Conventional Threats Watchlist

Browse by attack type

Showing 441–460 of 804 threats, newest first

shell-injectiongithub-actionsci-cdsupply-chainsecrets-exfiltrationself-hosted-runnerswazuhagent-relevant

A critical shell injection vulnerability in Wazuh's GitHub Actions workflows allows attackers to execute arbitrary commands by submitting malicious pull requests containing crafted VERSION.json files. Because affected variables are directly interpolated into shell run steps, attackers can achieve command execution and exfiltrate sensitive secrets such as GITHUB_TOKEN and AWS credentials, particularly dangerous on self-hosted runners with broader network and credential access.

Updated Aug 2, 2026 · CVSS 10

freerdprdphttp-smugglingcrlf-injectionproxy-abuseremote-desktopagent-relevant

FreeRDP versions up to 3.28.0 fail to sanitize CRLF and control characters in the server-controlled TargetNetAddress field of RDP redirection PDUs. A malicious or compromised RDP server can exploit this to inject arbitrary headers or requests into the client's HTTP proxy CONNECT request, potentially enabling request smuggling, proxy authentication bypass, or lateral request injection against internal infrastructure.

Updated Aug 2, 2026 · CVSS 9.8

FreeRDPTLScertificate-validationman-in-the-middleRDPagent-relevant

FreeRDP versions up to 3.28.0 contain multiple flaws in their custom TLS certificate identity verification logic, allowing an attacker with a trusted or misissued certificate to impersonate legitimate RDP servers. This weakens TLS server authentication and enables man-in-the-middle attacks against RDP sessions, with a critical CVSS score of 9.8.

Updated Aug 2, 2026 · CVSS 9.8

wordpressauthentication-bypassplugin-vulnerabilityaccount-takeovercms-securitybroken-access-control

The Single Sign On For TNG WordPress plugin (versions up to 2.0.0) contains a critical authentication bypass vulnerability allowing unauthenticated attackers to reset any account's password, including administrators. Exploitation leads to complete site takeover with no user interaction or prior authentication required.

Updated Aug 2, 2026 · CVSS 9.8

wordpressplugin-vulnerabilityunauthenticated-rcefile-deletionpath-traversalsite-takeovercms

The FormGent WordPress plugin (versions up to 1.9.2) contains a critical unauthenticated arbitrary file deletion vulnerability caused by a missing capability check on its REST API endpoint. On Linux servers, attackers can bypass path traversal protections to delete wp-config.php, forcing the site into a fresh-install state that enables full site takeover.

Updated Aug 2, 2026 · CVSS 9.1

ad-fraudbotnetresidential-proxyiot-securityandroidclick-fraudsupply-chain

Researchers at Bitsight identified an operation dubbed Fuyao in which cheap Android TV boxes ship with pre-installed apps that spoof device identifiers to impersonate Samsung, Huawei, Xiaomi, or Vivo smartphones, enabling large-scale ad fraud. The same devices are also weaponized to covertly route third-party traffic through owners' home broadband connections, effectively turning them into residential proxy nodes. The operation has been attributed to Zhejiang Fengwo IoT Technology Co., Ltd., a China-based manufacturer.

Updated Aug 1, 2026

spear-phishingloaderbackdoorgo-malwarerust-malwarelaw-firm-targetingLNK-abuse

A newly documented Go-based loader called HollowFrame is being used to deploy a Rust-based backdoor tracked as Matryoshka in targeted spear-phishing attacks, with at least one confirmed intrusion against a law firm. The infection begins with a phishing email linking to an encrypted archive containing a malicious Windows LNK file that triggers a multi-stage execution chain leading to backdoor deployment.

Updated Aug 1, 2026

APTChina-nexusCentral-Asiagovernmentespionagemalwarebackdoor

A suspected Chinese-speaking threat actor has been conducting an espionage campaign since January 2025, primarily targeting government organizations in Central Asia and Afghanistan, as well as Syria. The campaign employs two custom malware families, OctLurk and SilkLurk, to establish persistent access for likely intelligence collection purposes.

Updated Aug 1, 2026

supply-chainclipboard-hijackingcryptocurrency-theftmalvertisingjavascriptweb-skimmer

Attackers compromised Adform's ad-serving script, injecting malicious JavaScript into websites using the platform. The script performs clipboard hijacking, replacing copied cryptocurrency wallet addresses with attacker-controlled addresses to redirect funds. This is a classic supply-chain attack leveraging a trusted third-party ad network to achieve broad, indirect distribution across many unrelated sites.

Updated Aug 1, 2026

arch-linuxaurpackage-takeoverlinuxopen-sourcesupply-chain-attackagent-relevant

A wave of malicious actors have been adopting abandoned or orphaned Arch User Repository (AUR) packages and inserting malware into them, prompting Arch Linux to temporarily disable the package adoption feature. This supply-chain attack vector allows attackers to compromise trusted package names that users and automated systems may install without deep scrutiny.

Updated Aug 1, 2026

data-breachcloud-securitythird-party-riskhealthcarepii-exposurepharma

Amgen disclosed a data breach in which threat actors stole corporate and patient health data stored across multiple cloud systems operated by third-party service providers. The incident highlights ongoing risks tied to outsourced cloud infrastructure and vendor security posture in the pharmaceutical sector.

Updated Aug 1, 2026

ICSOTcritical-infrastructureenergy-sectormissing-authenticationCWE-306fuel-managementembedded-linux

Toptech Systems RCU II+ and Multiload II+ devices, used in fuel management systems within the energy sector, expose an unauthenticated Target Communications Framework (TCF) debug service that grants full root-level access to the underlying embedded Linux system. An attacker with adjacent network access could exploit this to view/modify the filesystem, manipulate processes, and control network interfaces, effectively achieving full device compromise. CISA rates this CVSS v3.1 8.8 (High), though exploitation requires network adjacency rather than remote internet access.

Updated Aug 1, 2026 · CVSS 8.8

mikrotikrouterossession-managementapi-vulnerabilitynetwork-infrastructurevpn-exposureCWE-613

A session-management flaw in MikroTik RouterOS's API allows authenticated users whose permissions have been downgraded to retain their prior access levels, since sessions are not properly invalidated after permission changes or inactivity timeouts. The advisory description also notes a more severe potential consequence: low-privilege API access could be leveraged to extract a router's WireGuard private key in plaintext, enabling full VPN impersonation and decryption of associated traffic. No public exploitation has been reported at this time.

Updated Aug 1, 2026 · CVSS 4.9

guidanceopen-sourcesoftware-supply-chainrisk-managementSBOMvulnerability-managementCISAagent-relevant

CISA has released guidance titled 'Open Source Software: Security Principles and Practices' to help agencies and organizations securely use, evaluate, and publish open source software. This is not a threat disclosure but a best-practices document covering OSS lifecycle risk management, a new C4 Framework for trust assessment, SBOM usage, secure development, and handling open source AI systems.

Updated Aug 1, 2026

rcedeserializationpicklepytorchcomfyuiunauthenticatedagent-relevantai-infrastructuresupply-chain-risk

CVE-2026-68771 is a critical unauthenticated remote code execution vulnerability in ComfyUI v0.23.0, a widely used node-based interface for AI/ML pipelines including Stable Diffusion and generative workflows. Attackers can upload a malicious pickle file and trigger deserialization via the LoadTrainingDataset node, achieving arbitrary code execution as the ComfyUI process user with no authentication required.

Updated Aug 1, 2026 · CVSS 9.8

agent-relevantrcepythonmachine-learningmodel-loadingsupply-chainhuggingfaceragllm-tooling

A critical logic flaw in the popular sentence-transformers Python library allows attackers to bypass the trust_remote_code=False safety control and achieve arbitrary code execution when a model is loaded from a local path. Because a flawed guard condition treats any existing filesystem path as implicitly trusted, malicious Python files placed inside a model directory (referenced via modules.json) will execute automatically at import time, even when developers believe they have disabled remote code execution.

Updated Aug 1, 2026 · CVSS 9.8

apachetraffic-serveruse-after-freememory-corruptionreverse-proxycdnagent-relevant

A use-after-free vulnerability has been identified in Apache Traffic Server's intercept plugin functionality, affecting multiple major version branches from 8.0.0 through 10.1.3. The flaw could lead to denial of service or potentially further memory corruption impacts on affected proxy deployments. Patches are available in versions 9.2.15 and 10.1.4.

Updated Aug 1, 2026 · CVSS 5.9

apachetraffic-serveroverflowrce-potentialreverse-proxycdnagent-relevant

A vulnerability in the regex_remap plugin of Apache Traffic Server allows stack and integer overflows through crafted substitution input, potentially leading to crashes or remote code execution. The flaw affects a broad range of ATS versions (8.0.0–8.1.9, 9.0.0–9.2.14, 10.0.0–10.1.3) and is rated high severity with a CVSS score of 8.1.

Updated Aug 1, 2026 · CVSS 8.1

apachetraffic-servermemory-corruptionuse-after-freepath-traversalout-of-bounds-writereverse-proxycdn

A vulnerability in the Cripts framework of Apache Traffic Server allows out-of-bounds writes, path traversal, and use-after-free conditions in versions 10.0.0 through 10.1.3. Successful exploitation could lead to memory corruption, potential remote code execution, or unauthorized file access on affected proxy/caching servers. Users should upgrade to version 10.1.4 to remediate the issue.

Updated Aug 1, 2026 · CVSS 8.1

ad-fraudiot-botnetresidential-proxyclick-fraudgeneric-android-tv-boxesconsumer-iotfraud-as-a-service

A widespread analysis of low-cost generic Android TV streaming boxes reveals they covertly enroll users' home internet connections into residential proxy networks and simulate mobile device behavior to commit large-scale ad fraud on AI-generated websites. This scheme defrauds advertisers and online merchants while exposing consumers' networks to third-party abuse without their knowledge or consent.

Updated Jul 31, 2026