THREAT OPS › Threat News
Threat Intelligence News
12123 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- Between Two Nerds: Set cyberspace ablazeriskybiz_news · 2026-06-29
- [NVD] CVE-2026-43746 (MEDIUM 6.5) — A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.nvd · 2026-06-29
- [NVD] CVE-2026-43743 (MEDIUM 4.7) — A race condition was addressed with improved state handling. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, iOS 26.7 and iPadOS 26.7, macOS Tahoe 26.5.2, macOS Tahoe 26.7, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.nvd · 2026-06-29
- [NVD] CVE-2026-43715 (HIGH 8.8) — A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, iOS 26.7 and iPadOS 26.7, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to mnvd · 2026-06-29
- Enterprise Tech In, Shell Out (Progress Kemp LoadMaster Uninitialized Heap to Pre-Auth RCE CVE-2026-8037)watchtowr · 2026-06-29
- Jailbreaker: LLM Jailbreak Testing You Can Actually Repeatspecterops · 2026-06-29
- [NVD] CVE-2026-12912 (HIGH 7.3) — A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLog-compressed TIFF image. This issue occurs when decoding Pixarlog codec images with the PIXARLOGDATAFMT_8BITABGR output format and a specific stride value, leadnvd · 2026-06-29
- Inside the Advisory Database and what happens when vulnerability volume breaks recordsgithub_security_lab · 2026-06-29
- Unmasking the Digital Trail: Essential Techniques for Vetting AI-Generated Contentflashpoint · 2026-06-29
- [NVD] CVE-2026-54371 (HIGH 7.1) — attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathnvd · 2026-06-29
- [NVD] CVE-2026-13676 (HIGH 7.5) — fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, silently leaving the host in its original Unicode form while normalize() annvd · 2026-06-29
- 29th June – Threat Intelligence Reportcheckpoint_research · 2026-06-29
- The Bear Necessities: A Look at the Drivers, Dynamics, and Applications of the Pro-Russia Influence Ecosystemmandiant_gti · 2026-06-29
- From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akiradfirreport · 2026-06-29
- [NVD] CVE-2026-41992 (HIGH 7.5) — GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution. GNU gzip maintains a global array that is shared across the LZ77, LZW, and LZnvd · 2026-06-29
- [NVD] CVE-2026-13601 (HIGH 7.1) — A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG documnvd · 2026-06-29
- [NVD] CVE-2026-53325 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: agp/amd64: Fix broken error propagation in agp_amd64_probe() A NULL pointer dereference was observed in the AMD64 AGP driver when running in a virtualized environment (e.g. qemu/kvm) without a physical AMD nortnvd · 2026-06-29
- Risky Bulletin: White House asks OpenAI to restrict GPT 5.6riskybiz_news · 2026-06-29
- Sponsored: Corelight’s blueprint for AI-era defenceriskybiz_news · 2026-06-29
- [CISA KEV] CVE-2026-48558 — SimpleHelp SimpleHelp: SimpleHelp Authentication Bypass Vulnerabilitycisa_kev · 2026-06-29
- [NVD] CVE-2026-58052 (LOW 3.3) — 7-Zip for Windows through 26.01 fails to preserve the Mark-of-the-Web when extracting a crafted RAR5 archive, because its guard that suppresses an archive-supplied Zone.Identifier stream matches the exact name 'Zone.Identifier' while a RAR5 STM record named ':Zone.Identifier:$DATnvd · 2026-06-28
- [NVD] CVE-2026-58049 (HIGH 8.6) — FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary check and validates the DLTA region in pixel rather than byte units, so a DLTA run on a PAL8 frame can access several bytes past thenvd · 2026-06-28
- [NVD] CVE-2026-49869 (CRITICAL 10.0) — Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whitelist the public configuration endpoint from Basic Auth. Because the check is a suffix match rather thanvd · 2026-06-26
- Time Travel Debugging with Codexspecterops · 2026-06-26
- AI in Cybersecurity: Benefits and Riskszscaler_threatlabz · 2026-06-26
- Threat Brief: Mitigating Large-Scale Credential Attacksunit42 · 2026-06-26
- Critical Unauthenticated Remote Code Execution in Splunk Enterprise (CVE-2026-20253)zscaler_threatlabz · 2026-06-26
- From CI/CD to Cloud Data: How Shai Hulud Persistence Leads to Redshift Breachfortinet_research · 2026-06-26
- [NVD] CVE-2026-49486 (HIGH 7.5) — The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never called `prot_p()`, so although the control channel was TLS-protected the data channel was transmitted in cleartext. Any deployment using `FTPSHook` or `FTPSFileTransmitOperatonvd · 2026-06-26
- Risky Bulletin: Operation Endgame dismantles Amadey and StealerCriskybiz_news · 2026-06-26
- From Launch to Leadership: Zscaler AI Protect Raises the Bar for AI Securityzscaler_threatlabz · 2026-06-25
- Hardening Federal Networks for the Mythos Era: What the AI Executive Order and BOD 26-04 Demand Nowzscaler_threatlabz · 2026-06-25
- [NVD] CVE-2025-71338 (CRITICAL 10.0) — Flowise through 2.2.7 fails to sanitize path segments in the document-store loader endpoint, allowing unauthenticated attackers to write files outside the storage directory. Attackers can use parent-directory sequences to escape the storage directory and overwrite application filnvd · 2026-06-25
- CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructureunit42 · 2026-06-25
- The AI Paradox: To Earn Enough Trust to Move Fast, You Have to Trust Nothingzscaler_threatlabz · 2026-06-25
- Miasma Returns: Leo Platform Compromise in npmsonatype · 2026-06-25
- The CRA Readiness Reality: What Changed (and What Didn’t) Between 2025 and 2026?openssf_blog · 2026-06-25
- Wordfence Intelligence Weekly WordPress Vulnerability Report (June 15, 2026 to June 21, 2026)wordfence · 2026-06-25
- Emile Dirks Elected to PEN Canada’s Board of Directorscitizenlab · 2026-06-25
- [NVD] CVE-2026-9800 (HIGH 8.1) — A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role, scope, and User-Managed Access (UMA) permission checks. By including the configured access-denied page path within a request URL, envd · 2026-06-25
- The Salesforce-Klue Incident: How Zscaler Protects SaaS Datazscaler_threatlabz · 2026-06-25
- The Agentic AI Threat Model: Prompt Injection, Context Poisoning, and Agent Behavior Driftzscaler_threatlabz · 2026-06-25
- Cisco Finesse Remote File Inclusion Vulnerabilitycisco_psirt · 2026-06-25
- STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatusmandiant_gti · 2026-06-25
- Computer-Use and TOCTOU: What You Click Is Not What You Get!embracethered · 2026-06-25
- [NVD] CVE-2026-53266 (HIGH 8.8) — In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(skb, 0). This is intentional: at the bridge ebtables hooks thnvd · 2026-06-25
- [NVD] CVE-2026-53250 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: xsk: cache csum_start/csum_offset to fix TOCTOU in xsk_skb_metadata() The TX metadata area resides in the UMEM buffer which is memory-mapped and concurrently writable by userspace. In xsk_skb_metadata(), csum_snvd · 2026-06-25
- [NVD] CVE-2026-53196 (MEDIUM 6.8) — In the Linux kernel, the following vulnerability has been resolved: USB: serial: io_ti: fix heap overflow in get_manuf_info() get_manuf_info() reads le16_to_cpu(rom_desc->Size) bytes from the device I2C EEPROM into a buffer allocated with kmalloc_obj(), which is sizeof(struct envd · 2026-06-25
- [NVD] CVE-2026-53185 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: zram: fix use-after-free in zram_bvec_write_partial() zram_read_page() picks the sync or async backing device read path based on whether the parent bio is NULL. zram_bvec_write_partial() passes its parent bio nvd · 2026-06-25
- [NVD] CVE-2026-53178 (HIGH 8.1) — In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtraction Add guards to ensure ie_length is large enough before subtracting fixed IE offsets to prevent unsigned integer underflow.nvd · 2026-06-25
- [NVD] CVE-2026-53176 (CRITICAL 9.8) — In the Linux kernel, the following vulnerability has been resolved: IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN In drivers/infiniband/ulp/isert/ib_isert.c, isert_login_recv_done() computes the login request payload length as wc->byte_len minus ISER_HEADERS_LEN witnvd · 2026-06-25
- Srsly Risky Biz: Open weight models make the Mythos debate mootriskybiz_news · 2026-06-25
- [CISA KEV] CVE-2026-12569 — PTC Windchill and FlexPLM: PTC Windchill and FlexPLM Improper Input Validation Vulnerabilitycisa_kev · 2026-06-25
- [CISA KEV] CVE-2026-20230 — Cisco Unified Communications Manager: Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerabilitycisa_kev · 2026-06-25
- Evaluating Mexico’s New Cybersecurity Planrecordedfuture · 2026-06-25
- Where Expertise Meets Algorithm: The Insikt Group® Intelligence Edgerecordedfuture · 2026-06-25
- [NVD] CVE-2026-2050 (HIGH 7.8) — GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit anvd · 2026-06-24
- [NVD] CVE-2026-13201 (HIGH 7.3) — A flaw was found in KubeVirt's safepath package used by virt-handler. The OpenAtNoFollow function uses O_PATH|O_NOFOLLOW to obtain a file descriptor to a path leaf, but downstream operations resolve the path via /proc/self/fd/N using link-following syscalls. When the leaf is a synvd · 2026-06-24
- [NVD] CVE-2026-49980 (CRITICAL 9.8) — Rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.46.0 until 1.74.3, rclone rcd --rc-serve accepts unauthenticated GET and HEAD requests to paths of the form: /[remote:path]/object. The remote value is parsed fromnvd · 2026-06-24
- OpenSSF Newsletter – June 2026openssf_blog · 2026-06-24
- Disposable Tooling: Building LLM-Generated Mythic Agents from Prompt to Deploymentspecterops · 2026-06-24
- [NVD] CVE-2026-53098 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: fix use-after-free bugs in mt7915_mac_dump_work() When the mt7915 pci chip is detaching, the mt7915_crash_data is released in mt7915_coredump_unregister(). However, the work item dump_work mnvd · 2026-06-24
- [NVD] CVE-2026-53092 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: bpf: Fix linked reg delta tracking when src_reg == dst_reg Consider the case of rX += rX where src_reg and dst_reg are pointers to the same bpf_reg_state in adjust_reg_min_max_vals(). The latter first modifies nvd · 2026-06-24
- [NVD] CVE-2026-53090 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: bpf: Fix ld_{abs,ind} failure path analysis in subprogs Usage of ld_{abs,ind} instructions got extended into subprogs some time ago via commit 09b28d76eac4 ("bpf: Add abnormal return checks."). These are only anvd · 2026-06-24
- [NVD] CVE-2026-53078 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops When a BPF sock_ops program accesses ctx fields with dst_reg == src_reg, the SOCK_OPS_GET_SK() and SOCK_OPS_GET_FIELD() macros fail to zero tnvd · 2026-06-24
- [NVD] CVE-2026-53071 (HIGH 8.8) — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp l2cap_ecred_reconf_rsp() calls l2cap_chan_del() without holding l2cap_chan_lock(). Every other l2cap_chan_del() caller in the file acquires the nvd · 2026-06-24
- [NVD] CVE-2026-53016 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - copy IV using skcipher ivsize AF_ALG rfc3686-ctr-aes-ccp requests pass an 8-byte IV to the driver. ccp_aes_complete() restores AES_BLOCK_SIZE bytes into the caller's IV buffer while RFC3686 skcipnvd · 2026-06-24
- [NVD] CVE-2026-53010 (CRITICAL 9.8) — In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in smb2_open during durable reconnect In smb2_open, the call to ksmbd_put_durable_fd(fp) drops the reference to the durable file descriptor early during the durable reconnect process. nvd · 2026-06-24
- [NVD] CVE-2026-53006 (CRITICAL 9.8) — In the Linux kernel, the following vulnerability has been resolved: ipv6: fix possible UAF in icmpv6_rcv() Caching saddr and daddr before pskb_pull() is problematic since skb->head can change. Remove these temporary variables: - We only access &ipv6_hdr(skb)->saddr and &ipv6_nvd · 2026-06-24
- [NVD] CVE-2026-53000 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: netfilter: nat: use kfree_rcu to release ops Florian Westphal says: "Historically this is not an issue, even for normal base hooks: the data path doesn't use the original nf_hook_ops that are used to register nvd · 2026-06-24
- [NVD] CVE-2026-52973 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: futex: Drop CLONE_THREAD requirement for private default hash alloc Currently need_futex_hash_allocate_default() depends on strict pthread semantics, abusing CLONE_THREAD. This breaks the non-concurrency assumnvd · 2026-06-24
- [NVD] CVE-2026-52972 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Cap AEAD AD length to 0x80000000 In order to prevent arithmetic overflows when checking the TX buffer size, cap the associated data length to 0x80000000.nvd · 2026-06-24
- [NVD] CVE-2026-52961 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: ceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size The generic/642 test-case can reproduce the kernel crash: [40243.605254] ------------[ cut here ]------------ [40243.605956] kernel BUG at nvd · 2026-06-24
- [NVD] CVE-2026-52946 (HIGH 7.5) — In the Linux kernel, the following vulnerability has been resolved: fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling A SOFTIRQ-safe to SOFTIRQ-unsafe lock order deadlock can occur in send_sigio() and send_sigurg() when a process group receives a signal. When FASYNC nvd · 2026-06-24
- May 2026 Threat Trend Report on APT Attacks (South Korea)ahnlab · 2026-06-24
- Ransom & Dark Web Issues Week 4, June 2026ahnlab · 2026-06-24
- [NVD] CVE-2026-56223 (HIGH 8.7) — Capgo before 12.128.2 contains a cross-domain SSO account takeover vulnerability in the provision-user endpoint that allows attackers to merge arbitrary victim accounts based on email match without validating SSO provider domain authorization. An attacker with enterprise org adminvd · 2026-06-24
- Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Managermandiant_gti · 2026-06-24
- [NVD] CVE-2026-52944 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix FSCTL permission bypass by adding a permission check for FSCTL_SET_SPARSE FSCTL_SET_SPARSE in fsctl_set_sparse() modifies the file's sparse attribute and saves it through xattr without any permissionnvd · 2026-06-24
- [NVD] CVE-2026-52942 (HIGH 7.1) — In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_log: validate MAC header was set before dumping it The fallback path of dump_mac_header() guards the MAC header access only with "skb->mac_header != skb->network_header", without checking skb_mac_nvd · 2026-06-24
- [NVD] CVE-2026-52933 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: io_uring/poll: fix signed comparison in io_poll_get_ownership() io_poll_get_ownership() uses a signed comparison to check whether poll_refs has reached the threshold for the slowpath: if (unlikely(atomic_rnvd · 2026-06-24
- [NVD] CVE-2026-52930 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: ipc/shm: serialize orphan cleanup with shm_nattch updates shm_destroy_orphaned() walks the shm idr under shm_ids(ns).rwsem, but that does not serialize all fields tested by shm_may_destroy(). In particular, shnvd · 2026-06-24
- [NVD] CVE-2026-52924 (CRITICAL 9.8) — In the Linux kernel, the following vulnerability has been resolved: sctp: purge outqueue on stale COOKIE-ECHO handling sctp_stream_update() is only invoked when the association is moved into COOKIE_WAIT during association setup/reconfiguration. In this path, the outbound streamnvd · 2026-06-24
- [NVD] CVE-2026-52923 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: ipc: limit next_id allocation to the valid ID range The checkpoint/restore sysctl path can request the next SysV IPC id through ids->next_id. ipc_idr_alloc() currently forwards that request to idr_alloc() withnvd · 2026-06-24
- [NVD] CVE-2026-52912 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_queue: hold bridge skb->dev while queued br_pass_frame_up() rewrites skb->dev from the ingress port to the bridge master before queueing bridge LOCAL_IN packets. NFQUEUE only holds references on snvd · 2026-06-24
- Risky Bulletin: FortiBleed hacks involved a lot of traffic sniffingriskybiz_news · 2026-06-24
- Unlocking the Cloudflare app ecosystem with OAuth for allcloudflare_security · 2026-06-24
- FortiBleed Campaign Exposing Credentials for 73,932 FortiGate Systemsrecordedfuture · 2026-06-24
- PCI Compliance Isn’t a Checkbox: How to Secure Ecommerce Checkouts Before Attackers Arrivesucuri_blog · 2026-06-23
- OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threatunit42 · 2026-06-23
- macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the Analyst, Not the Sandboxsentinelone · 2026-06-23
- [NVD] CVE-2026-54513 (HIGH 8.1) — jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), nvd · 2026-06-23
- [NVD] CVE-2026-41862 (HIGH 8.8) — Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts without enforcing a class allowlist (CWE-502, deserialisation of untrusted data), which can lead to remote code execution inside the application nvd · 2026-06-23
- [NVD] CVE-2026-11819 (MEDIUM 5.5) — Module: plugins/modules/keyring_info.py CVSS 3.1: 5.5 MEDIUM — AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Issue: The module retrieves a passphrase from the OS native keyring (GNOME Keyring, macOS Keychain, Windows Credential Manager) and places it directly into result["passphrase"] nvd · 2026-06-23
- AI Threat Report: How Artificial Intelligence Is Used Across Illicit Communitiesflashpoint · 2026-06-23
- The White House's post-quantum executive order is an important milestone. It’s time to get to workcloudflare_security · 2026-06-23
- Zscaler and AWS Join Forces to Secure GenAI Across Government, Healthcare, and Educationzscaler_threatlabz · 2026-06-23
- [NVD] CVE-2026-56694 (MEDIUM 5.4) — NanoClaw before 2.1.0 contains a privilege escalation vulnerability in the channel-registration approval flow where handleChannelApprovalResponse fails to validate admin privileges over target agent groups. Scoped admins can submit forged or stale connect callback values to wire nvd · 2026-06-23
- [NVD] CVE-2026-56693 (MEDIUM 5.5) — NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the create_agent delivery-action handler that performs privileged central-database writes without host-side authorization checks. Confined agent containers can invoke create_agent to create arbitrary agent grnvd · 2026-06-23
- [NVD] CVE-2026-56692 (MEDIUM 5.5) — NanoClaw before 2.1.17 contains a symlink following vulnerability in forwardAttachedFiles that allows container-controlled agents to exfiltrate host-readable files. The host validates attachment filenames using only isSafeAttachmentName before copying with fs.copyFileSync, which nvd · 2026-06-23