Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
A flaw was found in crun. When the container configuration does not give /dev a dedicated mount, terminal setup can redirect /dev/console onto an attacker-controlled path, including via the read-only-rootfs bind-mount fallback. Affected versions are crun 1.29.1 and earlier. Default configurations that mount a fresh /dev are not exposed. No fixed release is available yet. Join the discussion | GCVE Database | 09/10/2026, 09:31:34 UTC Added: 09/10/2026, 13:23:43 UTC |
0 CVE-2026-88265 is a moderate security flaw in crun affecting versions 1.29.1 and earlier. The vulnerability allows a non-root container process to follow a symlink when reopening /dev/null after pivot_root, potentially attaching a host file to container stdio and changing its ownership. This requires specific conditions, such as a malicious container image replacing /dev/null with a symlink and the container not mounting a fresh /dev. No fixed release is currently available, and default configurations that mount a fresh /dev are not exposed to this issue. Join the discussion | GCVE Database | 09/10/2026, 08:57:03 UTC Added: 09/10/2026, 13:23:43 UTC |
CVE-2026-84042 is a high-severity vulnerability in crun affecting versions 1.29 and later. When crun is built with libkrun and a container is started rootful with passt networking enabled (krun.use_passt), it can execute attacker-controlled payloads from the container image with host root privileges. This is a regression introduced in crun 1.29. The issue involves improper privilege management, allowing privilege escalation to host root. Mitigation currently involves avoiding running untrusted container images with krun and passt networking until a fixed version is released. Join the discussion | GCVE Database | 09/10/2026, 08:24:50 UTC Added: 09/10/2026, 13:23:43 UTC |
crun is an open source OCI Container Runtime fully written in C. Prior to version 1.28, crun's default device setup opens the container rootfs `/dev` directory without `O_NOFOLLOW`. If an OCI bundle contains `rootfs/dev` as a symlink and the bundle configuration does not mount `/dev`, crun follows that symlink and creates the default device nodes and stdio symlinks at the symlink target outside the container rootfs. In a local rootful crun replay, this created fixed device nodes and symlinks outside the rootfs before crun returned failure. A pre-existing file named `ptmx` in the target directory was also replaced by crun's forced `ptmx -> pts/ptmx` symlink. Version 1.28 fixes the issue. Join the discussion | CVE Database V5 | 08/14/2026, 16:16:37 UTC Added: 08/14/2026, 16:27:44 UTC |
Showing 1 to 4 of 4 results