Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'reddit'

View all threats tagged with 'reddit'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: reddit

Threats Tagged 'reddit'

Click on any threat for detailed analysis and mitigation recommendations

Developed a beginner-level firewall for LLMs
0

A beginner-level firewall for large language models (LLMs) has been developed as a project by college students. The firewall uses a two-tiered approach combining heuristic methods and a machine learning classifier to detect injection and jailbreak attempts before they reach the LLM. The implementation is based on llama-3.3 and may experience occasional delays in detection time. The project is shared publicly for feedback but does not represent a known vulnerability or active threat.

Join the discussion
State of CPS Security: Data Center Exposures
0

A report by Claroty Team82 analyzed over 750,000 data center cyber-physical system (CPS) assets and found significant exposure risks. Approximately 18% of data center infrastructure assets are one network hop away from systems making risky outbound internet connections. Critical systems such as power distribution units and HVAC/cooling systems have high exposure rates. Many building management systems communicate over insecure protocols and run outdated firmware. Legacy protocols like BACnet and Modbus are widely used in OT control and IoT systems. Additionally, 23% of IoT devices contain known exploited vulnerabilities. Attackers can leverage indirect pathways such as IT footholds, third-party remote access, and trusted network relationships to reach operational infrastructure assets.

Join the discussion
21 year old pleads guilty to hacking court database and multinational corporation
0

A 21-year-old individual pleaded guilty to hacking the Stark County Criminal Justice Information System (CJIS) and a multinational corporation in Connecticut. The intrusions occurred in 2023 and 2024, involving unauthorized access to sensitive personal and employee data. The attacker used custom programs and malware, employing proxy servers to conceal identity. He also destroyed digital evidence to obstruct the federal investigation. Sentencing is pending, with potential prison time estimated between 21 to 27 months due to mitigating factors.

Join the discussion
New WordPress Pre-Auth XSS (CVE-2026-64638) Could Lead to RCE: Have you patched your instances yet?CVE-2026-64638
0

CVE-2026-64638 is a high-severity pre-authentication reflected cross-site scripting (XSS) vulnerability in WordPress login pages that can lead to remote code execution (RCE) under specific conditions. The flaw allows attacker-controlled JavaScript to execute in the browser of a visitor after a failed login attempt. Exploitation requires a logged-in administrator to interact with an attacker-controlled page, potentially enabling PHP code execution on the server. The vulnerability affects default WordPress installations and was patched in WordPress 7.0.3 and backported to versions back through 4.7. Versions older than 4.7 remain vulnerable. WordPress recommends immediate updating, and automatic background updates should apply the patch automatically. No in-the-wild exploitation has been reported as of the advisory date.

Join the discussion
Despite federal warnings, thousands of U.S. industrial controllers used in water systems remain exposed online
0

A recent scan identified over 4,000 Rockwell Automation and Allen-Bradley industrial controllers used in U.S. water and wastewater systems exposed directly to the internet. Despite federal warnings, many of these devices remain accessible, including 22 in cities recently targeted by cyberattacks. The exposed devices use the EtherNet/IP protocol, which can allow remote identification and potential configuration changes if improperly secured. Some devices appear vulnerable to a known remote code execution flaw disclosed in 2017 (CVE-2017-16740). The FBI and EPA have confirmed cyberattacks on water utilities in multiple states, with some attacks causing operational disruptions such as pressure loss and flooding. The exposure is attributed to mass scanning and opportunistic exploitation rather than targeted zero-day attacks. Manufacturers and federal agencies have long advised against placing such controllers on the public internet.

Join the discussion
CISA's OSS Security Principles and Practices
0

The Cybersecurity and Infrastructure Security Agency (CISA) released a strategic framework titled 'OSS Security Principles and Practices' to guide federal agencies in managing open source software (OSS) securely throughout its lifecycle. The framework highlights OSS benefits such as transparency, cost efficiency, and flexibility, while addressing unique risks like decentralized development and supply chain vulnerabilities. It introduces the C4 Framework to assess OSS risk across codebase, community, conduct, and configuration. The guidelines mandate rigorous source code inventories, legal reviews, and encourage contributing security fixes upstream. Special considerations for AI systems require full access to training data and pipelines to ensure security. These principles aim to strengthen supply chain risk management and can be applied beyond federal agencies.

Join the discussion
tl;dv (AI meeting assistant) left 181,874 meetings exposed via misconfigured Firestore, including live calls you could join. Researcher disclosed in January, still unpatched 6 months later.
0

The AI meeting assistant tl;dv exposed 181,874 meetings due to a misconfigured Firestore database. This exposure included live calls that unauthorized users could join. The vulnerability was disclosed by a researcher in January but remains unpatched six months later.

Join the discussion
Hacked Accounts on Messenger
0

Reports have emerged on Reddit about accounts on the Messenger platform being hacked. The claim involves images sent in group chats that allegedly contain malicious content capable of compromising accounts when clicked. However, the information is based on a single Reddit post with minimal discussion and no technical details or vendor confirmation. No specific vulnerability, exploit, or patch information is provided.

Join the discussion
40%+ of AI-Generated Code Has Security Issues; We Open-Sourced a Way to Help
0

Research indicates that over 40% of AI-generated code contains security issues, often due to missing framework- and version-specific security details. To address this, an open-source project called AI Code Security Cards provides library-specific security guidance for developers and AI coding agents. The project covers more than 60 libraries and frameworks across multiple programming languages, offering practical instructions to mitigate common security pitfalls. This initiative aims to improve the security posture of AI-generated code by guiding coding agents on unsafe defaults, validation, authentication patterns, and security changes between library versions.

Join the discussion
Looking for cybersecurity people to provide honest feedback for an CISSP practice bank/platform I have built.
0

This content is a request for feedback on a CISSP practice exam platform created by an individual. It is a community engagement post seeking input on question quality and relevance, not a security threat or vulnerability.

Join the discussion

Showing 1 to 10 of 182 results

Filters:Tag: reddit
Page 1 of 19
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses