Skip to main content

Threats Tagged 'threat-intelligence'

View all threats tagged with 'threat-intelligence'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: threat-intelligence

Threats Tagged 'threat-intelligence'

Click on any threat for detailed analysis and mitigation recommendations

ServiceRadar (OSS) is an open-source distributed network monitoring system designed for infrastructure and services in constrained environments. It integrates threat intelligence feeds such as CISA-KEV and NVD2 via VulnCheck community feeds and collects software inventory from endpoints using an agent. The platform features a modern WebAssembly-based plugin system for secure extensibility, real-time monitoring, and cloud-based alerting. There is no indication of a security vulnerability or exploit associated with this software in the provided information.

Join the discussion

This is a free mobile application called VulniPulse that provides alerts for CVEs and end-of-life information across 30+ vendors and 160+ platforms. It offers phone and email notifications for tracked vulnerabilities and includes features such as filtering by severity and vendor, as well as lifecycle product checks. The app aggregates official vendor security advisories and lifecycle data to help IT and security professionals monitor vulnerabilities. There is no indication that the app itself introduces a security vulnerability or threat.

Join the discussion

This entry describes a promotional post for a project called Threat Hub, which is a tailored threat intelligence hub offering customized threats and alerts. The content is a link post on Reddit with minimal discussion and no technical vulnerability or exploit details provided.

Join the discussion

This entry is a discussion post on Reddit about the current state of threat intelligence tooling. The author shares their experience developing a threat intelligence investigation platform that aims to streamline workflows and leverage AI to accelerate development, but not to automate analysis. The post invites feedback and testing of the tool hosted on huntingbadguys.online. There is no indication of a security vulnerability or active threat in the content.

Join the discussion

Amazon Threat Intelligence has reported that Russian GRU-affiliated hackers are shifting their tactics from exploiting software vulnerabilities to targeting misconfigured devices. This change indicates a preference for leveraging security weaknesses caused by improper configurations rather than relying on zero-day or known software flaws. Such misconfigurations can include exposed management interfaces, default credentials, or improperly secured network services. The threat is assessed as medium severity due to the moderate impact and the relative ease of exploitation without requiring sophisticated zero-day vulnerabilities. European organizations, especially those with extensive networked infrastructure and IoT deployments, may be at increased risk if devices are not properly secured. Countries with significant critical infrastructure and technology sectors, such as Germany, France, and the UK, could be primary targets. Mitigation requires focused efforts on device configuration management, continuous monitoring, and strict access controls rather than solely patch management. This shift in attacker behavior underscores the importance of comprehensive security hygiene beyond patching software vulnerabilities. Defenders should prioritize auditing device configurations, enforcing strong authentication, and segmenting networks to reduce exposure.

Join the discussion

RedTail cryptominer malware has been observed targeting exposed Docker APIs on port 2375/tcp, marking a new evolution in its attack surface. Previously known for exploiting PHP vulnerabilities, PAN-OS, and Ivanti products, this is the first public evidence of RedTail leveraging unsecured Docker endpoints. The malware communicates with a command and control server at IP 178.16.55.224 using a distinctive User-Agent string "libredtail-http. " There is no prior public documentation of RedTail targeting Docker, suggesting either a blind spot in threat intelligence or a recent tactical shift as of November 2025. Exploiting exposed Docker APIs allows attackers to deploy cryptominers directly on container hosts, potentially leading to resource exhaustion and operational disruption. European organizations using Docker with unsecured APIs are at risk, especially those in sectors with high container adoption. Mitigation requires immediate restriction of Docker API exposure, network segmentation, and enhanced monitoring for unusual Docker activity.

Join the discussion

There is a critical surge in AI-powered phishing campaigns, with a 300% year-over-year increase and a significant rise in attack sophistication. These campaigns leverage machine learning to analyze organizational communication patterns and employee behavior, generating highly personalized and contextually relevant phishing emails in real time. Traditional signature-based detection methods are largely ineffective against these dynamic, unique attack vectors. The FBI reports over 200 US organizations compromised within 30 days, and NIST predicts that by 2025, 90% of successful breaches will stem from AI-driven phishing. Although primarily targeting US infrastructure, European organizations are at risk due to the global nature of phishing and interconnected business relationships. Defenders must adopt advanced behavioral analytics, AI-driven detection, and comprehensive employee training to mitigate these threats effectively. Countries with significant digital infrastructure and high adoption of targeted sectors are most vulnerable. This threat is critical due to its high impact on confidentiality, integrity, and availability, ease of exploitation without user authentication, and broad attack surface.

Join the discussion

Batteries included collaborative knowledge management solution for threat intelligence researchers Source: https://cradle.sh/

Join the discussion

Showing 1 to 8 of 8 results

Filters:Tag: threat-intelligence
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses