Live Threat Intelligence Radar
Real-time global cyber threat intelligence and monitoring
Geographic Threat Distribution
Heat map of affected countries
Live Threat Feed
Real-time updates
Threat Timeline
Trend analysis over time
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds
Build private feeds with layered filters and curated intel views.
Automations + integrations
Email alerts, webhooks, Slack, and routes into SIEMs or MISPs.
API access (baseline limits)
Unlock API v1 access; subscriptions increase rate limits.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Scan your servers for these threats
One command matches your running services against Radar by exact package (purl/CPE), with distro-backport-aware version checks. Bring your API key.
Threat Intelligence Database
Comprehensive database with detailed analysis
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.16.0 until 3.0.14, ThreadSafeCookieStore incompletely validates cookie Domain attributes. Missing private-section and default public-suffix rules, absent A-label normalization, locale-sensitive lowercasing, public-suffix host-only handling, and numeric or IP host checks allow one origin to store a cookie later sent to another origin. Applications sharing one client across trust domains can therefore receive attacker-injected cookies and may be exposed to session fixation. This issue is fixed in version 3.0.14. Join the discussion | CVE Database V5 | 10/07/2026, 20:57:36 UTC Added: 10/07/2026, 21:04:06 UTC |
0 AsyncHttpClient versions from 2.1.0 up to but not including 3.0.14 have an improper authentication vulnerability due to the enabled-by-default cookie store replacing explicitly set Cookie headers. This can cause requests to execute under the wrong user session by mixing cookies between users. The issue bypasses a previous fix that only covered cookies added via addCookie, not those set directly in headers. The vulnerability is fixed in version 3.0.14. Join the discussion | CVE Database V5 | 10/07/2026, 20:54:34 UTC Added: 10/07/2026, 21:04:06 UTC |
0 AsyncHttpClient versions from 2.2.0 up to but not including 3.0.14 have an uncontrolled resource consumption vulnerability in WebSocket permessage-deflate decompression. When compression is enabled, the decompression process is unbounded, allowing a malicious WebSocket peer to send a small compressed message that expands to a very large buffer, potentially exhausting JVM heap memory. This issue is fixed in version 3.0.14. Join the discussion | CVE Database V5 | 10/07/2026, 20:51:04 UTC Added: 10/07/2026, 21:04:06 UTC |
Hackers compromised third-party operators managing the authoritative DNS records for the country-code top-level domains (ccTLDs) of Ghana (.GH), American Samoa (.AS), and Sierra Leone (.SL). By modifying these DNS records, attackers were able to obtain unauthorized HTTPS certificates for several Google domains and other organizations' domains within these ccTLDs. This allowed them to hijack domains, redirect traffic to attacker-controlled infrastructure, and impersonate legitimate brands. Google confirmed its own systems were not compromised and worked with certificate authorities to revoke the fraudulent certificates and block them in Chrome. The incident highlights risks associated with third-party DNS registry security and certificate issuance processes. HighNews Join the discussion | Bleeping Computer | 10/07/2026, 20:50:13 UTC Added: 10/07/2026, 21:03:25 UTC |
CVE-2026-76286 affects Splunk MCP Server versions 1.2 up to but not including 1.2.1. The vulnerability allows a user with the mcp_tool_execute capability to run a custom API tool that sends the user's Splunk platform authentication token to a URL controlled by another user. This can lead to token theft and unauthorized access to data and actions as the original user. The issue arises because the server does not sufficiently verify that the URL request is sent to the expected destination. Join the discussion | CVE Database V5 | 10/07/2026, 20:46:40 UTC Added: 10/07/2026, 21:04:11 UTC |
CVE-2026-76285 concerns multiple internally identified vulnerabilities in Splunk Enterprise related to improper adherence to coding standards. These weaknesses can lead to increased severity or resultant vulnerabilities. The affected versions include 9.4 up to but not including 9.4.15, 10.0 up to but not including 10.0.10, 10.2 up to but not including 10.2.7, and 10.4 up to but not including 10.4.3. Splunk has addressed these issues in the specified fixed versions. Join the discussion | CVE Database V5 | 10/07/2026, 20:46:39 UTC Added: 10/07/2026, 21:04:11 UTC |
CVE-2026-76284 is a vulnerability in Splunk Enterprise where the product does not properly ensure that structured messages or data are well-formed and meet certain security properties before processing. This issue affects multiple versions of Splunk Enterprise and was addressed in versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. The vulnerability relates to improper neutralization of input data, potentially leading to security risks if exploited. Join the discussion | CVE Database V5 | 10/07/2026, 20:46:39 UTC Added: 10/07/2026, 21:04:11 UTC |
CVE-2026-76283 is a vulnerability in Splunk Enterprise involving a failure or incorrect use of protection mechanisms that defend against directed attacks. Multiple internally identified vulnerabilities were addressed in versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. The issue is grouped under a single CVE identifier but covers multiple weaknesses. No CVSS score or detailed exploit information is provided. Join the discussion | CVE Database V5 | 10/07/2026, 20:46:38 UTC Added: 10/07/2026, 21:04:11 UTC |
CVE-2026-76282 is a vulnerability in Splunk Enterprise involving improper control of a resource throughout its lifecycle. Multiple internally identified vulnerabilities were addressed in versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. The issue relates to the software not maintaining or incorrectly maintaining control over resources during creation, use, and release. Join the discussion | CVE Database V5 | 10/07/2026, 20:46:38 UTC Added: 10/07/2026, 21:04:11 UTC |
CVE-2026-76281 is an improper access control vulnerability in Splunk Enterprise that allows unauthorized actors to access restricted resources. Multiple internally identified vulnerabilities were addressed in versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. The issue affects several versions prior to these fixed releases. Join the discussion | CVE Database V5 | 10/07/2026, 20:46:37 UTC Added: 10/07/2026, 21:04:11 UTC |
Showing 1 to 10 of 19289 results