Threats Tagged 'cybersecurity'
View all threats tagged with 'cybersecurity'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cybersecurity'
Click on any threat for detailed analysis and mitigation recommendations
Despite federal warnings, thousands of U.S. industrial controllers used in water systems remain exposed online 0 A recent scan identified over 4,000 Rockwell Automation and Allen-Bradley industrial controllers used in U.S. water and wastewater systems exposed directly to the internet. Despite federal warnings, many of these devices remain accessible, including 22 in cities recently targeted by cyberattacks. The exposed devices use the EtherNet/IP protocol, which can allow remote identification and potential configuration changes if improperly secured. Some devices appear vulnerable to a known remote code execution flaw disclosed in 2017 (CVE-2017-16740). The FBI and EPA have confirmed cyberattacks on water utilities in multiple states, with some attacks causing operational disruptions such as pressure loss and flooding. The exposure is attributed to mass scanning and opportunistic exploitation rather than targeted zero-day attacks. Manufacturers and federal agencies have long advised against placing such controllers on the public internet. Join the discussion | Reddit Cybersecurity | 08/06/2026, 19:14:00 UTC Added: 08/06/2026, 19:26:02 UTC |
CISA's OSS Security Principles and Practices 0 The Cybersecurity and Infrastructure Security Agency (CISA) released a strategic framework titled 'OSS Security Principles and Practices' to guide federal agencies in managing open source software (OSS) securely throughout its lifecycle. The framework highlights OSS benefits such as transparency, cost efficiency, and flexibility, while addressing unique risks like decentralized development and supply chain vulnerabilities. It introduces the C4 Framework to assess OSS risk across codebase, community, conduct, and configuration. The guidelines mandate rigorous source code inventories, legal reviews, and encourage contributing security fixes upstream. Special considerations for AI systems require full access to training data and pipelines to ensure security. These principles aim to strengthen supply chain risk management and can be applied beyond federal agencies. Join the discussion | Reddit Cybersecurity | 08/06/2026, 17:40:25 UTC Added: 08/06/2026, 17:41:03 UTC |
tl;dv (AI meeting assistant) left 181,874 meetings exposed via misconfigured Firestore, including live calls you could join. Researcher disclosed in January, still unpatched 6 months later. 0 The AI meeting assistant tl;dv exposed 181,874 meetings due to a misconfigured Firestore database. This exposure included live calls that unauthorized users could join. The vulnerability was disclosed by a researcher in January but remains unpatched six months later. Join the discussion | Reddit Cybersecurity | 08/05/2026, 20:21:00 UTC Added: 08/05/2026, 20:41:04 UTC |
Hacked Accounts on Messenger 0 Reports have emerged on Reddit about accounts on the Messenger platform being hacked. The claim involves images sent in group chats that allegedly contain malicious content capable of compromising accounts when clicked. However, the information is based on a single Reddit post with minimal discussion and no technical details or vendor confirmation. No specific vulnerability, exploit, or patch information is provided. Join the discussion | Reddit Cybersecurity | 08/05/2026, 10:20:33 UTC Added: 08/05/2026, 11:11:04 UTC |
40%+ of AI-Generated Code Has Security Issues; We Open-Sourced a Way to Help 0 Research indicates that over 40% of AI-generated code contains security issues, often due to missing framework- and version-specific security details. To address this, an open-source project called AI Code Security Cards provides library-specific security guidance for developers and AI coding agents. The project covers more than 60 libraries and frameworks across multiple programming languages, offering practical instructions to mitigate common security pitfalls. This initiative aims to improve the security posture of AI-generated code by guiding coding agents on unsafe defaults, validation, authentication patterns, and security changes between library versions. Join the discussion | Reddit Cybersecurity | 08/05/2026, 09:34:58 UTC Added: 08/05/2026, 09:56:02 UTC |
Looking for cybersecurity people to provide honest feedback for an CISSP practice bank/platform I have built. 0 This content is a request for feedback on a CISSP practice exam platform created by an individual. It is a community engagement post seeking input on question quality and relevance, not a security threat or vulnerability. Join the discussion | Reddit Cybersecurity | 08/05/2026, 04:23:57 UTC Added: 08/05/2026, 04:26:03 UTC |
The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2 0 An exposed open directory at a staging server revealed an active intrusion by operators linked to The Gentlemen ransomware group. The operation involved establishing persistent access through privileged account creation, credential theft via LSASS dumping, and lateral movement across a Windows domain. Attackers deployed multiple implants including EtherRAT, which retrieves command-and-control domains from an Ethereum smart contract, alongside Sliver and custom Go reverse shells. Lateral movement was achieved through remote scheduled tasks distributing MSI payloads, while security products were disabled and reverse tunnels established for persistent access. The infrastructure and tactics align with previously documented The Gentlemen campaigns, including a ClickFix operation deploying EtherRAT. Join the discussion | Reddit NetSec | 08/05/2026, 08:26:37 UTC Added: 08/04/2026, 18:26:01 UTC |
Researchers altered a forensic DNA evidence file in 45 minutes and the analysis software raised no warning (CVE-2026-17583)CVE-2026-17583 0 CVE-2026-17583 is a vulnerability affecting Thermo Fisher's Applied Biosystems human identification instruments. The .fsa and .hid forensic DNA evidence files can be altered between the instrument writing them and the analysis software loading them without detection. Researchers demonstrated that they could modify these files in about 45 minutes, merging DNA profiles into a single file that appeared unaltered since 2015. Thermo Fisher issued a bulletin adding digital signatures to files written after the update, but no retroactive validation exists for older files, and some end-of-life products receive no updates. This leaves historical forensic DNA evidence files vulnerable to undetectable tampering. Join the discussion | Reddit Cybersecurity | 08/05/2026, 20:23:32 UTC Added: 08/04/2026, 16:56:02 UTC |
Tool: inspect chrome/ff extensions without having to download or install them 0 This is a tool that allows users to inspect Chrome, Firefox, and Edge browser extensions without downloading or installing them. It provides features such as code beautification, searching across files, and sharing URLs to specific extension files. The tool is intended for reviewing browser extensions safely and conveniently. Join the discussion | Reddit Cybersecurity | 08/04/2026, 13:39:16 UTC Added: 08/04/2026, 14:11:03 UTC |
Exploiting Zero Touch Provisioning (ZTP) 0 Research has disclosed 15 new vulnerabilities in TP-Link's Omada ecosystem related to Zero Touch Provisioning (ZTP), with some affecting other TP-Link product lines. These vulnerabilities enable exploitation at a fleet scale rather than individual devices. TP-Link has fixed these vulnerabilities. The research will be presented at Black Hat and DEF CON conferences. Join the discussion | Reddit Cybersecurity | 08/04/2026, 13:14:57 UTC Added: 08/04/2026, 14:11:03 UTC |
Showing 1 to 10 of 193 results