Other Conventional Threats

Other conventional threat types

Showing 81–100 of 390 threats, newest first

cisconetwork-managementcrossworksecure-workloadcvss-10patch-tuesdaynetwork-infrastructure

Cisco has released patches addressing nine vulnerabilities across its Crosswork platforms and Secure Workload software, five of which carry the maximum CVSS score of 10.0. These flaws affect Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning regardless of device configuration, posing significant risk to network orchestration infrastructure.

Updated Aug 23, 2026 · CVSS 10

vendor-contentSOCsecurity-operationsAI-in-securitynon-incident

This item is promotional/informational content from The Hacker News discussing how Wazuh, an open-source security platform, integrates AI to improve SOC (Security Operations Center) workflows. It does not describe an active threat, vulnerability, exploit, or attack campaign.

Updated Aug 23, 2026

privacylegal-settlementregulatorychild-privacynon-technical

TikTok has agreed to pay $400 million to settle a 2024 U.S. Department of Justice lawsuit alleging violations of child privacy laws, specifically related to prior consent decree obligations. This is a regulatory and legal enforcement action rather than a cybersecurity incident, involving no exploited vulnerability, malware, or technical compromise.

Updated Aug 23, 2026

privacydigital-identityvendor-contentnon-technicalnot-a-threat

This is an informational/promotional article from Anonyome Labs discussing the benefits of using separate digital personas (distinct emails, phone numbers, payment methods) to reduce data broker correlation and limit exposure from breaches and identity theft. It does not describe an active threat, vulnerability, or attack campaign.

Updated Aug 23, 2026

windowsnamed-pipesipcprivilege-escalationaccess-controlendpoint-securityagent-relevant

This report is an educational/advisory piece from ThreatLocker discussing how weak access controls on Windows named pipes can expose privileged services to untrusted or malicious processes. It highlights best practices such as endpoint verification, command authorization, input validation, and least-privilege scoping to mitigate abuse of interprocess communication channels.

Updated Aug 23, 2026

wordpressplugin-vulnerabilityphp-object-injectionunauthenticateddeserializationpop-chainweb-application-security

The WS Form LITE WordPress plugin (versions up to 1.10.80) contains a PHP Object Injection vulnerability caused by insecure deserialization of untrusted form submission meta values. While no exploitable POP (Property-Oriented Programming) chain exists within the plugin itself, the presence of a vulnerable POP chain in any other installed plugin or theme could enable unauthenticated attackers to achieve file deletion, data exfiltration, or remote code execution.

Updated Aug 23, 2026 · CVSS 9.8

wordpressssrfplugin-vulnerabilityaccount-takeovermailguncve-2026-78003unauthenticated

The Mailgun for WordPress plugin (versions up to 2.2.0) contains an unauthenticated SSRF vulnerability caused by insufficient input validation in the add_list() function. Attackers can leverage this flaw to make authenticated requests to any Mailgun API endpoint using the site's stored API key, enabling creation of email-forwarding rules that intercept password reset emails and result in full administrator account takeover.

Updated Aug 23, 2026 · CVSS 9.8

IBMAIXPowerVMVIOSprivilege-escalationRCEunixcritical-infrastructure

A critical vulnerability (CVE-2026-17145) affects IBM AIX versions 7.2 and 7.3, as well as IBM PowerVM VIOS 4.1, allowing a remote, unauthenticated attacker to execute arbitrary code due to improper privilege management. With a CVSS score of 9.8, this flaw poses severe risk to enterprises running IBM Power systems, potentially enabling full system compromise. Organizations using these platforms for critical workloads, including hosted virtualized environments, should prioritize patching.

Updated Aug 23, 2026 · CVSS 9.8

kubernetesmulti-clustersubmarinerlighthouseprivilege-escalationopenshiftcluster-federationagent-relevant

A critical vulnerability in Lighthouse (Submariner's multi-cluster service discovery component) allows an attacker who has compromised a spoke cluster to inject malicious EndpointSlices and ServiceImports into arbitrary namespaces on peer clusters, including sensitive system namespaces. This can lead to traffic hijacking, privilege escalation, and broader compromise of federated Kubernetes/OpenShift environments.

Updated Aug 23, 2026 · CVSS 9.9

windowslolbinlolbin-driverkernel-exploitdefenderedr-evasionliving-off-the-landprivilege-escalationagent-relevant

Check Point Research disclosed a technique abusing Microsoft Defender's own legitimately signed boot-time remediation driver (BTR.sys) to perform arbitrary kernel-level file and registry operations on Windows systems, including deletion of security software at boot. Because BTR.sys is Microsoft-signed and no external or malicious driver is introduced, the technique bypasses driver-signature enforcement and many endpoint protections, affecting Windows 7 through Windows 11 25H2.

Updated Aug 22, 2026

windows-updatecompatibility-issuergb-softwarenon-securitybug

Microsoft has identified that games crashing or failing to launch after installing the August 2026 Windows updates may be caused by conflicts with RGB lighting peripheral software rather than a security vulnerability. This is a functional compatibility bug affecting gaming systems, not a cybersecurity threat.

Updated Aug 22, 2026

awscredential-exposurecloud-securitysecrets-managementapi-keysagent-relevant

Over 9,300 AWS access keys publicly exposed between August 2022 and August 2026 remain active and valid, granting attackers full control over corporate AWS accounts. These leaked credentials likely originate from hardcoded secrets in public repositories, misconfigured applications, or logging errors, posing an ongoing risk of account takeover, data theft, and resource abuse.

Updated Aug 22, 2026

kubernetesmulti-clustersubmarinernetwork-hijacktraffic-interceptioncloud-nativeagent-relevant

A critical vulnerability in Submariner, a multi-cluster Kubernetes networking tool, allows a malicious spoke cluster to advertise arbitrary and unvalidated network subnets to peer clusters. This enables the attacker to hijack traffic intended for legitimate destinations, rerouting it through an attacker-controlled tunnel for interception, disruption, or man-in-the-middle attacks across the federated cluster mesh.

Updated Aug 22, 2026 · CVSS 9.9

IBMAIXPowerVMVIOSfile-overwriteinput-validationremote-attack

A critical vulnerability (CVE-2026-16926) affects IBM AIX 7.2, 7.3, and PowerVM VIOS 4.1, allowing remote attackers to overwrite arbitrary files due to improper input sanitization. With a CVSS score of 9.1, this flaw poses significant risk to enterprise Unix/virtualization environments running on IBM Power hardware.

Updated Aug 22, 2026 · CVSS 9.1

kubernetesrbacprivilege-escalationcluster-adminopenshiftoperatoragent-relevant

The search-v2-operator, commonly deployed in Kubernetes/OpenShift environments (e.g., Red Hat Advanced Cluster Management), is provisioned with a ClusterRole granting effectively cluster-admin level permissions. This over-privileged configuration allows the operator or any workload/service account leveraging it to impersonate users, forge RBAC bindings, approve CSRs, and manage ManifestWork objects, enabling full cluster takeover.

Updated Aug 22, 2026 · CVSS 9.9

iotrouterbuffer-overflowrcepublic-exploitnvramcgi

A critical stack-based buffer overflow vulnerability exists in TRENDnet TEW-823DRU routers (firmware 1.1.02b01) due to unsafe use of strcpy on the wan_l2tp_password parameter in /cgi-bin/wan.cgi. The flaw is remotely exploitable without complex prerequisites, and public exploit code is already available, making it an immediate risk for internet-exposed or compromised-network devices.

Updated Aug 22, 2026 · CVSS 9.9

rcen8ngogsworkflow-automationai-assisted-exploitationsigned-driver-abuseliving-off-the-landagent-relevantself-hosted-tools

This roundup covers multiple distinct security issues, including a remote code execution flaw in the Gogs self-hosted Git service, a workflow-to-RCE chain in the n8n automation platform, abuse of signed drivers for defense evasion, and use of AI models (GLM-5.3) to assist in exploit research. Collectively these lower the barrier for attackers by chaining trusted functionality and legitimate software behaviors into compromise paths.

Updated Aug 21, 2026

ICSOTbuilding-automationcredential-exposureCWE-316local-privilegeJohnson-Controls

Johnson Controls Simplex Incident Manager versions up to V2.01 store user credentials, including passwords and authentication tokens, in cleartext within system memory. A local low-privileged attacker could extract these credentials using memory-dumping techniques, potentially gaining unauthorized access to the application and connected building automation systems. Johnson Controls has released patched version v2.01.01 to remediate the issue.

Updated Aug 21, 2026 · CVSS 5.8

TrueConfCISA-KEVunauthenticated-RCEmissing-authenticationvideo-conferencingremote-code-execution

TrueConf Server contains a missing authentication vulnerability that allows a remote, unauthenticated attacker with network access to port 4307/TCP to execute arbitrary scripts on the server. This flaw has been added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild, and requires urgent remediation ahead of the CISA-mandated due date of 2026-08-23.

Updated Aug 21, 2026

ai-safetyopenaireinforcement-learningmodel-traininginternal-controlsagent-relevantgovernance

OpenAI temporarily paused reinforcement learning (RL) training of its newest frontier models for two weeks to strengthen internal defenses and expand monitoring, citing growing risks as model capability increases. The move appears preventive, referencing a prior 'Hugging Face-like incident' as a cautionary precedent rather than disclosing an active breach or exploit.

Updated Aug 20, 2026