Other Conventional Threats

Other conventional threat types

Showing 21–40 of 385 threats, newest first

CISAKEVPaperCutauthentication-bypassunsafe-reflectionprint-managementfederalvulnerability-managementBOD-26-04

CISA has added two actively exploited PaperCut NG/MF vulnerabilities to its Known Exploited Vulnerabilities catalog, one involving missing authentication for a critical function and another involving unsafe reflection. These flaws pose significant risk to organizations running PaperCut print management software, with federal agencies required to remediate under BOD 26-04.

Updated Sep 1, 2026

iaciamprivilege-escalationcloud-securitypulumiinfrastructure-as-codeagent-relevant

A critical privilege escalation vulnerability in hulumi (versions prior to v1.3.2) allows attackers with access to a documented IAM principal to abuse an overly permissive weekly integration policy. This enables creation of persistent, higher-privilege af-e2e-* roles in sandbox accounts, potentially leading to full account compromise.

Updated Sep 1, 2026 · CVSS 9.8

data-breachdata-theftaviationcustomer-dataextortion

The threat actor group FulcrumSec claims to have stolen 86 GB of data from Manchester Airports Group (MAG), including detailed customer, booking, and travel records. BleepingComputer validated at least one traveller's record from leaked samples, suggesting the breach scope exceeds what MAG initially disclosed.

Updated Aug 31, 2026

wordpressauthentication-bypassprivilege-escalationplugin-vulnerabilitycms

The MyHome Core plugin for WordPress (versions up to 4.4.5) contains an authentication bypass vulnerability that allows unauthenticated attackers to hijack unconfirmed user accounts, including administrator accounts, under specific configuration conditions. Successful exploitation grants full administrative access to the WordPress site, enabling complete site takeover.

Updated Aug 31, 2026 · CVSS 9.8

wordpresswoocommerceprivilege-escalationplugin-vulnerabilityunauthenticatedweb-application-security

The Custom User Registration Fields for WooCommerce WordPress plugin (up to v2.2.3) allows unauthenticated attackers to escalate privileges to Administrator by manipulating the checkout request. The vulnerability arises from unsanitized user-controlled role data being passed directly into WordPress's role assignment function, enabling full site takeover during account registration at checkout.

Updated Aug 31, 2026 · CVSS 9.8

directory-traversalpath-traversalfile-managerrce-potentialweb-applicationagent-relevant

Cloud Commander before version 19.20.2 contains a critical directory traversal vulnerability in its REST file-operation and markdown endpoints, allowing unauthenticated or minimally privileged attackers to read, write, move, or copy files outside the configured root directory. With a CVSS score of 9.8, this flaw can lead to full system compromise, data exfiltration, or arbitrary file overwrite.

Updated Aug 31, 2026 · CVSS 9.8

agent-relevantmcpargocdunauthenticated-accessgitopsprivilege-escalationapi-token-exposure

argocd-mcp version 0.8.0 exposes its HTTP transport on all network interfaces without enforcing authentication on incoming MCP sessions, even when an ARGOCD_API_TOKEN is configured. Any attacker with network access to the listener can invoke the full MCP tool surface, leveraging the operator's stored Argo CD token to create applications, trigger syncs, and modify GitOps resources without any credentials of their own.

Updated Aug 31, 2026 · CVSS 10

androidprivacyencryptionechtlsmobile-securitydefensive-feature

This is not a threat but a defensive feature announcement: Google's Android 17 introduces OS-wide support for Encrypted Client Hello (ECH), preventing network providers and on-path observers from seeing which websites a device connects to. The update also includes additional protections against cellular network vulnerabilities and home network privacy risks.

Updated Aug 30, 2026

piracyiptvlaw-enforcementcopyright-infringement

A 68-year-old individual in the U.K. was sentenced to over six years in prison for running an illegal IPTV service that generated approximately $1.3 million over three years. This is a law enforcement action against digital piracy infrastructure rather than a cybersecurity threat targeting organizations or systems.

Updated Aug 30, 2026

privacybrowser-updateemail-aliasingnot-a-vulnerability

This report describes a new privacy feature in Brave browser version 1.94 called 'Email Aliases,' which allows users to generate disposable email addresses to reduce tracking when signing up for online services. This is a legitimate product feature announcement, not a security threat, vulnerability, or malicious campaign.

Updated Aug 30, 2026

icsscadaxxetlscertificate-validationlog4netiec-60870-5-104critical-infrastructure

ASE2000 V2 Communications Test Set versions 2.25 through 2.37 contain two vulnerabilities: an XML External Entity (XXE) flaw inherited from a bundled outdated Apache log4net library, and an improper TLS certificate validation flaw affecting IEC 60870-5-104 secure communications. Successful exploitation could allow attackers to read/write arbitrary local files, trigger outbound network requests, or perform man-in-the-middle attacks to intercept and modify protected substation/grid communications.

Updated Aug 30, 2026 · CVSS 9.8

authentication-bypassbroken-access-controliotrest-apiunauthenticated-rce-riskagent-relevant

rust-iot-platform contains a critical authentication bypass vulnerability in which most REST API endpoints lack authentication checks in their handler code. Unauthenticated attackers can fully manage user accounts—creating, listing, retrieving, updating, and deleting them—leading to complete account and access control compromise.

Updated Aug 30, 2026 · CVSS 9.8

wordpressplugin-vulnerabilityrceunauthenticatedfile-uploadweb-application-security

The Sigma Forms Pro WordPress plugin (versions up to 1.4.5) contains a critical vulnerability that allows unauthenticated attackers to achieve remote code execution by exploiting improper capability handling and MIME type validation during form submissions. Several default plugin templates ship with unrestricted file upload fields, making exploitation immediately feasible on default installs without any attacker reconnaissance or configuration changes.

Updated Aug 30, 2026 · CVSS 9.8

sql-injectionibm-concertremote-exploitdata-breachcve-2026-3627agent-relevant

IBM Concert versions 1.0.0 through 2.3.1 contain a critical SQL injection vulnerability that allows a remote, unauthenticated attacker to manipulate backend database queries. Exploitation could result in unauthorized viewing, modification, or deletion of sensitive application data. With a CVSS score of 9.1, this vulnerability poses significant risk to organizations running unpatched instances.

Updated Aug 30, 2026 · CVSS 9.1

data-extortiongovernmentdata-breachberlinstate-networkdouble-extortion

Berlin's state administrative network was compromised in August 2026, with attackers exfiltrating data and subsequently demanding an extortion payment. The Berlin government has publicly refused to pay, and forensic investigation has revealed additional data outflows from the Senate Department for Mobility, Transport, Climate Protection and Environment, suggesting a broader compromise than initially disclosed.

Updated Aug 29, 2026

data-breachhealthcareextortionshinyhuntersthird-party-riskpatient-dataPII exposure

McKesson, a major healthcare and pharmaceutical distribution company, disclosed a breach involving unauthorized access to third-party applications, with the ShinyHunters extortion group claiming theft of 284 million patient records. The incident highlights ongoing risks from third-party application compromise and large-scale extortion campaigns targeting healthcare data supply chains.

Updated Aug 29, 2026

icsotcisa-advisoryfuel-managementargument-injectionbuffer-overflowrcephplegacy-software

All-Line Equipment Company's Fuel-Boss fuel management systems (Standard, Portal, Master/Slave, and Backflush variants) running PHP 7.1.5 or earlier are vulnerable to two high-severity flaws: an argument injection vulnerability in the PHP imap_open() function and a buffer overflow in PHP-FPM's FastCGI handling. Successful exploitation could allow remote attackers to execute arbitrary OS commands or code on affected systems, posing risk to critical manufacturing, defense, emergency services, and transportation sector operators using this equipment.

Updated Aug 29, 2026 · CVSS 8.7

ICSIoTcellular-gatewayauthentication-bypassCSRFcleartext-credentialsweak-cryptoMQTTunpatchedno-vendor-fix

The Ebyte NA111-M cellular/MQTT gateway (firmware 9013-2-17) contains 13 vulnerabilities, several rated critical (CVSS 9.8), including missing authentication, client-side authentication bypass, weak cryptographic hashing, and cleartext transmission/storage of credentials including MQTT traffic. Combined, these flaws allow unauthenticated remote attackers to fully compromise the device, gaining administrative control, intercepting or replaying credentials, and disrupting availability. Ebyte has not delivered a patch despite CISA coordination attempts, leaving deployed units permanently exposed absent compensating network controls.

Updated Aug 29, 2026 · CVSS 9.8

ICSOTdenial-of-serviceCC-LinkMELSECcritical-manufacturingMitsubishi-ElectricCVE-2025-3511

Multiple Mitsubishi Electric FA products, including CC-Link IE TSN modules and MELSEC iQ-R/iQ-F series Ethernet and CPU modules, contain a denial-of-service vulnerability (CVE-2025-3511) in their Ethernet function. A remote attacker can send a specially crafted UDP packet to cause a DoS condition, communication delay, or timeout error, requiring a system reset for recovery in most cases.

Updated Aug 29, 2026 · CVSS 7.5

IBM-iprivilege-escalationunauthenticatedsession-hijackingGUI-vulnerability

A critical unauthenticated privilege escalation vulnerability exists in IBM Administration Runtime Expert (ARE) for i, allowing remote attackers to execute actions under another authenticated user's session. This flaw, rated 9.9 CVSS, poses severe risk to IBM i systems used for enterprise administration and automation, potentially enabling full system compromise without prior credentials.

Updated Aug 29, 2026 · CVSS 9.9