Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
A critical heap-based buffer overflow vulnerability exists in esnet iperf3 versions 3.20 and 3.21 in the decrypt_rsa_message() function. The flaw allows an unauthenticated client to overflow a 256-byte RSA buffer by providing an oversized authtoken, potentially leading to memory corruption. This vulnerability is fixed in version 3.22. Join the discussion | CVE Database V5 | 09/30/2026, 21:32:14 UTC Added: 09/30/2026, 21:48:45 UTC |
0 PyJWT versions 2.11.0 through 2.13.0 contain a vulnerability in the _merge_options() method where a mutable options mapping provided by the caller can be modified improperly when verify_signature is false. This can cause the options mapping to retain false values for critical JWT claim checks in subsequent decode calls with signature verification enabled, potentially allowing acceptance of tokens with invalid claims. Applications that create a fresh options mapping for each decode call are not affected. Join the discussion | CVE Database V5 | 09/30/2026, 21:15:12 UTC Added: 09/30/2026, 21:33:29 UTC |
0 iperf3 3.21 (esnet/iperf) contains a remote, unauthenticated heap use-after-free: the server's per-test watchdog server_timer_proc() frees streams without cancelling/joining their worker threads, so a blocked worker dereferences a freed iperf_stream; fixed in 3.22. Join the discussion | CVE Database V5 | 09/30/2026, 21:11:52 UTC Added: 09/30/2026, 21:19:02 UTC |
This content is a podcast episode discussing a hospital ransomware incident where staff could not trust patient records, highlighting challenges in incident response and the importance of rehearsal for CISOs. It includes insights on rapid exploitation enabled by AI and the complexity of layered defenses. The episode also emphasizes the need for incident response exercises to consider scenarios where data and logs may be unreliable. Join the discussion | Reddit Cybersecurity | 09/30/2026, 20:43:34 UTC Added: 09/30/2026, 20:47:55 UTC |
The Russian state-sponsored threat actor Star Blizzard has developed a new malware delivery technique called RedFlick to deploy its CosmicPulse backdoor. This method automates the infection chain by using a password-protected archive containing a virtual disk with a malicious shortcut file, which when opened, triggers hidden commands to download and install malware components via scheduled tasks. These tasks perform distinct roles to evade detection and ultimately deliver the CosmicPulse backdoor, capable of executing attacker-supplied Python code. The campaigns primarily target Ukrainian individuals and institutions, as well as international NGOs, think tanks, governments, and financial organizations supporting Ukraine. Microsoft recommends phishing-resistant authentication, Conditional Access policies, email protection, and endpoint detection and response solutions to mitigate these attacks. Join the discussion | Bleeping Computer | 09/30/2026, 20:34:01 UTC Added: 09/30/2026, 20:48:08 UTC |
0 CVE-2026-92172 is a vulnerability in Meta Horizon OS prior to version 66.0.0.733.524. It involves improper restriction of communication channels, allowing an application to receive a privileged PendingIntent with a CallerIdentity from the OVRMediaService. This flaw enables the application to impersonate the com.oculus.horizon package to any endpoint within the OS that relies on CallerIdentity authentication. Join the discussion | CVE Database V5 | 09/30/2026, 20:26:49 UTC Added: 09/30/2026, 20:48:43 UTC |
0 CVE-2026-92173 is a vulnerability in Meta Horizon OS prior to version 74.0.0.878.1682. It involves improper restriction of communication channels, allowing an attacker to induce MediaSyncJobReceiver to send a privileged PendingIntent with a com.oculus.vrshell CallerIdentity to an arbitrary application. This enables the application to impersonate the com.oculus.vrshell package and other packages signed with the same key within the OS. Join the discussion | CVE Database V5 | 09/30/2026, 20:26:33 UTC Added: 09/30/2026, 20:48:43 UTC |
0 Kiteworks Email Protection Gateway versions before 9.5.0 contain a Server-Side Request Forgery (SSRF) vulnerability. This flaw allows a remote, unauthenticated attacker to cause the gateway to make crafted requests to internal or unintended network destinations when rendering message content with external resource references. Exploitation could lead to disclosure of sensitive internal information or unintended actions on internal systems. The vulnerability has a high severity with a CVSS score of 9.1. No explicit patch information is provided, so users should verify vendor advisories for remediation status. Join the discussion | CVE Database V5 | 09/30/2026, 20:25:02 UTC Added: 09/30/2026, 20:48:43 UTC |
0 CVE-2026-102106 is an improper authentication vulnerability in the Kiteworks Email Protection Gateway administrative service. The service does not consistently enforce administrator authentication, allowing an attacker referencing a valid administrator account to bypass password checks. This can enable unauthorized creation, modification, or deletion of internal users and managed domains, as well as changes to security configurations. Deleting a managed domain can remove its user accounts and potentially lock out legitimate administrators. Join the discussion | CVE Database V5 | 09/30/2026, 20:24:46 UTC Added: 09/30/2026, 20:48:43 UTC |
0 Kiteworks Core has a business logic vulnerability in its file-request feature that allows an authenticated user to impersonate another user when sending requests. This flaw arises because the server does not verify that the requester is authorized to act as the specified account. Exploitation requires the feature to be enabled for the attacker and the targeted recipient to respond to the request. The vulnerability affects versions prior to 9.5.1 and has a medium severity rating with a CVSS score of 4.6. Join the discussion | CVE Database V5 | 09/30/2026, 20:24:29 UTC Added: 09/30/2026, 20:48:43 UTC |
Showing 1 to 10 of 3902 results