Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:pypi/torch-musa

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

The torch-musa package on PyPI contains malicious code that exfiltrates basic host information such as IP address and username during installation or import. The package overrides the install command in setup.py to execute this malicious behavior. It serves no legitimate purpose beyond this data exfiltration.

Join the discussion
CVE-2025-65213: n/aCVE-2025-65213
0

CVE-2025-65213 is a critical unsafe deserialization vulnerability in MooreThreads torch_musa library affecting all versions. The vulnerability arises from the use of Python's pickle.load() on user-controlled file paths in the compare_for_single_op() and nan_inf_track_for_single_op() functions without proper validation. This allows attackers to craft malicious pickle files that execute arbitrary Python code upon deserialization, leading to remote code execution with the privileges of the victim process. The vulnerability has a CVSS score of 9.8, indicating a critical severity with network attack vector, no required privileges or user interaction, and full impact on confidentiality, integrity, and availability. No known exploits are currently reported in the wild. European organizations using torch_musa in AI or data processing workflows are at significant risk, especially those in countries with strong AI development sectors. Immediate mitigation involves restricting or validating input sources for pickle files, employing safer serialization methods, and isolating processes handling untrusted data. Given the critical nature and ease of exploitation, this vulnerability demands urgent attention to prevent potential widespread compromise.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Package: pkg:pypi/torch-musa
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses