THREAT OPS › Threat News
Threat Intelligence News
12148 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [NVD] CVE-2026-45897 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_counter: serialize reset with spinlock Add a global static spinlock to serialize counter fetch+reset operations, preventing concurrent dump-and-reset from underrunning values. The lock is taken nvd · 2026-05-27
- [NVD] CVE-2026-42789 (MEDIUM 4.8) — Improper Following of a Certificate's Chain of Trust vulnerability in Erlang OTP public_key (pubkey_cert module) allows a non-CA certificate to be accepted as an intermediate issuer, enabling certificate chain forgery. In lib/public_key/src/pubkey_cert.erl, pubkey_cert:validate_nvd · 2026-05-27
- [NVD] CVE-2026-2340 (MEDIUM 6.5) — A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with writenvd · 2026-05-27
- [NVD] CVE-2026-1933 (HIGH 7.1) — A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, authenticated users with underlying filesystem write permissions may create or delete reparse point metadata through SMB operationsnvd · 2026-05-27
- [NVD] CVE-2026-45841 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO nf_osf_match_one() computes ctx->window % f->wss.val in the OSF_WSS_MODULO branch with no guard for f->wss.val == 0. A CAP_NET_ADMIN user can add snvd · 2026-05-27
- [NVD] CVE-2026-3012 (HIGH 8.0) — A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store without proper verification. An attacker wnvd · 2026-05-27
- Risky Bulletin: Iran to reconnect to the Internetriskybiz_news · 2026-05-27
- [CISA KEV] CVE-2026-48027 — Nx Nx Console: Nx Console Embedded Malicious Code Vulnerabilitycisa_kev · 2026-05-27
- [CISA KEV] CVE-2026-45321 — TanStack TanStack: TanStack Unspecified Vulnerabilitycisa_kev · 2026-05-27
- [CISA KEV] CVE-2026-8398 — Daemon Daemon Tools Lite: Daemon Tools Lite Embedded Malicious Code Vulnerabilitycisa_kev · 2026-05-27
- [NVD] CVE-2026-5260 (HIGH 8.2) — A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information nvd · 2026-05-26
- [NVD] CVE-2026-48710 (MEDIUM 6.5) — Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` heanvd · 2026-05-26
- [NVD] CVE-2026-42013 (HIGH 8.2) — A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the validation process to incorrectly fall back to checking the Common Name (CN) field. This could allow a remote attacker to bypass proper certificate validation, ponvd · 2026-05-26
- [NVD] CVE-2026-42012 (HIGH 7.1) — A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certificate validation process to invd · 2026-05-26
- [NVD] CVE-2026-48864 (HIGH 7.8) — A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerablenvd · 2026-05-26
- [NVD] CVE-2026-7374 (CRITICAL 9.9) — A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console sockets. By replacing the console socket nvd · 2026-05-26
- The Hidden Risk of Service Accounts and Non-Human Identitiesspecterops · 2026-05-26
- Phishing Campaign Deploys JavaScript-Driven PureLogs Variant to Steal Sensitive Datafortinet_research · 2026-05-26
- [NVD] CVE-2026-8376 (CRITICAL 9.8) — Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the size of the joined substring bnvd · 2026-05-26
- [CISA KEV] CVE-2026-48172 — LiteSpeed cPanel Plugin: LiteSpeed cPanel Plugin Privilege Escalation Vulnerabilitycisa_kev · 2026-05-26
- Detecting Tycoon 2FA AiTM attacks across Entra ID and Google Workspaceelastic_security · 2026-05-26
- Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerabilitymandiant_gti · 2026-05-25
- 2 PhaaS 2 Furious: The Evolution of Chinese-Language Phishing Servicesmandiant_gti · 2026-05-25
- [NVD] CVE-2026-46300 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: net: skbuff: preserve shared-frag marker during coalescing skb_try_coalesce() can attach paged frags from @from to @to. If @from has SKBFL_SHARED_FRAG set, the resulting @to skb can contain the same externallynvd · 2026-05-23
- Update: search-for-compression.py Version 0.0.7didier_stevens · 2026-05-23
- [Breach] Baker Distributing — 102,935 accounts exposedhibp_breaches · 2026-05-23
- [Breach] DentaQuest — 2,553,599 accounts exposedhibp_breaches · 2026-05-23
- [Breach] Charter — 4,851,517 accounts exposedhibp_breaches · 2026-05-23
- [NVD] CVE-2026-39821 (CRITICAL 9.6) — The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programnvd · 2026-05-22
- [NVD] CVE-2026-9277 (HIGH 8.1) — shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The `.op` field was backslash-escaped character by character using `/(.)/g`, which in JavaScript does not match line terminators (\n, \r, U+2028, U+2029). A line tenvd · 2026-05-22
- Bringing full YAML anchor support to zizmortrailofbits · 2026-05-22
- [NVD] CVE-2026-39835 (MEDIUM 5.3) — SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.nvd · 2026-05-22
- [NVD] CVE-2026-39832 (CRITICAL 9.1) — When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client nownvd · 2026-05-22
- [NVD] CVE-2026-39830 (CRITICAL 9.1) — A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now nvd · 2026-05-22
- [NVD] CVE-2026-39829 (HIGH 7.5) — The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA parameter could cause several minutes of CPU consumption during signature verification. This could be triggered by unauthenticated cliennvd · 2026-05-22
- [NVD] CVE-2026-39828 (MEDIUM 6.3) — When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restrictions such as force-command after a second factor succeeded. Returning non-nil Permissions with Parnvd · 2026-05-22
- WordPress Site Down? Here’s How to Get Back Onlinesucuri_blog · 2026-05-22
- [CISA KEV] CVE-2026-9082 — Drupal Core: Drupal Core SQL Injection Vulnerabilitycisa_kev · 2026-05-22
- PHANTOMPULSE: anatomy of a hijackable blockchain-C2 RATelastic_security · 2026-05-22
- Introducing TailscaleHound: Mapping Tailscale Attack Paths in BloodHoundspecterops · 2026-05-21
- [NVD] CVE-2026-43502 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: net/rds: handle zerocopy send cleanup before the message is queued A zerocopy send can fail after user pages have been pinned but before the message is attached to the sending socket. The purge path currently nvd · 2026-05-21
- [NVD] CVE-2026-43501 (CRITICAL 9.8) — In the Linux kernel, the following vulnerability has been resolved: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows ipv6_rpl_srh_rcv() decompresses an RFC 6554 Source Routing Header, swaps the next segment into ipv6_hdr->daddr, recompresses, then pulls the old hnvd · 2026-05-21
- [NVD] CVE-2026-43499 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task instead of current in remove_waiter() remove_waiter() is used by the slowlock paths, but it is also used for proxy-lock rollback in rt_mutex_start_proxy_lock() when invoked from futex_nvd · 2026-05-21
- [NVD] CVE-2026-22880 (MEDIUM 6.1) — Mattermost Mobile Apps versions <=2.37 11.4 2.0.37 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to properly validate the SSO authentication callback origin which allows an attacker controlling a malicious Mattermost server to steal user credentials for a legitimate Mattermost server via nvd · 2026-05-21
- SEO poisoning campaign leverages Gemini and Claude Code impersonation to deliver infostealereclecticiq · 2026-05-21
- [NVD] CVE-2026-9149 (MEDIUM 6.5) — A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allocation and a subsequent out-of-bounds writenvd · 2026-05-21
- The Vulnerability Flood Is Now a Board Conversation. Here's How to Lead It.recordedfuture · 2026-05-21
- [CISA KEV] CVE-2025-34291 — Langflow Langflow: Langflow Origin Validation Error Vulnerabilitycisa_kev · 2026-05-21
- [CISA KEV] CVE-2026-34926 — Trend Micro Apex One: Trend Micro Apex One (On-Premise) Directory Traversal Vulnerabilitycisa_kev · 2026-05-21
- [NVD] CVE-2026-9150 (MEDIUM 6.5) — A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA512 checksum tags, leading to menvd · 2026-05-20
- [NVD] CVE-2026-8632 (HIGH 7.8) — A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vulnerability may allow escalation of privileges and/or arbitrary code execution via operating system command injection.nvd · 2026-05-20
- [NVD] CVE-2026-8631 (CRITICAL 9.8) — A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vulnerability may allow escalation of privileges and/or arbitrary code execution via an integer overflow in the hpcups processing path when handling crafted print nvd · 2026-05-20
- Cisco Nexus 3000 and 9000 Series Switches Border Gateway Protocol Denial of Service Vulnerabilitycisco_psirt · 2026-05-20
- Cisco Secure Workload Unauthorized API Access Vulnerabilitycisco_psirt · 2026-05-20
- Cisco ThousandEyes Virtual Appliance Authenticated Remote Code Execution Vulnerabilitycisco_psirt · 2026-05-20
- Cisco ThousandEyes Enterprise Agent BrowserBot Command Injection Vulnerabilitycisco_psirt · 2026-05-20
- [NVD] CVE-2026-5946 (HIGH 7.5) — Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or DNS messages that specify meta-classes (`ANY` or `NONE`) in the question section. Specially crafted requests reaching tnvd · 2026-05-20
- [NVD] CVE-2026-3039 (HIGH 7.5) — BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory consumption when receiving and processing maliciously-constructed packets. Typically these servers will be found in Active Directory integrated DNS deploymentsnvd · 2026-05-20
- Misconfigured, Enrolled and Dormant: Anatomy of a P2Pinfect Kubernetes Compromisefortinet_research · 2026-05-20
- [NVD] CVE-2026-44390 (MEDIUM 5.3) — NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability when handling replies with very large RRsets that Unbound needs to perform name compression for. Malicious upstream responses with very large RRsets with records that don't share a suffix above the root cannvd · 2026-05-20
- [NVD] CVE-2026-42534 (MEDIUM 5.3) — NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the jostle logic that could defeat its purpose and degrade resolution performance. Retransmits of the same query could renew the age of slow running queries and not allow the jostle logic to see them as nvd · 2026-05-20
- [NVD] CVE-2026-41292 (HIGH 7.5) — NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to a degradation of service attack related to parsing long lists of incoming EDNS options. An adversary sending queries with too many EDNS options can hold Unbound threads hostage while they are parsing and creatnvd · 2026-05-20
- [NVD] CVE-2026-3985 (HIGH 7.5) — The Creative Mail – Easier WordPress & WooCommerce Email Marketing plugin for WordPress is vulnerable to SQL Injection via the 'checkout_uuid' parameter in all versions up to, and including, 1.6.9. This is due to insufficient escaping on the user supplied parameter and lack of sunvd · 2026-05-20
- [CISA KEV] CVE-2008-4250 — Microsoft Windows: Microsoft Windows Buffer Overflow Vulnerabilitycisa_kev · 2026-05-20
- [CISA KEV] CVE-2009-1537 — Microsoft DirectX: Microsoft DirectX NULL Byte Overwrite Vulnerabilitycisa_kev · 2026-05-20
- [CISA KEV] CVE-2009-3459 — Adobe Acrobat and Reader: Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerabilitycisa_kev · 2026-05-20
- [CISA KEV] CVE-2010-0249 — Microsoft Internet Explorer: Microsoft Internet Explorer Use-After-Free Vulnerabilitycisa_kev · 2026-05-20
- [NVD] CVE-2026-5090 (MEDIUM 6.1) — Template::Plugin::HTML versions before 3.103 for Perl allows HTML and JavaScript to be injected. The html_filter function did not escape single quotes. HTML attributes inside of single quotes could be have code injected. For example, the variable "var" in <a id='ref' titlenvd · 2026-05-19
- Continued Evolution of Persistence Mechanism Against Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defensecisco_psirt · 2026-05-19
- [NVD] CVE-2025-14575 — An Uncontrolled Search Path Element vulnerability in the OpenSSL TLS backend of Qt Network (qtbase) in Qt Qt Framework (Unix) allows a local attacker to load a rogue CA certificate as a trusted system authority via a crafted certificate file placed in the application's working dinvd · 2026-05-19
- [NVD] CVE-2026-7860 — A possible information disclosure vulnerability exists in the Vaadin Maven plugin and Vaadin Gradle plugin that exposes the full set of environment variables in build logs whenever the frontend build process exits with a non-zero status. Because the build environment may contain nvd · 2026-05-19
- [NVD] CVE-2026-43492 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() Yiming reports an integer underflow in mpi_read_raw_from_sgl() when subtracting "lzeros" from the unsigned "nbytes". For this to happen, the scnvd · 2026-05-19
- At Mythos Speed: A Defender's Playbook for the AI Vulnerability Surge in 2026recordedfuture · 2026-05-19
- Mini Shai-Hulud Hits AntV: 300+ Malicious npm Packages Published via Compromised Maintainer Accountsnyk · 2026-05-18
- What to Do When a Third-Party Data Breach Puts Your Website at Risksucuri_blog · 2026-05-18
- [NVD] CVE-2026-8836 (CRITICAL 9.8) — A vulnerability was found in lwIP up to 2.2.1. Affected is the function snmp_parse_inbound_frame of the file src/apps/snmp/snmp_msg.c of the component snmpv3 USM Handler. Performing a manipulation of the argument msgAuthenticationParameters results in stack-based buffer overflow.nvd · 2026-05-18
- [NVD] CVE-2026-42009 (HIGH 7.5) — A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequennvd · 2026-05-18
- Why commercial cyber threat intelligence is failing defense operationseclecticiq · 2026-05-18
- Project Glasswing: what Mythos showed uscloudflare_security · 2026-05-18
- Pwn2Own Berlin 2026: Day Three Results and Master of Pwzdi_blog · 2026-05-16
- [NVD] CVE-2026-45736 (MEDIUM 4.4) — ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability is fixed in 8.20.1.nvd · 2026-05-15
- Welcome to BlackFile: Inside a Vishing Extortion Operationmandiant_gti · 2026-05-15
- Raising the bar: Quality, shared responsibility, and the future of GitHub’s bug bounty programgithub_security_lab · 2026-05-15
- PureLogs: Delivery via PawsRunner Steganographyfortinet_research · 2026-05-15
- Pwn2Own Berlin 2026 - Day Two Resultszdi_blog · 2026-05-15
- April 2026 CVE Landscaperecordedfuture · 2026-05-15
- [NVD] CVE-2026-44673 (HIGH 7.5) — libyang is a YANG data modeling language library. Prior to SO 5.2.15, lyb_read_string() in src/parser_lyb.c contains an integer overflow that results in a heap buffer overflow when parsing a maliciously crafted LYB binary blob. An attacker who can supply LYB data to any libyang cnvd · 2026-05-14
- [NVD] CVE-2026-44513 (HIGH 8.8) — Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, a trust_remote_code bypass in DiffusionPipeline.from_pretrained allows arbitrary remote code execution despite the user passing trust_remote_code=False (or omitting it, which is the default). The vulnernvd · 2026-05-14
- Cisco Catalyst SD-WAN Manager Vulnerabilitiescisco_psirt · 2026-05-14
- Cisco Crosswork Network Controller and Cisco Network Services Orchestrator Advisorycisco_psirt · 2026-05-14
- [NVD] CVE-2026-6477 (HIGH 8.8) — Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., resunvd · 2026-05-14
- LABScon25 Replay | Breach Alpha: Trading on Cyber Falloutsentinelone · 2026-05-14
- Pwn2Own Berlin 2026 - Day One Resultszdi_blog · 2026-05-14
- TSUBAME Report Overflow (Oct-Dec 2025)jpcert_blog · 2026-05-14
- Beyond Acceleration and Automation: How AI + Intelligence Changes Cyber Defenserecordedfuture · 2026-05-14
- NIST NVD Enrichment Policy Change: Prioritizing Vulnerabilities with Attacker Behavior Signalsrecordedfuture · 2026-05-14
- [Breach] Golf Canada — 568,972 accounts exposedhibp_breaches · 2026-05-14
- [NVD] CVE-2026-42561 (HIGH 7.5) — Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.27, python-multipart has a denial of service vulnerability in multipart part header parsing. When parsing multipart/form-data, MultipartParser previously had no limit on the number of part headers or the sinvd · 2026-05-13
- [NVD] CVE-2026-8496 (MEDIUM 6.1) — A cross-site scripting (XSS) vulnerability exists in Alinto SOGo, version 5.12.7. A maliciously crafted ICS calendar invitation files allows arbitrary JavaScript execution within the authenticated SOGo webmail session. The issue occurs because SVG content embedded in the descripnvd · 2026-05-13
- [NVD] CVE-2026-44248 (MEDIUM 5.3) — Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDecoder, the decodeVariableHeader() method is nvd · 2026-05-13