Skip to main content

High Severity Threats

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Severity: High

Filtered Threats

Click on any threat for detailed analysis and mitigation recommendations

Misuse and misconfiguration in Bluetooth communication in SwitchBot Door Lock Series allows an attacker to bypass the electronic lock and access controls via a manipulated communication protocol.

Join the discussion

Missing Authorization vulnerability in ThemeHunk Th Shop Mania th-shop-mania allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Th Shop Mania: from n/a through 1.9.1.

Join the discussion

Deserialization of Untrusted Data vulnerability in ExpressTech Quiz And Survey Master quiz-master-next allows Object Injection.This issue affects Quiz And Survey Master: from n/a through 11.2.7.

Join the discussion

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Delight Star Inc. WP Associate Post R2 wp-associate-post-r2 allows Reflected XSS.This issue affects WP Associate Post R2: from n/a through 5.0.1.

Join the discussion

Deserialization of Untrusted Data vulnerability in mklacroix Product Configurator for WooCommerce product-configurator-for-woocommerce allows Object Injection.This issue affects Product Configurator for WooCommerce: from n/a through 1.7.5.

Join the discussion

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Datasolution AcyMailing SMTP Newsletter acymailing allows Reflected XSS.This issue affects AcyMailing SMTP Newsletter: from n/a through 11.1.0.

Join the discussion

This report summarizes multiple cybersecurity incidents and emerging threats including AI-assisted bank breaches in South Korea, a poem-guided botnet called PoeLLM targeting AI and open-source services, a supply chain attack on the Tensorlake npm SDK, and the sentencing of the Empire Market co-founder. The PoeLLM malware uses a novel method of hiding its command-and-control server IP address encoded in a GitHub-hosted poem. The Tensorlake npm SDK was compromised to deliver a credential-stealing worm. Nvidia's DCGM Exporter had a high-severity denial-of-service vulnerability that has been patched. The South Korean bank breaches are under investigation with AI suspected to be involved. The Empire Market co-founder received a 40-year prison sentence for running a dark web marketplace. These events highlight evolving attack techniques and ongoing law enforcement actions.

Join the discussion

Hackers hijacked the .gh, .sl, and .as country-code top-level domains (ccTLDs), modifying authoritative DNS records and obtaining unauthorized HTTPS certificates for several Google domains and other organizations. Google blocked these unauthorized certificates in Chrome and worked with certificate authorities to revoke them. The incident highlights risks associated with third-party ccTLD management and certificate issuance. Google recommends domain owners monitor Certificate Transparency logs and implement restrictive CAA DNS records to prevent future unauthorized certificate issuance.

HighNews
Join the discussion

Beginning October 7, 2026, threat actors exploited two critical vulnerabilities in AhsayCBS backup utility (CVE-2026-105133 and CVE-2026-105134) to achieve unauthenticated remote code execution on exposed systems. The attackers chained these vulnerabilities together, first bypassing authentication and then executing code with SYSTEM privileges. Post-exploitation activities included deploying JSP webshells, installing XMRig cryptocurrency miners disguised as Microsoft Edge processes, and dropping an AI-assisted PowerShell script that monitors and terminates Task Manager to hide mining operations. The attackers established persistence through a fake Windows service named MicrosoftEdgeUpdateSvc and utilized a vulnerable WinRing0x64.sys kernel driver to enable kernel-level hardware access for optimized mining performance. All AhsayCBS versions through 10.3.4 are affected, with managed service providers being the primary targets.

Join the discussion

In Apache CXF, the Netty-based HTTP client transport (cxf-rt-transports-http-netty-client) did not verify that the hostname in the server’s TLS certificate matched the host being called. This applied over both HTTP/1.1 and HTTP/2, even when disableCNCheck was left at its default value of false. The certificate chain was validated against the configured trust store, but the endpoint’s identity was not. A network attacker able to intercept traffic could present any certificate trusted by the client, such as a publicly issued certificate for a domain they control, and impersonate the target service. They could then read or modify the exchanged messages, including credentials.  Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.

Join the discussion

Showing 1 to 10 of 53252 results

Filters:Severity: High
Page 1 of 5326
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses