Conventional Threats Watchlist

Browse by attack type

Showing 281–300 of 804 threats, newest first

macOSauthentication-bypasscryptominingmoneroexploit-code-publicagent-relevant

Hackers are actively exploiting a macOS Screen Sharing authentication bypass vulnerability following the release of public exploit code, according to the Netherlands' NCSC. Attackers use the flaw to gain unauthorized remote access to macOS systems and deploy Monero (XMR) cryptocurrency miners. Organizations running exposed macOS Screen Sharing services are at immediate risk of unauthorized access and resource hijacking.

Updated Aug 15, 2026 · CVSS 8.1

banking-fraudthird-party-riskservice-provider-compromiselaw-enforcementfinancial-crime

Law enforcement in Brazil and Europe arrested seven individuals connected to a fraud scheme that exploited a vulnerability at a third-party service provider to withdraw approximately €30 million from Commerzbank customer accounts. The case highlights the ongoing risk that vulnerabilities in banking service providers and payment intermediaries pose to end customers.

Updated Aug 15, 2026

AI-safetywatermarkingcontent-provenancenot-a-threatinformational

This is a news report on Anthropic's plans to implement watermarking for AI-generated text produced by Claude, aimed at improving content provenance and detection of AI-generated material. This is a defensive/product feature announcement rather than a security threat, vulnerability, or attack campaign.

Updated Aug 15, 2026

ICSOTvulnerabilityOS-command-injectionSiemensvideo-management-systemphysical-securityCVE-2026-3014privileged-user-exploit

Siemens Siveillance Video Management Servers (based on Milestone XProtect) contain a critical OS command injection vulnerability in the Management Server API that allows users with edit permissions to execute arbitrary code in the context of the Management Server service. Siemens has released patched versions for the affected V2023 R3, V2024 R1, and V2025 product lines and urges immediate updates.

Updated Aug 15, 2026 · CVSS 9.1

icsotbuilding-automationxsscwe-79johnson-controlsmetasyscisa-advisory

A high-severity persistent cross-site scripting vulnerability affects Johnson Controls Metasys building automation systems (versions 12–15), allowing a low-privilege user to inject a malicious payload via a crafted URL that executes in other users' sessions, including administrators. This could lead to session hijacking and unauthorized access within critical infrastructure environments such as commercial facilities, manufacturing, energy, and government sites. No public exploitation has been reported to CISA at this time, but patches or vendor guidance are available for supported versions.

Updated Aug 15, 2026 · CVSS 8

ICSOTCVE-2026-64887CVE-2026-34492hard-coded-keypath-traversalarbitrary-file-readcritical-infrastructurejohnson-controlsCISA

Johnson Controls Airwall versions 4.0.4 and earlier contain two vulnerabilities: a hard-coded cryptographic key used identically across all deployments, and an arbitrary file read flaw via path traversal. Combined, these could allow an attacker with local access or code/binary access to decrypt sensitive configuration data or read arbitrary files including credential stores and private keys. No public exploitation has been reported, and both flaws require local access or high attack complexity, limiting immediate risk.

Updated Aug 15, 2026 · CVSS 7

IBMDb2Db2 MirrorIBM iauthentication-bypassimproper-input-validationCVE-2026-17182critical-infrastructuredatabase-security

CVE-2026-17182 is a critical authentication bypass vulnerability in IBM Db2 Mirror for i affecting versions 7.4, 7.5, and 7.6, allowing remote attackers to bypass authentication controls due to improper validation of request URI path segments. Exploitation could result in unauthorized access, disclosure, or alteration of sensitive database information without requiring credentials. With a CVSS score of 9.8, this vulnerability poses a severe risk to organizations running affected Db2 Mirror deployments.

Updated Aug 15, 2026 · CVSS 9.8

path-traversalibm-db2remote-code-executionibm-iunauthenticateddatabase

A critical path traversal vulnerability in IBM Db2 Mirror for i allows remote attackers to write arbitrary files to unintended filesystem locations. With a CVSS score of 9.3, successful exploitation could lead to arbitrary code execution, data corruption, or full system compromise on affected IBM i platforms.

Updated Aug 15, 2026 · CVSS 9.3

grav-cmsprivilege-escalationapi-key-abusebroken-access-controlcms-vulnerabilityrce-chainagent-relevant

A critical vulnerability in the getgrav/grav-plugin-api plugin (before 1.0.13) allows an attacker holding a minimal-scope API key to mint a new, unscoped super-access API key by submitting an empty scopes array. This bypasses intended scope restrictions and can be chained with configuration write access to achieve full remote code execution on the underlying Grav CMS instance.

Updated Aug 15, 2026 · CVSS 9.8

path-traversalopenwrtrouter-securityrceprivilege-escalationssh-backdooredge-devicenetwork-infrastructure

A critical path traversal vulnerability in luci-app-openvpn allows authenticated attackers to write arbitrary files outside the intended upload directory, enabling persistent root-level code execution on OpenWrt-based devices. Exploitation involves planting SSH keys in system directories to maintain access across reboots, making this a severe threat to routers and embedded network infrastructure.

Updated Aug 15, 2026 · CVSS 9.9

path-traversalrceibmunauthenticatedagent-relevant

A critical vulnerability (CVE-2026-17482) in IBM Documentation Offline versions 1.0.0 through 1.4.1 allows remote attackers to execute arbitrary code due to improper control of file paths. With a CVSS score of 9.8, this flaw is likely exploitable without authentication and poses severe risk to any host running the affected software. Organizations should treat this as an urgent patching priority given the potential for full system compromise.

Updated Aug 15, 2026 · CVSS 9.8

adobecoldfusionrcecommand-injectionprivilege-escalationpatch-tuesdayagent-relevant

Adobe has released patches for multiple critical vulnerabilities affecting ColdFusion, Commerce, and Campaign Classic, including at least one flaw rated a maximum CVSS score of 10.0. Successful exploitation could allow unauthenticated attackers to achieve arbitrary OS command execution and privilege escalation on affected servers.

Updated Aug 14, 2026 · CVSS 10

security-reportbenchmarkdetection-gaplateral-movementbreach-and-attack-simulationdefense-analytics

Picus Labs' Blue Report 2026 analyzed over 338 million attack simulations across production environments in H1 2026, finding that while perimeter/edge defenses have improved significantly, internal detection and containment capabilities have deteriorated. Attackers are increasingly succeeding not through loud, high-signature attacks but through low-noise techniques that evade internal detection once initial defenses are bypassed.

Updated Aug 14, 2026

sharepointauthentication-bypasspoc-exploitmicrosofton-premisesrce-riskagent-relevant

Threat actors are actively exploiting CVE-2026-55040, a critical SharePoint authentication bypass vulnerability, following the public release of proof-of-concept code. The flaw, patched in Microsoft's July 2026 Patch Tuesday, stems from weak authentication controls and carries a CVSS score of 9.1, allowing attackers to bypass security controls on unpatched SharePoint servers.

Updated Aug 14, 2026 · CVSS 9.1

ransomwareEDR-evasionsafe-modedata-exfiltrationakiradouble-extortion

An Akira ransomware affiliate compromised a target network and rebooted a system into Safe Mode with Networking to disable endpoint detection and response (EDR) protections. The attacker successfully exfiltrated data but failed to deploy the encryption payload, resulting in a partial (extortion-only) compromise rather than full ransomware impact.

Updated Aug 14, 2026

law-enforcementfraudcall-center-scaminvestment-scamsocial-engineeringtakedown

Ukrainian authorities dismantled 94 fraudulent call centers that were running investment scams and attempting to gain unauthorized access to victims' bank accounts. Millions in cash were seized during the coordinated operation, representing a significant disruption to organized fraud networks operating in the region.

Updated Aug 14, 2026

spywaremercenary-spywaremobile-securityiosnation-statesurveillancetargeted-attack

Apple has issued new 'Threat Notification' alerts warning select iPhone users that they have been targeted by mercenary spyware attacks. These notifications, part of Apple's ongoing threat intelligence program, indicate highly targeted, sophisticated attacks typically associated with commercial spyware vendors like NSO Group or Intellexa rather than broad-based malware campaigns.

Updated Aug 14, 2026

ICSOTBACnetdenial-of-serviceSiemensbuilding-automationCVE-2026-59693

A denial-of-service vulnerability (CVE-2026-59693) affects Siemens Desigo DXR and PXC building automation controllers. An attacker with adjacent network access can send a malformed BACnet packet to cause the device to stop responding, requiring a manual reset or reboot to restore functionality. Siemens has released firmware updates to remediate the issue.

Updated Aug 14, 2026 · CVSS 4.3

ICSSiemensprivilege-escalationpath-traversalvulnerabilityCVECISA-advisorylicensing-server

Siemens License Server (SLS) versions prior to 5.1 and 5.3 are affected by two vulnerabilities: an insecure sudoers policy enabling local privilege escalation to root, and a path traversal flaw allowing remote unauthenticated attackers to read arbitrary files. Siemens has released patched versions and CISA has published an advisory recommending immediate updates.

Updated Aug 14, 2026 · CVSS 7.5

ICSCISA-advisorySiemensout-of-bounds-readfile-parsingCVE-2026-64629critical-manufacturing

Siemens Parasolid, a 3D geometric modeling kernel used in CAD/CAM/CAE software across critical manufacturing, contains an out-of-bounds read vulnerability (CVE-2026-64629) triggered when parsing malformed X_T files. Successful exploitation could crash the application or allow arbitrary code execution in the context of the current process. Siemens has released patched versions (V38.0.235 and V38.1.230) and users are advised to update.

Updated Aug 14, 2026 · CVSS 7.8