Conventional Threats Watchlist

Browse by attack type

Showing 301–320 of 804 threats, newest first

wordpressplugin-backdoorsupply-chainrcepersistenceweb-shell

A tampered build of Ninja Tables Pro 5.2.11 was distributed through a decommissioned update server, embedding a malicious PHP updater component that grants attackers persistent backdoor access. The compromised plugin creates a passwordless admin account, drops web shells in mu-plugins and uploads directories, and registers scheduled tasks that survive plugin removal, making remediation difficult. Organizations running affected WordPress instances face full site takeover risk, including any hosted applications, APIs, or backend services running on the same host.

Updated Aug 14, 2026 · CVSS 9.8

wordpresssupply-chainbackdoorplugin-compromiseagent-relevantpersistencerce

A tampered build of Fluent Forms Pro 6.2.7 distributed via a decommissioned update server injects a malicious PHP file that installs a backdoor REST API endpoint, a passwordless administrator account, and persistent scheduled tasks. This constitutes a supply-chain compromise capable of full site takeover, with persistence mechanisms designed to survive plugin removal.

Updated Aug 14, 2026 · CVSS 9.8

rsyncaccess-control-bypassip-spoofingunauthenticatednetwork-protocolagent-relevant

A critical vulnerability in rsync daemon versions prior to 3.5.0 allows unauthenticated remote attackers to spoof source IP addresses via a crafted PROXY protocol header, bypassing IP-based hosts allow/deny access controls. This enables attackers who can reach the rsync daemon port to gain unauthorized access to file shares that would otherwise be restricted by network-level trust policies.

Updated Aug 14, 2026 · CVSS 9.1

IBM-iprivilege-escalationauthorization-flawenterprise-serverinsider-threat

A critical vulnerability in IBM i affects versions 7.3 through 7.6, allowing a remote authenticated attacker to escalate privileges through improper authorization checks on high-authority threads. With a CVSS score of 9.6, this flaw could enable an attacker with low-level access to gain full administrative control over the system.

Updated Aug 14, 2026 · CVSS 9.6

IBM-iprivilege-escalationuncontrolled-search-patharbitrary-code-executionauthenticated-attackenterprise-server

A critical vulnerability in IBM i versions 7.3 through 7.6 allows a remote authenticated attacker to execute arbitrary code by exploiting an uncontrolled search path element. With a CVSS score of 9.9, this flaw could enable low-privileged users to escalate to full system compromise on affected IBM Power Systems servers.

Updated Aug 14, 2026 · CVSS 9.9

AI-securityLLMreasoning-APIsession-replaycredential-exposureAPI-key-leakageagent-relevantOpenAIAnthropicGoogle

Researchers disclosed a flaw in how OpenAI, Anthropic, and Google encode and carry hidden chain-of-thought reasoning between API calls, allowing encrypted reasoning objects from one session to be replayed into another session. This cross-session replay allowed weaker models to decode or expose internal reasoning content from stronger models, including sensitive data such as API keys and passwords captured in session logs.

Updated Aug 13, 2026

browser-extensionchrome-web-storevpn-proxy-abusetraffic-interceptionrussian-speaking-userssupply-chaincredential-exposure

A coordinated campaign involving 737 free VPN and proxy Chrome extensions, published across at least 40 developer accounts, has been found intercepting browser traffic and routing it through attacker-controlled proxy infrastructure. The campaign primarily targets Russian-speaking users attempting to bypass service blocks, with 274 extensions identified as impersonating 66 legitimate brands, and has amassed over 75,000 installs.

Updated Aug 13, 2026

lazarusnorth-koreaaptzero-daywindowsoperation-dream-jobdefense-sectoraerospaceprivilege-escalationbackdoor

The North Korea-linked Lazarus Group exploited a zero-day vulnerability in Microsoft Windows to gain SYSTEM-level privileges and deploy a previously unseen backdoor. The campaign, part of the long-running Operation Dream Job cyber espionage effort, targeted defense and aerospace organizations in France, Germany, Brazil, and India. The vulnerability has since been patched by Microsoft.

Updated Aug 13, 2026

adobe-commercemagentoecommerceaccount-takeoveractive-exploitationcve-2026-71362

Attackers are actively exploiting a critical vulnerability in Adobe Commerce and Magento platforms that allows hijacking of customer accounts. The flaw is being targeted in the wild shortly after disclosure, putting online retailers and their customer data at risk of unauthorized access and fraud.

Updated Aug 13, 2026

androidmobile-malwarenfc-relayratbanking-trojancredit-card-fraudfraud

A newly identified Android malware campaign pairs a novel NFC relay tool called WindRelay with the established SpyNote RAT to capture and relay victims' live credit card data to attackers in real time. The combo also facilitates taking out fraudulent loans using stolen victim information, indicating a financially motivated criminal operation targeting mobile banking users.

Updated Aug 13, 2026

data-theftsalesforceservicenowmisconfigurationcustomer-portalexposed-dataanonymous-accesssaas-security

A campaign dubbed 'City-Forum' is using custom tooling to systematically harvest data exposed to anonymous/unauthenticated users through misconfigured Salesforce Experience Cloud sites and ServiceNow customer portals. The attackers exploit overly permissive guest-user access controls rather than a software vulnerability, allowing bulk extraction of sensitive records without authentication.

Updated Aug 13, 2026

kubernetesprivilege-escalationrceopenshiftmulticluster-enginecluster-curatoragent-relevantcloud-infrastructure

A critical flaw (CVE-2026-73268, CVSS 9.9) in the cluster-curator-controller component of multicluster engine (MCE) allows tenants with limited ClusterCurator permissions to inject arbitrary Job specifications that execute with the controller's elevated privileges. Successful exploitation enables arbitrary code execution, privilege escalation, and access to cluster-wide secrets, posing severe risk to multi-tenant Kubernetes/OpenShift environments.

Updated Aug 13, 2026 · CVSS 9.9

kubernetesrhacmprivilege-escalationconfused-deputycluster-securitymulti-tenancyagent-relevant

A critical flaw in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM) allows a low-privileged namespace-admin tenant to abuse a highly privileged ServiceAccount via Subscription Custom Resources. This confused-deputy attack enables deployment of arbitrary cluster-scoped resources, leading to full privilege escalation and potential arbitrary code execution across the entire managed cluster.

Updated Aug 13, 2026 · CVSS 9.9

icsotprofinetbuffer-overflowunauthenticated-rceindustrial-control-systemscritical-infrastructure

A critical buffer overflow vulnerability exists in the PROFINET service of an industrial device in its default configuration, allowing unauthenticated remote attackers to crash the device or execute arbitrary code. With a CVSS score of 9.8, this flaw poses severe risk to industrial control system (ICS) and operational technology (OT) environments where the affected device is deployed.

Updated Aug 13, 2026 · CVSS 9.8

adobeauthorization-bypassrcecvss10marketing-platformno-user-interaction

A critical Incorrect Authorization vulnerability in Adobe Campaign Classic (ACC) allows an unauthenticated attacker to execute arbitrary code in the context of the current user without any user interaction required. The maximum CVSS score of 10.0 and changed scope indicate the flaw can escalate impact beyond the vulnerable component itself, making this a top-priority patching target for any organization running ACC.

Updated Aug 13, 2026 · CVSS 10

patch-tuesdaymicrosoftwindowszero-dayvulnerability-managementagent-relevant

Microsoft's August 2026 Patch Tuesday addresses nearly 398 vulnerabilities across Windows and supported software, including one flaw already under active exploitation and two others that were publicly disclosed prior to patching. Organizations should prioritize patching the actively exploited vulnerability to reduce risk of compromise.

Updated Aug 12, 2026

zoomzero-clickannotation-toolvideo-conferencingclient-hijackrcescreen-sharing

A flaw in Zoom's screen annotation feature could have allowed any meeting participant to hijack the client of another attendee, including the presenter, without any user interaction. The vulnerability required no click, download, or visible prompt, making it a fully zero-click, in-meeting attack vector. This poses significant risk to organizations relying on Zoom for internal and external communications, including those coordinating distributed teams or automated workflows via meeting integrations.

Updated Aug 12, 2026

botnetddosandroidiothttp2mirai-variant

Kimwolf v7, an evolution of the AISURU Android/IoT botnet, was discovered by Palo Alto Networks Unit 42 in February 2026 with enhanced HTTP/2-based DDoS capabilities designed to blend malicious traffic with legitimate browsing patterns. The improvements increase operational resilience and evasion, making detection and mitigation more difficult for defenders relying on traditional traffic-signature analysis.

Updated Aug 12, 2026

SandwormAPTRussiatrojanized-softwareVPNsocial-engineeringjob-lurecredential-theftIT-professionalsagent-relevant

The Russian state-linked threat group Sandworm is targeting system administrators and IT professionals with fake job offers designed to lure victims into installing a trojanized WireGuard VPN client. The campaign, active since at least May 2026, aims to compromise privileged accounts and gain persistent access to enterprise networks through social engineering and malicious software.

Updated Aug 12, 2026

ransomwareblockchaindata-leakresilient-infrastructuredecentralized-C2extortion

DeadLock is a ransomware operation that leverages blockchain-backed decentralized infrastructure to host its victim communication portals and data-leak sites, making takedown efforts by law enforcement and security researchers significantly more difficult. This resilience model represents an evolving trend among ransomware groups seeking to evade traditional infrastructure disruption tactics.

Updated Aug 12, 2026