Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Search: medium.com

Search Results: "medium.com"

Click on any threat for detailed analysis and mitigation recommendations

Strategies for Analyzing Native Code in Android Applications: Combining Ghidra and Symbolic… Source: https://revflash.medium.com/strategies-for-analyzing-native-code-in-android-applications-combining-ghidra-and-symbolic-aaef4c9555df

Join the discussion

Manipulating India’s Stock Market: The GST Portal Data Leak Source: https://aseem-shrey.medium.com/manipulating-indias-stock-market-the-gst-portal-data-leak-b5437c817071

Join the discussion

How Exposed TeslaMate Instances Leak Sensitive Tesla Data Source: https://s3yfullah.medium.com/how-exposed-teslamate-instances-leak-sensitive-tesla-data-80bedd123166

Join the discussion

Just published a new write-up where I walk through how a small HTTP method misconfiguration led to admin credentials being exposed. It's a simple but impactful example of why misconfigurations matter. 📖 Read it here: [https://is4curity.medium.com/admin-emails-passwords-exposed-via-http-method-change-da23186f37d3](https://is4curity.medium.com/admin-emails-passwords-exposed-via-http-method-change-da23186f37d3) Let me know what you think — and feel free to share similar cases! \#bugbounty #infosec #pentest #writeup #websecurity

Join the discussion

Hey folks, Just published a write-up where I turned a blind XSS into Remote Code Execution , and the final step? Injecting commands via Accept-Language header, parsed by a vulnerable PHP script. No logs. No alert. Just clean shell access. Would love to hear your thoughts or similar techniques you've seen! 🧠🛡️ [https://is4curity.medium.com/from-blind-xss-to-rce-when-headers-became-my-terminal-d137d2c808a3](https://is4curity.medium.com/from-blind-xss-to-rce-when-headers-became-my-terminal-d137d2c808a3)

Join the discussion

I recently tested a language-learning site that used live frontend filtering to block HTML input (e.g., <img> <svg> tags were removed as you typed). But by injecting the payload directly via browser console (without typing it), the input was submitted and stored. Surprisingly, the XSS executed later on my own profile page — indicating stored execution from a DOM-based bypass. I wrote a short write-up here: [https://is4curity.medium.com/xss-before-submit-a-dom-based-execution-flaw-hidden-in-plain-sight-5633bdd686c9](https://is4curity.medium.com/xss-before-submit-a-dom-based-execution-flaw-hidden-in-plain-sight-5633bdd686c9) enjoy

Join the discussion

GIMP Heap Overflow Re-Discovery and Exploitation (CVE-2025–6035) Source: https://medium.com/@cy1337/malloc-overflow-deep-dive-9357eeef416b

Join the discussion

While experimenting with the idea of converting a normal USB (e.g., SanDisk) into a BadUSB or Rubber Ducky device, I explored its technical limitations and potential uses for cybersecurity learning. This write-up documents what worked, what didn’t, and why reprogrammable microcontrollers (like those in Digispark or Rubber Ducky) are essential for true HID emulation. I also shared a hands-on PowerShell experiment for extracting Wi-Fi credentials as a basic USB-based manual attack vector.

Join the discussion

While preparing for CEH and doing passive analysis of a live WordPress-based site, I came across a full vulnerability chain — including user enumeration, exposed backup files, SQLi, and insecure headers. I documented the process, wrote a responsible disclosure report, and summarized the technical lessons in this article. Feedback from professionals here would be highly appreciated. Link above ⬆️

Join the discussion

Showing 1 to 10 of 12 results

Filters:medium.com
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses