Conventional Threats Watchlist

Browse by attack type

Showing 761–780 of 817 threats, newest first

beyondtrustremote-accessprivileged-access-managementauthorization-bypassvendor-advisoryagent-relevant

A critical vulnerability (CVSS 9.9) in BeyondTrust Remote Support and Privileged Remote Access allows an authenticated, low-privileged attacker to bypass authorization checks and access data or resources outside their permitted scope. Because these platforms are widely used to broker privileged remote sessions, exploitation could enable lateral movement into sensitive infrastructure, including servers hosting automation and AI agent tooling.

Updated Jul 8, 2026 · CVSS 9.9

authentication-bypassprivileged-accessremote-access-softwarepre-auth-rceagent-relevant

A critical pre-authentication vulnerability in BeyondTrust Remote Support allows unauthenticated attackers to bypass access controls and gain unauthorized access, including to privileged accounts, when a specific authentication configuration is enabled. Given the 9.8 CVSS score and lack of authentication requirement, this flaw is highly likely to be weaponized quickly by opportunistic and targeted threat actors. Organizations using this remote support appliance should treat this as an urgent patching priority.

Updated Jul 8, 2026 · CVSS 9.8

path-traversaladobe-coldfusionrcecisa-kevknown-exploitedweb-server

CVE-2026-48282 is a path traversal vulnerability in Adobe ColdFusion that can lead to arbitrary code execution in the context of the current user. It has been added to CISA's Known Exploited Vulnerabilities catalog with an aggressive three-day remediation window, indicating active exploitation in the wild.

Updated Jul 8, 2026

CISA-KEVunauthenticated-rcearbitrary-file-uploadjoomla-extensionweb-applicationcms

Joomlack Page Builder, a Joomla CMS extension, contains an improper access control flaw that allows unauthenticated attackers to upload arbitrary files and achieve remote code execution. The vulnerability has been added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild, with a remediation due date of July 10, 2026.

Updated Jul 8, 2026

CISA-KEVweb-shellunauthenticated-RCECMSJoomlafile-uploadactive-exploitation

CVE-2026-48908 is an unauthenticated arbitrary file upload vulnerability in JoomShaper SP Page Builder, a popular page-building extension for Joomla CMS. Attackers can upload and execute malicious PHP files without authentication, leading to full remote code execution on affected servers. The vulnerability is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation in the wild.

Updated Jul 8, 2026 · CVSS 9.8

credential-exposurecloud-securitygovernmentawsgovclouddata-leakinsider-riskagent-relevant

A contractor for CISA maintained a public GitHub repository that exposed highly privileged AWS GovCloud credentials and internal CISA build, test, and deployment documentation. This exposure represents a severe operational security failure that could grant attackers deep access into sensitive federal cybersecurity infrastructure. The leak went unaddressed for an extended period before remediation this past weekend.

Updated Jul 7, 2026

botnetddosiotarrestlaw-enforcementthreat-actor

Canadian authorities arrested a 23-year-old Ottawa man alleged to be 'Dort,' the operator of Kimwolf, a fast-spreading IoT botnet responsible for large-scale DDoS attacks over the past six months. The suspect also allegedly conducted doxing and swatting campaigns against a journalist and a security researcher, and now faces criminal charges in both the U.S. and Canada. While the operator's arrest may disrupt operations, the underlying botnet infrastructure and malware may persist or be repurposed by other actors.

Updated Jul 7, 2026

AI-abusesocial-engineeringaccount-takeoverchatbot-exploitationagent-relevantprompt-injectionidentity-theft

Attackers discovered and shared a method on Telegram to manipulate Meta's AI-powered support assistant into resetting passwords for high-profile Instagram accounts without proper identity verification. This led to the compromise and defacement of accounts belonging to the Obama White House and a senior U.S. Space Force official with pro-Iranian propaganda. The incident highlights how conversational AI agents deployed for customer support can be socially engineered into bypassing security controls.

Updated Jul 7, 2026

giteadockerauthentication-bypassheader-spoofingdevopsci-cdagent-relevantsource-code-managementself-hosted-git

Threat actors are actively probing internet-facing Gitea Docker deployments to exploit CVE-2026-20896, a critical authentication bypass flaw disclosed just 13 days prior. The vulnerability allows unauthenticated attackers to spoof the X-WEBAUTH-USER header and gain elevated privileges, potentially leading to full repository compromise.

Updated Jul 7, 2026 · CVSS 9.8

kvmhypervisor-escapelinux-kerneluse-after-freevirtualizationcloud-infrastructureagent-relevant

A 16-year-old use-after-free vulnerability in the Linux KVM hypervisor's shared shadow MMU code allows a malicious guest VM to corrupt host kernel memory on both Intel and AMD x86 systems. Tracked as CVE-2026-53359 and dubbed 'Januscape,' the flaw currently has a public proof-of-concept that crashes the host, while the researcher claims a working, unreleased exploit exists that could achieve full guest-to-host escape.

Updated Jul 7, 2026 · CVSS 8.8

irannation-statec2-frameworkmoisisraelgovernmentit-sectorcheck-point-research

A threat cluster linked to Iran's Ministry of Intelligence and Security (MOIS) has been observed using a previously undocumented modular command-and-control framework called Cavern (Cav3rn) to target Israeli IT providers and government organizations. Check Point Research attributes the activity to a state-sponsored espionage campaign aimed at establishing persistent access within high-value networks. The framework's modular design suggests ongoing development and long-term operational use by the threat actor.

Updated Jul 7, 2026

piracylaw-enforcementstreamingarresttakedown

Vietnamese authorities arrested seven individuals suspected of operating HiAnime, a large-scale anime piracy streaming platform, which was shut down in June. This is a law enforcement action against copyright infringement infrastructure rather than a cyberattack targeting organizations or individuals.

Updated Jul 7, 2026

vishingteams-abusesocial-engineeringinitial-accessratremote-access-trojanhelp-desk-impersonationagent-relevant

Threat actors are impersonating corporate IT support staff over Microsoft Teams voice calls to socially engineer employees into installing the EtherRAT remote access trojan. Once installed, the malware grants attackers initial access to corporate networks, potentially enabling lateral movement, credential theft, and further compromise. This campaign leverages trust in internal communication tools rather than exploiting a software vulnerability.

Updated Jul 7, 2026

phishingcredential-theftbrand-impersonationgoogle-accountssocial-engineeringrecruitment-scam

A large-scale phishing campaign impersonates over 30 well-known brands, including Adobe, Netflix, Coca-Cola, and OpenAI, using fake job interview lures to steal Google account credentials from marketing professionals. The attackers leverage trusted brand names and recruitment pretexts to bypass victim skepticism and harvest credentials likely for account takeover, further phishing, or resale.

Updated Jul 7, 2026

icsotxz-utilsliblzmarace-conditiondenial-of-servicecritical-manufacturingbr-industrial-automation

A high-severity race condition vulnerability (CVE-2025-31115) in the XZ Utils liblzma multithreaded decoder affects multiple B&R Industrial Automation GmbH HMI/panel products, potentially causing crashes or memory corruption. The flaw stems from improper handling of invalid input in the lzma_stream_decoder_mt function, and has been patched in XZ Utils 5.8.1 with corresponding firmware updates from B&R.

Updated Jul 7, 2026 · CVSS 7.5

credential-leakcloud-securitygovernmentgithub-exposureinsider-riskawsagent-relevant

A contractor for CISA intentionally published AWS GovCloud access keys and a large set of other agency secrets to a public GitHub account, prompting congressional inquiries into the incident. CISA is currently working to contain the exposure and rotate or invalidate the leaked credentials, but the scope and duration of exposure remain unclear.

Updated Jul 6, 2026

bulletproof-hostingrussiadisinformationlaw-enforcement-actioninfrastructure-seizurenation-stateEU-sanctions

Dutch authorities arrested two co-owners of hosting companies that had taken over the technical infrastructure of Stark Industries Solutions, an ISP sanctioned by the EU for enabling Russian cyberattacks, influence operations, and disinformation campaigns. The operation resulted in the seizure of roughly 800 servers used as bulletproof hosting infrastructure supporting state-linked malicious cyber activity across the EU.

Updated Jul 6, 2026

npmsupply-chainnorth-koreatyposquattingdeveloper-targetingcredential-theftagent-relevant

North Korea-linked threat actors published malicious npm packages ('rollup-packages-polyfill-core' and 'rollup-runtime-polyfill-core') that impersonate the legitimate 'rollup-plugin-polyfill-node' project, replicating its metadata to deceive developers. These packages are designed to enable remote access and exfiltrate developer secrets, continuing a pattern of North Korean supply-chain attacks against the JavaScript/npm ecosystem.

Updated Jul 6, 2026

malwareransomwarephishingmodular-frameworkcredential-theftlateral-movementCrownXagent-relevant

Researchers have identified Avalon, a previously undocumented modular malware framework distributed via a multi-stage phishing chain designed to evade traditional security controls. The framework integrates credential harvesting, lateral movement, remote access, backup/recovery disruption, and ransomware deployment (CrownX) into a single unified toolkit, making it a versatile end-to-end intrusion and extortion platform.

Updated Jul 6, 2026

linuxkernelprivilege-escalationandroidepollagent-relevant

A newly disclosed Linux kernel vulnerability dubbed 'Bad Epoll' (CVE-2026-46242) allows an unprivileged local user to escalate privileges to root, affecting Linux desktops, servers, and Android devices. A patch has already been released, but unpatched systems remain fully exploitable by any local user or process with code execution.

Updated Jul 6, 2026 · CVSS 7.8