Threats Tagged 'netsec'
View all threats tagged with 'netsec'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'netsec'
Click on any threat for detailed analysis and mitigation recommendations
Volume Booster (2M Chrome users) silently activated a commerce-tracking SDK with zero permission prompts 0 The Volume Booster Chrome extension, with approximately 2 million weekly users, silently activated a commerce-tracking SDK (Give Freely) between versions 1.0.2 and 1.0.4 without triggering Chrome's permission re-consent prompt. The extension had previously been granted broad host permissions that were dormant until the SDK was activated. This SDK collects device identifiers, geolocation data, and telemetry continuously, regardless of user interaction with the extension's visible UI. The Chrome Web Store listing's privacy declaration does not disclose these data flows, creating a discrepancy between declared and actual behavior. Join the discussion | Reddit NetSec | 06/21/2026, 20:58:27 UTC Added: 06/21/2026, 23:09:03 UTC |
Worth a MalExt Report? A 2 Million-User Chrome Extension Added Give Freely/Wildlink in a 5-Day Update 0 A popular Chrome extension with over 2 million users introduced a new component related to Give Freely/Wildlink in a rapid update cycle. This addition enables merchant detection, affiliate attribution, and donation campaigns without requesting new permissions, meaning users received the update automatically. The Give Freely/Wildlink infrastructure appears in multiple unrelated extensions, suggesting it is a white-label monetization or fundraising SDK. There is no evidence of malware, credential theft, or overtly malicious behavior at this time. The main concern is potential transparency and privacy implications due to expanded functionality without explicit user consent. Join the discussion | Reddit NetSec | 06/17/2026, 20:10:41 UTC Added: 06/17/2026, 20:49:54 UTC |
Hackers for Granny: A Call to Arms Against Industrialized Fraud 0 This report highlights organized fraud syndicates operating from Myanmar, Cambodia, and Laos that target elderly victims by exploiting loneliness and cognitive decline. The criminals use legitimate remote access tools, real-time deepfakes, voice cloning, and psychological manipulation to perpetrate their schemes. The source maps the attack kill chain and proposes a defensive tool called Granny Kate to help protect elderly users. The call to action invites security researchers and developers to contribute to improving this defense. No specific software vulnerability or exploit details are provided. Join the discussion | Reddit NetSec | 06/16/2026, 14:33:40 UTC Added: 06/16/2026, 14:45:03 UTC |
Researcher accidentally gained access to a threat actor-controlled phishing website 0 A security researcher accidentally gained access to a phishing website controlled by a threat actor. The incident revealed operational mistakes by the threat actor, including exposure of backend panels and infrastructure details. This access provides valuable insight into phishing infrastructure and potential pivot points for threat intelligence investigations. The event was shared on Reddit's r/netsec community with a link to a detailed write-up. No specific software versions or patches are involved. The severity is assessed as medium based on the nature of the exposure and potential intelligence value. Join the discussion | Reddit NetSec | 06/14/2026, 06:50:30 UTC Added: 06/14/2026, 06:54:15 UTC |
PromptSnatcher: AdBlocker stealing Ai Chats - 90k installs 0 PromptSnatcher is a malicious data collection operation involving two Chrome browser extensions masquerading as ad blockers with approximately 90,000 combined installs. These extensions intercept full conversation histories, model usage, and subscription tier information from eight major AI platforms, including ChatGPT, Claude, Gemini, and others. The exfiltrated data is sent to operator-controlled servers without clear user notification beyond a vague "Enhanced Protection" consent. The extensions dynamically update their parsing logic from remote command-and-control servers, enabling ongoing targeting without extension updates. Firefox variants falsely declare no data collection permissions while performing equivalent data interception. The operation uses distinct infrastructure for each extension and employs sophisticated API hooking to capture and transmit sensitive AI chat data. Join the discussion | Reddit NetSec | 06/13/2026, 22:11:13 UTC Added: 06/13/2026, 22:39:16 UTC |
Pre-auth XXE → HTTP SSRF on ArubaOS 8.13.2 closed as "theoretical / no valid PoC" despite TCP pcap, sshd localhost log, and internal port scan — documenting for community review 0 A pre-authentication XML External Entity (XXE) vulnerability leading to HTTP Server-Side Request Forgery (SSRF) was reported on ArubaOS 8.13.2, specifically on port 32000's default XML API which requires no authentication. The report includes evidence such as TCP packet captures, SSH localhost logs, and internal port scans via SSRF. Despite this evidence, the issue was closed by the vendor as theoretical with no valid proof of concept. The vulnerability details and proof of concept are publicly documented on GitHub for community review. Join the discussion | Reddit NetSec | 06/10/2026, 18:54:54 UTC Added: 06/10/2026, 19:00:48 UTC |
GhostTrace – a Windows forensic scanner that finds what "Uninstall" leaves behind (22 modules, read-only, offline) 0 GhostTrace is a Windows forensic scanner tool designed to detect remnants left behind after software uninstallation. It operates offline and read-only, scanning 22 forensic modules including registry keys, prefetch entries, scheduled tasks, WMI subscriptions, and more. The tool aims to provide forensic evidence of persistence, execution, user activity, and installed software traces without modifying the system or generating network traffic. It is intended for investigative use rather than automatic threat verdicts. Join the discussion | Reddit NetSec | 06/10/2026, 06:53:29 UTC Added: 06/10/2026, 06:55:33 UTC |
X.com silently injects session-bound tracking tokens into your clipboard on every copy — security tools correctly flag this as malicious injection 0 X.com injects session-bound tracking tokens into the clipboard content whenever a user copies text or links from the site. This injection includes appending tracking parameters to URLs and embedding hidden HTML elements with encoded tracking data. Security tools flag this behavior as malicious injection due to the clipboard manipulation resembling techniques used by malware. There is no opt-out or disclosure from X.com, and the bug bounty program has been dissolved. Join the discussion | Reddit NetSec | 06/09/2026, 13:19:28 UTC Added: 06/09/2026, 13:25:33 UTC |
I found 23 Chrome extensions hijacking 758,000 users' searches for affiliate revenue 0 SearchJack is a campaign involving 23 deceptive Chrome extensions that hijack users' default search engines, silently routing approximately 758,000 users' search queries through operator-controlled affiliate monetization networks. These extensions present various advertised functionalities but primarily serve to generate affiliate revenue without user consent. The campaign involves at least 8 distinct monetization brokers and 22 publishers, many of which anonymize their identities. The extensions often use manifest-only wrappers or runtime obfuscation to evade detection. This activity constitutes a significant privacy violation and poses a security risk as operators could inject malicious content into search results without updating the extension code. Join the discussion | Reddit NetSec | 06/09/2026, 09:50:47 UTC Added: 06/09/2026, 09:55:32 UTC |
Four coordinated npm supply chain campaigns active in May–June 2026 — TTPs, IOCs, and detection notes 0 Four coordinated npm supply chain campaigns were active during May and June 2026, targeting the npm ecosystem with various sophisticated techniques including dependency confusion, namespace compromise, scope confusion, and typosquatting. These campaigns employ multi-stage postinstall execution chains that fetch and run platform-specific payloads, aiming to steal environment variables, CI/CD secrets, cloud metadata service tokens, and other sensitive credentials. The campaigns affect multiple platforms (Windows, macOS, Linux) and cloud environments (GCP, Azure). Detection relies on identifying version sentinels, cloud metadata endpoint access patterns, and characteristic postinstall behaviors. An open-source scanner with detection capabilities for these campaigns is available for community use. Join the discussion | Reddit NetSec | 06/02/2026, 19:08:29 UTC Added: 06/02/2026, 19:18:25 UTC |
Showing 1 to 10 of 10 results