Conventional Threats Watchlist

Browse by attack type

Showing 141–160 of 804 threats, newest first

iransanctionscritical-infrastructurestate-sponsoredtreasurygeopolitical

The U.S. Department of the Treasury has imposed new sanctions on Iranian cyber actors linked to breaches of critical infrastructure, as part of a broader economic pressure campaign against Iran. This is a policy and enforcement action rather than a newly disclosed technical vulnerability, though it signals continued Iranian state-sponsored targeting of critical infrastructure sectors.

Updated Aug 26, 2026

npmphishingsupply-chainfake-captchacloudflare-impersonationagent-relevant

Threat actors are abusing npm and its mirror services to host malicious HTML pages that impersonate Cloudflare CAPTCHA verification screens. Visitors who interact with these fake pages are redirected to attacker-controlled sites, likely for further phishing, malware delivery, or credential theft. The abuse leverages the inherent trust and reachability of npm's infrastructure to evade detection and blocklisting.

Updated Aug 26, 2026

data-breachPIISSN-exposuremedical-datamuseum-sectorthird-party-risk

The Los Angeles County Museum of Art (LACMA) disclosed a data breach from the prior year that exposed sensitive personal information, including Social Security numbers and medical data, belonging to customers and employees. Details on the initial attack vector and threat actor attribution have not been publicly confirmed at this time.

Updated Aug 26, 2026

CISAKEVGiteacode-injectionactive-exploitationagent-relevantself-hosted-gitRCE

CISA added CVE-2026-60004, a code injection vulnerability in Gitea, to its Known Exploited Vulnerabilities catalog based on confirmed active exploitation. Federal agencies are required under BOD 26-04 to remediate this vulnerability on a prioritized basis, and CISA urges all organizations to do the same given the risk of total asset compromise.

Updated Aug 26, 2026

ICSIoTsmart-homecredential-exposureCWE-522vulnerability-disclosure

Rently Smart Home versions 20.1.0 and earlier contain a vulnerability that insufficiently protects credentials, allowing an attacker to retrieve PINs, including the Master PIN, and override standard user permissions. Rently has released a patch as of late June 2026, and no known public exploitation has been reported.

Updated Aug 26, 2026 · CVSS 8.1

ICSIoTgatewayauthentication-bypassCSRFcleartext-credentialsMQTTunpatchedcritical-infrastructure

The Ebyte NE2-D11 gateway (Firmware FW-9167-0-11) contains eleven distinct vulnerabilities including missing authentication, client-side authentication bypass, cleartext credential and MQTT traffic transmission, CSRF, clickjacking, and missing authorization checks. Several flaws are rated CVSS 9.8, allowing an unauthenticated remote attacker to fully compromise device confidentiality, integrity, and availability. Ebyte has not released a patch or responded to CISA coordination requests, leaving affected deployments in critical manufacturing and energy sectors exposed with no vendor remediation timeline.

Updated Aug 26, 2026 · CVSS 9.8

nokogirilibxml2use-after-freerubysupply-chainxmldtdxincludeagent-relevant

Nokogiri versions before 1.15.6 and 1.16.x before 1.16.2 bundle a vulnerable version of libxml2 affected by CVE-2024-25062, a use-after-free in the xmlTextReader module. Applications using Nokogiri::XML::Reader with DTD validation and XInclude expansion enabled on untrusted XML input can trigger memory corruption, potentially leading to crashes or code execution.

Updated Aug 26, 2026 · CVSS 9.8

nokogirirubylibxml2libxsltxml-parsingdenial-of-servicememory-disclosurercesupply-chainagent-relevant

Nokogiri versions before 1.13.2 for CRuby ship vulnerable vendored copies of libxml2 2.9.12 and libxslt 1.1.34, exposing applications to denial-of-service, memory disclosure, and potential remote code execution when processing untrusted XML/XSL input. This is a widely-used Ruby gem for XML/HTML parsing, meaning the vulnerability propagates transitively into any application, service, or pipeline that depends on it.

Updated Aug 26, 2026 · CVSS 9.8

unrestricted-file-uploadweb-shellrcesoftware-repositorysupply-chain-riskagent-relevant

CVE-2026-16286 is a critical unrestricted file upload vulnerability in TRtek's Software Repository Management product, allowing unauthenticated attackers to upload malicious web shells to the underlying web server. Successful exploitation grants remote code execution, giving attackers full control over the affected host. Given the product's role as a software repository, this flaw poses supply-chain risk to any downstream systems, including AI agent pipelines, that pull artifacts from a compromised instance.

Updated Aug 26, 2026 · CVSS 9.8

wordpressplugin-vulnerabilityprivilege-escalationunauthenticatedcms-security

The Total Donations plugin for WordPress (versions up to 2.0.5) contains a critical privilege escalation vulnerability that allows unauthenticated attackers to gain administrator-level access. Given the CVSS score of 9.8, this flaw is trivially exploitable and could lead to full site takeover.

Updated Aug 26, 2026 · CVSS 9.8

gitpythonpythonsupply-chainrcegit-config-injectionagent-relevantci-cddependency-risk

GitPython versions before 3.1.59 mishandle multi-line git-config values during write operations, allowing crafted config entries with embedded newlines to be corrupted into live directives such as core.hooksPath. This enables an attacker who can influence a repository's config file to achieve arbitrary code execution the next time any unrelated GitPython write operation touches that config, with a critical CVSS score of 9.8.

Updated Aug 26, 2026 · CVSS 9.8

giteacode-injectiongit-hooksrcerepository-write-accesscisa-kevagent-relevantci-cdsupply-chain-risk

Gitea, a widely deployed self-hosted Git service, contains a code injection vulnerability that lets an attacker with repository write access plant a malicious Git hook via the diffpatch API endpoint, resulting in arbitrary shell command execution as the Gitea service account. CISA has added this to its Known Exploited Vulnerabilities catalog with a short remediation window, indicating active exploitation in the wild.

Updated Aug 26, 2026

weekly-recapsupply-chaincredential-leakplc-securitygitlabstripeexposed-servicesagent-relevant

This is a weekly aggregated security recap covering multiple loosely-related incidents, including AI-assisted attacks against industrial PLC systems, GitLab-related compromises, and leaked Stripe API keys. The report is high-level and lacks technical depth on specific CVEs, exploit chains, or IOCs, functioning primarily as an industry news digest rather than a single actionable threat profile.

Updated Aug 25, 2026

malwaregamingseo-poisoningsocial-engineeringcredential-theftmalvertising

Threat actors are distributing the Weedhack malware family through fake Minecraft client websites that closely mimic legitimate gaming projects, using SEO poisoning to drive traffic. McAfee Labs has blocked over 6,300 access attempts to these malicious sites, indicating an active and sustained campaign targeting gamers, particularly those seeking cheat clients or modified game builds.

Updated Aug 25, 2026

ai-coding-toolsopen-source-riskdependency-managementremediation-debtsupply-chainagent-relevant

This is not a discrete attack but an industry advisory piece highlighting how AI coding assistants are rapidly increasing the volume of open-source dependencies introduced into codebases, outpacing security teams' ability to review and remediate vulnerabilities. The resulting backlog of unpatched or unreviewed packages creates a growing attack surface and increases organizational risk of supply-chain compromise.

Updated Aug 25, 2026

legalregulatoryprivacydata-protectionchildren-privacyCOPPAnon-security-incident

The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated entities resolving allegations that the platform violated the Children's Online Privacy Protection Act (COPPA) by unlawfully collecting personal data from children under 13 without parental consent. This is a legal and regulatory enforcement action, not a cyberattack, vulnerability disclosure, or malware campaign.

Updated Aug 25, 2026

wordpressauthentication-bypasssamlplugin-vulnerabilityprivilege-escalationweb-security

Attackers are actively exploiting two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress, allowing forgery of SAML responses to gain unauthorized administrator access. Sites running vulnerable versions of the plugin are at immediate risk of full site takeover.

Updated Aug 25, 2026

NAT bypassrouter vulnerabilityunpatchedresidential gatewayport forwardingbroadband ISPIoT exposurenetwork security

An unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers allows remote, unauthenticated attackers to create arbitrary port-forwarding rules, bypassing NAT protections and exposing internal network devices directly to the internet. The flaw affects devices deployed by multiple U.S. broadband providers, putting a large base of residential and small-office networks at risk of direct exposure of internal systems such as NAS devices, cameras, and smart home hubs.

Updated Aug 25, 2026

oracleweblogichttp-serverknown-exploited-vulnerabilityCISAaccess-controlagent-relevant

CISA has added CVE-2026-21962, an improper access control vulnerability affecting Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in, to its Known Exploited Vulnerabilities (KEV) catalog based on confirmed active exploitation. Federal civilian agencies are required under BOD 26-04 to remediate this vulnerability on a priority basis, and CISA urges all organizations to do the same given the active exploitation in the wild.

Updated Aug 25, 2026

network-deviceauthorization-bypasssyslogremote-exploitedge-deviceDrayTek

Multiple DrayTek VigorSwitch models are affected by a set of unauthorized operation vulnerabilities in syslog-related functions caused by missing authorization checks. A remote, unauthenticated attacker can send crafted requests to modify device configuration, restart services, alter startup configuration, or clear logs, potentially leading to persistent network manipulation, denial of service, or evidence destruction.

Updated Aug 25, 2026 · CVSS 9.1