Threats Tagged 'exposed'
View all threats tagged with 'exposed'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'exposed'
Click on any threat for detailed analysis and mitigation recommendations
A critical remote code execution (RCE) vulnerability chain has been demonstrated affecting OpenBao and HashiCorp Vault. OpenBao has released patches in versions 2.6.3 and 2.7.0 to fully mitigate the issue. However, HashiCorp Vault remains exposed due to a lack of coordinated disclosure and official mitigation. The exploit requires only unauthenticated access and a specific Raft snapshot policy to achieve full server compromise. This is the second RCE ever found in Vault's codebase and is considered highly plausible in real-world environments. Join the discussion | Reddit NetSec | 09/29/2026, 21:43:15 UTC Added: 09/29/2026, 22:06:12 UTC |
A Redis cryptomining botnet compromised 3,562 Redis servers by exploiting unsecured no-auth configurations. The botnet operator's own files were exposed in an open directory, revealing the full toolkit and detailed campaign logs. The attack leveraged rogue replication commands to deploy a cron job that runs the XMRig miner, targeting Monero mining pools. The issue is due to missing authentication and insecure default configurations, not a software vulnerability. The affected Redis versions range from 2.8.17 to 7.2.0. Mitigation involves configuring Redis securely by enabling authentication and disabling replication features if unused. Join the discussion | Reddit NetSec | 09/08/2026, 17:53:35 UTC Added: 09/08/2026, 18:37:03 UTC |
A recent scan identified over 4,000 Rockwell Automation and Allen-Bradley industrial controllers used in U.S. water and wastewater systems exposed directly to the internet. Despite federal warnings, many of these devices remain accessible, including 22 in cities recently targeted by cyberattacks. The exposed devices use the EtherNet/IP protocol, which can allow remote identification and potential configuration changes if improperly secured. Some devices appear vulnerable to a known remote code execution flaw disclosed in 2017 (CVE-2017-16740). The FBI and EPA have confirmed cyberattacks on water utilities in multiple states, with some attacks causing operational disruptions such as pressure loss and flooding. The exposure is attributed to mass scanning and opportunistic exploitation rather than targeted zero-day attacks. Manufacturers and federal agencies have long advised against placing such controllers on the public internet. Join the discussion | Reddit Cybersecurity | 08/06/2026, 19:14:00 UTC Added: 08/06/2026, 19:26:02 UTC |
The AI meeting assistant tl;dv exposed 181,874 meetings due to a misconfigured Firestore database. This exposure included live calls that unauthorized users could join. The vulnerability was disclosed by a researcher in January but remains unpatched six months later. Join the discussion | Reddit Cybersecurity | 08/05/2026, 20:21:00 UTC Added: 08/05/2026, 20:41:04 UTC |
A massive data leak exposed approximately 24 billion stolen credentials collected from various sources including infostealer logs, Telegram cybercrime channels, and breach compilations. The data included usernames, email addresses, plaintext passwords, and associated service URLs. The leak was discovered in an exposed Elasticsearch cluster containing over 8.3 terabytes of data. The database was taken offline shortly after discovery, limiting further investigation. The exposed credentials put billions of accounts at risk of takeover, especially those without multi-factor authentication enabled. The data owner appeared to actively update the collection with recent breach information. No specific software versions are affected as this is a data breach event rather than a software vulnerability. Join the discussion | Reddit Cybersecurity | 06/19/2026, 07:35:14 UTC Added: 06/19/2026, 08:19:57 UTC |
A report reveals that over 2,000 AI-built applications created on vibe-coding platforms are publicly exposed on the internet without adequate access controls, often granting admin access by default. These applications connect directly to corporate production systems and contain sensitive corporate, operational, or personal data. The exposure results from employees building and deploying these apps without IT or security oversight, exploiting gaps in traditional security tools that do not monitor session-layer activities or custom AI-built applications. This risk surface spans multiple industries and continents and persists despite mature security stacks. The issue is not due to malicious intent but rather the lack of governance and visibility over these new AI-driven development workflows. Join the discussion | Reddit Cybersecurity | 05/29/2026, 12:28:35 UTC Added: 05/29/2026, 12:33:21 UTC |
Netmirror, a free movie application, was exposed in a security-related incident reported via a Reddit Malware subreddit post. The exposure involves the app reportedly 'robbing' users, implying malicious behavior or data compromise. There is no detailed technical information or evidence of active exploitation in the wild. No affected versions or patch information is provided, and the source is primarily a Reddit post linking to an external Medium article. The severity is assessed as medium based on the reported impact and lack of confirmed exploits. Join the discussion | Reddit Malware | 05/18/2026, 07:53:25 UTC Added: 05/19/2026, 17:48:38 UTC |
A critical security threat has emerged involving over 10,000 Fortinet firewalls that are vulnerable to an actively exploited two-factor authentication (2FA) bypass. This vulnerability allows attackers to circumvent the additional security layer provided by 2FA, potentially gaining unauthorized access to firewall management interfaces. The exploitation of this flaw can lead to severe consequences including network compromise, data breaches, and disruption of services. European organizations using Fortinet firewalls are at significant risk, especially those in sectors with high reliance on secure perimeter defenses. The threat is rated high severity due to the potential impact on confidentiality, integrity, and availability, combined with the ease of exploitation without requiring user interaction. Immediate mitigation steps include applying vendor patches once available, restricting administrative access via VPN or IP whitelisting, and enhancing network monitoring for suspicious activities. Countries with high Fortinet market penetration and critical infrastructure sectors, such as Germany, France, the UK, and the Netherlands, are likely to be most affected. Defenders must prioritize this threat to prevent widespread compromise and maintain network security. Join the discussion | Reddit InfoSec News | 01/02/2026, 19:01:45 UTC Added: 01/02/2026, 19:13:43 UTC |
The DarkSpectre browser extension campaigns have compromised approximately 8.8 million users worldwide by distributing malicious browser extensions. These campaigns involve extensions that likely perform unauthorized data collection, user tracking, or other malicious activities, impacting user privacy and security. Although no specific affected versions or exploits in the wild are detailed, the scale of impact and exposure indicates a high-severity threat. European organizations using popular browsers susceptible to these extensions are at risk of data leakage and potential downstream attacks. The threat does not require user authentication but likely depends on user installation of malicious extensions, making user awareness critical. Mitigation involves proactive monitoring of browser extensions, enforcing strict extension policies, and educating users about risks. Countries with high browser usage and significant digital economies, such as Germany, France, and the UK, are most likely to be affected. Given the broad impact on confidentiality and potential integrity of user data, ease of exploitation through extension installation, and large affected user base, this threat is assessed as high severity. Defenders should prioritize detection and removal of these extensions and strengthen endpoint security controls. Join the discussion | Reddit InfoSec News | 12/31/2025, 17:12:55 UTC Added: 12/31/2025, 17:13:50 UTC |
The MongoBleed vulnerability is a high-severity flaw that leads to leakage of MongoDB secrets, exposing approximately 87,000 servers worldwide. This breach allows attackers to extract sensitive database credentials and potentially access confidential data. Although no known exploits are currently active in the wild, the scale of exposed servers and the nature of leaked secrets pose a significant risk. European organizations using MongoDB without adequate protections are vulnerable to unauthorized data access and potential data breaches. The threat primarily impacts confidentiality and integrity of data, with possible availability issues if attackers manipulate or delete data. Mitigation requires immediate auditing of MongoDB deployments, securing credentials, and applying any available patches or configuration changes to prevent unauthorized access. Countries with high MongoDB adoption and critical infrastructure relying on these databases are at greater risk. Given the ease of exploitation without authentication and the broad exposure, the severity is assessed as high. Defenders should prioritize monitoring for unusual database access patterns and enforce strict access controls to mitigate this threat. Join the discussion | Reddit InfoSec News | 12/28/2025, 22:19:13 UTC Added: 12/30/2025, 22:18:54 UTC |
Showing 1 to 10 of 54 results