Conventional Threats Watchlist

Browse by attack type

Showing 581–600 of 804 threats, newest first

cryptocurrencydefioracle-manipulationoff-chain-infrastructurefinancial-theft

Attackers stole approximately $23.75 million from the Ostium decentralized trading platform's liquidity provider vault by compromising off-chain infrastructure responsible for feeding price data into the protocol. Rather than exploiting on-chain smart contract logic, the attackers targeted the trust boundary between off-chain price oracles and the on-chain settlement layer, enabling manipulated or falsified price feeds to drain vault funds.

Updated Jul 21, 2026

vpnzero-daysonicwallremote-accessedge-devicemalwarenetwork-perimeter

Threat actors exploited two previously undisclosed vulnerabilities in SonicWall SMA1000 series VPN appliances as zero-days for several weeks before public disclosure, deploying custom malware on compromised devices. The attacks targeted internet-facing remote access infrastructure, giving attackers a persistent foothold into victim networks.

Updated Jul 21, 2026

data-breachoracle-ebshr-datathird-party-riskvulnerability-exploitation

Estée Lauder disclosed a data breach after threat actors exploited a vulnerability in Oracle E-Business Suite, the platform used for the company's HR operations. The breach exposed employee data and is part of a broader pattern of attacks targeting Oracle E-Business Suite deployments across multiple organizations.

Updated Jul 21, 2026 · CVSS 9.8

icsscadadenial-of-servicenasacfscwe-476aerospacetransportation

A NULL pointer dereference vulnerability (CVE-2026-15352) in NASA's Core Flight System (cFS) Health & Safety (HS) Application allows a remote, unauthenticated attacker to crash the application via a crafted Housekeeping Telemetry request, causing a denial-of-service condition. The flaw affects versions prior to v7.0.1 and has been patched by NASA; no known public exploitation has been reported.

Updated Jul 21, 2026 · CVSS 7.5

command-injectionrceunpatched-fixweb-applicationphpcve-2026-64625cve-2026-45578

AVideo before version 29.0 contains an incomplete patch for a previously disclosed command injection vulnerability, allowing attackers to execute arbitrary OS commands via the Live plugin's on_publish.php endpoint. Despite the use of escapeshellarg(), the execAsync() function re-wraps escaped commands in a double-quoted sh -c shell, enabling command substitution through $() and backticks. This flaw carries a critical CVSS score of 9.8 and requires no authentication for exploitation.

Updated Jul 21, 2026 · CVSS 9.8

agent-relevantrcepickle-deserializationllm-infrastructureunauthenticatedzmqai-inference-framework

A critical unauthenticated remote code execution vulnerability exists in ktransformers, a popular LLM inference acceleration framework, affecting versions through 0.6.3. Attackers can send crafted pickle payloads to the SchedulerServer's ZMQ ROUTER socket, which is bound to all network interfaces by default, to achieve arbitrary command execution as the server process with no authentication required.

Updated Jul 21, 2026 · CVSS 9.8

command-injectiongradiorceunauthenticatedai-toolingtext-to-speechagent-relevantsupply-chain-risk

GPT-SoVITS, a popular open-source voice cloning/text-to-speech toolkit, contains a critical unauthenticated OS command injection vulnerability (CVSS 9.8) in its Gradio-based web UI. Attackers can execute arbitrary shell commands as the server process user by injecting shell metacharacters into ASR, slicing, denoising, or UVR5 path parameters, with no authentication required.

Updated Jul 21, 2026 · CVSS 9.8

nginxrcedosweb-serverheap-overflowunauthenticatedagent-relevant

F5 disclosed and patched a critical heap buffer overflow in nginx worker processes that can be triggered remotely by an unauthenticated attacker via crafted HTTP requests. The flaw can crash worker processes, causing denial of service, and may allow remote code execution in some configurations. Organizations running affected nginx or NGINX Plus versions should upgrade immediately.

Updated Jul 20, 2026

supply-chainrubygemsrubydeveloper-toolsmalicious-packageagent-relevant

Researchers identified a software supply chain attack dubbed SleeperGem involving three malicious RubyGems packages published to the official RubyGems registry. The packages, including one impersonating the legitimate 'git-credential-manager' tool, were designed to deliver additional payloads to developer machines. The attack targets Ruby developers and CI/CD pipelines that pull dependencies directly from RubyGems.

Updated Jul 20, 2026

cardingfraudresidential-proxiesbrowser-fingerprintingidentity-spoofingcybercrime-marketplace

Cybercriminals engaged in carding are increasingly seeking 'clean' residential proxies—IPs with no prior fraud flags—combined with spoofed browser fingerprints and device profiles to bypass modern fraud detection systems. This reflects an evolution in fraud tradecraft as anti-fraud vendors improve detection of traditional proxy and VPN traffic, pushing criminals toward more sophisticated identity-blending techniques.

Updated Jul 20, 2026

sponsored-contentprivacyage-verificationbiometricsnon-threat

This article is vendor-sponsored content from Incode discussing on-device age estimation technology as a privacy-preserving alternative to traditional facial biometric verification methods. It describes a product approach rather than a vulnerability, exploit, or active threat campaign. No malicious activity, IOCs, or CVEs are present in this content.

Updated Jul 20, 2026

supply-chainaptrussiagovernmentsoftware-update-abuseespionage

An advanced threat actor is abusing the legitimate update mechanism of ViPNet, a widely used private networking/VPN software suite in Russia, to deliver malicious payloads to government agencies and other organizations. The attack leverages trust in software update channels, a classic supply-chain technique, to gain persistent access to sensitive networks.

Updated Jul 20, 2026

north-korealazaruscontagious-interviewottercookiesteganographyfake-job-lurecredential-theftcrypto-theftagent-relevant

North Korean threat actors behind the Contagious Interview campaign are using fake coding tests and job postings to lure developers into running malicious projects. The payloads are hidden via steganography in SVG flag images, ultimately deploying a four-stage OtterCookie-aligned malware chain that steals browser credentials, crypto wallets, and files.

Updated Jul 19, 2026

code-signingcertificate-theftsupply-chainGoldenEyeDogAPT-Q-27Dragon BreathDigiCertChina-nexusagent-relevant

A threat cluster dubbed CylindricalCanine, attributed as a sub-group of the Chinese cybercrime actor GoldenEyeDog (aka APT-Q-27, Dragon Breath, Miuuti Group), was linked to the April 2026 breach of certificate authority DigiCert and the theft of code-signing certificates. Stolen certificates can be used to sign malware so it appears trusted, enabling supply-chain compromise across downstream software consumers.

Updated Jul 19, 2026

infostealercredential-theftagent-relevantbrowser-securitydata-exfiltration

Microsoft has identified a significant surge in attacks deploying ACR Stealer, an information-stealing malware targeting enterprise customers. The malware harvests browser-stored passwords, authentication tokens, and sensitive documents, posing a serious risk to organizational credential security and downstream account compromise.

Updated Jul 19, 2026

wordpressrcepublic-exploitcmsweb-applicationpatch-nowagent-relevant

Public exploit code has been released for critical remote code execution vulnerabilities dubbed "wp2shell" affecting WordPress Core, significantly increasing the risk of widespread exploitation. Administrators are urged to patch immediately as attackers can now leverage readily available exploit tooling to compromise unpatched sites.

Updated Jul 19, 2026 · CVSS 9.8

7-ziprcearchive-exploitfile-parsingpatch-availableagent-relevant

7-Zip version 26.02 patches a remote code execution vulnerability that can be triggered when a user opens a specially crafted compressed archive. Attackers could leverage social engineering to deliver malicious archives and gain code execution on victim systems. Users and organizations should update immediately to mitigate risk.

Updated Jul 19, 2026

ICSOTdenial-of-serviceCISA-advisoryRockwell-AutomationCIP-protocoldouble-free

A high-severity denial-of-service vulnerability (CVE-2026-12659) affects Rockwell Automation Flex 5000 Adapter version 6.011 due to a double-free condition triggered by crafted CIP packets. Successful exploitation halts the affected module, requiring a manual power cycle to restore operation, posing operational risk to industrial control environments.

Updated Jul 19, 2026 · CVSS 7.5

ICSSCADAPLCengineering-workstationdriver-vulnerabilitykernel-memory-corruptionlocal-privilege-escalationcritical-manufacturingCISA-advisory

AutomationDirect Productivity Suite versions up to v4.6.2.2 contain six vulnerabilities including out-of-bounds write/read flaws and a divide-by-zero condition, primarily triggered via crafted IOCTL requests to a kernel driver or malicious USB devices. Exploitation requires local or physical access and could lead to kernel memory corruption, privilege escalation, information disclosure, or denial-of-service on engineering workstations. No known public exploitation has been reported, and the vulnerabilities are not remotely exploitable.

Updated Jul 19, 2026 · CVSS 7

ICSOTcritical-manufacturingmemory-corruptionout-of-bounds-writearbitrary-code-executionlocal-exploituser-interaction-required

Rockwell Automation Arena versions up to and including V17.00.00 contain four out-of-bounds write vulnerabilities (CVE-2026-8085, CVE-2026-8312, CVE-2026-8313, CVE-2026-8314) in the model.exe, expmt.exe, linker.exe, and siman.exe (Siman) components. Successful exploitation requires a user to open a malicious file, potentially allowing arbitrary code execution in the context of the current process. No public exploitation has been reported as of publication.

Updated Jul 19, 2026 · CVSS 7.8