Other Conventional Threats

Other conventional threat types

Showing 161–180 of 390 threats, newest first

weekly-recapsupply-chainzero-dayMCPagent-relevantrouter-backdoorAI-security

This week's roundup highlights a Metabase zero-day, supply-chain attacks targeting Model Context Protocol (MCP) tooling used in AI agent ecosystems, and backdoors found in consumer/enterprise routers. The report is an aggregated digest rather than a single incident, but the MCP supply-chain angle is directly relevant to organizations deploying AI agents and LLM tool-use frameworks.

Updated Aug 11, 2026

vendor-contentnot-a-threatapplication-securitydevsecopsAI-generated-codeinformational

This item is promotional content advertising a webinar about managing security risks introduced by AI-accelerated software development, rather than an active threat, vulnerability, or campaign. It highlights a legitimate industry concern: as AI coding assistants increase code output volume, security teams may struggle to keep pace with vulnerability review, dependency management, and risk prioritization.

Updated Aug 11, 2026

product-launchai-security-toolingvulnerability-researchpentestingnot-a-threatagent-relevant

This is a product announcement rather than an active threat: OpenAI has released 'GPT-5.6 Cyber,' a specialized model for vulnerability research, penetration testing, incident response, and remediation, gated to approved users. The release has security implications for both defenders and potential misuse by threat actors if access controls are bypassed or credentials are compromised.

Updated Aug 11, 2026

OTICScritical-infrastructureenergyAPNcellular-networkremote-accessindustrial-control-systems

Hackers breached the operational technology (OT) network of a small Polish heat-and-power plant serving approximately 50,000 residents by exploiting a private Access Point Name (APN) used for remote cellular connectivity. The incident, disclosed as having occurred the prior year, highlights how insufficiently secured private cellular networks can serve as an overlooked pathway into critical infrastructure control systems.

Updated Aug 11, 2026

SAPcommand-injectionRCEmanufacturinginput-validationcritical-infrastructure

A critical command injection vulnerability affects SAP Manufacturing Integration and Intelligence (MII), allowing a high-privileged attacker to submit crafted input that is insufficiently validated, leading to arbitrary OS command execution. Exploitation could fully compromise confidentiality, integrity, and availability of the affected system. Organizations running SAP MII in manufacturing or industrial environments should prioritize patching.

Updated Aug 11, 2026 · CVSS 9.1

kubernetesauthentication-bypassprivilege-escalationmaasmulti-tenancyagent-relevantai-infrastructureapi-security

CVE-2026-14450 is a critical authentication bypass vulnerability in the Model-as-a-Service (MaaS) API layer fronted by Kuadrant's AuthPolicy gateway. Any pod within the affected Kubernetes cluster can forge the X-MaaS-Username and X-MaaS-Group HTTP headers, which are trusted verbatim without first-party verification, enabling full cross-tenant privilege escalation. This allows attackers to mint ServiceAccount tokens in other tenants' namespaces, revoke arbitrary API keys, and exfiltrate model access configuration data.

Updated Aug 11, 2026 · CVSS 9.9

routercommand-injectiontelnetfirmwarerceiotnetwork-device

A critical command injection vulnerability exists in the TelnetSSH configuration function of MSI Radix AXE6600 router firmware v781521, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This flaw could be leveraged to fully compromise home and small-office network infrastructure, enabling traffic interception, lateral movement, or botnet recruitment.

Updated Aug 11, 2026 · CVSS 9.8

routercommand-injectionrcesshfirmwarenetwork-deviceunauthenticated

A critical command injection vulnerability exists in the TelnetSSH configuration function of MSI Radix AXE6600 routers running firmware v781521, allowing remote attackers to execute arbitrary commands with root privileges. Given the CVSS score of 9.8, this flaw is likely remotely exploitable without authentication, making affected devices prime targets for botnet recruitment, traffic interception, or use as network pivot points.

Updated Aug 11, 2026 · CVSS 9.8

prompt-injectionagent-relevantAI-securitydata-exfiltrationAtlassianindirect-prompt-injectionRAGLLM-tool-use

Security researchers demonstrated that Atlassian's Rovo AI assistant can be manipulated via attacker-controlled content (e.g., uploaded files or embedded instructions) to collect Jira and Confluence data accessible to a signed-in user and exfiltrate it to an external server. Two independent research teams found separate exploitation paths; only one has been confirmed remediated by Atlassian.

Updated Aug 10, 2026

sharepointgovernmentdata-breachaccount-compromiseon-premises

Switzerland's Federal Office of Information Technology disclosed that attackers exploited vulnerabilities in on-premises Microsoft SharePoint servers to compromise roughly 200 government accounts. The incident highlights ongoing risks tied to unpatched or exposed SharePoint deployments within critical government infrastructure.

Updated Aug 10, 2026

routercommand-injectionrcefirmwareiotunauthenticatednetwork-infrastructure

A critical command injection vulnerability exists in the alg function of MSI Radix AXE6600 router firmware v781521, allowing remote attackers to execute arbitrary commands with root privileges. With a CVSS score of 9.8, this flaw could enable full device takeover, network pivoting, and traffic interception on affected routers.

Updated Aug 10, 2026 · CVSS 9.8

routercommand-injectionrceiotfirmwareunauthenticated-rce

A critical unauthenticated command injection vulnerability (CVE-2026-71986) exists in the dmz function of MSI Radix AXE6600 router firmware v781521, allowing remote attackers to execute arbitrary commands and gain root access. With a CVSS score of 9.8, this flaw poses severe risk to any network relying on the affected device for perimeter security or connectivity.

Updated Aug 10, 2026 · CVSS 9.8

routercommand-injectionrcefirmwareiotnetwork-deviceunauthenticated

A critical unauthenticated command injection vulnerability exists in the wps.cgi interface of MSI Radix AXE6600 routers running firmware v781521. Remote attackers can inject malicious commands via the pin2g, pin5g, or pin6g parameters to achieve arbitrary command execution with root privileges. This flaw can allow full device takeover, enabling network-level man-in-the-middle attacks, traffic interception, and pivoting into internal networks.

Updated Aug 10, 2026 · CVSS 9.8

webmailcss-injectionphishingcredential-theftui-redressagent-relevantemail-security

PortSwigger researcher Gareth disclosed a class of CSS-based attacks that allow content embedded in an email to escape its intended message boundary and manipulate the surrounding webmail interface. Affecting Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail, the techniques can capture passwords, hijack trusted UI elements, leak session tokens, take over third-party accounts, and manipulate AI tools that process email content.

Updated Aug 9, 2026

critical-infrastructureportstransportationoperational-disruptionIT-OT

The North Carolina Ports Authority confirmed a cyberattack that disrupted IT systems and slowed operations at the Port of Wilmington, Port of Morehead City, and Charlotte Inland Port. Details on the attack vector, threat actor, and data impact have not been publicly disclosed as of this report. The incident highlights ongoing risk to critical maritime and logistics infrastructure.

Updated Aug 9, 2026

wordpressplugin-vulnerabilityprivilege-escalationauthentication-bypassai-pluginagent-relevantunauthenticated-rce-equivalent

The AI Copilot – Content Generator WordPress plugin (versions up to 1.5.6) contains an authorization bypass vulnerability allowing unauthenticated attackers to create administrator accounts and fully take over affected sites. The flaw stems from a nonce value being exposed in publicly accessible JavaScript, rendering the plugin's authorization check ineffective on any page rendering the [aiwu-form] shortcode or public chatbot.

Updated Aug 9, 2026 · CVSS 9.8

data-breachhealthcarepii-exposurethird-party-risk

Unlimited Technology Systems, a healthcare software company, disclosed a data breach affecting more than 3.8 million individuals stemming from an incident that occurred in October 2025. Details on the specific attack vector, threat actor, and exact data types exposed remain limited in public reporting.

Updated Aug 8, 2026

aviationicsotprotocol-vulnerabilitydosmessage-injectionradio-frequencycritical-infrastructure

Five vulnerabilities in the Controller-Pilot Data Link Communications (CPDLC) protocol over ATN-B1, used for aircraft-air traffic control text communications, allow unauthenticated message injection, denial-of-service, and forced session resets via unauthenticated clear-text radio frequency links. While not creating an unsafe aircraft condition directly, exploitation can degrade operational safety margins by increasing controller/pilot workload, delaying safety-critical instructions, and reducing situational awareness. No public exploitation has been observed, and attack complexity is high, requiring lab-like conditions.

Updated Aug 8, 2026 · CVSS 7.1

dellopenmanageauthentication-bypassserver-managementunauthenticated-accessremote-exploit

CVE-2026-56793 is an improper authentication vulnerability in Dell OpenManage Server Administrator (OMSA) affecting versions prior to 11.1.0.2. An unauthenticated remote attacker could exploit this flaw to gain unauthorized access to server management interfaces, potentially leading to further compromise of underlying infrastructure.

Updated Aug 8, 2026 · CVSS 7.7

azurecloudprivilege-escalationnetwork-securitysqlagent-relevant

CVE-2026-62836 is a high-severity vulnerability in Azure SQL Managed Instance caused by improper restriction of communication channels to intended endpoints. An unauthorized attacker could exploit this over the network to elevate privileges without prior authentication, potentially gaining unauthorized access to sensitive data and control over database resources.

Updated Aug 8, 2026 · CVSS 8.7