Skip to main content

Live Threat Intelligence Radar

Real-time global cyber threat intelligence and monitoring

Geographic Threat Distribution

Heat map of affected countries

Full map →
Threat density
037454
132 countries affected

Live Threat Feed

Real-time updates

LIVE

Threat Timeline

Trend analysis over time

Drag to select a custom date range
Hover over data points to see details • Click points to view threats for that date • Drag to zoom into a time period
Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

View Plans & PricingCompare all plans

API access activates after upgrading in Console -> Billing.

Custom feeds

Build private feeds with layered filters and curated intel views.

Automations + integrations

Email alerts, webhooks, Slack, and routes into SIEMs or MISPs.

API access (baseline limits)

Unlock API v1 access; subscriptions increase rate limits.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
threat-finder — Open SourceFREE CLI

Scan your servers for these threats

One command matches your running services against Radar by exact package (purl/CPE), with distro-backport-aware version checks. Bring your API key.

Get it on GitHub

Threat Intelligence Database

Comprehensive database with detailed analysis

View all →
Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Last 30 days

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.16.0 until 3.0.14, ThreadSafeCookieStore incompletely validates cookie Domain attributes. Missing private-section and default public-suffix rules, absent A-label normalization, locale-sensitive lowercasing, public-suffix host-only handling, and numeric or IP host checks allow one origin to store a cookie later sent to another origin. Applications sharing one client across trust domains can therefore receive attacker-injected cookies and may be exposed to session fixation. This issue is fixed in version 3.0.14.

Join the discussion

AsyncHttpClient versions from 2.1.0 up to but not including 3.0.14 have an improper authentication vulnerability due to the enabled-by-default cookie store replacing explicitly set Cookie headers. This can cause requests to execute under the wrong user session by mixing cookies between users. The issue bypasses a previous fix that only covered cookies added via addCookie, not those set directly in headers. The vulnerability is fixed in version 3.0.14.

Join the discussion

AsyncHttpClient versions from 2.2.0 up to but not including 3.0.14 have an uncontrolled resource consumption vulnerability in WebSocket permessage-deflate decompression. When compression is enabled, the decompression process is unbounded, allowing a malicious WebSocket peer to send a small compressed message that expands to a very large buffer, potentially exhausting JVM heap memory. This issue is fixed in version 3.0.14.

Join the discussion

Hackers compromised third-party operators managing the authoritative DNS records for the country-code top-level domains (ccTLDs) of Ghana (.GH), American Samoa (.AS), and Sierra Leone (.SL). By modifying these DNS records, attackers were able to obtain unauthorized HTTPS certificates for several Google domains and other organizations' domains within these ccTLDs. This allowed them to hijack domains, redirect traffic to attacker-controlled infrastructure, and impersonate legitimate brands. Google confirmed its own systems were not compromised and worked with certificate authorities to revoke the fraudulent certificates and block them in Chrome. The incident highlights risks associated with third-party DNS registry security and certificate issuance processes.

HighNews
Join the discussion

CVE-2026-76286 affects Splunk MCP Server versions 1.2 up to but not including 1.2.1. The vulnerability allows a user with the mcp_tool_execute capability to run a custom API tool that sends the user's Splunk platform authentication token to a URL controlled by another user. This can lead to token theft and unauthorized access to data and actions as the original user. The issue arises because the server does not sufficiently verify that the URL request is sent to the expected destination.

Join the discussion

CVE-2026-76285 concerns multiple internally identified vulnerabilities in Splunk Enterprise related to improper adherence to coding standards. These weaknesses can lead to increased severity or resultant vulnerabilities. The affected versions include 9.4 up to but not including 9.4.15, 10.0 up to but not including 10.0.10, 10.2 up to but not including 10.2.7, and 10.4 up to but not including 10.4.3. Splunk has addressed these issues in the specified fixed versions.

Join the discussion

CVE-2026-76284 is a vulnerability in Splunk Enterprise where the product does not properly ensure that structured messages or data are well-formed and meet certain security properties before processing. This issue affects multiple versions of Splunk Enterprise and was addressed in versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. The vulnerability relates to improper neutralization of input data, potentially leading to security risks if exploited.

Join the discussion

CVE-2026-76283 is a vulnerability in Splunk Enterprise involving a failure or incorrect use of protection mechanisms that defend against directed attacks. Multiple internally identified vulnerabilities were addressed in versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. The issue is grouped under a single CVE identifier but covers multiple weaknesses. No CVSS score or detailed exploit information is provided.

Join the discussion

CVE-2026-76282 is a vulnerability in Splunk Enterprise involving improper control of a resource throughout its lifecycle. Multiple internally identified vulnerabilities were addressed in versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. The issue relates to the software not maintaining or incorrectly maintaining control over resources during creation, use, and release.

Join the discussion

CVE-2026-76281 is an improper access control vulnerability in Splunk Enterprise that allows unauthorized actors to access restricted resources. Multiple internally identified vulnerabilities were addressed in versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. The issue affects several versions prior to these fixed releases.

Join the discussion

Showing 1 to 10 of 19289 results

Page 1 of 1929
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses