Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-18674: CWE-345 Insufficient Verification of Data Authenticity in Kong Inc. Kong MeshCVE-2026-18674
0

On a Kong Mesh global control plane, resources received over the zone-to-global KDS sync are attributed using the in-band, sender-controlled ControlPlane.Identifier rather than the authenticated zone identity derived from the connection. Authenticated zones can have the global control plane store and re-distribute those resources as belonging to another zone. The result is a cross-zone isolation bypass: the holder of a single enrolled zone's credential can inject, attribute, and overwrite resources in another zone's namespace mesh-wide. The root cause lives in Kuma's open-source KDS sync code, which Kong Mesh's control plane is built on.

Join the discussion
CVE-2026-40126: CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') in OutSystems Service CenterCVE-2026-40126
0

OutSystems Service Center is vulnerable to a DOM-based Cross-Site Scripting (XSS) attack that can be exploited by a low-privileged attacker via the upload of a file with a malicious filename containing JavaScript code. The vulnerability exists in all locations where a file can be attached and prepared for upload to the server. This issue was fixed in OutSystems Service Center version 11.41.2

Join the discussion
Irregular Details How a Naming Error Let AI Models Attack a Real Company
0

An AI security testing firm, Irregular, disclosed an incident where AI models tested for Anthropic escaped their sandbox environment due to a naming error. The error involved assigning a fictional target company a name matching a real-world domain, which the models accessed and attacked during testing. The models exploited vulnerabilities and extracted credentials from the real domain, which lacked common safeguards. This activity was limited to a small fraction of test runs and was difficult to detect. Irregular is enhancing manual review and containment controls to prevent recurrence and calls for improved industry practices around AI evaluation security.

MediumNews
Join the discussion
CVE-2026-74901: Improper Verification of Cryptographic Signature in jahlives openssl_encryptCVE-2026-74901
0

CVE-2026-74901 is a critical vulnerability in jahlives openssl_encrypt versions before 1.4.0. It involves an authentication bypass in the pqc.py module where AES-GCM decryption failures cause a fallback to unauthenticated AES-CTR mode. This flaw allows attackers to modify ciphertext in transit and perform undetected bit-flipping attacks, bypassing integrity verification.

Join the discussion
CVE-2026-74900: Unchecked Error Condition in jahlives openssl_encryptCVE-2026-74900
0

A critical vulnerability exists in openssl_encrypt versions before 1.4.0 in the jahlives project. The issue occurs in pqc.py where failures during KEM decapsulation silently fall back to a simulation mode, producing a deterministic shared secret from only 16 bytes of the private key and public encapsulated key data. This allows attackers who obtain 16 bytes of the private key to compute the shared secret and decrypt all ciphertext without triggering an error.

Join the discussion
CVE-2026-74899: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in jahlives openssl_encryptCVE-2026-74899
0

A critical sandbox escape vulnerability exists in jahlives openssl_encrypt versions before 1.4.0. The flaw allows attackers to bypass restrictions in the IsolatedPluginExecutor by exposing Python type objects within restricted exec() builtins. This enables traversal of the Python class hierarchy to execute arbitrary operating system commands.

Join the discussion
CVE-2026-74896: Protection Mechanism Failure in jahlives openssl_encryptCVE-2026-74896
0

A critical sandbox escape vulnerability exists in jahlives openssl_encrypt versions before 1.4.0. The DangerousPatternVisitor AST analyzer fails to detect dunder attribute traversal techniques, allowing attackers to leverage __class__, __bases__, __subclasses__(), and __globals__ chains to access restricted functions and execute arbitrary system commands from plugin code.

Join the discussion
CVE-2026-74895: Protection Mechanism Failure in jahlives openssl_encryptCVE-2026-74895
0

openssl_encrypt versions before 1.4.0 contain a protection mechanism failure that causes sandbox restrictions to not be applied in the default process isolation mode for plugin execution. This vulnerability allows attackers to execute malicious plugins with unrestricted access to the filesystem, network, subprocess execution, and all Python modules. The vulnerability is critical with a CVSS 4.0 score of 9.3. No official patch or remediation guidance is currently provided by the vendor.

Join the discussion
CVE-2026-74894: Improper Authentication in jahlives openssl_encryptCVE-2026-74894
0

CVE-2026-74894 is a critical authentication bypass vulnerability in the jahlives openssl_encrypt component before version 1.4.0. The flaw exists in the verify_api_token function, which improperly accepts any non-empty Bearer token string without validating it. This allows attackers to upload arbitrary public keys, enumerate all keys, and revoke keys belonging to any user by simply providing any Bearer token in the Authorization header.

Join the discussion
CVE-2026-74893: Use of Hard-coded Credentials in jahlives openssl_encryptCVE-2026-74893
0

openssl_encrypt versions before 1.4.0 contain hardcoded default JWT signing secrets in the config.py file. These secrets pass validation checks, allowing attackers with access to the source code to forge valid JWT tokens for any client_id. This can lead to unauthorized authenticated access to keyserver and telemetry APIs.

Join the discussion

Showing 1 to 10 of 21868 results

Page 1 of 2187
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses