Conventional Threats Watchlist

Browse by attack type

Showing 741–760 of 817 threats, newest first

zero-day-brokerexploit-marketfraudvendor-risksupply-chaintrust-and-safetydisinformation

Krebs on Security reports that a startup soliciting zero-day vulnerabilities in popular software for large payouts is operated by individuals with histories of fraud, fake intelligence companies, and a defunct AI-based lobbying platform run under assumed identities. This raises significant vendor-trust and supply-chain risk concerns for any organization considering selling vulnerabilities to, or purchasing exploit intelligence from, this entity. There is no confirmed active exploitation tied to this report, but the operators' background suggests elevated risk of exploit misuse, data misrepresentation, or fraudulent business practices.

Updated Jul 9, 2026

residential-proxyfake-installertrojanized-softwaremalvertisingdns-abuseagent-relevant

A threat actor dubbed Lurking Lizard has been running a residential proxy business since at least August 2022 using more than 230 lookalike domains that distribute trojanized software installers, including fake 7-Zip installers. Victims who download these fake installers unknowingly turn their devices into residential proxy exit nodes, which are then resold for anonymized traffic routing, potentially including malicious or fraudulent activity.

Updated Jul 9, 2026

npmpypisupply-chaincredential-theftpayment-fraudstealer-malwaretyposquattingagent-relevant

Threat actors published malicious packages on npm and PyPI masquerading as legitimate SDKs for Paysafe, Skrill, and Neteller payment platforms. These packages deliver information-stealing malware that harvests credentials from developers and downstream application users. The campaign highlights the ongoing risk of typosquatting and impersonation attacks within open-source package registries.

Updated Jul 9, 2026

data-breachextortionhigher-educationfile-storagecredential-theft

Mount Royal University in Calgary confirmed that attackers breached its network and exfiltrated data from file storage systems before deleting it, with threat actors publicly claiming responsibility for the attack. The incident reflects an ongoing trend of threat actors targeting higher-education institutions for data theft and extortion rather than traditional ransomware encryption.

Updated Jul 9, 2026

microsoft-defenderzero-daypatch-tuesdaywindowsendpoint-security

Microsoft disclosed and patched a zero-day vulnerability in Microsoft Defender, dubbed 'RoguePlanet', following the June 2026 Patch Tuesday cycle. The vulnerability was actively exploited or publicly known prior to patch release, prompting an out-of-band advisory. Organizations relying on Defender for endpoint protection should prioritize patching to prevent detection evasion or compromise of protected hosts.

Updated Jul 9, 2026

icsotauthentication-bypassxssend-of-lifecisa-advisory

CISA disclosed two vulnerabilities in Digi International's PortServer TS and Digi One SP/SP IA/IA serial-to-network devices: an authentication bypass allowing unauthenticated access to restricted web resources, and a stored XSS flaw exploitable by authenticated administrators. These are legacy, end-of-life industrial devices used across critical manufacturing, communications, IT, and transportation sectors, with no vendor firmware fix planned for the XSS issue.

Updated Jul 9, 2026 · CVSS 8.2

ICSOTenergy-sectorinsecure-transmissioncredential-theftsession-hijackingHitachi-EnergyPROMOD-V

Hitachi Energy PROMOD V versions 1.0.10 and prior rely on insecure HTTP communication instead of HTTPS due to a lack of TLS support in the third-party Digipede grid server component. This flaw could allow an attacker with network access to intercept or manipulate data in transit, potentially leading to credential theft, session hijacking, or unauthorized access to industrial engineering workstations.

Updated Jul 9, 2026 · CVSS 7.1

xssspoofingdynamics-365customer-voicemicrosoftweb-vulnerabilityinput-validation

CVE-2026-47646 is a cross-site scripting (XSS) vulnerability in Microsoft Dynamics 365 Customer Voice that allows an unauthorized, unauthenticated attacker to inject malicious scripts and perform spoofing attacks over a network. With a CVSS score of 9.3, this flaw could enable attackers to impersonate legitimate users or interfaces, potentially harvesting credentials or session data submitted through survey forms.

Updated Jul 9, 2026 · CVSS 9.3

wordpressplugin-vulnerabilityfile-uploadrceunauthenticatedcms-security

The Blocksy Companion Pro WordPress plugin (versions before 2.1.47) contains a critical unauthenticated arbitrary file upload vulnerability in its Advanced Reviews and Custom Fonts feature, allowing attackers to achieve remote code execution without any authentication. Exploitation involves bypassing a weak extension validation check using double-extension filenames, enabling attackers to upload and execute malicious PHP web shells. Given the CVSS score of 9.8 and ease of exploitation, this vulnerability poses severe risk to any WordPress site running the affected plugin version.

Updated Jul 9, 2026 · CVSS 9.8

device-code-phishingmicrosoft-365oauth-abusecredential-theftbusiness-email-compromisesocial-engineeringagent-relevant

A phishing campaign dubbed DEBULL abuses Microsoft's legitimate device-code authentication flow to hijack Microsoft 365 accounts, using collaboration-themed lures rather than fake login pages. Because the attack leverages the real Microsoft login experience and obtains valid OAuth tokens, it bypasses many traditional phishing detections and can persist beyond password resets. The campaign was active between late June and early July 2026, as reported by ZeroBEC.

Updated Jul 8, 2026

agent-relevantchatbot-securityprivilege-escalationcloud-misconfigurationgoogle-cloudconversational-aidata-exposure

Varonis researchers discovered a critical flaw in Google Dialogflow CX that allowed an attacker with edit access to one Code Block-enabled conversational agent to hijack other Code Block-enabled agents within the same Google Cloud project. Exploitation could expose live conversation data, steal user-shared information, and enable injection of attacker-controlled bot responses, including deceptive prompts to re-enter passwords. Google has since remediated the issue, but the flaw highlights significant multi-tenancy isolation risks in managed conversational AI platforms.

Updated Jul 8, 2026 · CVSS 7.5

androidbanking-trojanmaastelegrammobile-malwarecredential-theftotp-interceptionoblivion-variant

RedWing is a newly identified Android malware-as-a-service operation, rented out via Telegram for roughly $300/month, that allows low-skill attackers to take full control of victim devices, steal banking credentials, and intercept one-time passcodes (OTPs). Discovered by Zimperium's zLabs, it is believed to be a new variant of the Oblivion malware family, lowering the barrier of entry for widespread mobile banking fraud.

Updated Jul 8, 2026

backdoorrouterfirmwareiotauthentication-bypassnetwork-infrastructure

A hidden authentication backdoor has been discovered in multiple versions of Tenda router firmware, allowing attackers to gain unauthorized administrative access to the device's web management panel. This could enable full device takeover, traffic interception, and use of the router as a pivot point into internal networks.

Updated Jul 8, 2026

china-nexusORB-networkrouter-compromiseedge-device-exploitationbotnetstate-sponsored

Chinese state-linked threat actor UAT-7810 is deploying new malware dubbed LONGLEASH to expand an Operational Relay Box (ORB) network, primarily by compromising unpatched internet-facing Ruckus routers. The ORB network is used to anonymize and relay malicious traffic, complicating attribution and enabling downstream intrusion campaigns.

Updated Jul 8, 2026

data-breachsource-code-theftthird-party-riskIT-servicesextortion

Accenture confirmed a security breach after a threat actor claimed to have stolen approximately 35 GB of source code and other internal data, subsequently offering it for sale on underground forums. As a major IT services and consulting provider, exposure of Accenture's internal source code and data poses downstream risk to its extensive client base across multiple industries.

Updated Jul 8, 2026

ICSCISA-advisorymemory-corruptionlocal-attack-vectorEDA-softwareelectronics-design-automationuse-after-freebuffer-overflow

Labcenter Proteus 9 (build 9.1_SP4_Build_42914), an electronic design automation tool used across critical infrastructure sectors, contains three high-severity memory corruption vulnerabilities including an out-of-bounds write, a stack-based buffer overflow, and a use-after-free. Successful exploitation requires local access and user interaction (e.g., opening a crafted file) but could lead to arbitrary code execution or information disclosure. No known public exploitation has been reported, and the vendor has released version 9.2 SPO to address the issues.

Updated Jul 8, 2026 · CVSS 7.8

ICSSCADAenergy-sectorbuffer-overflownginxCISA-advisorydenial-of-servicecritical-infrastructure

Hitachi Energy e-mesh EMS versions 4.1.6, 4.4.2, and 4.7.0 contain a heap-based buffer overflow vulnerability in the bundled NGINX ngx_http_rewrite_module (CVE-2026-42945), affecting NGINX v1.30.0 and below. Successful exploitation could crash the NGINX worker process (denial of service) and, under certain conditions where ASLR is disabled or bypassed, allow arbitrary code execution on the affected energy management system.

Updated Jul 8, 2026 · CVSS 8.1

wordpressrceplugin-vulnerabilityunauthenticatedwoocommercecve-2026-14345web-application-security

The WPFunnels WordPress plugin (versions up to 3.12.7) contains a critical unauthenticated RCE vulnerability caused by unsanitized handling of the 'postData' parameter, which allows attackers to inject PHP code into a log file that is later executed via include_once. With a CVSS score of 9.8, this flaw enables full server compromise on any WordPress site running the vulnerable plugin with logging enabled.

Updated Jul 8, 2026 · CVSS 9.8

traefikheader-injectionauthentication-bypassforwardauthreverse-proxyapi-gatewayagent-relevant

Traefik reverse proxy versions prior to v2.11.51, v3.6.22, and v3.7.6 fail to strip underscore-variant identity headers when using BasicAuth, DigestAuth, or ForwardAuth middlewares, allowing attackers to inject spoofed identity or authorization headers that backends normalize as legitimate. This enables authentication bypass and identity spoofing on any route protected by these middlewares, with a maximum CVSS score of 10.0 reflecting trivial exploitability and full compromise potential.

Updated Jul 8, 2026 · CVSS 10

arcgisfile-uploadunauthenticatedgisweb-application

CVE-2026-9182 is an unrestricted file upload vulnerability in ArcGIS Server that allows an unauthenticated attacker to upload arbitrary crafted files to an affected endpoint. This could lead to further compromise such as web shell deployment or remote code execution depending on server configuration and processing of uploaded files.

Updated Jul 8, 2026 · CVSS 5.3