Threats Tagged 'osint:certainty="50"'
View all threats tagged with 'osint:certainty="50"'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'osint:certainty="50"'
Click on any threat for detailed analysis and mitigation recommendations
KadNap botnet IOC (mainly Asus router) Join the discussion | CIRCL OSINT Feed | 03/13/2026, 00:00:00 UTC Added: 03/13/2026, 16:58:53 UTC |
PFCloud · Bulletproof Hosting · Datacarry Ransomware MediumMalware Join the discussion | CIRCL OSINT Feed | 02/18/2026, 00:00:00 UTC Added: 06/30/2026, 06:09:09 UTC |
Fake 7-Zip downloads are turning home PCs into proxy nodes MediumUnknown#misp-galaxy:mitre-attack-pattern="domain generation algorithms - t1568.002"#misp-galaxy:mitre-attack-pattern="match legitimate name or location - t1036.005"#misp-galaxy:mitre-attack-pattern="windows service - t1543.003" Join the discussion | CIRCL OSINT Feed | 02/12/2026, 00:00:00 UTC Added: 05/10/2026, 02:19:32 UTC |
0 A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints. Join the discussion | CVE Database V5 | 01/29/2026, 00:00:00 UTC Added: 12/03/2025, 15:54:37 UTC |
OSINT - ResidentBat: A new spyware family used by Belarusian KGB MediumUnknown Join the discussion | CIRCL OSINT Feed | 12/17/2025, 00:00:00 UTC Added: 12/17/2025, 21:51:55 UTC |
Kunai Analysis Report - Malware Sample Abusing Open Recursive DNS for Exfiltration Join the discussion | CIRCL OSINT Feed | 12/15/2025, 00:00:00 UTC Added: 12/15/2025, 19:00:07 UTC |
BRICKSTORM Backdoor - MAR-251165.c1.v1 MediumUnknown Join the discussion | CIRCL OSINT Feed | 12/13/2025, 00:00:00 UTC Added: 12/13/2025, 16:06:36 UTC |
Sha1-Hulud is a newly identified cyber threat involving supply chain compromise and covert command and control (C2) communications using application layer protocols. Attackers exploit link-local IP addresses such as 169.254.169.254 and 169.254.170.2, commonly associated with cloud metadata services, to bypass perimeter defenses and blend malicious traffic with legitimate communications. A JavaScript component named bun_environment.js has been identified as part of the attack chain. MediumUnknown Join the discussion | CIRCL OSINT Feed | 11/26/2025, 00:00:00 UTC Added: 11/29/2025, 08:19:38 UTC |
Salesforce Gainsight Security Advisory - Nov 2025 MediumMalware Join the discussion | CIRCL OSINT Feed | 11/26/2025, 00:00:00 UTC Added: 11/29/2025, 08:19:38 UTC |
XCTDH Crypto Heist Part 3 - Yashraj Solanki Join the discussion | CIRCL OSINT Feed | 11/18/2025, 00:00:00 UTC Added: 11/18/2025, 14:39:37 UTC |
Showing 1 to 10 of 39 results