Threats Affecting Austria
View all threats affecting or targeting Austria. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Affecting Austria
Click on any threat for detailed analysis and mitigation recommendations
Manic is a newly discovered Android malware family that steals banking credentials, intercepts sensitive data, and allows remote control of infected devices. It uniquely exfiltrates stolen data even without an internet connection by exploiting Android Accessibility services to capture keystrokes and replay them on targeted apps. The malware targets banking apps, government apps, crypto wallets, and two-factor authentication apps across multiple European countries. Infection vectors likely include unofficial app stores, malicious APKs, and phishing links, with no evidence of distribution via Google Play. Manic abuses Accessibility permissions to spy on users, grant itself additional permissions, and prevent removal. It overlays an invisible keyboard to capture passwords and sensitive input. The malware has been active since at least May 2026 and continues to evolve to evade detection. Join the discussion | Kaspersky Security Blog | 08/31/2026, 17:18:45 UTC Added: 08/31/2026, 17:22:57 UTC |
A newly identified Android malware family named Manic combines banking malware and mobile spyware capabilities, targeting Ukrainian banks, government services, messaging applications, Russian and European financial institutions, and global fintech and cryptocurrency services. Active since February 2026, Manic enables extensive Device Takeover operations through sophisticated surveillance and remote-control features. It employs advanced PIN stealing techniques without requiring traditional overlay attacks, utilizing Accessibility services as a UI keylogger to capture lock-screen inputs, recovery phrases, and authentication codes. A distinctive feature is its Wi-Fi mesh egress technique, allowing compromised devices to relay stolen data through other infected phones via Wi-Fi Direct, Bluetooth, or BLE when direct C2 access is unavailable. The malware monitors 169 applications including banks, cryptocurrency wallets, government eID services, and military-focused messengers across multiple countries. Join the discussion | AlienVault OTX General | 08/20/2026, 11:45:48 UTC Added: 08/20/2026, 23:22:26 UTC |
Kratos is a mature Phishing-as-a-Service operation targeting Microsoft 365 users across the United States, Europe, and other regions. The platform enables attackers to steal credentials through trusted platforms, anti-bot verification, and convincing login pages. Researchers traced three generations of the kit and uncovered 1,484 previously unattributed detonations. The operation targets organizations across more than 20 countries with particularly strong concentration in the US, Spain, and Southern Europe. Kratos includes an operator panel allowing deployment of phishing domains, configurable Telegram or email delivery, geographic restrictions, and multiple anti-bot systems. The kit has evolved through three page generations (V0, V1, V2) with different exfiltration code. Activity has been visible since January 2026, with the operator panel active since September 2025. Join the discussion | AlienVault OTX General | 07/14/2026, 16:36:39 UTC Added: 07/16/2026, 10:17:37 UTC |
Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 30.0.9 and 31.0.1, incorrect path handling with groupfolders caused the admin_audit app to not properly log all actions on files and folders inside groupfolders. This vulnerability is fixed in Nextcloud Server and Enterprise Server prior to 30.0.9 and 31.0.1. Join the discussion | CVE Database V5 | 07/13/2026, 09:29:28 UTC Added: 12/05/2025, 16:45:20 UTC |
A new variant of the TrickMo Android banking trojan was identified between January and February 2026, representing a substantial platform redesign rather than new capabilities. The malware has migrated its command-and-control infrastructure entirely onto The Open Network (TON) using .adnl endpoints, moving away from conventional internet infrastructure. Active campaigns have targeted banking and wallet users in France, Italy, and Austria. Once accessibility permissions are granted, operators gain real-time device control including credential phishing, keylogging, screen recording, SMS interception, and bidirectional remote control. New features include network reconnaissance capabilities and SSH tunnelling that transform infected devices into programmable network pivots and SOCKS5 proxy exit nodes, enabling operators to bypass IP-based fraud detection systems while accessing victim networks. Join the discussion | AlienVault OTX General | 05/11/2026, 09:07:43 UTC Added: 05/11/2026, 09:51:23 UTC |
The ShinyHunters hacker group claimed to have stolen over 350GB of information from European Commission cloud systems. The post European Commission Reports Cyber Intrusion and Data Theft appeared first on SecurityWeek . Join the discussion | SecurityWeek | 03/30/2026, 11:29:45 UTC Added: 03/30/2026, 11:38:17 UTC |
0 Improper Restriction of XML External Entity Reference vulnerability in XMLUtils.java in Slovensko.Digital Autogram allows remote unauthenticated attacker to conduct SSRF (Server Side Request Forgery) attacks and obtain unauthorized access to local files on filesystems running the vulnerable application. Successful exploitation requires the victim to visit a specially crafted website that sends request containing a specially crafted XML document to /sign endpoint of the local HTTP server run by the application. Join the discussion | CVE Database V5 | 03/19/2026, 11:25:44 UTC Added: 03/19/2026, 13:54:25 UTC |
0 A Cross-Site Scripting (XSS) vulnerability exists in the web-based configuration interface of Zucchetti Axess access control devices, including XA4, X3/X3BIO, X4, X7, and XIO / i-door / i-door+. The vulnerability is caused by improper sanitization of user-supplied input in the dirBrowse parameter of the /file_manager.cgi endpoint. Join the discussion | CVE Database V5 | 03/18/2026, 00:00:00 UTC Added: 03/18/2026, 17:13:23 UTC |
The extension fails to properly reset the generated MFA code after successful authentication. This leads to a possible MFA bypass for future login attempts by providing an empty string as MFA code to the extensions MFA provider. Join the discussion | CVE Database V5 | 03/17/2026, 08:34:52 UTC Added: 03/17/2026, 08:58:21 UTC |
0 CVE-2026-32100 is a medium severity vulnerability in the Shopware open commerce platform's swag platform-security component. The /api/_info/config API endpoint exposes sensitive information about active security fixes without requiring authentication. This information disclosure could aid attackers in identifying unpatched vulnerabilities. The issue affects versions prior to 2.0.16, 3.0.12, and 4.0.7 and has a CVSS score of 5. Join the discussion | CVE Database V5 | 03/12/2026, 18:10:58 UTC Added: 03/12/2026, 18:15:36 UTC |
Showing 1 to 10 of 2572 results