Other Conventional Threats

Other conventional threat types

Showing 41–60 of 385 threats, newest first

redpandaadmin-apiunauthenticated-accessmisconfigurationbroker-compromiseagent-relevantdata-streamingrag-pipeline

Redpanda versions through 26.2.2 bind the Admin API to all network interfaces (0.0.0.0:9644) with authentication disabled by default, allowing any network-reachable attacker to be treated as a superuser. This enables unauthenticated creation and deletion of broker accounts, cluster configuration tampering, and disruption of partition replication, posing a critical risk to any exposed deployment.

Updated Aug 29, 2026 · CVSS 9.8

mcpagent-relevantrceunauthenticated-accessai-agent-infrastructuresupply-chaindefault-configuration

The mcp-http-server package used by UI-TARS-desktop's MCP servers defaulted to binding on all network interfaces ('::') with no mandatory authentication middleware, exposing the @agent-infra/mcp-server-commands and @agent-infra/mcp-server-filesystem tools to unauthenticated network access. Any remote client able to reach the exposed port could invoke the run_command tool to execute arbitrary OS commands, or read/write arbitrary files, as the user running the MCP server. The flaw was fixed by changing the default bind address to 127.0.0.1, but the package version number was not incremented, making patch detection reliant on commit history rather than semantic versioning.

Updated Aug 29, 2026 · CVSS 10

iot-botnetcritical-infrastructuresharepointrcec2-abusescanningexploit-chainwater-utilities

This is a weekly digest from The Hacker News summarizing over 30 distinct security stories, including a 296,000-device IoT botnet, targeting of 100+ water utility systems, and a SharePoint remote code execution exploit chain. The roundup lacks technical depth on any single incident but signals a broad wave of activity spanning critical infrastructure targeting, malicious tooling with delayed payload activation, and abuse of public infrastructure for command-and-control traffic.

Updated Aug 28, 2026

data-breachaviationcustomer-datawifiPII

Manchester Airports Group (MAG) disclosed a breach in which attackers accessed and stole customer data, including Wi-Fi sign-up information from Manchester, Stansted, and East Midlands airports. The incident highlights ongoing risks to critical transportation infrastructure operators handling large volumes of traveler personal data.

Updated Aug 28, 2026

cisakevknown-exploited-vulnerabilitiesownCloudlinux-kerneljfrog-artifactorypatch-managementagent-relevant

CISA has added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: an ownCloud improper authentication flaw, an unspecified Linux Kernel vulnerability, and a JFrog Artifactory path traversal issue. These vulnerabilities pose significant risk to federal and enterprise systems and are subject to expedited remediation under BOD 26-04. Organizations using these technologies should prioritize patching to prevent exploitation.

Updated Aug 28, 2026

ICSOTCNCdenial-of-serviceCWE-1285Mitsubishi Electriccritical-manufacturingfirmware-vulnerability

A vulnerability (CVE-2025-2399) in multiple Mitsubishi Electric CNC Series products allows a remote attacker to trigger an out-of-bounds read by sending specially crafted packets to TCP port 683, resulting in a denial-of-service condition. The flaw affects a wide range of M800/M80/E80, M800V/M80V, and M700V/M70V/E70 series controllers used in industrial manufacturing environments. Vendor fixes are available for most affected product lines, with mitigations recommended for systems that cannot be immediately patched.

Updated Aug 28, 2026 · CVSS 5.9

ICSot-securitycommand-injectionauthentication-bypassremote-access-devicecisa-advisoryunauthenticated-access

The Xiiaozet LK100W device, versions prior to 2.1.240, contains three critical vulnerabilities including OS command injection, missing authentication for a critical function, and an authentication bypass that together could allow a remote attacker to fully compromise the device. Two of the three flaws are rated CVSS v3.1 9.8 (Critical) and require no authentication or user interaction to exploit remotely. CISA has published an advisory recommending immediate firmware update to v2.1.240.

Updated Aug 28, 2026 · CVSS 9.8

icsotrockwell-automationpassword-hashingbcryptcwe-916cisa-advisorycritical-manufacturingtransportation

Rockwell Automation OTTO Fleet Manager versions up to V2.36.2 use a bcrypt implementation with an insufficient work factor, weakening stored password hashes against offline brute-force attacks. Exploitation requires an attacker to first obtain an unencrypted system backup, after which weakly hashed credentials could be cracked more easily. Rockwell has released version 2.36.3 to remediate the issue, along with guidance to enable encrypted system backups.

Updated Aug 28, 2026 · CVSS 6.8

input-validationansi-escape-injectionkey-verification-bypassterminal-spoofingpgpidentity-verificationsupply-chain-riskagent-relevant

A critical flaw in openssl_encrypt (before 1.4.9) allows attackers to inject unsanitized ANSI escape sequences into the email field of identity documents, enabling forgery of the fingerprint verification line shown to users. This undermines the out-of-band verification mechanism designed to prevent key substitution/MITM attacks, allowing attackers to trick users into trusting an attacker-controlled key.

Updated Aug 28, 2026 · CVSS 9.8

cvekey-substitutioncryptographic-flawidentity-verificationfingerprint-bypasssupply-chainagent-relevant

openssl_encrypt versions prior to 1.4.9 fail to properly re-derive and validate cryptographic fingerprints when loading identities from identity.json, allowing attackers to silently substitute public keys while preserving the claimed fingerprint. This enables man-in-the-middle style attacks where encrypted data is protected with attacker-controlled keys and forged signatures pass verification, undermining the core trust model of the identity store.

Updated Aug 28, 2026 · CVSS 9.8

grav-cmsapi-key-abuseprivilege-escalationbroken-access-controlcve-2026-80203agent-relevant

The getgrav/grav-plugin-api plugin before version 1.0.18 fails to properly validate API key scope in a critical authorization function, allowing an API key with limited privileges to perform super-admin actions if it belongs to a super-admin account. This flaw enables attackers holding a low-scoped but valid API key to disable 2FA, hijack or delete API keys, and manipulate super-admin accounts, effectively granting full administrative takeover.

Updated Aug 28, 2026 · CVSS 9.8

path-traversaljfrogartifactorycve-2026-66384cisa-kevsupply-chainagent-relevant

JFrog Artifactory is affected by a path traversal vulnerability that allows an authenticated user to write files outside the intended Docker cache directory under specific remote-repository configurations. CISA has added this CVE to its Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild, with a remediation deadline of September 10, 2026. Organizations using Artifactory as a package/artifact registry should treat this as a priority patching item.

Updated Aug 28, 2026

legal-settlementregulatorychild-safetynon-security-incident

Meta has agreed to a proposed settlement of up to approximately $18 billion with a bipartisan coalition of 52 state attorneys general over allegations that Facebook and Instagram were designed to foster compulsive use among children and teenagers. This is a legal and regulatory matter rather than a cybersecurity incident, involving no technical exploitation, vulnerability, or malicious activity.

Updated Aug 27, 2026

rowhammergpu-securityprivilege-escalationdenial-of-servicehardware-attacknvidiaagent-relevant

Researchers disclosed GPUThor, a new Rowhammer-class attack that defeats NVIDIA's ECC memory protections, allowing attackers with local access to induce bit flips leading to denial-of-service or root-level privilege escalation. This is particularly concerning for shared GPU infrastructure such as cloud AI training clusters and multi-tenant inference environments.

Updated Aug 27, 2026

ICSIoTmissing-authorizationCWE-862payment-systemsunauthenticated-accessinformation-disclosure

PayRange API, used to manage internet-connected vending and payment devices, contains a missing authorization vulnerability that exposes verbose device management data to unauthenticated or authenticated attackers. Exploitation could allow information disclosure, denial of service, or manipulation of device-displayed content across the PayRange network. PayRange has not engaged with CISA to remediate the issue, leaving affected deployments exposed.

Updated Aug 27, 2026 · CVSS 8.8

kevcisavulnerability-managementpatch-prioritylegacy-softwarenetwork-applianceagent-relevant

CISA added six vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation, spanning Red Hat Libuser/ABRT, Microsoft SQL Server, Ajax.NET Professional, Linux Kernel, and Citrix NetScaler ADC/Gateway. BOD 26-04 mandates FCEB agencies prioritize rapid remediation of these on internet-facing assets, particularly those allowing full post-exploitation control. All organizations, including those hosting AI infrastructure, are encouraged to remediate promptly given confirmed in-the-wild exploitation.

Updated Aug 27, 2026

vulnerability-managementsecure-by-designCISAKEVpatch-managementrisk-prioritizationadvisory

CISA released a review analyzing FY2024-2025 vulnerability and exploitation data, finding that most breaches stem from unpatched, well-known vulnerabilities rather than novel attack techniques. The report highlights recurring software weakness classes and provides a risk-based prioritization framework (per BOD 26-04) to help organizations focus remediation efforts before automated and AI-assisted vulnerability discovery becomes more prevalent.

Updated Aug 27, 2026

privilege-escalationsymlink-attacklinuxred-hatCISA-KEVeol-software

CVE-2015-5287 is a local privilege escalation vulnerability in Red Hat's Automatic Bug Reporting Tool (ABRT), exploitable via a symlink attack on a predictably named file. The flaw allows local users with certain permissions to escalate privileges on affected Linux systems. This vulnerability has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation in the wild despite its age.

Updated Aug 27, 2026 · CVSS 6.9

linuxprivilege-escalationrace-conditionred-hatcisa-kevlocal-exploit

CVE-2015-3246 is a race condition vulnerability in Red Hat's libuser library that allows authenticated local users to corrupt /etc/passwd, resulting in denial of service or privilege escalation. The flaw has been added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild despite its age. Organizations still running affected libuser versions on Linux systems should prioritize patching before the specified due date.

Updated Aug 27, 2026

deserializationremote-code-executiondotnetlegacy-softwareend-of-lifeCISA-KEV

Ajax.NET Professional (AjaxPro) is affected by a deserialization vulnerability (CVE-2021-23758) that allows remote code execution through instantiation of arbitrary .NET classes. The affected product is end-of-life, meaning no vendor patch is available, and CISA has added it to the Known Exploited Vulnerabilities catalog due to active exploitation.

Updated Aug 27, 2026