Skip to main content

Live Threat Intelligence Radar

Real-time global cyber threat intelligence and monitoring

Geographic Threat Distribution

Heat map of affected countries

Full map →
Threat density
037457
132 countries affected

Live Threat Feed

Real-time updates

LIVE

Threat Timeline

Trend analysis over time

Drag to select a custom date range
Hover over data points to see details • Click points to view threats for that date • Drag to zoom into a time period
Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

View Plans & PricingCompare all plans

API access activates after upgrading in Console -> Billing.

Custom feeds

Build private feeds with layered filters and curated intel views.

Automations + integrations

Email alerts, webhooks, Slack, and routes into SIEMs or MISPs.

API access (baseline limits)

Unlock API v1 access; subscriptions increase rate limits.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
threat-finder — Open SourceFREE CLI

Scan your servers for these threats

One command matches your running services against Radar by exact package (purl/CPE), with distro-backport-aware version checks. Bring your API key.

Get it on GitHub

Threat Intelligence Database

Comprehensive database with detailed analysis

View all →
Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Last 30 days

Stored cross-site scripting (XSS) vulnerabilities in the Ninja Forms and WPC Product Bundles for WooCommerce WordPress plugins are being exploited to install backdoors and create rogue administrator accounts. The attacks deliver malicious JavaScript payloads that execute in the context of authenticated administrators, allowing the installation of a malicious plugin and creation of hidden admin accounts. These backdoors persist even after removal of the malicious plugin. The vulnerabilities require an authenticated session to exploit and affect Ninja Forms versions 3.15.3 and older and WPC Product Bundles for WooCommerce versions 8.6.6 and older. Site administrators are advised to upgrade to Ninja Forms 3.15.4 or later and WPC Product Bundles for WooCommerce 8.6.7 or later. Existing infections require manual cleanup as updates do not remove backdoors.

HighVulnerability#wordpress#xss
Join the discussion

CVE-2026-106586 is a low-severity vulnerability in OpenSSH versions before 10.6 where the 'restrict' keyword in authorized_keys did not apply to tunnel forwarding as intended. This represents an incorrect control flow implementation issue distinct from CVE-2026-73283.

Join the discussion

CVE-2026-106585 is a vulnerability in OpenSSH versions before 10.6 where the sshd and ssh components do not verify if the maximum packet length is exceeded during decompression of highly compressed data. This improper handling can lead to data amplification issues. The vulnerability has a medium severity with a CVSS score of 6.5.

Join the discussion

An off-by-one error (CWE-193) in ssh-keygen in OpenSSH versions before 10.6 causes certificates to have incorrect expiration times due to mishandling of Daylight Saving Time. This issue may have a slightly more severe impact on users in some Antarctic locations. The vulnerability has a low CVSS score of 2.5 and does not affect confidentiality or availability, only integrity to a limited extent.

Join the discussion

Bulletin ID: 2026-127-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/06/2026 13:30 PM PDT Description: bedrock-agentcore-starter-toolkit is an AWS-maintained open-source Python package, distributed via GitHub and PyPI, that provides a command-line interface for importing Amazon Bedrock Agents into local development environments. We identified CVE-2026-105812, a code injection issue that could allow arbitrary code execution when a specially crafted agent is imported and subsequently run or deployed, and CVE-2026-106032, an external reference handling issue that could cause unintended network requests or local file access during agent import. Affected versions: >= 0.1.4 and <= 0.3.13 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

Join the discussion

CVE-2026-104045 is a vulnerability in the System Security Services Daemon (SSSD) component of Red Hat Enterprise Linux 10. It involves a race condition in the autofs responder between asynchronous enumeration completion and map invalidation. A local user can exploit this flaw to cause a denial of service by triggering excessive memory consumption, potentially disrupting or crashing the autofs service.

Join the discussion

CVE-2026-106582 is a low-severity vulnerability in OpenSSH versions before 10.6 where the use of an LZ77 dictionary coder creates a covert channel, contrary to findings in the research paper arXiv 2609.07709 "Crossing the Streams." This vulnerability affects OpenSSH's sshd and ssh components.

Join the discussion

CVE-2026-106032 is a server-side request forgery (SSRF) vulnerability in the OpenAPI schema processing of the agent import functionality in Amazon Bedrock AgentCore Starter Toolkit versions 0.1.4 through 0.3.13. An authenticated remote actor within the same AWS account can exploit this flaw to cause the environment of a user importing a Bedrock Agent to make arbitrary outbound requests and read arbitrary local files. The issue is fixed in version 0.3.14. The affected toolkit is deprecated, and users are recommended to migrate to the supported replacement @aws/agentcore CLI, which does not contain this vulnerability.

Join the discussion

CVE-2026-106555 is a low-severity vulnerability in OpenSSH versions before 10.6 where the GSSAPIAuthentication state can be incorrectly persisted across authentication attempts in sshd. This issue relates to improper resource transfer between security spheres, potentially allowing authentication state leakage. The vulnerability has a CVSS score of 2.2, indicating low impact, with limited confidentiality impact and no integrity or availability impact reported.

Join the discussion

CVE-2026-106553 is a low severity vulnerability in OpenSSH versions before 10.6 where credentials may incorrectly persist after a failed GSSAPIAuthentication attempt. This issue relates to improper resource handling in sshd, potentially allowing credential persistence beyond intended scope.

Join the discussion

Showing 1 to 10 of 19222 results

Page 1 of 1923
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses