Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:rpm/nvidia/geforce

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

LokiBot, an infostealer first advertised in May 2015, continues to operate after more than a decade with numerous variants. The malware targets credentials from over a hundred software products including browsers, cryptocurrency wallets, password managers, email and FTP clients. A recent campaign delivers LokiBot through malspam with JScript email attachments, executing a multi-stage infection chain involving PowerShell loaders and .NET injectors protected by ConfuserEx. The final payload uses process injection into aspnet_compiler.exe, employing API hashing techniques to evade detection. While LokiBot maintains extensive credential theft capabilities, recent samples exhibit broken persistence mechanisms due to patched decryption subroutines. The malware communicates with C2 servers to exfiltrate compressed stolen data and await further commands, demonstrating continued evolution despite reduced activity in recent years.

Join the discussion

NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel driver, where a user could cause an incorrect permission assignment for a critical resource. A successful exploit of this vulnerability might lead to data tampering and denial of service.

Join the discussion

CVE-2026-24191 is a high-severity vulnerability in the NVIDIA Display Driver for Windows affecting GeForce products prior to version 596.36. It is a time-of-check time-of-use (TOCTOU) race condition that could allow an attacker to cause denial of service, escalate privileges, disclose information, tamper with data, or execute code. The vulnerability requires local access with low privileges and high attack complexity. No official patch or remediation guidance has been provided yet by NVIDIA. There are no known exploits in the wild at this time.

Join the discussion

CVE-2026-24193 is a high-severity vulnerability in NVIDIA GeForce display drivers for Windows and Linux that allows an out-of-bounds write. Exploitation could lead to denial of service, privilege escalation, information disclosure, data tampering, or code execution. The issue affects all driver versions prior to 580.159.03. No official patch or remediation guidance is currently confirmed from the vendor. The vulnerability requires local access with low privileges and no user interaction is needed for exploitation.

Join the discussion

CVE-2026-24196 is an out-of-bounds read vulnerability in the NVIDIA Display Driver for Linux affecting GeForce products. Exploitation could lead to denial of service and information disclosure. The vulnerability affects all driver versions prior to 595.71.05. The CVSS score is 7.1, indicating high severity. No official patch or remediation level has been confirmed yet. There are no known exploits in the wild at this time.

Join the discussion

CVE-2026-24197 is a medium severity vulnerability in the NVIDIA GeForce Display Driver for Linux affecting Multi-Instance GPU (MIG) partition management. The issue arises from insecure default initialization of memory subsystem routing resources, which can cause data corruption or system hangs during partition reconfiguration. Exploitation could result in denial of service but does not impact confidentiality or integrity. The vulnerability affects all driver versions prior to 595.71.05. No official patch or remediation guidance is currently available from the vendor. There are no known exploits in the wild at this time.

Join the discussion

A race condition vulnerability (CWE-362) exists in the NVIDIA Display Driver for Linux kernel module affecting GeForce drivers prior to version 595.71.05. This flaw arises from improper synchronization when reordering compiler or processor memory instructions. Exploitation could result in a denial of service condition. The vulnerability has a medium severity with a CVSS score of 4.7. No known exploits are reported in the wild. Patch status is not confirmed as no official fix or vendor advisory is provided.

Join the discussion

A vulnerability in the NVIDIA GeForce GPU Display Driver for Linux allows an advanced attacker with high privileges to exploit a race condition that could leak sensitive memory. This exposure might lead to limited unauthorized disclosure of information, denial of service, and data tampering. The issue affects all driver versions prior to 595.71.05. No official patch or remediation guidance is currently confirmed from the vendor. The vulnerability has a medium severity rating with a CVSS score of 5.6.

Join the discussion

CVE-2026-24182 is a medium severity vulnerability in NVIDIA GeForce display drivers for Windows and Linux. It involves improper locking that could allow an attacker to leak held driver locks. Exploitation of this flaw may result in a denial of service condition. The issue affects all driver versions prior to 595.71.05. No official patch or remediation guidance has been confirmed yet. There are no known exploits in the wild at this time.

Join the discussion

CVE-2026-24187 is a use-after-free vulnerability in the NVIDIA Display Driver for Linux affecting GeForce products. Exploitation could allow an attacker with local access to cause denial of service, escalate privileges, disclose information, tamper with data, or execute arbitrary code. The vulnerability affects all driver versions prior to 595.71.05. There is no official patch or remediation level confirmed at this time. The vulnerability has a high severity score of 8.8 and no known exploits in the wild have been reported.

Join the discussion

Showing 1 to 10 of 17 results

Filters:Package: pkg:rpm/nvidia/geforce
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses