THREAT OPS › Threat News
Threat Intelligence News
12115 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- PSA: WordPress Core Patched Unauthenticated Remote Code Execution Vulnerability Chainwordfence · 2026-07-17
- Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitationvolexity · 2026-07-17
- Friday Squid Blogging: Squid Washing Up on Cape Cod Beachschneier · 2026-07-17
- [NVD] CVE-2026-16118 (HIGH 7.1) — A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/nvd · 2026-07-17
- Metasploit Wrap Up: An HTTP to SMB relay plus Payload Improvementsrapid7 · 2026-07-17
- Microsoft Edge security advisory (AV26-714)cccs_ca · 2026-07-17
- US Military Smartphones Targeted Through Roaming and Ad Techcitizenlab · 2026-07-17
- [NVD] CVE-2026-16108 (MEDIUM 4.3) — A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. This component is responsible for managing groups that are automatically assigned to new users within a realm. The issue allows a delegated administrator with realm-viewing permissions to snvd · 2026-07-17
- [NVD] CVE-2026-16106 (MEDIUM 4.9) — A flaw was found in the admin REST API of Keycloak, a solution for identity and access management. The issue occurs when a delegated administrator attempts to remove a child role from a composite role. Due to missing authorization checks, an attacker with limited administrative pnvd · 2026-07-17
- [NVD] CVE-2026-16104 (MEDIUM 4.3) — A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycloak identity and access management. The issue occurs because the system fails to mask sensitive configuration values, such as reCAPnvd · 2026-07-17
- [NVD] CVE-2026-16103 (MEDIUM 4.3) — A flaw was found in the keycloak-services component of Keycloak. This issue is an incomplete fix for CVE-2026-9798, where brute-force protection checks were added to the Client-Initiated Backchannel Authentication (CIBA) initiation handler but were omitted from the token redemptinvd · 2026-07-17
- [NVD] CVE-2026-16093 (MEDIUM 5.4) — Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. A flaw was discovered where this enforcement can be bypassed. An attacker with valid client credentials can provide a fanvd · 2026-07-17
- Extending Zero Trust to the Browser: A New Frontier for Enterprise Securityzscaler_threatlabz · 2026-07-17
- Microsoft at Black Hat USA 2026: Defending trust in the age of AI and supply chain attacksmsstic · 2026-07-17
- Google Chrome security advisory (AV26-713)cccs_ca · 2026-07-17
- [NVD] CVE-2026-16089 (MEDIUM 5.4) — A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs because OAuth 2.0 authorization codes are not properly bound to the client that originally requested them. An attacker who can intercept an authorization code can modify it to be renvd · 2026-07-17
- Broadcom VMware security advisory (AV26-712)cccs_ca · 2026-07-17
- Inside Qilin Ransomware: Custom Rust Loader and Kernel-Level EDR Killerflashpoint · 2026-07-17
- [NVD] CVE-2026-16072 (MEDIUM 4.9) — A flaw was found in the organization management component of Keycloak. A delegated administrator with permission to manage organizations can create an invitation for a non-existent email address and then retrieve the secret registration link directly through the application progrnvd · 2026-07-17
- FreePBX security advisory (AV26–711)cccs_ca · 2026-07-17
- The Joy and Pain of OT Cybersecurity: A Conversation With Lesley Carhartduo_decipher · 2026-07-17
- [NVD] CVE-2026-15943 (MEDIUM 5.5) — A flaw was found in the Keycloak keycloak-services component, which handles the management of identity providers. The issue occurs when a delegated administrator updates an OIDC identity provider using a masked client secret sentinel value. Due to improper validation, Keycloak renvd · 2026-07-17
- Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogyunit42 · 2026-07-17
- Google Chrome Multiple Vulnerabilitieshkcert · 2026-07-17
- IBM WebSphere Products Security Restriction Bypass Vulnerabilityhkcert · 2026-07-17
- Tracking Advanced Persistent Threat Groups | Recorded Futurerecordedfuture · 2026-07-17
- ACR Stealer: Two observed intrusion chains amid increased threat activitymsstic · 2026-07-16
- AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Reportunit42 · 2026-07-16
- Wordfence Intelligence Weekly WordPress Vulnerability Report (July 6, 2026 to July 12, 2026)wordfence · 2026-07-16
- Fortinet security advisory (AV26-351) – Update 2cccs_ca · 2026-07-16
- Fortinet security advisory (AV26-568) – Update 1cccs_ca · 2026-07-16
- [NVD] CVE-2026-15945 (MEDIUM 4.3) — A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching fonvd · 2026-07-16
- Begun, the Patch Wars havetalos · 2026-07-16
- CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilitiestenable · 2026-07-16
- [Security Blog] Modern Software’s Hidden Cost: Managing Risk in the Open-Source Ecosystemhkcert · 2026-07-16
- Least privilege for AI agents: Identity, access, and tool bindingmsstic · 2026-07-16
- Attack Cases by the Kimsuky Group Impersonating Diplomats (PebbleDash, PrxClient)ahnlab · 2026-07-16
- [NVD] CVE-2026-5674 (HIGH 8.8) — A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio compatibility layer. An attacker with minimal permissions within a sandboxed environment can load a malinvd · 2026-07-16
- Fit for Detection: Hunting U-Boot Vulnerabilities at Scalebinarly · 2026-07-16
- Demystifying AI Exploits: A Blueprint for AI-Assisted Vulnerability Managementmandiant_gti · 2026-07-16
- Navigating The OpenSSF is as Easy as Floating Down A Lazy Riveropenssf_blog · 2026-07-16
- HelloNet campaign: new malicious modules launched through the ViPNet update systemsecurelist · 2026-07-16
- The best defenders build AI agents together: Join Tenable for SWARM at Black Hat ’26tenable · 2026-07-16
- Sunsetting the Public AttackerKB Platformrapid7 · 2026-07-16
- The TTF Trap: A Global Campaign of a Low-Detection Lua Loaderfortinet_research · 2026-07-16
- GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltrationsecurelist · 2026-07-16
- NASA Core Flight System (cFS) Health & Safety (HS) Applicationcisa_ics · 2026-07-16
- Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogixcisa_ics · 2026-07-16
- Rockwell Automation Flex 5000 Adaptercisa_ics · 2026-07-16
- SALTO ProAccess Spacecisa_ics · 2026-07-16
- AutomationDirect Productivity Suitecisa_ics · 2026-07-16
- Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBTcisa_ics · 2026-07-16
- [NVD] CVE-2026-22752 (CRITICAL 9.6) — Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affects Spring Authorization Server: from 7.0.0 through 7.0.4, from 1.5.0 through 1.5.6, from 1.4.0 through 1.4.9, from 1.3.0 through 1.3.10.nvd · 2026-07-16
- The Hunter's Paradox: Is it time to embrace automated threat hunting?talos · 2026-07-16
- UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaigntalos · 2026-07-16
- From Indirect Prompt Injection to DNS Exfiltration in macOS Terminalembracethered · 2026-07-16
- Standardizing SSL Key Logging: A Step Forward for Secure Diagnosticszscaler_threatlabz · 2026-07-16
- Srsly Risky Biz: Ransomware uses AI to amp up negotiationsriskybiz_news · 2026-07-16
- [NVD] CVE-2026-53366 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: ipv4: account for fraggap on the paged allocation path In __ip_append_data(), when the paged-allocation branch is taken, alloclen and pagedlen are computed as alloclen = fragheaderlen + transhdrlen; pagedlennvd · 2026-07-16
- [NotCVE-2026-0001] Cloudflare Universal SSL CAA augmentation weakens RFC 8657 account binding — CVE-2026-14440 assigned 163 days after public no-CVE disclosurefulldisclosure · 2026-07-16
- Subject: Advisory Submission: EZ Game Booster - Cleartext Storage of Sensitive Credentials (CWE-312)fulldisclosure · 2026-07-16
- CVE-2026-56877 - Skillable SCORM userId authorisation bypassfulldisclosure · 2026-07-16
- Google Chrome Multiple Vulnerabilitieshkcert · 2026-07-16
- Zoom Products Multiple Vulnerabilitieshkcert · 2026-07-16
- Samsung Products Multiple Vulnerabilitieshkcert · 2026-07-16
- Unpacking the AsyncAPI npm supply chain compromise and import-time payload deliverymsstic · 2026-07-16
- [NVD] CVE-2026-1609 (HIGH 8.1) — A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user account is disabled, Keycloak fails to validate the user’s disabled status during JWT authorization grant processing. A remote attacker with low privileges can exnvd · 2026-07-16
- TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chainselastic_security · 2026-07-16
- [CISA KEV] CVE-2026-25089 — Fortinet FortiSandbox: Fortinet FortiSandbox OS Command Injection Vulnerabilitycisa_kev · 2026-07-16
- [CISA KEV] CVE-2026-39808 — Fortinet FortiSandbox: Fortinet FortiSandbox OS Command Injection Vulnerabilitycisa_kev · 2026-07-16
- AI Has Enhanced Iran’s Asymmetric Playbook During the 2026 Conflictrecordedfuture · 2026-07-16
- [CISA KEV] CVE-2026-58644 — Microsoft SharePoint: Microsoft SharePoint Deserialization of Untrusted Data Vulnerabilitycisa_kev · 2026-07-16
- Empower Security Teams to See More and Respond Faster to Modern Threats with Zscaler Endpoint Contextzscaler_threatlabz · 2026-07-15
- The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15)unit42 · 2026-07-15
- When Attackers Wield Frontier AI: How to Keep Your Private Apps Unbreachablezscaler_threatlabz · 2026-07-15
- Why “Least Privilege” Fails in Real Environmentsspecterops · 2026-07-15
- Bug in Cursor Allows Simple RCEduo_decipher · 2026-07-15
- Cisco Advance Notification for Publication of July 15, 2026, Security Advisoriescisco_psirt · 2026-07-15
- Turning threat intelligence into decisive action with Defender Expertsmsstic · 2026-07-15
- [Security Blog] StrikeShark Campaign Exploits Known Vulnerabilities to Deploy Cobalt Strike via SharkLoaderhkcert · 2026-07-15
- Cisco RoomOS Security Hardening Release: July 2026cisco_psirt · 2026-07-15
- Cisco Identity Services Engine Path Traversal Vulnerabilitycisco_psirt · 2026-07-15
- There and Back Again: An Operators Guide on NTLM Relaying Egressspecterops · 2026-07-15
- Understanding Claude Tag’s access model in Slack and how to configure it securelytenable · 2026-07-15
- Security Issues in the Korean & Global Financial Sector in June 2026ahnlab · 2026-07-15
- June 2026 Threat Trend Report on Ransomwareahnlab · 2026-07-15
- Ransom & Dark Web Issues Week 3, July 2026ahnlab · 2026-07-15
- ClaudeFix: Shared Claude Chats Meet ClickFixzscaler_threatlabz · 2026-07-15
- The Risk of Exposed Cloud Functions and How to Hardenmandiant_gti · 2026-07-15
- Investigating Persistence Mechanisms in AWSrapid7 · 2026-07-15
- 5 reasons to bring application security data into your exposure management platformtenable · 2026-07-15
- TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Developmentunit42 · 2026-07-15
- OkoBot: new sophisticated malware framework targets cryptocurrency userssecurelist · 2026-07-15
- Open Source, Open Infrastructure, and the Space Betweensonatype · 2026-07-15
- ZDI-26-444: 7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerabilityzdi_published · 2026-07-15
- ZDI-26-440: Fuji Electric Tellus pcid64 Driver Untrusted Pointer Dereference Denial of Service Vulnerabilityzdi_published · 2026-07-15
- ZDI-26-439: Fuji Electric Tellus pcid64 Driver Exposed Dangerous Method Local Privilege Escalation Vulnerabilityzdi_published · 2026-07-15
- ZDI-26-438: Rockwell Automation Arena Simulation DOE File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerabilityzdi_published · 2026-07-15
- ZDI-26-436: (Pwn2Own) Autel MaxiCharger AC Elite Home USB Heap-based Buffer Overflow Arbitrary Code Execution Vulnerabilityzdi_published · 2026-07-15
- ZDI-26-435: (Pwn2Own) Autel MaxiCharger AC Elite Home NFC Stack-based Buffer Overflow Arbitrary Code Execution Vulnerabilityzdi_published · 2026-07-15