THREAT OPS › Threat News
Threat Intelligence News
12130 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- Sponsored: Understanding CI/CD attack pathsriskybiz_news · 2026-06-12
- [NVD] CVE-2026-20746 — Virtual attribute handling in Ping Identity PingDirectory in affected versions allows only authorized users to exhaust java memory heap when recent login history is enabled and copying virtual attributes that reference ds-privilege-name values.nvd · 2026-06-12
- [NVD] CVE-2026-9125 (MEDIUM 6.4) — The Presto Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_url' parameter of the [presto_player_overlay] shortcode in versions up to, and including, 4.2.0 This is due to insufficient input sanitization and output escaping in the getOverlays(nvd · 2026-06-12
- [Breach] American Tower — 216,601 accounts exposedhibp_breaches · 2026-06-12
- [CISA KEV] CVE-2026-35273 — Oracle PeopleSoft Enterprise PeopleTools: Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerabilitycisa_kev · 2026-06-12
- [Breach] JCPenney — 368,418 accounts exposedhibp_breaches · 2026-06-12
- [NVD] CVE-2026-44890 (HIGH 7.5) — Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can cause DoS by sending crafted Redis payloads across multiple connections without `\r\n`. This exhausts tnvd · 2026-06-11
- [NVD] CVE-2026-44250 (HIGH 7.5) — Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can cause DoS by sending a crafted Redis payload with deeply nested arrays. This forces the server to allocnvd · 2026-06-11
- [NVD] CVE-2026-44249 (HIGH 8.1) — Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid pubnvd · 2026-06-11
- [NVD] CVE-2026-52860 (HIGH 7.8) — Vim is an open source, command line text editor. Prior to version 9.2.0597, Vim's Python omni-completion executes reconstructed function and class definitions from the current buffer with exec() as part of populating the completion dictionary. Python evaluates function default vanvd · 2026-06-11
- [NVD] CVE-2026-47162 (HIGH 8.8) — Vim is an open source, command line text editor. Prior to version 9.2.0495, a Vimscript code injection vulnerability exists in s:NetrwBookHistSave() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when serializing browsed directory paths to the history file ~nvd · 2026-06-11
- [NVD] CVE-2026-44496 (HIGH 7.5) — Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and before 1.16.0 on the 1.x line build a regular expression from the configured XSRF cookie name without escaping regex metacharacters. In standard browser environmentsnvd · 2026-06-11
- [NVD] CVE-2026-44495 (HIGH 7.0) — Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already polluted Object.prototype.transfnvd · 2026-06-11
- [NVD] CVE-2026-44494 (HIGH 8.7) — Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's dependency tree to be escalated into a full Man-nvd · 2026-06-11
- [NVD] CVE-2026-44492 (HIGH 8.6) — Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise IPv4-mapped IPv6 addresses. When NO_PROXY lists an IPv4 address such as 127.0.0.1 or 169.254.169.254, a request URL using the IPv4-mapped IPv6 form (::ffff:7f00:nvd · 2026-06-11
- [NVD] CVE-2026-44488 (HIGH 7.5) — Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce configured request and response size limits when requests were sent with the fetch adapter. Applications that selected adapter: 'fetch', or ran in environments whnvd · 2026-06-11
- [NVD] CVE-2026-44487 (HIGH 7.5) — Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’s Node.js HTTP adapter may forward a Proxy-Authorization header to a redirected origin during specific proxy-to-direct redirect flows. This affects Node.js usage, where an initial nvd · 2026-06-11
- [NVD] CVE-2026-44486 (HIGH 7.5) — Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’ Node.js HTTP adapter can leak proxy credentials to a redirect target in affected versions. When a request is sent through an authenticated proxy, Axios may add a Proxy-Authorizatinvd · 2026-06-11
- Building an Indirect Prompt Injection Workflowspecterops · 2026-06-11
- ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploitmandiant_gti · 2026-06-11
- From SQLi to RCE – Exploiting LangGraph’s Checkpointercheckpoint_research · 2026-06-11
- LABScon25 Replay | Keynote: Steps to an Ecology of Cybersentinelone · 2026-06-11
- Threat Actors Weaponize AI Hype to Deliver AsyncRATfortinet_research · 2026-06-11
- [NVD] CVE-2026-6552 — Rejected reason: This CVE ID has been rejected. GitLab determined that the reported behavior does not constitute a vulnerability: linking a group SAML identity requires the user to explicitly consent to that group controlling their GitLab account for sign-in, and management of grnvd · 2026-06-11
- The Escalating Cyber Risk Landscape in Regional Conflicts & Strategic Actions for 2026eclecticiq · 2026-06-11
- [NVD] CVE-2026-41001 (MEDIUM 5.3) — Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker's data directory when no explicit path is configured. A local attacker on the same host can pre-create this predictable directory or place a symlink before the applnvd · 2026-06-11
- [NVD] CVE-2026-41000 (LOW 3.7) — Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-time checks. As a result, protections against replay of UsernameToken nonces and creation timestamps, Timestamp elements, and certain SAML one-time-use semantics nvd · 2026-06-11
- [NVD] CVE-2026-40999 (HIGH 8.6) — When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate outbound connections through configured WebServiceMessageSender instances to destinations taken directly from request headers without verifying that those destinations are safe to cnvd · 2026-06-11
- [NVD] CVE-2026-40998 (HIGH 8.2) — Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed attacker-controlled XML with the JDK's default DocumentBuilderFactory behavior instead of Spring's hardened parser configuration. Applications that evaluate XPath anvd · 2026-06-11
- [NVD] CVE-2026-40997 (MEDIUM 5.3) — Several Spring WS integration paths with Spring Security could surface detailed account state (for example locked or disabled user semantics) to remote SOAP clients through exception messages or callback outcomes, instead of failing with generic authentication errors. That behavinvd · 2026-06-11
- [NVD] CVE-2026-40996 (MEDIUM 4.8) — Wss4jSecurityInterceptor defaulted allowRSA15KeyTransportAlgorithm to true, overriding Apache WSS4J's safer default for validation RequestData. Inbound WS-Security decryption could therefore accept RSA PKCS#1 v1.5 (rsa-1_5) encrypted key material unless operators explicitly reconnvd · 2026-06-11
- [NVD] CVE-2026-40995 (MEDIUM 5.4) — X509AuthenticationProvider could issue a fully authenticated X509AuthenticationToken when a presented certificate mapped to UserDetails, without applying Spring Security's standard account lifecycle checks (disabled, locked, expired, or credentials-expired accounts). Affected venvd · 2026-06-11
- [NVD] CVE-2026-40994 (HIGH 8.2) — Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation disabled WSS4J BSP enforcement on RequestData. Services that validate WS-Security on the network could therefore accept messages that violate BSP rules, weakeningnvd · 2026-06-11
- [NVD] CVE-2026-40992 (MEDIUM 5.0) — Spring Boot's Mail auto-configuration does not enable hostname verification. Applications that set the relevant JavaMail property, such as spring.mail.properties.mail.smtp.ssl.checkserveridentity=true, are not affected. Affected versions: Spring Boot 4.0.0 through 4.0.6; 3.5.0 tnvd · 2026-06-11
- [NVD] CVE-2026-40987 (HIGH 7.1) — A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem (outside the configured local-directory) with attacker-controlled content. Affected versions: Spring Integration 7.0.0 through 7.0.4; 6.5.0 through 6.5.8; 6.4.0 through 6.4nvd · 2026-06-11
- [NVD] CVE-2026-40986 (MEDIUM 4.8) — Spring Web Flow's JavaScript RemotingHandler renders the body of an error response as HTML even when the response is not "text/html", which can result in a scripting attack in the user's browser if the error response from the server contains error details with input reflected fronvd · 2026-06-11
- Srsly Risky Biz: Europe wants to wean itself off US techriskybiz_news · 2026-06-11
- Recorded Future Launches Impact and Metrics Dashboardrecordedfuture · 2026-06-11
- Entra Agent ID: The blueprint blast radiusdatadog_seclabs · 2026-06-11
- Cyber-Enabled Maritime Sanctions Evasionrecordedfuture · 2026-06-11
- [Breach] Ralph Lauren — 139,903 accounts exposedhibp_breaches · 2026-06-11
- [CISA KEV] CVE-2026-10520 — Ivanti Sentry: Ivanti Sentry OS Command Injection Vulnerabilitycisa_kev · 2026-06-11
- [NVD] CVE-2026-46625 (HIGH 7.5) — JavaScript Cookie is a JavaScript API for handling cookies, client-side. Prior to version 3.0.7, js-cookie's internal assign() helper copies properties with for...in + plain assignment. When the source object is produced by JSON.parse, the JSON object's "__proto__" member is an onvd · 2026-06-10
- [NVD] CVE-2026-6893 (HIGH 7.5) — A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracut's legacy DHCP path. These options are impnvd · 2026-06-10
- [NVD] CVE-2026-48859 (MEDIUM 5.3) — Observable Timing Discrepancy vulnerability in Erlang/OTP ssh (ssh_auth, ssh_options modules) allows unauthenticated remote username enumeration via timing side-channel in password authentication. When the SSH daemon is configured with the user_passwords or password option, ssh_nvd · 2026-06-10
- Oops, I Weaponized the Database: Abusing AI Features in SQL Server 2025specterops · 2026-06-10
- Who Runs the Ransomware Group ‘The Gentlemen?’krebs · 2026-06-10
- 2026-007: Critical Vulnerability in Windows Netlogoncert_eu · 2026-06-10
- Risky Bulletin: Nightmare Eclipse drops fresh 0dayriskybiz_news · 2026-06-10
- [NVD] CVE-2026-11837 (HIGH 7.3) — A local privilege escalation vulnerability was found in the ansible.posix authorized_key module. The module's keyfile() function uses os.chown() instead of os.lchown() and opens files without O_NOFOLLOW when managing SSH authorized keys. An unprivileged local user can pre-stage snvd · 2026-06-10
- Prompt Engineering for Security Agents: A Measurable Approach with GEPAspecterops · 2026-06-10
- Introducing GhostWorks: A Practical AI Initiative from SpecterOpsspecterops · 2026-06-10
- [NVD] CVE-2026-41697 (MEDIUM 4.8) — Spring Data Relational does not properly escape binding values of externally-controlled input when using StringMatcher (STARTING, ENDING, or CONTAINING) in Query By Example (QBE). An attacker can supply wildcard characters to perform boolean-based blind data inference. Affected nvd · 2026-06-10
- 2026 FIFA World Cup: What Public Safety Officials Need to Knowrecordedfuture · 2026-06-10
- China's Noncombatant Evacuation Operations: 2005–2025recordedfuture · 2026-06-10
- A Record-Breaking Patch Tuesday for June 2026krebs · 2026-06-09
- [NVD] CVE-2026-47938 (CRITICAL 10.0) — Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed.nvd · 2026-06-09
- The June 2026 Security Update Reviewzdi_blog · 2026-06-09
- [NVD] CVE-2026-47991 (MEDIUM 6.1) — Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Redirect (Open Redirect) vulnerability that could result in a Security feature bypass. An attacker could construct a malicious URL that redirects a victim to an attacker-controlled nvd · 2026-06-09
- [NVD] CVE-2026-45447 (HIGH 8.8) — Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process crashes, heap corruption, or potentially remote code execution. When processing a PKCS#nvd · 2026-06-09
- User-to-User Authentication: Down the Rabbit Hole – Part 1specterops · 2026-06-09
- [NVD] CVE-2026-11793 (MEDIUM 4.9) — A stack buffer overflow flaw was found in 389 Directory Server. The checkPrefix() function in pw.c copies an attacker-controlled algorithm ID into a 256-byte stack buffer without bounds checking when parsing reversible-encrypted attribute values. An attacker with Directory Managenvd · 2026-06-09
- [NVD] CVE-2026-11788 (MEDIUM 5.9) — A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the system is under memory pressure.nvd · 2026-06-09
- [NVD] CVE-2026-46323 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: net: gro: don't merge zcopy skbs skb_gro_receive() can currently copy frags between the source and GRO skb, without checking the zerocopy status, and in particular the SKBFL_MANAGED_FRAG_REFS flag. When SKBFL_nvd · 2026-06-09
- [NVD] CVE-2026-46316 (CRITICAL 9.3) — In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry vgic_its_invalidate_cache() walks the per-ITS translation cache with xa_for_each() and drops the cache's reference on each ennvd · 2026-06-09
- [NVD] CVE-2025-10263 (CRITICAL 9.1) — Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C, Cortex-A710, Cortex-A78, A78AE & A78C, Cortex-A77, Cortex-A76 & A76A may allow writes to resources owned by a higher exnvd · 2026-06-09
- [NVD] CVE-2026-9698 (CRITICAL 9.8) — DBI versions before 1.648 for Perl saved errors in a limited-sized buffer. Error messages that were returned when RaiseError, PrintError or HandleError were set were written to a 200-byte buffer without a length limit. Attackers that can influence the error text in an applicatinvd · 2026-06-09
- Defend against frontier cyber models: Cloudflare's architecture as customer zerocloudflare_security · 2026-06-09
- [NVD] CVE-2026-41710 (MEDIUM 5.9) — An attacker can craft a large number of unique requests that trigger a failure, exhausting the capacity of the application-wide stateful retry cache. Once the cache is full, it permanently rejects any further updates, causing all later stateful retries and circuit breakers in thenvd · 2026-06-09
- [NVD] CVE-2026-40984 (HIGH 7.5) — In Micrometer, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Affected versions: micrometer-core 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.14.15; 1.13.0 through 1.13.18; 1.9.0 throughnvd · 2026-06-09
- [CISA KEV] CVE-2026-11645 — Google Chromium V8: Google Chromium V8 Out-of-Bounds Read and Write Vulnerabilitycisa_kev · 2026-06-09
- [CISA KEV] CVE-2026-7473 — Arista Extensible Operating System: Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerabilitycisa_kev · 2026-06-09
- [CISA KEV] CVE-2026-20245 — Cisco Catalyst SD-WAN Manager: Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerabilitycisa_kev · 2026-06-09
- Russia’s Defense-Based Economy Risks Forcing Putin to Fight Warsrecordedfuture · 2026-06-09
- [Breach] Goose Creek — 6,574,121 accounts exposedhibp_breaches · 2026-06-09
- [Breach] University of Nottingham — 454,635 accounts exposedhibp_breaches · 2026-06-09
- Crowdsourced AI += Knosticvirustotal_blog · 2026-06-08
- Between Two Nerds: Nerds at NATOriskybiz_news · 2026-06-08
- [NVD] CVE-2026-48507 (HIGH 7.1) — Snipe-IT is an IT asset/license management system. A vulnerability in versions prior to 8.6.0 allows a non-admin user holding only the granular `users.edit` permission to lock every admin out of the instance by editing the `activated` flag (which determines whether or not a usernvd · 2026-06-08
- [NVD] CVE-2026-46306 (HIGH 7.5) — In the Linux kernel, the following vulnerability has been resolved: flow_dissector: do not dissect PPPoE PFC frames RFC 2516 Section 7 states that Protocol Field Compression (PFC) is NOT RECOMMENDED for PPPoE. In practice, pppd does not support negotiating PFC for PPPoE sessionnvd · 2026-06-08
- [NVD] CVE-2026-46305 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: os_dep: avoid NULL pointer dereference in rtw_cbuf_alloc The return value of kzalloc_flex() is used without ensuring that the allocation succeeded, and the pointer is dereferenced unconditionvd · 2026-06-08
- [NVD] CVE-2026-46303 (HIGH 8.2) — In the Linux kernel, the following vulnerability has been resolved: isofs: validate Rock Ridge CE continuation extent against volume size rock_continue() reads rs->cont_extent verbatim from the Rock Ridge CE record and passes it to sb_bread() without checking that the block numnvd · 2026-06-08
- [NVD] CVE-2026-39910 (HIGH 8.8) — STACKIT IaaS API contains a missing authorization check vulnerability that allows authenticated, low-privileged attackers to escalate privileges to full organization compromise by attaching arbitrary service accounts to virtual machines they control. Attackers can exploit the unvnvd · 2026-06-08
- [NVD] CVE-2026-44185 (HIGH 7.3) — Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.nvd · 2026-06-08
- [NVD] CVE-2026-42536 (HIGH 7.5) — Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.nvd · 2026-06-08
- Keeping a Short Leash: New AzureHound Least-Privilege Documentationspecterops · 2026-06-08
- 8th June – Threat Intelligence Reportcheckpoint_research · 2026-06-08
- Turning Cloudflare’s threat indicators into real-time WAF rulescloudflare_security · 2026-06-08
- Customer case study: How Intelligence Center™ helps CTI teams cut through noise and act with confidenceeclecticiq · 2026-06-08
- Risky Bulletin: RubyGems adds dependency cooldowns to counter supply chain attacksriskybiz_news · 2026-06-08
- [CISA KEV] CVE-2026-42271 — BerriAI LiteLLM: BerriAI LiteLLM Command Injection Vulnerabilitycisa_kev · 2026-06-08
- [CISA KEV] CVE-2026-50751 — Check Point Security Gateway: Check Point Security Gateway Improper Authentication Vulnerabilitycisa_kev · 2026-06-08
- May 2026 CVE Landscaperecordedfuture · 2026-06-08
- Seeking Counsel: Ongoing Targeted Campaign Against US Law Firmsmandiant_gti · 2026-06-05
- [NVD] CVE-2026-11332 (HIGH 7.8) — A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags thronvd · 2026-06-05
- Risky Bulletin: EU unveils digital sovereignty planriskybiz_news · 2026-06-05
- [NVD] CVE-2026-41567 (HIGH 7.2) — Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped through `docker cp -`, the daemon resolves decompression binaries nvd · 2026-06-05
- Why Holistic Sourcing Wins: The Numbers Behind the Recorded Future Advantagerecordedfuture · 2026-06-05
- [CISA KEV] CVE-2026-28318 — SolarWinds Serv-U: SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerabilitycisa_kev · 2026-06-05
- [Breach] Madison Square Garden Sports — 9,796,738 accounts exposedhibp_breaches · 2026-06-05