Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-105099 is a cross-site scripting (XSS) vulnerability in Omega Solution CoinEx Crypto 2025. The flaw exists in an unknown functionality of the /user/ticket file related to Ticket Attachment Upload. The vulnerability can be exploited remotely and requires low privileges with user interaction. The product website is no longer available, and the vendor did not respond to disclosure attempts. No patch or remediation information is available. Join the discussion | CVE Database V5 | 10/04/2026, 03:30:16 UTC Added: 10/04/2026, 05:02:36 UTC |
CVE-2026-105098 is an information disclosure vulnerability in Omega Solution CoinEx Crypto 2025. It affects an unknown function within the /ticket/customer file of the Support Ticket API component. The flaw is triggered by manipulating the status, page, or count arguments, allowing remote attackers to disclose information. The product appears to be retired or replaced, and the vendor did not respond to disclosure attempts. No patch or remediation information is available. Join the discussion | CVE Database V5 | 10/04/2026, 02:45:13 UTC Added: 10/04/2026, 03:31:40 UTC |
0 CVE-2026-88779 is a high-severity vulnerability affecting NetScaler ADC and NetScaler Gateway products. It impacts versions before 14.1-73.41, 13.1-64.28, and 13.1-37.282. The vulnerability has a CVSS 4.0 base score of 8.7, indicating a significant security risk. No known exploits are reported in the wild, and the affected products are not cloud services. Join the discussion | CVE Database V5 | 10/04/2026, 02:35:35 UTC Added: 10/04/2026, 03:31:40 UTC |
CVE-2026-105097 is an authorization bypass vulnerability in Omega Solution CoinEx Crypto 2025 affecting the Customer Information API component. The flaw arises from manipulation of the ID argument in the /customer-currency/ file, allowing unauthorized access. Remote exploitation is possible, and public exploit code exists. The vendor has not responded to disclosure and the product website is no longer available, suggesting possible retirement or replacement of the product. Join the discussion | CVE Database V5 | 10/04/2026, 02:00:11 UTC Added: 10/04/2026, 02:31:41 UTC |
Google's Gemini AI is reportedly testing a feature that could grant it broad access to macOS devices, including files, apps, and web browsing capabilities, potentially without asking for permission each time. This capability is not yet live and has not been officially confirmed by Google. The feature would allow Gemini to read, create, modify, or delete files anywhere on the Mac, and interact with native apps such as Mail, Safari, and Messages. However, Gemini would still require explicit user permission for sensitive actions like financial transactions or accepting legal terms. The rollout timeline and specific Gemini model involved remain unclear. Apple is reportedly considering restrictions to limit AI agents' access to personal data on Macs. Join the discussion | Bleeping Computer | 10/03/2026, 23:12:34 UTC Added: 10/03/2026, 23:16:13 UTC |
0 CVE-2026-105124 is a stored cross-site scripting (XSS) vulnerability in vincent-peugnet wcms versions up to 3.18.0. It allows unauthenticated attackers to inject malicious scripts via the login user field and visitor comment website field. These scripts can execute with administrator or editor privileges when rendered in specific admin interfaces such as adminlog.php and editrightbar.php. Join the discussion | CVE Database V5 | 10/03/2026, 22:30:13 UTC Added: 10/03/2026, 23:31:37 UTC |
0 CVE-2026-105123 is a high-severity remote code execution vulnerability in vincent-peugnet wcms through version 3.18.0. Authenticated editors can exploit an unrestricted file upload flaw via the /api/v0/media/upload/ endpoint to upload arbitrary files, including executable .php files. The vulnerability also allows path traversal using encoded ../ sequences to write files outside the intended media directory and supports arbitrary file deletion via the DELETE /api/v0/media/ endpoint. Join the discussion | CVE Database V5 | 10/03/2026, 22:30:12 UTC Added: 10/03/2026, 23:31:37 UTC |
This content is a discussion post referencing a YouTube video that speculates about AI potentially reversing engineering digital systems and causing disruption. The post questions the video's claims, noting that actual compromise of server architectures would require encryption keys or authentication bypass methods. It also contrasts this with offline product piracy, which may be easier to achieve. There is no concrete vulnerability or exploit detailed. Join the discussion | Reddit Cybersecurity | 10/03/2026, 21:33:07 UTC Added: 10/03/2026, 21:46:01 UTC |
A suspected member of the ShinyHunters hacking group, known as Rey (Saif al-Din Khader), has been detained in Jordan and is cooperating with the FBI to help identify and locate other group members. ShinyHunters is an extortion group known for massive data thefts and attacks on cloud SaaS environments. The group claimed responsibility for a cyberattack on FBI systems using an alleged Oracle PeopleSoft zero-day vulnerability, though this has not been independently verified. Following arrests and law enforcement pressure, ShinyHunters operations have shown signs of disruption, but some activity continues. Rey has been linked to multiple high-profile breaches and extortion campaigns over the past two years. Cooperation from detained members is aiding ongoing investigations and arrests. HighThreat Actor Join the discussion | Bleeping Computer | 10/03/2026, 19:09:38 UTC Added: 10/03/2026, 19:16:16 UTC |
The infrabench package on PyPI is a malicious package that pretends to perform legitimate activities but actually deploys a cryptocurrency miner. It is part of a campaign identified as 2026-10-voxeval with clear malicious intent. The affected versions are 0.1.0, 0.1.1, and 0.2.0. Join the discussion | GCVE Database | 10/03/2026, 16:21:40 UTC Added: 10/03/2026, 17:20:36 UTC |
Showing 1 to 10 of 143631 results