THREAT OPS › Threat News
Threat Intelligence News
12121 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [Breach] Brinks Home — 732,162 accounts exposedhibp_breaches · 2026-07-13
- [NVD] CVE-2026-56336 (MEDIUM 5.3) — Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /private/sso/check-domain endpoint that returns internal org_id and provider_id values. Attackers can enumerate email domains to build mappings of domains to organization UUIDs and SSO pnvd · 2026-07-12
- [NVD] CVE-2026-56281 (LOW 3.8) — Capgo before 12.128.2 contains a sql injection vulnerability in the POST /private/admin_stats endpoint where the limit parameter is destructured from unvalidated request body and interpolated directly into Cloudflare Analytics Engine SQL queries via template literals. An attackernvd · 2026-07-12
- Case Study: Distribution of a CoinMiner Targeting Linux SSH Servers via Malware Distribution via Network Transmissionahnlab · 2026-07-11
- Weekly Metasploit Update: Exploits for FlowiseAI CSV Agent and MacOS Package Kitrapid7 · 2026-07-11
- [NVD] CVE-2026-15080 (MEDIUM 4.3) — Cross-Site Request Forgery (CSRF) vulnerability in Drupal Ray Enterprise Translation allows Cross Site Request Forgery. This issue affects Ray Enterprise Translation versions: from 0.0.0 to 4.0.4, from 4.1.0 to 4.1.4, from 11.0.0 to 11.0.4.nvd · 2026-07-10
- No Manners Here: The Ruthless Rise of The Gentlemen Ransomwareunit42 · 2026-07-10
- [NVD] CVE-2026-38059 (HIGH 7.5) — The iDirect iQ200 exposes the /api/identity and /api/ REST API endpoints without authentication. An unauthenticated attacker with network access can retrieve sensitive device information including the serial number, Device ID (DID), Terminal Private Key identifier (TPK), MAC addrnvd · 2026-07-10
- [NVD] CVE-2026-38057 (HIGH 8.1) — The iDirect iQ200 does not validate CSRF tokens on state-changing API endpoints after authentication. The /api/reboot endpoint accepts POST requests authenticated solely by a session cookie that lacks the SameSite attribute. A remote attacker can host a malicious web page that, wnvd · 2026-07-10
- CVE-2026-47291: Remote Code Execution in the Windows HTTP.syszdi_blog · 2026-07-10
- [NVD] CVE-2026-15378 (CRITICAL 9.3) — A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind Server-Side Request Forgery (SSRF) by submitting a specially crafted XML Schema Definition (XSD) string. This can lead to unauthorized access to sensitive infonvd · 2026-07-10
- [NVD] CVE-2026-15028 (LOW 3.9) — A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a specially crafted tar archive. The issue occurs during the parsing of a PAX extended header containing a malformed SUN.holesdata sparse-file attribute. Successfulnvd · 2026-07-10
- Risky Bulletin: NSA Tailored Access Operations is backriskybiz_news · 2026-07-10
- Sponsored: Why Sublime doesn’t toss AI at every emailriskybiz_news · 2026-07-10
- New Forg365 PhaaS Kit Emergesduo_decipher · 2026-07-10
- June 2026 CVE Landscaperecordedfuture · 2026-07-10
- [CISA KEV] CVE-2026-56291 — Balbooa Forms: Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerabilitycisa_kev · 2026-07-10
- [CISA KEV] CVE-2026-48939 — iCagenda iCagenda: iCagenda Unrestricted Upload of File with Dangerous Type Vulnerabilitycisa_kev · 2026-07-10
- Why Do F1 Teams Need Cybersecurity, and How Is AI Changing the Threat Landscape?zscaler_threatlabz · 2026-07-09
- WolfSSL, GeoVision, VTK vulnerabilitiestalos · 2026-07-09
- Winning 54% of the timetalos · 2026-07-09
- [NVD] CVE-2026-11404 (HIGH 7.5) — Cesanta Mongoose before 7.22 contains an out-of-bounds read in the built-in TLS server function mg_tls_server_recv_hello(), which uses an attacker-controlled session_id_len byte from a TLS ClientHello as a buffer index without validating it against the length of received data. A nvd · 2026-07-09
- Finding SOCKS with Proxywatchspecterops · 2026-07-09
- Wordfence Intelligence Weekly WordPress Vulnerability Report (June 29, 2026 to July 5, 2026)wordfence · 2026-07-09
- Beware of Phishing Emails Disguised as Money Transfer Confirmationsahnlab · 2026-07-09
- Why we cannot wait for better post-quantum signature algorithmscloudflare_security · 2026-07-09
- Q2 2026 Open Source Malware Indexsonatype · 2026-07-09
- One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforcementsentinelone · 2026-07-09
- Unfit to Boot: Breaking U-Boot's FIT Signature Verificationbinarly · 2026-07-09
- [NVD] CVE-2026-59692 (HIGH 7.5) — A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. A remote unauthenticated attacker can send a certificanvd · 2026-07-09
- [NVD] CVE-2026-59691 (HIGH 7.1) — A heap buffer overflow vulnerability was found in GStreamer's rfbsrc plugin. When a client connects to a malicious RFB/VNC server that advertises a 16bpp framebuffer and sends Hextile-encoded updates, the Hextile background fill path writes 32-bit pixel values into a buffer allocnvd · 2026-07-09
- Srsly Risky Biz: US Supreme Court undermines Section 702 intelriskybiz_news · 2026-07-09
- [REVIVE-SA-2026-003] Revive Adserver Vulnerabilitiesfulldisclosure · 2026-07-09
- Kainos Shares Five Essential Tips for Your Zscaler Deployment at Scalezscaler_threatlabz · 2026-07-09
- RiskX interview video featuring Colin Mahony and Mastercard's Aditi Sawhneyrecordedfuture · 2026-07-09
- [NVD] CVE-2026-15105 (MEDIUM 6.3) — A flaw has been found in davenardella snap7 up to 1.4.3. This affects the function TS7Worker::PerformFunctionRead of the file src/core/s7_server.cpp of the component ReadVar Request Handler. This manipulation causes out-of-bounds write. The attack requires access to the local netnvd · 2026-07-08
- [NVD] CVE-2026-59822 (HIGH 8.2) — LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAuth2 passthrough fallback path that replaced nvd · 2026-07-08
- [NVD] CVE-2026-15154 (MEDIUM 6.5) — A flaw was found in `guardrails-detectors`, a component of Red Hat OpenShift AI. This vulnerability, known as Regular Expression Denial of Service (ReDoS), allows a remote attacker to provide specially crafted regular expressions to the public detection API. This can cause catastnvd · 2026-07-08
- [NVD] CVE-2026-39822 (HIGH 7.8) — On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symbnvd · 2026-07-08
- [NVD] CVE-2026-59262 (MEDIUM 6.5) — AFFiNE's histories GraphQL field fails to validate Doc.Read permission before exposing document edit history, allowing authenticated workspace members to retrieve restricted content timelines. Attackers can supply arbitrary document GUIDs to access full edit histories including unvd · 2026-07-08
- AI Surveillance Is Being Supercharged–And It Will Chill Social Progresscitizenlab · 2026-07-08
- Building a Mental Model for Kubernetes Security Researchspecterops · 2026-07-08
- Beyond Alert Fatigue: Architecting Next-Gen Data Security with Zscaler Workflow Automationzscaler_threatlabz · 2026-07-08
- June 2026 Dark Web Threat Actor Trend Reportahnlab · 2026-07-08
- June 2026 Dark Web Breach Incident Trend Reportahnlab · 2026-07-08
- June 2026 Dark Web Issue Trend Reportahnlab · 2026-07-08
- Beware of Phishing Emails Disguised as Project Proposalsahnlab · 2026-07-08
- Ransom & Dark Web Issues Week 2, July 2026ahnlab · 2026-07-08
- Researchers Find New GhostApproval Bug in Many AI Coding Assistantsduo_decipher · 2026-07-08
- Security Teams Are Ready To Become More Preemptive. What’s Holding Them Back?rapid7 · 2026-07-08
- Varonis Atlas Secures Cursor and the Agentic Development Lifecyclevaronis_blog · 2026-07-08
- Felons, Fraudsters Flog Offensive Cybersecurity Startupkrebs · 2026-07-08
- Mutation testing comes to DAMLtrailofbits · 2026-07-08
- Inside the Underground Economy: 5 Dark Web Trends Shaping the 2026 Threat Landscapecyble · 2026-07-08
- Keyword lists: Stop re-entering the same organizational context across every workfloweclecticiq · 2026-07-08
- Risky Bulletin: DHS IG investigates forced CISA reassignmentsriskybiz_news · 2026-07-08
- The Threat Isn’t the Frontier Modelrecordedfuture · 2026-07-08
- ClickFix to Cash-Out: Anatomy of a Mexican Banking-Fraud Toolkitelastic_security · 2026-07-08
- [NVD] CVE-2026-14380 (HIGH 8.8) — DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. When a string is assigned to a DBI handle's Profile attribute, DBI splits it into path, package and arguments, and interpolates the package part in a string eval with no validationnvd · 2026-07-07
- Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflationunit42 · 2026-07-07
- AI, Trust, and the Future of Threat Intelligenceflashpoint · 2026-07-07
- [NVD] CVE-2026-59708 (HIGH 7.5) — The GET /api/v1/public/:accessId/portfolio endpoint in ghostfolio accepts private access IDs without validating granteeUserId filtering, allowing unauthenticated access to full portfolio data. Attackers with a private access ID can retrieve sensitive portfolio information includinvd · 2026-07-07
- How to Set Red Team Objectives that Produce Valuespecterops · 2026-07-07
- [NVD] CVE-2026-59709 (MEDIUM 4.3) — Ghostfolio's PUT /api/v1/portfolio/holding/:dataSource/:symbol/tags endpoint fails to verify Access.permissions field when processing the Impersonation-Id header, allowing read-only access grantees to modify portfolio holding tags. Attackers with valid read-only share tokens can nvd · 2026-07-07
- What if you received an email about transferring your Kakao account? Check this first.ahnlab · 2026-07-07
- Files Locked Behind a White Padlock: A Warning from WhiteLock Ransomwareahnlab · 2026-07-07
- Chinese APT UAT-7810 Expands Malware Arsenalduo_decipher · 2026-07-07
- The ‘Ghost’ in the Database: Recovering Active ADFS Signing Keys via Machine DPAPImandiant_gti · 2026-07-07
- Rogue Agent: How a Single Code Block Could Hijack Your AI Conversations in Google’s DialogFlowvaronis_blog · 2026-07-07
- [NVD] CVE-2026-49487 (MEDIUM 6.5) — In Apache Airflow before 3.3.0, the REST API task-instance detail and list endpoints returned a deferred task's trigger kwargs without masking. When a deferred operator passed a secret (for example a provider API key) into its trigger, any authenticated user with DAG-scoped task-nvd · 2026-07-07
- [NVD] CVE-2026-49296 (MEDIUM 6.5) — Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-located in the same source file. `GET /api/v2/dagSources/{dag_id}` — and the equivalent Dag-source view in the UI — returned the entire source file without redacting Dags thenvd · 2026-07-07
- [NVD] CVE-2026-48892 (MEDIUM 6.5) — The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables like `AIRFLOW__SECRETS__BACKEND_KWARG__SECRET_ID` and `AIRFLOW__WORKERS__SECRETS_BACKEND_KWARG__SECRET_ID`) as synthetic config options whose option names were not in `sensitive_connvd · 2026-07-07
- [NVD] CVE-2026-48891 (MEDIUM 4.3) — A bug in Apache Airflow's `/ui/dependencies` scheduling graph endpoint applied the caller's readable-Dag filter to the top-level serialized Dag key but still emitted referenced Dag IDs through the `dep.source` and `dep.target` fields of trigger / sensor dependency entries. An autnvd · 2026-07-07
- [NVD] CVE-2026-48828 (MEDIUM 6.5) — The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `should_hide_value_for_key` check (which triggers on secret-suffixed key names like `*_password` / `*_token` / `*_secret`) could not fire for JSON-decodable variable nvd · 2026-07-07
- [NVD] CVE-2026-14476 (HIGH 8.0) — A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitize .. sequences in the gPCFileSysPath LDAP attribute, allowing an attacker with AD GPO management access to write files outside the GPO cache directory as root. nvd · 2026-07-07
- [NVD] CVE-2026-14474 (HIGH 8.8) — A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting rnvd · 2026-07-07
- Threat landscape for industrial automation systems. Q1 2026securelist · 2026-07-07
- UAT-7810 continues building ORB networks using new malwaretalos · 2026-07-07
- OPNsense XPATH Injection (CVE-2026-53582)fulldisclosure · 2026-07-07
- SCHUTZWERK-SA-2025-001: Authentication Bypass for SafeLine SL6 and SL6+fulldisclosure · 2026-07-07
- The Director’s Cut: Trusted Perimeters Become Board Liabilitieszscaler_threatlabz · 2026-07-07
- [CISA KEV] CVE-2026-48908 — JoomShaper SP Page Builder: JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerabilitycisa_kev · 2026-07-07
- [CISA KEV] CVE-2026-55255 — Langflow Langflow: Langflow Authorization Bypass Through User-Controlled Key Vulnerabilitycisa_kev · 2026-07-07
- [CISA KEV] CVE-2026-56290 — Joomlack Page Builder: Joomlack Page Builder Improper Access Control Vulnerabilitycisa_kev · 2026-07-07
- [CISA KEV] CVE-2026-48282 — Adobe ColdFusion: Adobe ColdFusion Path Traversal Vulnerabilitycisa_kev · 2026-07-07
- SSE Architecture Explained: How SSE Enables Zero Trustzscaler_threatlabz · 2026-07-06
- [NVD] CVE-2026-59713 (HIGH 8.1) — Leantime contains an OIDC login CSRF vulnerability in the verifyState() method that unconditionally returns true without validating state parameters. Attackers can craft malicious callback URLs with attacker-controlled authorization codes to perform session fixation, logging victnvd · 2026-07-06
- [NVD] CVE-2026-59712 (HIGH 8.1) — Leantime's Users::getUser method in the JSON-RPC API lacks proper authorization checks, allowing authenticated users to retrieve full user credential rows including password hashes, TOTP secrets, and session tokens. Attackers can exploit this by calling users.getUser with arbitranvd · 2026-07-06
- Between Two Nerds: Why AI has not meant more hacks. Yet.riskybiz_news · 2026-07-06
- Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilitiescisco_psirt · 2026-07-06
- Vulnerability Trend Report for Q2 2026ahnlab · 2026-07-06
- AI Is Forcing a New Open Source Security Modelsonatype · 2026-07-06
- Mid-Year Threat Trends: What H1 2026 Signals for the Rest of the Yearcyble · 2026-07-06
- Cavern Manticore: Exposing Iran-Linked Modular C2 Frameworkcheckpoint_research · 2026-07-06
- 6th July – Threat Intelligence Reportcheckpoint_research · 2026-07-06
- Cisco Catalyst Center Arbitrary File Read Vulnerabilitycisco_psirt · 2026-07-06
- [NVD] CVE-2026-9165 (HIGH 7.7) — A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not limit the depth of GraphQL queries served on the authenticated GraphQL API. An authenticated user with a valid API token can send deeply nested queries that cause excessive resource connvd · 2026-07-06
- When checking the URL isn’t enough: a Device Code Phishing attack via a Microsoft websitesecurelist · 2026-07-06
- Risky Bulletin: EU official’s phone infected with Pegasusriskybiz_news · 2026-07-06
- Vidar Infostealer Being Spread through Phishing Emailsahnlab · 2026-07-05