Skip to main content

Live Threat Intelligence Radar

Real-time global cyber threat intelligence and monitoring

Geographic Threat Distribution

Heat map of affected countries

Full map →
Threat density
037457
132 countries affected

Live Threat Feed

Real-time updates

LIVE

Threat Timeline

Trend analysis over time

Drag to select a custom date range
Hover over data points to see details • Click points to view threats for that date • Drag to zoom into a time period
Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

View Plans & PricingCompare all plans

API access activates after upgrading in Console -> Billing.

Custom feeds

Build private feeds with layered filters and curated intel views.

Automations + integrations

Email alerts, webhooks, Slack, and routes into SIEMs or MISPs.

API access (baseline limits)

Unlock API v1 access; subscriptions increase rate limits.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
threat-finder — Open SourceFREE CLI

Scan your servers for these threats

One command matches your running services against Radar by exact package (purl/CPE), with distro-backport-aware version checks. Bring your API key.

Get it on GitHub

Threat Intelligence Database

Comprehensive database with detailed analysis

View all →
Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Last 30 days

`download_wheel()` runs `pip download` and hands the result straight to the seeder, with nothing checking the bytes it gets back. The embedded pip and setuptools wheels carry a `BUNDLE_SHA256` that virtualenv checks on every load, but a wheel fetched over the network for the periodic-update feature or the `--download` flag had no equivalent verification. A compromised index, a stale mirror, or a MITM'd download (when TLS is intercepted, e.g. via a misconfigured or malicious CA) could substitute a different wheel under the same distribution/version/filename, and virtualenv would cache and seed it into every environment created afterward with no warning. Fixed by computing the downloaded wheel's sha256 and comparing it against the digest PyPI's public JSON API reports for that exact release, independent of which index actually served the file. The check is skipped, not treated as failure, when a custom index (`PIP_INDEX_URL`, `PIP_EXTRA_INDEX_URL`, `PIP_INDEX`) is configured, since a private index can legitimately serve a different, intentionally rebuilt wheel. Fix: https://github.com/pypa/virtualenv/pull/3251

Join the discussion

### Summary `pyvenv.cfg` is a line-based format with no escape syntax. `PyEnvCfg.write()` wrote values verbatim, while `PyEnvCfg._read_values()` parses the file with `str.splitlines()`. A value containing a line boundary therefore became additional configuration lines, and because reading is last-wins, the injected keys replaced any key written earlier in the file. ### Impact The `prompt` value is the reachable input: it is set by `--prompt`, by the `VIRTUALENV_PROMPT` environment variable, or from the config file, and `write()` emits `prompt` before `home`. A crafted prompt can therefore set `home` in the generated `pyvenv.cfg`: ```console $ virtualenv --prompt $'x"\nhome = /attacker/path\nprompt = "z' venv $ grep '^home' venv/pyvenv.cfg home = /attacker/path ``` `home` is what tooling reads to locate the base interpreter, so a consumer that trusts it can be pointed elsewhere. `implementation`, `version_info`, `version`, `executable`, `command` and `virtualenv` are also written before `prompt` and can be replaced the same way. This requires the prompt to come from somewhere other than the person running the command, for example a CI job templating a branch name into it, tooling deriving an environment name from user-supplied data, or an inherited `VIRTUALENV_PROMPT`. Where the operator supplies the prompt directly they already control the command line, and the effect is corruption rather than privilege gain: the value is truncated at the boundary and read back with a dangling quote. ### Details The boundary set is the one `str.splitlines()` recognizes, which is wider than `\n`: `\r`, `\v`, `\f`, the file, group and record separators, `U+0085`, `U+2028` and `U+2029` were all written through unchanged and all split the line when read back. ### Patches `PyEnvCfg.write()` now collapses those boundaries to spaces as it serializes each line, so it cannot emit a structurally invalid file regardless of what a caller places in `content`. ### Workarounds Do not pass externally influenced data as the virtualenv prompt. Strip line boundaries from any value before using it as `--prompt` or `VIRTUALENV_PROMPT`.

Join the discussion

The anthropic-sdk package version 0.1.0 on PyPI contains malicious code that downloads and executes a remote script. It fingerprints the environment to detect sandboxing and delays execution before exfiltrating sensitive data such as credentials, environment variables, AI chat files, and SSH keys. If HTTPS exfiltration fails, it attempts DNS-based data exfiltration. The package also uses DNS to control execution centrally.

Join the discussion

Mammoth.js versions from 1.3.0 up to but not including 1.12.3 contain a regular expression denial of service (ReDoS) vulnerability in the style map tokeniser. This vulnerability arises from overlapping regex alternatives in the lib/styles/parser/tokeniser.js component. An attacker can exploit this by supplying a crafted .docx file with an unterminated quoted string containing repeated backslash escapes, causing the Node.js event loop to block.

Join the discussion

CVE-2026-105218 is a critical vulnerability in the go-pay gopay library versions prior to 1.5.119. The flaw disables TLS certificate verification in the default HTTP client, allowing man-in-the-middle attackers to impersonate payment provider APIs. This enables attackers to intercept and modify sensitive merchant credentials, signatures, transaction data, and payment-related responses.

Join the discussion

CVE-2026-105217 is a vulnerability in Cockpit CMS versions 2.12.0 up to but not including 2.14.1 where TLS certificate verification is disabled in the cron.php web worker restart request. This allows network attackers performing man-in-the-middle attacks on the outbound connection to the site URL to present any certificate and capture the worker token, potentially enabling them to start the web worker.

Join the discussion

go-micro versions before 6.0.0 have an improper certificate validation vulnerability. The shared TLS helper sets InsecureSkipVerify to true by default, allowing network attackers to impersonate services. This enables man-in-the-middle attackers to present any certificate and intercept or modify gRPC transport, HTTP and RabbitMQ broker, and Consul or etcd registry traffic, including authentication tokens and credentials.

Join the discussion

A flaw has been found in invariant-systems-ai aiir up to 1.7.0. The affected element is an unknown function of the component Policy Gate Handler. Executing a manipulation can lead to improper verification of cryptographic signature. The attack can be executed remotely. It is advisable to upgrade the affected component. The GitHub repository of this project is not available anymore. This vulnerability only affects products that are no longer supported by the maintainer.

Join the discussion

YesWiki versions before 4.6.7 have a cross-site scripting (XSS) vulnerability in the Bazar valeur action. This flaw allows page editors to inject malicious scripts by rendering unescaped HTML fetched from a remote URL. Exploitation involves attackers directing the vulnerable script to a controlled server returning crafted markup that executes JavaScript in viewers' browsers. The vulnerability has a medium severity rating with a CVSS score of 5.4.

Join the discussion

CVE-2026-104402 is a medium severity vulnerability in farvisun Mindio Magic MCP (mindio-magic-mcp) versions up to 0.5.6. It involves the insertion of sensitive information into sent data, allowing retrieval of embedded sensitive data. The vulnerability has a CVSS 3.1 base score of 4.3, indicating a low impact on confidentiality with no impact on integrity or availability. No patch or remediation information is currently available.

Join the discussion

Showing 1 to 10 of 18556 results

Page 1 of 1856
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses