Conventional Threats Watchlist

Browse by attack type

Showing 41–60 of 789 threats, newest first

path-traversaldokploytraefikrceunauthenticatedpublic-exploitagent-relevantself-hosted-paasdevops-tooling

A critical unauthenticated path traversal vulnerability affects Dokploy up to version 0.29.7, specifically in the writeTraefikConfigInPath function used by the Settings component to generate Traefik configuration files. The flaw allows remote attackers to manipulate the path argument to write files outside intended directories, potentially leading to configuration overwrite, service disruption, or remote code execution. A public exploit is available and the vendor has not responded to disclosure, leaving deployments unpatched and exposed.

Updated Sep 2, 2026 · CVSS 9.9

d-linknasos-command-injectioncginetwork-storagepublicly-disclosedremote-exploitiot

A critical OS command injection vulnerability affects multiple D-Link NAS devices (DNS-320L, DNS-327L, DNS-340L, DNS-345) through the usb_device.cgi CGI handler. The flaw allows unauthenticated remote attackers to execute arbitrary OS commands via the f_ups_ip parameter, and a public exploit is already available, making immediate exploitation highly likely.

Updated Sep 2, 2026 · CVSS 9.1

backdoorValleyRATSilver Foxadwarecode-signing-abuseantivirus-evasionRATChina

The Silver Fox threat actor is distributing the ValleyRAT backdoor concealed within a digitally signed Chinese desktop-wallpaper application called QN Wallpaper. By running under a trusted, signed process that users commonly whitelist in antivirus exclusions, the malware evades detection and establishes persistent remote access on infected hosts.

Updated Sep 1, 2026

insider-threatdprkfraudulent-employmentsocial-engineeringsanctions-evasionidentity-fraud

North Korean threat actors are expanding their long-running fraudulent IT worker employment scheme into new sectors, including healthcare and sales/marketing roles. This insider threat operation uses stolen or fabricated identities to secure remote employment, generating revenue for the DPRK regime while creating potential access and data exposure risks for employers.

Updated Sep 1, 2026

outageavailabilityexchange-onlinemicrosoft365authentication-failureemail-delivery

Microsoft Exchange Online experienced a widespread service disruption causing authentication failures, email delays, and delivery failures for customers. This is an availability incident rather than a malicious attack, but it can disrupt business email operations and any downstream services relying on Exchange authentication or mail flow.

Updated Sep 1, 2026

clickfixsocial-engineeringpowershellreverse-tunnelfake-captchainitial-accessagent-relevant

Microsoft has identified a new ClickFix variant called TerminalFix that uses fake Cloudflare CAPTCHA verification prompts on compromised websites to trick users into copy-pasting and executing malicious PowerShell commands in Windows Terminal. The attack establishes reverse tunnels for persistent remote access, enabling attackers to bypass network perimeter defenses.

Updated Sep 1, 2026

deficryptocurrencyprice-oracle-manipulationflash-loancronossmart-contract-exploitblockchain

An attacker exploited a price-manipulation vulnerability in the Tectonic cryptocurrency lending platform on the Cronos blockchain, enabling fraudulent borrowing of approximately $74 million. The exploit forced validators to halt and restart the Cronos network to contain the incident, disrupting trading activity network-wide.

Updated Sep 1, 2026

CISAKEVPaperCutauthentication-bypassunsafe-reflectionprint-managementfederalvulnerability-managementBOD-26-04

CISA has added two actively exploited PaperCut NG/MF vulnerabilities to its Known Exploited Vulnerabilities catalog, one involving missing authentication for a critical function and another involving unsafe reflection. These flaws pose significant risk to organizations running PaperCut print management software, with federal agencies required to remediate under BOD 26-04.

Updated Sep 1, 2026

iaciamprivilege-escalationcloud-securitypulumiinfrastructure-as-codeagent-relevant

A critical privilege escalation vulnerability in hulumi (versions prior to v1.3.2) allows attackers with access to a documented IAM principal to abuse an overly permissive weekly integration policy. This enables creation of persistent, higher-privilege af-e2e-* roles in sandbox accounts, potentially leading to full account compromise.

Updated Sep 1, 2026 · CVSS 9.8

iam-misconfigurationoidcawsgithub-actionssupply-chaincicd-securityagent-relevant

A critical flaw in @hulumi/policies before version 1.3.2 allows attackers to craft AWS IAM condition operators (ForAnyValue:StringLike) that evade security guardrails designed to detect overly permissive GitHub Actions OIDC trust policies. This enables attackers to establish stealthy, wildcard-based trust relationships between arbitrary GitHub repositories/workflows and AWS IAM roles, potentially leading to unauthorized cross-account access.

Updated Sep 1, 2026 · CVSS 9.8

iotrouterbuffer-overflowrcetotolinkpublic-exploitunauthenticated

A critical stack-based buffer overflow vulnerability affects the TOTOLINK NR1800X router firmware, exploitable remotely via the setUploadSetting function without authentication. A public exploit exists, making this an immediate risk for internet-exposed devices.

Updated Sep 1, 2026 · CVSS 9.9

d-linkrouteriotrcebuffer-overflownetwork-deviceunauthenticatedexploit-published

A critical remote code execution vulnerability exists in D-Link DIR-825M 1.1.8 routers, caused by a stack-based buffer overflow in the LTE Module Firmware Upgrade handler (formLtefotaUpgradeFibocom). An attacker can remotely manipulate the fota_url parameter to trigger the overflow, with a public exploit already available, making this an immediate risk to exposed devices.

Updated Sep 1, 2026 · CVSS 9.9

buffer-overflowrouteriotremote-code-executionpublic-exploittendaboa-web-server

A critical, publicly disclosed vulnerability affects the Tenda HG10 router (firmware 300001138) via its Boa Web Server admin interface. The flaw allows remote, unauthenticated attackers to trigger a buffer overflow through the destNet parameter in the formIPv6Routing function, potentially leading to full device compromise. With a CVSS score of 10.0 and public exploit code available, active exploitation is highly likely.

Updated Sep 1, 2026 · CVSS 10

PaperCutCISA-KEVRCEunsafe-reflectionchained-exploitprint-managementjava

PaperCut NG/MF is affected by an unsafe reflection vulnerability that allows attackers to manipulate system configuration parameters and execute arbitrary Java bytecode under the security context of the PaperCut server process. This flaw has been added to CISA's Known Exploited Vulnerabilities catalog and can be chained with CVE-2026-81578 to achieve full remote code execution, mirroring the exploitation pattern seen in prior PaperCut attacks used for ransomware and network intrusion.

Updated Sep 1, 2026

roboticsiotroot-rcebluetoothphysical-securityunitreehumanoid-robothardware

Security researcher Olivier Laflamme disclosed two independent exploit chains achieving root remote code execution on the Unitree G1 EDU humanoid robot, tracked as CVE-2026-76639 and CVE-2026-76640. One chain requires only Bluetooth Low Energy proximity to compromise the robot's Locomotion PC, while the other exploits a network-adjacent path through the chat_go and bashrunner components, posing serious risks for research, industrial, and educational deployments of the robot.

Updated Aug 31, 2026

browser-extensioncryptocurrency-theftmalicious-extensionchromeedgewallet-stealeragent-relevant

Researchers identified 19 malicious Chrome and Edge extensions published over the past six months that steal cryptocurrency wallet secrets and drain funds. The extensions share common code and tradecraft, suggesting a coordinated campaign distributed through official browser extension stores. This poses a broad supply-chain risk to any user or organization installing these extensions.

Updated Aug 31, 2026

clickfixsocial-engineeringpowershellwindows-terminalreverse-tunnelbackdoorfake-captchainitial-accessagent-relevant

Microsoft disclosed a new ClickFix-style social engineering campaign, dubbed TerminalFix, that uses fraudulent Cloudflare CAPTCHA pages to trick users into executing malicious commands in Windows Terminal or PowerShell instead of the traditional Run dialog. Successful execution deploys a reverse-tunnel backdoor granting attackers persistent remote access to the compromised host. This shift to terminal-based execution increases the likelihood that victims run more complex, capability-rich payloads compared to earlier ClickFix variants.

Updated Aug 31, 2026

browser-extensionchrome-web-storeedgecryptocurrency-theftclickfixmalware-frameworkdata-exfiltrationagent-relevant

Multiple malicious extensions distributed through the Chrome Web Store and Microsoft Edge Add-ons store delivered a modular malware framework capable of stealing cryptocurrency, browsing history, and other sensitive data. The campaign also deployed ClickFix-style social engineering lures to trick users into executing further malicious commands, expanding the attack's reach beyond simple browser compromise.

Updated Aug 31, 2026

infostealersession-hijackingcredential-theftAI-account-abuseagent-relevantLLM-abusetoken-theft

Anthropic has warned that infostealer malware infecting user PCs is exfiltrating active Claude session tokens, allowing attackers to hijack accounts and consume victims' paid usage. This represents a growing trend of infostealers specifically targeting AI service credentials and session cookies rather than just traditional banking or email accounts.

Updated Aug 31, 2026

data-breachdata-theftaviationcustomer-dataextortion

The threat actor group FulcrumSec claims to have stolen 86 GB of data from Manchester Airports Group (MAG), including detailed customer, booking, and travel records. BleepingComputer validated at least one traveller's record from leaked samples, suggesting the breach scope exceeds what MAG initially disclosed.

Updated Aug 31, 2026