Conventional Threats Watchlist

Browse by attack type

Showing 721–740 of 804 threats, newest first

ICSOTPLCarbitrary-file-writeremote-code-executionpath-traversalcritical-infrastructureend-of-life-software

OpenPLC v3's legacy web UI program-upload workflow allows an authenticated user to write arbitrary files anywhere on the filesystem due to unsanitized handling of the prog_file parameter. This flaw can be escalated to full native code execution as the OpenPLC runtime user by planting a malicious C++ source file that gets auto-compiled during normal program build operations, posing a severe risk to industrial control environments in Critical Manufacturing, Energy, Transportation, and Water/Wastewater sectors.

Updated Jul 10, 2026 · CVSS 9.9

ICSSCADAschneider-electricpath-traversalcrlf-injectionlog-injectionauthentication-bypassdenial-of-serviceindustrial-control-systemsCISA-advisory

Schneider Electric PowerChute Serial Shutdown versions 1.4 and earlier contain seven distinct vulnerabilities spanning path traversal, CRLF injection, weak authentication throttling, uncontrolled resource consumption, and sensitive information logging. Successful exploitation could allow attackers to overwrite critical files, forge log data, exhaust system resources, or expose sensitive information, though no public exploitation has been reported. Schneider Electric has released version 1.5 to remediate all identified issues.

Updated Jul 10, 2026 · CVSS 6.1

rceunauthenticatedwebuiterminal-apiagent-relevantpty-hijackcritical-infrastructure-exposure

Hermes WebUI versions before 0.51.788 expose an embedded terminal API that lacks authentication, allowing remote attackers to open a PTY session and execute arbitrary shell commands with only four HTTP requests. Given the CVSS score of 9.8 and the trivial exploitation path, this vulnerability poses a severe risk to any internet-facing or internally exposed Hermes deployment.

Updated Jul 10, 2026 · CVSS 9.8

authentication-bypassssrfapi-key-theftoauth-abuseagent-relevantllm-provider-hijackcloud-metadata-exposurewebui-vulnerability

A critical authentication bypass in Hermes WebUI (versions before 0.51.307) allows unauthenticated attackers to spoof local-origin IP restrictions using a forged X-Forwarded-For header, gaining access to onboarding endpoints intended only for local administrators. This enables server-side request forgery against internal infrastructure, hijacking of LLM provider configurations and API keys, and abuse of OAuth device-code flows to mint persistent access tokens. Given the CVSS score of 9.1, this vulnerability poses severe risk to any deployment exposing Hermes WebUI to untrusted networks.

Updated Jul 10, 2026 · CVSS 9.1

moveitpath-traversalfile-uploadvulnerabilityprogress-software

A path equivalence vulnerability has been identified in Progress MOVEit Transfer's File Upload modules, affecting versions before 2025.0.8 and 2025.1.0 before 2025.1.4. The flaw carries a low CVSS score of 3.5, indicating limited exploitability or impact compared to prior MOVEit vulnerabilities, but it warrants patching given the product's history as a target for mass exploitation.

Updated Jul 10, 2026 · CVSS 3.5

opensshuse-after-freeclient-sidesshmemory-corruptionagent-relevant

CVE-2026-60002 is a use-after-free vulnerability in OpenSSH clients prior to version 10.4, triggered when a malicious or compromised server changes its host key during a key re-exchange. Exploitation could lead to client-side memory corruption, potentially enabling denial of service or code execution on systems initiating SSH connections.

Updated Jul 10, 2026 · CVSS 7.7

account-takeoverauthentication-bypasspassword-recoveryesriarcgisgisweb-application

CVE-2026-13020 is a weak password recovery mechanism vulnerability in Esri Portal for ArcGIS (versions 12.1 and earlier) that allows a remote, unauthenticated attacker to hijack a user's account by manipulating the forgotten-password flow. Organizations running ArcGIS Enterprise on Windows, Linux, or Kubernetes are at risk of unauthorized account access without prior credentials.

Updated Jul 10, 2026 · CVSS 8.1

zero-day-brokerexploit-marketfraudvendor-risksupply-chaintrust-and-safetydisinformation

Krebs on Security reports that a startup soliciting zero-day vulnerabilities in popular software for large payouts is operated by individuals with histories of fraud, fake intelligence companies, and a defunct AI-based lobbying platform run under assumed identities. This raises significant vendor-trust and supply-chain risk concerns for any organization considering selling vulnerabilities to, or purchasing exploit intelligence from, this entity. There is no confirmed active exploitation tied to this report, but the operators' background suggests elevated risk of exploit misuse, data misrepresentation, or fraudulent business practices.

Updated Jul 9, 2026

residential-proxyfake-installertrojanized-softwaremalvertisingdns-abuseagent-relevant

A threat actor dubbed Lurking Lizard has been running a residential proxy business since at least August 2022 using more than 230 lookalike domains that distribute trojanized software installers, including fake 7-Zip installers. Victims who download these fake installers unknowingly turn their devices into residential proxy exit nodes, which are then resold for anonymized traffic routing, potentially including malicious or fraudulent activity.

Updated Jul 9, 2026

npmpypisupply-chaincredential-theftpayment-fraudstealer-malwaretyposquattingagent-relevant

Threat actors published malicious packages on npm and PyPI masquerading as legitimate SDKs for Paysafe, Skrill, and Neteller payment platforms. These packages deliver information-stealing malware that harvests credentials from developers and downstream application users. The campaign highlights the ongoing risk of typosquatting and impersonation attacks within open-source package registries.

Updated Jul 9, 2026

data-breachextortionhigher-educationfile-storagecredential-theft

Mount Royal University in Calgary confirmed that attackers breached its network and exfiltrated data from file storage systems before deleting it, with threat actors publicly claiming responsibility for the attack. The incident reflects an ongoing trend of threat actors targeting higher-education institutions for data theft and extortion rather than traditional ransomware encryption.

Updated Jul 9, 2026

microsoft-defenderzero-daypatch-tuesdaywindowsendpoint-security

Microsoft disclosed and patched a zero-day vulnerability in Microsoft Defender, dubbed 'RoguePlanet', following the June 2026 Patch Tuesday cycle. The vulnerability was actively exploited or publicly known prior to patch release, prompting an out-of-band advisory. Organizations relying on Defender for endpoint protection should prioritize patching to prevent detection evasion or compromise of protected hosts.

Updated Jul 9, 2026

icsotauthentication-bypassxssend-of-lifecisa-advisory

CISA disclosed two vulnerabilities in Digi International's PortServer TS and Digi One SP/SP IA/IA serial-to-network devices: an authentication bypass allowing unauthenticated access to restricted web resources, and a stored XSS flaw exploitable by authenticated administrators. These are legacy, end-of-life industrial devices used across critical manufacturing, communications, IT, and transportation sectors, with no vendor firmware fix planned for the XSS issue.

Updated Jul 9, 2026 · CVSS 8.2

ICSOTenergy-sectorinsecure-transmissioncredential-theftsession-hijackingHitachi-EnergyPROMOD-V

Hitachi Energy PROMOD V versions 1.0.10 and prior rely on insecure HTTP communication instead of HTTPS due to a lack of TLS support in the third-party Digipede grid server component. This flaw could allow an attacker with network access to intercept or manipulate data in transit, potentially leading to credential theft, session hijacking, or unauthorized access to industrial engineering workstations.

Updated Jul 9, 2026 · CVSS 7.1

xssspoofingdynamics-365customer-voicemicrosoftweb-vulnerabilityinput-validation

CVE-2026-47646 is a cross-site scripting (XSS) vulnerability in Microsoft Dynamics 365 Customer Voice that allows an unauthorized, unauthenticated attacker to inject malicious scripts and perform spoofing attacks over a network. With a CVSS score of 9.3, this flaw could enable attackers to impersonate legitimate users or interfaces, potentially harvesting credentials or session data submitted through survey forms.

Updated Jul 9, 2026 · CVSS 9.3

wordpressplugin-vulnerabilityfile-uploadrceunauthenticatedcms-security

The Blocksy Companion Pro WordPress plugin (versions before 2.1.47) contains a critical unauthenticated arbitrary file upload vulnerability in its Advanced Reviews and Custom Fonts feature, allowing attackers to achieve remote code execution without any authentication. Exploitation involves bypassing a weak extension validation check using double-extension filenames, enabling attackers to upload and execute malicious PHP web shells. Given the CVSS score of 9.8 and ease of exploitation, this vulnerability poses severe risk to any WordPress site running the affected plugin version.

Updated Jul 9, 2026 · CVSS 9.8

device-code-phishingmicrosoft-365oauth-abusecredential-theftbusiness-email-compromisesocial-engineeringagent-relevant

A phishing campaign dubbed DEBULL abuses Microsoft's legitimate device-code authentication flow to hijack Microsoft 365 accounts, using collaboration-themed lures rather than fake login pages. Because the attack leverages the real Microsoft login experience and obtains valid OAuth tokens, it bypasses many traditional phishing detections and can persist beyond password resets. The campaign was active between late June and early July 2026, as reported by ZeroBEC.

Updated Jul 8, 2026

agent-relevantchatbot-securityprivilege-escalationcloud-misconfigurationgoogle-cloudconversational-aidata-exposure

Varonis researchers discovered a critical flaw in Google Dialogflow CX that allowed an attacker with edit access to one Code Block-enabled conversational agent to hijack other Code Block-enabled agents within the same Google Cloud project. Exploitation could expose live conversation data, steal user-shared information, and enable injection of attacker-controlled bot responses, including deceptive prompts to re-enter passwords. Google has since remediated the issue, but the flaw highlights significant multi-tenancy isolation risks in managed conversational AI platforms.

Updated Jul 8, 2026 · CVSS 7.5

androidbanking-trojanmaastelegrammobile-malwarecredential-theftotp-interceptionoblivion-variant

RedWing is a newly identified Android malware-as-a-service operation, rented out via Telegram for roughly $300/month, that allows low-skill attackers to take full control of victim devices, steal banking credentials, and intercept one-time passcodes (OTPs). Discovered by Zimperium's zLabs, it is believed to be a new variant of the Oblivion malware family, lowering the barrier of entry for widespread mobile banking fraud.

Updated Jul 8, 2026

backdoorrouterfirmwareiotauthentication-bypassnetwork-infrastructure

A hidden authentication backdoor has been discovered in multiple versions of Tenda router firmware, allowing attackers to gain unauthorized administrative access to the device's web management panel. This could enable full device takeover, traffic interception, and use of the router as a pivot point into internal networks.

Updated Jul 8, 2026