Other Conventional Threats

Other conventional threat types

Showing 181–200 of 390 threats, newest first

vmwarevspheresession-hijackinginformation-disclosuredellvsiunauthenticated-rcevirtualization-security

Dell Virtual Storage Integrator (VSI) for VMware vSphere Client versions prior to 10.11.1.0 contain a critical sensitive information disclosure vulnerability that allows unauthenticated remote attackers to steal active session credentials. Exploitation enables full impersonation of authenticated users, including administrators, within vSphere environments.

Updated Aug 8, 2026 · CVSS 9.1

credential-theftdata-extortioncloud-securitysnowflakelegal-actionagent-relevant

Connor Riley Moucka, a Canadian national linked to the 2024 Snowflake extortion campaign, pleaded guilty to computer fraud and conspiracy charges tied to breaches of over 165 organizations, including the theft of call and text metadata for more than 100 million AT&T customers. The campaign exploited stolen credentials and lack of MFA on customer Snowflake accounts rather than a vulnerability in Snowflake itself, enabling mass data theft and subsequent extortion.

Updated Aug 7, 2026

ciscosd-wanios-xenetwork-infrastructurevulnerabilitypatch-tuesdayrceagent-relevant

Cisco disclosed 12 vulnerabilities affecting Catalyst SD-WAN Software and IOS XE Software, including three critical flaws with CVSS scores of 9.8, discovered during an internal security review. These issues affect SD-WAN devices regardless of configuration and IOS XE devices running in autonomous or controller mode, posing significant risk to enterprise network infrastructure.

Updated Aug 7, 2026 · CVSS 9.8

extortionransomwarefinancial-sectordata-theftUNC6671BlackFile

A wave of cyberattacks against hedge funds, private-equity firms, and other financial organizations has been attributed to UNC6671, an extortion group linked to the BlackFile threat actors. The campaign appears focused on data theft and extortion rather than pure ransomware encryption, targeting high-value financial sector victims. Details on initial access vectors and specific TTPs remain limited in current reporting.

Updated Aug 7, 2026

not-a-threatproduct-updateopenaichatgptinformational

This article reports a routine product update from OpenAI, announcing new ChatGPT model versions (GPT-5.6 Sol and GPT-5.6 Luna) being rolled out to Plus, Pro, and Free tier users. There is no vulnerability, exploit, malware, or attack activity described in this content.

Updated Aug 7, 2026

ICSSCADAABBMongoDBthird-party-componentdenial-of-servicevulnerability-disclosurecritical-infrastructure

ABB Ability Zenon's IIoT services bundle an outdated MongoDB 4.2 instance affected by 13 known MongoDB vulnerabilities, including memory disclosure, authentication/authorization bypass, denial-of-service, log injection, and certificate validation flaws. Successful exploitation could allow attackers to bypass security controls, crash services, execute unauthorized actions, or expose sensitive data on affected industrial control system deployments worldwide.

Updated Aug 7, 2026 · CVSS 7.8

ICSOTvulnerabilityhardcoded-credentialsCWE-327cameraCISA-advisory

Johnson Controls TL280 camera devices running firmware versions below 5.63 contain a vulnerability involving use of a broken or risky cryptographic algorithm, tracked as CVE-2026-27871, which stems from hardcoded credentials embedded in the firmware. Successful exploitation could allow an attacker to access sensitive information on the device, though the attack requires high complexity and privileges. Johnson Controls has released firmware 5.63 to remediate the issue and recommends network segmentation and credential rotation as mitigations.

Updated Aug 7, 2026 · CVSS 4.1

ICS-medicalDICOMheap-overflowout-of-bounds-writeRCEhealthcareCISA-advisory

A heap out-of-bounds write vulnerability (CVE-2026-17264) affects Medixant RadiAnt DICOM Viewer versions 2025.2 and earlier, triggered by opening a maliciously crafted DICOM file with malformed JPEG-compressed pixel data. Successful exploitation could crash the application or potentially allow remote code execution, though built-in exploit mitigations (CFG, DEP, ASLR) reduce practical exploitability. No known public exploitation has been reported to date.

Updated Aug 7, 2026 · CVSS 4.3

unauthenticated-accessdatabase-destructiondata-integritysql-injectionsocket.ioiotsatellite-systemssupply-chain-riskagent-relevant

CVE-2026-53984 is a critical unauthenticated vulnerability in Ground Station software prior to version 0.6.0, allowing any network peer to destroy or tamper with the entire SQLite database via an exposed Socket.IO event handler. Attackers can wipe operational data or inject fabricated orbital-source URLs to redirect the ground station to attacker-controlled servers, enabling data manipulation and potential downstream compromise.

Updated Aug 7, 2026 · CVSS 9.1

agent-relevantllm-abusecredential-theftdiscounted-api-accessgray-marketclaudeanthropicmitmprompt-interception

Poison Claude is an underground service advertising discounted, illegitimate access to Anthropic's Claude models (including Opus 4.8/4.7/4.6 and Sonnet 4.6), likely by reselling stolen or abused API credentials/accounts. The operator sits in the middle of every session, meaning all customer prompts, outputs, and potentially embedded secrets pass through an untrusted third party. This represents a significant confidentiality and data-exfiltration risk for any individual or organization using the service, including those integrating it into automated or agentic workflows.

Updated Aug 6, 2026

scamsocial-engineeringgen-ai-abusefraudromance-scaminvestment-scamgambling-scamimpersonationcambodiaopenaichatgpt

OpenAI disrupted a Cambodia-based scam network operating out of Poipet that used coordinated ChatGPT accounts to generate content for investment fraud, romance scams, illegal gambling promotion, and law enforcement impersonation schemes. The operation leveraged generative AI to scale social engineering content creation and craft convincing fraudulent communications targeting victims across multiple scam categories. OpenAI banned the associated accounts as part of its abuse enforcement efforts.

Updated Aug 6, 2026

SQL injectionpost-exploitationOracle databasenetwork intrusioninitial accessdatabase security

Threat actors exploited a SQL injection vulnerability to deploy the khunt post-exploitation toolkit directly within an Oracle database, using it as a foothold to breach the broader corporate network. This attack highlights database servers as an underexploited but high-value initial access vector, especially when they hold elevated privileges or trusted network connectivity.

Updated Aug 6, 2026

cloud-securitydata-breachextortioncredential-theftsnowflakesaas-compromise

A Canadian national pleaded guilty to participating in a large-scale data theft and extortion campaign targeting Snowflake cloud storage customers, affecting at least 165 organizations. The attackers used stolen or weak credentials—lacking multi-factor authentication—to access customer Snowflake instances, exfiltrate sensitive data, and extort victims for millions of dollars.

Updated Aug 6, 2026

boringproxysshprivilege-escalationtunnel-abusecredential-theftrceself-hosted-infrastructureagent-relevant

A critical vulnerability in boringproxy (through 0.10.0) allows low-privileged authenticated users to inject arbitrary SSH public keys into the server's authorized_keys file via a newline injection flaw in the tunnel creation endpoint's domain parameter. Successful exploitation grants attackers persistent SSH shell access to the proxy server and enables theft of cleartext credentials, tunnel private keys, and TLS certificates stored in the local database. Given the CVSS score of 9.9, this represents a full compromise path from limited tunnel-creation privileges to complete host takeover.

Updated Aug 6, 2026 · CVSS 9.9

apache-nifibroken-access-controlauthorization-bypassrest-apiagent-relevantdata-pipeline

Apache NiFi versions 2.0.0 through 2.10.0 contain a broken access control vulnerability in the Asset management REST API tied to Parameter Contexts. An attacker with write access to one Parameter Context can delete Assets belonging to a different Parameter Context they are not authorized for, by manipulating the supplied identifiers. This affects deployments that rely on differentiated authorization across Parameter Contexts as a security boundary.

Updated Aug 6, 2026 · CVSS 9.1

apache-nifibroken-access-controlprivilege-escalationcode-executiondata-pipelinerag-pipelineagent-relevant

Apache NiFi versions 1.10.0 through 2.10.0 contain a broken authorization flaw in the Parameter Context update REST API that fails to enforce component-level authorization checks. An authenticated user with only Parameter Context modification rights can alter parameter values affecting components they are not authorized to manage, potentially triggering code execution via scripting-based parameters during automatic validation. Organizations should upgrade to NiFi 2.11.0 immediately, especially those using component-level authorization policies.

Updated Aug 6, 2026 · CVSS 9.8

ICSautomotive-securitybluetoothhard-coded-credentialsIoTCISA-advisory

Acrisure KARR BT and DR-100 anti-theft systems use a shared, hard-coded Bluetooth authentication key across all affected devices, allowing an attacker within Bluetooth range to send unauthorized commands to a vehicle. This could enable unauthorized door unlocking or engine immobilization. Acrisure has released a firmware update (July 20, 2026) to address the flaw, and no public exploitation has been reported.

Updated Aug 5, 2026 · CVSS 8.1

ICSmedical-devicedata-integrityhealthcareCWE-353CVSS-8.4local-attack-vectorforensic-data-tampering

A vulnerability in multiple Thermo Fisher Applied Biosystems Genetic Analyzer software products allows tampering with .fsa/.hid output files due to missing integrity checks, which could result in falsified DNA test results. The flaw requires local access and no user interaction, affecting eight product lines including several that are end-of-life with no patch available.

Updated Aug 5, 2026 · CVSS 8.4

authentication-bypasscmsweb-applicationunauthenticated-accessplugin-vulnerability

MaxSite CMS versions 109.5 and earlier contain a critical authentication bypass in the AJAX dispatcher, allowing unauthenticated attackers to reach admin-gated plugin endpoints. Exploitation requires only a crafted X-Requested-With header and a base64-encoded path pointing to any *-ajax.php file, enabling actions like poll manipulation and potentially more severe abuse depending on the targeted plugin.

Updated Aug 5, 2026 · CVSS 9.8

apachetomcatencryption-bypasscisa-kevcluster-securityagent-relevant

Apache Tomcat contains a vulnerability that allows attackers to bypass the EncryptInterceptor, a component intended to encrypt sensitive data transmitted between nodes in a Tomcat cluster. This CVE has been added to CISA's Known Exploited Vulnerabilities catalog with a short remediation window, indicating active exploitation in the wild. Organizations running clustered Tomcat deployments should prioritize patching immediately.

Updated Aug 5, 2026