Threats Affecting Sweden
View all threats affecting or targeting Sweden. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Affecting Sweden
Click on any threat for detailed analysis and mitigation recommendations
0 Mbed TLS before 3.6.4 has a race condition in AESNI detection if certain compiler optimizations occur. An attacker may be able to extract an AES key from a multithreaded program, or perform a GCM forgery. Join the discussion | CVE Database V5 | 09/15/2026, 00:00:00 UTC Added: 07/04/2025, 14:54:28 UTC |
A threat actor exploited CVE-2026-15409, a critical unauthenticated server-side request forgery vulnerability in SonicWall SMA1000 appliances, to gain command execution and steal credentials. The attacker used a modified public proof-of-concept exploit to access internal Erlang services on the appliance, enabling remote code execution. This allowed extraction of LDAP configurations, Active Directory credentials, and deployment of tools to dump secrets from internal Windows systems. The campaign targeted at least 250 SonicWall SMA1000 devices across multiple countries and sectors, with confirmed credential theft in France, India, Italy, and the US. The attack leveraged compromised appliances as pivots into internal networks, exposing sensitive Active Directory data and enabling DCSync attacks against domain controllers. The targeting was opportunistic and technology-driven rather than sector-specific. The campaign was uncovered through an open directory left exposed by the attacker, providing a comprehensive view of the operation. Join the discussion | Reddit ThreatIntel | 09/10/2026, 17:51:25 UTC Added: 09/10/2026, 17:52:10 UTC |
Trezor warned customers that threat actors who breached its third-party email provider are conducting phishing attacks targeting its users. The phishing emails impersonate Trezor and claim a critical hardware vulnerability, attempting to trick recipients into clicking malicious links. Trezor has taken down the fraudulent domain and is investigating the breach. This incident follows a prior data breach involving Trezor's shipping provider ShipMonk, which exposed customer order data affecting tens of thousands of users across multiple countries. The phishing attack leverages compromised email infrastructure rather than a direct vulnerability in Trezor products. Join the discussion | Bleeping Computer | 09/10/2026, 06:56:33 UTC Added: 09/10/2026, 07:07:20 UTC |
Exploit-DB RSS Feed | 09/03/2026, 00:00:00 UTC Added: 09/03/2026, 17:44:19 UTC | |
0 CVE-2025-70336 is a medium severity stored cross-site scripting (XSS) vulnerability in PodcastGenerator version 3.2.9. It allows remote attackers with authenticated access to inject malicious scripts via the 'TITLE', 'SHORT DESCRIPTION', and 'LONG DESCRIPTION' fields when creating new live items. The injected payload executes when users view the 'View All Live Items' or 'Live Stream' pages, potentially compromising user sessions and data. Exploitation requires authentication and user interaction, limiting its immediate impact but still posing risks to confidentiality and integrity. No known exploits are currently in the wild, and no patches have been published yet. European organizations using PodcastGenerator 3.2.9, especially media and broadcasting entities, should be vigilant and apply strict input validation and output encoding as interim mitigations. Join the discussion | CVE Database V5 | 09/02/2026, 00:00:00 UTC Added: 01/28/2026, 15:35:57 UTC |
0 CVE-2026-23736 is a high-severity prototype pollution vulnerability in the seroval JavaScript value stringification library (versions below 1.4.1). The flaw arises from improper input validation during JSON deserialization, allowing attackers to modify object prototype attributes maliciously. Exploitation requires no authentication or user interaction and can be performed remotely over the network. Successful attacks can lead to partial compromise of confidentiality, integrity, and availability of affected applications. The vulnerability is fixed in seroval version 1.4.1. European organizations using vulnerable versions in their JavaScript environments should prioritize updating to mitigate risks. Join the discussion | CVE Database V5 | 09/02/2026, 00:00:00 UTC Added: 01/21/2026, 23:20:56 UTC |
0 CVE-2025-68137 is a high-severity buffer overflow vulnerability in the EVerest everest-core EV charging software stack versions prior to 2025.10.0. It arises from an integer overflow in the SdpPacket::parse_header() function, causing incorrect buffer length calculations that lead to either an infinite loop or a stack buffer overflow depending on the server configuration (TCP or TLS). This vulnerability can result in full compromise of confidentiality, integrity, and availability without requiring authentication or user interaction. The flaw is fixed in version 2025.10.0. European organizations operating EV charging infrastructure using affected versions are at risk of service disruption and potential remote code execution. Mitigation requires immediate upgrade to the patched version and careful network segmentation of EV charging systems. Join the discussion | CVE Database V5 | 09/02/2026, 00:00:00 UTC Added: 01/21/2026, 19:35:56 UTC |
0 Payload is a free and open source headless content management system. Prior to 3.73.0, when querying JSON or richText fields, user input was directly embedded into SQL without escaping, enabling blind SQL injection attacks. An unauthenticated attacker could extract sensitive data (emails, password reset tokens) and achieve full account takeover without password cracking. This vulnerability is fixed in 3.73.0. Join the discussion | CVE Database V5 | 09/01/2026, 00:00:00 UTC Added: 02/06/2026, 21:30:09 UTC |
Thirteen malicious Composer theme packages published on Packagist across five vendor namespaces inject JavaScript into Vietnamese movie and comic streaming sites. The injected code executes two operations: a mobile ad-fraud and gambling redirect chain, and on iPhones, a WebKit-to-kernel exploit chain installing spyware. The iOS chain weaponizes CVE-2025-31277 and CVE-2025-43529, targeting devices running iOS 18.4 through 18.6.x on iPhone XS through iPhone 16. The exploit chain progresses from WebKit renderer through GPU process to kernel escape via AppleM2ScalerCSCDriver, ultimately deploying spyware that exfiltrates keychain databases, cryptocurrency wallet seeds from seven wallet applications, Wi-Fi passwords, SMS, photos, contacts, and location data. Infrastructure resolves to FUNNULL, a sanctioned provider operated by Chinese national Liu Lizhi. The theme operators are Vietnamese-based, publishing trojanized forks of OphimCMS and KKPhim projects, affecting site operators who unknowingly serve malicious... Join the discussion | CVE Database V5 | 08/31/2026, 20:09:42 UTC Added: 12/17/2025, 20:58:40 UTC |
PaperCut is warning that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. [...] Join the discussion | Bleeping Computer | 08/27/2026, 16:31:53 UTC Added: 08/27/2026, 16:37:13 UTC |
Showing 1 to 10 of 20218 results