Other Conventional Threats

Everything on the watchlist that doesn't fit one category: misconfigurations, data breaches, novel techniques, and advisories that span several classes.

Other conventional threat types

Showing 1–20 of 385 threats, newest first

data-breachhealthcareregulatory-fineGDPRprivacy

France's data protection authority (CNIL) fined Hôpital privé de la Loire €500,000 for failing to adequately protect the personal data of 727,000 patients and their relatives. The breach exposed sensitive health-related information, highlighting inadequate security controls and non-compliance with GDPR data protection obligations.

Updated Sep 4, 2026

ICSOTprivilege-escalationlocal-attackinstaller-vulnerabilityCWE-250OPC-UA

A local privilege escalation vulnerability exists in the OPC UA LocalDiscoveryServer (LDS) installer prior to version 1.04.420, allowing an attacker with local keyboard/display access during installation to hijack a high-privilege console window and execute arbitrary commands. Exploitation requires local access and user interaction, limiting remote attack potential, but could lead to full system compromise on affected industrial control hosts.

Updated Sep 4, 2026 · CVSS 4.6

ICSSCADAcritical-infrastructureprivilege-escalationdefault-configurationIgnitionCWE-276

Inductive Automation Ignition versions 8.1.53 and earlier ship with a blank 'Create Project Role(s)' setting, allowing any authenticated user capable of executing gateway scripts to create projects without proper authorization. This default misconfiguration affects widely deployed industrial control system software across Critical Manufacturing, Energy, and IT sectors worldwide, with no known public exploitation reported at this time.

Updated Sep 4, 2026 · CVSS 8.8

ICSOTdenial-of-serviceCIP-protocolRockwell-AutomationEtherNet-IPindustrial-control-systemsCISA-advisory

A high-severity denial-of-service vulnerability (CVE-2025-10478) affects all versions of the Rockwell Automation 1756-ENBT ControlLogix EtherNet/IP bridge module. An attacker can send a crafted CIP packet to crash the module, requiring a manual restart to restore functionality, potentially disrupting industrial communications in critical infrastructure environments.

Updated Sep 4, 2026 · CVSS 7.5

browsermobileandroidfirefoxpatch-available

A vulnerability described only as 'Other issue' has been identified in Firefox Focus for Android, carrying a CVSS score of 9.8, indicating potential for severe impact if exploited. The issue has been resolved in Firefox 155, and the vagueness of the public description suggests Mozilla has withheld technical details pending broader patch adoption.

Updated Sep 4, 2026 · CVSS 9.8

ai-securitydefensive-toolingindustry-newscyber-ai-modelsfairwind-programagent-relevant

Google, Anthropic, and OpenAI announced new cybersecurity-focused AI models and structured access programs, including Google's Gemini 3.8 Flash Cyber and the Fairwind Program, which grants early access to advanced defensive AI capabilities for high-priority defenders such as governments, healthcare, and telecom providers. This is an industry development announcement rather than an active threat, but it signals shifts in the AI-driven security tooling landscape that organizations running AI agents should track.

Updated Sep 3, 2026

ICSOTdenial-of-serviceRockwell-AutomationLogixCIP-protocolcritical-manufacturingmemory-corruption

A high-severity denial-of-service vulnerability affects multiple Rockwell Automation Logix Platform controllers due to improper input length validation during CIP message processing. Successful exploitation causes a major nonrecoverable fault (MNRF), requiring a physical power cycle to restore operations. No public exploitation has been observed at this time.

Updated Sep 3, 2026 · CVSS 7.5

known-exploited-vulnerabilitiesCISA-KEVpatch-managementsql-injectioncommand-injectionssrfauthentication-bypassrequest-smugglingagent-relevantLLM-gateway

CISA added seven vulnerabilities to its Known Exploited Vulnerabilities catalog based on confirmed active exploitation, spanning products including Sangoma Switchvox, Starlette, Kestra, BerriAI LiteLLM, JFrog Artifactory, and SonicWall SMA1000 appliances. These flaws include SQL injection, OS command injection, SSRF, authentication bypass, and HTTP request smuggling, posing significant risk to organizations with these products exposed to the internet. Federal agencies must remediate per BOD 26-04, and CISA urges all organizations to prioritize patching.

Updated Sep 3, 2026

guidancecrisis-communicationscritical-infrastructureOT-securityCISAincident-responseadvisory

CISA, the FBI, and international partners released joint guidance on best practices for service providers to communicate clearly and effectively during IT and OT outages, whether caused by cyberattacks, human error, equipment failure, or natural hazards. The guidance stresses clarity, accountability, and transparency to reduce public panic, preserve trust, and support containment and recovery efforts during disruptions. This is a policy/best-practice advisory rather than a description of an active threat, exploit, or vulnerability.

Updated Sep 3, 2026

kubernetesmulti-clusterrceroot-privilege-escalationipsecconfig-injectionagent-relevant

A critical vulnerability in Submariner's cert-auth mode allows a malicious cluster to inject arbitrary ipsec.conf directives via an unsanitized CableName field in a Custom Resource Definition. This enables remote code execution as root on gateway nodes through leftupdown hook abuse, fully compromising the multi-cluster networking layer.

Updated Sep 3, 2026 · CVSS 9.1

data-breachidentity-theftPII-exposuredark-webidentity-verificationKYCthird-party-risk

A newly launched dark web identity theft service is selling digital scans of over 153 million U.S. and Canadian drivers licenses, apparently sourced from a breach or insider leak at a Louisiana-based identity verification company. The FBI's New Orleans field office has opened a formal inquiry into the origin of the leaked images. This represents a massive PII exposure event impacting identity verification supply chains widely used for KYC and onboarding processes.

Updated Sep 2, 2026

financial-fraudpayment-systemsbrazilbanking-malwarethreat-actorlatin-america

Breeze Comet is a financially motivated threat actor targeting Brazilian financial services, retail, and e-commerce organizations since 2024, specializing in manipulating payment systems and banking software to execute fraudulent transfers. Google Threat Intelligence Group and Mandiant have tracked hundreds of fraudulent transactions attributed to this group, indicating a mature and persistent operation against Brazil's financial ecosystem.

Updated Sep 2, 2026

data-breachhealthcarePIIPHI

Aesto LLC, operating as Aesto Health, disclosed a data breach impacting more than 9.5 million individuals. The specific attack vector, threat actor, and full scope of compromised data have not been detailed in the initial disclosure. This incident represents a significant healthcare data exposure event given the scale of affected patients.

Updated Sep 2, 2026

icsotscadadenial-of-servicerockwell-automationcritical-manufacturingcisa-advisory

A high-severity denial of service vulnerability affects multiple Rockwell Automation Logix controller families, including ControlLogix, CompactLogix, GuardLogix, and their variants. Exploitation via corrupt crafted data can trigger a major nonrecoverable fault (MNRF), requiring physical recovery actions such as program downloads or stage 2 resets. No public exploitation has been reported to date, and vendor firmware fixes are available.

Updated Sep 2, 2026 · CVSS 7.5

ICSOTindustrial-control-systemsrockwell-automationfactorytalk-historianremote-code-executiondenial-of-serviceCISA-advisorycritical-infrastructure

CISA disclosed two vulnerabilities affecting Rockwell Automation Historian ME (FactoryTalk Historian Machine Edition) Series B 5.202 and Series C 7.101. The more severe flaw (CVE-2025-12768, CVSS 8.0) allows a low-privileged authenticated attacker to achieve remote code execution via an out-of-bounds write, while the second (CVE-2026-12661, CVSS 4.5) enables a network-adjacent authenticated attacker to crash the device through a stack-based buffer overflow. No public exploitation has been reported at this time.

Updated Sep 2, 2026 · CVSS 8

ICSOTdenial-of-serviceindustrial-control-systemsrockwell-automationCIP-protocolCVE-2026-9621CVE-2026-9622CVE-2026-9624CVE-2026-9625

Rockwell Automation RSLinx Classic versions up to 4.50 contain four vulnerabilities (integer overflow/underflow and buffer overflow conditions) exploitable via crafted CIP packets, allowing remote unauthenticated attackers to crash the RSLinx Classic service. Successful exploitation causes a denial-of-service condition requiring service restart, potentially disrupting industrial communications in critical manufacturing environments. No public exploitation has been reported at this time.

Updated Sep 2, 2026 · CVSS 8.6

kubernetespolicy-bypassprivilege-escalationcontainer-securityadmission-controlleragent-relevant

A logic flaw in Kyverno's policy exception handling (v1.9.0–v1.12.7) allows attackers to bypass enforce-mode security policies by crafting resource names that match a less restrictive PolicyException. This can be exploited to circumvent critical controls such as hostPath volume restrictions, potentially enabling container breakout or node compromise.

Updated Sep 2, 2026 · CVSS 9

insider-threatdprkfraudulent-employmentsocial-engineeringsanctions-evasionidentity-fraud

North Korean threat actors are expanding their long-running fraudulent IT worker employment scheme into new sectors, including healthcare and sales/marketing roles. This insider threat operation uses stolen or fabricated identities to secure remote employment, generating revenue for the DPRK regime while creating potential access and data exposure risks for employers.

Updated Sep 1, 2026

outageavailabilityexchange-onlinemicrosoft365authentication-failureemail-delivery

Microsoft Exchange Online experienced a widespread service disruption causing authentication failures, email delays, and delivery failures for customers. This is an availability incident rather than a malicious attack, but it can disrupt business email operations and any downstream services relying on Exchange authentication or mail flow.

Updated Sep 1, 2026

deficryptocurrencyprice-oracle-manipulationflash-loancronossmart-contract-exploitblockchain

An attacker exploited a price-manipulation vulnerability in the Tectonic cryptocurrency lending platform on the Cronos blockchain, enabling fraudulent borrowing of approximately $74 million. The exploit forced validators to halt and restart the Cronos network to contain the incident, disrupting trading activity network-wide.

Updated Sep 1, 2026