Conventional Threats Watchlist

Browse by attack type

Showing 801–817 of 817 threats, newest first

open-redirectprivilege-escalationmicrosoft-365copilotagent-relevantcloud-security

CVE-2026-41106 is a critical open redirect vulnerability in Microsoft 365 Copilot that allows an unauthenticated attacker to elevate privileges over a network. Given the 9.3 CVSS score and network attack vector, this flaw could be leveraged to hijack authentication flows or session tokens tied to Copilot's integrated services.

Updated Jul 5, 2026 · CVSS 9.3

CASSSOcryptographic-flawAES-GCMIV-reuseauthentication-bypassunauthenticatedagent-relevant

Apereo CAS versions 7.3.0 before 8.0.0-RC6 use a fixed all-zero initialization vector with AES-GCM to encrypt webflow conversation state, allowing unauthenticated remote attackers to collect tokens from the login page and perform known-plaintext cryptanalysis to recover the encryption keystream. This can lead to full decryption of session state and potentially enable authentication bypass or session manipulation within enterprise SSO infrastructure.

Updated Jul 5, 2026 · CVSS 9.1

default-credentialsauthentication-bypassunauthenticated-accessself-hosted-appCVE-2026-58466rss-automationagent-relevant

AutoBangumi versions prior to 3.2.8 seed a default administrator account with publicly known credentials whenever the users table is empty, allowing any unauthenticated attacker to log in and gain full administrative control. This includes the ability to manipulate RSS feeds, downloader configuration, and all authenticated API endpoints, effectively giving attackers complete control of the deployed instance.

Updated Jul 5, 2026 · CVSS 9.8

rcecommand-injectionauthentication-bypassdockercontainer-securityagent-relevant

Dockwatch versions through 0.6.567 contain a critical unauthenticated command injection vulnerability enabling full remote host compromise. Attackers can bypass authentication via a missing exit() call after an auth redirect in loader.php, then inject arbitrary shell commands through the composePath parameter in ajax/compose.php. Given Dockwatch's typical deployment with a mounted Docker socket, successful exploitation grants attackers control over the entire container host and all managed containers.

Updated Jul 5, 2026 · CVSS 9.8

botnetresidential-proxyproxywaredevice-compromisefbi-seizurealarum-technologiesnetnut

The FBI, working with industry partners, seized hundreds of domains linked to NetNut, a residential proxy service operated by publicly-traded Israeli firm Alarum Technologies. The takedown follows security research connecting NetNut to the Popa botnet, a network of at least two million devices compromised without meaningful user consent. This represents a significant disruption to a large-scale proxyware/botnet infrastructure used to monetize unwitting victims' internet connections.

Updated Jul 4, 2026

ICSRTUcredential-exposureinsecure-permissionsschneider-electriccritical-infrastructure

Schneider Electric EasyLogic T150 and Saitel DP RTU devices contain two vulnerabilities that could allow unauthorized access to sensitive credentials and password hashes. CVE-2026-9650 allows an unauthenticated attacker with physical access to extract credentials from firmware or system files, while CVE-2026-9651 allows a privileged local attacker to read improperly protected system files containing password hashes. No public exploitation has been reported to CISA at this time.

Updated Jul 4, 2026 · CVSS 7.5

CISAKEVSharePointdeserializationactive-exploitationBOD-26-04federal-agencies

CISA added CVE-2026-45659, a deserialization of untrusted data vulnerability in Microsoft SharePoint Server, to its Known Exploited Vulnerabilities catalog due to confirmed active exploitation. Federal civilian agencies are required under BOD 26-04 to remediate this vulnerability on an expedited basis given its potential for full system compromise on publicly exposed assets. All organizations, not just federal agencies, are strongly encouraged to prioritize patching.

Updated Jul 4, 2026

containerdCRICDIkubernetescontainer-escapeprivilege-escalationcheckpoint-restoredevice-injection

A critical vulnerability in containerd's CRI implementation allows users with pod creation permissions to bypass Kubernetes resource allocation and device plugin enforcement by injecting arbitrary Container Device Interface (CDI) edits through malicious checkpoint image metadata. This can result in unauthorized access to host device nodes and mounts, potentially leading to container breakout or privilege escalation on affected nodes. Exploitation requires CDI to be enabled on the node with matching host CDI specifications for the targeted device.

Updated Jul 4, 2026 · CVSS 9.6

botnetandroidresidential-proxyad-fraudaccount-takeoverdata-scrapingiot

The Popa botnet is a large-scale Android-based malware network that has compromised millions of consumer TV boxes over the past four years, using them as unwitting relays for internet traffic. Security researchers have linked this infrastructure to NetNut, a residential proxy service operated by publicly-traded Israeli company Alarum Technologies Ltd (NASDAQ: ALAR), raising concerns about corporate involvement in facilitating malicious traffic relay networks.

Updated Jul 4, 2026

ICSsatelliteCSRFmissing-authenticationAPI-exposuredenial-of-serviceinformation-disclosure

Two high-severity vulnerabilities affect ST Engineering iDirect iQ-Series satellite terminals (Evolution iQ, 3315-Series, 9-Series) running firmware <=4.5.2.1. Successful exploitation could allow an unauthenticated attacker to retrieve sensitive device credentials or force device reboots via CSRF, potentially causing terminal impersonation or denial-of-service on satellite links. No known public exploitation has been reported to CISA at this time.

Updated Jul 4, 2026 · CVSS 8.1

ICSfirmwaresecure-bootphysical-accesssatelliteCWE-347reaction-wheel

CubeSpace CW0057 Reaction Wheel firmware versions prior to 5.0.20 fail to properly verify cryptographic signatures on firmware updates, relying only on CRC-32 integrity checks. An attacker with physical access could upload arbitrary malicious firmware without authentication, though the device remains recoverable via an independent bootloader.

Updated Jul 4, 2026 · CVSS 6.1

authentication-bypassOIDCremote-code-execution-riskCISA-KEVprivilege-escalationMFA-bypass

A critical authentication bypass vulnerability exists in SimpleHelp's OIDC authentication flow, where identity tokens are accepted without cryptographic signature verification. This allows a remote, unauthenticated attacker to forge tokens and gain fully authenticated technician-level access, potentially bypassing multi-factor authentication safeguards. The vulnerability has been added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation.

Updated Jul 4, 2026

Supply ChainPythonDeveloper Tools

Coordinated campaign publishing typosquatted Python packages to steal environment variables, SSH keys, and cloud credentials from developer workstations and CI/CD pipelines.

Updated Jul 3, 2026

Social EngineeringIdentityMFA Bypass

English-speaking group using SIM-swapping and MFA fatigue attacks to compromise enterprise identity providers via IT help desk impersonation calls.

Updated Jul 3, 2026

APTState-SponsoredCritical Infrastructure

Chinese state-sponsored group maintaining persistent access in US energy, water, and telecom networks using living-off-the-land techniques that blend with normal admin activity.

Updated Jul 3, 2026

Zero-DayVPNEdge Device

Two chained zero-days in Ivanti VPN appliances enabling unauthenticated remote code execution. Mass exploitation targeting government and defense across 12 countries.

Updated Jul 3, 2026 · CVSS 9.1

RansomwareHealthcareRaaS

Fourth-generation LockBit ransomware-as-a-service with enhanced encryption completing full-disk encryption in under four minutes. Actively targeting hospitals, municipal governments, and manufacturing.

Updated Jul 3, 2026 · CVSS 9.8