Other Conventional Threats

Other conventional threat types

Showing 201–220 of 390 threats, newest first

authentication-bypasscrmprivilege-escalationunauthenticated-rce-pathweb-applicationpre-authagent-relevant

Krayin CRM 2.2.4 contains a critical missing authentication vulnerability that allows unauthenticated attackers to overwrite the primary administrator account by exploiting a flaw in the installer middleware bypass logic. Successful exploitation grants full administrative access to all CRM data, including customer records, credentials, and any integrated API keys or tokens.

Updated Aug 4, 2026 · CVSS 9.8

rceeval-injectionsql-injectionhealthcareopenemrweb-applicationprivilege-escalation

A critical remote code execution vulnerability exists in OpenEMR through 8.2.0, allowing authenticated administrators to inject PHP payloads into the categories database table via SQL manipulation. The payload is later executed through an unsanitized eval() call in the CategoryTree component, which can be triggered by unauthenticated or low-privilege pages, resulting in full command execution as the web server user.

Updated Aug 4, 2026 · CVSS 9.1

command-injectionrouteriotrceopenvpnunauthenticatedpublic-exploit

A critical command injection vulnerability exists in the ovpn-client.so plugin of GL.iNet GL-MT3000 routers (up to firmware 4.4.5), reachable via the /cgi-bin/glc endpoint. An attacker can remotely inject OS commands through the Hostname parameter of the get_recommend_config function, potentially achieving full device compromise. The exploit has been publicly disclosed, increasing the likelihood of active exploitation.

Updated Aug 4, 2026 · CVSS 9.8

chromebrowser-securitypatch-managementvulnerability-disclosuregoogle

Google released three Chrome updates (versions 149, 150, and 151) fixing a cumulative total of 1,442 security bugs, far exceeding the combined total of the previous 23 releases. This represents a significant spike in disclosed vulnerabilities, largely attributed to internal discovery efforts rather than active exploitation reports.

Updated Aug 3, 2026

browser-securitychromeextensionsdefensive-featurenew-tab-hijacking

Google is developing a Chrome security feature to block policy-installed extensions from hijacking the New Tab page or overriding the default search engine. This is a defensive enhancement rather than an active exploit, aimed at curbing a common malicious/adware extension technique often used to redirect traffic and harvest ad revenue or credentials.

Updated Aug 3, 2026

cryptocurrencyhardware-walletrng-flawkey-managementbitcoin-theftsupply-chain

A flawed random number generator in COLDCARD hardware wallet firmware produced predictable or low-entropy seed phrases, enabling attackers to reconstruct private keys and drain wallets. The flaw is believed responsible for the theft of approximately $88.6 million in Bitcoin from thousands of affected wallets.

Updated Aug 3, 2026

not-a-threatai-industry-newsproduct-announcement

This article is a product news item about OpenAI's unreleased 'Astra' model, reported to have solved several long-standing math and theoretical computer science problems internally. It contains no information about a vulnerability, exploit, malware, or attack campaign and does not constitute a cybersecurity threat.

Updated Aug 3, 2026

authentication-bypassaccount-takeoverscimidentity-managementbetter-authssosupply-chainagent-relevant

A critical authorization bypass in the @better-auth/scim plugin allows an authenticated user to mint a SCIM token that collides with an existing SSO/SAML/OIDC/OAuth provider namespace, granting full read/write/delete access over unrelated user accounts and sessions. This enables account takeover, unauthorized profile/email rewriting, and mass deprovisioning across the identity system. Given the 9.9 CVSS score and low attack complexity, this is highly exploitable in any deployment using SCIM provisioning alongside social/SSO logins.

Updated Aug 3, 2026 · CVSS 9.9

cryptocurrencyhardware-walletweak-rngfirmware-vulnerabilitybitcoin-theftsupply-chain

A March 2021 firmware integration error in Coinkite's Coldcard hardware wallet caused seed generation to rely on a deterministic software pseudorandom number generator (PRNG) instead of proper entropy sources, producing predictable private keys. Attackers exploited this weakness to systematically drain 1,196 Bitcoin addresses, stealing 1,082.65 BTC (~$70.2 million) in just 41 minutes on July 30. Galaxy Research identified the pattern and linked the mass sweep directly to the firmware defect, exposing years of latent risk for affected wallet holders.

Updated Aug 2, 2026

agent-relevantai-agent-abuseautonomous-attackdeepseekllm-misuseserver-exploitationchina-nexus

A Chinese-speaking threat actor is leveraging the DeepSeek AI model combined with the open-source Hermes Agent framework to autonomously scan, target, and exploit internet-exposed vulnerable servers with minimal human oversight. This represents a notable escalation in offensive AI usage, where an agentic LLM pipeline performs reconnaissance, exploitation, and possibly post-exploitation actions with limited operator intervention. The campaign highlights growing risk from adversaries weaponizing legitimate agent frameworks originally built for benign automation.

Updated Aug 2, 2026

non-securityvendor-announcementinformationalopenaipricing

This item is a routine business/product announcement from OpenAI regarding API pricing changes for its GPT-5.6 model variants ('Luna' and 'Terra'), not a security incident. No vulnerability, exploit, malware, or attack technique is described.

Updated Aug 2, 2026

ICSOTdenial-of-serviceIEC61850GOOSEMMSout-of-bounds-readenergy-sectorCISA-advisory

MZ Automation GmbH's libiec61850 library, widely used in industrial control systems for substation automation, contains eight out-of-bounds read vulnerabilities (CVE-2026-66720, 66369, 63550, 65421, 66364, 66349, 56758, 66360) in its GOOSE, MMS, ACSE, and ISO Presentation layer parsers. Successful exploitation via crafted network messages can crash affected processes, causing denial-of-service conditions on devices in energy sector control systems. No public exploitation has been reported; a patched version (1.6.2) is available.

Updated Aug 2, 2026 · CVSS 7.5

ICSCISA-advisoryfile-uploadXSSHTML-injectionbuilding-management-systemJohnson-Controls

CISA disclosed three low-to-medium severity vulnerabilities in Johnson Controls OpenBlue Employee (FMS Employee) versions <=V2025.3.1, including unrestricted file upload, stored XSS, and HTML injection flaws. Exploitation requires authenticated access and user interaction, limiting practical risk, though successful attacks could allow malicious file uploads, persistent script execution, or content manipulation within the application. No public exploitation has been reported.

Updated Aug 2, 2026 · CVSS 2.4

icsothard-coded-credentialscryptographybillboard-controllercisa-advisory

Watchfire Controller Software used in digital billboard/LED sign controllers (BC550, BC750, BC760, BC760DC) contains hard-coded, self-signed RSA private keys and X.509 certificates embedded in plaintext firmware patch binaries. Successful exploitation could allow an attacker to intercept or spoof HTTPS/TLS connections to the web management interface and deliver malicious firmware to gain full control of the controller. Watchfire has released patched firmware versions to remediate the issue.

Updated Aug 2, 2026 · CVSS 5.7

freerdprdphttp-smugglingcrlf-injectionproxy-abuseremote-desktopagent-relevant

FreeRDP versions up to 3.28.0 fail to sanitize CRLF and control characters in the server-controlled TargetNetAddress field of RDP redirection PDUs. A malicious or compromised RDP server can exploit this to inject arbitrary headers or requests into the client's HTTP proxy CONNECT request, potentially enabling request smuggling, proxy authentication bypass, or lateral request injection against internal infrastructure.

Updated Aug 2, 2026 · CVSS 9.8

FreeRDPTLScertificate-validationman-in-the-middleRDPagent-relevant

FreeRDP versions up to 3.28.0 contain multiple flaws in their custom TLS certificate identity verification logic, allowing an attacker with a trusted or misissued certificate to impersonate legitimate RDP servers. This weakens TLS server authentication and enables man-in-the-middle attacks against RDP sessions, with a critical CVSS score of 9.8.

Updated Aug 2, 2026 · CVSS 9.8

wordpressauthentication-bypassplugin-vulnerabilityaccount-takeovercms-securitybroken-access-control

The Single Sign On For TNG WordPress plugin (versions up to 2.0.0) contains a critical authentication bypass vulnerability allowing unauthenticated attackers to reset any account's password, including administrators. Exploitation leads to complete site takeover with no user interaction or prior authentication required.

Updated Aug 2, 2026 · CVSS 9.8

wordpressplugin-vulnerabilityunauthenticated-rcefile-deletionpath-traversalsite-takeovercms

The FormGent WordPress plugin (versions up to 1.9.2) contains a critical unauthenticated arbitrary file deletion vulnerability caused by a missing capability check on its REST API endpoint. On Linux servers, attackers can bypass path traversal protections to delete wp-config.php, forcing the site into a fresh-install state that enables full site takeover.

Updated Aug 2, 2026 · CVSS 9.1

data-breachcloud-securitythird-party-riskhealthcarepii-exposurepharma

Amgen disclosed a data breach in which threat actors stole corporate and patient health data stored across multiple cloud systems operated by third-party service providers. The incident highlights ongoing risks tied to outsourced cloud infrastructure and vendor security posture in the pharmaceutical sector.

Updated Aug 1, 2026

ICSOTcritical-infrastructureenergy-sectormissing-authenticationCWE-306fuel-managementembedded-linux

Toptech Systems RCU II+ and Multiload II+ devices, used in fuel management systems within the energy sector, expose an unauthenticated Target Communications Framework (TCF) debug service that grants full root-level access to the underlying embedded Linux system. An attacker with adjacent network access could exploit this to view/modify the filesystem, manipulate processes, and control network interfaces, effectively achieving full device compromise. CISA rates this CVSS v3.1 8.8 (High), though exploitation requires network adjacency rather than remote internet access.

Updated Aug 1, 2026 · CVSS 8.8