●
The U.S. Department of Justice and the U.K.'s National Crime Agency and Crown Prosecutor signed a memorandum to cooperate on cases involving Southeast Asian scam operations.
52 threat-intel feeds. Filter by vendor, severity, exploitation status, region, sector, and a selectable timeframe. Hourly updates. Free, no login.
Look up APT groups, TTPs, and intel context in seconds.
ThreatFilter pulls fresh advisories hourly from 52 public sources (CISA KEV, NVD, vendor PSIRTs, regional CERTs, and independent security press). The freshness dot in the header shows how recently a source was fetched.
Vendor / severity / exploitation / sector tagging shown here is currently heuristic — it is derived in your browser by matching each item's title and summary against a 349-vendor alias catalog with word-boundary keyword rules. It is intentionally conservative (no loose substring hits) but it is not a substitute for the dedicated ML classifier; treat tags as a strong hint, and always open the source for ground truth.
Use the filter bar to narrow by vendor, severity, exploitation status, region, and sector. The Timeframe control (24h · 48h · 7d · 30d · 90d · All, default 7 days) sets how far back the feed reaches — picking a longer window fetches deeper history, not just the most recent items. Counts on each tile reflect the loaded window of items, not all-time.
Boolean search syntax
cisco vpn — both words must appear (implicit AND)cisco OR fortinet — either wordcisco AND vpn NOT ios — combine; NOT excludes"zero day" — exact phrase in quotes(rce OR "remote code") AND linux — parenthesised groupscve-2024 — plain words still substring-match for back-compatCase-insensitive. Operators are case-sensitive (must be uppercase).
The U.S. Department of Justice and the U.K.'s National Crime Agency and Crown Prosecutor signed a memorandum to cooperate on cases involving Southeast Asian scam operations.
A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served alter…
In its first annual assessment, published Friday, the City of London Police said victims reported losing £6.3 million ($8.5 million) to account hacks in the year ending March 31, up from £1.2 million …
Russia's data centers are concentrated in areas increasingly exposed to Ukrainian drone attacks. The Kremlin wants them to stiffen their physical defenses.
Tracked as CVE-2026-9586, the unauthenticated SQL injection flaw can be exploited remotely for arbitrary code execution. The post Sangoma Switchvox Vulnerabilities Exploited in the Wild appeared first…
A tidal wave of bug reports is overwhelming software vendors, exposing secure-by-design failures and creating disclosure bottlenecks.
In a joint advisory released Thursday, the G7 Cyber Security Working Group and the U.S. Cybersecurity and Infrastructure Security Agency, CISA, said organizations should begin moving to post-quantum c…
As X expands into payments, users are receiving password-reset emails they didn’t request. Here’s what may be happening and how to stay safe.
Dubbed PostGREShell, CVE-2026-6471 turns low-level replication access into code execution, permanent superuser privileges and a persistent database backdoor. The post 12-Year-Old PostgreSQL Vulnerabil…
OverviewA new Linux toolkit, identified by Rapid7 Labs, has been targeting organizations across South Korea’s automotive and media industries with minimal detection. The campaign made use of a HAProxy…
Catch promises the capabilities of a trusted executive assistant, with built-in controls governing what data and systems it can access. The post Catch Raises $5 Million for AI Executive Assistant With…
The flaws could allow attackers with administrative access to a virtual machine to execute code on the host system. The post VMware Workstation and Fusion Updates Patch Critical Vulnerability appeared…
Google’s Chrome 152 security update resolves 12 vulnerabilities, including a high-severity type confusion flaw in the V8 engine. The post Google Patches 6th Chrome Zero-Day of 2026 appeared first on S…
It’s a vulnerability that allows someone to recover the order of ballots cast, newly exploited with AI tools. Nearly four years since the original vulnerability was disclosed, I was still able to use …
We cannot forget that AI coding agents are not yet trustworthy: Researchers at a stealth startup in Israel scanned 6,214 live domains belonging to defense contractors, Fortune 500, and Big Tech compan…
Kaspersky GERT experts have discovered new backdoors used by the Toy Ghouls group. One version of the backdoor uses the HiveMQ MQTT broker as its command-and-control server; the other uses the Matrix-…
The deal highlights Nvidia’s push to champion increasingly popular open-source AI models. The post Nvidia Is Buying AI Platform Hugging Face for $13 Billion appeared first on SecurityWeek.
Researchers found that apps available on SuperBox devices could add your household connection to a residential proxy network.
Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 …
Plex is urging users to update their instances to the latest version following the release of an update that patches multiple security flaws. The fixes are available in Plex Media Server 1.43.3 and Pl…
Google on Thursday released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-85046 …
Fusion is a capability you mature into, not a team you hire. Here is the honest maturity path, the metrics that fund it, and the on-ramp that costs no headcount, startable this quarter.
OpenAI on Thursday officially unveiled GPT‑6 Astra, which it described as the "world's most intelligent and aligned model." The development comes days after the artificial intelligence (AI) company sa…
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à …
No items match. Try widening filters or clearing region.
Couldn't reach the feed
The advisory API didn't respond. It's usually a brief hiccup — give it a moment and try again.