Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:npm/@agiflowai/aicode-toolkit

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

A threat actor compromised the official HBO Max Reddit account and used it to run a malvertising campaign that directed macOS and Windows users to a fake HBO Max site. The site prompted users to execute commands that installed malware designed to steal credentials, messages, browser data, and cryptocurrency wallet information, and maintain persistence. The campaign, active for 48 hours, used multiple malware families including MacSync, AMOS Helper, Amatera Stealer, AnimateClipper, and ZigClipper. Clipboard stealers replaced cryptocurrency addresses to divert transactions. Reddit suspended the malicious ads after notification.

Join the discussion

CVE-2026-91782 is a medium severity vulnerability in GNU Binutils version 2.47. It involves a null pointer dereference in the elf_x86_allocate_dynrelocs function within the Dynamic Relocation Allocation component. The vulnerability requires local access to exploit and does not require user interaction. Exploit code is publicly available. Upgrading to GNU Binutils version 2.48 resolves the issue.

Join the discussion

A hidden functionality vulnerability exists in LITE-ON Technology Corporation FF-RFI079I4 and FF-RFI078I4 devices. This flaw allows users with SSH login and enable mode access to execute arbitrary operating system commands. The vulnerability affects versions from initial releases up to but not including version 02.01.15. It has a high severity rating with a CVSS score of 8.8.

Join the discussion

CVE-2026-77853 is an OS command injection vulnerability in LITE-ON Technology Corporation's FF-RFI079I4 and FF-RFI078I4 products. It allows a user with login access to the product's M-Plane (NETCONF) interface to execute arbitrary operating system commands. This vulnerability affects versions from 0 up to but not including 02.01.15. The issue is classified as high severity with a CVSS score of 8.8.

Join the discussion

CVE-2026-91826 is a stack-based buffer overflow vulnerability in Samsung Opensource rLottie, a library for rendering vector animations. The flaw allows attackers to cause memory corruption by overflowing buffers when processing specially crafted vector animations. This vulnerability has a medium severity rating with a CVSS score of 4.4. No affected versions or patch information are explicitly provided.

Join the discussion

CVE-2026-91781 is a medium severity vulnerability in GNU Binutils 2.47 involving a null pointer dereference in the ELF Section Handler function elf_x86_64_common_section_index. The issue requires local access to exploit and has been publicly disclosed. Upgrading to version 2.48 addresses the vulnerability.

Join the discussion

Microsoft has acknowledged that the September 2026 security update KB5002914 for Excel causes copy and paste operations to silently fail for some users. This issue affects the usability of Excel but does not indicate a security vulnerability or exploitation. No affected versions or patch status details are provided.

LowNews
Join the discussion

CVE-2026-91780 is a medium severity vulnerability in GNU Binutils 2.47 involving a null pointer dereference in the elf_link_add_object_symbols function within bfd/elflink.c. The flaw requires local access to exploit and could lead to a denial of service or application crash. Public exploit code is available, but no vendor response or patch has been issued yet.

Join the discussion

CVE-2026-75092 is a privilege escalation vulnerability in the leapp-upgrade-el9toel10 tool used during Red Hat Enterprise Linux upgrades from version 9 to 10. The flaw arises because the scan_mysql actor runs the MySQL daemon validation command as root, bypassing normal user restrictions. An attacker with OS-level access as the mysql user can place malicious plugins in a MySQL-owned directory, which are then loaded during the upgrade process with root privileges. This allows arbitrary code execution as root in an unconfined SELinux domain when an administrator runs the upgrade workflow. The vulnerability requires prior compromise of the mysql OS identity and administrator invocation of the upgrade process. No patch or mitigation currently meets Red Hat's criteria for deployment.

Join the discussion

CVE-2026-91779 is a medium severity vulnerability in GNU Binutils 2.47 affecting the Eh Frame Handler component. It involves a null pointer dereference in the _bfd_elf_eh_frame_section_offset function, which can be triggered by a local attacker. The vulnerability has a CVSS score of 4.8 and public exploit code is available. The vendor has not yet responded or issued a patch.

Join the discussion

Showing 1 to 10 of 131733 results

Filters:Package: pkg:npm/@agiflowai/aicode-toolkit
Page 1 of 13174
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses