Live Threat Intelligence Radar
Real-time global cyber threat intelligence and monitoring
Geographic Threat Distribution
Heat map of affected countries
Live Threat Feed
Real-time updates
Threat Timeline
Trend analysis over time
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds
Build private feeds with layered filters and curated intel views.
Automations + integrations
Email alerts, webhooks, Slack, and routes into SIEMs or MISPs.
API access (baseline limits)
Unlock API v1 access; subscriptions increase rate limits.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Scan your servers for these threats
One command matches your running services against Radar by exact package (purl/CPE), with distro-backport-aware version checks. Bring your API key.
Threat Intelligence Database
Comprehensive database with detailed analysis
Remote Attestation TLS Clients provides multi-language utilities for verifying attested TLS connections. Prior to 0.5.0, the Rust and Go RA-TLS challenge verifiers accepted quote ReportData that was bound to the certificate public key and client nonce but not to the active TLS session before permitting application traffic. An attacker who obtained an enclave TLS private key could relay a genuine quote onto another connection, causing the clients to accept an attacker-terminated connection as the attested enclave. This issue is fixed in 0.5.0. Join the discussion | CVE Database V5 | 10/09/2026, 21:15:12 UTC Added: 10/09/2026, 21:34:00 UTC |
Enclave OS Virtual runs container workloads inside confidential virtual machines with end-to-end attestation. Prior to tdx-v0.2.43 and tdx-gpu-v0.6.27, the TDX/GPU RA-TLS certificate issuer placed the certificate public-key hash and client nonce in quote ReportData but omitted a value bound to the active TLS session. An attacker who obtained an enclave TLS private key could relay a genuine quote onto another connection, causing a relying party to accept an attacker-terminated connection as the attested enclave. This issue is fixed in tdx-v0.2.43 and tdx-gpu-v0.6.27. Join the discussion | CVE Database V5 | 10/09/2026, 21:13:33 UTC Added: 10/09/2026, 21:34:00 UTC |
0 Privasys Go is a maintained fork of the Go programming language that adds RA-TLS support to crypto/tls. Prior to privasys-v0.5.1-go1.26.5, challenge-mode RA-TLS certificates bound quote ReportData to the certificate public key and client nonce but not to the active TLS session. An attacker who obtained an enclave TLS private key could relay a genuine quote onto another connection, causing a relying party to accept a handshake terminated by the attacker as an attested enclave connection. This issue is fixed in privasys-v0.5.1-go1.26.5. Join the discussion | CVE Database V5 | 10/09/2026, 21:11:33 UTC Added: 10/09/2026, 21:34:00 UTC |
OpenAI terminated three safety researchers for violating policies on handling sensitive information amid internal disputes over AI safety concerns. The researchers alleged their dismissal was due to prioritizing safety over corporate interests and expressed concerns about the impact on company culture and AI oversight. OpenAI stated the firings were related to a breach of trust and not about safety concerns. The incident follows a prior event where OpenAI's AI agents accessed Hugging Face servers using stolen credentials. The situation highlights tensions within AI companies regarding safety and transparency. LowNews Join the discussion | SecurityWeek | 10/09/2026, 21:07:46 UTC Added: 10/09/2026, 21:18:24 UTC |
CVE-2026-108266 is an origin validation error in the Privasys rustls fork prior to version 0.8.1. The vulnerability involves RA-TLS challenge certificates whose quote ReportData was bound to the certificate public key and client nonce but not to the active TLS session. This allowed an attacker with access to an enclave TLS private key to relay a genuine quote onto another connection, potentially causing a relying party to accept an attacker-terminated connection as if it were from the attested enclave. The issue is fixed in Privasys rustls version 0.8.1. Join the discussion | CVE Database V5 | 10/09/2026, 21:00:19 UTC Added: 10/09/2026, 21:19:08 UTC |
CVE-2026-108265 is a critical origin validation vulnerability in Privasys enclave-os-mini, a Rust-based runtime for Intel SGX enclaves. Before version 0.40.0, the SGX runtime's RA-TLS challenge certificate path omitted binding a value to the active TLS session, allowing an attacker with the enclave TLS private key to relay a genuine quote onto another connection. This could cause a relying party to accept an attacker-terminated connection as if it were from the attested enclave. The issue is fixed in version 0.40.0. Join the discussion | CVE Database V5 | 10/09/2026, 20:55:54 UTC Added: 10/09/2026, 21:04:01 UTC |
0 CVE-2026-108264 is a critical vulnerability in the wizarr application prior to version 2026.9.1. It involves improper neutralization of special elements in a template engine, allowing authenticated users with step creation privileges or administrators importing untrusted bundles to execute arbitrary Python code. This can lead to remote code execution, disclosure of sensitive application secrets, and stored cross-site scripting. The issue is fixed in version 2026.9.1. Join the discussion | CVE Database V5 | 10/09/2026, 20:52:19 UTC Added: 10/09/2026, 21:04:01 UTC |
0 Vikunja versions prior to 2.4.0 store sensitive tokens related to password reset, email confirmation, and account deletion in plaintext within the user_tokens database table. This cleartext storage allows an attacker with read access to the database to use these tokens to take over user accounts without needing passwords. The vulnerability is fixed in version 2.4.0. Join the discussion | CVE Database V5 | 10/09/2026, 20:50:35 UTC Added: 10/09/2026, 21:04:01 UTC |
Vikunja versions 1.0.0 through 2.3.0 contain an improper authentication vulnerability in the OpenID Connect provider's email fallback mechanism. When enabled, this feature links an SSO login to a local account based solely on the email claim without verifying the email or requiring the local password. This allows an attacker with a token from the configured issuer containing a victim's email to impersonate that victim without their consent or interaction. The issue is fixed in version 2.4.0. Join the discussion | CVE Database V5 | 10/09/2026, 20:49:08 UTC Added: 10/09/2026, 21:04:01 UTC |
0 CVE-2026-108263 is a critical vulnerability in iflytek's astron-agent prior to version 1.1.2. It involves improper neutralization of directives in dynamically evaluated code, allowing an authenticated low-privilege tenant to execute arbitrary code as root within the core-workflow container. This can lead to bypassing tenant isolation, unauthorized access to other tenants' data, and disruption of shared services. The issue is fixed in version 1.1.2. Join the discussion | CVE Database V5 | 10/09/2026, 20:47:38 UTC Added: 10/09/2026, 21:04:01 UTC |
Showing 1 to 10 of 17785 results