Conventional Threats Watchlist

Browse by attack type

Showing 61–80 of 804 threats, newest first

clickfixsocial-engineeringpowershellreverse-tunnelfake-captchainitial-accessagent-relevant

Microsoft has identified a new ClickFix variant called TerminalFix that uses fake Cloudflare CAPTCHA verification prompts on compromised websites to trick users into copy-pasting and executing malicious PowerShell commands in Windows Terminal. The attack establishes reverse tunnels for persistent remote access, enabling attackers to bypass network perimeter defenses.

Updated Sep 1, 2026

deficryptocurrencyprice-oracle-manipulationflash-loancronossmart-contract-exploitblockchain

An attacker exploited a price-manipulation vulnerability in the Tectonic cryptocurrency lending platform on the Cronos blockchain, enabling fraudulent borrowing of approximately $74 million. The exploit forced validators to halt and restart the Cronos network to contain the incident, disrupting trading activity network-wide.

Updated Sep 1, 2026

CISAKEVPaperCutauthentication-bypassunsafe-reflectionprint-managementfederalvulnerability-managementBOD-26-04

CISA has added two actively exploited PaperCut NG/MF vulnerabilities to its Known Exploited Vulnerabilities catalog, one involving missing authentication for a critical function and another involving unsafe reflection. These flaws pose significant risk to organizations running PaperCut print management software, with federal agencies required to remediate under BOD 26-04.

Updated Sep 1, 2026

iaciamprivilege-escalationcloud-securitypulumiinfrastructure-as-codeagent-relevant

A critical privilege escalation vulnerability in hulumi (versions prior to v1.3.2) allows attackers with access to a documented IAM principal to abuse an overly permissive weekly integration policy. This enables creation of persistent, higher-privilege af-e2e-* roles in sandbox accounts, potentially leading to full account compromise.

Updated Sep 1, 2026 · CVSS 9.8

iam-misconfigurationoidcawsgithub-actionssupply-chaincicd-securityagent-relevant

A critical flaw in @hulumi/policies before version 1.3.2 allows attackers to craft AWS IAM condition operators (ForAnyValue:StringLike) that evade security guardrails designed to detect overly permissive GitHub Actions OIDC trust policies. This enables attackers to establish stealthy, wildcard-based trust relationships between arbitrary GitHub repositories/workflows and AWS IAM roles, potentially leading to unauthorized cross-account access.

Updated Sep 1, 2026 · CVSS 9.8

iotrouterbuffer-overflowrcetotolinkpublic-exploitunauthenticated

A critical stack-based buffer overflow vulnerability affects the TOTOLINK NR1800X router firmware, exploitable remotely via the setUploadSetting function without authentication. A public exploit exists, making this an immediate risk for internet-exposed devices.

Updated Sep 1, 2026 · CVSS 9.9

d-linkrouteriotrcebuffer-overflownetwork-deviceunauthenticatedexploit-published

A critical remote code execution vulnerability exists in D-Link DIR-825M 1.1.8 routers, caused by a stack-based buffer overflow in the LTE Module Firmware Upgrade handler (formLtefotaUpgradeFibocom). An attacker can remotely manipulate the fota_url parameter to trigger the overflow, with a public exploit already available, making this an immediate risk to exposed devices.

Updated Sep 1, 2026 · CVSS 9.9

buffer-overflowrouteriotremote-code-executionpublic-exploittendaboa-web-server

A critical, publicly disclosed vulnerability affects the Tenda HG10 router (firmware 300001138) via its Boa Web Server admin interface. The flaw allows remote, unauthenticated attackers to trigger a buffer overflow through the destNet parameter in the formIPv6Routing function, potentially leading to full device compromise. With a CVSS score of 10.0 and public exploit code available, active exploitation is highly likely.

Updated Sep 1, 2026 · CVSS 10

PaperCutCISA-KEVRCEunsafe-reflectionchained-exploitprint-managementjava

PaperCut NG/MF is affected by an unsafe reflection vulnerability that allows attackers to manipulate system configuration parameters and execute arbitrary Java bytecode under the security context of the PaperCut server process. This flaw has been added to CISA's Known Exploited Vulnerabilities catalog and can be chained with CVE-2026-81578 to achieve full remote code execution, mirroring the exploitation pattern seen in prior PaperCut attacks used for ransomware and network intrusion.

Updated Sep 1, 2026

roboticsiotroot-rcebluetoothphysical-securityunitreehumanoid-robothardware

Security researcher Olivier Laflamme disclosed two independent exploit chains achieving root remote code execution on the Unitree G1 EDU humanoid robot, tracked as CVE-2026-76639 and CVE-2026-76640. One chain requires only Bluetooth Low Energy proximity to compromise the robot's Locomotion PC, while the other exploits a network-adjacent path through the chat_go and bashrunner components, posing serious risks for research, industrial, and educational deployments of the robot.

Updated Aug 31, 2026

browser-extensioncryptocurrency-theftmalicious-extensionchromeedgewallet-stealeragent-relevant

Researchers identified 19 malicious Chrome and Edge extensions published over the past six months that steal cryptocurrency wallet secrets and drain funds. The extensions share common code and tradecraft, suggesting a coordinated campaign distributed through official browser extension stores. This poses a broad supply-chain risk to any user or organization installing these extensions.

Updated Aug 31, 2026

clickfixsocial-engineeringpowershellwindows-terminalreverse-tunnelbackdoorfake-captchainitial-accessagent-relevant

Microsoft disclosed a new ClickFix-style social engineering campaign, dubbed TerminalFix, that uses fraudulent Cloudflare CAPTCHA pages to trick users into executing malicious commands in Windows Terminal or PowerShell instead of the traditional Run dialog. Successful execution deploys a reverse-tunnel backdoor granting attackers persistent remote access to the compromised host. This shift to terminal-based execution increases the likelihood that victims run more complex, capability-rich payloads compared to earlier ClickFix variants.

Updated Aug 31, 2026

browser-extensionchrome-web-storeedgecryptocurrency-theftclickfixmalware-frameworkdata-exfiltrationagent-relevant

Multiple malicious extensions distributed through the Chrome Web Store and Microsoft Edge Add-ons store delivered a modular malware framework capable of stealing cryptocurrency, browsing history, and other sensitive data. The campaign also deployed ClickFix-style social engineering lures to trick users into executing further malicious commands, expanding the attack's reach beyond simple browser compromise.

Updated Aug 31, 2026

infostealersession-hijackingcredential-theftAI-account-abuseagent-relevantLLM-abusetoken-theft

Anthropic has warned that infostealer malware infecting user PCs is exfiltrating active Claude session tokens, allowing attackers to hijack accounts and consume victims' paid usage. This represents a growing trend of infostealers specifically targeting AI service credentials and session cookies rather than just traditional banking or email accounts.

Updated Aug 31, 2026

data-breachdata-theftaviationcustomer-dataextortion

The threat actor group FulcrumSec claims to have stolen 86 GB of data from Manchester Airports Group (MAG), including detailed customer, booking, and travel records. BleepingComputer validated at least one traveller's record from leaked samples, suggesting the breach scope exceeds what MAG initially disclosed.

Updated Aug 31, 2026

iotroutermemory-corruptionremote-code-executionpublicly-disclosedtotolink

A critical remotely exploitable memory corruption vulnerability exists in TOTOLINK A720R routers running firmware 4.1.5cu.630_B20250509, affecting the setMacFilterRules function within cstecgi.cgi. The flaw is triggered via manipulation of the 'desc' argument in MAC filtering rules and has been publicly disclosed with exploit details available, increasing the likelihood of active exploitation.

Updated Aug 31, 2026 · CVSS 9.1

wordpressauthentication-bypassprivilege-escalationplugin-vulnerabilitycms

The MyHome Core plugin for WordPress (versions up to 4.4.5) contains an authentication bypass vulnerability that allows unauthenticated attackers to hijack unconfirmed user accounts, including administrator accounts, under specific configuration conditions. Successful exploitation grants full administrative access to the WordPress site, enabling complete site takeover.

Updated Aug 31, 2026 · CVSS 9.8

wordpresswoocommerceprivilege-escalationplugin-vulnerabilityunauthenticatedweb-application-security

The Custom User Registration Fields for WooCommerce WordPress plugin (up to v2.2.3) allows unauthenticated attackers to escalate privileges to Administrator by manipulating the checkout request. The vulnerability arises from unsanitized user-controlled role data being passed directly into WordPress's role assignment function, enabling full site takeover during account registration at checkout.

Updated Aug 31, 2026 · CVSS 9.8

directory-traversalpath-traversalfile-managerrce-potentialweb-applicationagent-relevant

Cloud Commander before version 19.20.2 contains a critical directory traversal vulnerability in its REST file-operation and markdown endpoints, allowing unauthenticated or minimally privileged attackers to read, write, move, or copy files outside the configured root directory. With a CVSS score of 9.8, this flaw can lead to full system compromise, data exfiltration, or arbitrary file overwrite.

Updated Aug 31, 2026 · CVSS 9.8

agent-relevantmcpargocdunauthenticated-accessgitopsprivilege-escalationapi-token-exposure

argocd-mcp version 0.8.0 exposes its HTTP transport on all network interfaces without enforcing authentication on incoming MCP sessions, even when an ARGOCD_API_TOKEN is configured. Any attacker with network access to the listener can invoke the full MCP tool surface, leveraging the operator's stored Argo CD token to create applications, trigger syncs, and modify GitOps resources without any credentials of their own.

Updated Aug 31, 2026 · CVSS 10