Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/@moonshot-ai/kimi-code

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-88036 is a vulnerability in the GridFS component of the MongoDB C Driver where improper neutralization of special elements in data query logic allows a structured file identifier to be misinterpreted as a query condition. This can enable an authenticated user with influence over the identifier to access stored file content beyond the intended target or delete all GridFS file chunks in the affected bucket, making stored content unreadable.

Join the discussion

CVE-2026-88035 is an integer overflow vulnerability in the MongoDB C Driver's client-side authentication path. It occurs when a size check wraps around due to an unusually large user-name value, allowing the value to be copied beyond the bounds of a small buffer. This can cause the application embedding the driver to terminate unexpectedly. Exploitation requires a build with the optional external SASL authentication backend and a connection configured to use it.

Join the discussion

CVE-2026-88034 is a medium severity vulnerability in the GridFS component of the MongoDB C++ Driver. It involves improper neutralization of special elements in data query logic, allowing an authenticated user with limited privileges to manipulate a structured file identifier. This can lead to unauthorized access to stored file content beyond the intended target or deletion of all GridFS file chunks in the affected bucket, making stored files unreadable.

Join the discussion

CVE-2026-88033 is a vulnerability in the GridFS component of the MongoDB Java Driver where improper neutralization of special elements in data query logic allows a caller-supplied file identifier to be misinterpreted as a query condition. This can enable an authenticated user with influence over the identifier to access stored file content beyond the intended file, delete all file chunks in the affected bucket, or rename unintended files during a rename operation.

Join the discussion

CVE-2026-88032 is a high-severity use-after-free vulnerability in the reactive client-side encryption component of the MongoDB Java Driver. It occurs when native resources are freed while an encrypted operation is still using them if the operation is cancelled. Exploiting this requires a reactive encryption setup that retrieves KMS credentials on demand. Successful exploitation can cause the hosting application process to terminate.

Join the discussion

Cisco Talos disclosed a complex WebDAV infection chain linked to a Russian threat actor (UAT-10820) targeting a Ukrainian government organization. The campaign delivers the Amatera stealer along with secondary payloads such as ZigCryptoStealer and NetSupport Manager. This operation appears opportunistic and broad-based, focusing on cryptocurrency and credential theft rather than a highly targeted attack. Attackers use creative delivery and evasion techniques, including abusing legitimate infrastructure like the BNB Smart Chain for bulletproof hosting and fake CAPTCHA prompts to bypass web filters. Secondary payloads include a vulnerable driver to terminate endpoint detection and response (EDR) software and unauthorized remote access tools, enabling persistent control over infected systems. Security teams are advised to monitor for unusual WebDAV activity and suspicious DLL execution via rundll32.exe ordinal calls, educate users about fake verification prompts, and ensure endpoint solutions have robust memory scanning capabilities. No patch information is provided for this threat. The disclosure also includes a broader discussion on cybersecurity workforce mental health but is unrelated to the technical threat.

HighAnalysis#cisco
Join the discussion

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Go Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable.

Join the discussion

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Ruby Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable.

Join the discussion

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Python Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable. The affected rename operation may also rename a stored file other than the intended target.

Join the discussion

Improper neutralization of special elements in data query logic in the polymorphic relation handling of the MongoDB integration for Laravel can cause a caller-supplied relation identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence a stored relation identifier may cause an affected application to return a document other than the intended relation target.

Join the discussion

Showing 1 to 10 of 131972 results

Filters:Package: pkg:github/@moonshot-ai/kimi-code
Page 1 of 13198
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses