Conventional Threats Watchlist

Browse by attack type

Showing 661–680 of 804 threats, newest first

perlregexinteger-overflowlogic-flawinput-validationagent-relevantrag-pipelinesupply-chain-risk

A flaw in Perl's regex engine (Perl_study_chunk) causes silent match corruption when an alternation pattern contains more than 65535 fixed-string branches, due to a 16-bit field overflow during trie compilation. This can produce false positive or false negative matches with no warning, undermining any security or filtering logic that relies on such patterns.

Updated Jul 15, 2026 · CVSS 9.1

joomlacmsfile-deletionunauthenticatedweb-vulnerabilityhelix-ultimate

CVE-2026-57830 is a critical vulnerability in the Helix Ultimate Joomla extension that allows unauthenticated attackers to delete arbitrary files on the underlying server. This could lead to denial of service, configuration file loss, or destruction of critical application data without requiring any authentication.

Updated Jul 15, 2026 · CVSS 9.1

sonicwallsma1000code-injectioncisa-kevremote-accessvpnprivileged-attackercommand-execution

CVE-2026-15410 is a code injection vulnerability in SonicWall SMA1000 Appliances that allows an authenticated remote attacker with administrator privileges to execute arbitrary OS commands. The flaw has been added to CISA's Known Exploited Vulnerabilities catalog, indicating confirmed active exploitation in the wild. Organizations using SMA1000 for secure remote access are urged to remediate under an accelerated timeline.

Updated Jul 15, 2026

sharepointprivilege-escalationcisa-kevunauthenticatedon-premisesexploited-in-the-wild

CVE-2026-56164 is a missing authentication for critical function vulnerability in Microsoft SharePoint Server that allows an unauthorized, remote attacker to elevate privileges over the network. CISA has added this CVE to its Known Exploited Vulnerabilities (KEV) catalog with an aggressive three-day remediation deadline, indicating active exploitation in the wild. Organizations running on-premises SharePoint Server deployments should treat this as an urgent patching priority.

Updated Jul 15, 2026

CISA-KEVactive-exploitationprivilege-escalationADFSidentity-infrastructureactive-directoryagent-relevant

CVE-2026-56155 is a known-exploited privilege escalation vulnerability in Microsoft Active Directory Federation Services (ADFS) caused by insufficient granularity of access control. It allows an authorized but low-privileged attacker to elevate privileges locally, potentially leading to compromise of federated identity infrastructure. CISA has added it to the Known Exploited Vulnerabilities catalog with a remediation deadline of July 28, 2026.

Updated Jul 15, 2026

credential-exposuregithubcloud-securitysecrets-managementgovernmentsupply-chaininsider-riskagent-relevant

A CISA contractor inadvertently published dozens of sensitive internal credentials, including AWS GovCloud keys, in a public GitHub repository where they remained exposed for nearly six months before external notification by a security journalist. The incident highlights systemic weaknesses in secrets management, contractor oversight, and detection capability within a federal cybersecurity agency, raising concerns about the broader public and private sector's exposure to similar risks.

Updated Jul 14, 2026

ShareFileCitrix Bleed 2ransomwareAI-assisted attacksvulnerability exploitationpatch-lagagent-relevant

This weekly recap highlights multiple concurrent threats including exploitation of ShareFile vulnerabilities, ransomware campaigns leveraging the 'Citrix Bleed 2' flaw, and a rising trend of attackers using AI coding tools to accelerate exploit development. The report underscores how unpatched, previously disclosed vulnerabilities continue to be actively exploited due to delayed remediation, and how trusted software supply chains are increasingly weaponized against their own users.

Updated Jul 14, 2026

macosinfostealergatekeeper-bypassnotarization-abusenative-c++credential-theftagent-relevant

CrashStealer is a newly identified macOS information stealer written in native C++ that uses a notarized dropper to bypass Gatekeeper security checks. Unlike typical macOS stealers built with AppleScript or Objective-C wrappers, its native implementation and local password validation suggest a more sophisticated, evasion-focused development approach. The malware is designed to harvest sensitive data from compromised systems, including credentials and stored secrets.

Updated Jul 14, 2026

macOSinfostealercredential-theftkeychaincrypto-walletagent-relevant

CrashStealer is a newly identified macOS information-stealing malware that disguises itself as Apple's legitimate crash-reporting utility to gain user trust and system access. Once executed, it harvests saved credentials, macOS Keychain data, and cryptocurrency wallet files, exfiltrating them to attacker-controlled infrastructure. Its impersonation of a trusted system tool makes it likely to evade casual user scrutiny and some endpoint defenses.

Updated Jul 14, 2026

npmsupply-chaininfostealerjscramblerjavascriptmalicious-packageagent-relevant

A threat actor compromised the Jscrambler npm package and published a malicious version containing infostealer malware, which was downloaded nearly 1,500 times before detection. This represents a supply chain attack targeting developers and CI/CD pipelines that depend on the Jscrambler client-side web security tooling.

Updated Jul 14, 2026

cyberattacktaxi-industryjapaninfrastructure-shutdownincident-response

Nihon Kotsu, Japan's largest taxi operator, suffered a cyberattack that forced the company to shut down parts of its IT infrastructure. Details on the attack vector, threat actor, and data impact have not been disclosed. The incident highlights ongoing targeting of transportation and logistics companies by threat actors.

Updated Jul 14, 2026

state-sponsoredrussiafsbrouter-hygienesnmp-abusenetwork-devicescritical-infrastructureciscosmart-installcredential-theftproxy-infrastructure

Russian FSB Center 16 (aka Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, Static Tundra) is conducting a long-running, opportunistic global campaign exploiting poorly configured and vulnerable networking devices, primarily routers, using SNMP abuse and known Cisco CVEs. Targeting spans critical infrastructure sectors including communications, energy, financial services, defense industrial base, government, and healthcare. A joint advisory from CISA, NSA, FBI, and 15 international partner agencies urges organizations to harden router/SNMP configurations and disable legacy protocols.

Updated Jul 14, 2026

CISAKEVCiscoCSRFvulnerability-managementfederal-agenciesnetwork-infrastructure

CISA added CVE-2008-4128, a Cross-Site Request Forgery vulnerability in Cisco IOS, to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. Federal Civilian Executive Branch agencies must remediate this per BOD 26-04, and CISA recommends all organizations prioritize patching this vulnerability on publicly exposed assets.

Updated Jul 14, 2026

cve-2026-61498command-injectionunauthenticated-rceweb-applicationvitec-flamingoroot-privilege-escalation

A critical unauthenticated OS command injection vulnerability exists in Vitec Flamingo 4.12.2's graph generation endpoint, allowing remote attackers to execute arbitrary commands with root privileges. The flaw stems from unsanitized GET parameters being passed directly into shell execution functions, combined with insecure passwordless sudo configuration on the web server. Given the CVSS score of 9.8 and lack of authentication requirement, this is highly likely to be mass-exploited by opportunistic attackers and botnets once a public PoC emerges.

Updated Jul 14, 2026 · CVSS 9.8

gawklinuxheap-corruptioninteger-overflowdenial-of-service32-bitopen-sourceagent-relevant

A vulnerability in gawk's builtin.c (do_sub() routine) allows an integer overflow that corrupts heap metadata and objects, causing crashes on 32-bit builds of gawk version 5.4.0 and earlier. The flaw could potentially be leveraged for further exploitation beyond denial of service depending on heap layout and attacker control over input strings passed to gawk substitution functions.

Updated Jul 14, 2026 · CVSS 9.1

gawkinteger-overflowheap-corruptionmemory-corruptionlinuxgnu-utilsdenial-of-serviceagent-relevant

A critical integer overflow vulnerability in gawk's builtin.c allows attackers to trigger memory exhaustion and corrupt heap metadata with attacker-controlled bytes, affecting versions 5.4.0 and below. Given gawk's ubiquity as a core text-processing utility on Linux/Unix systems, this vulnerability poses risk to any system, script, or automated pipeline that invokes gawk for data transformation.

Updated Jul 14, 2026 · CVSS 9.1

os-command-injectionrouteriotunauthenticated-rcefastcgipublic-exploit

A critical unauthenticated OS command injection vulnerability affects the Comfast CF-WR631AX V3 router firmware up to version 2.7.0.8, exploitable remotely via the system_wl_upload_pic_file function in the webmgnt FastCGI backend. A public exploit exists, and the vendor has not responded to disclosure, leaving affected devices permanently exposed to compromise.

Updated Jul 14, 2026 · CVSS 9.8

ImageMagickheap-overflowout-of-bounds-readimage-processingdenial-of-serviceagent-relevant

ImageMagick versions prior to 7.1.2-19 contain a heap buffer over-read in the magnify operation, triggered by an unrecognized magnify:method value. Exploitation can lead to information disclosure from adjacent heap memory or crash the process, resulting in denial of service.

Updated Jul 14, 2026 · CVSS 3.3

ciscoioscsrfnetwork-devicecisa-kevweb-management-interface

Cisco IOS 12.4 contains cross-site request forgery vulnerabilities in its HTTP-based management interface, allowing remote attackers to trick authenticated administrators into executing arbitrary privileged commands. This flaw is included in CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild. Successful exploitation could lead to full device reconfiguration or compromise of network infrastructure.

Updated Jul 14, 2026

RATChina-nexusRustgRPCC2SEO-poisoningcounterfeit-installersSilver-Fox

The China-linked threat actor Silver Fox has been attributed a new Rust-based remote access trojan called MODBEACON, which uses gRPC streaming to encrypt and obfuscate its command-and-control traffic. Despite appearing as an opportunistic, low-sophistication campaign relying on SEO poisoning and trojanized installers for distribution, researchers assess the group demonstrates notable organizational and technical maturity.

Updated Jul 13, 2026