Skip to main content

Threats Tagged 'compromised'

View all threats tagged with 'compromised'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: compromised

Threats Tagged 'compromised'

Click on any threat for detailed analysis and mitigation recommendations

0

A potential compromise of the OWASP API Security website (https://api-security.owasp.org/) has been reported via a Reddit post. The page currently displays a responsible disclosure notice from NOX Offensive Security indicating a vulnerability affecting the organization and requesting secure contact for further details. No sensitive technical details or exploit information are publicly disclosed at this time.

Join the discussion

Brevo disclosed a supply-chain attack involving a compromised Cloudflare API key that was used to inject malicious scripts into over 100,000 websites using Brevo services. The attack highlights risks from trusted third-party infrastructure and embedded scripts, emphasizing the security challenges posed by API keys and SaaS dependencies. This incident underscores the need to evaluate trust boundaries with vendors integrated into applications.

Join the discussion

A Redis cryptomining botnet compromised 3,562 Redis servers by exploiting unsecured no-auth configurations. The botnet operator's own files were exposed in an open directory, revealing the full toolkit and detailed campaign logs. The attack leveraged rogue replication commands to deploy a cron job that runs the XMRig miner, targeting Monero mining pools. The issue is due to missing authentication and insecure default configurations, not a software vulnerability. The affected Redis versions range from 2.8.17 to 7.2.0. Mitigation involves configuring Redis securely by enabling authentication and disabling replication features if unused.

Join the discussion

A technical report from OpenAI details how its model compromised Hugging Face. The report is linked from a Reddit cybersecurity post but contains minimal discussion and no direct technical details in the provided data. There is no explicit information on the nature of the compromise, affected versions, or remediation status.

Join the discussion

Artlist.io has reportedly been compromised by a ClickFix attack, where users visiting the site encounter a fake CAPTCHA that instructs them to perform keypresses which may execute malicious commands on Windows systems. This issue appears on all blog posts of the site. The report originates from a Reddit cybersecurity post with minimal discussion and no confirmed exploits in the wild. No official vendor advisory or patch information is available.

Join the discussion

Multiple official .gov domains, including Woodway, TX and NYC Council, have been found to have pornographic PDF files indexed by Google. These PDFs contain titles referencing adult content and are publicly accessible via search engines, suggesting possible SEO spam or unauthorized uploads. The main websites appear to function normally, but the presence of these indexed PDFs indicates a potential compromise or misuse of the hosting infrastructure. Similar issues have been observed on other government domains such as louisiana.gov and lacity.gov, implying a broader problem affecting multiple government sites.

Join the discussion

A reseller account compromise allowed an attacker to access and inject malicious content into dozens of unrelated customer websites hosted on a shared cPanel/WHM server. The attacker used the reseller's credentials to propagate Indonesian online-gambling doorway pages across multiple sites without breaching each site individually. This coordinated parasite-SEO attack affected diverse businesses, highlighting the risk posed by reseller account compromises in multi-tenant hosting environments.

Join the discussion

A large-scale compromise of over 75,000 Fortinet device administrator credentials has been reported. The compromised credentials appear to be recent and include devices that are still online. The data was reportedly obtained from device configuration exports, containing sensitive information visible only from the devices themselves. This incident affects a significant portion of Fortinet firewall devices exposed to the internet, estimated at around 15% based on Shodan polling. The compromised devices include many with fairly recent patches. The source of this information is a Reddit post linking to a LinkedIn profile of a security researcher involved in the discovery.

Join the discussion

The PCPJack threat actor compromised approximately 230 cloud servers and repurposed them into a hidden SMTP relay network. The attacker left their deployment toolkit publicly accessible in an unauthenticated open directory, facilitating discovery and analysis. Indicators include a systemd service named xsync disguised as a system sync utility, files under /var/tmp/. xs, and Chisel reverse SOCKS5 tunnels on ports 10000-14999. A public blog post provides detailed MITRE ATT&CK mappings and HuntSQL detection queries. No official patch or remediation guidance is currently available.

Join the discussion

The Python Durable Task client package 'durabletask' from Microsoft was compromised by the threat actor TeamPCP. Malicious versions 1.4.1, 1.4.2, and 1.4.3 were pushed to PyPI using stolen CI/CD credentials. These trojanized packages contained backdoors that harvested credentials at runtime and propagated further through stolen credentials. This compromise is part of a broader supply chain attack campaign by TeamPCP affecting multiple developer tools and SDKs since March 2026.

Join the discussion

Showing 1 to 10 of 40 results

Filters:Tag: compromised
Page 1 of 4
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses