Conventional Threats Watchlist

Browse by attack type

Showing 621–640 of 804 threats, newest first

browser-extensionai-agentclaudeanthropicprivilege-abuseagent-relevantcross-extension-attackdata-exfiltration

A vulnerability in Anthropic's Claude for Chrome browser extension allows a malicious co-installed extension to simulate user clicks and covertly trigger Claude's predefined AI actions. Since Claude may hold authenticated access to connected services like Gmail, Google Docs, Google Calendar, and Salesforce, an attacker could abuse this to exfiltrate data or perform unauthorized actions on the user's behalf without genuine user consent.

Updated Jul 17, 2026

ransomwaremanufacturingOT-disruptionfood-and-beveragesupply-chain-disruptioncritical-infrastructure

Coca-Cola disclosed that a ransomware attack against its Fairlife dairy subsidiary has disrupted operations, forcing a temporary suspension of Fairlife product manufacturing across the United States. The incident highlights continued targeting of large food and beverage manufacturers by ransomware operators seeking to leverage operational disruption for extortion leverage.

Updated Jul 17, 2026

macosinfostealercredential-theftsocial-engineeringagent-relevant

ClickLock is a newly identified macOS information-stealing malware that forcibly terminates all visible user processes to coerce victims into entering their system login password. Once captured, this password can be used to unlock keychains, decrypt stored credentials, and gain deeper system access. The technique represents an evolution in macOS malware social engineering, exploiting user trust in system prompts.

Updated Jul 17, 2026

kev-catalogfortinetfortisandboxmicrosoft-sharepointos-command-injectiondeserializationactive-exploitationfcebbod-26-04agent-relevant

CISA added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog: two OS command injection flaws in Fortinet FortiSandbox and a deserialization of untrusted data vulnerability in Microsoft SharePoint. All three are confirmed to be exploited in the wild and pose significant risk to organizations running these products, particularly federal agencies bound by BOD 26-04 remediation timelines.

Updated Jul 17, 2026

ICSphysical-securityaccess-controlprivilege-escalationauthorization-bypassCISA-advisory

A privilege escalation vulnerability exists in SALTO ProAccess Space access control software versions prior to 6.13, affecting installations using the tenancy/logical partition feature. An authenticated attacker with valid operator credentials can bypass partition boundaries to access spaces outside their assigned tenancy, potentially compromising physical access control across an organization's facilities.

Updated Jul 17, 2026 · CVSS 6.5

ICSOTSCADASiemenscritical-infrastructureenergy-sectorvulnerabilityfirmwareprivilege-escalationdenial-of-service

Siemens has disclosed four vulnerabilities affecting SICAM 8 product firmware (CPCI85 and SICORE base systems) used in energy and critical manufacturing environments. The flaws include an exposed debugging interface, insufficient firmware update signature validation, insecure default OPC UA security settings, and unverified password changes, which combined could lead to denial of service, unauthorized access, or persistent code execution on affected devices. Siemens has released firmware updates (V26.20/V26.20.0) to remediate all four issues.

Updated Jul 17, 2026 · CVSS 7.2

adobe-commercemagentoe-commerceauthorization-bypassweb-applicationunauthenticated-exploit

A high-severity Incorrect Authorization vulnerability affects Adobe Commerce, allowing attackers to bypass security controls and gain unauthorized read and write access without requiring user interaction. This flaw poses significant risk to e-commerce platforms storing sensitive customer, payment, and order data.

Updated Jul 17, 2026 · CVSS 8.2

microsoft-365-copilotiosprivilege-escalationaccess-controlagent-relevantai-agent-security

A high-severity access control flaw in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network. Exploitation could grant attackers elevated access to Copilot functionality and connected data without proper authorization, posing risk to enterprise mobile deployments.

Updated Jul 17, 2026 · CVSS 8.1

windowsrdprceinteger-overflownetwork-exploitableunauthenticatedagent-relevant

CVE-2026-58594 is an integer overflow/wraparound vulnerability in Windows Remote Desktop Protocol (RDP) that allows an unauthorized, remote attacker to execute arbitrary code over the network. With a CVSS score of 8.8, this flaw poses significant risk to any exposed or internally reachable RDP service, enabling potential full system compromise without prior authentication.

Updated Jul 17, 2026 · CVSS 8.8

windowsrceuse-after-freesstpnetwork-protocolremote-accessvpn

CVE-2026-50694 is a use-after-free vulnerability in Windows' Secure Socket Tunneling Protocol (SSTP) implementation that allows an unauthorized, remote attacker to execute arbitrary code over the network. Given SSTP's role in VPN connectivity, this flaw poses significant risk to organizations relying on Windows-based VPN gateways and remote access infrastructure. The CVSS score of 8.1 reflects high severity with network-based exploitability and no authentication required.

Updated Jul 17, 2026 · CVSS 8.1

active-directoryrceheap-overflowwindowsnetwork-exploitdomain-controlleragent-relevant

CVE-2026-49164 is a heap-based buffer overflow in Active Directory Domain Services (AD DS) that allows an unauthorized, remote attacker to execute arbitrary code without authentication. Given AD DS's central role in enterprise identity infrastructure, successful exploitation could lead to full domain compromise. The CVSS score of 8.1 reflects high impact combined with network-based, low-complexity attack requirements.

Updated Jul 17, 2026 · CVSS 8.1

CISA-KEVunauthenticated-RCEcommand-injectionFortinetnetwork-security-appliancemalware-sandboxedge-deviceagent-relevant

CVE-2026-39808 is an unauthenticated OS command injection vulnerability in Fortinet FortiSandbox, added to CISA's Known Exploited Vulnerabilities catalog with a short remediation window (added 2026-07-16, due 2026-07-19), indicating active exploitation in the wild. Attackers can send crafted HTTP requests to execute arbitrary commands without authentication, potentially gaining full control of the appliance.

Updated Jul 17, 2026

iotbotnetllm-generated-malwareai-assisted-malwarelinuxmirai-variant

TuxBot v3 Evolution is a newly disclosed IoT botnet framework whose codebase shows evidence of being partially generated using an LLM, including a leftover safety disclaimer the developer failed to strip out. The botnet targets vulnerable IoT devices for likely DDoS and further propagation purposes, illustrating growing use of generative AI tools in lowering the barrier to malware development.

Updated Jul 16, 2026

agent-relevantAI-agent-abuseLLM-toolingbotnetthreat-actorgemini-cliagentic-malware

A Russian-speaking threat actor known as 'bandcampro' has been observed repurposing Google's open-source Gemini CLI AI tool as an autonomous hacking agent to conduct offensive operations and manage a small-scale botnet. This represents a real-world case of adversaries weaponizing legitimate agentic AI tooling to automate reconnaissance, exploitation, and malware/botnet management tasks.

Updated Jul 16, 2026

zoomaccount-takeoverwindowsunauthenticatedvulnerabilityclient-side

Zoom has disclosed a critical vulnerability affecting its desktop client and software development kit (SDK) for Windows that could allow an unauthenticated attacker to hijack user accounts. No public exploitation has been reported yet, but the severity rating indicates high risk if a working exploit emerges. Organizations using Zoom on Windows endpoints should prioritize patching.

Updated Jul 16, 2026

investment-fraudlaw-enforcementtakedownsocial-engineeringfinancial-crime

Dutch Police arrested multiple suspects linked to a large-scale international investment fraud scheme that defrauded tens of thousands of victims out of over €100 million. The operation reportedly used deceptive online investment platforms and social engineering tactics to lure victims into fraudulent schemes.

Updated Jul 16, 2026

kevcisaactive-exploitationptc-windchillflexplmcisco-ucmssrfimproper-input-validationfederal-agencies

CISA has added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities Catalog: an improper input validation flaw in PTC Windchill and FlexPLM, and an SSRF vulnerability in Cisco Unified Communications Manager. Both are confirmed under active exploitation and pose significant risk, particularly to federal enterprise systems subject to BOD 26-04 remediation timelines.

Updated Jul 16, 2026

CISAKEVauthentication-bypassSimpleHelpremote-access-toolactive-exploitationBOD-26-04agent-relevant

CISA has added CVE-2026-48558, an authentication bypass vulnerability in SimpleHelp remote access software, to its Known Exploited Vulnerabilities catalog based on confirmed active exploitation. Federal civilian agencies are required under BOD 26-04 to remediate the flaw on a prioritized timeline, and CISA urges all organizations, public and private, to do the same.

Updated Jul 16, 2026

sharepointrcedeserializationmachine-key-theftwebshellpost-exploitationkevmicrosoftagent-relevant

CISA has confirmed active exploitation of three SharePoint Server on-premises vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164) allowing remote code execution, IIS machine key theft, and deserialization-based persistence. Two additional unexploited CVEs (CVE-2026-55040, CVE-2026-58644) have also been disclosed by Microsoft as high-risk if unpatched. All supported on-premises SharePoint versions are affected, prompting CISA to mandate emergency patching under its KEV catalog.

Updated Jul 16, 2026

ICSOTABBT-MAC Plusfile-disclosureaccess-control-bypassXSSdenial-of-servicecritical-infrastructurecritical-manufacturing

ABB disclosed four vulnerabilities in T-MAC Plus 4.0-24, a Terminal Management System used in chemical, petroleum, and bulk terminal operations. The most severe issue (CVSS 9.9) allows authenticated users to exfiltrate sensitive files via crafted HTTP GET requests due to IIS misconfiguration, while other flaws enable privilege escalation, stored XSS, and physical-access-based denial of service against Card Reader services. ABB has released version 4.0-25 to remediate all four issues.

Updated Jul 16, 2026 · CVSS 9.9