Skip to main content

Live Threat Intelligence Radar

Real-time global cyber threat intelligence and monitoring

Geographic Threat Distribution

Heat map of affected countries

Full map →
Threat density
037457
132 countries affected

Live Threat Feed

Real-time updates

LIVE

Threat Timeline

Trend analysis over time

Drag to select a custom date range
Hover over data points to see details • Click points to view threats for that date • Drag to zoom into a time period
Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

View Plans & PricingCompare all plans

API access activates after upgrading in Console -> Billing.

Custom feeds

Build private feeds with layered filters and curated intel views.

Automations + integrations

Email alerts, webhooks, Slack, and routes into SIEMs or MISPs.

API access (baseline limits)

Unlock API v1 access; subscriptions increase rate limits.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
threat-finder — Open SourceFREE CLI

Scan your servers for these threats

One command matches your running services against Radar by exact package (purl/CPE), with distro-backport-aware version checks. Bring your API key.

Get it on GitHub

Threat Intelligence Database

Comprehensive database with detailed analysis

View all →
Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Last 30 days

The SelectorsHub Chrome extension, used by approximately 400,000 users, has been found to open advertisement tabs selected by its server without any user interaction. The extension fetches ads from a server that can change the URLs dynamically without extension updates. It also collects cookies broadly and sends user selectors to a domain that currently redirects to a gambling site. This behavior resembles adware and poses privacy and security concerns, especially for users in sensitive environments.

Join the discussion

CVE-2026-93326 is a medium severity vulnerability in moby BuildKit where a specially crafted Git build step can bypass some policy validation rules by making the repository appear to come from a different remote URL during Git clone. However, stricter validations based on commit SHA, commit data, or signatures remain effective.

Join the discussion

CVE-2026-71297 is a vulnerability in Red Hat Multicluster Engine for Kubernetes affecting the maestro gRPC broker. It allows a remote attacker with a valid client certificate to bypass authentication. This enables unauthorized subscription to other consumers' event streams and the ability to publish forged agent status, potentially leading to information disclosure and data integrity compromise. The vulnerability has a medium severity with a CVSS score of 5.4. No affected versions or patch information are explicitly provided in the available data.

Join the discussion

CVE-2026-105767 is an OS command injection vulnerability in the integrate-platform-docs composite GitHub Action of Chainguard Academy (edu). The flaw arises from improper neutralization of special elements in inputs used directly in Bash gcloud storage cp commands. This allows an actor controlling the project_id or storage_bucket inputs to execute arbitrary shell commands on the GitHub Actions runner. However, the only known caller passes repository secrets and runs on trusted triggers, so untrusted inputs were not known to reach the vulnerable code. The CVSS score is low (2.1).

Join the discussion

CVE-2026-105766 is a low-severity vulnerability in Chainguard Academy (edu) involving cleartext transmission of sensitive information. The issue arises from the use of the $scheme variable in nginx.conf for trailing-slash directory redirects, which causes HTTPS requests for slashless directory paths to be redirected to HTTP URLs. This occurs because TLS terminates at the load balancer, and the redirect response uses HTTP, exposing content to on-path attackers. Browsers with HSTS preload support for the .dev domain are not affected, but clients without HSTS enforcement, such as command-line HTTP clients and scripts, are vulnerable.

Join the discussion

CVE-2026-105392 is a medium severity vulnerability in Lybbn Django-Vue-Lyadmin up to version 3.2.12. It involves the use of a hard-coded cryptographic key in the JWT signing component, specifically related to the SECRET_KEY argument in backend/application/settings.py. This flaw allows remote attackers to exploit the system. The project maintainer advises developers to manually change the default keys before deployment to mitigate the issue.

Join the discussion

A path traversal vulnerability (CWE-35) was identified in the Ghost content management system versions 6.14.0 through 6.26.0. This flaw allowed staff users to access local files outside the intended data storage directories on the server. The issue was addressed and fixed in version 6.27.0. The vulnerability has a low severity with a CVSS score of 3.8.

Join the discussion

CVE-2026-105389 is a medium severity vulnerability in feelcrm-os version 1.0.0 that allows remote attackers to perform unrestricted file uploads via manipulation of the 'cmd' argument in the UploadTicketFile endpoint. The vulnerability exists in the file UploadController.class.php. The issue was reported early to the project but has not yet received a response or patch. Exploit details have been publicly disclosed, but no known active exploitation in the wild has been confirmed.

Join the discussion

A Server-Side Request Forgery (SSRF) vulnerability exists in the Ghost content management system versions from 1.18.0 up to but not including 6.27.0. This flaw affects the webhooks feature and allows staff users to make the Ghost server send requests to internal hosts. The vulnerability has a low severity score and is fixed in version 6.27.0.

Join the discussion

A vulnerability in Ghost, a Node.js content management system, allowed unauthorized access to comments due to improper input validation. This issue affected versions from 5.9.0 up to but not including 6.44.1 and was fixed in version 6.44.1. The vulnerability is classified under CWE-943, indicating improper neutralization of special elements in data query logic. The CVSS 3.1 score is 6.5, reflecting a medium severity with high confidentiality impact but no integrity or availability impact.

Join the discussion

Showing 1 to 10 of 18479 results

Page 1 of 1848
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses