Threat Intelligence Overview
Aggregated from Reddit, HackerNews, GitHub Advisories, NVD, and 12 RSS feeds
Total Articles
1,599
All sources
Zero-Days
213
Critical severity
AI / Agentic
179
LLM & agent threats
Active Sources
20
Scraped sources
By Category
Top Sources
Recent Scrape Jobs
ALL
+0 added · 3/7/2026
ALL
+0 added · 3/7/2026
ALL
+0 added · 3/6/2026
ALL
+0 added · 3/6/2026
ALL
+0 added · 3/5/2026
Latest Articles
View all →CVE-2026-22052: ONTAP versions 9.12.1 and higher with S3 NAS buckets are susceptible to an information disclosure vulnerability. Successful exploit could allow an authenticated attacker to view a listing of the conte
CVE-2026-2297: The import hook in CPython that handles legacy *.pyc files (SourcelessFileLoader) is incorrectly handled in FileLoader (a base class) and so does not use io.open_code() to read the .pyc files. sys.aud
CVE-2026-29086: Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, the setCookie() utility did not validate semicolons (;), carriage returns (\r), or newlin
CVE-2026-29085: Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when using streamSSE() in Streaming Helper, the event, id, and retry fields were not vali
CVE-2026-29045: Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when using serveStatic together with route-based middleware protections (e.g. app.use('/a
CVE-2026-26002: Open OnDemand is an open-source high-performance computing portal. The Files application in OnDemand versions prior to 4.0.9 and 4.1.3 is susceptible to malicious input when navigating to a directory.
CVE-2025-41257: Suprema’s BioStar 2 in version 2.9.11.6 allows users to set new password without providing the current one. Exploiting this flaw combined with other vulnerabilities can lead to unauthorized account ac
CVE-2026-29000: pac4j-jwt versions prior to 4.5.9, 5.7.9, and 6.3.3 contain an authentication bypass vulnerability in JwtAuthenticator when processing encrypted JWTs that allows remote attackers to forge authenticati