Other Conventional Threats

Other conventional threat types

Showing 241–260 of 390 threats, newest first

space-systemsmissing-authenticationapi-securitycritical-infrastructureunauthenticated-accessspacecraft-command

AMMOS Instrument Toolkit (AIT) Deep Space Network Interface versions before 2.2.2 contain a critical missing authentication vulnerability in the Space Link Extension (SLE) interface manager. Unauthenticated attackers with network access can directly invoke seven exposed API routes to start/stop DSN sessions, exfiltrate telemetry, and inject arbitrary frames into active spacecraft communication links, posing a severe risk to mission integrity and safety.

Updated Jul 30, 2026 · CVSS 9.8

cryptanalysispost-quantumAESHAWKlattice-cryptographyresearchagent-relevant

Anthropic reports that its Claude Mythos Preview model assisted researchers in deriving a full key-recovery attack against the post-quantum signature scheme HAWK-256 and a substantially faster attack against 7-round AES-128. This is a research disclosure demonstrating AI-accelerated cryptanalysis rather than an active exploit, but it signals growing capability for AI-assisted discovery of cryptographic weaknesses that could erode confidence in specific PQC candidates and reduced-round symmetric ciphers.

Updated Jul 29, 2026

guidancecritical-infrastructureoperational-technologycisabest-practices

CISA and Australian cybersecurity authorities released joint guidance advising critical infrastructure operators to prepare procedures for isolating operational technology (OT) systems during cyberattacks or major disruptions. This is preventive advisory content rather than an active threat, aimed at improving resilience planning for industrial control environments.

Updated Jul 29, 2026

dns-hijackingsupply-chain-riskdrone-softwareuavtraffic-interceptiondomain-security

CubePilot, an Australian developer of flight controller software for drones, suffered a DNS hijacking attack that allowed threat actors to intercept traffic intended for its domains. The attack caused significant operational disruption and raises concerns about the integrity of software, firmware, or documentation served to CubePilot's customer base during the compromise window.

Updated Jul 29, 2026

critical-infrastructureoperational-technologynetwork-segmentationresilience-guidancegovernment-advisoryics-ot

CISA and the Australian Cyber Security Centre, alongside the FBI and international partners, released joint guidance titled 'CI Fortify' to help critical infrastructure organizations isolate vital operational technology and enabling systems during disruptions or crises. The guidance is a proactive best-practice advisory rather than a response to a specific active threat, focusing on network mapping, segmentation, and sustained isolated operations.

Updated Jul 29, 2026

MikroTikRouterOSbrute-forceauthentication-bypassCWE-307network-deviceICS-advisory

MikroTik RouterOS and Cloud Hosted Router contain a flaw in API authentication handling that fails to enforce rate-limiting or account lockout, allowing attackers to conduct high-volume brute-force login attempts, including bypassing per-connection delays via concurrent sessions. Successful exploitation could grant unauthorized administrative access to the affected router. No public exploitation has been reported and the vulnerability requires adjacent network access, not remote internet-based exploitation.

Updated Jul 29, 2026 · CVSS 8.8

ICSmendixsiemensaccess-controlprivilege-escalationdocumentation-gaplow-code

Siemens Mendix Runtime has a documentation gap regarding the special access-control behavior of the System.User entity, which can lead developers to misconfigure access rules and unintentionally expose sensitive user data or grant privilege escalation within deployed Mendix applications. A common misconfiguration allows anonymous users to gain access to all stored records via System.User specializations, even without explicitly configured access rights.

Updated Jul 29, 2026 · CVSS 9.1

path-traversalfile-writeibm-asperafile-transferarbitrary-file-writeagent-relevant

IBM Aspera Desktop App versions 1.0.5 through 1.0.19 contain a path traversal vulnerability that allows files transferred via Aspera to be written outside the user-selected download destination. This could enable attackers to overwrite sensitive files, plant malicious payloads in arbitrary filesystem locations, or achieve code execution depending on where files land.

Updated Jul 29, 2026 · CVSS 9.3

IBMAsperaFaspexcommand-injectionfile-transferRCEauthenticated-exploit

A critical shell command injection vulnerability affects IBM Aspera Faspex 5 versions 5.0.0 through 5.0.15.4, allowing a remote authenticated attacker to execute arbitrary code on the underlying host. Given the high CVSS score of 9.1 and the widespread use of Aspera Faspex for enterprise file transfer, successful exploitation could lead to full system compromise, data theft, or lateral movement within affected networks.

Updated Jul 29, 2026 · CVSS 9.1

asperafaspexrcefile-transferunquoted-shellauthenticated-attackeragent-relevant

A critical vulnerability (CVE-2026-14958) in IBM Aspera Faspex 5 versions 5.0.0 through 5.0.15.4 allows a remote authenticated attacker to execute arbitrary code via unquoted shell interpolation. With a CVSS score of 9.1, exploitation could lead to full compromise of the file transfer server and any systems or credentials it interfaces with.

Updated Jul 29, 2026 · CVSS 9.1

websphereaccess-controlprivilege-escalationadmin-consoleibmenterprise-middlewareagent-relevant

IBM WebSphere Application Server versions 9.0 and 8.5 contain a critical broken access control vulnerability in the administrative console that allows privilege escalation. Exploitation could grant an attacker administrative control over the application server, enabling full compromise of hosted applications and backend services. Given the CVSS score of 9.8, this vulnerability is likely remotely exploitable with low complexity and no required privileges.

Updated Jul 29, 2026 · CVSS 9.8

industry-initiativeai-securityagent-relevantopen-sourcegovernance

NVIDIA and 36 other organizations, including Microsoft, Cisco, Cloudflare, CrowdStrike, Hugging Face, IBM, Palo Alto Networks, Red Hat, and the Linux Foundation, have formed the Open Secure AI Alliance to develop shared open standards and tools for securing software and AI agents. As part of this effort, the group open-sourced the NOOA framework, aimed at improving security tooling and best practices across the AI ecosystem. This is not a threat or vulnerability disclosure but an industry defensive initiative relevant to organizations deploying AI agents.

Updated Jul 28, 2026

CISAKEVknown-exploited-vulnerabilityFortinetFortiOSAristaVeloCloudcommand-injectioninformation-disclosurenetwork-infrastructurefederal-agenciespatch-management

CISA has added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: a sensitive information exposure flaw in Fortinet FortiOS (CVE-2025-68686) and an OS command injection vulnerability in Arista VeloCloud Orchestrator On-Prem (CVE-2026-16812). Both are confirmed to be exploited in the wild and require urgent remediation under BOD 26-04 for federal agencies, with CISA recommending all organizations prioritize patching.

Updated Jul 28, 2026

apache-thriftrpcout-of-bounds-readinput-validationcppagent-relevantrag-pipelinemicroservices

CVE-2026-58662 is a critical out-of-bounds read vulnerability in Apache Thrift's C++ bindings caused by improper validation of specified quantity in input, affecting all versions before 0.24.0. Attackers can exploit this by sending crafted Thrift messages to trigger memory over-reads, potentially leading to information disclosure, service crashes, or further exploitation depending on the deployment context.

Updated Jul 28, 2026 · CVSS 9.1

apache-thriftout-of-bounds-readrpcmemory-corruptionopen-sourceagent-relevant

Apache Thrift's c_glib bindings prior to version 0.24.0 contain an out-of-bounds read vulnerability with a CVSS score of 9.1, indicating potential for information disclosure or denial of service. Apache Thrift is a widely used cross-language RPC framework, and this flaw could be exploited by processing malicious serialized data through affected bindings.

Updated Jul 28, 2026 · CVSS 9.1

apache-thriftrpcbuffer-overflowmemory-corruptionagent-relevantsupply-chain-componentcpp

A critical heap-based buffer overflow has been identified in the C++ bindings of Apache Thrift, a widely used cross-language RPC framework, affecting all versions prior to 0.24.0. The vulnerability carries a CVSS score of 9.8, indicating remote exploitability with low attack complexity and potential for full system compromise. Organizations using Thrift-based services must upgrade immediately to mitigate risk of remote code execution or denial of service.

Updated Jul 28, 2026 · CVSS 9.8

apache-thrifttlscertificate-validationmitmagent-relevantrpcsupply-chain-dependency

Apache Thrift's c_glib bindings before version 0.24.0 fail to properly validate that a TLS certificate's hostname matches the connected host, allowing an attacker positioned on the network path to present a mismatched but otherwise valid certificate and impersonate a trusted server. This affects any application using the c_glib Thrift client library to establish TLS-secured RPC connections, enabling man-in-the-middle attacks against Thrift-based service communication.

Updated Jul 28, 2026 · CVSS 9.1

fortinetfortiosnetwork-securitypost-exploitationpersistence-bypasscisa-kevedge-device

CVE-2025-68686 is a vulnerability in Fortinet FortiOS that allows a remote unauthenticated attacker to bypass a previously deployed patch addressing a symbolic link persistency mechanism used in post-exploitation scenarios. Exploitation requires prior compromise of the device at the filesystem level via another vulnerability, making this a persistence and detection-evasion enabler rather than an initial access vector. It has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild.

Updated Jul 28, 2026

outagecloud-reliabilitymicrosoft365azureavailabilityno-malicious-activity

Microsoft confirmed that a bug in its automated network maintenance request system caused a widespread outage affecting Microsoft 365 and Azure services. The bug erroneously removed IP routes from more network devices than intended, disrupting connectivity and service availability. This was a self-inflicted operational failure, not the result of a cyberattack or malicious activity.

Updated Jul 27, 2026

outageavailabilityopenaichatgptagent-relevant

OpenAI confirmed a worldwide outage affecting ChatGPT connectivity, disrupting user access to the chatbot service. No evidence suggests this was caused by a malicious attack; it appears to be an availability incident rather than a security breach.

Updated Jul 27, 2026