Other Conventional Threats

Other conventional threat types

Showing 361–380 of 390 threats, newest first

agent-relevantchatbot-securityprivilege-escalationcloud-misconfigurationgoogle-cloudconversational-aidata-exposure

Varonis researchers discovered a critical flaw in Google Dialogflow CX that allowed an attacker with edit access to one Code Block-enabled conversational agent to hijack other Code Block-enabled agents within the same Google Cloud project. Exploitation could expose live conversation data, steal user-shared information, and enable injection of attacker-controlled bot responses, including deceptive prompts to re-enter passwords. Google has since remediated the issue, but the flaw highlights significant multi-tenancy isolation risks in managed conversational AI platforms.

Updated Jul 8, 2026 · CVSS 7.5

backdoorrouterfirmwareiotauthentication-bypassnetwork-infrastructure

A hidden authentication backdoor has been discovered in multiple versions of Tenda router firmware, allowing attackers to gain unauthorized administrative access to the device's web management panel. This could enable full device takeover, traffic interception, and use of the router as a pivot point into internal networks.

Updated Jul 8, 2026

data-breachsource-code-theftthird-party-riskIT-servicesextortion

Accenture confirmed a security breach after a threat actor claimed to have stolen approximately 35 GB of source code and other internal data, subsequently offering it for sale on underground forums. As a major IT services and consulting provider, exposure of Accenture's internal source code and data poses downstream risk to its extensive client base across multiple industries.

Updated Jul 8, 2026

ICSCISA-advisorymemory-corruptionlocal-attack-vectorEDA-softwareelectronics-design-automationuse-after-freebuffer-overflow

Labcenter Proteus 9 (build 9.1_SP4_Build_42914), an electronic design automation tool used across critical infrastructure sectors, contains three high-severity memory corruption vulnerabilities including an out-of-bounds write, a stack-based buffer overflow, and a use-after-free. Successful exploitation requires local access and user interaction (e.g., opening a crafted file) but could lead to arbitrary code execution or information disclosure. No known public exploitation has been reported, and the vendor has released version 9.2 SPO to address the issues.

Updated Jul 8, 2026 · CVSS 7.8

ICSSCADAenergy-sectorbuffer-overflownginxCISA-advisorydenial-of-servicecritical-infrastructure

Hitachi Energy e-mesh EMS versions 4.1.6, 4.4.2, and 4.7.0 contain a heap-based buffer overflow vulnerability in the bundled NGINX ngx_http_rewrite_module (CVE-2026-42945), affecting NGINX v1.30.0 and below. Successful exploitation could crash the NGINX worker process (denial of service) and, under certain conditions where ASLR is disabled or bypassed, allow arbitrary code execution on the affected energy management system.

Updated Jul 8, 2026 · CVSS 8.1

traefikheader-injectionauthentication-bypassforwardauthreverse-proxyapi-gatewayagent-relevant

Traefik reverse proxy versions prior to v2.11.51, v3.6.22, and v3.7.6 fail to strip underscore-variant identity headers when using BasicAuth, DigestAuth, or ForwardAuth middlewares, allowing attackers to inject spoofed identity or authorization headers that backends normalize as legitimate. This enables authentication bypass and identity spoofing on any route protected by these middlewares, with a maximum CVSS score of 10.0 reflecting trivial exploitability and full compromise potential.

Updated Jul 8, 2026 · CVSS 10

arcgisfile-uploadunauthenticatedgisweb-application

CVE-2026-9182 is an unrestricted file upload vulnerability in ArcGIS Server that allows an unauthenticated attacker to upload arbitrary crafted files to an affected endpoint. This could lead to further compromise such as web shell deployment or remote code execution depending on server configuration and processing of uploaded files.

Updated Jul 8, 2026 · CVSS 5.3

beyondtrustremote-accessprivileged-access-managementauthorization-bypassvendor-advisoryagent-relevant

A critical vulnerability (CVSS 9.9) in BeyondTrust Remote Support and Privileged Remote Access allows an authenticated, low-privileged attacker to bypass authorization checks and access data or resources outside their permitted scope. Because these platforms are widely used to broker privileged remote sessions, exploitation could enable lateral movement into sensitive infrastructure, including servers hosting automation and AI agent tooling.

Updated Jul 8, 2026 · CVSS 9.9

credential-exposurecloud-securitygovernmentawsgovclouddata-leakinsider-riskagent-relevant

A contractor for CISA maintained a public GitHub repository that exposed highly privileged AWS GovCloud credentials and internal CISA build, test, and deployment documentation. This exposure represents a severe operational security failure that could grant attackers deep access into sensitive federal cybersecurity infrastructure. The leak went unaddressed for an extended period before remediation this past weekend.

Updated Jul 7, 2026

AI-abusesocial-engineeringaccount-takeoverchatbot-exploitationagent-relevantprompt-injectionidentity-theft

Attackers discovered and shared a method on Telegram to manipulate Meta's AI-powered support assistant into resetting passwords for high-profile Instagram accounts without proper identity verification. This led to the compromise and defacement of accounts belonging to the Obama White House and a senior U.S. Space Force official with pro-Iranian propaganda. The incident highlights how conversational AI agents deployed for customer support can be socially engineered into bypassing security controls.

Updated Jul 7, 2026

piracylaw-enforcementstreamingarresttakedown

Vietnamese authorities arrested seven individuals suspected of operating HiAnime, a large-scale anime piracy streaming platform, which was shut down in June. This is a law enforcement action against copyright infringement infrastructure rather than a cyberattack targeting organizations or individuals.

Updated Jul 7, 2026

icsotxz-utilsliblzmarace-conditiondenial-of-servicecritical-manufacturingbr-industrial-automation

A high-severity race condition vulnerability (CVE-2025-31115) in the XZ Utils liblzma multithreaded decoder affects multiple B&R Industrial Automation GmbH HMI/panel products, potentially causing crashes or memory corruption. The flaw stems from improper handling of invalid input in the lzma_stream_decoder_mt function, and has been patched in XZ Utils 5.8.1 with corresponding firmware updates from B&R.

Updated Jul 7, 2026 · CVSS 7.5

credential-leakcloud-securitygovernmentgithub-exposureinsider-riskawsagent-relevant

A contractor for CISA intentionally published AWS GovCloud access keys and a large set of other agency secrets to a public GitHub account, prompting congressional inquiries into the incident. CISA is currently working to contain the exposure and rotate or invalidate the leaked credentials, but the scope and duration of exposure remain unclear.

Updated Jul 6, 2026

bulletproof-hostingrussiadisinformationlaw-enforcement-actioninfrastructure-seizurenation-stateEU-sanctions

Dutch authorities arrested two co-owners of hosting companies that had taken over the technical infrastructure of Stark Industries Solutions, an ISP sanctioned by the EU for enabling Russian cyberattacks, influence operations, and disinformation campaigns. The operation resulted in the seizure of roughly 800 servers used as bulletproof hosting infrastructure supporting state-linked malicious cyber activity across the EU.

Updated Jul 6, 2026

not-a-security-threatmodel-performanceai-product-news

This article reports user dissatisfaction with the relaunch of 'Claude Fable,' a model reported to underperform relative to its original release. This is a product quality/performance issue, not a security vulnerability, breach, or malicious campaign.

Updated Jul 6, 2026

flipper-zerofirmwareopen-sourcehardware-toolcommunity-development

This item is a product/business update reporting that Flipper Devices will continue developing Flipper Zero firmware with a smaller internal team and increased reliance on community contributions. It is not a disclosed vulnerability, exploit, or active threat campaign, but a governance and development-model change for a widely used pentesting/hardware hacking tool.

Updated Jul 6, 2026

ICSCISA-advisorystoragehardcoded-credentialscommand-injectionsql-injectionxssunauthenticated-RCEroot-accesscritical-infrastructure

StoneFly Storage Concentrator (SC) and its Virtual Machine variant contain five critical/medium vulnerabilities including hardcoded credentials, two unauthenticated OS command injection flaws leading to root-level remote code execution, an unauthenticated SQL injection exposing session tokens and password hashes, and a reflected XSS. Combined, these flaws allow attackers to fully compromise storage infrastructure without authentication, potentially affecting Defense Industrial Base, Energy, Financial Services, Healthcare, and IT sector organizations worldwide.

Updated Jul 6, 2026 · CVSS 10

ICSSCADAXXEinformation-disclosuredata-centerschneider-electricCWE-611

A medium-severity XML External Entity (XXE) vulnerability affects Schneider Electric EcoStruxure IT Data Center Expert versions 9.1.1 and prior, allowing an authenticated attacker to disclose server-side file contents via crafted XML payloads to SOAP service endpoints. Schneider Electric has released version 9.1.2 to remediate the issue, and no known public exploitation has been reported.

Updated Jul 6, 2026 · CVSS 6.5

sql-injectioncve-2026-4321unpatchedend-of-lifeweb-applicationraeradestekz

A critical SQL injection vulnerability has been identified in Destekz, a product from Raera (Ankara Web Design and Digital Advertising Agency), with a CVSS score of 9.8. The vendor has confirmed the product is no longer supported, meaning no patch will be released, leaving all deployments permanently vulnerable to exploitation.

Updated Jul 6, 2026 · CVSS 9.8