Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-46580: CWE-829: Inclusion of Functionality from Untrusted Control Sphere in Eclipse Foundation Eclipse TheiaCVE-2026-46580 0 In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were automatically loaded and could override or extend the AI agent's system prompts. An attacker could craft a malicious repository containing prompt template files that, when the workspace was opened in Theia, replaced the AI's system instructions with attacker-controlled content (indirect prompt injection). Combined with other AI chat features available in untrusted workspaces, this enabled attack chains leading to data exfiltration via Markdown image rendering or arbitrary command execution via task definitions. Join the discussion | CVE Database V5 | 06/18/2026, 14:26:59 UTC Added: 06/18/2026, 15:20:12 UTC |
CVE-2026-44691: CWE-829: Inclusion of Functionality from Untrusted Control Sphere in Eclipse Foundation Eclipse TheiaCVE-2026-44691 0 In Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g. .theia/tasks.json, .vscode/tasks.json) could be executed without requiring workspace trust. An attacker could craft a malicious repository that, when cloned and opened in Theia, leads to execution of arbitrary commands with the user's privileges. In combination with AI chat features and a workspace .theia/settings.json that disabled tool confirmation, this could be triggered automatically by sending a message in the AI chat. Join the discussion | CVE Database V5 | 06/18/2026, 14:35:25 UTC Added: 06/18/2026, 15:20:12 UTC |
CVE-2026-44688: CWE-1427 Improper neutralization of input used for LLM prompting in Eclipse Foundation Eclipse TheiaCVE-2026-44688 0 In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part of its prompt context without distinguishing them from system instructions. An attacker could craft a malicious repository with adversarial directory or file names that, when analyzed by the AI agent, would cause the agent to follow attacker-controlled instructions (indirect prompt injection). Combined with other AI chat features available in untrusted workspaces, this enabled attack chains leading to data exfiltration via Markdown image rendering or arbitrary command execution via task definitions. Join the discussion | CVE Database V5 | 06/18/2026, 14:22:33 UTC Added: 06/18/2026, 15:20:12 UTC |
CVE-2026-22551: CWE-201: Insertion of Sensitive Information Into Sent Data in Eclipse Foundation Eclipse TheiaCVE-2026-22551 0 In Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown image tags from AI responses, triggering HTTP requests to arbitrary external URLs without restriction. Combined with prompt injection in a malicious workspace, an attacker could induce the AI agent to construct image URLs encoding sensitive information from the workspace or conversation context, exfiltrating it to attacker-controlled servers. The workspace trust enforcement introduced in v1.71.0 mitigates the documented attack chain by disabling AI features in untrusted workspaces. Join the discussion | CVE Database V5 | 06/18/2026, 14:32:01 UTC Added: 06/18/2026, 15:20:12 UTC |
Showing 1 to 4 of 4 results