Other Conventional Threats

Other conventional threat types

Showing 101–120 of 390 threats, newest first

data-breachcloud-providerjapancustomer-data-exposurethird-party-riskagent-relevant

Sakura Internet, a major Japanese cloud and data center provider, disclosed unauthorized access to its sales management system, exposing contract and membership data for up to 1.36 million accounts. The breach affects a company that provides hosting and cloud infrastructure to numerous business customers, raising downstream exposure concerns.

Updated Aug 20, 2026

outageavailabilityopenaichatgptagent-relevant

OpenAI confirmed a major outage affecting ChatGPT, with users unable to log in, sign up, or access previous conversations. The incident appears to be a service availability failure rather than a security breach or exploitation of a vulnerability.

Updated Aug 20, 2026

ICSOTSCADAPLCSiemensS7commcritical-infrastructureAI-generated-exploitsreconnaissanceCISA-advisory

NSA, CISA, FBI, DOE, and EPA have issued a joint advisory warning of active threat actor targeting of Internet-exposed Siemens S7 Series PLCs (S7-200 through S7-1500) across U.S. critical infrastructure sectors. Threat actors are using AI-assisted development to rapidly generate exploitation scripts—built on the open-source snap7/python-snap7 library—that masquerade as legitimate OT monitoring tools to gain read/write access via the S7comm protocol, likely as reconnaissance and pre-positioning for future disruptive operations.

Updated Aug 20, 2026

oracleposhospitalityunauthenticated-rcecve-2026-60591network-exploitabledos

CVE-2026-60591 is a critical, easily exploitable vulnerability in Oracle Hospitality Simphony POS software that allows unauthenticated attackers with network access to compromise data integrity and availability. Affected versions span 19.8 through 19.10.1, and successful exploitation can result in unauthorized data modification/deletion and denial of service. Organizations using Simphony in restaurant, hotel, or retail point-of-sale environments should prioritize patching due to the low complexity and lack of authentication required for exploitation.

Updated Aug 20, 2026 · CVSS 9.1

extortionsocial-engineeringransomware-affiliatesecondary-extortionfraud

A threat actor group calling itself 'Ransom Busters' is contacting organizations previously victimized by ransomware attacks, falsely claiming to have hacked the original ransomware operators' infrastructure and offering to delete stolen data for a fee of $20,000 to $60,000. This appears to be a secondary extortion scam preying on already-compromised victims rather than a legitimate data recovery or threat actor takedown service.

Updated Aug 19, 2026

security-controlsdetection-gapvendor-reportbehavioral-testingbreach-attack-simulationdefense-validation

This is a vendor research report (Picus Security's Blue Report 2026) rather than an active threat, highlighting that security controls often block well-known attack signatures but fail to detect variant or behavioral approaches achieving the same malicious objective. The report underscores the need for continuous behavioral and adversarial testing rather than relying solely on signature- or IOC-based defenses.

Updated Aug 19, 2026

product-announcementiotprivacyconsumer-technot-a-threat

This is a product feature announcement, not a security threat. Comcast is rolling out WiFi-based motion sensing (using channel state information from existing routers/wireless devices) as part of its Xfinity Shield home security platform, enabling presence/motion detection without dedicated cameras or sensors.

Updated Aug 19, 2026

CISAMalcolmnetwork-traffic-analysisRCEpath-traversalauthorization-bypassdenial-of-servicefile-uploadRBAC-bypasszip-bombagent-relevant

Multiple vulnerabilities have been disclosed in CISA's Malcolm network traffic analysis tool suite, including an unauthenticated-adjacent arbitrary PHP code execution flaw (CVE-2026-55676, CVSS 8.8), two nginx/Lua RBAC bypasses via URI normalization mismatches (CVE-2026-63177, CVE-2026-19670), a path traversal in archive extraction (CVE-2026-63134), and two resource-exhaustion/DoS flaws involving malicious archives and decompression bombs (CVE-2026-63133, CVE-2026-19671). Versions prior to 26.06.1/26.07.0/26.08.0 depending on the specific CVE are affected, with vendor patches available and no known public exploitation reported at this time.

Updated Aug 19, 2026 · CVSS 8.8

ICSindustrial-control-systemssiemensbuffer-overflowlocal-code-executionengineering-softwareCWE-121

Siemens Simcenter Femap and Simcenter Nastran versions prior to V2606 contain a stack-based buffer overflow vulnerability triggered when an application binary parses a malicious string as a file argument. Successful exploitation could allow an attacker to achieve remote code execution in the context of the current process, though exploitation requires user interaction (tricking a user into running the binary with a crafted argument).

Updated Aug 19, 2026 · CVSS 7.8

iotfirmwarebuffer-overflowremote-code-executioncameraunpatched-deviceexploit-published

A critical remotely exploitable stack-based buffer overflow has been discovered in TRENDnet TV-IP751WIC IP cameras running firmware 11.03.03, affecting multiple configuration-handling functions within the alphapd web server component. A public exploit exists, and given the device's end-of-life status, no vendor patch is expected, leaving all deployed units permanently vulnerable to remote compromise.

Updated Aug 19, 2026 · CVSS 9.9

privilege-escalationcmsbroken-access-controlgravweb-applicationagent-relevant

Grav CMS before version 2.0.14 contains a broken access control flaw in the admin plugin's group blueprint, allowing a low-privileged delegated admin.users operator to modify the access field and grant themselves super-admin rights. This enables full administrative takeover of the Grav instance, including scheduler and Twig template evaluation capabilities that can be leveraged for remote code execution.

Updated Aug 19, 2026 · CVSS 9.1

xssstored-xssosint-toolingcredential-theftapi-key-exposureweb-application-securityagent-relevant

SpiderFoot fails to sanitize correlation titles derived from untrusted external scan data such as server banners and metadata, allowing attackers to inject malicious HTML/JavaScript. When an operator views the correlations dashboard, the injected script executes in their browser session, potentially exfiltrating stored API keys and session tokens.

Updated Aug 19, 2026 · CVSS 9.3

outageavailabilitygithubthird-party-dependencyagent-relevant

GitHub experienced a widespread outage affecting its website, API, Actions, Pull Requests, and other core services. This is a service availability incident rather than a malicious attack, but it disrupts development workflows, CI/CD pipelines, and any automated systems dependent on GitHub's infrastructure.

Updated Aug 18, 2026

data-breachthird-party-risksupply-chainretaillogisticsPII-exposure

Pokémon Center notified customers in the UK and Germany of a data breach involving their personal and order information, caused by a compromise at third-party logistics provider CEVA Logistics. The breach resulted in exposure of customer data and led to the cancellation of some pending orders, highlighting risks inherent in outsourced fulfillment operations.

Updated Aug 18, 2026

credential-theftcloud-securitydata-breachazureidentity-compromiseagent-relevant

A threat actor claims to be selling 3.6 million employee records allegedly exfiltrated from Microsoft Azure environments belonging to multiple Fortune 500 companies. The intrusion reportedly stemmed from compromised credentials rather than a platform vulnerability, highlighting ongoing risks around identity and access management in cloud tenants. The claim remains unverified but poses significant exposure risk if confirmed.

Updated Aug 18, 2026

wordpressplugin-vulnerabilityprivilege-escalationauthorization-bypasscve-2026-18432

The Frontend Admin by DynamiApps WordPress plugin (versions up to 3.29.9) contains a critical privilege escalation vulnerability caused by a flawed authorization check that can be bypassed with a non-numeric user ID value. Attackers, in some configurations even unauthenticated, can exploit this to gain administrator access by hijacking the default admin account's password or email. Given the 9.8 CVSS score and low exploitation complexity, this vulnerability poses a severe risk to any WordPress site running the affected plugin.

Updated Aug 18, 2026 · CVSS 9.8

routeriotauthentication-bypassunauthenticated-accesspublic-exploitnetwork-perimeter

A critical improper authentication vulnerability has been identified in the httpd component of Tenda AC10 routers running firmware 16.03.10.09_multi_TDE01, specifically within the R7WebsSecurityHandler function. The flaw allows a remote, unauthenticated attacker to bypass authentication controls, and a public exploit is already available, significantly raising the likelihood of active exploitation.

Updated Aug 18, 2026 · CVSS 9.8

ddosmessagingavailabilitythreemanetwork-attack

Threema, a secure messaging service, suffered multiple large-scale DDoS attacks that caused severe disruptions to user communications. The attacks appear focused on service availability rather than data compromise, with no evidence of encryption bypass or user data exposure reported.

Updated Aug 17, 2026

outageavailabilityanthropicclaudeagent-relevant

Anthropic's Claude AI service experienced a major outage affecting multiple services, with users reporting login failures and degraded performance. This is an availability incident rather than a confirmed malicious cyberattack, though the root cause has not been publicly disclosed.

Updated Aug 17, 2026

data-breachcryptocurrencyhardware-walletPII-exposuredark-web-sale

Cryptocurrency hardware wallet vendor SafePal disclosed a data breach affecting approximately 39,798 customers after an application flaw was exploited to exfiltrate customer order information. A threat actor is now advertising the stolen data for sale on underground forums, raising risk of targeted phishing and social engineering against affected customers.

Updated Aug 17, 2026