Conventional Threats Watchlist

Browse by attack type

Showing 781–800 of 817 threats, newest first

not-a-security-threatmodel-performanceai-product-news

This article reports user dissatisfaction with the relaunch of 'Claude Fable,' a model reported to underperform relative to its original release. This is a product quality/performance issue, not a security vulnerability, breach, or malicious campaign.

Updated Jul 6, 2026

flipper-zerofirmwareopen-sourcehardware-toolcommunity-development

This item is a product/business update reporting that Flipper Devices will continue developing Flipper Zero firmware with a smaller internal team and increased reliance on community contributions. It is not a disclosed vulnerability, exploit, or active threat campaign, but a governance and development-model change for a widely used pentesting/hardware hacking tool.

Updated Jul 6, 2026

ICSCISA-advisorystoragehardcoded-credentialscommand-injectionsql-injectionxssunauthenticated-RCEroot-accesscritical-infrastructure

StoneFly Storage Concentrator (SC) and its Virtual Machine variant contain five critical/medium vulnerabilities including hardcoded credentials, two unauthenticated OS command injection flaws leading to root-level remote code execution, an unauthenticated SQL injection exposing session tokens and password hashes, and a reflected XSS. Combined, these flaws allow attackers to fully compromise storage infrastructure without authentication, potentially affecting Defense Industrial Base, Energy, Financial Services, Healthcare, and IT sector organizations worldwide.

Updated Jul 6, 2026 · CVSS 10

ICSSCADAXXEinformation-disclosuredata-centerschneider-electricCWE-611

A medium-severity XML External Entity (XXE) vulnerability affects Schneider Electric EcoStruxure IT Data Center Expert versions 9.1.1 and prior, allowing an authenticated attacker to disclose server-side file contents via crafted XML payloads to SOAP service endpoints. Schneider Electric has released version 9.1.2 to remediate the issue, and no known public exploitation has been reported.

Updated Jul 6, 2026 · CVSS 6.5

sql-injectioncve-2026-4321unpatchedend-of-lifeweb-applicationraeradestekz

A critical SQL injection vulnerability has been identified in Destekz, a product from Raera (Ankara Web Design and Digital Advertising Agency), with a CVSS score of 9.8. The vendor has confirmed the product is no longer supported, meaning no patch will be released, leaving all deployments permanently vulnerable to exploitation.

Updated Jul 6, 2026 · CVSS 9.8

linuxprint-spoolerprivilege-escalationrceincomplete-patchhplipcve-2026-14544agent-relevant

CVE-2026-14544 is an incomplete fix for the previously patched CVE-2026-8631, leaving an integer overflow in HPLIP's hpcups print-processing path exploitable via specially crafted print jobs. A remote attacker able to submit print data can trigger memory corruption leading to privilege escalation or arbitrary code execution on the host. With a CVSS score of 9.8, this represents a critical, low-complexity threat to any Linux system with HPLIP installed.

Updated Jul 6, 2026 · CVSS 9.8

wordpresswoocommerceplugin-vulnerabilityarbitrary-file-deletionpath-traversalunauthenticatedrce-potential

The Printcart Web to Print Product Designer plugin for WooCommerce (versions up to 2.5.2) contains a critical vulnerability allowing unauthenticated attackers to delete arbitrary files on the server. Combined with a bypassable nonce mechanism, this flaw could enable deletion of critical files such as wp-config.php, potentially leading to remote code execution and full site compromise.

Updated Jul 6, 2026 · CVSS 9.1

patch-tuesdaymicrosoftwindowsvulnerability-managementrcepublic-exploitagent-relevant

Microsoft released fixes for nearly 200 vulnerabilities in June 2026, its largest Patch Tuesday to date, with roughly 34 rated critical. Public exploit code exists for at least three of the flaws, creating urgent risk of active exploitation against unpatched Windows systems.

Updated Jul 5, 2026

ransomwareransomware-as-a-serviceaffiliate-recruitmentattributioncybercrimedouble-extortion

The Gentlemen is a rapidly growing ransomware-as-a-service (RaaS) operation that has become the second most active ransomware gang by victim count, driven by an aggressive affiliate recruitment strategy offering 90% of ransom proceeds. Investigative reporting by Krebs on Security examines OSINT clues pointing to the real-world identity of the group's administrator, highlighting the operational and personal risks facing RaaS operators as attribution efforts intensify.

Updated Jul 5, 2026

scattered-spidersocial-engineeringlegal-actioncybercrime-groupcritical-infrastructuretransportationidentity-thefthelp-desk-fraud

Two members of the Scattered Spider cybercrime group pleaded guilty on the first day of their UK trial for a August 2024 cyberattack that crippled Transport for London (TfL). This marks a significant law enforcement outcome against a group known for sophisticated social engineering, SIM-swapping, and help-desk impersonation attacks targeting large enterprises and critical infrastructure.

Updated Jul 5, 2026

embedded-systemsfirmwareiotsupply-chainunpatchedmemory-corruptionfat-exfat

Security firm runZero disclosed seven unpatched vulnerabilities in FatFs, a widely embedded filesystem library used to read and write FAT/exFAT formats on USB drives and SD cards. Because FatFs is bundled into firmware across security cameras, drones, industrial controllers, and hardware crypto wallets, these flaws could enable attackers with physical or logical access to removable media to trigger memory corruption or logic errors in a huge range of downstream devices.

Updated Jul 5, 2026

north-koreasupply-chainnpmpackagistgolangchrome-extensioncontagious-interviewmaintainer-account-compromiseagent-relevant

North Korean threat actors tied to the Contagious Interview campaign have published 108 malicious packages and browser extensions across npm, Packagist, Go, and the Chrome Web Store in an operation dubbed PolinRider. The campaign leverages compromised maintainer accounts to distribute malware through widely trusted software registries, posing an ongoing supply-chain risk as new packages continue to surface.

Updated Jul 5, 2026

extortiondata-theftransom-negotiationgovernment-targetcryptocurrencyno-encryption

A U.S. government entity paid approximately $1 million in extortion payments to a group calling itself Kairos to prevent the leak of stolen data. Analysis of a leaked negotiation chat and blockchain payment trail suggests Kairos may operate purely as a data-theft extortion outfit without deploying ransomware encryption, distinguishing it from traditional ransomware gangs. This case highlights the growing prevalence of extortion-only threat actors targeting public sector organizations.

Updated Jul 5, 2026

phishing-as-a-serviceMicrosoft 365credential-theftsession-token-theftAiTMagent-relevant

ARToken is a newly identified phishing-as-a-service (PhaaS) platform operating as an affiliate of the EvilTokens phishing ecosystem, offering attackers a turnkey toolkit to compromise Microsoft 365 accounts. The platform enables adversary-in-the-middle (AiTM) style credential and session token theft at scale, lowering the barrier to entry for large-scale enterprise account compromise.

Updated Jul 5, 2026

botnetresidential-proxyandroid-malwareiottakedownmobile-security

A joint law enforcement and industry operation involving Google disrupted NetNut, a residential proxy network built on approximately 2 million compromised Android devices, including smart TVs and streaming boxes. The infrastructure allowed threat actors and paying customers to route traffic through unwitting victims' devices, enabling anonymized malicious activity such as credential stuffing, ad fraud, and scraping. The takedown cuts off access to this proxy pool but does not necessarily remediate infections on affected devices.

Updated Jul 5, 2026

ICSmedical-devicesDICOMpath-traversaldenial-of-servicehealthcareCISA-advisory

OFFIS DCMTK Toolkit versions <=3.7.0 contain five vulnerabilities including a critical path traversal flaw (CVSS 9.8) allowing malicious DICOM servers to write arbitrary files on clients, plus multiple unauthenticated memory-exhaustion and type-confusion bugs that can crash storescp and worklist server processes. These affect healthcare imaging infrastructure worldwide and could enable file write outside intended directories, cross-department data disclosure, or denial of service against clinical DICOM services. No public exploitation has been reported to CISA as of the advisory date.

Updated Jul 5, 2026 · CVSS 9.8

icsotmitsubishi-electric7-zippath-traversalbuffer-overflowdenial-of-servicecritical-manufacturingcisa-advisory

Mitsubishi Electric MELSOFT Update Manager SW1DND-UDM-M versions 1.000A through 1.014Q contain four vulnerabilities in its bundled 7-Zip component, including a heap-based buffer overflow, NULL pointer dereference, link following, and path traversal issue. Successful exploitation requires local access and user interaction to decompress a specially crafted archive, and could lead to denial-of-service, data tampering, or arbitrary code execution. No public exploitation has been observed, and the vulnerabilities are not remotely exploitable.

Updated Jul 5, 2026 · CVSS 8.8

ICSIoThardcoded-credentialsCVE-2026-13768CVE-2026-55726CVE-2026-54477smart-agriculturecloud-misconfigurationazure-blob-storage

Gardyn IoT Hub devices (Home and Studio firmware, Cloud API) contain three vulnerabilities including a critical hard-coded Azure IoT Hub owner key that allows unauthenticated attackers to access connection info and execute arbitrary commands on any connected device. Additional flaws expose device logs via a publicly listable Azure Blob Storage container and allow clickjacking/XSS on the admin panel due to missing security headers. No public exploitation has been reported, and Gardyn has patched server-side infrastructure and recommends firmware/app updates.

Updated Jul 5, 2026 · CVSS 10

ssrfazurecloudprivilege-escalationopenaiagent-relevantapi-abuse

CVE-2026-45499 is a critical server-side request forgery (SSRF) vulnerability in Azure OpenAI that allows an authorized attacker to escalate privileges remotely over a network. With a CVSS score of 9.9, exploitation could grant attackers access beyond their intended scope within Azure's OpenAI service infrastructure. This poses significant risk to organizations relying on Azure OpenAI for production workloads, including internal tooling and AI-driven applications.

Updated Jul 5, 2026 · CVSS 9.9