Conventional Threats Watchlist

Browse by attack type

Showing 361–380 of 804 threats, newest first

wordpressplugin-vulnerabilityprivilege-escalationauthentication-bypassai-pluginagent-relevantunauthenticated-rce-equivalent

The AI Copilot – Content Generator WordPress plugin (versions up to 1.5.6) contains an authorization bypass vulnerability allowing unauthenticated attackers to create administrator accounts and fully take over affected sites. The flaw stems from a nonce value being exposed in publicly accessible JavaScript, rendering the plugin's authorization check ineffective on any page rendering the [aiwu-form] shortcode or public chatbot.

Updated Aug 9, 2026 · CVSS 9.8

vishingsocial-engineeringsaasdata-extortioncredential-thefthelp-desk-impersonationagent-relevant

UNC6671 is a data extortion group conducting voice phishing attacks against financial services, private equity, and professional services firms. The group impersonates IT help desk staff and contacts employees via personal phones to coerce urgent 'security migration' actions that grant attackers access to SaaS environments and enterprise data.

Updated Aug 8, 2026

clickfixmacosinfostealercrypto-theftsocial-engineeringcredential-theftagent-relevant

A ClickFix-style social engineering campaign is delivering a Go-based macOS infostealer capable of draining cryptocurrency wallets, harvesting browser-stored passwords, Apple iCloud Keychain data, and cached credentials. The infection chain uses a shell script that profiles the victim's CPU architecture before fetching an architecture-specific malware payload, indicating deliberate targeting and evasion.

Updated Aug 8, 2026

npmtyposquattingsupply-chainRATinfostealermalwarecross-platformagent-relevant

Nearly 800 malicious npm packages were identified delivering a cross-platform Remote Access Trojan and infostealer payload to Windows, macOS, and Linux systems. The packages use AI-generated or randomly typo-squatted names to trick developers into installing them via automated or manual dependency resolution.

Updated Aug 8, 2026

social-engineeringdata-breachcorporate-espionageemployee-targetingcredential-theft

Levi Strauss & Co. disclosed that attackers used social engineering tactics against three employees to gain unauthorized access to corporate data stored on their machines. The incident resulted in the theft of corporate information, though full scope of the compromised data has not been publicly detailed. This represents a targeted human-layer attack rather than a technical exploit of infrastructure.

Updated Aug 8, 2026

data-breachhealthcarepii-exposurethird-party-risk

Unlimited Technology Systems, a healthcare software company, disclosed a data breach affecting more than 3.8 million individuals stemming from an incident that occurred in October 2025. Details on the specific attack vector, threat actor, and exact data types exposed remain limited in public reporting.

Updated Aug 8, 2026

sql-injectionzero-daydata-breachmetabasebusiness-intelligenceagent-relevant

A critical, previously unknown SQL injection vulnerability in Metabase, a widely used open-source business intelligence and analytics platform, was exploited in zero-day attacks to breach customer instances and exfiltrate data. Confirmed victims include Framework and Tally, both of which have publicly disclosed the incidents. The flaw allows attackers to bypass authentication and query controls to access sensitive underlying database contents.

Updated Aug 8, 2026

aviationicsotprotocol-vulnerabilitydosmessage-injectionradio-frequencycritical-infrastructure

Five vulnerabilities in the Controller-Pilot Data Link Communications (CPDLC) protocol over ATN-B1, used for aircraft-air traffic control text communications, allow unauthenticated message injection, denial-of-service, and forced session resets via unauthenticated clear-text radio frequency links. While not creating an unsafe aircraft condition directly, exploitation can degrade operational safety margins by increasing controller/pilot workload, delaying safety-critical instructions, and reducing situational awareness. No public exploitation has been observed, and attack complexity is high, requiring lab-like conditions.

Updated Aug 8, 2026 · CVSS 7.1

CISAKEVcommand-injectionProgress-LoadMasterload-balancernetwork-appliancefederal-agenciesactive-exploitation

CISA has added CVE-2026-8037, a command injection vulnerability in Progress LoadMaster, to its Known Exploited Vulnerabilities catalog based on confirmed active exploitation in the wild. Federal civilian agencies are required under BOD 26-04 to remediate this vulnerability on a prioritized timeline due to its potential to grant attackers total control of affected assets.

Updated Aug 8, 2026

dellopenmanageauthentication-bypassserver-managementunauthenticated-accessremote-exploit

CVE-2026-56793 is an improper authentication vulnerability in Dell OpenManage Server Administrator (OMSA) affecting versions prior to 11.1.0.2. An unauthenticated remote attacker could exploit this flaw to gain unauthorized access to server management interfaces, potentially leading to further compromise of underlying infrastructure.

Updated Aug 8, 2026 · CVSS 7.7

azurecloudprivilege-escalationnetwork-securitysqlagent-relevant

CVE-2026-62836 is a high-severity vulnerability in Azure SQL Managed Instance caused by improper restriction of communication channels to intended endpoints. An unauthorized attacker could exploit this over the network to elevate privileges without prior authentication, potentially gaining unauthorized access to sensitive data and control over database resources.

Updated Aug 8, 2026 · CVSS 8.7

vmwarevspheresession-hijackinginformation-disclosuredellvsiunauthenticated-rcevirtualization-security

Dell Virtual Storage Integrator (VSI) for VMware vSphere Client versions prior to 10.11.1.0 contain a critical sensitive information disclosure vulnerability that allows unauthenticated remote attackers to steal active session credentials. Exploitation enables full impersonation of authenticated users, including administrators, within vSphere environments.

Updated Aug 8, 2026 · CVSS 9.1

command-injectionunauthenticated-rcenetwork-applianceload-balancerCISA-KEVedge-deviceagent-relevant

CVE-2026-8037 is an unauthenticated command injection vulnerability in Progress LoadMaster that allows attackers to execute arbitrary commands on the appliance via unsanitized input on multiple management endpoints. CISA has added this to its Known Exploited Vulnerabilities catalog with a short remediation window, indicating active exploitation in the wild. Organizations using LoadMaster for load balancing and application delivery, including in front of internal services, should treat this as an urgent patching priority.

Updated Aug 8, 2026

credential-theftdata-extortioncloud-securitysnowflakelegal-actionagent-relevant

Connor Riley Moucka, a Canadian national linked to the 2024 Snowflake extortion campaign, pleaded guilty to computer fraud and conspiracy charges tied to breaches of over 165 organizations, including the theft of call and text metadata for more than 100 million AT&T customers. The campaign exploited stolen credentials and lack of MFA on customer Snowflake accounts rather than a vulnerability in Snowflake itself, enabling mass data theft and subsequent extortion.

Updated Aug 7, 2026

spectreside-channelcpu-vulnerabilityintelamdlinux-kernelspeculative-executionagent-relevant

MIT CSAIL researchers demonstrated a new microarchitectural attack called Interrupt Injection that bypasses existing Spectre v2 mitigations on Intel and AMD CPUs by timing a hardware interrupt to re-poison the branch predictor immediately after the kernel sanitizes it. The attack was proven on an AMD Zen 2 system running Linux 6.14 with all default Spectre v2 defenses enabled, allowing an unprivileged local process to leak protected kernel or cross-process data via speculative execution.

Updated Aug 7, 2026

ciscosd-wanios-xenetwork-infrastructurevulnerabilitypatch-tuesdayrceagent-relevant

Cisco disclosed 12 vulnerabilities affecting Catalyst SD-WAN Software and IOS XE Software, including three critical flaws with CVSS scores of 9.8, discovered during an internal security review. These issues affect SD-WAN devices regardless of configuration and IOS XE devices running in autonomous or controller mode, posing significant risk to enterprise network infrastructure.

Updated Aug 7, 2026 · CVSS 9.8

kvmvirtualizationprivilege-escalationlinux-kernelvm-escapenested-virtualizationcloud-infrastructureagent-relevant

A newly disclosed Linux kernel vulnerability dubbed Zapscape (CVE-2026-64561) affects KVM/x86's shadow MMU and can allow an attacker with kernel-level privileges inside a nested L1 guest VM to escape isolation and execute code on the host. This poses significant risk to cloud and virtualization providers that expose nested virtualization to untrusted or semi-trusted tenants.

Updated Aug 7, 2026

extortionransomwarefinancial-sectordata-theftUNC6671BlackFile

A wave of cyberattacks against hedge funds, private-equity firms, and other financial organizations has been attributed to UNC6671, an extortion group linked to the BlackFile threat actors. The campaign appears focused on data theft and extortion rather than pure ransomware encryption, targeting high-value financial sector victims. Details on initial access vectors and specific TTPs remain limited in current reporting.

Updated Aug 7, 2026

macOSinfostealerClickFixcrypto-theftsocial-engineeringcredential-theftagent-relevant

A ClickFix-style social engineering campaign is distributing a Go-based infostealer targeting macOS users, designed to exfiltrate cryptocurrency wallets, browser-saved passwords, Apple Keychain contents, and cached credentials. The attack relies on tricking victims into manually executing malicious commands via fake verification or error prompts, bypassing typical download-based security controls.

Updated Aug 7, 2026

not-a-threatproduct-updateopenaichatgptinformational

This article reports a routine product update from OpenAI, announcing new ChatGPT model versions (GPT-5.6 Sol and GPT-5.6 Luna) being rolled out to Plus, Pro, and Free tier users. There is no vulnerability, exploit, malware, or attack activity described in this content.

Updated Aug 7, 2026