Threats Tagged 'web'
View all threats tagged with 'web'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'web'
Click on any threat for detailed analysis and mitigation recommendations
Online ad firm Adform’s script compromised to steal cryptocurrency 0 Online advertising firm Adform suffered a supply-chain attack that delivered cryptocurrency-stealing scripts to websites using its ad platform, replacing wallet addresses copied to visitors' clipboards with ones controlled by an attacker. [...] Join the discussion | Bleeping Computer | 07/31/2026, 21:09:25 UTC Added: 07/31/2026, 21:18:04 UTC |
CVE-2026-18394: CWE-863: Incorrect Authorization in AWS Strands Agents ToolsCVE-2026-18394 0 Incorrect authorization in the http_request tool in Strands Agents Tools before 0.8.2 might allow remote attackers to obtain credentials configured via HTTP_REQUEST_TOKEN_CONFIG by influencing the LLM to route requests through actor-controlled proxy infrastructure. To remediate this issue, users should upgrade to version 0.8.2. Join the discussion | CVE Database V5 | 07/31/2026, 19:34:15 UTC Added: 07/31/2026, 19:48:39 UTC |
Read This Before You Buy That TV Streaming Stick 0 Generic TV streaming devices, particularly the H96 brand, have been found to engage in fraudulent activities by spoofing themselves as mobile phones to click ads on AI-generated websites. These devices secretly rent out users' internet connections and participate in a large-scale ad fraud operation coordinated by apps linked to Zhejiang Fengwo IoT Technology Ltd, a company based in mainland China. The fraudulent network uses AI-generated content sites that only display ads to these spoofed devices, generating fake ad clicks to defraud online merchants and advertising networks. The operation is facilitated by proprietary tools allowing low-skilled operators to automate fraud routines. No direct patch or remediation is currently indicated for these devices. Join the discussion | Krebs on Security | 07/30/2026, 16:49:00 UTC Added: 07/31/2026, 01:31:43 UTC |
Canada’s Bill C-8 is here: Why the 72-hour reporting rule will redefine critical infrastructure security 0 Canada’s Bill C-8, the Critical Cyber Systems Protection Act (CCSPA), mandates critical infrastructure operators to report cyber incidents within 72 hours and imposes heavy financial penalties for non-compliance. The law targets sectors such as telecommunications, energy, transportation, and banking, requiring formal cybersecurity programs and mitigation of supply chain risks. The act highlights the operational challenge of detecting and reporting breaches rapidly in environments where IT and OT systems converge. Bill C-8 emphasizes the need for unified visibility across IT, OT, and IoT assets to meet the strict reporting deadline and avoid penalties. Solutions that combine active and passive monitoring can help eliminate blind spots and prioritize vulnerabilities that threaten physical safety and uptime. The legislation aims to enhance national critical infrastructure security by enforcing timely incident reporting and comprehensive asset management. Join the discussion | Tenable Research | 07/30/2026, 16:05:00 UTC Added: 07/30/2026, 16:20:43 UTC |
CVE-2026-44098: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Phoenix Contact CHARX SEC-3150CVE-2026-44098 0 This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Phoenix Contact CHARX SEC-3150 devices. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2026-44098. Join the discussion | CVE Database V5 | 07/30/2026, 06:49:53 UTC Added: 07/30/2026, 07:22:39 UTC |
Russian hackers exploit Exchange OWA zero-day for long-term mailbox access 0 The Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is exploiting an Exchange Outlook Web Access vulnerability in email campaigns to deliver a sophisticated backdoor called OWAReaper. [...] Join the discussion | Bleeping Computer | 07/29/2026, 23:44:07 UTC Added: 07/29/2026, 23:52:17 UTC |
ScreenConnect leveraged in cyberattacks | Kaspersky official blog 0 Leveraging legitimate software is one of cybercriminals’ tactics of choice, with remote management tools ranking among their top tools. A recent example involves the remote administration utility ScreenConnect. It’s designed for IT support teams to troubleshoot systems and configure software seamlessly in the background. However, when weaponized by threat actors, ScreenConnect becomes a versatile attack vehicle used to harvest data, deploy malware, and move laterally across corporate networks. During a recent incident detected by Kaspersky Managed Detection and Response , our experts identified an attempt to use ScreenConnect in an attack. This allowed a detailed study of how attackers used this application in a large-scale malware distribution campaign. The following breakdown illustrates the mechanics of ScreenConnect-assisted attacks, and outlines key strategies to defend your organization against them. How ScreenConnect reaches target computers In the campaign analyzed by our experts, the attackers bundled ScreenConnect with legitimate free business software. They established a network of phishing websites to spoof popular tools, including OBS Studio, DS4Windows, DNS Jumper, Glary Utilities, Bandizip, Process Hacker, and others. These rogue websites featured high-quality designs that could be taken for the official pages, making them highly convincing to unsuspecting users. Once the victim clicks the download button for the software, an archive is downloaded to their computer that contains additional files alongside the requested application: A legitimately signed Microsoft executable ( exe ), renamed to match the expected application installer (for example, OBS-Studio-Installer.exe ) A malicious library named res.1033.dll An Assets directory containing installers for both ScreenConnect and the intended application Launching the renamed file disguised as the app installer triggers DLL sideloading of a malicious library. This library silently runs the ScreenConnect installation without restarting the system, while using the standard Windows installer to set up the software the user originally tried to install. The attackers used search engine optimization techniques to drive traffic to their fake websites. As a result, these malicious pages appeared at the top of search results for certain free software utilities on major search engines. Our experts discovered over 90 domain names translated into more than 10 different languages. While most of these websites targeted English, Russian, and Chinese speakers, several domains catered to German, French, Spanish, Arabic, and other regional audiences. A detailed analysis of the IP addresses and associated spoofed domains is available in our technical research article on Securelist, along with full indicators of compromise. Why the attackers exploited ScreenConnect In this campaign, attackers leveraged ScreenConnect to generate and execute malicious scripts on victim machines. These scripts served several key functions: they created exclusions for specific drives, directories, and processes within Windows Defender, disabled the User Account Control (UAC) security mechanism, and delivered and deployed AsyncRAT – a remote access Trojan. To maintain persistence, the scripts configured a Windows scheduled task to run the malicious code at preset intervals. AsyncRAT then established a connection with the attackers’ command-and-control server to receive further instructions. The primary objective of this campaign appears to be gaining unauthorized access to enterprise systems, likely to then resell it on cybercrime marketplaces. How to secure corporate infrastructure Although ScreenConnect in and of itself is a legitimate tool, its presence poses a security risk to corporate environments. Consequently, Kaspersky security solutions detect this application as not-a-virus:HEUR:RemoteAdmin.MSIL.ConnectWise.gen. Security teams should implement the following controls: Enforce strict applicatio… Join the discussion | Kaspersky Security Blog | 07/29/2026, 15:49:29 UTC Added: 07/29/2026, 16:00:05 UTC |
Malicious sites use JavaScript to build malware in browser memory 0 A large malvertising campaign uses fake Solana, Luno, and TradingView websites with malicious JavaScript that assembles malware directly in browser memory. The attack uses service workers and shared workers to build a unique malware executable locally, avoiding transmission of a complete file over the network. This technique helps evade static detection and complicates analysis. The campaign targets retail traders and crypto investors primarily in Asia Pacific and Latin America. The malware reportedly can intercept network traffic, steal credentials and cryptocurrency wallet data, record keystrokes, take screenshots, and maintain persistence. Users are advised to download financial software only from official sources and verify digital signatures. Join the discussion | Bleeping Computer | 07/25/2026, 15:21:09 UTC Added: 07/25/2026, 15:22:07 UTC |
Why live chat agents can read your messages before you hit “Send” | Kaspersky official blog 0 On some websites, agents can read your messages before you even send them. We explain how these tracking mechanisms work, what data sites collect, and why this can be a risk. Join the discussion | Kaspersky Security Blog | 07/24/2026, 16:18:19 UTC Added: 07/24/2026, 16:24:04 UTC |
Chick-fil-A data breach affects more than 13,000 customers 0 Chick-fil-A has confirmed that over 13,000 customers had their accounts breached in a wave of credential stuffing attacks targeting its website and mobile app between June 17 and June 19. [...] Join the discussion | Bleeping Computer | 07/24/2026, 14:04:29 UTC Added: 07/24/2026, 14:22:23 UTC |
Showing 1 to 10 of 29 results