Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
The torch-musa package on PyPI contains malicious code that exfiltrates basic host information such as IP address and username during installation or import. The package overrides the install command in setup.py to execute this malicious behavior. It serves no legitimate purpose beyond this data exfiltration. Join the discussion | GCVE Database | 07/22/2026, 18:09:16 UTC Added: 07/22/2026, 23:24:28 UTC |
0 CVE-2025-65213 is a critical unsafe deserialization vulnerability in MooreThreads torch_musa library affecting all versions. The vulnerability arises from the use of Python's pickle.load() on user-controlled file paths in the compare_for_single_op() and nan_inf_track_for_single_op() functions without proper validation. This allows attackers to craft malicious pickle files that execute arbitrary Python code upon deserialization, leading to remote code execution with the privileges of the victim process. The vulnerability has a CVSS score of 9.8, indicating a critical severity with network attack vector, no required privileges or user interaction, and full impact on confidentiality, integrity, and availability. No known exploits are currently reported in the wild. European organizations using torch_musa in AI or data processing workflows are at significant risk, especially those in countries with strong AI development sectors. Immediate mitigation involves restricting or validating input sources for pickle files, employing safer serialization methods, and isolating processes handling untrusted data. Given the critical nature and ease of exploitation, this vulnerability demands urgent attention to prevent potential widespread compromise. Join the discussion | CVE Database V5 | 12/15/2025, 00:00:00 UTC Added: 12/15/2025, 19:00:20 UTC |
Showing 1 to 2 of 2 results