Conventional Threats Watchlist

Browse by attack type

Showing 201–220 of 804 threats, newest first

supply-chainrustcrates.iobuild-time-malwaredependency-confusiontyposquattingagent-relevant

A compromised maintainer account was used to publish malicious versions of three popular Rust crates (arrayref, internment, append-only-vec), collectively downloaded over 245 million times. The malicious releases introduced a typosquatted dependency whose build script downloaded and executed a remote payload at compile time, enabling arbitrary code execution on any system that built the affected packages.

Updated Aug 21, 2026

phishingai-generated-contentmspemail-securityidentity-securitysocial-engineering

This is a vendor advisory (Kaseya via BleepingComputer) describing how AI is making phishing emails more personalized and convincing, allowing them to bypass traditional email filters. It recommends MSPs adopt layered monitoring across identity, email, and endpoint activity to catch attacks that reach user inboxes.

Updated Aug 21, 2026

wordpresselementorrcefile-uploadweb-plugincms-securityagent-relevant

A critical vulnerability in the Elementor Pro WordPress plugin allows unauthenticated or low-privileged attackers to upload executable files, leading to full remote code execution on the underlying server. Given Elementor Pro's massive install base, this flaw poses a significant risk of mass exploitation against WordPress-hosted sites and infrastructure.

Updated Aug 21, 2026 · CVSS 9.8

supply-chainrustcrates.ioinfostealermalicious-packagebuild-time-executionagent-relevant

Attackers compromised the maintainer account of the widely-used Rust crate 'arrayref' and published a malicious version that executes infostealer malware at compile time on developer systems. Any developer or CI/CD pipeline pulling the poisoned version would trigger malware execution during the build process, risking credential and secret theft.

Updated Aug 21, 2026

ICSOTbuilding-automationcredential-exposureCWE-316local-privilegeJohnson-Controls

Johnson Controls Simplex Incident Manager versions up to V2.01 store user credentials, including passwords and authentication tokens, in cleartext within system memory. A local low-privileged attacker could extract these credentials using memory-dumping techniques, potentially gaining unauthorized access to the application and connected building automation systems. Johnson Controls has released patched version v2.01.01 to remediate the issue.

Updated Aug 21, 2026 · CVSS 5.8

CISAKEVTrueConfauthentication-bypasscode-injectionactive-exploitationfederal-mandatevideo-conferencing

CISA has added two actively exploited vulnerabilities affecting TrueConf Server to its Known Exploited Vulnerabilities catalog: a missing authentication for critical function flaw (CVE-2026-72529) and a code injection vulnerability (CVE-2026-72530). These vulnerabilities pose significant risk as they can be chained to bypass authentication and execute arbitrary code, with BOD 26-04 requiring FCEB agencies to remediate rapidly.

Updated Aug 21, 2026

oracleweblogicrmiunauthenticated-rcefusion-middlewareagent-relevant

CVE-2026-60977 is a critical, easily exploitable vulnerability in Oracle WebLogic Server that allows an unauthenticated attacker with network access via RMI to fully compromise the server. With a CVSS score of 9.8, successful exploitation can lead to complete takeover of confidentiality, integrity, and availability. Organizations running affected WebLogic versions should prioritize immediate patching due to the low attack complexity and lack of authentication requirements.

Updated Aug 21, 2026 · CVSS 9.8

browser-securityuse-after-freemozillafirefoxthunderbirdrcememory-corruptionagent-relevant

A critical use-after-free vulnerability in the DOM Core & HTML component of Firefox and Thunderbird could allow attackers to execute arbitrary code via crafted web content. The flaw has been patched in Firefox 154, Firefox ESR 140.14/153.1, and Thunderbird 154, 140.14, and 153.1. With a CVSS score of 9.8, unpatched systems are at severe risk of remote exploitation.

Updated Aug 21, 2026 · CVSS 9.8

browser-vulnerabilityuse-after-freefirefoxthunderbirdmozillarceagent-relevant

A critical use-after-free vulnerability exists in the Graphics: ImageLib component of Firefox and Thunderbird, carrying a CVSS score of 9.8. Successful exploitation could allow remote code execution via crafted image content rendered by the affected browser or mail client, posing significant risk to any endpoint running unpatched versions.

Updated Aug 21, 2026 · CVSS 9.8

browser-vulnerabilityuse-after-freefirefoxthunderbirdmemory-corruptionrce-potentialagent-relevant

A critical use-after-free vulnerability (CVE-2026-74940) exists in the Graphics: Text rendering component of Firefox and Thunderbird, carrying a CVSS score of 9.8. Successful exploitation could allow remote code execution, potentially enabling attackers to compromise systems that browse untrusted content or process malicious documents/emails.

Updated Aug 21, 2026 · CVSS 9.8

browser-vulnerabilityuse-after-freewebassemblyfirefoxthunderbirdrceagent-relevant

A critical use-after-free vulnerability (CVE-2026-74936) exists in the WebAssembly component of Firefox's JavaScript engine, carrying a CVSS score of 9.8. The flaw affects multiple Firefox and Thunderbird release channels and has been patched in the latest versions, indicating high urgency for organizations to update immediately.

Updated Aug 21, 2026 · CVSS 9.8

TrueConfCISA-KEVunauthenticated-RCEmissing-authenticationvideo-conferencingremote-code-execution

TrueConf Server contains a missing authentication vulnerability that allows a remote, unauthenticated attacker with network access to port 4307/TCP to execute arbitrary scripts on the server. This flaw has been added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild, and requires urgent remediation ahead of the CISA-mandated due date of 2026-08-23.

Updated Aug 21, 2026

CISA-KEVcode-injectionRCEsandbox-escapevideo-conferencingnetwork-exposed-service

TrueConf Server is vulnerable to a code injection flaw that allows an unauthenticated remote attacker to escape an isolated execution environment and run arbitrary code on the host via port 4307/TCP. The vulnerability has been added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild, with remediation required by September 3, 2026.

Updated Aug 21, 2026

espionageAPTRATCentral Asiagovernmentnation-state

SilkParasite is a newly identified cyber espionage operation targeting government bodies in Central Asia, first observed in late 2025. The campaign leverages seven distinct RAT families, five of which are previously undocumented, indicating a well-resourced threat actor with custom malware development capabilities.

Updated Aug 20, 2026

ai-safetyopenaireinforcement-learningmodel-traininginternal-controlsagent-relevantgovernance

OpenAI temporarily paused reinforcement learning (RL) training of its newest frontier models for two weeks to strengthen internal defenses and expand monitoring, citing growing risks as model capability increases. The move appears preventive, referencing a prior 'Hugging Face-like incident' as a cautionary precedent rather than disclosing an active breach or exploit.

Updated Aug 20, 2026

spectreside-channelcloudflare-workersserverlessjwt-theftspeculative-executionagent-relevant

Researchers demonstrated a remote Spectre-class microarchitectural side-channel attack against Cloudflare Workers that allows a malicious Worker to leak secret data, including JSON Web Tokens, from a co-located victim Worker in production at up to 12 bits per second. This represents a 360x throughput improvement over a 2021 proof-of-concept and confirms that multi-tenant serverless/edge compute platforms remain vulnerable to cross-tenant speculative execution leakage despite existing mitigations.

Updated Aug 20, 2026

data-breachcloud-providerjapancustomer-data-exposurethird-party-riskagent-relevant

Sakura Internet, a major Japanese cloud and data center provider, disclosed unauthorized access to its sales management system, exposing contract and membership data for up to 1.36 million accounts. The breach affects a company that provides hosting and cloud infrastructure to numerous business customers, raising downstream exposure concerns.

Updated Aug 20, 2026

ransomwareextortionsocial-engineeringfrauddouble-extortionfake-recovery-service

A suspected ransomware affiliate is impersonating a legitimate data recovery firm called 'Ransom Busters,' contacting victims prior to public disclosure of breaches and offering fraudulent decryption keys and data deletion services for payment. This represents a secondary extortion layer that exploits victim desperation and confusion during active incident response, potentially resulting in double payment with no guarantee of data recovery or deletion.

Updated Aug 20, 2026

outageavailabilityopenaichatgptagent-relevant

OpenAI confirmed a major outage affecting ChatGPT, with users unable to log in, sign up, or access previous conversations. The incident appears to be a service availability failure rather than a security breach or exploitation of a vulnerability.

Updated Aug 20, 2026

ICSOTSCADAPLCSiemensS7commcritical-infrastructureAI-generated-exploitsreconnaissanceCISA-advisory

NSA, CISA, FBI, DOE, and EPA have issued a joint advisory warning of active threat actor targeting of Internet-exposed Siemens S7 Series PLCs (S7-200 through S7-1500) across U.S. critical infrastructure sectors. Threat actors are using AI-assisted development to rapidly generate exploitation scripts—built on the open-source snap7/python-snap7 library—that masquerade as legitimate OT monitoring tools to gain read/write access via the S7comm protocol, likely as reconnaissance and pre-positioning for future disruptive operations.

Updated Aug 20, 2026