Google wants to store a selfie video of your facemalwarebytes_blog · 2026-07-24
- Security as a Business Enabler: A Guide for Modern CISOsorca_security · 2026-07-24
- Cloud Security Assessment: A Complete Guide for Security Teamsorca_security · 2026-07-24
- [NVD] CVE-2026-16730 (MEDIUM 5.5) — A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer setup (notably SO_PEERPIDFD) are handled as fatal failures, causing the broker to exit. A local attacker who can open many connections to the user session bus can nvd · 2026-07-24
- Beyond the Play Store: How Android threats really spreadmalwarebytes_blog · 2026-07-24
- ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Linkthehackernews · 2026-07-24
- Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Serversthehackernews · 2026-07-24
- Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Dothehackernews · 2026-07-24
- Why AI Needs a “Genie Coefficient”schneier · 2026-07-24
- Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministrythehackernews · 2026-07-24
- Golden Chickens Resurfaces With Four New Malware Families and Modular Implantsthehackernews · 2026-07-24
- Multiple Vulnerabilities in Internet-Facing Systems Targeting Hong Kong’s Education Sectorhkcert · 2026-07-24
- NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chatsthehackernews · 2026-07-24
- Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Saythehackernews · 2026-07-24
- Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacksthehackernews · 2026-07-24
- [NVD] CVE-2026-11922 (MEDIUM 6.5) — A vulnerability in zenml-io/zenml versions 0.57.0 through 0.94.2 allows an attacker to bypass rate-limiting on the `POST /api/v1/login` and self password-change endpoints by rotating the `X-Forwarded-For` header. The rate limiter keys requests by `request.client.host`, which is dnvd · 2026-07-24
- Risky Bulletin: Western cyber agencies warn of Russian hacks of Zimbra serversriskybiz_news · 2026-07-24
- MongoDB Multiple Vulnerabilitieshkcert · 2026-07-24
- Google Chrome Multiple Vulnerabilitieshkcert · 2026-07-24
- Microsoft Edge Multiple Vulnerabilitieshkcert · 2026-07-24
- Inside Elastic InfoSec's agentic SOC: When to inline your agent's skills for a 5× cost reductionelastic_security · 2026-07-24
- Ransomware is the Scoreboardrecordedfuture · 2026-07-24
- [NVD] CVE-2026-6924 — A bug in the entropy initialization for SiWx917 causes the DRBG to use a predictable seed. As such, all random numbers generated in the Matter code use the same stream of numbers. This vulnerability was discovered after the impacted repository was already deprecated.nvd · 2026-07-23
- [NVD] CVE-2026-15630 (CRITICAL 9.9) — A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body).nvd · 2026-07-23
- Wordfence Intelligence Weekly WordPress Vulnerability Report (July 13, 2026 to July 19, 2026)wordfence · 2026-07-23
- [NVD] CVE-2026-65918 (HIGH 7.1) — PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vulnerability in the GIF decoder's read_from_tensor callback that passes unclamped length to memcpy. Attackers can supply malicious or truncated GIF files to cause denial of service vnvd · 2026-07-23
- Don’t swing at everythingtalos · 2026-07-23
- Verification Closes the Loophorizon3 · 2026-07-23
- A New Threat Landscape Meets A New Kind of Defenderwordfence · 2026-07-23
- OpenAI Agents Escape Testing Sandbox and Breach Hugging Face Production Infrastructureorca_security · 2026-07-23
- [NVD] CVE-2026-43823 (HIGH 7.5) — When initializing an RSA public key from DER or PEM bytes throws an error, the EVP_PKEY* is double-freed: first in the catch block, then in the deinit. This can lead to a crash on future memory allocations. This double-free manifests when BoringSSL cannot decode the public key frnvd · 2026-07-23
- [NVD] CVE-2026-43820 (HIGH 7.7) — NIOSSLCertificate._subjectAlternativeNames provides access to the raw bytes for a cert's SANs. NIOSSL provides access to a buffer assumed to be backed by an ASN1_STRING, but not all SANs are backed by ASN1_STRING, so accessing the buffer for such a type can lead to out-of-bounds nvd · 2026-07-23
- June 2026 Threat Trend Report on APT Attacks (South Korea)ahnlab · 2026-07-23
- Email threat landscape: Q2 2026 trends and insightsmsstic · 2026-07-23
- JetBrains security advisory (AV26-739)cccs_ca · 2026-07-23
- Russian Global Webmail Espionageunit42 · 2026-07-23
- The Flashpoint Method: Prioritizing Vulnerabilities in an Era of AI-Accelerated Discoveryflashpoint · 2026-07-23
- Microsoft security advisory – July 2026 monthly rollup (AV26-698) – Update 3cccs_ca · 2026-07-23
- Unified Security Platform: Everything Security Leaders Should Knoworca_security · 2026-07-23
- Security Operating Model: Building a Modern Security Programorca_security · 2026-07-23
- What Happened Between OpenAI and Hugging Face?rapid7 · 2026-07-23
- Check Point security advisory (AV26-735) – Update 1cccs_ca · 2026-07-23
- Your LLM Is Showing: New Data Finds Sharp Rise in Exposed AI Toolsduo_decipher · 2026-07-23
- Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suitecisa_advisories · 2026-07-23
- MZ Automation libIEC61850cisa_advisories · 2026-07-23
- Rockwell Automation ThinManagercisa_advisories · 2026-07-23
- Johnson Controls XAAP Androidcisa_advisories · 2026-07-23
- Panduit IntraVUEcisa_advisories · 2026-07-23
- Johnson Controls C-CURE 9000 and Victor application servercisa_advisories · 2026-07-23
- MZ Automation lib60870cisa_advisories · 2026-07-23
- Weintek cMT3092Xcisa_advisories · 2026-07-23
- How Synthetic Identity Fraud is Coming for Machine Identitiesthehackernews · 2026-07-23
- Millions of cars could be tracked and unlocked by a hidden security flawmalwarebytes_blog · 2026-07-23
- WhatsApp Web chats exposed by Adobe’s Acrobat extension flawmalwarebytes_blog · 2026-07-23
- [NVD] CVE-2026-16745 (HIGH 8.8) — A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker nvd · 2026-07-23
- End-to-End Encryption and “Going Dark”schneier · 2026-07-23
- Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channeltalos · 2026-07-23
- Preview: Cisco Talos at Black Hat USA 2026talos · 2026-07-23
- 2026-009: Critical Vulnerabilities in Microsoft SharePointcert_eu · 2026-07-23
- Srsly Risky Biz: Knives are out for open-weight AI modelsriskybiz_news · 2026-07-23
- Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Accessthehackernews · 2026-07-23
- [NVD] CVE-2026-6390 (MEDIUM 6.8) — A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one triggers an ALERT-level error, a specially crafted filename containing printf format specifiers can be reinterpreted. This format string vulnerability may allownvd · 2026-07-23
- ZDI-26-452: Dify AI Workflow oauth_redirect_url Open Redirect Vulnerabilityzdi_published · 2026-07-23
- IBM WebSphere Products Multiple Vulnerabilitieshkcert · 2026-07-23
- A project is publishing full analyses of AI-discovered 0-days - first batch of 10 with reproducible exploitsfulldisclosure · 2026-07-23
- Synology stale DNS allows practical interception of traffic from vulnerable DSM clientsfulldisclosure · 2026-07-23
- Amplitude customers using domain proxies should update their configuration immediately.fulldisclosure · 2026-07-23
- TSUBAME Report Overflow (Jan-Mar 2026)jpcert_blog · 2026-07-23
- TAG-195 Upgrades MaaS Ecosystem with Modular Toolsrecordedfuture · 2026-07-23
- How Elasticsearch ES|QL COMPLETION turns noisy curl and wget rules into high-fidelity cloud security alertselastic_security · 2026-07-23
- wp2shell hits WordPress: detecting pre-auth RCE from plugin drop to command executionelastic_security · 2026-07-23
- Zscaler CXO Monthly Roundup | June 2026zscaler_threatlabz · 2026-07-22
- How to Find Which ISP is Slowing Down Your Userszscaler_threatlabz · 2026-07-22
- CVE-2026-60167, CVE-2026-60168, CVE-2026-60169 & CVE-2026-60170 | Oracle Hospitality Simphony Multiple Vulnerabilitieshorizon3 · 2026-07-22