Skip to main content

Threats Tagged 'netsec'

View all threats tagged with 'netsec'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: netsec

Threats Tagged 'netsec'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-84388 is a critical vulnerability in the FortiPAM Chrome extension used for Privileged Access Management. It allows any website visited by the user to control the browser's proxy settings for the session and to open new tabs that can be screen recorded and streamed to an attacker's server. This enables attackers to conduct phishing attacks by capturing sensitive user activity in attacker-controlled tabs without user consent.

Join the discussion

RCEKit is an open-source toolkit designed to detect and confirm remote code execution (RCE) vulnerabilities during authorized penetration testing and security research. It uses multiple methods to distinguish confirmed RCE from weaker signals or false positives by generating unique tokens and verifying their presence in target responses or out-of-band callbacks. The tool has been tested against real-world CVEs such as Webmin CVE-2019-15107, Apache Struts2 S2-001, and Log4Shell CVE-2021-44228, demonstrating its ability to confirm or classify RCE findings accurately. RCEKit does not report uncertain cases as confirmed, instead assigning them lower confidence tiers. It supports testing via URLs or captured HTTP requests and offers various probing methods, including reflected, eval, time-based, lookup, and deserialization injection techniques. The tool is intended for use only on authorized targets and requires careful configuration due to the high volume of requests it generates.

Join the discussion

A file collision bug in the PcapSplitter library causes silent packet loss when TCP sessions reuse the same 5-tuple, resulting in file truncation or corruption. This occurs because the filename generation is based only on IP and port, causing multiple sessions to overwrite the same output file. The issue was identified during PCAP processing and fixed by suffixing filenames only on actual collisions. The bug led to fewer packets being written than reported, with no error exit codes, making detection difficult.

Join the discussion

A security researcher named Gal Weizman disclosed a browser security research achievement involving a single browser extension that successfully exploited vulnerabilities in Chrome, Comet, Edge, Opera, and Claude in Chrome. This research led to the discovery of two CVEs and earned $20,000 in bounty rewards from multiple major vendors including Anthropic, Perplexity, Google, Microsoft, and Opera. No detailed technical information or affected versions are provided.

Join the discussion
0

This content is a Reddit post requesting participation in a survey for thesis work, containing a link to a Qualtrics survey form. There is no indication of a security threat, vulnerability, or malicious activity associated with this request.

Join the discussion

A Chinese-speaking threat actor group known as Red Heron exploited a recently disclosed remote code execution vulnerability (CVE-2026-60004) in Gitea, a self-hosted Git service, in a multinational campaign. The campaign targeted internet-facing Gitea instances across multiple countries, including Canada, Argentina, Taiwan, the United States, and Sri Lanka, focusing on sectors such as defense, elections, energy, aerospace, telecommunications, government, and research. The attackers used automated tools to steal source code, credentials, and maintain persistent access, including root-level control on some infrastructure. They deployed a novel Linux implant named JITTERLY with extensive post-exploitation capabilities and embedded a previously undocumented rootkit called SIXZUT to maintain stealth and persistence. The campaign demonstrates rapid weaponization of n-day vulnerabilities in development platforms and highlights significant risks to source code confidentiality and infrastructure integrity.

Join the discussion

EchelonGraphBot is a web crawler operated by EchelonGraph, Inc. that scans public websites to check configurations such as HTTPS enforcement, certificate expiration, TLS versions, security headers, cookie flags, and redirects. It visits a large number of third-party hosts approximately once per day, respecting robots.txt and rate limits. Operators can opt out via a DNS TXT record or robots.txt. The bot's activity is transparent and publicly documented, with no evidence of malicious intent or exploitation. The operator offers to adjust probing frequency upon request and honors opt-out requests.

Join the discussion

This report discusses a method to locate Flutter's TLS certificate verifier function within a stripped libflutter.so binary on ARM64 devices without relying on fragile byte signatures. Flutter bundles its own BoringSSL and does not use Android's network security config, requiring patching of the ssl_crypto_x509_session_verify_cert_chain function to modify trusted CAs. The function can be identified by cross-referencing unique strings and specific ARM64 prologue characteristics, enabling reliable patching across multiple Flutter engine versions. This technique was validated on apps using Flutter engine versions 2.19.2 through 3.11.1. The report also highlights a common pitfall in patching tools that fail to handle split APKs correctly. No active exploits or vendor patches are mentioned.

Join the discussion

A joint Tenable-SentinelOne analysis of 93 CVE-actor attribution pairs reveals that both state-sponsored actors and cybercriminals independently converge on the same edge infrastructure. Special thanks to SentinelOne® Incident Readiness & Response for their contributions to this publication. It is the shared attack surface where state-sponsored threat actors and financially motivated criminal groups independently converge — not the province of a single adversary category, and not exclusively a nation-state problem, despite two years of headlines about China-nexus actors targeting Ivanti, Fortinet, and Palo Alto Networks. The data here tells a different and much broader story. One focused on vendors vs CVEs. Key Takeaways Two independent observation systems, Tenable exposure telemetry across thousands of customer containers and SentinelOne DFIR casework across 66 CVEs, converge 79% on the same vendor attack surfaces despite minimal CVE-level overlap. Twelve CVEs in the combined dataset have confirmed multi-nexus attribution: state-sponsored and criminal actors independently exploiting the same vulnerability, across five nexus categories (China, Russia, DPRK, Iran, ransomware). The exposure picture is flatter than the headlines suggest: Fortinet, the vendor most associated with edge-device attacks in the press, sits mid-pack on container-grain exposure (25%) — well behind F5 (54%) and in a tight 10-point band with Check Point, Ivanti, and Citrix. 54% of customer environments running F5 products have at least one exposed, actively-exploited CVE; Citrix customers show the slowest remediation patterns at 461 days median time to patch. Remediation complexity, particularly of high priority CVEs, leads to a statistically significant 24-day remediation gap, leaving large windows of opportunity for attackers. The same product lines get hit again and again: Ivanti EPMM and Ivanti Connect Secure each show a newly exploited CVE roughly every 8.5 to 13 months. Leverage multiple defense-in-depth strategies: patch as quickly as possible, but also minimize the attack surface (feature-set minimization) and run endpoints in protect mode to better stop lateral movement from attacks that gain initial access. The convergence is the story Twelve CVEs in the combined dataset have confirmed multi-nexus attribution: state-sponsored and criminal actors independently exploiting the same vulnerability, across five nexus categories. Four examples illustrate the pattern: CVE Product Actors (Nexus) Significance CVE-2026-15409 SonicWall SMA1000 UTA0533 (unattributed) + INC Ransomware Espionage-to-ransomware succession on an active zero-day CVE-2023-42793 JetBrains TeamCity APT29 (Russia) + Lazarus (DPRK) Two state-sponsored actors from different nations on the same CVE CVE-2024-3400 PAN-OS GlobalProtect UTA0218 (China) + INC Ransomware China-nexus zero-day reused by ransomware operators CVE-2024-24919 Check Point Quantum PurpleHaze (China) + Fox Kitten (Iran) China and Iran independently exploiting the same gateway vulnerability The remaining eight confirmed multi-nexus CVEs span Fortinet, Citrix, Cisco, and Ivanti product lines. State-sponsored actors and ransomware operators are not operating in separate vulnerability ecosystems. They share the same entry points into the same products. The breadth of the convergence, not any single actor's activity, is the finding. That pattern holds across the full combined analysis. Three conclusions emerge: Vendor attack surfaces are the persistent exploitation target. The same eleven vendors (i.e., Fortinet, Citrix, Ivanti, Palo Alto Networks, Cisco, Juniper, VMware, Microsoft, Oracle, CrushFTP, and Meta's React framework ) appear in both observation systems at 79% convergence, and all seven edge-product vendors converge. Serial exploitation timing on Ivanti products shows the vulnerability-to-exploitation pipeline refreshing at 8.5 to 13-month intervals on the same product lines. This is structural, not episodic. Patch…

Join the discussion

A Redis cryptomining botnet compromised 3,562 Redis servers by exploiting unsecured no-auth configurations. The botnet operator's own files were exposed in an open directory, revealing the full toolkit and detailed campaign logs. The attack leveraged rogue replication commands to deploy a cron job that runs the XMRig miner, targeting Monero mining pools. The issue is due to missing authentication and insecure default configurations, not a software vulnerability. The affected Redis versions range from 2.8.17 to 7.2.0. Mitigation involves configuring Redis securely by enabling authentication and disabling replication features if unused.

Join the discussion

Showing 1 to 10 of 586 results

Filters:Tag: netsec
Page 1 of 59
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses