Threats Affecting Netherlands
View all threats affecting or targeting Netherlands. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Affecting Netherlands
Click on any threat for detailed analysis and mitigation recommendations
0 A previously unknown modular multi-stage framework named MovieReaper has been discovered targeting users through compromised torrent files. Attackers compromised the public torrent repository itorrents[.]org, enabling them to distribute malicious loaders disguised as popular movies, including "The Odyssey." The campaign began in mid-August 2026 and affected hundreds of victims across multiple countries. The malware employs a sophisticated infection chain with fileless execution, utilizing blockchain network Solana for C2 infrastructure resilience. The framework includes multiple stages: an initial loader with anti-sandbox checks, shellcode that retrieves C2 addresses from Solana blockchain, UAC bypass with persistence mechanisms, and a final file manager module providing comprehensive file system access. The campaign demonstrates advanced evasion techniques including manual API resolution, vectored exception handling, and in-memory execution. Join the discussion | CVE Database V5 | 09/17/2026, 16:23:20 UTC Added: 02/24/2026, 14:47:12 UTC |
0 Mbed TLS before 3.6.4 has a race condition in AESNI detection if certain compiler optimizations occur. An attacker may be able to extract an AES key from a multithreaded program, or perform a GCM forgery. Join the discussion | CVE Database V5 | 09/15/2026, 00:00:00 UTC Added: 07/04/2025, 14:54:28 UTC |
MacSync Stealer is a macOS information stealer and remote-access stager delivered through ClickFix social engineering and malvertising campaigns. Operating under a malware-as-a-service model, it employs sophisticated evasion techniques including process daemonization, single-byte XOR obfuscation, and in-memory AppleScript execution to bypass Apple Gatekeeper, XProtect, and EDR solutions. The malware exfiltrates credentials, browser data, cryptocurrency wallets, and SSH keys through fault-tolerant 10MB chunked uploads to command-and-control infrastructure. MacSync targets professionals in software engineering, cryptocurrency, fintech, and corporate environments across North America, Europe, and Asia-Pacific regions, with campaigns impersonating legitimate services like Google Meet, Claude AI, Docker, and TradingView to trick victims into executing malicious Terminal commands. MediumMalware Join the discussion | AlienVault OTX General | 09/08/2026, 12:29:01 UTC Added: 09/09/2026, 09:22:16 UTC |
An unpatched zero-day vulnerability dubbed StyleSmuggler affects all current versions of Magento and Adobe Commerce, including 2.4.9, enabling unauthenticated remote code execution. Active exploitation began on September 4th, 2026. The attack operates in two stages: injecting malicious PHP code into Magento's template system using styles properties to evade safeguards, then executing the poisoned code via failed payment emails. Upon successful compromise, attackers deploy a Rust-based backdoor disguised as legitimate system processes (kworker, fc-cache, or chronyd) that connects to command and control servers. The backdoor uses NTP-shaped UDP traffic for C2 communication to evade detection. A second unrelated attacker has also been observed exploiting the same vulnerability to deploy PHP web shells. Affected merchants should deploy immediate mitigation measures, scan for compromise, and temporarily disable GraphQL until an official patch is released. Join the discussion | CVE Database V5 | 09/07/2026, 17:15:59 UTC Added: 09/09/2025, 13:33:51 UTC |
Google has updated the Chrome browser to address an actively exploited high-severity zero-day flaw in the V8 engine and 11 other vulnerabilities. [...] Join the discussion | Bleeping Computer | 09/04/2026, 11:48:17 UTC Added: 09/04/2026, 12:07:22 UTC |
0 Metabase versions from 0.58.0 up to but not including 0.58.15, 0.59.0 up to but not including 0.59.12, 0.60.0 up to but not including 0.60.6.3, and 0.61.0 up to but not including 0.61.1.4 are affected by an authenticated remote code execution vulnerability. This vulnerability allows an authenticated attacker to execute arbitrary code remotely on the affected system. Join the discussion | Exploit-DB RSS Feed | 09/03/2026, 00:00:00 UTC Added: 09/03/2026, 17:44:19 UTC |
0 FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and remote code execution. This issue has been patched in endpoint versions 15.0.66, 16.0.89, and 17.0.3. Join the discussion | CVE Database V5 | 09/03/2026, 00:00:00 UTC Added: 08/28/2025, 16:47:48 UTC |
SonicWall warned customers that threat actors are chaining two new SMA1000 zero-day vulnerabilities in remote code execution attacks. [...] Join the discussion | Bleeping Computer | 09/02/2026, 06:39:29 UTC Added: 09/02/2026, 07:07:13 UTC |
Ghost is a Node.js content management system. From version 0.7.2 to 6.19.0, specifically crafted malicious themes can execute arbitrary code on the server running Ghost. This issue has been patched in version 6.19.1. Join the discussion | CVE Database V5 | 09/02/2026, 00:00:00 UTC Added: 03/05/2026, 06:03:33 UTC |
Cosign provides code signing and transparency for containers and binaries. In versions 3.0.4 and below, an issuing certificate with a validity that expires before the leaf certificate will be considered valid during verification even if the provided timestamp would mean the issuing certificate should be considered expired. When verifying artifact signatures using a certificate, Cosign first verifies the certificate chain using the leaf certificate's "not before" timestamp and later checks expiry of the leaf certificate using either a signed timestamp provided by the Rekor transparency log or from a timestamp authority, or using the current time. The root and all issuing certificates are assumed to be valid during the leaf certificate's validity. There is no impact to users of the public Sigstore infrastructure. This may affect private deployments with customized PKIs. This issue has been fixed in version 3.0.5. Join the discussion | CVE Database V5 | 09/02/2026, 00:00:00 UTC Added: 02/19/2026, 22:32:05 UTC |
Showing 1 to 10 of 31066 results