Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/monica-ai/desktop

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-17106, known as CopyEscape, is a high-severity vulnerability in Docker's 'docker cp' command that allows a malicious container to write arbitrary files to the host filesystem. The flaw stems from a filesystem race condition during archive creation combined with unsafe symbolic link handling during extraction. This can lead to arbitrary file creation or overwriting on the host and potentially code execution depending on the privileges of the Docker CLI user. Docker has released official fixes in Docker Engine/CLI version 29.7.2 and later, Docker Desktop 4.86.0 and later, and Docker Sandboxes 0.38.0 and later.

Join the discussion

Mattermost Desktop App versions up to 6.2.2.0 do not redact the pre-authentication secret in diagnostics reports. This allows a local attacker with access to these reports or log files to obtain the plaintext pre-auth secret configured for a connected server. The vulnerability is identified as CVE-2026-75587 and has a low severity rating.

Join the discussion

Zen is a firefox-based browser. Prior to 1.19.13b, Zen Browser did not provide a persistent, clearly visible security notification when a webpage entered fullscreen mode, allowing an attacker-controlled page to hide the real browser UI and origin information, imitate a trusted website UI, and combine with long-domain URL eliding to spoof a trusted origin for phishing and credential theft. This issue is fixed in version 1.19.13b.

Join the discussion

Zen is a firefox-based browser. Prior to 1.21.5b, Zen's glance and split-view context-menu actions, Open link in glance and Split link in new tab, load a page-controlled link URL with the System principal instead of the originating page's principal, allowing a malicious web page to place a link to a file URL that can load with System privileges when opened through either context-menu item and bypass the content-to-file security check that blocks an ordinary click. This issue is fixed in version 1.21.5b.

Join the discussion

CVE-2026-8936 is a high-severity vulnerability affecting Docker Desktop version 4.33.0. It involves uncontrolled recursion in the grpcfuse kernel module, which can cause a virtual machine panic when a container creates deeply nested directories on a bind-mounted host folder. This triggers a dentry invalidation event leading to the issue. The vulnerability has been fixed in Docker Desktop version 4.76.0.

Join the discussion

The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and executes arbitrary Python files from model directories via the model_file configuration field in config.json. When a model's config.json specifies a model_file pointing to a Python file, MLX-LM uses importlib to load and execute it with no trust_remote_code gate or equivalent safety check. The MLX backend runs without sandboxing, resulting in arbitrary code execution on the Docker host as the Docker Desktop user. Any container on the Docker network can trigger this by calling the model-runner.docker.internal API to pull a malicious model from an attacker-controlled OCI registry and request inference.

Join the discussion

The vllm-metal inference backend in Docker Model Runner on macOS unconditionally sets trust_remote_code=True when loading model tokenizers, and runs without sandboxing. This causes transformers.AutoTokenizer.from_pretrained() to import and execute arbitrary Python files included in any model pulled from an OCI registry, resulting in arbitrary code execution on the Docker host as the Docker Desktop user when inference is triggered. Any container on the Docker network can trigger this by calling the model-runner.docker.internal API to pull a malicious model and request inference.

Join the discussion

CVE-2026-44659 is a medium-severity vulnerability in the Zen Browser desktop versions prior to 1.19.12b. The browser incorrectly truncates long hostnames in the address bar, showing only the attacker-controlled prefix of a subdomain and hiding the actual registrable domain. This UI misrepresentation can mislead users into trusting malicious sites that visually imitate legitimate brands, compromising the URL bar as a security indicator and enabling phishing or supply-chain attacks. The issue is fixed in version 1.19.12b. No known exploits are reported in the wild.

Join the discussion

Zen is a firefox-based browser. Prior to 1.19.12b, RSS feed URLs entered by the user are validated to http: or https: in promptForFeedUrl, but item links inside the feed are not subject to the same restriction. The provider maps each RSS/Atom item link into item.url, filters only for presence and date, and returns the item list. The live-folder manager later creates pinned lazy tabs from these values with gBrowser.addTrustedTab(item.url, ...). This vulnerability is fixed in 1.19.12b.

Join the discussion

Zen is a firefox-based browser. Prior to 1.19.9b, Zen Browser ships a Mozilla Application Resource (MAR) updater (org.mozilla.updater) that has had all MAR signature verification stripped from the Firefox codebase it was forked from. The MAR files served to users contain zero cryptographic signatures, and the updater binary contains zero cryptographic verification code. This eliminates the defense-in-depth that MAR signing provides. If the update server or GitHub release pipeline is compromised, arbitrary unsigned code can be delivered to all Zen users via the auto-update mechanism. This vulnerability is fixed in 1.19.9b.

Join the discussion

Showing 1 to 10 of 28 results

Filters:Package: pkg:github/monica-ai/desktop
Page 1 of 3
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses