Conventional Threats Watchlist

Browse by attack type

Showing 701–720 of 804 threats, newest first

sharefileprogress-softwarestorage-zone-controllerfile-transferactive-exploitationvendor-advisoryenterprise-storage

Progress Software has urgently instructed ShareFile customers to shut down Windows servers hosting Storage Zone Controllers in response to a credible external security threat. The company has proactively disabled access to affected accounts while investigating with internal and external security teams, though no CVE or technical exploit details have been publicly disclosed yet. This mirrors past Progress Software incidents (e.g., MOVEit) where file-transfer products were mass-exploited via zero-days.

Updated Jul 11, 2026

data-breachtelecomlaw-enforcementinvestigationnetherlands

Dutch police report strong indications that Dutch hackers were behind a February breach at telecommunications provider Odido. Details on the attack vector, data exfiltrated, and threat actor identity remain limited at this stage of the investigation.

Updated Jul 11, 2026

ryukransomwarelegal-actioncybercrimelaw-enforcement

An Armenian national has pleaded guilty in U.S. federal court to participating in Ryuk ransomware attacks against American companies, facing up to 15 years in prison. This is a legal/law enforcement development rather than a new active threat campaign, though it underscores the continued prosecution of Ryuk-affiliated actors.

Updated Jul 11, 2026

firmwarebootloaderu-bootembedded-systemspersistencesupply-chainagent-relevant

Six newly disclosed vulnerabilities in the widely used U-Boot bootloader could allow attackers with local or physical access to execute malicious code during the boot process. Exploitation could bypass secure boot protections and enable stealthy, persistent firmware-level malware that survives OS reinstalls and standard remediation. The flaws pose a significant risk to embedded devices, IoT systems, and edge hardware that rely on U-Boot for initialization.

Updated Jul 11, 2026

CISAKEVAdobeColdFusionpath-traversalactive-exploitationfederal-agenciesBOD-26-04

CISA has added CVE-2026-48282, a path traversal vulnerability in Adobe ColdFusion, to its Known Exploited Vulnerabilities catalog based on confirmed active exploitation in the wild. Federal civilian agencies must remediate per BOD 26-04, and CISA urges all organizations to prioritize patching this flaw due to its demonstrated attractiveness to threat actors.

Updated Jul 11, 2026

CISAKEVfile-uploadweb-applicationCMSpluginJoomlaactive-exploitationBOD-26-04

CISA has added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog: an unrestricted file upload flaw in iCagenda (CVE-2026-48939) and a similar flaw in Balbooa Forms (CVE-2026-56291). Both vulnerabilities allow attackers to upload dangerous file types, potentially leading to remote code execution on affected web servers.

Updated Jul 11, 2026

wordpressfile-uploadrceunauthenticatedplugin-vulnerabilityweb-application

The Instant Appointment plugin for WordPress (versions up to 1.2) contains a critical arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files, potentially leading to remote code execution. Given the CVSS score of 9.8 and lack of authentication requirement, this vulnerability is highly likely to be targeted by automated exploitation once public details are available.

Updated Jul 11, 2026 · CVSS 9.8

open-webuipyodidesandbox-escapecsrfprivilege-escalationself-hosted-llmagent-relevantragllm-tool-use

Open WebUI versions prior to 0.10.0 execute client-side Python via Pyodide inside a same-origin web worker, which lacks proper isolation from the host page's authenticated session. A malicious stored chat payload can leverage pyodide.http.pyfetch or JS-exposed fetch/XMLHttpRequest APIs to make authenticated same-origin requests when a victim runs the code, enabling access to admin-only endpoints and server-side tool execution. This effectively turns a chat message into a stored XSRF/RCE primitive against self-hosted AI deployments.

Updated Jul 11, 2026 · CVSS 7.3

moveitfile-transferinjectiondata-exposuremanaged-file-transfer

A vulnerability in Progress MOVEit Transfer's Custom Reports module allows improper neutralization of special elements in data query logic, potentially enabling unauthorized data access or manipulation. This affects versions before 2025.0.7 and 2025.1.0 through 2025.1.3, and is reminiscent of prior MOVEit vulnerabilities that were exploited at scale for mass data theft.

Updated Jul 11, 2026 · CVSS 6.4

sql-injectionapi-gatewayibmunauthenticatedapi-connectagent-relevant

IBM API Connect versions 10.0.8.0-10.0.8.9 and 12.1.0.0-12.1.0.3 contain an unauthenticated SQL injection vulnerability in the password reset functionality, rated critical with a CVSS score of 9.1. An attacker can exploit this remotely without credentials to access, modify, or exfiltrate backend database contents.

Updated Jul 11, 2026 · CVSS 9.1

default-credentialsapi-securityunauthorized-accessagent-relevant

IBM API Connect versions 12.1.0.0 through 12.1.0.3 ship with default credentials that remain active until an administrator manually enforces a password change. Attackers aware of these default credentials can gain unauthorized access to the API management platform before remediation occurs, potentially compromising API gateways, backend integrations, and associated secrets.

Updated Jul 11, 2026 · CVSS 8.1

cvecisa-kevfile-uploadrceweb-applicationwordpress-pluginunauthenticated

iCagenda, a WordPress event management plugin, contains an unrestricted file upload vulnerability in its file attachment feature that allows attackers to upload malicious PHP files. This can lead to full remote code execution on the underlying web server. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild.

Updated Jul 11, 2026

CISA-KEVunauthenticated-RCEfile-uploadplugin-vulnerabilityweb-applicationCMSJoomlaWordPresspatch-priority

Balbooa Forms, a form-builder component/plugin, contains an unrestricted file upload vulnerability allowing unauthenticated attackers to upload malicious executable files and achieve remote code execution. The flaw has been added to CISA's Known Exploited Vulnerabilities catalog with a compressed three-day remediation window, indicating active exploitation in the wild.

Updated Jul 11, 2026

npmsupply-chainpackage-managerinstall-scripts2faagent-relevantdependency-securitynodejs

GitHub has released npm version 12, which disables automatic execution of package install scripts by default and deprecates granular access tokens (GATs) that could be used to bypass two-factor authentication. This is a defensive supply-chain security improvement aimed at reducing the risk of malicious packages executing arbitrary code during installation, a common vector in npm supply-chain attacks.

Updated Jul 10, 2026

wiperdestructive-malwarefake-ransomwarespywarewindowsbackdoormicrosoft-research

Microsoft has identified GigaWiper, a modular Windows backdoor that combines three legacy destructive tools into a single operator-controlled framework. The malware offers command-selectable payloads including full disk wiping, Windows drive overwriting, and fake ransomware that encrypts files without retaining decryption keys, making recovery impossible even if a ransom is paid.

Updated Jul 10, 2026

githubreconnaissanceoauth-abuseaccount-compromisesupply-chain-reconapi-abuseagent-relevant

Datadog Security Labs identified multiple overlapping campaigns systematically enumerating corporate GitHub organizations, repositories, and user accounts via the GitHub API. Operators use dormant 'ghost' accounts and compromised OAuth tokens or personal access tokens to blend in with legitimate traffic while conducting reconnaissance, likely as a precursor to supply-chain or targeted intrusion operations.

Updated Jul 10, 2026

vishingvoice-phishingdevice-code-phishingMFA-abuseSharePointdata-extortionidentity-attacksocial-engineeringcloud-securityagent-relevant

A newly identified data-extortion group called Helix is targeting organizations' SharePoint environments using identity-focused attack techniques, including voice phishing (vishing), device code phishing, and MFA abuse. The group's approach bypasses traditional malware-based detection by exploiting human trust and authentication weaknesses to gain access and exfiltrate sensitive data for extortion purposes.

Updated Jul 10, 2026

npmsupply-chaincryptocurrencywallet-stealergithub-compromiseagent-relevant

Attackers compromised the GitHub repository of Injective Labs' SDK project and published a malicious version of the package to npm. The trojanized package harvested cryptocurrency wallet private keys and mnemonic seed phrases from developers and downstream applications that installed it.

Updated Jul 10, 2026

linuxopen-sourceinsider-threatdistributionrepository-securityagent-relevant

A contributor to the OpenMandriva Linux distribution reportedly attempted to sabotage the project following an internal dispute among maintainers. The distribution's team detected and responded to the incident, though specifics on the exact method and scope of the sabotage attempt remain limited in the initial reporting.

Updated Jul 10, 2026

ICSSCADAhard-coded-credentialsSNMPcritical-infrastructureenergy-sectorprotection-relayunauthenticated-access

Schneider Electric's Easergy MiCOM Px40 Series protection relays contain hard-coded credentials (CWE-798) exposed via the SNMP protocol, allowing an unauthenticated remote attacker to access basic device identification information. The vulnerability affects a wide range of firmware versions across nearly all Px40 relay models used in medium, high, and extra high voltage protection applications worldwide.

Updated Jul 10, 2026 · CVSS 5.3