Threats Tagged 'ttps'
View all threats tagged with 'ttps'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'ttps'
Click on any threat for detailed analysis and mitigation recommendations
voidsyscall is a cross-platform implant and command-and-control (C2) framework that operates by issuing direct syscalls on Windows and raw syscalls on Linux, bypassing the Windows API layer entirely. It uses multiple stealthy injection techniques and evasion methods to avoid detection by endpoint detection and response (EDR) tools, including runtime resolution of syscall numbers, unhooking ntdll, and polymorphic code injection. The implant supports encrypted C2 communication over HTTPS, DNS, and ICMP channels using AES-256-GCM encryption. It includes advanced anti-analysis features such as VM, sandbox, and debugger detection, and performs token manipulation and memory encryption to hinder forensic analysis. No official patch or remediation is indicated, and this tool is presented as an offensive implant framework rather than a vulnerability. Join the discussion | Reddit Cybersecurity | 09/13/2026, 14:28:36 UTC Added: 09/13/2026, 14:46:27 UTC |
YCombinator's Paxel tool, which analyzes AI coding sessions, transmits sensitive user data including Cloudflare OAuth tokens, git email addresses, and verbatim user prompts sent to Claude's LLM proxy servers. This data transmission occurs even before the tool's Docker container starts and includes detailed behavioral reports with bash command histories. The tool strips file contents and LLM responses but sends user input prompts unaltered. This exposure was confirmed through live HTTPS interception and packet capture. The vendor has not provided a patch or official remediation guidance at this time. Join the discussion | Reddit BlueTeam | 06/17/2026, 04:51:13 UTC Added: 06/17/2026, 17:20:02 UTC |
Four coordinated npm supply chain campaigns were active during May and June 2026, targeting the npm ecosystem with various sophisticated techniques including dependency confusion, namespace compromise, scope confusion, and typosquatting. These campaigns employ multi-stage postinstall execution chains that fetch and run platform-specific payloads, aiming to steal environment variables, CI/CD secrets, cloud metadata service tokens, and other sensitive credentials. The campaigns affect multiple platforms (Windows, macOS, Linux) and cloud environments (GCP, Azure). Detection relies on identifying version sentinels, cloud metadata endpoint access patterns, and characteristic postinstall behaviors. An open-source scanner with detection capabilities for these campaigns is available for community use. Join the discussion | Reddit NetSec | 06/02/2026, 19:08:29 UTC Added: 06/02/2026, 19:18:25 UTC |
Multiple vulnerabilities have been discovered in GnuPG and other cryptographic tools, as presented at the 39th Chaos Communication Congress (39C3). These vulnerabilities affect the security of widely used cryptographic software that underpins secure communications and data integrity. Although no known exploits are currently active in the wild, the vulnerabilities pose a medium-level risk due to their potential to undermine confidentiality and integrity of encrypted data. The issues were publicly disclosed via a Reddit NetSec post and accompanied by detailed presentations and vulnerability listings on gpg.fail. European organizations relying on GnuPG and similar cryptographic tools for secure email, software signing, or encrypted communications should assess their exposure and apply mitigations promptly. The threat is particularly relevant for countries with high adoption of open-source cryptographic software and critical infrastructure sectors. Mitigation requires careful patch management once updates become available, alongside enhanced monitoring for suspicious cryptographic anomalies. Given the nature of the vulnerabilities, the suggested severity is medium, reflecting moderate impact and exploitation complexity without current active attacks. Join the discussion | Reddit NetSec | 12/29/2025, 18:28:50 UTC Added: 12/30/2025, 22:24:59 UTC |
A verified second-preimage collision has been demonstrated against the SHA-256 hashing algorithm by exploiting a structural vulnerability in the message schedule (W-schedule) of its compression function. This attack specifically targets the Bitcoin Genesis Block header, producing an alternative input that yields the same 256-bit hash output. Unlike previous theoretical attacks, this is a practical, bit-perfect collision verified by standard SHA-256 implementations. The discovery fundamentally undermines the collision resistance property of SHA-256 under certain internal state conditions, raising concerns about the integrity of systems relying on SHA-256 for cryptographic security. No known exploits are currently observed in the wild, and no patches or mitigations have been published yet. European organizations using SHA-256 in critical infrastructure, blockchain technologies, or digital signatures may face increased risk. Immediate mitigation involves transitioning to more secure hash functions and monitoring cryptographic dependencies. The threat is assessed as high severity due to the potential impact on confidentiality, integrity, and trustworthiness of digital assets without requiring user interaction or authentication. Join the discussion | Reddit NetSec | 12/27/2025, 02:03:01 UTC Added: 12/27/2025, 02:09:23 UTC |
A critical vulnerability has been discovered in the early boot process of modern UEFI systems from major vendors like ASUS and MSI, where the IOMMU (Input-Output Memory Management Unit) is reported as active but is not actually enforced during the DXE phase. This flaw creates a window during system startup where malicious peripherals can perform unrestricted DMA (Direct Memory Access) attacks, potentially leading to arbitrary code execution or system compromise. The vulnerability arises from a discrepancy between the firmware's reported DMA protection status and the actual enabling of IOMMU translation tables. No known exploits are currently in the wild, and BIOS patches have not yet been widely released. European organizations using affected hardware are at risk, especially those with high-value targets requiring strong hardware-level memory protection. Immediate mitigation involves monitoring vendor updates and restricting physical access to vulnerable systems until patches are available. Join the discussion | Reddit NetSec | 12/24/2025, 11:35:30 UTC Added: 12/24/2025, 11:43:07 UTC |
A novel cryptanalysis approach called the Kaoru Method proposes linearizing SHA-256's modular addition by modeling it as fractional modular arithmetic, enabling the reconstruction of a Universal Carry Map that removes modular barriers. This method simplifies differential cryptanalysis by making carry behavior predictable rather than noisy, potentially undermining SHA-256's assumed non-linearity. While no direct exploits or collisions have been demonstrated yet, this theoretical framework could pave the way for future attacks on SHA-256's compression function. The research is recent and experimental, with code and theory publicly released for validation. European organizations relying on SHA-256 for integrity, authentication, or digital signatures should monitor developments closely. Immediate practical exploitation is not confirmed, but the cryptographic assumptions underlying many security protocols could be challenged if this method matures. Mitigations include diversifying cryptographic algorithms, preparing for post-quantum or alternative hash adoption, and engaging with cryptographic research communities. Countries with strong tech sectors and critical infrastructure relying heavily on SHA-256, such as Germany, France, and the UK, are most likely to be affected. The threat severity is assessed as medium given the theoretical nature, no known exploits, and the foundational importance of SHA-256. Join the discussion | Reddit NetSec | 12/24/2025, 05:33:11 UTC Added: 12/24/2025, 05:42:13 UTC |
This information describes an update to a publicly available STIX feed used for sharing cyber threat intelligence indicators. The update improves the feed's structure by implementing proper STIX 2.1 object hierarchies, including IPv4Address SCOs with deterministic UUIDs and relationships linking indicators to malware families. This enhancement facilitates better integration and deduplication when used alongside multiple threat feeds, improving the accuracy and usability of threat intelligence platforms like OpenCTI. There is no direct security vulnerability or exploit described, and no known active exploitation in the wild. The update is a technical improvement to a threat intelligence feed rather than a new malware or attack vector. European organizations relying on threat intelligence feeds can benefit from more precise and interoperable data, but this does not represent a direct threat. The suggested severity is low since this is an intelligence feed improvement without direct impact on confidentiality, integrity, or availability. Join the discussion | Reddit NetSec | 12/22/2025, 19:20:00 UTC Added: 12/22/2025, 19:34:29 UTC |
A newly discovered Rust-based DDoS botnet exploits exposed Docker APIs on port 2375 to recruit compromised hosts. The malware uses asynchronous Rust libraries and obfuscation techniques to evade detection, with no antivirus engines initially detecting it. Its command-and-control (C2) protocol is weakly secured, lacking encryption and using predictable nonces and hardcoded credentials. The botnet infrastructure is centralized on a single server, which serves both malware distribution and C2 functions. The researcher developed a honeypot that impersonates infected bots to monitor ongoing DDoS targets in real time. This threat highlights the risks of exposed Docker APIs and the challenges traditional detection tools face with modern Rust-based malware. European organizations running Docker with exposed APIs are at risk of compromise and subsequent participation in DDoS attacks. Mitigation requires immediate restriction of Docker API exposure, network segmentation, and deployment of custom detection rules based on provided YARA and Snort signatures. Countries with high Docker adoption and significant internet infrastructure are most likely affected. The threat is assessed as medium severity due to moderate impact and exploitation complexity but notable evasion capabilities. Join the discussion | Reddit NetSec | 12/22/2025, 15:47:03 UTC Added: 12/22/2025, 15:58:25 UTC |
Vulnhalla is an open-source tool developed by CyberArk Labs to improve the triage of static analysis alerts generated by CodeQL by leveraging GPT-4o to reduce false positives. It addresses the common problem of overwhelming numbers of 'maybe' vulnerability alerts that hinder effective vulnerability management. By filtering out approximately 96% of false positives, Vulnhalla enabled researchers to identify confirmed CVEs in critical open-source projects such as the Linux Kernel, FFmpeg, Redis, Bullet3, and RetroArch within two days. This approach enhances the accuracy and efficiency of vulnerability detection, potentially accelerating patching and reducing exposure windows. Although Vulnhalla itself is not a vulnerability or exploit, its use reveals previously hidden vulnerabilities that could be exploited if left unpatched. European organizations relying on affected open-source components could face increased risk if these vulnerabilities are not promptly addressed. Mitigation involves integrating Vulnhalla or similar AI-assisted triage tools into existing static analysis workflows to improve vulnerability identification and prioritization. Countries with significant open-source development, large technology sectors, or critical infrastructure relying on Linux and related software are more likely to be impacted. Given the tool's role in uncovering vulnerabilities rather than being a direct threat, the suggested severity for this context is medium, reflecting the importance of improved detection but no direct exploitation vector from Vulnhalla itself. Join the discussion | Reddit NetSec | 12/21/2025, 10:47:14 UTC Added: 12/21/2025, 11:01:47 UTC |
Showing 1 to 10 of 69 results