Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation Join the discussion | CVE Database V5 | 07/23/2026, 08:03:58 UTC Added: 07/23/2026, 08:37:35 UTC |
The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signature validation when the wildcard answer is a CNAME or DNAME record. Join the discussion | CVE Database V5 | 07/23/2026, 08:03:37 UTC Added: 07/23/2026, 08:37:35 UTC |
0 If the auth responds very slowly and the records expire in between, the capping of TTLs is not enforced for lack of data. This does not happen on regular resolve as then then the child records are used immediately if not expired and thus valid, or the records are expired, and in that case not used. So this case can only happen if almost expired records are used to refresh the authoritative NS records. Join the discussion | CVE Database V5 | 07/23/2026, 07:49:04 UTC Added: 07/23/2026, 08:37:35 UTC |
This fix provides extra hardening for the 5.4.x branch by doing extra validation of incoming answers from authoritative servers. Join the discussion | CVE Database V5 | 06/25/2026, 13:16:45 UTC Added: 06/25/2026, 14:16:21 UTC |
Spoofing replies to Recursor might mark an IP of an authoritative server as not supporting EDNS, causing valdiation of DNSSEC records served by that server to fail. Join the discussion | CVE Database V5 | 06/25/2026, 13:01:40 UTC Added: 06/25/2026, 14:16:23 UTC |
An invalid zone might pass ZONEMD validation while it should not. This is only relevant if ZoneToCache is configured with ZONEMD validation. Join the discussion | CVE Database V5 | 06/25/2026, 13:01:08 UTC Added: 06/25/2026, 14:16:21 UTC |
Incomplete validation of the SOA record present in a catalog zone might lead to a crash. Join the discussion | CVE Database V5 | 06/25/2026, 12:59:38 UTC Added: 06/25/2026, 14:16:21 UTC |
A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to a crash of the Recursor due to insuffcient input validation. Join the discussion | CVE Database V5 | 06/25/2026, 12:59:16 UTC Added: 06/25/2026, 14:16:21 UTC |
ECS zero scoped answers are stored in the packet cache while they should not. This impacts only configurations that have ECS enabled; Join the discussion | CVE Database V5 | 06/25/2026, 12:58:51 UTC Added: 06/25/2026, 14:16:21 UTC |
0 A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to cache poisoning. Join the discussion | CVE Database V5 | 06/25/2026, 12:58:27 UTC Added: 06/25/2026, 13:16:11 UTC |
Showing 1 to 10 of 23 results