Conventional Threats Watchlist

Browse by attack type

Showing 381–400 of 804 threats, newest first

ICSSCADAABBMongoDBthird-party-componentdenial-of-servicevulnerability-disclosurecritical-infrastructure

ABB Ability Zenon's IIoT services bundle an outdated MongoDB 4.2 instance affected by 13 known MongoDB vulnerabilities, including memory disclosure, authentication/authorization bypass, denial-of-service, log injection, and certificate validation flaws. Successful exploitation could allow attackers to bypass security controls, crash services, execute unauthorized actions, or expose sensitive data on affected industrial control system deployments worldwide.

Updated Aug 7, 2026 · CVSS 7.8

ICSOTvulnerabilityhardcoded-credentialsCWE-327cameraCISA-advisory

Johnson Controls TL280 camera devices running firmware versions below 5.63 contain a vulnerability involving use of a broken or risky cryptographic algorithm, tracked as CVE-2026-27871, which stems from hardcoded credentials embedded in the firmware. Successful exploitation could allow an attacker to access sensitive information on the device, though the attack requires high complexity and privileges. Johnson Controls has released firmware 5.63 to remediate the issue and recommends network segmentation and credential rotation as mitigations.

Updated Aug 7, 2026 · CVSS 4.1

ICS-medicalDICOMheap-overflowout-of-bounds-writeRCEhealthcareCISA-advisory

A heap out-of-bounds write vulnerability (CVE-2026-17264) affects Medixant RadiAnt DICOM Viewer versions 2025.2 and earlier, triggered by opening a maliciously crafted DICOM file with malformed JPEG-compressed pixel data. Successful exploitation could crash the application or potentially allow remote code execution, though built-in exploit mitigations (CFG, DEP, ASLR) reduce practical exploitability. No known public exploitation has been reported to date.

Updated Aug 7, 2026 · CVSS 4.3

unauthenticated-accessdatabase-destructiondata-integritysql-injectionsocket.ioiotsatellite-systemssupply-chain-riskagent-relevant

CVE-2026-53984 is a critical unauthenticated vulnerability in Ground Station software prior to version 0.6.0, allowing any network peer to destroy or tamper with the entire SQLite database via an exposed Socket.IO event handler. Attackers can wipe operational data or inject fabricated orbital-source URLs to redirect the ground station to attacker-controlled servers, enabling data manipulation and potential downstream compromise.

Updated Aug 7, 2026 · CVSS 9.1

browser-vulnerabilitytype-confusionrcemicrosoft-edgechromiumagent-relevant

CVE-2026-66321 is a type confusion vulnerability in Microsoft Edge (Chromium-based) that allows an unauthorized remote attacker to execute arbitrary code, typically via a malicious or compromised web page. Exploitation requires a victim to interact with attacker-controlled content, but successful attacks can lead to full code execution within the browser context.

Updated Aug 7, 2026 · CVSS 7.4

agent-relevantllm-abusecredential-theftdiscounted-api-accessgray-marketclaudeanthropicmitmprompt-interception

Poison Claude is an underground service advertising discounted, illegitimate access to Anthropic's Claude models (including Opus 4.8/4.7/4.6 and Sonnet 4.6), likely by reselling stolen or abused API credentials/accounts. The operator sits in the middle of every session, meaning all customer prompts, outputs, and potentially embedded secrets pass through an untrusted third party. This represents a significant confidentiality and data-exfiltration risk for any individual or organization using the service, including those integrating it into automated or agentic workflows.

Updated Aug 6, 2026

scamsocial-engineeringgen-ai-abusefraudromance-scaminvestment-scamgambling-scamimpersonationcambodiaopenaichatgpt

OpenAI disrupted a Cambodia-based scam network operating out of Poipet that used coordinated ChatGPT accounts to generate content for investment fraud, romance scams, illegal gambling promotion, and law enforcement impersonation schemes. The operation leveraged generative AI to scale social engineering content creation and craft convincing fraudulent communications targeting victims across multiple scam categories. OpenAI banned the associated accounts as part of its abuse enforcement efforts.

Updated Aug 6, 2026

ClickFixmacOSsocial-engineeringfingerprintingevasionmalware-lureinitial-access

A large-scale ClickFix campaign spanning over 250 front-end domains uses server-side browser fingerprinting to selectively serve fake software download lures to macOS users while hiding malicious content from crawlers and sandboxes. Microsoft Threat Intelligence has been tracking this infrastructure for weeks, noting the increased sophistication of its evasion techniques targeting Mac users specifically.

Updated Aug 6, 2026

SQL injectionpost-exploitationOracle databasenetwork intrusioninitial accessdatabase security

Threat actors exploited a SQL injection vulnerability to deploy the khunt post-exploitation toolkit directly within an Oracle database, using it as a foothold to breach the broader corporate network. This attack highlights database servers as an underexploited but high-value initial access vector, especially when they hold elevated privileges or trusted network connectivity.

Updated Aug 6, 2026

cloud-securitydata-breachextortioncredential-theftsnowflakesaas-compromise

A Canadian national pleaded guilty to participating in a large-scale data theft and extortion campaign targeting Snowflake cloud storage customers, affecting at least 165 organizations. The attackers used stolen or weak credentials—lacking multi-factor authentication—to access customer Snowflake instances, exfiltrate sensitive data, and extort victims for millions of dollars.

Updated Aug 6, 2026

ransomwarelaw-enforcementsentencingcybercrimeransom-cartel

Maksim Silnikau, creator and administrator of the Ransom Cartel ransomware operation, has been sentenced to 16 years in prison for orchestrating attacks against at least 18 companies worldwide. This is a law enforcement outcome rather than an active ongoing threat, though affiliates and derivative variants of the ransomware family may still pose risk to organizations that have not fully remediated prior infections.

Updated Aug 6, 2026

CISAKEVJetBrainsTeamCitydeserializationCI/CDagent-relevantactive-exploitationfederal-mandate

CISA has added CVE-2026-63077, a deserialization of untrusted data vulnerability in JetBrains TeamCity, to its Known Exploited Vulnerabilities catalog based on confirmed active exploitation. Under BOD 26-04, FCEB agencies must prioritize remediation of this vulnerability on publicly exposed assets, as it may grant attackers total control of affected systems post-exploitation. All organizations, including those outside federal scope, are strongly encouraged to remediate promptly given the severity of CI/CD compromise.

Updated Aug 6, 2026

boringproxysshprivilege-escalationtunnel-abusecredential-theftrceself-hosted-infrastructureagent-relevant

A critical vulnerability in boringproxy (through 0.10.0) allows low-privileged authenticated users to inject arbitrary SSH public keys into the server's authorized_keys file via a newline injection flaw in the tunnel creation endpoint's domain parameter. Successful exploitation grants attackers persistent SSH shell access to the proxy server and enables theft of cleartext credentials, tunnel private keys, and TLS certificates stored in the local database. Given the CVSS score of 9.9, this represents a full compromise path from limited tunnel-creation privileges to complete host takeover.

Updated Aug 6, 2026 · CVSS 9.9

apache-nifibroken-access-controlauthorization-bypassrest-apiagent-relevantdata-pipeline

Apache NiFi versions 2.0.0 through 2.10.0 contain a broken access control vulnerability in the Asset management REST API tied to Parameter Contexts. An attacker with write access to one Parameter Context can delete Assets belonging to a different Parameter Context they are not authorized for, by manipulating the supplied identifiers. This affects deployments that rely on differentiated authorization across Parameter Contexts as a security boundary.

Updated Aug 6, 2026 · CVSS 9.1

apache-nifibroken-access-controlprivilege-escalationcode-executiondata-pipelinerag-pipelineagent-relevant

Apache NiFi versions 1.10.0 through 2.10.0 contain a broken authorization flaw in the Parameter Context update REST API that fails to enforce component-level authorization checks. An authenticated user with only Parameter Context modification rights can alter parameter values affecting components they are not authorized to manage, potentially triggering code execution via scripting-based parameters during automatic validation. Organizations should upgrade to NiFi 2.11.0 immediately, especially those using component-level authorization policies.

Updated Aug 6, 2026 · CVSS 9.8

deserializationrceunauthenticatedci-cdteamcitykevagent-relevantbuild-pipeline

A critical unauthenticated remote code execution vulnerability has been identified in JetBrains TeamCity, exploitable via insecure deserialization in the agent polling protocol. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog with an unusually short remediation window, indicating active or imminent exploitation. Organizations running TeamCity build servers should treat this as an urgent patching priority.

Updated Aug 6, 2026

social-engineeringrmm-abusescreenconnectfake-updatesinitial-accessagent-relevant

Securonix Threat Labs identified an active, multi-wave social engineering campaign dubbed SMOKE#SCREEN that uses fake Adobe and Zoom update prompts, fraudulent document review notices, and system maintenance lures to trick victims into installing ConnectWise ScreenConnect. Once installed, the legitimate RMM tool grants attackers persistent, stealthy remote access to compromised endpoints, bypassing many traditional malware detection controls due to ScreenConnect's legitimate code signing.

Updated Aug 5, 2026

phishing-as-a-serviceMFA-bypassdevice-code-phishingOAuth-abuseAiTMtoken-theftcredential-theftagent-relevant

The Greatness PhaaS platform has added device code phishing capabilities, allowing attackers to abuse the legitimate OAuth 2.0 Device Authorization Grant flow to bypass MFA and hijack user sessions via stolen tokens. Combined with its existing adversary-in-the-middle (AiTM) credential phishing, this significantly lowers the barrier for attackers to compromise MFA-protected accounts at scale.

Updated Aug 5, 2026

phishingPhaaSMicrosoft 365adversary-in-the-middledevice-code phishingcredential theftbusiness-email-compromiseagent-relevant

The Greatness phishing-as-a-service platform has evolved from basic credential phishing to adversary-in-the-middle (AiTM) and device-code phishing techniques, now spoofing RingCentral notifications to target Microsoft 365 accounts. This expansion enables attackers to bypass MFA protections and steal session tokens, significantly increasing the risk of successful account takeovers across organizations using Microsoft 365.

Updated Aug 5, 2026

TP-LinkOmadaZTPnetwork-infrastructureRCEvulnerability-chainIoTfirmware

TP-Link has patched 15 vulnerabilities in the zero-touch provisioning mechanism of its Omada network devices. These flaws can be chained with previously disclosed vulnerabilities to achieve remote code execution, potentially allowing attackers to breach entire networks through compromised network infrastructure.

Updated Aug 5, 2026