Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-48037: CWE-693: Protection Mechanism Failure in kerberosmansour hulumiCVE-2026-48037 0 Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, AccountFoundation reuse paths silently downgrade GuardDuty / Security Hub posture. This issue has been patched in version 1.4.0. Join the discussion | CVE Database V5 | 07/24/2026, 18:44:23 UTC Added: 07/24/2026, 19:07:40 UTC |
CVE-2026-48036: CWE-755: Improper Handling of Exceptional Conditions in kerberosmansour hulumiCVE-2026-48036 0 Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, consumers running drift detection in CI / cron could see transient adapter failures silently cached as "all clear" — masking real attacks for up to six hours — or see ordinary provider-version churn falsely promoted to incident severity. Either way, the verdict source was unreliable for downstream incident workflows that gate on it. This issue has been patched in version 1.4.0. Join the discussion | CVE Database V5 | 07/24/2026, 18:44:05 UTC Added: 07/24/2026, 19:07:40 UTC |
CVE-2026-48035: CWE-1059: Insufficient Technical Documentation in kerberosmansour hulumiCVE-2026-48035 0 Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, consumers using AccountFoundation could ship an AWS account whose CloudTrail / Config audit logs were deletable by any S3-delete-capable principal — while believing the startup-hardened tier guaranteed tamper-resistance. Sandbox-tier deployments had no audit immutability at all (defects 1 and 3 compounded). This issue has been patched in version 1.4.0. Join the discussion | CVE Database V5 | 07/24/2026, 18:43:35 UTC Added: 07/24/2026, 19:07:40 UTC |
CVE-2026-48034: CWE-284: Improper Access Control in kerberosmansour hulumiCVE-2026-48034 0 Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, there is a bypass via decoy sibling resources targeting a different bucket. This issue has been patched in version 1.4.0. Join the discussion | CVE Database V5 | 07/24/2026, 18:38:53 UTC Added: 07/24/2026, 19:07:40 UTC |
CVE-2026-48033: CWE-693: Protection Mechanism Failure in kerberosmansour hulumiCVE-2026-48033 0 Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, policy packs can be bypassed by a forged Pulumi-URN logical name. This issue has been patched in version 1.4.0. Join the discussion | CVE Database V5 | 07/24/2026, 18:39:18 UTC Added: 07/24/2026, 19:07:40 UTC |
CVE-2026-48032: CWE-697: Incorrect Comparison in kerberosmansour hulumiCVE-2026-48032 0 Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, IAM-role policy checks can be bypassed when the role trusts multiple OIDC providers. This issue has been patched in version 1.4.0. Join the discussion | CVE Database V5 | 07/24/2026, 18:39:05 UTC Added: 07/24/2026, 19:07:40 UTC |
Showing 1 to 6 of 6 results