Conventional Threats Watchlist

Browse by attack type

Showing 81–100 of 804 threats, newest first

ownCloudCISA-KEVCVE-2023-49105pre-authenticationwebdavchina-nexuscritical-infrastructurenuclear-sectordata-theft

A critical pre-authentication vulnerability in ownCloud (CVE-2023-49105, CVSS 9.8) was actively exploited by a suspected Chinese-speaking threat actor to breach a nuclear research institute in the Philippines and exfiltrate sensitive records. CISA has added the flaw to its Known Exploited Vulnerabilities catalog, confirming active in-the-wild exploitation and prompting mandated remediation for federal agencies.

Updated Aug 30, 2026 · CVSS 9.8

androidprivacyencryptionechtlsmobile-securitydefensive-feature

This is not a threat but a defensive feature announcement: Google's Android 17 introduces OS-wide support for Encrypted Client Hello (ECH), preventing network providers and on-path observers from seeing which websites a device connects to. The update also includes additional protections against cellular network vulnerabilities and home network privacy risks.

Updated Aug 30, 2026

wordpressplugin-vulnerabilityauthentication-bypassrceaccount-takeovercms-security

Five critical vulnerabilities have been disclosed across popular WordPress plugins and themes—WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP—that can lead to authentication bypass, account takeover, and remote code execution. The most severe flaw, CVE-2026-76581, carries a CVSS score of 9.8 and allows attackers to bypass authentication controls entirely. These issues pose significant risk to any organization running affected WordPress installations, as exploitation could lead to full site compromise.

Updated Aug 30, 2026 · CVSS 9.8

piracyiptvlaw-enforcementcopyright-infringement

A 68-year-old individual in the U.K. was sentenced to over six years in prison for running an illegal IPTV service that generated approximately $1.3 million over three years. This is a law enforcement action against digital piracy infrastructure rather than a cybersecurity threat targeting organizations or systems.

Updated Aug 30, 2026

privacybrowser-updateemail-aliasingnot-a-vulnerability

This report describes a new privacy feature in Brave browser version 1.94 called 'Email Aliases,' which allows users to generate disposable email addresses to reduce tracking when signing up for online services. This is a legitimate product feature announcement, not a security threat, vulnerability, or malicious campaign.

Updated Aug 30, 2026

icsscadaxxetlscertificate-validationlog4netiec-60870-5-104critical-infrastructure

ASE2000 V2 Communications Test Set versions 2.25 through 2.37 contain two vulnerabilities: an XML External Entity (XXE) flaw inherited from a bundled outdated Apache log4net library, and an improper TLS certificate validation flaw affecting IEC 60870-5-104 secure communications. Successful exploitation could allow attackers to read/write arbitrary local files, trigger outbound network requests, or perform man-in-the-middle attacks to intercept and modify protected substation/grid communications.

Updated Aug 30, 2026 · CVSS 9.8

authentication-bypassjwtalgorithm-confusionapi-securityaccount-takeoverrce-adjacentagent-relevant

A critical authentication bypass exists in Omnivore's API where the Apple sign-in JWT verification logic trusts the attacker-controlled 'alg' header field, enabling a classic RS256-to-HS256 algorithm confusion attack. An attacker can forge valid authentication tokens for any Apple-linked account by signing them with Apple's public RSA key treated as an HMAC secret, resulting in full account takeover without valid credentials.

Updated Aug 30, 2026 · CVSS 9.1

authentication-bypassbroken-access-controliotrest-apiunauthenticated-rce-riskagent-relevant

rust-iot-platform contains a critical authentication bypass vulnerability in which most REST API endpoints lack authentication checks in their handler code. Unauthenticated attackers can fully manage user accounts—creating, listing, retrieving, updating, and deleting them—leading to complete account and access control compromise.

Updated Aug 30, 2026 · CVSS 9.8

shinobicctvsql-injectionhardcoded-credentialswebsocketunauthenticated-rcevideo-surveillance

Shinobi, an open-source video surveillance/NVR platform, ships with a hardcoded connection key in its child node service that allows unauthenticated attackers to authenticate via WebSocket handshake and execute arbitrary SQL queries. This grants full read/write access to user records and camera configuration, enabling account takeover and surveillance system compromise.

Updated Aug 30, 2026 · CVSS 9.8

wordpressplugin-vulnerabilityrceunauthenticatedfile-uploadweb-application-security

The Sigma Forms Pro WordPress plugin (versions up to 1.4.5) contains a critical vulnerability that allows unauthenticated attackers to achieve remote code execution by exploiting improper capability handling and MIME type validation during form submissions. Several default plugin templates ship with unrestricted file upload fields, making exploitation immediately feasible on default installs without any attacker reconnaissance or configuration changes.

Updated Aug 30, 2026 · CVSS 9.8

sql-injectionibm-concertremote-exploitdata-breachcve-2026-3627agent-relevant

IBM Concert versions 1.0.0 through 2.3.1 contain a critical SQL injection vulnerability that allows a remote, unauthenticated attacker to manipulate backend database queries. Exploitation could result in unauthorized viewing, modification, or deletion of sensitive application data. With a CVSS score of 9.1, this vulnerability poses significant risk to organizations running unpatched instances.

Updated Aug 30, 2026 · CVSS 9.1

papercutrceauthentication-bypassunauthenticated-rceprint-managementexploit-chainpatch-now

Attackers are actively chaining two vulnerabilities in PaperCut NG and MF print management software to achieve unauthenticated remote code execution. PaperCut has released an emergency patch with additional hardening after confirming exploitation in the wild. Organizations running unpatched PaperCut servers face full server compromise with no authentication required.

Updated Aug 29, 2026 · CVSS 9.8

blockchaincosmosevmdeficrypto-theftsmart-contract-vulnerabilitysupply-chain

A critical, unpatched balance-handling flaw in the shared Cosmos EVM module was actively exploited between August 20-25, 2026, to drain funds from at least six blockchains built on the Cosmos ecosystem. Cosmos Labs was reportedly aware that all chains running the vulnerable module were exposed prior to exploitation, raising concerns about disclosure timing and coordinated patching failures.

Updated Aug 29, 2026

data-extortiongovernmentdata-breachberlinstate-networkdouble-extortion

Berlin's state administrative network was compromised in August 2026, with attackers exfiltrating data and subsequently demanding an extortion payment. The Berlin government has publicly refused to pay, and forensic investigation has revealed additional data outflows from the Senate Department for Mobility, Transport, Climate Protection and Environment, suggesting a broader compromise than initially disclosed.

Updated Aug 29, 2026

wordpressplugin-vulnerabilityrcephp-object-injectionunauthenticatedweb-application-securitycms

A maximum-severity vulnerability in the GiveWP WordPress donation plugin allows unauthenticated attackers to execute arbitrary commands on the hosting server. Given GiveWP's widespread use on nonprofit and fundraising websites, this flaw exposes a large number of internet-facing servers to full compromise without requiring any credentials.

Updated Aug 29, 2026

print-managementpatch-bypassactive-exploitationrcepath-traversalauthentication-bypass

PaperCut has issued a second emergency patch after security researchers found multiple ways to bypass the initial fixes for two actively exploited vulnerabilities in PaperCut NG and MF print management software. Attackers exploiting these flaws can potentially achieve unauthorized access or remote code execution, prompting urgent re-patching for organizations still running vulnerable versions.

Updated Aug 29, 2026

data-breachhealthcareextortionshinyhuntersthird-party-riskpatient-dataPII exposure

McKesson, a major healthcare and pharmaceutical distribution company, disclosed a breach involving unauthorized access to third-party applications, with the ShinyHunters extortion group claiming theft of 284 million patient records. The incident highlights ongoing risks from third-party application compromise and large-scale extortion campaigns targeting healthcare data supply chains.

Updated Aug 29, 2026

icsotcisa-advisoryfuel-managementargument-injectionbuffer-overflowrcephplegacy-software

All-Line Equipment Company's Fuel-Boss fuel management systems (Standard, Portal, Master/Slave, and Backflush variants) running PHP 7.1.5 or earlier are vulnerable to two high-severity flaws: an argument injection vulnerability in the PHP imap_open() function and a buffer overflow in PHP-FPM's FastCGI handling. Successful exploitation could allow remote attackers to execute arbitrary OS commands or code on affected systems, posing risk to critical manufacturing, defense, emergency services, and transportation sector operators using this equipment.

Updated Aug 29, 2026 · CVSS 8.7

ICSIoTcellular-gatewayauthentication-bypassCSRFcleartext-credentialsweak-cryptoMQTTunpatchedno-vendor-fix

The Ebyte NA111-M cellular/MQTT gateway (firmware 9013-2-17) contains 13 vulnerabilities, several rated critical (CVSS 9.8), including missing authentication, client-side authentication bypass, weak cryptographic hashing, and cleartext transmission/storage of credentials including MQTT traffic. Combined, these flaws allow unauthenticated remote attackers to fully compromise the device, gaining administrative control, intercepting or replaying credentials, and disrupting availability. Ebyte has not delivered a patch despite CISA coordination attempts, leaving deployed units permanently exposed absent compensating network controls.

Updated Aug 29, 2026 · CVSS 9.8

ICSOTdenial-of-serviceCC-LinkMELSECcritical-manufacturingMitsubishi-ElectricCVE-2025-3511

Multiple Mitsubishi Electric FA products, including CC-Link IE TSN modules and MELSEC iQ-R/iQ-F series Ethernet and CPU modules, contain a denial-of-service vulnerability (CVE-2025-3511) in their Ethernet function. A remote attacker can send a specially crafted UDP packet to cause a DoS condition, communication delay, or timeout error, requiring a system reset for recovery in most cases.

Updated Aug 29, 2026 · CVSS 7.5