Threats Tagged 'netsec'
View all threats tagged with 'netsec'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'netsec'
Click on any threat for detailed analysis and mitigation recommendations
The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2 0 An exposed open directory at a staging server revealed an active intrusion by operators linked to The Gentlemen ransomware group. The operation involved establishing persistent access through privileged account creation, credential theft via LSASS dumping, and lateral movement across a Windows domain. Attackers deployed multiple implants including EtherRAT, which retrieves command-and-control domains from an Ethereum smart contract, alongside Sliver and custom Go reverse shells. Lateral movement was achieved through remote scheduled tasks distributing MSI payloads, while security products were disabled and reverse tunnels established for persistent access. The infrastructure and tactics align with previously documented The Gentlemen campaigns, including a ClickFix operation deploying EtherRAT. Join the discussion | Reddit NetSec | 08/05/2026, 08:26:37 UTC Added: 08/04/2026, 18:26:01 UTC |
Xpsd: decide if a CVE is actually reachable in your tree (SARIF / GitHub code scanning) 0 Xpsd is an open-source tool designed to analyze whether reported CVEs or vulnerability scan findings are actually reachable in a given source code tree. It integrates with GitHub code scanning and uses an LLM-driven approach combined with structural code navigation and advisory lookups to provide verdicts on vulnerability reachability. The tool helps developers prioritize which vulnerabilities pose real risks in their codebase by providing evidence, call paths, and SARIF reports. It supports multiple vulnerability report formats and can be integrated into CI workflows. There is no indication that Xpsd itself is a vulnerability or threat. Join the discussion | Reddit NetSec | 08/03/2026, 19:04:38 UTC Added: 08/03/2026, 20:02:49 UTC |
How We Hacked Thousands of Data Centers in Minutes Using a 20-Year-Old Vulnerability 0 How We Hacked Thousands of Data Centers in Minutes Using a 20-Year-Old Vulnerability Source: https://lavahq.io/bmcradar Join the discussion | Reddit NetSec | 07/28/2026, 13:31:09 UTC Added: 07/28/2026, 13:36:56 UTC |
The state of vibe-coded app security: my analysis of 549 self-described AI-generated repos (study + raw data) 0 The state of vibe-coded app security: my analysis of 549 self-described AI-generated repos (study + raw data) Source: https://ogbuilds.ai/studies/vibe-coded-security Join the discussion | Reddit NetSec | 07/28/2026, 11:11:19 UTC Added: 07/28/2026, 12:06:55 UTC |
BrainDrain: A Chrome extension that collects your AI prompts without you ever opening it and has 100k users, 9 AI platforms 0 BrainDrain: A Chrome extension that collects your AI prompts without you ever opening it and has 100k users, 9 AI platforms Source: https://chromewebstore.google.com/detail/prompt-optimizer-secondbr/aajjgdpofhhcjmjoombjdfepplndhgcp Join the discussion | Reddit NetSec | 07/27/2026, 16:29:21 UTC Added: 07/27/2026, 17:36:59 UTC |
A featured Chrome extension "Planet Search" (2M installs) routes every query to the nextgeeker[.]com hijacker network 0 The Chrome extension "Planet Search" with approximately 2 million installs is a search hijacker that routes all user queries through a chain of undisclosed redirects ending at nextgeeker.com, a domain flagged by multiple vendors as a browser hijacker. The extension declares itself as a default search provider but does not disclose the intermediate redirects or the affiliate monetization relationship. The extension's code is minimal and does not reveal this behavior, as the redirect logic is entirely server-side. Users receive standard Google Custom Search results, but their queries transit through third-party domains that may observe search data. The extension is published by FREE VPN PLANET SRL, which also offers other extensions under investigation. The threat was reported to the Chrome Web Store and Google Safe Browsing on 2026-07-25. Join the discussion | Reddit NetSec | 07/25/2026, 10:23:37 UTC Added: 07/25/2026, 10:51:56 UTC |
I ran a paid bug-bounty-style game against my own multimodal prompt firewall, it didn't make money, so here's the code, the model and 13k real bypass attempts 0 This report describes a paid bug-bounty-style game conducted against a multimodal prompt firewall designed to detect prompt injection and jailbreak attempts targeting large language models (LLMs). The project includes open-source code, a fine-tuned DeBERTa-v3-large binary classifier model, and a dataset of 13,230 real-world attack attempts collected over a year. The detector uses a two-stage approach combining regex pattern matching and machine learning inference to filter malicious inputs across multiple modalities including text, images, documents, and audio. The dataset and tooling are intended as a mitigation layer rather than a complete solution, and the author encourages further testing and improvement. No direct vulnerability or exploit is reported, and no patch or fix is applicable as this is a defensive research artifact. Join the discussion | Reddit NetSec | 07/22/2026, 18:11:03 UTC Added: 07/22/2026, 18:21:57 UTC |
New Exploitable BOLA Found in Immich (self-hosted media platform) 0 A Broken Access Control vulnerability was discovered in Immich, a self-hosted media platform. The flaw allows any user to access photos stored in a locked folder without entering the required PIN. This occurs because one of the search endpoints (POST /search/random) does not enforce the PIN protection, exposing locked assets of the caller and their partners. Immich uses a PIN-elevated session to protect sensitive media, but this endpoint bypasses that control. Join the discussion | Reddit NetSec | 07/16/2026, 17:28:27 UTC Added: 07/16/2026, 17:47:26 UTC |
AI Agent for reconaissasion 0 This report describes an AI-powered reconnaissance agent tool recently shared on a public forum. The tool is presented as a minimum viable product (MVP) for conducting reconnaissance on specified targets in a controlled lab environment. There is no indication of a vulnerability or exploit associated with the tool itself. No affected software versions or patch information are provided. The tool appears to be a new offering for security professionals to experiment with automated reconnaissance capabilities. Join the discussion | Reddit NetSec | 07/16/2026, 07:25:29 UTC Added: 07/16/2026, 07:32:22 UTC |
ExporTheft: 11 "AI Chat Exporter" Chrome extensions upload full chat content on PDF export, while the store listing says "No uploads to external servers" 0 A family of 11 Chrome extensions named "AI Chat Exporter" falsely claim in their store listings that no chat data is uploaded to external servers and that all processing is local. However, during PDF export, these extensions send the full chat content to a developer-controlled cloud backend. Other export formats leak partial chat data via usage beacons. The extensions also track users across devices using a persistent client ID stored in Chrome sync storage. Approximately 5,500 users are affected on the main extension. This behavior contradicts the stated privacy claims and exposes sensitive chat content to unauthorized external servers. Join the discussion | Reddit NetSec | 07/13/2026, 23:18:54 UTC Added: 07/14/2026, 00:17:26 UTC |
Showing 1 to 10 of 11 results