Skip to content
Product
Use it
Threat intelligence API
Free key, 70+ endpoints, OpenAPI. The product.
Get started
Pick your stack, make your first call.
Live feed
The console: incidents, filters, entities, search.
Recipes
Runnable examples for the free key.
Free feeds
RSS, ransomware feed, IOC blocklist, MISP — no key.
CLI & agents
tc from a terminal; agent keys with scoped budgets.
The data
Incident records
900 articles a day become ~70 scored incidents.
Dark web
First-party leak-site collection: victims, groups, markets.
Validated IOCs
Indicators with a false-positive gate; STIX, MISP, CSV.
Vulnerabilities
CVEs with EPSS, KEV and exploit status.
Entity graph
Actors, malware, CVEs, companies — pivotable.
For teams
For service providers
Per-client feeds, alerts and branded digests.
Use cases
How teams and builders use the corpus.
About ThreatCluster
What it is and how it is built.
Pricing
Docs
Reference
OpenAPI (Swagger)
Every endpoint, parameter and response model.
ReDoc
The same reference, long-form.
Examples on GitHub
curl, Python and Node quickstarts; daily spec snapshot.
Guides
Quickstart & plans
Key, scopes, budgets, tiers.
Integrations
Splunk, Sentinel, Elastic, agents and terminals, step by step
Export formats
STIX 2.1, MISP, CSV, text.
CLI setup
Install, log in, wire an agent.
No results found
Sign in
Get a free key
No results found
Product
Threat intelligence API
Get started
Live feed
Recipes
Free feeds
CLI & agents
The data
Incident records
Dark web
Validated IOCs
Vulnerabilities
Entity graph
For teams
For service providers
Use cases
About ThreatCluster
Docs
OpenAPI (Swagger)
ReDoc
Examples on GitHub
Quickstart & plans
Integrations
Export formats
CLI setup
Pricing
Contact
Get a free key
Sign in
Back
CWE-352 - Cross-Site Request Forgery (csrf)
CWE Weakness
Threat entity extracted from intelligence sources
Sep 25: 1 mention
Sep 26: 3 mentions
Sep 27: 1 mention
Sep 28: 1 mention
Sep 29: 0 mentions
Sep 30: 0 mentions
Oct 1: 0 mentions
Sep 25
Sep 28
Oct 1
Entities
›
cwe
›
CWE-352 - Cross-Site Request Forgery (csrf)
Frequency
61
occurrences
First Seen
May 12, 2026
Last Seen
September 28, 2026
API
Overview
Recent Events
Profile
Profile
MITRE ATT&CK
1 / 2
Malware
Comet
Spy Corporate
MaliBot
Lunex Stealer
Hermes
Tools
Google Drive
Chrome
Gmail
Teams
CVEs
CVE-2026-19650
CVE-2026-19478
CVE-2026-77956
CVE-2026-76969
CVE-2026-76968
CVE-2026-76963
CVE-2026-76962
CVE-2026-76961
Regions
Uzbekistan
Tunisia
South Korea
Saudi Arabia
Russia
Sectors
Healthcare
Energy
Government
Technology
Insurance
Financial
-
REC
Recon
No techniques detected
-
RD
Resource Dev
No techniques detected
3
IA
Initial Access
T1566.002 - Spearphishing Link
T1078 - Valid Accounts
T1190 - Exploit Public-Facing Application
2
EX
Execution
T1059 - Command and Scripting Interpreter
T1053 - Scheduled Task/Job
2
PE
Persistence
T1505.003 - Web Shell
T1136 - Create Account
1
PE
Priv Esc
T1068 - Exploitation for Privilege Escalation
1
DE
Defense Evasion
T1070 - Indicator Removal
3
CA
Cred Access
T1110 - Brute Force
T1555.003 - Credentials From Web Browsers
T1003 - OS Credential Dumping
-
DI
Discovery
No techniques detected
-
LM
Lateral Mov
No techniques detected
-
CO
Collection
No techniques detected
1
C2
C2
T1071 - Application Layer Protocol
1
EX
Exfil
T1041 - Exfiltration Over C2 Channel
-
IM
Impact
No techniques detected
20
techniques detected across
8
tactics
Related Clusters (24)
Cisco IOS Vulnerability CVE-2008-4128 Under Active Exploitation
Jul 14
·
3 sources
80
Critical Zero-Day Exploits Target Citrix and Other Major Platforms
3d ago
·
5 sources
80
Russian FSB Exploits Vulnerable Routers to Target Critical Infrastructure
Jul 13
·
51 sources
78
Critical Vulnerability in NASA Ground Control Software Allows Unauthenticated Access
Aug 20
·
6 sources
78
Critical Authlib Vulnerabilities Discovered in Ubuntu Affecting JWT and CSRF
Jul 16
·
2 sources
74
Microsoft Issues Critical Security Patches for August 2026
Aug 12
·
2 sources
73
ShinyHunters Escalate Oracle PeopleSoft Exploitation Amid Microsoft Mega-Patch
2d ago
·
2 sources
73
Critical GitLab Vulnerability Allows Unauthenticated Data Deletion
Aug 18
·
23 sources
72
Critical Vulnerabilities in Adobe Connect Require Immediate Patching
Sep 23
·
3 sources
72
Critical Vulnerabilities Discovered in Jenkins Plugins
May 28
·
2 sources
72
OpenWrt Releases Critical Security Updates for DHCPv6 Vulnerabilities
Jul 29
·
2 sources
72
Critical XSS Vulnerability in Pretalx Conference Platform Exposed
May 28
·
3 sources
72
Critical CSRF Vulnerability in Elementor Plugin Allows Unauthorized Admin Account Creation
5d ago
·
2 sources
72
SAP Addresses Critical Vulnerabilities in Commerce Cloud and S/4HANA
May 12
·
6 sources
71
HestiaCP Vulnerability Allows Admin Takeover via Cron Job Exploit
Jul 5
·
1 sources
69
AI Browsers Face Serious Security Risks from Prompt Injection Attacks
Jul 9
·
2 sources
69
Critical CSRF Vulnerability in WWBN AVideo Exposes Admins to Attacks
Sep 9
·
1 sources
69
Critical NASA/JPL Software Flaw Allows Unauthorized Spacecraft Command
Aug 23
·
2 sources
67
Multiple CVEs in Magnolia CMS Expose Users to Remote Code Execution
Sep 22
·
4 sources
65
Multiple Adobe CVEs Disclosed: High-Risk Vulnerabilities Identified
Sep 23
·
3 sources
65
Critical Vulnerabilities Disclosed in ash_ai LLM Toolbox for Elixir Framework
Aug 31
·
3 sources
61
Fedora 43 and 44 Address Critical CSRF Vulnerability in Perl-Mojolicious
Jul 28
·
2 sources
58
New CVE Exploits Affect DedeCMS with Remote Code Execution Vulnerability
6d ago
·
3 sources
55
New Vulnerability Scanner Released for Educational Use
Sep 18
·
3 sources
25
Prev
1 / 5
Next
Related Articles (50)
Rapid7 Vulnerability & Exploit Database
Rapid7
·
3d ago
Oracle PeopleSoft, Microsoft patches, Elementor RCE under active exploitation
Defendwork
·
4d ago
Rapid7 Vulnerability & Exploit Database
Rapid7
·
4d ago
Patchstack explains
patchstack.com
·
5d ago
Elementor WordPress flaw lets attackers create admin accounts
Bleepingcomputer
·
5d ago
cve exploit
Sploitus
·
6d ago
GHSA-632h-h47v-g4x4
github.com
·
Sep 24
Adobe Patches Critical Flaws in Connect, AEM Forms
Securityweek
·
Sep 23
CVE Alert: CVE-2026-75743 – Adobe
Redpacketsecurity
·
Sep 23
CVE-2021
Sploitus
·
Sep 22
awesome-android
Sploitus
·
Sep 21
Vulnerability
Sploitus
·
Sep 18
Bounty Dynamics
www.microsoft.com
·
Sep 17
GHSA Gmx5 Mhqr H7rj
github.com
·
Sep 9
CVE Alert: CVE-2026-86718 – WWBN
Redpacketsecurity
·
Sep 9
6 Ways To Prevent Privilege Escalation Attacks
www.techtarget.com
·
Sep 8
September 2026
support.sap.com
·
Sep 8
September 2026 security updates
support.sap.com
·
Sep 8
HPE patches critical ArubaOS-CX remote code execution flaw
Bleepingcomputer
·
Sep 3
ash_ai 6-CVE Cluster Exposes the Full Agent Stack in Elixir's First Coordinated AI ...
Cryptorank
·
Sep 1
ash_ai 6-CVE Cluster Exposes the Full Agent Stack in Elixir's First Coordinated AI ...
Forkast.News
·
Aug 31
PSIRT WatchGuard CVE-2026-78174
psirt.watchguard.com
·
Aug 29
Inside A Multi Agent Ai Framework Used To Compromise Government Entities In Asia
www.dreamgroup.com
·
Aug 29
Falla crítica en software de NASA/JPL permite comandar naves espaciales sin autenticación
Ciberseguridadlatam
·
Aug 23
NASA ground control software vulnerability could allow spacecraft access
Feeds.Feedburner
·
Aug 21
Security Fixes Updates And Advisories
trueconf.com
·
Aug 21
Critical GitLab Flaw Lets Hackers Alter or Delete Public Projects
Thecyberexpress
·
Aug 19
GitLab ships out-of-band fix for CVSS 9.4 GraphQL bug
Aiweekly.Co
·
Aug 18
Critical GitLab Zero
Darkreading
·
Aug 18
Critical GitLab flaw allows attackers to delete and modify public repos
Csoonline
·
Aug 18
GitLab Ships Emergency Patch for Critical CVSS 9.4 GraphQL Flaw That Lets ...
Aiweekly.Co
·
Aug 18
NASA Ground Control Software Flaw Enables Unauthenticated Commands
Infosecurity-Magazine
·
Aug 18
GitLab Emergency Patch: Third GraphQL Flaw of 2026 Lets Unauthenticated Attackers ...
Techtimes
·
Aug 18
Ai Pentesting The Depth Of A Pentest On Demand
www.intruder.io
·
Aug 18
GitLab Patches Multiple Security Flaws in CE and EE With 19.2.4 Update
Gbhackers
·
Aug 18
August 2026 Monthly Patch
Csa.Sg
·
Aug 12
Attackers exploit backdoor in Cisco's firewall management software
Heise.De
·
Jul 30
OpenWrt releases security updates for critical DHCPv6 flaw and other vulnerabilities
Scworld
·
Jul 29
Fedora 44 perl-Mojolicious Critical CSRF Attack Mitigation 2026
Linuxsecurity
·
Jul 28
Agentic Browsers Rewind Web Security by 20 years
Darkreading
·
Jul 27
CT
cts.businesswire.com
·
Jul 23
CT
cts.businesswire.com
·
Jul 23
CVE-2008-4128
nvd.nist.gov
·
Jul 17
USN-8557-1: Authlib vulnerabilities
Ubuntu
·
Jul 16
CISA Known Exploited Vulnerabilities
nvd.nist.gov
·
Jul 15
CISA Warns of Decades
Cybersecuritynews
·
Jul 14
Old Cisco vulnerability under attack: Protection guide
Heise.De
·
Jul 14
US authorities warn that state
Cybersecuritydive
·
Jul 13
Ai Browsers Prompt Injection
www.theregister.com
·
Jul 12
Layerx Identifies Vulnerability In New Chatgpt Atlas Browser
layerxsecurity.com
·
Jul 10
Prev
1 / 10
Next
Related Entities
Data Breach
Sql Injection
Zero-day Exploit
Phishing
Malware
Cross-site Request Forgery (csrf)
Denial of Service
Cross-Site Scripting (xss)
Supply Chain Attack
Denial-of-Service
DDoS
Server-Side Request Forgery (ssrf)