Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
suspicious folder in edge userdata 0 A Reddit user reported discovering a suspicious folder named 'Edge Data Protection Lists' within the Microsoft Edge user data directory. The folder contains files such as smart_switch_list.json, llm_user_input_extractor_config.json, manifest.json, and office_endpoints_list.json. The user questioned the safety of these files while investigating Edge's cookie storage. No further technical details or vendor advisories are available. Join the discussion | Reddit Cybersecurity | 06/20/2026, 00:16:28 UTC Added: 06/20/2026, 00:26:25 UTC |
ThreatFox MISP Feed | 06/19/2026, 00:00:00 UTC Added: 06/20/2026, 00:11:19 UTC | |
Issue with containerd CRI Plugin - CVE-2026-50195, CVE-2026-53488, CVE-2026-53492, CVE-2026-53489, CVE-2026-47262CVE-2026-50195 0 Multiple vulnerabilities have been identified in the containerd CRI plugin affecting versions 1.7 through 2.3. These include issues such as image cache poisoning, arbitrary host command execution, device and host mount injection, arbitrary host file read, and denial of service via uncontrolled memory consumption. The vulnerabilities impact containerd runtimes used in Kubernetes environments and AWS managed container services. AWS is deploying patched runtimes for managed services, and patched releases are available upstream. Workarounds include disabling checkpoint/restore and CDI features where applicable. Join the discussion | AWS Security Bulletins | 06/19/2026, 00:29:27 UTC Added: 06/20/2026, 00:05:06 UTC |
AutoJack: How a single page can RCE the host running your AI agent 0 AutoJack is an exploit chain that allows a single malicious webpage to achieve remote code execution (RCE) on the host machine running an AI browsing agent. It abuses trust in localhost, lack of authentication, and unsafe parameter handling in AutoGen Studio’s MCP WebSocket. This vulnerability demonstrates that when AI agents browse untrusted content and access local services, traditional security boundaries like localhost can be bypassed. The exploit highlights a critical security risk for AI agents with local service access. Join the discussion | Microsoft Security Blog | 06/19/2026, 00:17:54 UTC Added: 06/20/2026, 00:04:36 UTC |
CVE-2026-11551: CWE-640 Weak Password Recovery Mechanism for Forgotten Password in wpmudev Branda – White Label & Branding, Free Login Page CustomizerCVE-2026-11551 0 The Branda plugin for WordPress contains a critical vulnerability that allows unauthenticated attackers to escalate privileges by taking over user accounts. This occurs because the plugin fails to properly validate user identity before allowing password updates. As a result, attackers can change passwords of arbitrary users, including administrators, gaining unauthorized access. The vulnerability affects all versions up to and including 3.4.29. No official patch or remediation guidance has been provided yet. Join the discussion | CVE Database V5 | 06/19/2026, 23:29:21 UTC Added: 06/19/2026, 23:41:33 UTC |
Office for Android Spoofing VulnerabilityCVE-2026-45649 0 CVE-2026-45649 is a high-severity spoofing vulnerability affecting Microsoft Excel for Android. The vulnerability relates to improper access control (CWE-284) that could allow an attacker to spoof or impersonate legitimate functionality or content within the application. The affected versions include all versions up to and including 16.0.20131.20024. No patch or official remediation information is currently provided. There are no known exploits in the wild at this time. Join the discussion | GCVE Database | 06/09/2026, 07:00:00 UTC Added: 06/19/2026, 22:59:43 UTC |
Klue OAuth breach victim list grows as Icarus hackers claim attack 0 Market intelligence platform Klue has publicly confirmed a recent security incident that allowed threat actors to steal OAuth tokens used to connect to customers' Salesforce environments, as the new "Icarus" extortion group publicly claims the attack. [...] Join the discussion | Bleeping Computer | 06/19/2026, 22:31:04 UTC Added: 06/19/2026, 22:41:37 UTC |
CVE-2026-56082: Improper Access Control in Cap-go capgoCVE-2026-56082 0 Capgo (Cap-go/capgo) before 12.128.2 contains an improper access control vulnerability in the SECURITY DEFINER PostgREST RPC function public.record_build_time, which is granted to the anon role and callable with only the public Supabase publishable (sb_publishable_*) anon key. An unauthenticated attacker can insert rows into public.build_logs for arbitrary organizations and, because the function uses ON CONFLICT (build_id, org_id) DO UPDATE, can overwrite existing usage/billing records by reusing the same build_id for a target org. This enables cross-tenant tampering of billing build logs and financial-impact denial of service by inflating billable build time. Join the discussion | CVE Database V5 | 06/19/2026, 21:39:21 UTC Added: 06/19/2026, 22:11:33 UTC |
CVE-2026-56081: Weak Password Recovery Mechanism for Forgotten Password in Cap-go capgoCVE-2026-56081 0 Cap-go before 12.128.2 contains an authentication logic flaw that lets an attacker register and control an account bound to a victim's email address before that email is verified. By enabling two-factor authentication on the pre-registered account, the attacker gains control over the account claimed under the victim's identity, allowing them to read and modify its state and enforce organization-level policies, while the legitimate user is denied access to the account tied to their own email. Join the discussion | CVE Database V5 | 06/19/2026, 21:39:20 UTC Added: 06/19/2026, 22:11:33 UTC |
CVE-2026-56080: Improper Authentication in Cap-go capgoCVE-2026-56080 0 Capgo before 12.128.2 contains a flaw in the Enforce Password Policy feature: after a Super Admin enables the policy and successfully changes their password to a compliant one, the backend does not update the password-compliance state. As a result, the backend continues to treat the account as non-compliant and repeatedly forces password-reset prompts, permanently locking the Super Admin out of organization access (organization lockout / denial of service) despite valid authentication. Join the discussion | CVE Database V5 | 06/19/2026, 21:39:20 UTC Added: 06/19/2026, 22:11:33 UTC |
Showing 1 to 10 of 81138 results