Conventional Threats Watchlist

Browse by attack type

Showing 541–560 of 804 threats, newest first

data-breachpii-exposureenergy-sectoraustraliacustomer-data-leak

Origin Energy, a major Australian energy provider, confirmed that an unauthorized party accessed customer data and subsequently leaked it online. The breach exposed sensitive personally identifiable information (PII), raising concerns about downstream fraud, phishing, and identity theft targeting affected customers.

Updated Jul 24, 2026

RATremote-access-trojanAI-powered-malwarevictim-profilingcredential-theftagent-relevant

Dolphin X is a newly identified remote access trojan that incorporates an AI-driven profiling feature to automatically score and rank infected hosts by potential value, allowing operators to prioritize high-value victims for follow-on exploitation. This automation reduces the manual triage effort typically required by threat actors managing large botnets of compromised machines.

Updated Jul 24, 2026

ICSOTpath-traversalrockwell-automationthinmanagerindustrial-control-systemsCWE-22

A high-severity path traversal vulnerability (CVE-2026-11917) affects multiple versions of Rockwell Automation ThinManager, allowing an authenticated attacker to write arbitrary files to restricted system directories outside the application's intended scope. No public exploitation has been reported at this time, but organizations in critical infrastructure sectors using affected versions should prioritize patching.

Updated Jul 24, 2026 · CVSS 8.1

ICSHMIvulnerabilityprivilege-escalationplaintext-passwordCWE-784CWE-732CWE-256CWE-286critical-manufacturingCISA-advisory

CISA disclosed four vulnerabilities in Weintek cMT3092X HMI devices and their EasyWeb web interface, allowing non-privileged users to escalate privileges via cookie/token manipulation, view plaintext-stored user credentials, and modify data that should be read-only. The highest-severity flaws (CVSS v3.1 8.8) enable full compromise of confidentiality, integrity, and availability on affected industrial control devices. No public exploitation has been reported, but a vendor patch is available.

Updated Jul 24, 2026 · CVSS 8.8

oracleldapdirectory-serviceunauthenticated-rceidentity-infrastructureagent-relevant

A maximum-severity vulnerability (CVSS 10.0) exists in Oracle Unified Directory's OUD Core component, allowing an unauthenticated attacker with network access via LDAP to fully compromise the directory service. The vulnerability's scope change indicates successful exploitation can impact additional connected products and systems beyond OUD itself.

Updated Jul 24, 2026 · CVSS 10

oracleaccess-managementauthentication-bypassunauthenticated-rcecritical-infrastructureidentity-provideragent-relevant

A maximum-severity (CVSS 10.0) vulnerability in Oracle Access Manager's Authentication Engine allows unauthenticated, network-based attackers to fully compromise the identity and access management system. The flaw has a scope change, meaning successful exploitation can cascade to impact other integrated applications and services relying on OAM for authentication.

Updated Jul 24, 2026 · CVSS 10

oracleaccess-managerfusion-middlewareunauthenticated-rceauthentication-bypassidentity-managementagent-relevant

A critical unauthenticated vulnerability (CVE-2026-60355) in Oracle Access Manager's Authentication Engine allows remote attackers to fully compromise the identity and access management system over HTTP with no credentials required. Given the CVSS 9.8 score and full confidentiality, integrity, and availability impact, successful exploitation could grant attackers complete control over enterprise authentication infrastructure. Organizations using Oracle Access Manager for SSO or identity federation are at severe risk of large-scale account takeover and downstream system compromise.

Updated Jul 24, 2026 · CVSS 9.8

oracleaccess-managerauthentication-bypassscope-changeidentity-providerssocritical-infrastructureagent-relevant

A critical vulnerability (CVSS 9.9) in Oracle Access Manager's Authentication Engine allows a low-privileged attacker with only network access via HTTP to fully compromise the identity and access management system. Due to a scope change, successful exploitation can impact additional connected products beyond Oracle Access Manager itself, making this a high-priority patching target for any organization relying on Oracle Fusion Middleware for SSO and access control.

Updated Jul 24, 2026 · CVSS 9.9

oraclecoherencerceunauthenticatedmiddlewarecritical-infrastructureagent-relevant

CVE-2026-60296 is a critical, easily exploitable vulnerability in Oracle Coherence (Oracle Fusion Middleware) that allows an unauthenticated attacker with network access to fully compromise the affected server over TCP. With a CVSS score of 9.8 and no authentication or user interaction required, this flaw poses severe risk to any organization running affected Coherence versions, including those used as caching/data grid layers behind enterprise and AI-driven applications.

Updated Jul 24, 2026 · CVSS 9.8

residential-proxyiotsmart-tvwebosproxywareprivacyconsumer-device-abuse

Researchers found that over 42% of apps on LG's webOS smart TV store secretly embed residential proxy SDKs, allowing unknown third parties to route their internet traffic through consumers' TVs without clear consent. LG has announced it will ban apps that turn smart TVs into always-on residential proxy nodes. This practice exposes users' home IP addresses and bandwidth to potentially malicious or anonymized traffic routed by unknown actors.

Updated Jul 23, 2026

browser-extensionadobe-acrobatwhatsapp-webcross-origindata-exposurechrome-extensionprivacy

A now-patched vulnerability chain in the Adobe Acrobat Chrome extension, dubbed HermeticReader by Guardio Labs and tracked as CVE-2026-48294, could allow malicious websites to silently read a user's WhatsApp Web data. The extension, installed by over 314 million users, contained a flaw that broke cross-origin isolation, enabling covert hijacking of session data without user interaction.

Updated Jul 23, 2026 · CVSS 7.4

linuxprivilege-escalationubuntusnaplpeagent-relevant

A high-severity local privilege escalation vulnerability in Ubuntu's snap-confine component allows an unprivileged local user to gain full root access on default Ubuntu Desktop installations. The flaw affects Ubuntu Desktop 24.04, 25.10, and 26.04 out of the box, making it a significant risk for any multi-user or shared Linux host.

Updated Jul 23, 2026 · CVSS 7.8

bug-bountypolicy-changegithubvulnerability-disclosureindustry-news

GitHub announced it will cut public bug bounty payouts by at least half across all severity levels starting July 27, 2026, while introducing a permanent invite-only VIP tier that retains higher payouts of $30,000 or more. Reports already submitted or in GitHub's triage queue before that date will honor the previous payout structure.

Updated Jul 23, 2026

ransomwareextortionsupply-chainthird-party-riskmanufacturingrail-industryEverest-gang

Swiss rail vehicle manufacturer Stadler Rail was targeted by the Everest ransomware gang, which breached a data exchange platform shared with one of its suppliers and demanded a $12.3 million ransom. Stadler rejected the demand, indicating the attack likely originated through a third-party or supplier-connected system rather than Stadler's core infrastructure.

Updated Jul 23, 2026

data-breachgovernmentespionagesouth-koreacredential-theftdiplomatic-targeting

South Korea's Ministry of Foreign Affairs disclosed that attackers breached the National Diplomatic Academy's online education system, maintaining unauthorized access for approximately ten months. The compromise resulted in theft of personal information belonging to current and former MFA employees, including overseas diplomats, raising concerns about follow-on espionage and social engineering targeting diplomatic personnel.

Updated Jul 23, 2026

data-breachfraudfintechidentity-theftPII-exposure

Upbound Group, the parent company of fintech lease-to-own provider Acima, disclosed that attackers who stole customer data from its systems used that information to fraudulently generate $13 million in Acima lease agreements. The incident highlights how stolen PII and account data can be weaponized for downstream financial fraud beyond the initial breach.

Updated Jul 23, 2026

ICSOTPAN-OSSiemensRUGGEDCOMcommand-injectionprivilege-escalationXSScritical-infrastructure

Siemens RUGGEDCOM APE1808 devices running Palo Alto Networks Virtual NGFW are affected by three vulnerabilities disclosed upstream in PAN-OS, including stored XSS, missing authorization leading to privilege escalation, and OS command injection allowing root-level code execution. Exploitation requires authenticated administrative access, which limits attack surface but still poses significant risk in industrial control system environments if management interfaces are exposed or misconfigured. Siemens recommends contacting customer support for patches and following standard ICS network isolation best practices.

Updated Jul 23, 2026 · CVSS 7.2

icsscadasiemensprivilege-escalationunquoted-search-pathvulnerability-disclosure

Multiple Siemens industrial and engineering software products bundling the IAM Client SDK are affected by an untrusted/unquoted search path vulnerability that could allow an authenticated local attacker to escalate privileges. Siemens has released patched versions for most affected products and recommends updating as soon as possible, with fixes pending for remaining products.

Updated Jul 23, 2026 · CVSS 6.7

CISAKEVCheck PointSmartConsoleSharePointdeserializationauthentication-bypassactive-exploitationfederal-agenciesagent-relevant

CISA has added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities Catalog: an improper authentication flaw in Check Point SmartConsole (CVE-2026-16232) and a deserialization of untrusted data vulnerability in Microsoft SharePoint (CVE-2026-50522). Both are confirmed to be exploited in the wild, prompting mandatory remediation timelines for FCEB agencies under BOD 26-04 and a strong recommendation for all organizations to patch immediately.

Updated Jul 23, 2026

oracleunauthenticated-rcenetwork-exploitablecvss-9.8testing-infrastructure

A critical unauthenticated remote code execution vulnerability affects Oracle Application Testing Suite version 13.3.0.1, allowing attackers with mere network access to fully compromise the system without any credentials or user interaction. The flaw carries a maximum-impact CVSS score of 9.8, threatening confidentiality, integrity, and availability, and is trivially exploitable, making it a high-priority patching target.

Updated Jul 23, 2026 · CVSS 9.8