Conventional Threats Watchlist

Agent threats are ThreatPulse's primary feed, but the systems agents run on still get owned the old-fashioned way. This watchlist tracks conventional vulnerabilities and campaigns — CISA Known Exploited Vulnerabilities, NVD entries with high CVSS scores, ransomware and infostealer operations, and supply-chain compromises — so a team securing agent deployments can see both halves of the picture in one place.

Every entry is deduplicated by CVE ID and source URL before synthesis, then written up with a summary, technical analysis, affected systems, indicators of compromise, and prioritized remediation steps.

Browse by attack type

Showing 1–20 of 789 threats, newest first

infostealerinitial-access-brokerwindowspython-malwareunderground-marketplaceagent-relevant

BraZetsu is a Python-based Windows malware framework used by Initial Access Brokers (IABs) to commoditize compromised hosts on underground marketplaces. Rather than acting as a standard infostealer, it functions as a comprehensive toolkit that profiles, categorizes, and packages victim systems for resale to other threat actors, including ransomware operators.

Updated Sep 4, 2026

cisconexus-9000ios-xrrceunauthenticatednetwork-infrastructureroot-accessagent-relevant

Cisco disclosed a critical unauthenticated remote code execution vulnerability (CVE-2026-20212, CVSS 9.8) affecting 10 Silicon One-based Nexus 9000 switch models, allowing attackers to execute code as root without credentials. Alongside this, Cisco released an IOS XR hardening bundle addressing 7 CVEs, two rated 9.8, with no available workarounds for any affected IOS XR version, making immediate patching the only mitigation.

Updated Sep 4, 2026 · CVSS 9.8

phishingoauth-abusecredential-theftsocial-engineeringaccount-takeoversupply-chainagent-relevant

This roundup aggregates multiple ongoing threat campaigns including CEO/executive impersonation phishing kits, a mass compromise affecting roughly 5,000 Dropbox accounts, and OAuth consent-phishing traps that trick users into granting malicious apps access via legitimate-looking 'Allow' prompts. The common thread is abuse of trust in normal workflows—IT calls, shared files, and trusted apps—rather than technical exploitation, making these attacks highly effective and hard to detect through traditional security controls.

Updated Sep 4, 2026

network-infrastructurearubaos-cxrcehpepatch-availableagent-relevant

HPE has released patches for a critical remote code execution vulnerability in ArubaOS-CX, the network operating system powering Aruba switches. Exploitation could allow attackers to gain control over network infrastructure, potentially enabling lateral movement and traffic interception across enterprise environments.

Updated Sep 4, 2026

supply-chainterraformcloudflarecredential-theftregistry-compromiseiacagent-relevant

Attackers gained unauthorized access to Coder's Cloudflare-hosted registry infrastructure and inserted rogue registry servers distributing trojanized Terraform modules. These malicious modules contained credential-stealing code, potentially exposing secrets and cloud credentials for any environment that pulled infrastructure definitions from the compromised registry.

Updated Sep 4, 2026

data-breachhealthcareregulatory-fineGDPRprivacy

France's data protection authority (CNIL) fined Hôpital privé de la Loire €500,000 for failing to adequately protect the personal data of 727,000 patients and their relatives. The breach exposed sensitive health-related information, highlighting inadequate security controls and non-compliance with GDPR data protection obligations.

Updated Sep 4, 2026

ICSOTprivilege-escalationlocal-attackinstaller-vulnerabilityCWE-250OPC-UA

A local privilege escalation vulnerability exists in the OPC UA LocalDiscoveryServer (LDS) installer prior to version 1.04.420, allowing an attacker with local keyboard/display access during installation to hijack a high-privilege console window and execute arbitrary commands. Exploitation requires local access and user interaction, limiting remote attack potential, but could lead to full system compromise on affected industrial control hosts.

Updated Sep 4, 2026 · CVSS 4.6

ICSSCADAcritical-infrastructureprivilege-escalationdefault-configurationIgnitionCWE-276

Inductive Automation Ignition versions 8.1.53 and earlier ship with a blank 'Create Project Role(s)' setting, allowing any authenticated user capable of executing gateway scripts to create projects without proper authorization. This default misconfiguration affects widely deployed industrial control system software across Critical Manufacturing, Energy, and IT sectors worldwide, with no known public exploitation reported at this time.

Updated Sep 4, 2026 · CVSS 8.8

ICSOTdenial-of-serviceCIP-protocolRockwell-AutomationEtherNet-IPindustrial-control-systemsCISA-advisory

A high-severity denial-of-service vulnerability (CVE-2025-10478) affects all versions of the Rockwell Automation 1756-ENBT ControlLogix EtherNet/IP bridge module. An attacker can send a crafted CIP packet to crash the module, requiring a manual restart to restore functionality, potentially disrupting industrial communications in critical infrastructure environments.

Updated Sep 4, 2026 · CVSS 7.5

mozillathunderbirdfirefoxmemory-corruptionbrowser-securityemail-client

A set of internally discovered memory corruption bugs affecting Thunderbird and its ESR branches could potentially be exploited to achieve code execution. Mozilla has patched the issue across Firefox and Thunderbird release and ESR channels, and no public exploitation has been confirmed at this time.

Updated Sep 4, 2026 · CVSS 9.8

thunderbirdfirefoxmemory-corruptionmozillabrowser-securityemail-client

Internal security research identified multiple memory corruption bugs in Thunderbird 154 that could potentially be exploited by attackers. Mozilla has patched these issues in Thunderbird 155 and Firefox 155, though no public exploitation has been confirmed. The high CVSS score reflects the potential severity if these flaws were weaponized.

Updated Sep 4, 2026 · CVSS 9.8

browser-vulnerabilityinteger-overflowfirefoxthunderbirdmemory-corruptionrceagent-relevant

A critical integer overflow vulnerability has been identified in the Graphics: ImageLib component of Mozilla Firefox and Thunderbird, carrying a CVSS score of 9.8. The flaw could allow attackers to achieve memory corruption and potentially remote code execution through crafted image content. Mozilla has released patches in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

Updated Sep 4, 2026 · CVSS 9.8

browser-vulnerabilitysite-isolationfirefoxthunderbirdmozillarce-potentialagent-relevant

A critical site isolation flaw in the DOM Navigation component affects Firefox, Firefox ESR, and Thunderbird, potentially allowing cross-origin data leakage or sandbox bypass. With a CVSS score of 9.8, successful exploitation could let attackers bypass browser security boundaries to access sensitive cross-site data. Mozilla has released patches in Firefox 155, Firefox ESR 153.2, and Thunderbird 155/153.2.

Updated Sep 4, 2026 · CVSS 9.8

browsermobileandroidfirefoxpatch-available

A vulnerability described only as 'Other issue' has been identified in Firefox Focus for Android, carrying a CVSS score of 9.8, indicating potential for severe impact if exploited. The issue has been resolved in Firefox 155, and the vagueness of the public description suggests Mozilla has withheld technical details pending broader patch adoption.

Updated Sep 4, 2026 · CVSS 9.8

malvertisingfake-installerdefender-evasionwindows-update-abuseinitial-accesschina-targetedagent-relevant

A malware campaign is using bogus software-download websites that impersonate legitimate vendors to trick users into downloading trojanized installers. Once executed, the malware disables Windows Update and weakens Microsoft Defender to maintain persistence and evade detection, with impact concentrated among China-based operations of multinational organizations and Chinese-speaking users.

Updated Sep 3, 2026

ai-securitydefensive-toolingindustry-newscyber-ai-modelsfairwind-programagent-relevant

Google, Anthropic, and OpenAI announced new cybersecurity-focused AI models and structured access programs, including Google's Gemini 3.8 Flash Cyber and the Fairwind Program, which grants early access to advanced defensive AI capabilities for high-priority defenders such as governments, healthcare, and telecom providers. This is an industry development announcement rather than an active threat, but it signals shifts in the AI-driven security tooling landscape that organizations running AI agents should track.

Updated Sep 3, 2026

authentication-bypassartifactorytoken-forgerysupply-chainagent-relevantci-cdprivilege-escalation

A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being actively exploited to forge tokens granting administrative access. Attackers exploiting this flaw can gain full control over artifact repositories used in software build and deployment pipelines, enabling malicious package injection and data exfiltration.

Updated Sep 3, 2026

wordpresssql-injectionplugin-vulnerabilityrcewebsite-takeoverunauthenticated-attack

A critical SQL injection vulnerability in the widely-used All-in-One WP Migration and Backup WordPress plugin allows unauthenticated attackers to execute remote code and fully compromise affected sites. With millions of active installations, this flaw poses a significant risk of mass exploitation, website defacement, and data theft.

Updated Sep 3, 2026 · CVSS 9.8

VoIPSQL-injectionRCEreverse-shellSangomaSwitchvoxunauthenticatedexploitation-in-the-wild

Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection flaw in the Sangoma Switchvox VoIP platform, to achieve remote code execution and deploy reverse shells. The vulnerability allows attackers to gain full control of vulnerable systems without credentials, posing a serious risk to organizations running exposed Switchvox deployments.

Updated Sep 3, 2026

ICSOTdenial-of-serviceRockwell-AutomationLogixCIP-protocolcritical-manufacturingmemory-corruption

A high-severity denial-of-service vulnerability affects multiple Rockwell Automation Logix Platform controllers due to improper input length validation during CIP message processing. Successful exploitation causes a major nonrecoverable fault (MNRF), requiring a physical power cycle to restore operations. No public exploitation has been observed at this time.

Updated Sep 3, 2026 · CVSS 7.5