Conventional Threats Watchlist

Browse by attack type

Showing 601–620 of 804 threats, newest first

xssibmai-hubweb-vulnerabilityagent-relevantinjectionrce-potential

A critical cross-site scripting (XSS) vulnerability affects IBM Engineering AI Hub versions 1.0.0, 1.1.0, and 1.2.0, allowing remote attackers to inject and execute arbitrary scripts through improperly sanitized web page generation. Given the high CVSS score of 9.3, successful exploitation could lead to session hijacking, credential theft, and unauthorized actions performed in the context of authenticated users, including administrators.

Updated Jul 19, 2026 · CVSS 9.3

sql-injectionweb-applicationunauthenticateddata-breachlaboratory-systems

A critical unauthenticated SQL injection vulnerability affects GisLab Laboratory Management System versions 1.4.03 through 08072026, allowing attackers to manipulate backend database queries. With a CVSS score of 9.8, this vulnerability could enable full database compromise, data exfiltration, or destruction without requiring valid credentials.

Updated Jul 19, 2026 · CVSS 9.8

authentication-bypasspassword-reset-flawcve-2026-12692enterprise-softwareunauthenticated-access

CVE-2026-12692 is a critical unverified password change vulnerability in Vimesoft Inc.'s Enterprise Video Platform, allowing attackers to bypass authentication by resetting user passwords without proper verification. With a CVSS score of 9.8, this flaw could allow full account takeover, including administrative accounts, with minimal attacker effort. Organizations running affected versions (3.11.0.0 to before 3.25.0) should treat this as an urgent patching priority.

Updated Jul 19, 2026 · CVSS 9.8

patch-tuesdaymicrosoftvulnerability-managementwindowsai-assisted-discoveryagent-relevant

Microsoft released patches for at least 570 security vulnerabilities in its July 2026 Patch Tuesday, nearly triple the prior month's record-setting release. Microsoft attributes the surge in discovered flaws to AI-assisted vulnerability research, signaling both increased attacker and defender use of AI tooling to find bugs at scale. Organizations face a substantially expanded patching burden across Windows and related Microsoft products.

Updated Jul 18, 2026

npmsupply-chainblockchain-c2RATvitemalicious-packagesoftware-supply-chainagent-relevant

Researchers at Checkmarx identified seven malicious npm packages targeting the Vite frontend tooling ecosystem, codenamed ViteVenom, which deliver a remote access trojan (RAT). The campaign extends the previously observed ChainVeil operation, leveraging a four-tier blockchain-based command-and-control infrastructure spanning multiple chains including Tron to evade takedown and detection.

Updated Jul 18, 2026

openssldenial-of-servicememory-exhaustiontlsunpatched-flawno-cveagent-relevant

A previously undisclosed OpenSSL flaw dubbed HollowByte allows an attacker to send an 11-byte crafted TLS request that forces an unpatched server to allocate up to 131 KB of memory for a message fragment that never completes, permanently consuming that memory on glibc-based systems until the process is restarted. OpenSSL silently patched the issue in June without issuing a CVE, advisory, or changelog entry, and Okta's Red Team later identified, named, and disclosed the bug.

Updated Jul 18, 2026

wordpressrceunauthenticatedcmsweb-vulnerabilityagent-relevant

A critical unauthenticated remote code execution vulnerability, dubbed wp2shell, was discovered in WordPress core affecting versions 6.9 and 7.0, exploitable via a single anonymous HTTP request even on default installs with no plugins. WordPress released patched versions 6.9.5 and 7.0.2 and pushed forced auto-updates to mitigate mass exploitation. Researcher Adam Kues of Assetnote (Searchlight Cyber) discovered and reported the flaw.

Updated Jul 18, 2026 · CVSS 9.8

data-breachthird-party-risksupply-chainprofessional-servicessupport-ticket-system

Ernst & Young (EY) disclosed a data breach stemming from the compromise of a third-party support ticket system used by its IT staff. The incident highlights ongoing risks associated with vendor and supply-chain access to sensitive internal support infrastructure. Details on the scope of data accessed and the threat actor responsible remain limited based on available reporting.

Updated Jul 18, 2026

openssldosmemory-exhaustionunauthenticatedtlsagent-relevant

HollowByte is a denial-of-service vulnerability in OpenSSL that allows unauthenticated remote attackers to exhaust server memory using a malicious 11-byte payload. The flaw affects any service exposing an OpenSSL-based TLS listener, potentially causing crashes or severe resource exhaustion with minimal attacker effort.

Updated Jul 18, 2026

data-breachextortionhealthcarethird-party-risklegacy-systemsportal-compromise

Abbott Laboratories is investigating two separate cybersecurity incidents: unauthorized access to legacy Exact Sciences systems within its Cancer Diagnostics business, and a separate extortion claim involving alleged theft of data from its LabCentral portal. Both incidents are under active investigation and details on scope, data types affected, and threat actor identity remain limited.

Updated Jul 18, 2026

ICSOTdenial-of-serviceCIPRockwell Automationindustrial-control-systemscritical-manufacturing

A high-severity denial-of-service vulnerability (CVE-2026-9653) affects Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT communication modules due to improper validation of CIP Implicit Connection packets. A network-based attacker can send crafted packets to repeatedly disrupt device connections, though connections recover automatically. Rockwell Automation has released patches for the EN2 and EN3 modules, while the ENBT module is discontinued and will not receive a fix.

Updated Jul 18, 2026 · CVSS 7.5

ICSSCADACISA-advisoryXSSweb-vulnerabilitycritical-manufacturingrockwell-automation

A stored cross-site scripting (XSS) vulnerability affects Rockwell Automation FactoryTalk DataMosaix Private Cloud versions 8.02 and earlier, allowing an authenticated high-privilege attacker to inject persistent malicious scripts via the Workflows configuration. Successful exploitation could lead to account takeover, credential theft, or redirection of other users to malicious sites when they access the affected page. No public exploitation has been reported to date.

Updated Jul 18, 2026 · CVSS 6.1

ICSOTdenial-of-servicebuffer-overflowrockwell-automationcritical-manufacturingfirmwarePLC

Three vulnerabilities (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) affect multiple Rockwell Automation Logix controller families, allowing an unauthenticated remote attacker to send an invalid project or malformed file data that triggers a classic buffer overflow, causing the device to enter a major non-recoverable fault (MNRF). Exploitation results in denial-of-service impacting industrial control processes rather than data confidentiality or integrity loss. No known public exploitation has been reported to CISA at this time.

Updated Jul 18, 2026 · CVSS 8.6

wordpressplugin-vulnerabilityprivilege-escalationunauthenticatedcmsweb-application

The Bricksforge WordPress plugin (versions up to 3.1.8.6) contains a critical privilege escalation flaw in its Pro Forms registration action. Improper validation of the fieldIds parameter allows unauthenticated attackers to whitelist arbitrary form fields, including the administrator role field, enabling full site takeover via crafted registration requests.

Updated Jul 18, 2026 · CVSS 9.8

yamcsauthentication-bypassbrute-forcemissing-rate-limitingmission-control-softwarecve-2026-44596

Yamcs, an open-source mission control framework, contains a vulnerability in its authentication endpoint that allows unlimited password-guessing attempts due to missing rate limiting and account lockout mechanisms. An unauthenticated remote attacker could exploit this to brute-force credentials for any user account. The issue is patched in versions 5.12.7 and 5.13.0.

Updated Jul 18, 2026 · CVSS 6.5

account-takeoverresponse-manipulationauthentication-bypassHCLweb-application

CVE-2026-56453 affects HCL DFXAnalytics, allowing a remote attacker to intercept and manipulate HTTP responses to bypass authentication or authorization controls. This can result in unauthorized access to targeted user accounts without requiring credential theft.

Updated Jul 18, 2026 · CVSS 5.5

open-webuicors-misconfigurationrcellm-toolingadmin-takeoveragent-relevant

Open WebUI versions prior to 0.3.14 contain a CORS misconfiguration (allow_origins=*) combined with authenticated cookie-based requests to the /api/v1/functions endpoint, enabling attacker-controlled websites to trigger arbitrary code execution on the server. Exploitation requires an authenticated admin to visit a malicious webpage, after which the attacker can silently deploy or modify server-side functions to achieve RCE. This poses a serious risk to any organization self-hosting Open WebUI as an interface for LLMs or agentic workflows.

Updated Jul 18, 2026 · CVSS 8.3

xssopen-webuioauthaccount-takeoverllm-uiagent-relevantsupply-chain-component

Open WebUI versions prior to 0.9.5 contain a stored cross-site scripting vulnerability in the OAuth 'picture' claim handling, where MIME type validation relies on file extension instead of Content-Type headers. This allows attackers to smuggle malicious SVG files that execute script content when rendered, enabling authentication token theft and account takeover of Open WebUI users.

Updated Jul 18, 2026 · CVSS 7.3

roundupransomwarespywareinfostealerbrowser-securitysupply-chainweekly-digest

This is a weekly aggregated security news digest from The Hacker News covering multiple unrelated stories, including spyware disguised as game cheats, ransomware attacks that reach full encryption within 24 hours, and abuse of Chrome sync settings for tracking or session hijacking. The source material lacks technical depth on any single incident, functioning as a curated list of headlines rather than a detailed incident report.

Updated Jul 17, 2026

scattered-spidersocial-engineeringcritical-infrastructuretransportationlaw-enforcementhelp-desk-attack

Two members of the Scattered Spider hacking collective, Owen Flowers (18) and Thalha Jubair (20), were sentenced to five and a half years each for a 2024 cyberattack on Transport for London (TfL) that caused an estimated £29 million in losses. The attack rendered 148 TfL systems inoperable and required in-person password resets for all 27,000 employees, highlighting the operational disruption capability of social-engineering-driven threat actors against critical transit infrastructure.

Updated Jul 17, 2026