Conventional Threats Watchlist

Browse by attack type

Showing 521–540 of 804 threats, newest first

ICSOTindustrial-control-systemsCISAplaintext-passwordconfused-deputypass-the-hashweak-encryptioncritical-infrastructure

Panduit IntraVUE versions 3.2.1a14 and earlier contain five vulnerabilities, including a critical confused-deputy proxy flaw (CVSS 10) that allows attackers with IT network access to bypass OT segmentation and manipulate industrial control devices without authentication. Additional flaws expose plaintext credentials via the API, leak host/share filesystem and asset information to unauthenticated users, and use weak encryption enabling pass-the-hash admin credential theft. CISA advises upgrading to version 3.2.1a16 or later; no known public exploitation has been reported to date.

Updated Jul 27, 2026 · CVSS 10

gitlabrceproof-of-conceptauthenticated-exploitjupyter-notebookheap-leakgitsource-code-managementagent-relevant

A public proof-of-concept exploit now lets any authenticated user with push access to a GitLab project execute arbitrary commands as the 'git' user on unpatched self-managed GitLab 18.11.3 instances. GitLab shipped a fix six weeks before the PoC was released, meaning organizations that have not applied the patch are immediately exposed to remote code execution. Because GitLab often hosts CI/CD pipelines, secrets, and automation scripts used by AI agent and MLOps workflows, this flaw poses a direct risk to agent-integrated development environments.

Updated Jul 26, 2026 · CVSS 8

fastjsonjavarceunpatchedspring-bootzero-dayagent-relevantsupply-chain-risk

Attackers are actively exploiting an unpatched critical vulnerability in Fastjson 1.x, Alibaba's widely used JSON serialization library for Java, to achieve unauthenticated remote code execution in Spring Boot applications. Security firms ThreatBook and Imperva have observed live exploitation attempts, and no official patch is currently available, leaving deployed systems exposed. The flaw allows a crafted JSON request to trigger code execution with the privileges of the underlying Java process.

Updated Jul 26, 2026 · CVSS 9

malvertisingwindowsfake-cryptosocial-engineeringevasionbun-runtimetrading-platforms

SourTrade is a malvertising campaign active since late 2024 that impersonates trusted brands like TradingView, Solana, and Luno to lure retail traders and crypto investors. It uniquely constructs its malicious Windows executable client-side, in the victim's browser, using a legitimate Bun JavaScript runtime as its base, avoiding detection by never serving a single complete malicious binary from a static URL.

Updated Jul 26, 2026

sextortiondata-breachextortionemail-scamShinyHunterssocial-engineering

Threat actors are leveraging email addresses and personal data leaked by the ShinyHunters extortion group to send mass sextortion emails demanding $2,000 in Bitcoin. The scam uses previously breached data to add false credibility, threatening victims with fake claims of compromising webcam footage or browsing history unless payment is made.

Updated Jul 26, 2026

malvertisingfileless-malwarecryptocurrencybrowser-based-attacksocial-engineeringin-memory-executionagent-relevant

A large-scale malvertising campaign is directing users to fake Solana, Luno, and TradingView websites that use malicious JavaScript to assemble malware directly in browser memory, evading disk-based detection. The campaign targets users seeking cryptocurrency and trading tools, likely aiming to steal credentials, wallet keys, or session tokens.

Updated Jul 26, 2026

clickfixcryptominingxmrigsocial-engineeringsteamgamingfake-fixclipboard-hijack

Threat actors are posting fake troubleshooting guides on Steam discussion forums that use the ClickFix social engineering technique to trick gamers into executing malicious commands via the Windows Run dialog. These commands ultimately deploy XMRig cryptominers on victim machines, hijacking system resources for cryptocurrency mining.

Updated Jul 26, 2026

ICSSCADAphysical-securitySSRFdeserializationremote-code-executioncritical-infrastructureCISA-advisory

Johnson Controls C-CURE 9000 and victor application server products contain three vulnerabilities, including a critical SSRF flaw (CVSS 9.6) in victor Web and a .NET deserialization-related SSRF issue enabling unauthenticated remote code execution on the application server. Successful exploitation could allow attackers with adjacent network access to compromise physical access control and video security systems, including connected client workstations used by security personnel.

Updated Jul 26, 2026 · CVSS 9.6

ICSOTIEC-60870-5-104denial-of-serviceout-of-bounds-readCISA-advisorycritical-infrastructureprotocol-library

MZ Automation's lib60870 library, versions 2.4.0 and earlier, contains an out-of-bounds read vulnerability (CVE-2026-16002) in its IEC 60870-5-104 protocol parsing code. Remote, unauthenticated attackers can crash the parsing process, causing a denial of service in energy, water/wastewater, and chemical sector control systems that rely on this library for SCADA/ICS communications.

Updated Jul 26, 2026 · CVSS 8.2

agent-relevantai-agentschatgptworkspace-agentsphishingprivilege-escalationopenaillm-security

Security researchers at Zenity Labs disclosed a critical vulnerability, dubbed AgentForger, in OpenAI's ChatGPT Workspace Agents that could allow an attacker to use a single phishing link to covertly create, authorize, and deploy a rogue autonomous AI agent inside a victim organization. OpenAI patched the issue as of June 8, but the flaw highlights significant risks in agent authorization and deployment workflows within enterprise AI platforms.

Updated Jul 25, 2026

active-directoryadcsprivilege-escalationkerberosdcsyncdomain-controllercredential-theftagent-relevant

Security researchers H0j3n and Aniq Fakhrul disclosed Certighost, an exploit chain allowing low-privileged Active Directory users to request a certificate impersonating a Domain Controller. The resulting Kerberos credential inherits directory replication rights, enabling attackers to perform DCSync and extract the krbtgt secret, effectively achieving full domain compromise.

Updated Jul 25, 2026

BlueNoroffNorth-KoreaAPTClickFixcrypto-theftsocial-engineeringtyposquattingwallet-draineragent-relevant

BlueNoroff, a North Korean state-sponsored threat actor, is operating an active phishing kit that impersonates Zoom and Microsoft Teams via typosquatted domains and ClickFix-style social engineering lures. The campaign profiles victims' cryptocurrency wallets before delivering malware, combining compromised industry contacts and trust abuse to maximize infection success.

Updated Jul 25, 2026

DNS hijackingcredential theftMicrosoft 365phishinghospitalitytravel-securitycaptive-portal-abuseagent-relevant

Threat actors are compromising DNS settings on hotel and conference center Wi-Fi routers/gateways to silently redirect guests to convincing fake Microsoft 365 login pages. Victims who enter credentials on these spoofed portals have their Microsoft 365 accounts stolen, potentially exposing corporate email, files, and connected services. The campaign leverages trust in hotel network infrastructure and captive portal flows to bypass user suspicion.

Updated Jul 25, 2026

data-breachlogisticspii-exposurecorporate-network-intrusion

OnTrac, a parcel delivery company, disclosed that attackers breached its corporate network and potentially accessed customer personal information. Details on the intrusion vector, threat actor, and full scope of compromised data remain limited based on available reporting.

Updated Jul 25, 2026

icsotiec61850buffer-overflowrcedenial-of-servicecritical-infrastructureenergy-sector

MZ Automation's libIEC61850 library, widely used for IEC 61850 substation automation and protection communications, contains four vulnerabilities including stack- and heap-based buffer overflows and NULL pointer dereferences. An unauthenticated, network-adjacent attacker could exploit these flaws to crash critical protection and control services or achieve remote code execution, directly threatening energy, manufacturing, and transportation ICS environments.

Updated Jul 25, 2026 · CVSS 9.2

ICSOTmobile-securitycleartext-storageAndroidCWE-312Johnson-Controlscritical-manufacturing

Johnson Controls XAAP Android application versions prior to 1.53 store application data locally in cleartext, allowing an attacker with physical device access and a separate compromise vector to read sensitive data in plaintext. Exploitation requires local device access and cannot be performed remotely over a network.

Updated Jul 25, 2026 · CVSS 3.3

agent-relevantmcprcedefault-credentialshost-header-bypassai-agent-infrastructureunauthenticated-accesschild-process-injection

9router versions up to 0.4.59 contain a chained vulnerability allowing a remote, unauthenticated attacker to gain full control of the host system. By logging in with a hardcoded default password, spoofing the Host header to bypass local-only network restrictions, and registering a malicious MCP plugin, an attacker can achieve arbitrary code execution. This is fixed in version 0.4.60 and should be patched immediately given the ease of exploitation and severity.

Updated Jul 25, 2026 · CVSS 9.9

path-traversalrceunauthenticatedllm-servingh2oGPTagent-relevantapi-key-exposure

h2oGPT through version 0.2.1 contains an unauthenticated path traversal vulnerability in its OpenAI-compatible files API that allows attackers to read, write, and delete arbitrary files on the host. Because the default API key is empty and the bearer token is used unsanitized as a path component, attackers can bypass authentication entirely and achieve remote code execution by overwriting startup hooks or application-loaded files.

Updated Jul 25, 2026 · CVSS 9.8

dnscache-poisoningunbounddns-resolverso_reuseportnetwork-securityagent-relevant

A vulnerability in NLnet Labs Unbound (versions 1.4.22 through 1.25.1) weakens DNS transaction security when SO_REUSEPORT load balancing is enabled, which is the default configuration. Attackers can infer the mapping between client source ports and internal worker threads, effectively reducing the entropy of outgoing query source ports and making DNS cache poisoning attacks significantly more feasible.

Updated Jul 25, 2026 · CVSS 9.3

zimbrazero-dayaptrussiaemail-compromise2fa-bypasscredential-theftespionageagent-relevant

A Russian state-sponsored espionage group exploited an unpatched zero-day vulnerability in Zimbra's webmail client to conduct a months-long mail collection campaign against Western targets. The exploit required no user interaction beyond opening a malicious email, and enabled theft of 90 days of mail history, full address book contents, browser-saved passwords, and 2FA recovery codes. NSA, CISA, and partner agencies have issued a joint advisory on the campaign.

Updated Jul 24, 2026