Threats Tagged 'vulnerability'
View all threats tagged with 'vulnerability'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'vulnerability'
Click on any threat for detailed analysis and mitigation recommendations
CISA will discontinue its Weekly Vulnerability Bulletin at the end of fiscal year 2026 (September 28, 2026) to shift from severity-based vulnerability management to risk-based vulnerability prioritization. Vulnerability information will continue to be available on CVE.org, and users are encouraged to rely on the Known Exploited Vulnerability (KEV) Catalog, CISA Cybersecurity Alerts and Advisories, and vendor security alerts for actionable updates. This change reflects evolving approaches to vulnerability management amid increasing CVE volume driven by AI-assisted research. Join the discussion | Reddit Cybersecurity | 09/16/2026, 17:27:15 UTC Added: 09/16/2026, 17:31:30 UTC |
A critical privilege-escalation vulnerability in LiteSpeed Web Server Enterprise versions before 6.3.7 allows a low-privilege shared-hosting user to potentially gain root access by bypassing isolation controls like CloudLinux CageFS. The advisory urges administrators to upgrade to version 6.3.7 or later to mitigate this risk. No CVE or public exploit details are currently available, but the issue is considered critical by cPanel. Join the discussion | Community Curated | 09/15/2026, 14:35:34 UTC Added: 09/15/2026, 14:35:34 UTC |
A local privilege escalation vulnerability in the Steam Client Service on Windows 10 and 11 allows any standard user to silently escalate privileges to SYSTEM without requiring admin rights, UAC prompts, or launching a game. The issue stems from a signature verification gap in Steam's installation process, enabling execution of code as SYSTEM without signature forgery. This was tested on Steam version 10.96.30.42. Valve was notified months prior to public disclosure. Join the discussion | Reddit Cybersecurity | 09/15/2026, 00:42:18 UTC Added: 09/15/2026, 00:46:27 UTC |
atomicvulns is an open-source educational project providing a collection of small, intentionally vulnerable web applications, each demonstrating a single OWASP Top 10 2021 vulnerability. It includes 38 isolated apps ('atoms'), each with a vulnerable and fixed version, plus walkthroughs for exploitation and remediation. The project is designed for pentest and AppSec learners to study and practice exploiting and fixing common web vulnerabilities in a focused, hands-on manner. It is not a vulnerability or exploit itself but a learning tool. Join the discussion | Reddit ExploitDev | 09/11/2026, 20:12:37 UTC Added: 09/12/2026, 08:17:03 UTC |
0 This content discusses the evolving threat landscape shaped by artificial intelligence accelerating vulnerability discovery and exploit development. AI has drastically shortened the window between vulnerability disclosure and exploitation, often enabling attackers to weaponize flaws before patches are available. Traditional vulnerability management programs, which rely on slower patch cycles, are increasingly ineffective. The attack surface is also expanding with AI components introducing new classes of vulnerabilities not covered by conventional scanning tools. The briefing cited recommends rapid, risk-driven patching, improved dependency management, and leveraging AI for proactive defense. It emphasizes that AI-accelerated attacks represent a lasting shift requiring security programs to adapt for speed and prioritization. Join the discussion | Reddit Cybersecurity | 08/23/2026, 18:44:16 UTC Added: 08/23/2026, 18:52:03 UTC |
This article provides a detailed technical breakdown of the active exploitation of the critical VMware vCenter vulnerability CVE-2026-59310 by a suspected APT group. It covers the attack chain, including the use of a directory traversal flaw to deploy persistent reverse SSH tools and web shells, and offers specific indicators of compromise and mitigation guidance. Join the discussion | Community Curated | 08/17/2026, 10:34:12 UTC Added: 08/17/2026, 10:34:12 UTC |
This article provides a detailed technical analysis of the critical macOS Screen Sharing vulnerability CVE-2026-65400, which allows unauthenticated remote root access via a logic flaw in the screensharingd daemon. It explains active exploitation by threat actors deploying Monero miners, the mechanics of the authentication bypass, and urgent mitigation steps including patching and network hardening. Join the discussion | Community Curated | 08/17/2026, 06:02:59 UTC Added: 08/17/2026, 06:02:59 UTC |
How We Hacked Thousands of Data Centers in Minutes Using a 20-Year-Old Vulnerability Source: https://lavahq.io/bmcradar Join the discussion | Reddit NetSec | 07/28/2026, 13:31:09 UTC Added: 07/28/2026, 13:36:56 UTC |
This report references multiple SharePoint vulnerabilities identified by CVE-2026-58644, CVE-2026-45659, and CVE-2026-50522. A proof-of-concept (PoC) exploit script is publicly available, demonstrating a potential security issue involving SharePoint's security token handling. The details suggest a security context token manipulation leading to remote code execution attempts. No patch or official remediation information is provided in the source data. Join the discussion | Reddit ThreatIntel | 07/27/2026, 11:46:44 UTC Added: 07/27/2026, 11:52:03 UTC |
CISA has issued an emergency directive to patch a critical remote code execution vulnerability (CVE-2026-0770) in the widely used Langflow AI framework, which is actively exploited in the wild. The flaw allows unauthenticated attackers to execute code as root, posing significant risk to exposed deployments. The advisory includes detailed mitigation steps such as restricting internet exposure and auditing logs for exploitation attempts. Join the discussion | Community Curated | 07/23/2026, 08:56:23 UTC Added: 07/23/2026, 08:56:23 UTC |
Showing 1 to 10 of 123 results