Skip to main content

Threats Tagged 'reddit'

View all threats tagged with 'reddit'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: reddit

Threats Tagged 'reddit'

Click on any threat for detailed analysis and mitigation recommendations

This is an academic research survey seeking input from U.S.-based IT and security professionals at small and medium-sized enterprises (SMEs) that have experienced ransomware attacks between 2021 and 2025. The research aims to empirically study which security controls effectively enable recovery and resilience after ransomware incidents at the SME scale. The survey is IRB-approved and anonymous, with no compensation offered.

Join the discussion

This report discusses a technique for arbitrary function execution in the Windows kernel context that bypasses Hypervisor-protected Code Integrity (HVCI) and Control-flow Enforcement Technology (CET), assuming the attacker has read and write primitives. The information is sourced from a Medium article shared on Reddit. No specific affected Windows versions or vendor advisories are provided. There is no indication of active exploitation in the wild or available patches.

Join the discussion

CVE-2026-84388 is a vulnerability in the FortiPAM Chrome extension used for Privileged Access Management. It allows any website to control the browser's proxy settings for the session and to open new tabs that can be screen recorded and sent to an attacker's server. This enables trivial phishing attacks by capturing sensitive user activity in attacker-controlled tabs. The vulnerability has a high impact due to the ability to monitor user activity and manipulate proxy settings without user consent.

Join the discussion

Picus Labs analyzed 338 million attack simulations in production environments, finding that perimeter defenses block 69% of attacks, while post-compromise blocking effectiveness drops to 37%. The research highlights challenges in detecting quiet discovery and collection actions, with only 10% blocked, and low alerting rates despite high logging. Different attack tools show varying detection rates depending on the method used. This data provides insights into the effectiveness of perimeter and post-compromise defenses and detection engineering.

Join the discussion

CVE-2026-25262 is a write-what-where vulnerability in the Qualcomm Sahara protocol confirmed experimentally on the Snapdragon 8 Gen 1 (SM8450) platform. The vulnerability allows arbitrary writes to SRAM during the Sahara handshake, bypassing signature verification and partially bypassing Firehose loader authorization. While the loader executes and responds to commands without authorization errors, full UFS storage access has not yet been achieved. The vulnerability was previously known to affect only legacy 32-bit Qualcomm platforms, but this research extends its applicability to modern 64-bit ARMv9 SoCs. Further investigation is ongoing to achieve full Firehose initialization and understand TrustZone dependencies. No official patch or remediation guidance is currently available.

Join the discussion

AI Governance Engineer is an open, versioned body of knowledge that maps AI governance frameworks such as the EU AI Act, ISO 42001, and NIST AI RMF to concrete artefacts satisfying each obligation. It provides a structured approach to AI governance engineering, emphasizing continuous, machine-readable evidence over point-in-time attestations. The resource includes chapters, a maturity model, reusable patterns, and data exports to support implementation and auditability of AI governance obligations.

Join the discussion
0

A potential compromise of the OWASP API Security website (https://api-security.owasp.org/) has been reported via a Reddit post. The page currently displays a responsible disclosure notice from NOX Offensive Security indicating a vulnerability affecting the organization and requesting secure contact for further details. No sensitive technical details or exploit information are publicly disclosed at this time.

Join the discussion

The ShinyHunters extortion group hacked and defaced the Clop (Cl0p) ransomware operation's data leak site by exploiting an unauthenticated file upload vulnerability in Grav CMS. They replaced the site content with their own messages and ASCII art, claiming to have stolen server data including source code, Grav CMS plugins, system logs, and private keys for Clop's Tor onion service. ShinyHunters threatened to extort Clop, demanding payment within 72 hours. This attack appears to be part of an ongoing feud between the two cybercrime groups, with ShinyHunters retaliating against threats made by Clop representatives. The incident raises questions about a potential shift in ransomware group dynamics toward direct attacks on rival groups. No independent verification of the full extent of data theft has been confirmed.

Join the discussion

A file collision bug in the PcapSplitter library causes silent packet loss when TCP sessions reuse the same 5-tuple, resulting in file truncation or corruption. This occurs because the filename generation is based only on IP and port, causing multiple sessions to overwrite the same output file. The issue was identified during PCAP processing and fixed by suffixing filenames only on actual collisions. The bug led to fewer packets being written than reported, with no error exit codes, making detection difficult.

Join the discussion

A security researcher named Gal Weizman disclosed a browser security research achievement involving a single browser extension that successfully exploited vulnerabilities in Chrome, Comet, Edge, Opera, and Claude in Chrome. This research led to the discovery of two CVEs and earned $20,000 in bounty rewards from multiple major vendors including Anthropic, Perplexity, Google, Microsoft, and Opera. No detailed technical information or affected versions are provided.

Join the discussion

Showing 1 to 10 of 3091 results

Filters:Tag: reddit
Page 1 of 310
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses