Security threats, piped to your terminal.

Spydr watches the CVE feeds, CISA’s known-exploited list and breach disclosures. Ask it from any terminal with curl, wire it into CI and alerts — or read the week’s highlights in The Security Skim.

curl https://spydr.io

46,280 CVEs 1,734 known exploited 1,018 breaches updated 1 hour ago

Exploited this week
curl "https://spydr.io/threats?exploited=1&since=7d&limit=5"
spydr · threats · exploited · since 7d            5 results · synced 20:44 UTC
──────────────────────────────────────────────────────────────────────────────
 8.7 high      CVE-2026-88779   2026-10-04  KEV EPSS 0.53%  NetScaler ADC
               Vulnerability in NetScaler ADC and NetScaler Gateway. This iss…
 9.8 critical  CVE-2026-104286  2026-10-01  KEV  EPSS 2.2%  Fortinet FortiMail
               An improper limitation of a pathname to a restricted directory…
 9.4 critical  CVE-2026-102490  2026-09-30  KEV EPSS 0.63%  Zammad GmbH Zammad
               All versions of Zammad including the latest alpha enable the l…
 9.4 critical  CVE-2026-102489  2026-09-30  KEV  EPSS 1.4%  Zammad GmbH Zammad
               Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack…
 9.8 critical  CVE-2026-76504   2026-09-30  KEV  EPSS 1.6%  Cisco Catalyst SD…
               A vulnerability in the API session-based authentication manage…
──────────────────────────────────────────────────────────────────────────────
page 1 of 1 · web: https://spydr.io/threats?exploited=1&since=7d&limit=5
scripts: add &format=json (or ndjson, csv, rss) · help: curl https://spydr.io/help
Data: This product uses data from the NVD API but is not endorsed or certified by the NVD. CISA KEV · FIRST EPSS.
Your stack
curl "https://spydr.io/threats?q=nginx,openssl,linux&cvss=7&limit=5"
spydr · threats · q=nginx,openssl,linux · cvss ≥ 7 3394 results · synced 20:44 UTC
──────────────────────────────────────────────────────────────────────────────
 9.2 critical  CVE-2026-42530   2026-06-17       EPSS 1.1%  F5 NGINX Open Sou…
               NGINX Open Source has a vulnerability in the ngx_http_v3_modul…
 9.2 critical  CVE-2026-42055   2026-06-17       EPSS 6.5%  F5 NGINX Open Sou…
               NGINX Plus and NGINX Open Source have a vulnerability in the n…
 7.1 high      CVE-2026-102335  2026-09-28      EPSS 0.23%  NginxProxyManager…
               Nginx Proxy Manager through 2.16.0 fails to restrict the advan…
 9.1 critical  CVE-2026-102334  2026-09-28      EPSS 0.45%  NginxProxyManager…
               Nginx Proxy Manager through 2.16.0 lacks rate-limiting on auth…
 8.8 high      CVE-2026-60005   2026-07-15      EPSS 0.53%  F5 NGINX Plus
               NGINX Plus and NGINX Open Source have a vulnerability in the n…
──────────────────────────────────────────────────────────────────────────────
page 1 of 679 · web: https://spydr.io/threats?q=nginx%2Copenssl%2Clinux&cvss=7&limit=5 · next: &page=2
scripts: add &format=json (or ndjson, csv, rss) · help: curl https://spydr.io/help
Data: This product uses data from the NVD API but is not endorsed or certified by the NVD. CISA KEV · FIRST EPSS.
Breaches
curl "https://spydr.io/breaches?since=30d&limit=4"
spydr · breaches · since 30d                      5 results · synced 18:44 UTC
──────────────────────────────────────────────────────────────────────────────
2026-09-30  Medela                    424K accounts     medela.… (sensitive)
            Email addresses, Employers, Job titles, Names, Phone numbers, Phy…
2026-09-22  LimeLeads                 17.8M accounts    limelea…
            Email addresses, Employers, Geographic locations, Job titles, Pho…
2026-09-21  Burger King Russia        3.2M accounts     burgerk…
            Dates of birth, Email addresses, Genders, Geographic locations, N…
2026-09-13  Chess.com (2026)          4.7M accounts     chess.c…
            Email addresses, Geographic locations, Names, Usernames
──────────────────────────────────────────────────────────────────────────────
page 1 of 2 · web: https://spydr.io/breaches?since=30d&limit=4
Breach data from Have I Been Pwned (haveibeenpwned.com), licensed under CC BY 4.0.

Two ways to keep up

The same feed, raw or distilled. Use whichever fits the moment.

In your terminal

Every page on this site is also an API. Filter by keyword, CVE, CVSS score, exploit status or date, and get a table, JSON, CSV or RSS back.

  • curl "https://spydr.io/threats?q=nginx&cvss=7"
  • curl "https://spydr.io/threats?kev=1&since=7d"
  • curl "https://spydr.io/breaches?since=30d"
API & automation docs →

In your inbox

The Security Skim reads the feed for you: every Tuesday, the vulnerabilities being exploited, the breaches worth knowing about and what to patch first.

  • Weekly digest, five minutes to read
  • Long reads when something big breaks
  • No sponsors, unsubscribe from any issue
Read The Skim →

Latest

Straight from the feed. CVE data 1 hour ago, breaches 3 hours ago.

Open the full feed

Added to CISA’s exploited list · last 7 days

Vulnerabilities added to CISA KEV in the last 7 days
Score CVE Affected Added to KEV
8.7 high CVE-2026-88779 KEV NetScaler ADC 4 Oct 2026
9.4 critical CVE-2026-102490 KEV Zammad GmbH Zammad 2 Oct 2026
9.4 critical CVE-2026-102489 KEV Zammad GmbH Zammad 2 Oct 2026
9.8 critical CVE-2026-104286 KEV Fortinet FortiMail 1 Oct 2026
9.8 critical CVE-2026-76504 KEV Cisco Catalyst SD-WAN Manager 30 Sept 2026
8.8 high CVE-2026-86950 KEV Apple iOS and iPadOS 29 Sept 2026

New high and critical CVEs · last 24 hours

High and critical CVEs published in the last 24 hours
Score CVE Affected Published
10.0 critical CVE-2026-100103 Perfoce P4 (Helix Core) 5 Oct 2026
9.9 critical CVE-2026-105691 penpot 5 Oct 2026
9.9 critical CVE-2026-105636 makeplane plane 5 Oct 2026
9.8 critical CVE-2026-97283 Liquid Web / StellarWP Advanced Post Manager 5 Oct 2026
9.8 critical CVE-2026-105641 makeplane plane 5 Oct 2026
9.8 critical CVE-2026-105639 makeplane plane 5 Oct 2026

Automate it

Plain HTTP, stable URLs and exit codes you can script against. Three places to start:

Alert Slack when something you run is exploited

crontab · hourly
0 * * * *  curl -s "https://spydr.io/threats.json?q=nginx,postgres,openssl&exploited=1&since=1h" \
  | jq -r '.results[] | "*\(.id)* \(.severity) — \(.products[0] // "")\n\(.url)"' \
  | while read -r line; do
      curl -s -X POST -H 'content-type: application/json' \
        -d "$(jq -n --arg t "$line" '{text:$t}')" "$SLACK_WEBHOOK_URL"
    done

Fail a build when a critical CVE lands in your stack

.github/workflows/security.yml
- name: Spydr gate
  run: |
    code=$(curl -s -o hits.txt -w '%{http_code}' \
      "https://spydr.io/threats?q=django,celery,redis&cvss=9&since=1d&fail=1")
    case $code in
      200) echo "No new critical CVEs" ;;
      409) cat hits.txt; exit 1 ;;
      *)   echo "Spydr unavailable ($code)"; exit 2 ;;
    esac

Follow it in any feed reader

RSS
https://spydr.io/threats.rss?exploited=1
https://spydr.io/threats.rss?q=kubernetes&cvss=7
https://spydr.io/breaches.rss
The Security Skim

The week in security, in five minutes.

A short email every Tuesday: what’s being exploited, which breaches matter, and the one thing to patch before Friday. Written by people, not scraped.

Subscribe

Free. Hosted on Substack at securityskim.com.