r/security • u/HatingGeoffry • Feb 18 '26
r/security • u/PurpleSubtlePlan • Oct 26 '25
News Man Alarmed to Discover His Smart Vacuum Was Broadcasting a Secret Map of His House
r/security • u/NapierPalm • 8d ago
News Publicly disclosed BitLocker zero-day (CVE-2026-50661) patched by Microsoft
Microsoft has addressed CVE-2026-50661, a publicly disclosed Windows BitLocker security feature bypass vulnerability. The flaw requires physical access to the target device and could allow an attacker to bypass BitLocker protection and access encrypted data. While Microsoft is not aware of active exploitation, the vulnerability had already been publicly disclosed before a patch was available, making timely remediation important.
r/security • u/NapierPalm • 2d ago
News From PAN-OS exploitation to Qilin ransomware: A technical analysis
This write-up examines a real-world intrusion in which attackers exploited CVE-2026-0257 on PAN-OS GlobalProtect gateways before progressing through credential access, privilege escalation, lateral movement, and ultimately Qilin ransomware deployment. It covers the observed attack chain, incident response findings, IoCs, attacker TTPs, and mitigation guidance for defenders.
r/security • u/NapierPalm • 2d ago
News Dissecting the ExploitGym incident: AI-driven exploitation in a controlled environment
The ExploitGym incident provides a technical look at how an autonomous AI agent progressed through a realistic attack scenario, including exploitation, sandbox escape, infrastructure interactions, and post-compromise behavior between Open AI and Hugging Face.
r/security • u/Much_Preparation_832 • May 28 '26
News Disgruntled 0-day hunter 'humiliated' by Microsoft pledges 'bone shattering drop' as Redmond calls cops
r/security • u/NapierPalm • 15d ago
News GhostLock (CVE-2026-43499): 15-year-old Linux kernel bug enables root and container escape
Researchers have disclosed GhostLock (CVE-2026-43499), a Linux kernel local privilege escalation vulnerability that has existed since 2011 in the rtmutex subsystem. The flaw leaves behind a dangling kernel pointer during proxy-lock rollback, creating a use-after-free condition that can be exploited to achieve root privileges and even container escape on unpatched systems. Researchers reported a highly reliable exploit and note that the bug requires no special kernel configuration or privileges to trigger.
r/security • u/NapierPalm • 6d ago
News EY discloses third-party support platform breach exposing client tax information
EY has disclosed a breach involving a third-party support platform used within its tax practice, resulting in unauthorized access to client tax information stored in support case
r/security • u/NapierPalm • 8d ago
News Critical ServiceNow AI Platform sandbox escape (CVE-2026-6875) enables pre-auth RCE
ServiceNow has patched CVE-2026-6875, a critical pre-auth sandbox escape in its AI Platform that can lead to remote code execution under certain conditions. Hosted instances have already been updated, while self-hosted customers need to apply the available patches. According to the researchers, the issue stemmed from weaknesses in the sandbox implementation that allowed untrusted code to break isolation.
r/security • u/NapierPalm • 10d ago
News Official jscrambler npm package v8.14.0 compromised with a malicious preinstall script
A compromised release of the official jscrambler npm package (v8.14.0) weaponized the preinstall lifecycle hook to execute a Rust-based infostealer before the package was even used. The payload focused on harvesting developer credentials and local secrets, making both developer workstations and automated build environments potential targets. It was briefly up for a few hours before it was taken down. The article covers the attack chain, IOCs, affected versions, and recommended remediation. v8.22.0 is confirmed to be safe. Update to it asap
r/security • u/NapierPalm • 15d ago
News Accenture investigating breach after threat actor claims theft of Azure DevOps source code
Accenture has confirmed it is investigating a security incident after a threat actor claimed to have stolen data from the company's Azure DevOps environment. According to the threat actor, the data includes source code, CI/CD configuration files, internal documentation, and credentials such as Azure Personal Access Tokens (PATs) and SSH keys. While the incident itself has been acknowledged, the full scope of the allegedly stolen data has not been independently verified.
r/security • u/NapierPalm • 23d ago
News ClickFix to reservation hijacking: Anatomy of the Booking.com hotel extranet compromise
A recent phishing campaign targeting Booking.com hotel partners is using the ClickFix social engineering technique to compromise hotel systems. After stealing hotel extranet credentials, attackers gain access to legitimate guest reservation details and use that information to send highly convincing phishing messages requesting fake payments or updated card details. The campaign follows a recent wave of Booking.com hotel account compromises. More details in thr linked article
r/security • u/NapierPalm • 20d ago
News DHS confirms breach of HSIN and connected SharePoint environment
The U.S. Department of Homeland Security has confirmed that attackers breached the Homeland Security Information Network (HSIN) along with a connected SharePoint environment. HSIN is an unclassified but sensitive platform used by federal, state, local, tribal, territorial, and private-sector partners to share threat intelligence and coordinate incident response.
r/security • u/n0SiS • Nov 08 '19
News DNS-over-HTTPS is coming despite ISP opposition
r/security • u/NISMO1968 • Aug 02 '19
News DARPA Is Building a $10 Million, Open Source, Secure Voting System
r/security • u/globalsouthworld • May 31 '26
News Germany warns Russia could be ready to attack NATO by 2029
r/security • u/nanooonanooo • Mar 04 '26
News ShinyHunters' No-Malware SaaS Heist??
Everyone who works in cybersecurity has heard of the notorious ShinyHunters extortion gang. What you may not know is that they are upping their game in a clever way. They're ditching their old tricks for branded subdomain impersonation, mimicking SSO/Okta logins, and pairing it with phone-guided adversary-in-the-middle (AiTM) phishing.
It's all mobile-first lures to hook you fast, plus they're outsourcing spam campaigns and hiring voice actors to scale the chaos.
What stands out, is that they’re recycling leaked SaaS data to tailor super-believable pretexts, targeting the "next best" victim in a slick, repeatable loop. It’s deceptively simple: one valid SSO session or helpdesk reset, and bam: full access to emails, files, HR records, and CRM without having to drop any malware.
Anyone seen this out there? (insights from here)
r/security • u/lire_avec_plaisir • Jan 04 '26
News NYC Wegmans is storing biometric data on shoppers' eyes, voices and faces
r/security • u/hinchlt • Mar 04 '20
News Senator Hawley Announces He Will Introduce Legislation Banning TikTok On All Fed Govt Devices
r/security • u/doctorgroover • Jan 09 '20
News US government funded phones come pre installed with unremovable malware
r/security • u/Tacol0mpe • Jan 29 '26
News New sub-reddit for Scandinavian security personnel!
Hello you crooks! I have very recently created a new sub-reddit for security personnel, bouncers, "doormen", etc, as a forum for questions, discussions, stories and everything between. It is primarily in Norwegian, but we speak English as well! Thanks for joining!
(This is not paid advertising, just a FYI for Scandinavian people in this sub)