Skip to content
Product
Use it
Threat intelligence API
Free key, 70+ endpoints, OpenAPI. The product.
Get started
Pick your stack, make your first call.
Live feed
The console: incidents, filters, entities, search.
Recipes
Runnable examples for the free key.
Free feeds
RSS, ransomware feed, IOC blocklist, MISP — no key.
CLI & agents
tc from a terminal; agent keys with scoped budgets.
The data
Incident records
900 articles a day become ~70 scored incidents.
Dark web
First-party leak-site collection: victims, groups, markets.
Validated IOCs
Indicators with a false-positive gate; STIX, MISP, CSV.
Vulnerabilities
CVEs with EPSS, KEV and exploit status.
Entity graph
Actors, malware, CVEs, companies — pivotable.
For teams
For service providers
Per-client feeds, alerts and branded digests.
Use cases
How teams and builders use the corpus.
About ThreatCluster
What it is and how it is built.
Pricing
Docs
Reference
OpenAPI (Swagger)
Every endpoint, parameter and response model.
ReDoc
The same reference, long-form.
Examples on GitHub
curl, Python and Node quickstarts; daily spec snapshot.
Guides
Quickstart & plans
Key, scopes, budgets, tiers.
Integrations
Splunk, Sentinel, Elastic, agents and terminals, step by step
Export formats
STIX 2.1, MISP, CSV, text.
CLI setup
Install, log in, wire an agent.
No results found
Sign in
Get a free key
No results found
Product
Threat intelligence API
Get started
Live feed
Recipes
Free feeds
CLI & agents
The data
Incident records
Dark web
Validated IOCs
Vulnerabilities
Entity graph
For teams
For service providers
Use cases
About ThreatCluster
Docs
OpenAPI (Swagger)
ReDoc
Examples on GitHub
Quickstart & plans
Integrations
Export formats
CLI setup
Pricing
Contact
Get a free key
Sign in
Back
CWE-200 - Exposure of Sensitive Information
CWE Weakness
Threat entity extracted from intelligence sources
Sep 8: 0 mentions
Sep 9: 0 mentions
Sep 10: 0 mentions
Sep 11: 3 mentions
Sep 12: 33 mentions
Sep 13: 14 mentions
Sep 14: 0 mentions
Sep 8
Sep 11
Sep 14
Entities
›
cwe
›
CWE-200 - Exposure of Sensitive Information
Frequency
2564
occurrences
First Seen
April 14, 2026
Last Seen
September 13, 2026
API
Overview
Recent Events
Profile
Profile
MITRE ATT&CK
1 / 2
Threat Actors
ShinyHunters
World Leaks
Lockbit
Malware
Vidar
Shai-hulud
Pegasus
StealC
LummaC2
RedLine
Acreed
Tools
Npm
Hugging Face
GitHub Actions
Docker
Node.js
Python
Curl
Claude Code
CVEs
CVE-2026-5222
CVE-2025-54505
CVE-2026-85880
CVE-2026-81963
CVE-2026-4786
CVE-2026-1502
CVE-2026-6100
Campaigns
FortiBleed
Regions
United States
China
India
Russia
France
Sectors
Government
Healthcare
Financial
Energy
Technology
Retail
-
REC
Recon
No techniques detected
-
RD
Resource Dev
No techniques detected
3
IA
Initial Access
T1566 - Phishing
T1078 - Valid Accounts
T1190 - Exploit Public-Facing Application
3
EX
Execution
T1059 - Command and Scripting Interpreter
T1203 - Exploitation for Client Execution
T1053 - Scheduled Task/Job
2
PE
Persistence
T1505.003 - Web Shell
T1547 - Boot Or Logon Autostart Execution
2
PE
Priv Esc
T1068 - Exploitation for Privilege Escalation
T1055 - Process Injection
1
DE
Defense Evasion
T1036 - Masquerading
4
CA
Cred Access
T1003 - OS Credential Dumping
T1110 - Brute Force
T1552.001 - Credentials In Files
T1555.003 - Credentials From Web Browsers
-
DI
Discovery
No techniques detected
1
LM
Lateral Mov
T1021 - Remote Services
-
CO
Collection
No techniques detected
2
C2
C2
T1071 - Application Layer Protocol
T1105 - Ingress Tool Transfer
2
EX
Exfil
T1041 - Exfiltration Over C2 Channel
T1567 - Exfiltration Over Web Service
1
IM
Impact
T1486 - Data Encrypted for Impact
23
techniques detected across
10
tactics
Related Clusters (50)
Critical Cisco FMC Vulnerabilities Under Active Exploitation
4d ago
·
32 sources
88
Critical Zero-Day Vulnerability CVE-2026-20182 Exploited in Cisco SD-WAN Systems
May 14
·
131 sources
87
Critical Unauthenticated RCE Vulnerability in LiteLLM Exploited in the Wild
Jun 9
·
17 sources
86
Critical Command Injection Vulnerability in Arista VeloCloud Orchestrator Under Active Exploitation
Jul 28
·
23 sources
84
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches
17h ago
·
2 sources
81
Lazarus Group Exploits Windows Zero-Day to Target Defense Sector
Aug 12
·
33 sources
81
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure
2d ago
·
34 sources
81
Russian Hackers Exploit Zimbra Zero-Day for Espionage Campaign
Jul 23
·
82 sources
81
GRU Compromises Home Routers in 23 States to Steal Outlook Credentials
May 22
·
6 sources
81
Critical Chrome Zero-Day CVE-2026-85046 Exploited in the Wild
Sep 4
·
60 sources
81
SonicWall SMA1000 Faces Critical Zero-Day Exploitation
Sep 2
·
45 sources
81
Critical RCE Vulnerability in IBM Langflow Under Active Exploitation
Aug 5
·
14 sources
80
F5 Issues Critical Patches for NGINX Vulnerabilities Allowing Remote Code Execution
Jun 18
·
24 sources
80
Critical RCE Vulnerability in Rails Active Storage Disclosed
Jul 30
·
16 sources
80
Critical Buffer Overflow Vulnerability in Silex Devices (CVE-2026-32956)
Apr 20
·
2 sources
80
Critical CVE-2026-48611 Vulnerability Allows OAuth Account Hijacking
Jun 12
·
2 sources
79
Critical Oracle WebLogic Flaw Under Active Exploitation
Aug 25
·
17 sources
79
Critical Exploitation of Sangoma Switchvox Vulnerabilities Underway
Sep 2
·
12 sources
79
Cl0p Ransomware Group Claims Data Theft from Nearly 50 Companies
Aug 14
·
30 sources
79
Head Mare Hackers Exploit TrueConf Vulnerabilities to Deploy Backdoors
Aug 8
·
23 sources
79
Operation Escaneo Targets Latin American Critical Infrastructure
Jun 18
·
4 sources
79
Widespread DNS Poisoning Campaign Targets Hotel Wi-Fi to Steal Credentials
Jul 24
·
73 sources
79
Apple Alerts Users of Targeted Mercenary Spyware Attacks in 110 Countries
Aug 13
·
102 sources
79
Massive Data Breach at Change Healthcare Affects 190 Million Americans
Jun 18
·
3 sources
78
Critical Authentication Bypass Vulnerability in Gorse Exposed
Jun 30
·
2 sources
78
Russian FSB Exploits Vulnerable Routers to Target Critical Infrastructure
Jul 13
·
76 sources
78
Armored Likho APT Targets Power Grids with BusySnake Stealer Malware
Jul 4
·
7 sources
78
Ubiquiti Patches Critical Vulnerabilities in UniFi OS Exposing Remote Attacks
May 22
·
51 sources
78
Critical RCE Vulnerabilities Under Active Exploitation
Sep 6
·
3 sources
78
AI Cyberattacks Targeting Critical Infrastructure Escalate
Sep 2
·
4 sources
78
Critical cPanel Vulnerability Exploited in Southeast Asia Cyber Attacks
May 4
·
3 sources
78
Ghost CMS SQL Injection Exploits 700+ Sites in Ongoing ClickFix Campaign
May 25
·
17 sources
78
Critical Flaws in Veeam and Terraform MCP Require Immediate Patching
Aug 5
·
2 sources
78
Critical Authorization Vulnerability in SiYuan (CVE-2026-66012)
Jul 26
·
2 sources
78
Operation Endgame Disrupts Evil Corp's SocGholish Malware Network
Jun 18
·
67 sources
78
Critical Vulnerabilities in Veeam Software Expose Systems to Remote Attacks
Aug 5
·
3 sources
78
Critical Memory Overread Vulnerability in Citrix NetScaler Exploited
May 29
·
2 sources
78
Critical CVE-2026-11624 Vulnerability in Model Context Protocol
Jun 14
·
3 sources
78
Critical Vulnerabilities in Paperclip AI Platform Enable Unauthenticated Command Execution
Aug 5
·
11 sources
78
Critical Vulnerability CVE-2026-32625 Discovered in LibreChat
Jun 3
·
2 sources
78
Critical Vulnerabilities Discovered in Splunk AI Toolkit
Jun 18
·
2 sources
78
Critical Vulnerabilities in FortiOS and Arista VeloCloud Under Active Exploitation
Jul 28
·
2 sources
78
EU Sanctions Russia Over Ongoing Cyber Espionage Campaign
Jul 13
·
172 sources
78
New Vulnerabilities Discovered in Serial-to-IP Converters Threaten Critical Infrastructure
Apr 21
·
9 sources
78
Critical Vulnerability in N-able Passportal Extensions Exposed
Aug 21
·
2 sources
78
EU Officials Targeted by State-Sponsored Cyberattacks on Messaging Apps
Aug 26
·
5 sources
78
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
Jul 22
·
16 sources
78
Russia's AI-Driven Cyber Espionage Targets Ukraine and Europe
1d ago
·
15 sources
78
Yahoo Confirms Breach of Over 1 Billion Accounts Linked to State-Sponsored Actors
Jun 3
·
3 sources
78
Escalating Cyber Threats Targeting U.S. Critical Infrastructure
Aug 12
·
2 sources
78
Prev
1 / 10
Next
Related Articles (50)
A flaw in voting machines in Georgia may allow voters to be matched to their ballots
Bostonglobe
·
2h ago
The secret ballot has been an article of faith in U.S. elections. That's being tested in Georgia
Pbs
·
5h ago
DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors
www.rapid7.com
·
6h ago
AI could exploit a flaw in Georgia's voting equipment and match voters to their ballots
Fortune
·
9h ago
Revolut says some customer data were exposed in e-mail-based scam
www.businesstimes.com.sg
·
10h ago
Revolut says data was exposed through fake government email
cointelegraph.com
·
10h ago
Revolut confirms customer data breach ahead of Israel launch
Ynetnews
·
11h ago
The secret ballot has been an article of faith in US elections. That's being tested in Georgia
Abcnews
·
12h ago
CISA Adds 5 Active Security Gaps to the KEV List
patribotics.blog
·
15h ago
Cyera: “Assumptions can be broken and once you look for them you find bugs”
Calcalistech
·
16h ago
Microsoft 974 patches, GitLab CVSS 10 exploited, Russia weaponizes Claude
Defendwork
·
17h ago
Revolut Confirms Limited Customer Data Breach via Impersonation Scam
Kucoin
·
20h ago
Solana Mobile Brevo Breach Exposes Users to Potential Phishing Threats
coinedition.com
·
23h ago
Revolut Confirms Customer Data Breach Due to Spoofed Government Request
Kucoin
·
23h ago
Revolut leak ties Bitcoin wallets to home addresses
Sg.Finance.Yahoo
·
1d ago
OpenAI's rogue AI tried to hack another company in May
Theverge
·
1d ago
Solana Mobile Brevo Breach Exposes Users to Potential Phishing Threats
Cryptorank
·
1d ago
Revolut confirms customer data breach from fake government requests
Cryptobriefing
·
1d ago
Revolut Leaks Customer Data to Hackers Posing as State Agency
News.Bitcoin
·
1d ago
Revolut Exposed KYC Data After Fraudulent Government Email Passed Security Checks
Securityaffairs.Co
·
1d ago
Why Payment Platforms Are Becoming New Frontline for Cyberattacks
Sundayguardianlive
·
1d ago
Revolut confirms it handed customer data to scammers posing as government agency
Cybernews
·
1d ago
Revolut confirms sensitive customer data breach, falling for fake government requests
Khaleejtimes
·
1d ago
Revolut Data Leak Exposes Sensitive Bitcoin and Identity Info
En.Cryptonomist.Ch
·
1d ago
Police warn of rise in unauthorised cryptocurrency account access through compromised emails
Channelnewsasia
·
1d ago
Revolut Data Breach: Am I Affected and What To Do?
Cryptoticker
·
1d ago
[EMPERADOR] – Ransomware Victim: Nexbex Solutions Private Limited
Redpacketsecurity
·
1d ago
Revolut confirms customer data breach through fake government requests
Techcrunch
·
1d ago
Multiple VLC Media Player Vulnerabilities Allow Attackers to Corrupt or Read Heap Memory
Cybersecuritynews
·
1d ago
Debian 13.7 Released with 107 Security Updates and 106 Bug Fixes
Linuxiac
·
1d ago
Revolut Suspected of Leaking High-Net-Worth Users' Data Due to Phishing Request
Kucoin
·
1d ago
Law firm documents appear on dark web as cyberattacks rise
Crypto.News
·
1d ago
OpenAI Agents RubyGems Attack: 2 Months Before HF Hack
Shattered
·
1d ago
🏴☠️ Krybit has just published a new victim : www.ibnsinatrust.com
Ransomware.Live
·
1d ago
🏴☠️ Krybit has just published a new victim : lasultanahotels.com
Ransomware.Live
·
1d ago
🏴☠️ Krybit has just published a new victim : intherpro.com
Ransomware.Live
·
1d ago
Revolut Handed Over Passports, Bitcoin Records After Fake Government Request Slipped ...
Glitchwire
·
1d ago
OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers
Thehackernews
·
1d ago
GitLab Issues Emergency Security Update For Maximum-Severity Vulnerability
Linkedin
·
1d ago
Citizen Lab on Eavesdropping on Students: Serbia Is Like a Buffet of Spyware
n1info.rs
·
1d ago
OpenAI's own agents attacked RubyGems with 2,000 malicious packages and nobody knows why
Pasqualepillitteri.It
·
1d ago
Greenberg Traurig Data Breach: SilentRansomGroup Targets Big Law
Darkwebdecoded
·
1d ago
Russia
Theins.Press
·
1d ago
Singapore police warn crypto users after hackers exploit compromised email accounts
Malaymail
·
1d ago
OpenAI Agents Flood RubyGems With 2,000 Packages and Exploit Build System for RCE
Gbhackers
·
1d ago
Researchers say OpenAI agents were behind May hacking campaign targeting RubyGems
Cyberscoop
·
1d ago
CVE-2026-85706: GitLab CVSS 10.0 Path Traversal Under Active Probing
Securityarsenal
·
1d ago
CVE Alert: CVE-2026-72708 – SPIP
Redpacketsecurity
·
2d ago
Two prominent US law firms Greenberg Traurig, Eckert Seamans disclose data breaches
Teiss
·
2d ago
Jabaroot: Behind the hacker group's claim of a 70000‑name leak in Morocco's police and intelligence
Middleeasteye
·
2d ago
Prev
1 / 10
Next
Related Entities
ShinyHunters
Data Breach
Phishing
Malware
Ransomware
Zero-day Exploit
Supply Chain Attack
DDoS
Sql Injection
Denial of Service
Credential Stuffing
Brute Force