Threats Tagged 'pdf'
View all threats tagged with 'pdf'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'pdf'
Click on any threat for detailed analysis and mitigation recommendations
A sophisticated phishing campaign has been detected that utilizes a multi-stage approach to evade detection. The attack begins with a procurement-themed email containing a PDF attachment. This PDF redirects victims to another PDF hosted on trusted cloud storage, which then leads to a fake Dropbox login page. The attackers exploit trusted platforms and harmless file formats to bypass security measures. The campaign uses social engineering tactics to harvest credentials, which are then exfiltrated to attacker-controlled infrastructure via Telegram. This method proves effective by leveraging legitimate business processes, trusted file types, and reputable cloud services to appear authentic and bypass automated security checks. Join the discussion | AlienVault OTX General | 02/02/2026, 18:31:08 UTC Added: 02/02/2026, 20:15:08 UTC |
Recent research by ActiveFence evaluated seven major large language models (LLMs) for vulnerabilities related to hate speech, disinformation, fraud, and child safety. The study found that 44% of LLM outputs were risky, with 68% of unsafe outputs related to hate speech, indicating significant weaknesses in content moderation and abuse prevention. Fraud-related outputs were comparatively better managed, but hate speech and child safety remain critical gaps. No tested model was fully safe, highlighting systemic risks in current LLM deployments. This threat is not a traditional software vulnerability but an exploitation of AI model behavior that can propagate harmful content. European organizations using or deploying LLMs should be aware of these risks, especially in sectors sensitive to hate speech and child protection. Mitigation requires tailored content filtering, continuous red-teaming, and collaboration with specialized threat intelligence providers. Countries with high AI adoption and strict regulatory environments around hate speech and child safety are most likely to be affected. Given the broad impact on confidentiality, integrity of information, and potential societal harm, and the ease of exploitation via user prompts, this threat is assessed as high severity. Join the discussion | Reddit NetSec | 12/17/2025, 22:17:58 UTC Added: 12/17/2025, 22:30:35 UTC |
This threat involves stealthy BGP route hijacking attacks that exploit vulnerabilities in Unicast Reverse Path Forwarding (uRPF) filtering, a mechanism designed to prevent IP spoofing in volumetric DDoS attacks. Attackers can manipulate routing to redirect or intercept traffic without detection, bypassing uRPF protections. Although no known exploits are currently in the wild, the technique poses a medium severity risk due to its potential to disrupt network traffic and compromise confidentiality and availability. European organizations relying on BGP and uRPF for network security, especially ISPs and large enterprises, could be impacted. Mitigation requires advanced BGP security practices beyond standard uRPF, including route validation and monitoring. Countries with significant internet infrastructure and BGP deployment, such as Germany, the UK, France, and the Netherlands, are most likely to be affected. The threat is medium severity given the complexity of exploitation and the partial mitigation offered by uRPF. Defenders should prioritize enhanced BGP security controls and continuous network monitoring to detect anomalous routing behavior. Join the discussion | Reddit NetSec | 10/21/2025, 11:50:10 UTC Added: 10/21/2025, 12:05:33 UTC |
0 A Technical Analysis on How a Chinese Company is Exporting The Great Firewall to Autocratic Regimes Source: https://interseclab.org/wp-content/uploads/2025/09/The-Internet-Coup_September2025.pdf Join the discussion | Reddit NetSec | 09/09/2025, 19:40:28 UTC Added: 09/09/2025, 19:40:56 UTC |
A targeted campaign has been observed since November 2024, primarily affecting organizations in France and Luxembourg. The attackers use socially engineered emails to deliver PDF documents containing embedded links to Remote Monitoring and Management (RMM) tool installers. This method bypasses many email and malware defenses. The PDFs are tailored to the victim's industry and often disguised as invoices, contracts, or property listings. The activity focuses on high-value sectors such as energy, government, banking, and construction. Various RMM tools are used, including FleetDeck, Atera, and Bluetrait. The attackers leverage direct download links and tools that require minimal setup, streamlining the infection process. This approach allows threat actors to gain initial access, disable security features, and potentially deploy subsequent malware using trusted tools. Join the discussion | AlienVault OTX General | 08/07/2025, 15:19:43 UTC Added: 08/07/2025, 21:47:44 UTC |
APT36, a Pakistan-based cyber espionage group, is actively targeting Indian defense personnel through sophisticated phishing campaigns. The group disseminates emails with malicious PDF attachments resembling official government documents. When opened, these PDFs display a blurred background and a button mimicking the National Informatics Centre login interface. Clicking the button redirects users to a fraudulent URL and initiates the download of a ZIP archive containing a malicious executable disguised as a legitimate application. This campaign highlights APT36's focus on credential theft and long-term infiltration of Indian defense networks, emphasizing the need for robust email security, user awareness programs, and proactive threat detection systems. Join the discussion | AlienVault OTX General | 06/21/2025, 14:51:24 UTC Added: 06/24/2025, 14:18:28 UTC |
This analysis examines cyber threats targeting government institutions worldwide, focusing on three case studies: a phishing email targeting the South Carolina Department of Employment and Workforce, a fraudulent domain mimicking the U.S. Social Security Administration, and a malicious PDF posing as a South African Judiciary notice. The study demonstrates how ANY.RUN's solutions, including Threat Intelligence Lookup, Interactive Sandbox, and YARA Search, can be utilized to detect, analyze, and mitigate these threats. Key findings include the use of FormBook stealer, remote access tools, and credential harvesting techniques. The analysis provides actionable insights for government cybersecurity teams to enhance their defensive strategies and response capabilities. Join the discussion | AlienVault OTX General | 06/04/2025, 19:24:18 UTC Added: 06/05/2025, 11:12:27 UTC |
Showing 1 to 7 of 7 results