Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

142K Leaked Attacker Files
0

A large collection of 142,000 attacker files was leaked, revealing detailed offensive operations by a threat actor. The leak includes agent transcripts, shell histories, reconnaissance data, exploit tools, stolen credentials, and victim evidence. Notably, the operator integrated AI coding agents into their attack workflow, bypassing approval checks and automating tasks via Telegram. The data dump also shows compromise of nearly 9,000 WordPress sites, a large reconnaissance corpus of 3.4 million hosts, cryptojacking activity, and an experimental blockchain-based command and control project. This leak provides insight into how AI agents are being used alongside traditional offensive tools at scale. No direct patch or remediation information is available from the source.

Join the discussion
CVE-2026-14163: Sensitive Variables exposed in Deployment Variable Snapshot JSON in Octopus Deploy Octopus ServerCVE-2026-14163
0

CVE-2026-14163 is a vulnerability in Octopus Server versions 3.2.6 and 2026.2.61 where sensitive variables may be exposed in clear-text within the deployment variable snapshot JSON under certain conditions. This exposure could allow unauthorized users with limited privileges to view sensitive information. The vulnerability has a high severity rating with a CVSS score of 7.1. No official patch or remediation guidance is currently provided by the vendor, and there are no known exploits in the wild.

Join the discussion
Microsoft says August Windows updates may cause gaming issues
0

Microsoft is investigating issues caused by the August 2026 Windows updates (notably KB5121003) that may prevent some games from launching or cause them to crash on Windows 11 systems, specifically versions 24H2 and 25H2. Affected users report symptoms such as games freezing, closing unexpectedly, EXCEPTION_ACCESS_VIOLATION errors, and system restarts. Microsoft has acknowledged the problem and is currently investigating the root cause. Users experiencing these issues are encouraged to report them via the Feedback Hub. No official patch or fix has been announced yet.

Join the discussion
CVE-2026-71368: Cross-site scripting (XSS) in Thinkingreed Inc. F-RevoCRMCVE-2026-71368
0

A cross-site scripting (XSS) vulnerability exists in Thinkingreed Inc.'s F-RevoCRM product. When a logged-in user views a specially crafted page, this vulnerability may allow unintended operations to be performed. The vulnerability has a CVSS score of 6.1, indicating medium severity. No specific affected versions or patches have been disclosed yet.

Join the discussion
CVE-2026-75860: CWE-269 Improper Privilege Management in JSON OptionsCVE-2026-75860
0

The JSON Options WordPress plugin up to version 0.0.4 contains a vulnerability where an action accessible to unauthenticated users lacks capability checks and nonce verification. This flaw allows attackers to update arbitrary WordPress options, potentially enabling user registration with the default role set to administrator. Exploiting this vulnerability can lead to privilege escalation and full site takeover.

Join the discussion
CVE-2026-74992: CWE-79 Cross-Site Scripting (XSS) in KirkiCVE-2026-74992
0

CVE-2026-74992 is a vulnerability in the Kirki WordPress plugin before version 6.2.3. It allows users with the Editor role to upload archives containing arbitrary files without proper validation or cleanup. This can lead to stored cross-site scripting (XSS) and potentially remote code execution (RCE) on some server configurations.

Join the discussion
CVE-2026-19699: CWE-863 Incorrect Authorization in GutenKitCVE-2026-19699
0

GutenKit WordPress plugin versions before 2.5.0 have insufficient authorization checks on certain REST API endpoints. This flaw allows users with Contributor role or higher to access mailing-list audience metadata from the connected marketing account. The vulnerability is classified as CWE-863 (Incorrect Authorization). There is no CVSS score or official patch information available yet.

Join the discussion
CVE-2026-19697: CWE-79 Cross-Site Scripting (XSS) in GutenKitCVE-2026-19697
0

GutenKit WordPress plugin versions before 2.5.0 have a stored Cross-Site Scripting (XSS) vulnerability due to improper sanitization of uploaded SVG files on some upload paths. This allows users with file upload capabilities, such as Authors, to upload malicious SVG files that can execute scripts when viewed by other users, including administrators.

Join the discussion
CVE-2026-19615: CWE-79 Cross-Site Scripting (XSS) in Admin and Site Enhancements (ASE)CVE-2026-19615
0

The Admin and Site Enhancements (ASE) WordPress plugin before version 9.0.1 contains a cross-site scripting (XSS) vulnerability due to improper sanitization of uploaded SVG files. This allows users with upload permissions to store SVG files containing JavaScript, which can execute in the browsers of users who open these files.

Join the discussion
CVE-2026-15049: CWE-434 Unrestricted Upload of File with Dangerous Type in Depicter — Popup & Slider BuilderCVE-2026-15049
0

The Depicter — Popup & Slider Builder WordPress plugin before version 4.8.0 contains a vulnerability where it does not validate file types during import uploads. This allows users with editor-level access to upload arbitrary files, including executable PHP scripts, to web-accessible directories. Such a flaw can lead to remote code execution if exploited.

Join the discussion

Showing 1 to 10 of 19927 results

Filters:Package: pkg:bitnami/java
Page 1 of 1993
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses