Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
142K Leaked Attacker Files 0 A large collection of 142,000 attacker files was leaked, revealing detailed offensive operations by a threat actor. The leak includes agent transcripts, shell histories, reconnaissance data, exploit tools, stolen credentials, and victim evidence. Notably, the operator integrated AI coding agents into their attack workflow, bypassing approval checks and automating tasks via Telegram. The data dump also shows compromise of nearly 9,000 WordPress sites, a large reconnaissance corpus of 3.4 million hosts, cryptojacking activity, and an experimental blockchain-based command and control project. This leak provides insight into how AI agents are being used alongside traditional offensive tools at scale. No direct patch or remediation information is available from the source. Join the discussion | Reddit Cybersecurity | 08/20/2026, 07:14:14 UTC Added: 08/20/2026, 07:22:03 UTC |
CVE-2026-14163: Sensitive Variables exposed in Deployment Variable Snapshot JSON in Octopus Deploy Octopus ServerCVE-2026-14163 0 CVE-2026-14163 is a vulnerability in Octopus Server versions 3.2.6 and 2026.2.61 where sensitive variables may be exposed in clear-text within the deployment variable snapshot JSON under certain conditions. This exposure could allow unauthorized users with limited privileges to view sensitive information. The vulnerability has a high severity rating with a CVSS score of 7.1. No official patch or remediation guidance is currently provided by the vendor, and there are no known exploits in the wild. Join the discussion | CVE Database V5 | 08/20/2026, 06:48:07 UTC Added: 08/20/2026, 06:52:55 UTC |
Microsoft says August Windows updates may cause gaming issues 0 Microsoft is investigating issues caused by the August 2026 Windows updates (notably KB5121003) that may prevent some games from launching or cause them to crash on Windows 11 systems, specifically versions 24H2 and 25H2. Affected users report symptoms such as games freezing, closing unexpectedly, EXCEPTION_ACCESS_VIOLATION errors, and system restarts. Microsoft has acknowledged the problem and is currently investigating the root cause. Users experiencing these issues are encouraged to report them via the Feedback Hub. No official patch or fix has been announced yet. Join the discussion | Bleeping Computer | 08/20/2026, 06:51:03 UTC Added: 08/20/2026, 06:52:18 UTC |
CVE-2026-71368: Cross-site scripting (XSS) in Thinkingreed Inc. F-RevoCRMCVE-2026-71368 0 A cross-site scripting (XSS) vulnerability exists in Thinkingreed Inc.'s F-RevoCRM product. When a logged-in user views a specially crafted page, this vulnerability may allow unintended operations to be performed. The vulnerability has a CVSS score of 6.1, indicating medium severity. No specific affected versions or patches have been disclosed yet. Join the discussion | CVE Database V5 | 08/20/2026, 06:28:34 UTC Added: 08/20/2026, 06:37:39 UTC |
CVE-2026-75860: CWE-269 Improper Privilege Management in JSON OptionsCVE-2026-75860 0 The JSON Options WordPress plugin up to version 0.0.4 contains a vulnerability where an action accessible to unauthenticated users lacks capability checks and nonce verification. This flaw allows attackers to update arbitrary WordPress options, potentially enabling user registration with the default role set to administrator. Exploiting this vulnerability can lead to privilege escalation and full site takeover. Join the discussion | CVE Database V5 | 08/20/2026, 06:00:16 UTC Added: 08/20/2026, 06:07:53 UTC |
CVE-2026-74992: CWE-79 Cross-Site Scripting (XSS) in KirkiCVE-2026-74992 0 CVE-2026-74992 is a vulnerability in the Kirki WordPress plugin before version 6.2.3. It allows users with the Editor role to upload archives containing arbitrary files without proper validation or cleanup. This can lead to stored cross-site scripting (XSS) and potentially remote code execution (RCE) on some server configurations. Join the discussion | CVE Database V5 | 08/20/2026, 06:00:16 UTC Added: 08/20/2026, 06:07:53 UTC |
CVE-2026-19699: CWE-863 Incorrect Authorization in GutenKitCVE-2026-19699 0 GutenKit WordPress plugin versions before 2.5.0 have insufficient authorization checks on certain REST API endpoints. This flaw allows users with Contributor role or higher to access mailing-list audience metadata from the connected marketing account. The vulnerability is classified as CWE-863 (Incorrect Authorization). There is no CVSS score or official patch information available yet. Join the discussion | CVE Database V5 | 08/20/2026, 06:00:15 UTC Added: 08/20/2026, 06:07:53 UTC |
CVE-2026-19697: CWE-79 Cross-Site Scripting (XSS) in GutenKitCVE-2026-19697 0 GutenKit WordPress plugin versions before 2.5.0 have a stored Cross-Site Scripting (XSS) vulnerability due to improper sanitization of uploaded SVG files on some upload paths. This allows users with file upload capabilities, such as Authors, to upload malicious SVG files that can execute scripts when viewed by other users, including administrators. Join the discussion | CVE Database V5 | 08/20/2026, 06:00:15 UTC Added: 08/20/2026, 06:07:53 UTC |
CVE-2026-19615: CWE-79 Cross-Site Scripting (XSS) in Admin and Site Enhancements (ASE)CVE-2026-19615 0 The Admin and Site Enhancements (ASE) WordPress plugin before version 9.0.1 contains a cross-site scripting (XSS) vulnerability due to improper sanitization of uploaded SVG files. This allows users with upload permissions to store SVG files containing JavaScript, which can execute in the browsers of users who open these files. Join the discussion | CVE Database V5 | 08/20/2026, 06:00:15 UTC Added: 08/20/2026, 06:07:53 UTC |
CVE-2026-15049: CWE-434 Unrestricted Upload of File with Dangerous Type in Depicter — Popup & Slider BuilderCVE-2026-15049 0 The Depicter — Popup & Slider Builder WordPress plugin before version 4.8.0 contains a vulnerability where it does not validate file types during import uploads. This allows users with editor-level access to upload arbitrary files, including executable PHP scripts, to web-accessible directories. Such a flaw can lead to remote code execution if exploited. Join the discussion | CVE Database V5 | 08/20/2026, 06:00:15 UTC Added: 08/20/2026, 06:07:53 UTC |
Showing 1 to 10 of 19927 results