Conventional Threats Watchlist

Browse by attack type

Showing 421–440 of 804 threats, newest first

authentication-bypassrmmpatch-bypasscisa-kevaccount-takeovern-central

CVE-2026-18577 is an authentication bypass in N-able N-central, a widely deployed remote monitoring and management (RMM) platform, resulting from an incomplete fix for the prior vulnerability CVE-2026-18556. CISA has added this flaw to its Known Exploited Vulnerabilities catalog with an unusually short remediation window, indicating active or imminent exploitation. Successful exploitation allows attackers to bypass authentication entirely and take over accounts within N-central.

Updated Aug 4, 2026

chromebrowser-securitypatch-managementvulnerability-disclosuregoogle

Google released three Chrome updates (versions 149, 150, and 151) fixing a cumulative total of 1,442 security bugs, far exceeding the combined total of the previous 23 releases. This represents a significant spike in disclosed vulnerabilities, largely attributed to internal discovery efforts rather than active exploitation reports.

Updated Aug 3, 2026

captive-portal-hijackfake-updateRATsurveillance-malwareMidnight-BlizzardStorm-2945hospitalitynation-statecredential-theftagent-relevant

Microsoft has identified a campaign, tracked as CaptiveCrunch, in which threat actors hijack hotel Wi-Fi captive portals to serve fake browser update prompts. Victims who install the fake update are infected with CornFlake, a remote access trojan capable of capturing webcam images, microphone audio, and keystrokes. The activity is attributed to Storm-2945, assessed as an operational sub-cluster of the Russian state-sponsored group Midnight Blizzard (APT29).

Updated Aug 3, 2026

adobecampaign-classicrceauthorization-bypassunauthenticatedcritical-vulnerability

Adobe has issued an emergency patch for a maximum-severity flaw (CVSS 10.0) in Campaign Classic, its enterprise marketing automation platform, caused by incorrect authorization checks. The vulnerability allows arbitrary code execution without any user interaction, making it a high-priority target for exploitation once details or a proof-of-concept become public.

Updated Aug 3, 2026 · CVSS 10

browser-securitychromeextensionsdefensive-featurenew-tab-hijacking

Google is developing a Chrome security feature to block policy-installed extensions from hijacking the New Tab page or overriding the default search engine. This is a defensive enhancement rather than an active exploit, aimed at curbing a common malicious/adware extension technique often used to redirect traffic and harvest ad revenue or credentials.

Updated Aug 3, 2026

cryptocurrencyhardware-walletrng-flawkey-managementbitcoin-theftsupply-chain

A flawed random number generator in COLDCARD hardware wallet firmware produced predictable or low-entropy seed phrases, enabling attackers to reconstruct private keys and drain wallets. The flaw is believed responsible for the theft of approximately $88.6 million in Bitcoin from thousands of affected wallets.

Updated Aug 3, 2026

not-a-threatai-industry-newsproduct-announcement

This article is a product news item about OpenAI's unreleased 'Astra' model, reported to have solved several long-standing math and theoretical computer science problems internally. It contains no information about a vulnerability, exploit, malware, or attack campaign and does not constitute a cybersecurity threat.

Updated Aug 3, 2026

arcadedbauthorization-bypassdatabaserce-adjacenttime-seriesagent-relevant

ArcadeDB versions prior to 26.7.2 contain a critical authorization bypass vulnerability affecting HTTP handlers for time series, batch, Prometheus, and Grafana endpoints. Unauthenticated or under-privileged attackers can access and manipulate arbitrary databases by directly invoking these endpoints with crafted database parameters, bypassing intended access controls. Given the CVSS score of 9.8, this vulnerability poses a severe risk of data theft, tampering, and destruction on any exposed ArcadeDB instance.

Updated Aug 3, 2026 · CVSS 9.8

arcadedbrceprivilege-escalationdatabasejavascript-injectionagent-relevant

ArcadeDB versions prior to 26.7.2 contain a critical authorization flaw allowing any database user to execute arbitrary JavaScript via the SQL DEFINE FUNCTION statement with LANGUAGE js, bypassing intended admin-only scripting restrictions. This effectively grants remote code execution to any actor with database access, regardless of assigned privilege level.

Updated Aug 3, 2026 · CVSS 9.8

arcadedbrcesandbox-escapejavascript-injectionprivilege-abusedatabaseagent-relevant

ArcadeDB before version 26.7.2 contains a critical flaw in its ScriptTriggerExecutor that improperly whitelists java.lang.* packages, allowing an authenticated user with UPDATE_SCHEMA permission to craft a malicious JavaScript trigger. This trigger can invoke Java.type to access Runtime.getRuntime().exec() or ProcessBuilder, resulting in arbitrary OS command execution when the trigger fires.

Updated Aug 3, 2026 · CVSS 9.8

authentication-bypassaccount-takeoverscimidentity-managementbetter-authssosupply-chainagent-relevant

A critical authorization bypass in the @better-auth/scim plugin allows an authenticated user to mint a SCIM token that collides with an existing SSO/SAML/OIDC/OAuth provider namespace, granting full read/write/delete access over unrelated user accounts and sessions. This enables account takeover, unauthorized profile/email rewriting, and mass deprovisioning across the identity system. Given the 9.9 CVSS score and low attack complexity, this is highly exploitable in any deployment using SCIM provisioning alongside social/SSO logins.

Updated Aug 3, 2026 · CVSS 9.9

gitpythonpythonrcecommand-injectionsupply-chaindependency-vulnerabilityagent-relevant

GitPython 3.1.50's protection against dangerous clone options (--upload-pack/-u) can be bypassed by passing the joined short-option form -u<value>, which the default unsafe-option gate fails to detect. Applications that pass attacker-influenced values into Repo.clone_from() with allow_unsafe_options=False are still vulnerable to arbitrary command execution during the clone operation. The issue is fixed in GitPython 3.1.51.

Updated Aug 3, 2026 · CVSS 9.8

supply-chainadtechcryptocurrencyclipboard-hijackingjavascriptmalvertisingweb-skimming

Attackers compromised a JavaScript file served by advertising technology provider Adform, injecting code that rewrites cryptocurrency wallet addresses copied by site visitors, redirecting funds to attacker-controlled wallets. The malicious script was distributed across multiple customer sites that embedded Adform's ad-serving code, exposing visitors who copied Bitcoin or other crypto addresses on July 27, 2026. Adform detected and remediated the incident, notified affected clients, and reported it to authorities.

Updated Aug 2, 2026

cryptocurrencyhardware-walletweak-rngfirmware-vulnerabilitybitcoin-theftsupply-chain

A March 2021 firmware integration error in Coinkite's Coldcard hardware wallet caused seed generation to rely on a deterministic software pseudorandom number generator (PRNG) instead of proper entropy sources, producing predictable private keys. Attackers exploited this weakness to systematically drain 1,196 Bitcoin addresses, stealing 1,082.65 BTC (~$70.2 million) in just 41 minutes on July 30. Galaxy Research identified the pattern and linked the mass sweep directly to the firmware defect, exposing years of latent risk for affected wallet holders.

Updated Aug 2, 2026

agent-relevantai-agent-abuseautonomous-attackdeepseekllm-misuseserver-exploitationchina-nexus

A Chinese-speaking threat actor is leveraging the DeepSeek AI model combined with the open-source Hermes Agent framework to autonomously scan, target, and exploit internet-exposed vulnerable servers with minimal human oversight. This represents a notable escalation in offensive AI usage, where an agentic LLM pipeline performs reconnaissance, exploitation, and possibly post-exploitation actions with limited operator intervention. The campaign highlights growing risk from adversaries weaponizing legitimate agent frameworks originally built for benign automation.

Updated Aug 2, 2026

non-securityvendor-announcementinformationalopenaipricing

This item is a routine business/product announcement from OpenAI regarding API pricing changes for its GPT-5.6 model variants ('Luna' and 'Terra'), not a security incident. No vulnerability, exploit, malware, or attack technique is described.

Updated Aug 2, 2026

railsrubyactive-storagercefile-readweb-frameworkagent-relevant

A critical vulnerability in Ruby on Rails' Active Storage framework allows unauthenticated attackers to read arbitrary files from an affected application, with a potential escalation path to remote code execution. Rails maintainers have released patches, and organizations running unpatched Active Storage implementations should prioritize updates given the severity and ease of exploitation typically associated with such flaws.

Updated Aug 2, 2026

ICSOTdenial-of-serviceIEC61850GOOSEMMSout-of-bounds-readenergy-sectorCISA-advisory

MZ Automation GmbH's libiec61850 library, widely used in industrial control systems for substation automation, contains eight out-of-bounds read vulnerabilities (CVE-2026-66720, 66369, 63550, 65421, 66364, 66349, 56758, 66360) in its GOOSE, MMS, ACSE, and ISO Presentation layer parsers. Successful exploitation via crafted network messages can crash affected processes, causing denial-of-service conditions on devices in energy sector control systems. No public exploitation has been reported; a patched version (1.6.2) is available.

Updated Aug 2, 2026 · CVSS 7.5

ICSCISA-advisoryfile-uploadXSSHTML-injectionbuilding-management-systemJohnson-Controls

CISA disclosed three low-to-medium severity vulnerabilities in Johnson Controls OpenBlue Employee (FMS Employee) versions <=V2025.3.1, including unrestricted file upload, stored XSS, and HTML injection flaws. Exploitation requires authenticated access and user interaction, limiting practical risk, though successful attacks could allow malicious file uploads, persistent script execution, or content manipulation within the application. No public exploitation has been reported.

Updated Aug 2, 2026 · CVSS 2.4

icsothard-coded-credentialscryptographybillboard-controllercisa-advisory

Watchfire Controller Software used in digital billboard/LED sign controllers (BC550, BC750, BC760, BC760DC) contains hard-coded, self-signed RSA private keys and X.509 certificates embedded in plaintext firmware patch binaries. Successful exploitation could allow an attacker to intercept or spoof HTTPS/TLS connections to the web management interface and deliver malicious firmware to gain full control of the controller. Watchfire has released patched firmware versions to remediate the issue.

Updated Aug 2, 2026 · CVSS 5.7