Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:pypi/blackduck-c-cpp

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-76055 is a high-severity OS command injection vulnerability in Black Duck's blackduck-c-cpp package manager component prior to version 3.0.7. It allows an attacker who can create a file in the scanned build directory to execute arbitrary OS commands as the user running the scan. This occurs because filesystem paths are interpolated into shell command strings without proper quoting or escaping, enabling shell metacharacters to be interpreted. No control over the build command or tool configuration is needed for exploitation.

Join the discussion

CVE-2026-76054 is a vulnerability in Black Duck blackduck-c-cpp versions 1.0.17 through 3.0.6 that allows an actor with code execution capability within the scanned project's build to access the Black Duck API token. This occurs because the token, when supplied via the BLACKDUCK_API_TOKEN or BD_HUB_TOKEN environment variables, is exposed through the ambient process environment inherited by subprocesses during build capture and signature scanning. Upgrading to version 3.0.7 or later addresses the vulnerability, but prior token exposure requires token rotation.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Package: pkg:pypi/blackduck-c-cpp
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses