Threats Affecting United Kingdom
View all threats affecting or targeting United Kingdom. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Affecting United Kingdom
Click on any threat for detailed analysis and mitigation recommendations
0 CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/settings.index.inc.php directly concatenates the administrator-controlled download_expire POST parameter into a raw UPDATE statement for CubeCart_downloads without numeric validation. An authenticated administrator can supply a comma-delimited value that changes the SET clause because HTML sanitization does not neutralize SQL syntax, allowing manipulation of database columns and potentially other data within the application's database privileges. This issue is fixed in version 6.7.5. Join the discussion | Exploit-DB RSS Feed | 09/17/2026, 22:02:48 UTC Added: 08/31/2026, 17:43:04 UTC |
0 It was discovered that libsoup incorrectly handled certain URLs when using an HTTP proxy. A remote attacker could possibly use this issue to inject arbitrary HTTP headers. (CVE-2026-1467) It was discovered that libsoup did not remove proxy authentication credentials when following HTTP redirects. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-1539) Ahmed Lekssays discovered that libsoup incorrectly parsed certain HTTP requests. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-1801) Join the discussion | CVE Database V5 | 09/17/2026, 16:27:25 UTC Added: 01/27/2026, 17:05:57 UTC |
A cybercriminal group dubbed GrelosGTM has been exploiting Google Tag Manager's legitimate functionality to compromise e-commerce websites. First detected in early April 2020, the group evolved their tactics by February 2021 to inject malicious Google Tag Manager scripts into targeted sites. The campaign affected at least seven websites running Magento CMS across Belgium, Italy, the United Kingdom, and the United States. Attackers inject custom Google Tag Manager scripts that load multi-stage JavaScript payloads through WebSocket connections. The final payload deploys a heavily obfuscated JavaScript sniffer designed to steal customers' payment card information during checkout using fake payment forms, with stolen data exfiltrated to attacker-controlled servers. Join the discussion | AlienVault OTX General | 09/15/2026, 08:15:42 UTC Added: 09/15/2026, 11:46:59 UTC |
0 Mbed TLS before 3.6.4 has a race condition in AESNI detection if certain compiler optimizations occur. An attacker may be able to extract an AES key from a multithreaded program, or perform a GCM forgery. Join the discussion | CVE Database V5 | 09/15/2026, 00:00:00 UTC Added: 07/04/2025, 14:54:28 UTC |
A threat actor exploited CVE-2026-15409, a critical unauthenticated server-side request forgery vulnerability in SonicWall SMA1000 appliances, to gain command execution and steal credentials. The attacker used a modified public proof-of-concept exploit to access internal Erlang services on the appliance, enabling remote code execution. This allowed extraction of LDAP configurations, Active Directory credentials, and deployment of tools to dump secrets from internal Windows systems. The campaign targeted at least 250 SonicWall SMA1000 devices across multiple countries and sectors, with confirmed credential theft in France, India, Italy, and the US. The attack leveraged compromised appliances as pivots into internal networks, exposing sensitive Active Directory data and enabling DCSync attacks against domain controllers. The targeting was opportunistic and technology-driven rather than sector-specific. The campaign was uncovered through an open directory left exposed by the attacker, providing a comprehensive view of the operation. Join the discussion | Reddit ThreatIntel | 09/10/2026, 17:51:25 UTC Added: 09/10/2026, 17:52:10 UTC |
Trezor warned customers that threat actors who breached its third-party email provider are conducting phishing attacks targeting its users. The phishing emails impersonate Trezor and claim a critical hardware vulnerability, attempting to trick recipients into clicking malicious links. Trezor has taken down the fraudulent domain and is investigating the breach. This incident follows a prior data breach involving Trezor's shipping provider ShipMonk, which exposed customer order data affecting tens of thousands of users across multiple countries. The phishing attack leverages compromised email infrastructure rather than a direct vulnerability in Trezor products. Join the discussion | Bleeping Computer | 09/10/2026, 06:56:33 UTC Added: 09/10/2026, 07:07:20 UTC |
An unpatched zero-day vulnerability dubbed StyleSmuggler affects all current versions of Magento and Adobe Commerce, including 2.4.9, enabling unauthenticated remote code execution. Active exploitation began on September 4th, 2026. The attack operates in two stages: injecting malicious PHP code into Magento's template system using styles properties to evade safeguards, then executing the poisoned code via failed payment emails. Upon successful compromise, attackers deploy a Rust-based backdoor disguised as legitimate system processes (kworker, fc-cache, or chronyd) that connects to command and control servers. The backdoor uses NTP-shaped UDP traffic for C2 communication to evade detection. A second unrelated attacker has also been observed exploiting the same vulnerability to deploy PHP web shells. Affected merchants should deploy immediate mitigation measures, scan for compromise, and temporarily disable GraphQL until an official patch is released. Join the discussion | CVE Database V5 | 09/07/2026, 17:15:59 UTC Added: 09/09/2025, 13:33:51 UTC |
Google has updated the Chrome browser to address an actively exploited high-severity zero-day flaw in the V8 engine and 11 other vulnerabilities. [...] Join the discussion | Bleeping Computer | 09/04/2026, 11:48:17 UTC Added: 09/04/2026, 12:07:22 UTC |
Exploit-DB RSS Feed | 09/03/2026, 00:00:00 UTC Added: 09/03/2026, 17:44:19 UTC | |
0 FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and remote code execution. This issue has been patched in endpoint versions 15.0.66, 16.0.89, and 17.0.3. Join the discussion | CVE Database V5 | 09/03/2026, 00:00:00 UTC Added: 08/28/2025, 16:47:48 UTC |
Showing 1 to 10 of 36737 results