Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Search Results: "medium.com"
Click on any threat for detailed analysis and mitigation recommendations
Strategies for Analyzing Native Code in Android Applications: Combining Ghidra and Symbolic… Source: https://revflash.medium.com/strategies-for-analyzing-native-code-in-android-applications-combining-ghidra-and-symbolic-aaef4c9555df Join the discussion | Reddit NetSec | 09/15/2025, 00:48:25 UTC Added: 09/15/2025, 01:02:15 UTC |
Manipulating India’s Stock Market: The GST Portal Data Leak Source: https://aseem-shrey.medium.com/manipulating-indias-stock-market-the-gst-portal-data-leak-b5437c817071 Join the discussion | Reddit NetSec | 09/04/2025, 22:45:39 UTC Added: 09/04/2025, 22:54:03 UTC |
How Exposed TeslaMate Instances Leak Sensitive Tesla Data Source: https://s3yfullah.medium.com/how-exposed-teslamate-instances-leak-sensitive-tesla-data-80bedd123166 Join the discussion | Reddit NetSec | 08/17/2025, 13:24:45 UTC Added: 08/17/2025, 13:32:42 UTC |
Just published a new write-up where I walk through how a small HTTP method misconfiguration led to admin credentials being exposed. It's a simple but impactful example of why misconfigurations matter. 📖 Read it here: [https://is4curity.medium.com/admin-emails-passwords-exposed-via-http-method-change-da23186f37d3](https://is4curity.medium.com/admin-emails-passwords-exposed-via-http-method-change-da23186f37d3) Let me know what you think — and feel free to share similar cases! \#bugbounty #infosec #pentest #writeup #websecurity Join the discussion | Reddit NetSec | 07/26/2025, 01:32:30 UTC Added: 07/26/2025, 01:32:48 UTC |
Hey folks, Just published a write-up where I turned a blind XSS into Remote Code Execution , and the final step? Injecting commands via Accept-Language header, parsed by a vulnerable PHP script. No logs. No alert. Just clean shell access. Would love to hear your thoughts or similar techniques you've seen! 🧠🛡️ [https://is4curity.medium.com/from-blind-xss-to-rce-when-headers-became-my-terminal-d137d2c808a3](https://is4curity.medium.com/from-blind-xss-to-rce-when-headers-became-my-terminal-d137d2c808a3) Join the discussion | Reddit NetSec | 07/13/2025, 00:35:21 UTC Added: 07/13/2025, 00:46:07 UTC |
I recently tested a language-learning site that used live frontend filtering to block HTML input (e.g., <img> <svg> tags were removed as you typed). But by injecting the payload directly via browser console (without typing it), the input was submitted and stored. Surprisingly, the XSS executed later on my own profile page — indicating stored execution from a DOM-based bypass. I wrote a short write-up here: [https://is4curity.medium.com/xss-before-submit-a-dom-based-execution-flaw-hidden-in-plain-sight-5633bdd686c9](https://is4curity.medium.com/xss-before-submit-a-dom-based-execution-flaw-hidden-in-plain-sight-5633bdd686c9) enjoy Join the discussion | Reddit NetSec | 07/09/2025, 03:16:41 UTC Added: 07/09/2025, 03:24:39 UTC |
GIMP Heap Overflow Re-Discovery and Exploitation (CVE-2025–6035) Source: https://medium.com/@cy1337/malloc-overflow-deep-dive-9357eeef416b Join the discussion | Reddit NetSec | 06/14/2025, 16:09:52 UTC Added: 06/14/2025, 17:19:31 UTC |
While experimenting with the idea of converting a normal USB (e.g., SanDisk) into a BadUSB or Rubber Ducky device, I explored its technical limitations and potential uses for cybersecurity learning. This write-up documents what worked, what didn’t, and why reprogrammable microcontrollers (like those in Digispark or Rubber Ducky) are essential for true HID emulation. I also shared a hands-on PowerShell experiment for extracting Wi-Fi credentials as a basic USB-based manual attack vector. Join the discussion | Reddit NetSec | 05/31/2025, 17:20:38 UTC Added: 05/31/2025, 17:28:32 UTC |
While preparing for CEH and doing passive analysis of a live WordPress-based site, I came across a full vulnerability chain — including user enumeration, exposed backup files, SQLi, and insecure headers. I documented the process, wrote a responsible disclosure report, and summarized the technical lessons in this article. Feedback from professionals here would be highly appreciated. Link above ⬆️ Join the discussion | Reddit NetSec | 05/31/2025, 16:31:02 UTC Added: 05/31/2025, 16:43:14 UTC |
Reddit NetSec | 05/28/2025, 17:52:56 UTC Added: 05/28/2025, 17:58:50 UTC |
Showing 1 to 10 of 12 results