Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-75589: CWE-208 Observable Timing DiscrepancyCVE-2026-75589
0

Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLAINTEXT signatures with a non-constant-time comparison in verify. Each of the three compares the signature carried in the message against the locally computed one with the eq operator, which returns as soon as the two strings differ. The time taken to reject a signature varies with the length of the matching prefix. RSA-SHA1 is not affected, as it verifies through the RSA key object rather than by comparing strings. A client that can submit messages and time the replies may recover a valid signature one byte at a time rather than searching the whole signature space. Under PLAINTEXT the value compared against is the signature key itself, so the search recovers consumer_secret and token_secret.

Join the discussion
CVE-2026-72889: CWE-347 Improper Verification of Cryptographic SignatureCVE-2026-72889
0

Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verify. verify resolves the signature method class from the signature_method parameter of the incoming message. signature_method is required on every request, so the algorithm used to check a signature is chosen by whoever sent it, and nothing lets the verifying party pin the method instead. When a message names HMAC-SHA1 or HMAC-SHA256, the key is derived from consumer_secret and token_secret rather than from the key the provider deployed. A provider deployed on RSA-SHA1 holds only the consumer public key, and RFC 5849 does not use consumer_secret for that method, so the required parameter is filled with a placeholder. A client that names HMAC-SHA1 instead has its signature checked against that placeholder, so a guessable one is enough to forge requests for any consumer key and token.

Join the discussion
Critical GitLab GraphQL Vulnerability CVE-2026-19478: Impact and Mitigation Guidance
0

This article provides a detailed explanation of the critical GitLab GraphQL vulnerability CVE-2026-19478, which allows unauthenticated attackers to delete public projects on self-managed GitLab instances. It includes affected versions, severity metrics, and patching guidance, along with information on a related CSRF flaw (CVE-2026-19650).

Join the discussion
CareCloud Data Breach Impact Grows to 3.7 Million Individuals
0

The CareCloud data breach, initially reported to affect approximately 350,000 individuals, has been updated to impact over 3.7 million people according to the Department of Health and Human Services (HHS) breach tracker. The breach involved unauthorized access to CareCloud's AWS environment in March 2026, resulting in the exfiltration of sensitive personal and healthcare information, including names, addresses, Social Security numbers, driver’s license numbers, dates of birth, health insurance details, and medical records. A limited subset of individuals also had full payment card information compromised. The breach was discovered following a disruption in the electronic health record environment. No specific threat actor has claimed responsibility, and it is unclear if a ransom was paid. The incident highlights a significant exposure of sensitive healthcare data on a large scale.

CriticalBreach
Join the discussion
CVE-2026-75981: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in cozmoslabs TranslatePress – Translate Multilingual sites with AI TranslationCVE-2026-75981
0

TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress versions up to and including 3.2.5 contains an unauthenticated stored cross-site scripting (XSS) vulnerability. The vulnerability arises because special gettext markers '#!trpst#' and '#!trpen#' are replaced with '<' and '>' in the translation rendering process, allowing attackers to inject HTML tags such as <img> with malicious attributes. This occurs in comments that survive standard sanitization, leading to script execution in visitors' browsers when viewing content in a secondary language.

Join the discussion
CVE-2026-15780: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in veronalabs WP Statistics – Simple, privacy-friendly Google Analytics alternativeCVE-2026-15780
0

WP Statistics plugin for WordPress has a stored cross-site scripting (XSS) vulnerability via the 'utm_campaign' parameter in versions up to and including 14.16.8. An unauthenticated attacker can inject malicious scripts that execute when a user accesses the affected page. The vulnerability arises because input sanitization and output escaping are insufficient, and the attack can be performed through a public REST endpoint by exploiting a base64-encoded parameter to bypass sanitization.

Join the discussion
CVE-2026-15446: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in nosilver4u EWWW Image OptimizerCVE-2026-15446
0

The EWWW Image Optimizer WordPress plugin up to version 8.7.3 contains a stored cross-site scripting (XSS) vulnerability via the 'data-script' lazy load attribute in post content. Authenticated users with contributor-level access or higher can inject malicious scripts that execute when other users view the affected pages. This occurs due to insufficient input sanitization and output escaping in handling the 'data-script' attribute combined with the plugin's use of the lazysizes ls.unveilhooks addon.

Join the discussion
How to Fix Terraform State Drift from Manual AWS Changes: A 2026 Guide
0

This article provides a detailed, actionable guide to diagnosing and fixing Terraform state drift caused by manual AWS console changes. It explains the root causes, step-by-step CLI commands to safely refresh and synchronize state without destroying resources, and best practices for locking down IAM roles and remote state management to prevent future drift.

Join the discussion
CVE-2026-8810: CWE-522: Insufficiently Protected Credentials in Insyde Software InsydeH2O, InsydeH2O ARMCVE-2026-8810
0

CVE-2026-8810 is a vulnerability in Insyde Software's InsydeH2O firmware for ARM platforms. It involves insufficient protection of HDD Password credentials stored in UEFI variables, allowing an attacker to potentially retrieve these passwords. The vulnerability has a CVSS score of 6.9, indicating a medium severity level. No patch or official remediation has been confirmed at this time.

Join the discussion
CVE-2026-19842: CWE-287 Improper Authentication in SAML Single Sign OnCVE-2026-19842
0

The SAML Single Sign On WordPress plugin before version 5.4.7 contains an improper authentication vulnerability. It fails to verify the signature of a SAML response before storing the certificate it carries. This flaw allows an attacker to store their own certificate as trusted by the site and then authenticate as any user, including administrators, via a one-click control. The vulnerability affects version 4.8.85 specifically. No official patch or remediation guidance is currently available.

Join the discussion

Showing 1 to 10 of 19627 results

Filters:Package: pkg:bitnami/distribution
Page 1 of 1963
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses