ScyScan - Free Online Security & Network Tools

ScyScan provides a suite of free security tools — try our web scanner, virus scanner, link checker, SSL checker, WHOIS lookup, and IP lookup all in one place.

Explore All Tools

Cybersecurity Toolkit

Choose from our range of free online security and network tools to protect your devices, websites, and online presence

Web Scanner

Check websites for vulnerabilities and other security issues, providing real-time results and detailed analysis.

Scan Website / URL

Virus Scanner

Scan files for malware, viruses, trojans, and other threats using multi-engine technology.

Scan Files

Link Checker

Verify URLs for safety, detect phishing attempts, and check if links lead to malicious websites.

Check Links

SSL Checker

Analyze SSL certificates, check expiration dates, and verify proper encryption implementation.

Check SSL

Whois

Get detailed domain registration information including owner details, registration dates, and expiration.

Lookup Domain

IP Lookup

Identify geographic location, ISP information, and other details about any IP address.

Lookup IP

Why Choose ScyScan

ScyScan brings together essential security and network tools in a single, free platform designed for everyday use

🔒

All-in-One Platform

Web scanner, link checker, virus scanner, SSL checker, WHOIS, and IP lookup — all available from one place.

🔄

Trusted Reliability

Built on up-to-date threat intelligence and network databases you can count on.

🚀

Results in Seconds

Most checks complete within seconds so you get answers fast.

💰

Completely Free

All our security and network tools are free to use with no hidden costs or fair use restrictions.

🌐

Online Access

No software installation required - access our tools from any browser, anywhere.

📊

Clear Reports

Receive straightforward analysis and easy-to-understand reports for every tool.

Built for Everyday Security

ScyScan combines multiple security data sources and network databases into one accessible platform. No complex setup — just enter what you need and get clear results.

Multiple Data Sources

Aggregated threat intelligence from trusted security feeds for comprehensive coverage

Network Databases

Access to extensive WHOIS and IP geolocation databases for accurate information

Privacy Focused

We respect your privacy and automatically delete scans and lookups after analysis

Continuously Updated

Data sources are refreshed regularly so you get current information.

How People Use ScyScan Tools

📧 Check Attachments

Use our virus scanner to check files before opening them

🌐 Audit Your Website

Run a web scan to check your website for known vulnerabilities

🔗 Verify Links

Use the link checker to test if a URL is safe before clicking

🔐 Inspect SSL

Check SSL certificate validity and configuration for any domain

🏢 Research Domains

Look up domain registration details with the WHOIS tool

📍 Trace IPs

Find geographic and network details for any IP address

Start Using ScyScan Tools

All tools are free and ready to use — no account or sign-up required

Explore All Tools

CISA sounds alarm on Langflow RCE, Trivy supply chain compromise after rapid exploitation

The US Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities catalog:

  • CVE-2026-33017, a recently disclosed code injection vulnerability in Langflow, an open-source framework for building AI agents and workflows, and
  • CVE-2026-33634, an embedded malicious code vulnerability in Aqua Security’s Trivy security scanner.

Their addition to the catalog means that US federal civilian agencies are required to address the flaws within their networks by April 8 and 9, respectively.

About CVE-2026-33017

CVE-2026-33017 is a critical vulnerability stemming from several security weaknesses and affects Langflow versions 1.8.2. and earlier. It may allow unauthenticated attackers to remotely execute code on a Langflow instance via a public flow build endpoint.

A very detailed security advisory for CVE-2026-33017 was made broadly visible on GitHub on March 17, 2026, and apparently had enough information for attackers to develop an exploit and start using it.

“Within 20 hours of the advisory’s publication, the Sysdig Threat Research Team (TRT) observed the first exploitation attempts in the wild,” the cloud security company shared.

“No public proof-of-concept (PoC) code existed at the time. Attackers built working exploits directly from the advisory description and began scanning the internet for vulnerable instances. Exfiltrated information included keys and credentials, which provided access to connected databases and potential software supply chain compromise.”

The occurrence serves as another confirmation of the shrinking window between “advisory publication” and “active exploitation”, Sysdig researchers noted.

“The collapse from months-long exploitation timelines to same-day weaponization is a structural shift in how vulnerabilities are exploited today. Organizations that rely on scheduled patch cycles to address critical vulnerabilities are operating on a timeline that attackers have already outpaced. Runtime detection, network segmentation, and rapid response capabilities are essential to bridging the gap between disclosure and remediation.”

It should be pointed out that Aviral Srivastava, the discoverer of CVE-2026-33017, unearthed the flaw while checking out how Langflow maintainers fixed CVE-2025–3248, a previously exploited vulnerability in the same code base.

This allowed him to pinpoint the same class of vulnerability, but on a different endpoint. It’s therefore also possible (though less likely) that attackers followed a similar approach.

About CVE-2026-33634

The CVE-2026-33634 identifier has been assigned to allow security teams to follow the ramifications of the Trivy supply chain compromise.

This compromise, which has been attributed to TeamPCP, happened on March 19, 2026, and allowed attackers to:

  • Publish a malicious Trivy v0.69.4 release
  • Force-push version tags in ‘aquasecurity/trivy-action’ to credential-stealing malware
  • Replace all tags in ‘aquasecurity/setup-trivy’ with malicious commits
  • Push out malicious trivy images on Docker Hub.

It also likely led to the LiteLLM supply chain attack, which resulted in compromised LiteLLM packages being published on PyPI.

Aqua Security outlined the incident and advised on recommended action for those that have been affected, and is expected to provide a meaningful update on their investigation in the coming days.

BerriAI, the creators of LiteLLM, have paused the release of new LiteLLM packages, and they’ve called in Mandiant to do a complete supply chain security review. According to Wiz researchers, LiteLLM is present in 36% of cloud environments they monitor, “signifying the potential for widespread impact.”

Both organizations have provided remediation instructions for affected users and developers.

In a public alert, the German Federal Office for Information Security (BSI) said that a number of compromises were reported them in the wake of and related to the Trivy attack. “According to current information, no data is believed to have been exfiltrated,” they said.

Top News: