THREAT OPS › Threat News
Threat Intelligence News
12120 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- ZDI-26-440: Fuji Electric Tellus pcid64 Driver Untrusted Pointer Dereference Denial of Service Vulnerabilityzdi_published · 2026-07-15
- ZDI-26-439: Fuji Electric Tellus pcid64 Driver Exposed Dangerous Method Local Privilege Escalation Vulnerabilityzdi_published · 2026-07-15
- ZDI-26-438: Rockwell Automation Arena Simulation DOE File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerabilityzdi_published · 2026-07-15
- ZDI-26-436: (Pwn2Own) Autel MaxiCharger AC Elite Home USB Heap-based Buffer Overflow Arbitrary Code Execution Vulnerabilityzdi_published · 2026-07-15
- ZDI-26-435: (Pwn2Own) Autel MaxiCharger AC Elite Home NFC Stack-based Buffer Overflow Arbitrary Code Execution Vulnerabilityzdi_published · 2026-07-15
- ZDI-26-434: (Pwn2Own) Autel MaxiCharger AC Elite Home USB Authentication Bypass Vulnerabilityzdi_published · 2026-07-15
- ZDI-26-433: (Pwn2Own) Autel MaxiCharger AC Elite Home Software Update Improper Verification of Cryptographic Signature Arbitrary Code Execution Vulnerabilityzdi_published · 2026-07-15
- ZDI-26-432: G DATA Total Security Backup Service Link Following Local Privilege Escalation Vulnerabilityzdi_published · 2026-07-15
- ZDI-26-431: ASUS Business Manager Service Client-Side Authentication Local Privilege Escalation Vulnerabilityzdi_published · 2026-07-15
- ZDI-26-430: MSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalation Vulnerabilityzdi_published · 2026-07-15
- ZDI-26-429: NVIDIA NeMo Framework Deserialization of Untrusted Data Remote Code Execution Vulnerabilityzdi_published · 2026-07-15
- ZDI-26-427: WatchGuard FireWare OS iked ike2_hmac Null Pointer Dereference Denial-of-Service Vulnerabilityzdi_published · 2026-07-15
- ZDI-26-425: OpenSSL OCSP Stapling Verification Double Free Remote Code Execution Vulnerabilityzdi_published · 2026-07-15
- ZDI-26-424: Synology DiskStation DS925+ MailPlus Improper Restriction of Communication Channel to Intended Endpoints Vulnerabilityzdi_published · 2026-07-15
- ZDI-26-422: Samsung rlottie Numeric Truncation Remote Code Execution Vulnerabilityzdi_published · 2026-07-15
- ZDI-26-420: Adobe Creative Cloud AGSService Incorrect Permission Assignment Local Privilege Escalation Vulnerabilityzdi_published · 2026-07-15
- ZDI-26-419: Adobe Creative Cloud AdobeUpdateService Uncontrolled Search Path Element Local Privilege Escalation Vulnerabilityzdi_published · 2026-07-15
- ZDI-26-418: Microsoft SharePoint SPFieldMultiLineText Cross-Site Scripting Vulnerabilityzdi_published · 2026-07-15
- ZDI-26-417: Microsoft Windows ServerManager Exposed Dangerous Method Local Privilege Escalation Vulnerabilityzdi_published · 2026-07-15
- ZDI-26-416: Microsoft Hyper-V netvsc Out-Of-Bounds Read Local Privilege Escalation Vulnerabilityzdi_published · 2026-07-15
- ZDI-26-415: Microsoft Windows WMI Providers Incorrect Authorization Local Privilege Escalation Vulnerabilityzdi_published · 2026-07-15
- ZDI-26-414: Microsoft PowerShell Help Directory Traversal Remote Code Execution Vulnerabilityzdi_published · 2026-07-15
- ZDI-26-411: NVIDIA NVTabular Pickle File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerabilityzdi_published · 2026-07-15
- ZDI-26-410: NVIDIA NeMo Framework Deserialization of Untrusted Data Remote Code Execution Vulnerabilityzdi_published · 2026-07-15
- ZDI-26-409: X.Org Server Glamor Font Heap-based Buffer Overflow Privilege Escalation Vulnerabilityzdi_published · 2026-07-15
- ZDI-26-408: X.Org Server ComputeScaledProperties Heap-based Buffer Overflow Privilege Escalation Vulnerabilityzdi_published · 2026-07-15
- ZDI-26-407: X.Org Server PCF Font Parsing Heap-based Buffer Overflow Privilege Escalation Vulnerabilityzdi_published · 2026-07-15
- ZDI-26-406: X.Org Server BitmapScaleBitmaps Integer Overflow Privilege Escalation Vulnerabilityzdi_published · 2026-07-15
- ZDI-26-405: X.Org Server GLX Extension Use-After-Free Privilege Escalation Vulnerabilityzdi_published · 2026-07-15
- [NVD] CVE-2026-15030 — Out-of-bounds Read in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to read memory regions beyond the intended firmware boundary by supplying a crafted IOCTL request that bypasses the validation. Refer to tnvd · 2026-07-15
- [NVD] CVE-2026-15029 — Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to perform arbitrary physical memory read and write operations via crafted IOCTL requests to the driver, bypassing OS-enforced nvd · 2026-07-15
- [NVD] CVE-2026-13585 — Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS Business Manager allow a local administrator to disclose sensitive information via crafted IOCTL requests, whinvd · 2026-07-15
- Unsealed DoJ Indictment Targets Bulletproof Hosting Servicesduo_decipher · 2026-07-15
- [CISA KEV] CVE-2026-46817 — Oracle E-Business Suite: Oracle E-Business Suite Improper Privilege Management Vulnerabilitycisa_kev · 2026-07-15
- [CISA KEV] CVE-2023-4346 — KNX Association KNX Protocol Connection Authorization Option 1: KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerabilitycisa_kev · 2026-07-15
- The Shift: A New Era of AI Regulationrecordedfuture · 2026-07-15
- [Breach] Exact Sciences — 10,869,543 accounts exposedhibp_breaches · 2026-07-15
- Demystifying Key Exchange: From Classical ECDHE to a Post-Quantum Futurezscaler_threatlabz · 2026-07-14
- [NVD] CVE-2026-45363 (CRITICAL 9.1) — ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard. Prior to 2.10.3 and 3.2.0, JWT.decode(token, '', true, algorithm: 'HS256') accepts an attacker-forged token because OpenSSL::HMAC.digest('SHA256', '', payload) returns a valid digest under an empty knvd · 2026-07-14
- Patch Tuesday - July 2026rapid7 · 2026-07-14
- Why Delaying WordPress Updates Increases Security Riskssucuri_blog · 2026-07-14
- Microsoft and Adobe Patch Tuesday, July 2026 Security Update Reviewqualys · 2026-07-14
- [NVD] CVE-2026-24220 (MEDIUM 6.4) — NVIDIA TensorRT-LLM for any platform contains a vulnerability in visual gen server, where an attacker could cause an unsafe deserialization by unauthorized zeroMQ deserialization. A successful exploit of this vulnerability might lead to code execution.nvd · 2026-07-14
- Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilitiestalos · 2026-07-14
- [NVD] CVE-2026-48000 (MEDIUM 6.1) — Adobe Commerce is affected by an Improper Redirect (Open Redirect) vulnerability that could result in a Security feature bypass. An attacker could construct a malicious URL that redirects a victim to an attacker-controlled site. Exploitation of this issue requires user interactionvd · 2026-07-14
- [NVD] CVE-2026-15711 (HIGH 7.5) — A vulnerability was found in libsoup's WebSocket frame parsing implementation. The library fails to validate length rules specified in RFC 6455 §5.5, which mandates that all WebSocket control frames (e.g., PING, PONG, CLOSE) contain a payload of 125 bytes or less. A remote, unautnvd · 2026-07-14
- [NVD] CVE-2026-15709 (HIGH 7.5) — A flaw was found in libsoup's WebSocket implementation when using the permessage-deflate extension. The extension's decompression loop (inflate()) processes data in chunks without enforcing an upper boundary limit on the output buffer size. While libsoup limits the incoming comprnvd · 2026-07-14
- Microsoft Patches a Record 570 Security Flawskrebs · 2026-07-14
- Microsoft’s July 2026 Patch Tuesday Addresses 569 CVEs (CVE-2026-56155, CVE-2026-56164)tenable · 2026-07-14
- How Qualys ETM Identity Detects Identity-Based Attacks Fasterqualys · 2026-07-14
- Prompt Injection Explained: How It Works, Why It Matters, and Practical Mitigationszscaler_threatlabz · 2026-07-14
- The July 2026 Security Update Reviewzdi_blog · 2026-07-14
- [NVD] CVE-2026-14646 (HIGH 7.7) — Nexus Repository 3 did not apply its existing Server-Side Request Forgery (SSRF) protections to HTTP redirect targets returned by proxy repository upstream servers. Any user with read access to a proxy repository backed by an attacker-controlled or compromised upstream server — invd · 2026-07-14
- [NVD] CVE-2026-14645 (MEDIUM 5.5) — Nexus Repository 3 does not validate the destination of the "Webhook: Global" capability's configured URL before making an outbound HTTP request, allowing a user holding the Capability Administration permission to cause the server to send requests to internal network locations (Snvd · 2026-07-14
- [NVD] CVE-2026-7494 (MEDIUM 5.0) — Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate Retrieval endpoint. A user holding the nexus:ssl-truststore:read permission could cause the server to initiate outbound connections to internal or otherwise restricted network hosts. Thnvd · 2026-07-14
- [NVD] CVE-2026-14504 (MEDIUM 6.5) — An authorization bypass in Nexus Repository 3's component upload API allowed a user with only read/browse privileges on a Swift, Terraform, or Conda hosted repository to upload arbitrary artifacts, bypassing the intended write-permission check.nvd · 2026-07-14
- [NVD] CVE-2026-11403 (HIGH 7.5) — A vulnerability in Sonatype Nexus Repository Manager's format-specific API key generation may allow a remote attacker to gain unauthorized access to repository operations as a targeted user. A format-specific API key realm (NuGet API Key, Docker Bearer Token, or npm Bearer Token)nvd · 2026-07-14
- Canada’s Electronic Spy Agency Conducted Cyberattacks on Criminals Brokering Fentanyl Ingredients, Report Sayscitizenlab · 2026-07-14
- AI Agents Are Creating a New Class of Employee Riskvaronis_blog · 2026-07-14
- June 2026 Infostealer Trend Reportahnlab · 2026-07-14
- What’s in the SOSS? Podcast #65 – S3E17 Signing the Future: Securing AI and ML Artifacts with Mihai Maruseacopenssf_blog · 2026-07-14
- CVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass (FIXED)rapid7 · 2026-07-14
- Varonis Atlas Extends Coverage Across the Claude Enterprise Suite — From Claude Cowork to Claude Codevaronis_blog · 2026-07-14
- [Video] Where protection starts: Cisco Talos Intelligence Integrationstalos · 2026-07-14
- [NVD] CVE-2026-12478 (MEDIUM 4.8) — The fix for CVE-2026-0716 (commit 6ff7ef0, libsoup 3.6.6) placed the integer overflow guard inside the if (masked) block, leaving unmasked server-to-client frames unprotected. A malicious WebSocket server can send a crafted unmasked frame with a payload length near UINT64_MAX to nvd · 2026-07-14
- The serpent’s tongue: Luring the Python out of its dentalos · 2026-07-14
- Rapid7 and Mindware Partner to Accelerate Cyber Resilience Across the Middle Eastrapid7 · 2026-07-14
- Accelerating Post-Quantum Readiness Timelines: A New Executive Order on Securing Against Advanced Cryptographic Attackszscaler_threatlabz · 2026-07-14
- [NVD] CVE-2026-44745 (HIGH 8.1) — SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthenticated remote attacker to craft a malicious link which, when clicked by a victim, could lead to unauthorized access. Successful expnvd · 2026-07-14
- [NVD] CVE-2026-27690 (CRITICAL 9.1) — Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. This could result in the exposure of user responses and cause the system to become unavailablnvd · 2026-07-14
- US Sanctions First VPN Cybercriminal Serviceduo_decipher · 2026-07-14
- AI Security Report 2026checkpoint_research · 2026-07-14
- [CISA KEV] CVE-2026-56155 — Microsoft Active Directory Federation Services: Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability cisa_kev · 2026-07-14
- [CISA KEV] CVE-2026-56164 — Microsoft SharePoint Server: Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerabilitycisa_kev · 2026-07-14
- [CISA KEV] CVE-2026-15410 — SonicWall SMA1000 Appliances: SonicWall SMA1000 Appliances Code Injection Vulnerabilitycisa_kev · 2026-07-14
- The FBI Warned About Fake Permit Fees. The Harder Question Is Where the Money Goes. | Recorded Futurerecordedfuture · 2026-07-14
- [CISA KEV] CVE-2026-15409 — SonicWall SMA1000 Appliances: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerabilitycisa_kev · 2026-07-14
- [NVD] CVE-2026-62240 (HIGH 7.4) — CrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url function that performs one-shot DNS resolution and blocklist checks before returning the original URL unchanged. Attackers can bypass the security filter by supplying URLs that redirect nvd · 2026-07-13
- [NVD] CVE-2026-62239 (MEDIUM 6.6) — FlashAttention through 2.8.3.post1, fixed in commit 0816ef1, contains a symlink attack vulnerability in the download_and_copy() function within hopper/setup.py that extracts NVIDIA toolchain archives without validating symlinks or filtering tar members. A local attacker can pre-pnvd · 2026-07-13
- [NVD] CVE-2026-62196 (HIGH 8.3) — OpenClaw versions 2026.3.22 before 2026.6.6 contain an authorization bypass vulnerability where WhatsApp group IDs can satisfy elevated sender allowlists. Attackers with lower-trust access can perform actions requiring stronger authorization by leveraging group ID validation in tnvd · 2026-07-13
- Defending SaaS-based applications against ShinyHunters OAuth abusemsstic · 2026-07-13
- Between Two Nerds: Exploits are not cyber powerriskybiz_news · 2026-07-13
- Request for Comments: CARE and Maven Centralsonatype · 2026-07-13
- [NVD] CVE-2026-53364 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: Fix memory leak in hci_le_big_terminate() hci_le_big_terminate() allocates iso_list_data via kzalloc_obj but returns 0 without freeing it when neither pa_sync_term nor big_sync_term flags anvd · 2026-07-13
- Understanding Illicit Ecosystems: How Dark Web Forums Structure Cybercrimeflashpoint · 2026-07-13
- [NVD] CVE-2026-57432 (HIGH 8.4) — Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack. S_measure_struct adds each item's size times its repeat count to a running total withnvd · 2026-07-13
- [NVD] CVE-2026-13221 (CRITICAL 9.1) — Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk. When such branches are combinvd · 2026-07-13
- [NVD] CVE-2026-59245 (HIGH 8.1) — In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission resource name produced by `resource_name()`, so a user granted per-DAG `access_control` on that one DAG was silently granted the global all-DAGs permission (privilenvd · 2026-07-13
- [NVD] CVE-2026-58065 (HIGH 8.1) — The Apache Airflow Git provider runs its git-over-SSH operations with `StrictHostKeyChecking=no` by default, disabling SSH host-key verification. An attacker who can intercept the network path between an Airflow worker and the Git server can impersonate the server (man-in-the-midnvd · 2026-07-13
- Lessons Learned from CISA’s Recent GitHub Leakkrebs · 2026-07-13
- June 2026 Threat Trend Report on APT Groupsahnlab · 2026-07-13
- 13th July – Threat Intelligence Reportcheckpoint_research · 2026-07-13
- Formula One and Cybersecurity in the AI Erazscaler_threatlabz · 2026-07-13
- [NVD] CVE-2026-4765 — Self Cross-Site Scripting (Self-XSS) vulnerability in the RD Station Conversas chat feature. The vulnerability lies in the ‘name’ parameter of the initialisation process due to incorrect sanitisation of user-supplied input. Exploitation allows specially crafted JavaScript code tonvd · 2026-07-13
- Rust-proof your code with our new Testing Handbook chaptertrailofbits · 2026-07-13
- EclecticIQ MCP Server: Connect your AI agents directly to your threat intelligenceeclecticiq · 2026-07-13
- Update on Attacks by Threat Group APT-C-60 in 2026jpcert_blog · 2026-07-13
- [CISA KEV] CVE-2008-4128 — Cisco IOS: Cisco IOS Cross-Site Request Forgery Vulnerabilitycisa_kev · 2026-07-13
- KlueセキュリティインシデントとRecorded Futureへの影響recordedfuture · 2026-07-13
- [Breach] Brinks Home — 732,162 accounts exposedhibp_breaches · 2026-07-13