Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
Himmelblau versions from 2.0.0 up to but not including 2.3.11, and from 3.0.0-alpha up to but not including 3.1.5, contain an authentication bypass vulnerability in the Device Authorization Grant flow. This flaw allows a user within the same Microsoft Azure Entra ID domain to gain a local Unix session as another user by using their own valid credentials. Join the discussion | CVE Database V5 | 05/27/2026, 18:53:29 UTC Added: 05/27/2026, 19:35:06 UTC |
Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From versions 2.0.0-alpha to before 2.3.9 and 3.0.0-alpha to before 3.1.1, there is a conditional local privilege escalation vulnerability in an edge-case naming collision. Only authenticated himmelblau users whose mapped CN/short name exactly matches a privileged local group name (e.g., "sudo", "wheel", "docker", "adm") can cause the NSS module to resolve that group name to their fake primary group. If the system uses NSS results for group-based authorization decisions (sudo, polkit, etc.), this can grant the attacker the privileges of that group. This issue has been patched in versions 2.3.9 and 3.1.1. Join the discussion | CVE Database V5 | 04/01/2026, 17:25:06 UTC Added: 04/01/2026, 19:29:40 UTC |
0 Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Prior to 3.1.0 and 2.3.8, the himmelblaud-tasks daemon, running as root, writes Kerberos cache files under /tmp/krb5cc_<uid> without symlink protections. Since commit 87a51ee, PrivateTmp is explicitly removed from the tasks daemon's systemd hardening, exposing it to the host /tmp. A local user can exploit this via symlink attacks to chown or overwrite arbitrary files, achieving local privilege escalation. This vulnerability is fixed in 3.1.0 and 2.3.8. Join the discussion | CVE Database V5 | 03/11/2026, 19:47:05 UTC Added: 03/11/2026, 19:59:52 UTC |
0 CVE-2026-31957 is a critical vulnerability in himmelblau versions 3.0.0 up to but not including 3.1.0, an interoperability suite for Microsoft Azure Entra ID and Intune. The issue arises when himmelblau is deployed without a configured tenant domain in its configuration file, causing authentication to be unscoped to any tenant. This allows the system to accept authentication attempts for arbitrary Entra ID domains by dynamically registering providers at runtime, which is intended only for initial or local bootstrap scenarios. In remote authentication environments, this behavior can lead to unauthorized access, compromising confidentiality, integrity, and availability. The vulnerability has a CVSS score of 10.0, indicating critical severity, and is fixed in version 3. Join the discussion | CVE Database V5 | 03/11/2026, 19:25:21 UTC Added: 03/11/2026, 19:44:49 UTC |
Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. A vulnerability present in versions 0.9.10 through 0.9.16 allows a user to authenticate to a Linux host via Himmelblau using an *invalid* Linux Hello PIN, provided the host is offline. While the user gains access to the local system, Single Sign-On (SSO) fails due to the network being down and the inability to issue tokens (due to a failure to unlock the Hello key). The core issue lies in an incorrect assumption within the `acquire_token_by_hello_for_business_key` function: it was expected to return a `TPMFail` error for an invalid Hello key when offline, but instead, a preceding nonce request resulted in a `RequestFailed` error, leading the system to erroneously transition to an offline success state without validating the Hello key unlock. This impacts systems using Himmelblau for authentication when operating in an offline state with Hello PIN authentication enabled. Rocky Linux 8 (and variants) are not affected by this vulnerability. The problem is resolved in Himmelblau version 0.9.17. A workaround is available for users who cannot immediately upgrade. Disabling Hello PIN authentication by setting `enable_hello = false` in `/etc/himmelblau/himmelblau.conf` will mitigate the vulnerability. Join the discussion | CVE Database V5 | 06/26/2025, 18:02:31 UTC Added: 06/26/2025, 18:19:57 UTC |
Showing 1 to 5 of 5 results