Conventional Threats Watchlist

Browse by attack type

Showing 501–520 of 804 threats, newest first

websphereaccess-controlprivilege-escalationadmin-consoleibmenterprise-middlewareagent-relevant

IBM WebSphere Application Server versions 9.0 and 8.5 contain a critical broken access control vulnerability in the administrative console that allows privilege escalation. Exploitation could grant an attacker administrative control over the application server, enabling full compromise of hosted applications and backend services. Given the CVSS score of 9.8, this vulnerability is likely remotely exploitable with low complexity and no required privileges.

Updated Jul 29, 2026 · CVSS 9.8

iotbotnetddosblockchain-c2resilient-infrastructuredecentralized-dnscncertxlab

Dysphoria, an IoT botnet lineage tracked by CNCERT and XLab, has upgraded its command-and-control architecture to use blockchain-based naming services and peer-to-peer relays across infected devices, making it significantly more resilient to takedown efforts. This evolution follows a March 2026 law enforcement disruption of related JackSkid infrastructure, indicating the operators are actively hardening their C2 model against future enforcement action.

Updated Jul 28, 2026

industry-initiativeai-securityagent-relevantopen-sourcegovernance

NVIDIA and 36 other organizations, including Microsoft, Cisco, Cloudflare, CrowdStrike, Hugging Face, IBM, Palo Alto Networks, Red Hat, and the Linux Foundation, have formed the Open Secure AI Alliance to develop shared open standards and tools for securing software and AI agents. As part of this effort, the group open-sourced the NOOA framework, aimed at improving security tooling and best practices across the AI ecosystem. This is not a threat or vulnerability disclosure but an industry defensive initiative relevant to organizations deploying AI agents.

Updated Jul 28, 2026

aristavelocloudsd-wancommand-injectionrceactive-exploitationnetwork-infrastructure

A maximum-severity OS command injection vulnerability (CVE-2026-16812, CVSS 10.0) in on-premises Arista VeloCloud Orchestrator (VCO) is being actively exploited in the wild. Successful exploitation allows unauthenticated or low-privilege attackers to achieve arbitrary code execution on the orchestrator, which centrally manages SD-WAN infrastructure across enterprise networks.

Updated Jul 28, 2026 · CVSS 10

botnetddosiot-malwaretraffic-relaylarge-scale-compromise

Dysphoria is a newly identified DDoS botnet that has compromised approximately 200,000 devices globally. The malware is being used both for distributed denial of service attacks and as a traffic relay/proxy network, indicating a dual-purpose criminal infrastructure. Its rapid scale suggests exploitation of weak credentials or unpatched vulnerabilities in widely deployed internet-facing devices.

Updated Jul 28, 2026

zero-daycommand-injectionnetwork-infrastructureSD-WANactive-exploitationedge-deviceRCE

Arista disclosed and patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator (VCO) deployments that has been actively exploited in the wild. Attackers can leverage the flaw to execute arbitrary commands on the orchestrator, potentially gaining control over SD-WAN management infrastructure. Organizations running on-premises VCO instances should patch immediately given confirmed exploitation.

Updated Jul 28, 2026 · CVSS 9.8

fastjsonjavarcezero-dayopen-sourcesupply-chaindeserializationagent-relevant

Threat actors are actively exploiting an unpatched remote code execution vulnerability in the widely-used FastJson Java library, targeting US-based organizations. The flaw requires no authentication or user interaction, making it highly attractive for mass exploitation and initial access into enterprise networks.

Updated Jul 28, 2026 · CVSS 9.8

CISAKEVknown-exploited-vulnerabilityFortinetFortiOSAristaVeloCloudcommand-injectioninformation-disclosurenetwork-infrastructurefederal-agenciespatch-management

CISA has added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: a sensitive information exposure flaw in Fortinet FortiOS (CVE-2025-68686) and an OS command injection vulnerability in Arista VeloCloud Orchestrator On-Prem (CVE-2026-16812). Both are confirmed to be exploited in the wild and require urgent remediation under BOD 26-04 for federal agencies, with CISA recommending all organizations prioritize patching.

Updated Jul 28, 2026

apache-thriftrpcout-of-bounds-readinput-validationcppagent-relevantrag-pipelinemicroservices

CVE-2026-58662 is a critical out-of-bounds read vulnerability in Apache Thrift's C++ bindings caused by improper validation of specified quantity in input, affecting all versions before 0.24.0. Attackers can exploit this by sending crafted Thrift messages to trigger memory over-reads, potentially leading to information disclosure, service crashes, or further exploitation depending on the deployment context.

Updated Jul 28, 2026 · CVSS 9.1

apache-thriftout-of-bounds-readrpcmemory-corruptionopen-sourceagent-relevant

Apache Thrift's c_glib bindings prior to version 0.24.0 contain an out-of-bounds read vulnerability with a CVSS score of 9.1, indicating potential for information disclosure or denial of service. Apache Thrift is a widely used cross-language RPC framework, and this flaw could be exploited by processing malicious serialized data through affected bindings.

Updated Jul 28, 2026 · CVSS 9.1

apache-thriftrpcbuffer-overflowmemory-corruptionagent-relevantsupply-chain-componentcpp

A critical heap-based buffer overflow has been identified in the C++ bindings of Apache Thrift, a widely used cross-language RPC framework, affecting all versions prior to 0.24.0. The vulnerability carries a CVSS score of 9.8, indicating remote exploitability with low attack complexity and potential for full system compromise. Organizations using Thrift-based services must upgrade immediately to mitigate risk of remote code execution or denial of service.

Updated Jul 28, 2026 · CVSS 9.8

apache-thrifttlscertificate-validationmitmagent-relevantrpcsupply-chain-dependency

Apache Thrift's c_glib bindings before version 0.24.0 fail to properly validate that a TLS certificate's hostname matches the connected host, allowing an attacker positioned on the network path to present a mismatched but otherwise valid certificate and impersonate a trusted server. This affects any application using the c_glib Thrift client library to establish TLS-secured RPC connections, enabling man-in-the-middle attacks against Thrift-based service communication.

Updated Jul 28, 2026 · CVSS 9.1

CISA-KEVSD-WANcommand-injectionnetwork-infrastructureedge-devicepre-auth-suspected

A critical OS command injection vulnerability (CVE-2026-16812) affects Arista VeloCloud Orchestrator On-Prem, a core SD-WAN management platform. CISA has added this to its Known Exploited Vulnerabilities catalog with an unusually short 3-day remediation window, indicating active exploitation in the wild. Successful exploitation grants attackers privileged access to the orchestrator host, threatening confidentiality, integrity, and availability of the entire managed SD-WAN fabric.

Updated Jul 28, 2026

fortinetfortiosnetwork-securitypost-exploitationpersistence-bypasscisa-kevedge-device

CVE-2025-68686 is a vulnerability in Fortinet FortiOS that allows a remote unauthenticated attacker to bypass a previously deployed patch addressing a symbolic link persistency mechanism used in post-exploitation scenarios. Exploitation requires prior compromise of the device at the filesystem level via another vulnerability, making this a persistence and detection-evasion enabler rather than an initial access vector. It has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild.

Updated Jul 28, 2026

ransomware-as-a-serviceRaaSaffiliate-modelDevManFunky MantisPRODAFTextortion

DevMan is a ransomware-as-a-service operation running a centralized web portal that lets affiliates build custom payloads, track victim status, and manage payouts. PRODAFT is tracking the broader operator infrastructure under the name Funky Mantis, indicating a structured, business-like criminal enterprise lowering the barrier to entry for ransomware deployment. The centralized tooling suggests active recruitment and scaling of affiliates, increasing the likely volume and diversity of attacks.

Updated Jul 27, 2026

Cl0pFIN11ransomwaredata-extortionPLMRCEpre-authPTC-WindchillFlexPLM

Cl0p-affiliated threat actors (FIN11, Graceful Spider, Lace Tempest) are exploiting internet-exposed PTC Windchill and FlexPLM PLM software through a chained vulnerability enabling unauthenticated remote code execution. The campaign appears focused on data theft and extortion rather than traditional file encryption, consistent with Cl0p's established MO of mass exploitation of enterprise file transfer and PLM platforms.

Updated Jul 27, 2026

phishingcredential-theftreal-time-hijackingsession-hijackinginsurance-sectorfinancial-fraudsocial-engineeringadversary-in-the-middle

CTM360 researchers identified a shift in insurance-sector phishing campaigns from traditional credential harvesting to real-time account hijacking, where stolen credentials and session tokens are used immediately to take over accounts before victims can react. This evolution suggests attackers are increasingly leveraging automated relay infrastructure or adversary-in-the-middle (AiTM) techniques to bypass MFA and act on stolen sessions within seconds of capture.

Updated Jul 27, 2026

outagecloud-reliabilitymicrosoft365azureavailabilityno-malicious-activity

Microsoft confirmed that a bug in its automated network maintenance request system caused a widespread outage affecting Microsoft 365 and Azure services. The bug erroneously removed IP routes from more network devices than intended, disrupting connectivity and service availability. This was a self-inflicted operational failure, not the result of a cyberattack or malicious activity.

Updated Jul 27, 2026

outageavailabilityopenaichatgptagent-relevant

OpenAI confirmed a worldwide outage affecting ChatGPT connectivity, disrupting user access to the chatbot service. No evidence suggests this was caused by a malicious attack; it appears to be an availability incident rather than a security breach.

Updated Jul 27, 2026

supply-chainpackage-securitygithubpypidependabotdefensive-measureagent-relevantopen-source-security

GitHub and PyPI have rolled out a time-based defense mechanism within Dependabot to reduce the risk and blast radius of supply-chain attacks against open-source packages. This is a defensive/protective development rather than an active threat, aimed at limiting exposure windows for malicious or compromised dependency updates.

Updated Jul 27, 2026