Skip to main content

Threats Tagged 'cybersecurity'

View all threats tagged with 'cybersecurity'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cybersecurity

Threats Tagged 'cybersecurity'

Click on any threat for detailed analysis and mitigation recommendations

A file collision bug in the PcapSplitter library causes silent packet loss when TCP sessions reuse the same 5-tuple, resulting in file truncation or corruption. This occurs because the filename generation is based only on IP and port, causing multiple sessions to overwrite the same output file. The issue was identified during PCAP processing and fixed by suffixing filenames only on actual collisions. The bug led to fewer packets being written than reported, with no error exit codes, making detection difficult.

Join the discussion

A security researcher named Gal Weizman disclosed a browser security research achievement involving a single browser extension that successfully exploited vulnerabilities in Chrome, Comet, Edge, Opera, and Claude in Chrome. This research led to the discovery of two CVEs and earned $20,000 in bounty rewards from multiple major vendors including Anthropic, Perplexity, Google, Microsoft, and Opera. No detailed technical information or affected versions are provided.

Join the discussion

Reports indicate that TikTok users' cameras have been hacked using an open weight AI model developed by a group named depthfirst. The claim is based on a news article discussing how free AI software is enhancing hacker capabilities. No technical details, affected versions, or confirmed exploits are provided in the available information.

Join the discussion
0

This content announces the soft reopening of the r/Darktrace subreddit community for discussions related to the Darktrace product and company. The subreddit was previously restricted and is now being moderated to allow more users while controlling spam and activity levels.

Join the discussion

This content compares four AI-based vulnerability scanners—Codex, Mythos, Aikido, and Audn—using the OWASP Juice Shop as a testbed. It is a discussion post on Reddit Cybersecurity sharing a link to an external artifact that evaluates these tools. No specific vulnerability or exploit is described.

Join the discussion

This content describes a research study survey targeting small-business information security professionals in the United States to assess their absorptive capacity in facing AI-driven threats. It is a call for participation in an academic study and does not describe a specific security vulnerability or threat.

Join the discussion
0

A suspicious URL (https://xysrx.com/PV.js) was found embedded below the closing HTML tag on the homepage of a website serving Clickfix. The JavaScript code fetched from this URL collects visitor environment data such as theme preference, timezone, screen resolution, and browser automation status, encodes this data, and conditionally injects additional HTML content triggered by user interactions like mouse clicks. This behavior suggests potential unauthorized content injection or tracking. No official vendor advisory or patch information is available.

Join the discussion

Brevo disclosed a supply-chain attack involving a compromised Cloudflare API key that was used to inject malicious scripts into over 100,000 websites using Brevo services. The attack highlights risks from trusted third-party infrastructure and embedded scripts, emphasizing the security challenges posed by API keys and SaaS dependencies. This incident underscores the need to evaluate trust boundaries with vendors integrated into applications.

Join the discussion

A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill Source: https://nvd.nist.gov/vuln/detail/CVE-2026-80844

Join the discussion

AI agents that rely on MCP (Model-Controller-Plugin) tool descriptions trust these descriptions similarly to how browsers trust TLS certificates. Attackers have begun exploiting this trust by poisoning tool metadata, which can lead to unauthorized actions such as secret exfiltration and silent email BCCs. This attack surface is not widely covered by existing security tools. The threat involves manipulating tool descriptions dynamically to alter agent behavior post-integration. The recommended defensive approach is to treat tool descriptions as untrusted input and implement measures such as pinning, hashing, and baseline comparisons to detect unauthorized changes.

Join the discussion

Showing 1 to 10 of 3099 results

Filters:Tag: cybersecurity
Page 1 of 310
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses