THREAT OPS › Threat News
Threat Intelligence News
12127 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- Cisco Crosswork Network Controller Server-Side Template Injection Vulnerabilitycisco_psirt · 2026-06-17
- Cisco Webex App Open Redirect Vulnerabilitycisco_psirt · 2026-06-17
- [NVD] CVE-2026-55748 (MEDIUM 6.0) — OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability.nvd · 2026-06-17
- [NVD] CVE-2026-54415 (HIGH 8.1) — Missing Authorization in the server management routes (routes/admin.php) in Azuriom Azuriom CMS before 1.2.11 on all platforms allows an authenticated attacker with the admin.access permission to create AzLink server tokens and take over non-admin user accounts by changing their nvd · 2026-06-17
- [NVD] CVE-2026-47103 (CRITICAL 9.8) — Python StateMachine versions 3.0.0 before 3.2.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary code by supplying malicious SCXML documents containing crafted `<data expr="...">` attributes evaluated unsafely. The SCXMLProcessor passes atnvd · 2026-06-17
- Ransom & Dark Web Issues Week 3, June 2026ahnlab · 2026-06-17
- What the ThreatLabz 2026 Phishing and Initial Access Report Means for the Public Sectorzscaler_threatlabz · 2026-06-17
- [NVD] CVE-2026-55738 (HIGH 8.8) — A stack-based buffer overflow exists in the raw_to_header function in src/microtar.c in rxi microtar 0.1.0. The function copies the 100-byte name and linkname fields of a TAR header with strcpy without guaranteeing null termination of the source.nvd · 2026-06-17
- [NVD] CVE-2026-54417 (HIGH 7.5) — An integer overflow in the mtar_next function in src/microtar.c in rxi microtar 0.1.0 allows a remote attacker to cause a denial of service (uncontrolled CPU consumption / infinite loop) via a crafted tar archive. mtar_next computes the offset to the next record as round_up(h.siznvd · 2026-06-17
- [NVD] CVE-2025-69130 (HIGH 8.8) — Deserialization of Untrusted Data vulnerability in Pixel Makers Creative INC. Entrepreneur - Booking for Small Businesses WordPress Theme allows Object Injection. This issue affects Entrepreneur - Booking for Small Businesses WordPress Theme: from n/a before 3.1.5.nvd · 2026-06-17
- FortiBleed — 75k Fortinet firewalls have admin passwords crackeddoublepulsar · 2026-06-17
- From Stars to Upvotes: Fake Reputation Fueling a Crypto Clipboard Hijackercheckpoint_research · 2026-06-17
- [NVD] CVE-2026-48779 (HIGH 7.5) — ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.0.0 up to 8.21.0 are affected by a memory exhaustion DoS vulnerability. A peer can send a high volumenvd · 2026-06-17
- [NVD] CVE-2026-46979 (MEDIUM 6.5) — Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Integration and Interfaces). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS nvd · 2026-06-17
- [NVD] CVE-2026-46851 (HIGH 8.1) — Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Peonvd · 2026-06-17
- Risky Bulletin: China arrests Silver Fox cybercrime group suspectsriskybiz_news · 2026-06-17
- State Digital Surveillance Risk Landscaperecordedfuture · 2026-06-17
- [NVD] CVE-2026-0165 (MEDIUM 6.5) — In several functions of the RTCP packet decoder, there is a possible out-of-bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.nvd · 2026-06-16
- [NVD] CVE-2026-0158 (MEDIUM 4.0) — In Camera, there is a possible unauthorized way to access photos due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.nvd · 2026-06-16
- [NVD] CVE-2026-0157 (MEDIUM 4.3) — In RtcpHeader::decodeRtcpHeader, there is a possible OOB read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.nvd · 2026-06-16
- [NVD] CVE-2026-0156 (HIGH 7.5) — In checkSsrcCollisionOnRcv of RtpSession.cpp, there is a possible memory safety issue due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.nvd · 2026-06-16
- [NVD] CVE-2026-0155 (MEDIUM 5.3) — In ImsMediaBitReader::ReadByteBuffer, there is a possible OOB read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.nvd · 2026-06-16
- [NVD] CVE-2026-0144 (HIGH 7.5) — In writeAocCommand of AocAudioCodec.cpp, there is a possible memory safety issue due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.nvd · 2026-06-16
- [NVD] CVE-2026-0142 (MEDIUM 4.0) — In iavb_parse_key_data of avb_rsa.c, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.nvd · 2026-06-16
- [NVD] CVE-2026-0141 (MEDIUM 5.3) — In decodeAppPacket of RtcpAppPacket.cpp, there is a possible OOB read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.nvd · 2026-06-16
- [NVD] CVE-2026-0140 (MEDIUM 4.3) — In RtpPacket::decodePacket, there is a possible out-of-bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.nvd · 2026-06-16
- [NVD] CVE-2026-0134 (MEDIUM 4.0) — In PostWipeData of recovery_ui.cpp, there is a possible data persistence issue after a factory reset due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.nvd · 2026-06-16
- [NVD] CVE-2026-0130 (MEDIUM 4.3) — In RtcpChunk::decodeRtcpChunk, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.nvd · 2026-06-16
- [NVD] CVE-2026-0128 (MEDIUM 6.5) — In RtcpFbPacket::decodeRtcpFbPacket, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.nvd · 2026-06-16
- Prevent AI-Powered Cyberattacks With Deception Technologyzscaler_threatlabz · 2026-06-16
- WordPress PBN Plugin Drops Dual Webshells via Database Injectionsucuri_blog · 2026-06-16
- Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerabilitycisco_psirt · 2026-06-16
- Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerabilitycisco_psirt · 2026-06-16
- Zero Trust for AI Agents: The Only Model Built for What’s Nextzscaler_threatlabz · 2026-06-16
- Mythic Embarking on the Open Seas: Containerized Payload Delivery for Kubernetes Assessmentsspecterops · 2026-06-16
- Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCEunit42 · 2026-06-16
- [NVD] CVE-2026-7273 (HIGH 8.8) — A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.nvd · 2026-06-16
- [Breach] Houston City College — 831,642 accounts exposedhibp_breaches · 2026-06-16
- [CISA KEV] CVE-2026-48907 — Widget Factory Joomla Content Editor : Widget Factory Joomla Content Editor Improper Access Control Vulnerabilitycisa_kev · 2026-06-16
- The Intelligence No One Else Has: Inside Recorded Future’s Proprietary Collection Enginerecordedfuture · 2026-06-16
- Inside the Modern SOC: The 72-Minute Raceunit42 · 2026-06-15
- Cisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerabilitycisco_psirt · 2026-06-15
- Between Two Nerds: Why NATO and cyber don't mixriskybiz_news · 2026-06-15
- [NVD] CVE-2026-53705 (HIGH 7.6) — A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size calculation (4 * block_samples * channels) in gst_wavpack_dec_handle_frame() causes a very small heap allocation. Thnvd · 2026-06-15
- [NVD] CVE-2026-53704 (HIGH 7.1) — A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package. When processing a RealMedia file containing a specially crafted FILEINFO metadata section, the demuxer parses variable-name and variable-value pairs using re_skip_pascal_string() without validatingnvd · 2026-06-15
- [NVD] CVE-2026-52722 (HIGH 7.1) — A signed integer overflow vulnerability was found in GStreamer's VMnc decoder. A crafted VMnc stream with large cursor dimensions can overflow signed integer payload-size arithmetic, bypassing a length check and leading to out-of-bounds reads. A remote attacker could trick a usernvd · 2026-06-15
- [NVD] CVE-2026-52720 (HIGH 8.8) — A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather than individual dimensions, allowing a malicious VNC server to send a rectangle that extends beyond the framebuffer. A remote attacknvd · 2026-06-15
- [NVD] CVE-2026-10634 (MEDIUM 4.8) — Zephyr's native TCP stack iterates the global connection list in net_tcp_foreach() (subsys/net/ip/tcp.c) using the SYS_SLIST_FOR_EACH_CONTAINER_SAFE macro, which caches a pointer to the next list node. Prior to this fix the function released tcp_lock while invoking the per-connecnvd · 2026-06-15
- Spying Via Your Mobile Phone: Companies Can Locate Any Device at Any Timecitizenlab · 2026-06-15
- Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Researchmandiant_gti · 2026-06-15
- 15th June – Threat Intelligence Reportcheckpoint_research · 2026-06-15
- Risky Bulletin: Arch Linux supply chain attack hits 1,900 packagesriskybiz_news · 2026-06-15
- [Breach] Sysco — 2,691,852 accounts exposedhibp_breaches · 2026-06-15
- [CISA KEV] CVE-2026-54420 — LiteSpeed cPanel Plugin: LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerabilitycisa_kev · 2026-06-15
- [CISA KEV] CVE-2026-20262 — Cisco Catalyst SD-WAN Manager: Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerabilitycisa_kev · 2026-06-15
- [Breach] Moody Bible Institute — 2,303,416 accounts exposedhibp_breaches · 2026-06-15
- [Breach] Glendale Community College — 793,925 accounts exposedhibp_breaches · 2026-06-15
- [Breach] June 2026 Stealer Logs — 56,278,397 accounts exposedhibp_breaches · 2026-06-15
- Sponsored: Ent on using AI to track human behavior on the endpointriskybiz_news · 2026-06-14
- [NVD] CVE-2026-54413 (HIGH 8.2) — driftregion iso14229 through 0.9.0 contains an integer underflow and downstream out-of-bounds read in the Handle_0x27_SecurityAccess function in iso14229.c that allows a remote unauthenticated attacker to crash a UDS server and potentially read memory past the receive buffer by snvd · 2026-06-14
- [NVD] CVE-2026-54412 (HIGH 8.2) — LiamBindle MQTT-C through version 1.1.6 contains a heap-based out-of-bounds read and integer underflow in the mqtt_unpack_publish_response function in src/mqtt.c that allows a remote unauthenticated attacker controlling an MQTT broker - or able to inject MQTT traffic into an unennvd · 2026-06-14
- [NVD] CVE-2026-54411 (MEDIUM 5.9) — Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling nvd · 2026-06-14
- [NVD] CVE-2026-54410 (HIGH 8.6) — nanoMODBUS through v1.23.0 contains an off-by-one buffer overflow in the recv_msg_header function of the Modbus/TCP server that allows remote unauthenticated attackers to write one attacker-controlled byte past the end of the 260-byte receive buffer by sending a crafted MBAP framnvd · 2026-06-14
- When a Government Pulls an AI Model: What the Fable 5 and Mythos 5 Suspension Means for Security Teamssnyk · 2026-06-14
- [NVD] CVE-2026-6428 (HIGH 7.6) — SQL Injection in reports/catalogue_out.pl in Koha Community Koha through 22.11.37, 23.x, 24.x before 24.11.16, 25.05.x before 25.05.11, 25.11.x before 25.11.05, 26.05.x before 26.05.01, and 26.11.x before 26.11.00 allows an authenticated staff user with the Reports module flag tonvd · 2026-06-13
- [NVD] CVE-2026-54231 (MEDIUM 5.5) — A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script queries the systemd journal for log entries matching the crashed process and writes the results to files in the dump directory without sanitizing embedded contnvd · 2026-06-13
- [NVD] CVE-2026-54230 (HIGH 7.0) — A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replaced with a symlink, the shell process running as root follows nvd · 2026-06-13
- [NVD] CVE-2026-54229 (HIGH 7.0) — A race condition was found in the abrt-dbus D-Bus service's ChownProblemDir method. ChownProblemDir opens the dump directory with DD_OPEN_READONLY and calls dd_chown to change ownership of all files to the caller's uid, succeeding even while post-create event handlers hold a writnvd · 2026-06-13
- [NVD] CVE-2026-54228 (HIGH 7.8) — A time-of-check time-of-use (TOCTOU) race condition was found in the abrt-dbus D-Bus service's SetElement method. Between dump directory creation and post-create event execution, any local user can call SetElement to write arbitrary text files into the root-owned dump directory, nvd · 2026-06-13
- Secure the High Value SAP Data Estate: Why Zero Trust Access is Now a Business Imperativezscaler_threatlabz · 2026-06-12
- [NVD] CVE-2026-44990 (CRITICAL 9.3) — ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the default configuration, versions of `sanitize-html` prior to 2.17.4 can turn attacker-controlled content inside a disallowed `xmp` elemnvd · 2026-06-12
- Shai-Hulud Campaign Evolution: Miasma, Hades, and AI Scanner Evasionzscaler_threatlabz · 2026-06-12
- Why Use App-Level Auth When Every Database Has Auth? (Splunk Enterprise CVE-2026-20253 Pre-Auth RCE)watchtowr · 2026-06-12
- [NVD] CVE-2026-12143 (HIGH 7.5) — form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header without escaping carriage return (CR), line feenvd · 2026-06-12
- [NVD] CVE-2026-44172 (CRITICAL 9.1) — MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the database using text protocol and big5 character set was vulnerablnvd · 2026-06-12
- Canada Finally Has a National AI Strategy. Experts Hate It.citizenlab · 2026-06-12
- [NVD] CVE-2026-50010 (HIGH 7.5) — Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SimpleTrustManagerFactory.engineGetTrustManagers() and related paths wrap any user-supplied plain X509TrustManager in X509TrustManagerWrappenvd · 2026-06-12
- [NVD] CVE-2026-48059 (HIGH 7.5) — Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, the HAProxy PROXY protocol v2 codec in netty leaks native or heap memory on every connection when a client sends a syntactically valid headenvd · 2026-06-12
- [NVD] CVE-2026-48043 (MEDIUM 5.3) — Netty is a network application framework for development of protocol servers and clients. In netty-codec-http2 prior to versions 4.1.135.Final and 4.2.15.Final, the `DelegatingDecompressorFrameListener` class orchestrates HTTP/2 decompression by embedding a per-stream `EmbeddedChnvd · 2026-06-12
- [NVD] CVE-2026-45416 (HIGH 7.5) — Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SslClientHelloHandler.decode() reads the 24-bit TLS handshake length and, when the ClientHello does not fit in the first record, eagerly allnvd · 2026-06-12
- [NVD] CVE-2026-44893 (HIGH 7.5) — Netty is a network application framework for development of protocol servers and clients. In netty-codec-haproxy prior to versions 4.1.135.Final and 4.2.15.Final, when decoding a PP2_TYPE_SSL TLV, HAProxyMessage.readNextTLV() first calls `header.retainedSlice(header.readerIndex()nvd · 2026-06-12
- Factoring "short-sleeve" RSA keys with polynomialstrailofbits · 2026-06-12
- [NVD] CVE-2026-50645 (HIGH 7.5) — There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache CXF, which can lead to uncontrolled resource consumption or a denial of service attack. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, nvd · 2026-06-12
- [NVD] CVE-2026-50634 (MEDIUM 6.5) — A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to process metadata that was not authenticated by the accepted signature. This can bypass the application's assumption that accepted `Content-Type` or protected HTTP-header metadata came nvd · 2026-06-12
- [NVD] CVE-2026-50633 (HIGH 8.1) — A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to manipulate the JCA deployment descriptor (ra.xml) or runtime activation parameters. Users are recommended to upgrade to versionnvd · 2026-06-12
- [NVD] CVE-2026-50632 (HIGH 8.1) — A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users are recommended to nvd · 2026-06-12
- [NVD] CVE-2026-50631 (HIGH 7.4) — A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-use semantics and generate multiple valid Access Tokens, when 'recycleRefreshTokens' is set to false. A leaked refresh token can be replayed concurrently by multnvd · 2026-06-12
- [NVD] CVE-2026-50630 (MEDIUM 6.5) — A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class. When constructing the WWW-Authenticate response header, the 'realm' parameter is concatenated without sanitizing Carriage Return (CR) and Line Feed (LF) characters. If an attacker can control the realm nvd · 2026-06-12
- [NVD] CVE-2026-50629 (MEDIUM 5.3) — The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages without sanitizing control characters. This allows an attacker to inject arbitrary content, including fake log entries, into the server's log files. Users are recnvd · 2026-06-12
- [NVD] CVE-2026-50628 (CRITICAL 9.8) — A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this security feature inadvertently creates an inverse security check. Users are recommended to upgrade to vnvd · 2026-06-12
- [NVD] CVE-2026-50627 (CRITICAL 9.1) — The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one Resource Server to be successfully replayed against a completely different Resource Server, leading to Token Confusion/Rounvd · 2026-06-12
- [NVD] CVE-2026-50623 (MEDIUM 4.8) — An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF. Due to a missing 'throw' keyword in the security context check, the introspection endpoint (/services/oauth2/introspect) can be accessed by any unauthenticated network attacker. Hnvd · 2026-06-12
- [NVD] CVE-2026-49875 (CRITICAL 9.8) — Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, wnvd · 2026-06-12
- [NVD] CVE-2026-48914 (MEDIUM 6.7) — A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a malformed virtio-blk SCSI requesnvd · 2026-06-12
- Borrowed Trust – Systematic Exploitation of Abandoned Cloud DNS Delegations to serve Thai Gambling SEO Contentcyble · 2026-06-12
- Marking Your Own Homework (Check Point Remote Access VPN IKEv1 Authentication Bypass CVE-2026-50751)watchtowr · 2026-06-12
- Risky Bulletin: CISA tightens patching rules amid bug delugeriskybiz_news · 2026-06-12
- Sponsored: Understanding CI/CD attack pathsriskybiz_news · 2026-06-12
- [NVD] CVE-2026-20746 — Virtual attribute handling in Ping Identity PingDirectory in affected versions allows only authorized users to exhaust java memory heap when recent login history is enabled and copying virtual attributes that reference ds-privilege-name values.nvd · 2026-06-12
- [NVD] CVE-2026-9125 (MEDIUM 6.4) — The Presto Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_url' parameter of the [presto_player_overlay] shortcode in versions up to, and including, 4.2.0 This is due to insufficient input sanitization and output escaping in the getOverlays(nvd · 2026-06-12