Radark watches every new vulnerability, keeps only the ones that hit your stack, and ranks them by what's actually being exploited. Delivered to Telegram, Slack, or a webhook.
The NVD publishes dozens of CVEs a day. You care about a handful. Radark does the filtering and the prioritization for you.
Tell it your tech — kubernetes, nginx, postgres, log4j — and only relevant CVEs get through.
Sorted by CISA KEV (actively exploited) → EPSS (exploit probability) → CVSS. What's on fire rises to the top.
Realtime to Telegram, or push to Slack and generic webhooks. A daily digest if you prefer calm.
Continuous, non-intrusive assessment of assets you own and verify — TLS, headers, exposures, templated checks.
Connect a repo once — version-precise CVEs on your composer/npm/pip/go lockfiles via OSV. Private packages excluded.
Every scan produces a shareable report mapped to PCI DSS · OWASP · MITRE ATT&CK · NIST CSF — with a risk score, step-by-step remediation, drift since the last scan, and posture over time.
| Sev | Finding | Framework refs |
|---|---|---|
| HIGH | HSTS not enforcedNEW Strict-Transport-Security header missing |
PCI 4.2.1 ATT&CK T1557 NIST PR.DS-2 |
| MED | Content-Security-Policy missing No XSS mitigation policy served |
PCI 6.4.3 ATT&CK T1059.007 NIST PR.PT-3 |
| LOW | Server version disclosed nginx/1.25.3 in response headers |
PCI 2.2.1 ATT&CK T1592 NIST PR.IP-1 |
Connect a repo once. Radark reads your lockfiles and alerts only on CVEs affecting the exact versions you ship — powered by OSV. Private packages are excluded; only manifest metadata is read, never your source.
| Package | Installed | Sev | Fixed in |
|---|---|---|---|
| lodash npm | 4.17.11 | CRIT | 4.17.12 |
| guzzlehttp/guzzle composer | 6.5.0 | HIGH | 6.5.8 |
| symfony/http-kernel composer | 4.4.0 | HIGH | 4.4.13 |
/watch kubernetes nginx postgres — or tap it in the Mini App with autocomplete.
NVD, CISA KEV, GitHub Advisories and EPSS, checked continuously.
Ranked alerts, de-duplicated, with the patch link. No noise, no digging.
Cancel anytime. Attack-surface scans run only on assets you own and verify by DNS.
Set it up in half a minute. First relevant alert lands today.
🛡️ Open Radark in Telegram