Other Conventional Threats

Other conventional threat types

Showing 381–390 of 390 threats, newest first

wordpresswoocommerceplugin-vulnerabilityarbitrary-file-deletionpath-traversalunauthenticatedrce-potential

The Printcart Web to Print Product Designer plugin for WooCommerce (versions up to 2.5.2) contains a critical vulnerability allowing unauthenticated attackers to delete arbitrary files on the server. Combined with a bypassable nonce mechanism, this flaw could enable deletion of critical files such as wp-config.php, potentially leading to remote code execution and full site compromise.

Updated Jul 6, 2026 · CVSS 9.1

scattered-spidersocial-engineeringlegal-actioncybercrime-groupcritical-infrastructuretransportationidentity-thefthelp-desk-fraud

Two members of the Scattered Spider cybercrime group pleaded guilty on the first day of their UK trial for a August 2024 cyberattack that crippled Transport for London (TfL). This marks a significant law enforcement outcome against a group known for sophisticated social engineering, SIM-swapping, and help-desk impersonation attacks targeting large enterprises and critical infrastructure.

Updated Jul 5, 2026

extortiondata-theftransom-negotiationgovernment-targetcryptocurrencyno-encryption

A U.S. government entity paid approximately $1 million in extortion payments to a group calling itself Kairos to prevent the leak of stolen data. Analysis of a leaked negotiation chat and blockchain payment trail suggests Kairos may operate purely as a data-theft extortion outfit without deploying ransomware encryption, distinguishing it from traditional ransomware gangs. This case highlights the growing prevalence of extortion-only threat actors targeting public sector organizations.

Updated Jul 5, 2026

ICSmedical-devicesDICOMpath-traversaldenial-of-servicehealthcareCISA-advisory

OFFIS DCMTK Toolkit versions <=3.7.0 contain five vulnerabilities including a critical path traversal flaw (CVSS 9.8) allowing malicious DICOM servers to write arbitrary files on clients, plus multiple unauthenticated memory-exhaustion and type-confusion bugs that can crash storescp and worklist server processes. These affect healthcare imaging infrastructure worldwide and could enable file write outside intended directories, cross-department data disclosure, or denial of service against clinical DICOM services. No public exploitation has been reported to CISA as of the advisory date.

Updated Jul 5, 2026 · CVSS 9.8

icsotmitsubishi-electric7-zippath-traversalbuffer-overflowdenial-of-servicecritical-manufacturingcisa-advisory

Mitsubishi Electric MELSOFT Update Manager SW1DND-UDM-M versions 1.000A through 1.014Q contain four vulnerabilities in its bundled 7-Zip component, including a heap-based buffer overflow, NULL pointer dereference, link following, and path traversal issue. Successful exploitation requires local access and user interaction to decompress a specially crafted archive, and could lead to denial-of-service, data tampering, or arbitrary code execution. No public exploitation has been observed, and the vulnerabilities are not remotely exploitable.

Updated Jul 5, 2026 · CVSS 8.8

ICSIoThardcoded-credentialsCVE-2026-13768CVE-2026-55726CVE-2026-54477smart-agriculturecloud-misconfigurationazure-blob-storage

Gardyn IoT Hub devices (Home and Studio firmware, Cloud API) contain three vulnerabilities including a critical hard-coded Azure IoT Hub owner key that allows unauthenticated attackers to access connection info and execute arbitrary commands on any connected device. Additional flaws expose device logs via a publicly listable Azure Blob Storage container and allow clickjacking/XSS on the admin panel due to missing security headers. No public exploitation has been reported, and Gardyn has patched server-side infrastructure and recommends firmware/app updates.

Updated Jul 5, 2026 · CVSS 10

default-credentialsauthentication-bypassunauthenticated-accessself-hosted-appCVE-2026-58466rss-automationagent-relevant

AutoBangumi versions prior to 3.2.8 seed a default administrator account with publicly known credentials whenever the users table is empty, allowing any unauthenticated attacker to log in and gain full administrative control. This includes the ability to manipulate RSS feeds, downloader configuration, and all authenticated API endpoints, effectively giving attackers complete control of the deployed instance.

Updated Jul 5, 2026 · CVSS 9.8

ICSRTUcredential-exposureinsecure-permissionsschneider-electriccritical-infrastructure

Schneider Electric EasyLogic T150 and Saitel DP RTU devices contain two vulnerabilities that could allow unauthorized access to sensitive credentials and password hashes. CVE-2026-9650 allows an unauthenticated attacker with physical access to extract credentials from firmware or system files, while CVE-2026-9651 allows a privileged local attacker to read improperly protected system files containing password hashes. No public exploitation has been reported to CISA at this time.

Updated Jul 4, 2026 · CVSS 7.5

ICSsatelliteCSRFmissing-authenticationAPI-exposuredenial-of-serviceinformation-disclosure

Two high-severity vulnerabilities affect ST Engineering iDirect iQ-Series satellite terminals (Evolution iQ, 3315-Series, 9-Series) running firmware <=4.5.2.1. Successful exploitation could allow an unauthenticated attacker to retrieve sensitive device credentials or force device reboots via CSRF, potentially causing terminal impersonation or denial-of-service on satellite links. No known public exploitation has been reported to CISA at this time.

Updated Jul 4, 2026 · CVSS 8.1

ICSfirmwaresecure-bootphysical-accesssatelliteCWE-347reaction-wheel

CubeSpace CW0057 Reaction Wheel firmware versions prior to 5.0.20 fail to properly verify cryptographic signatures on firmware updates, relying only on CRC-32 integrity checks. An attacker with physical access could upload arbitrary malicious firmware without authentication, though the device remains recoverable via an independent bootloader.

Updated Jul 4, 2026 · CVSS 6.1