As per the sources, on February 5, 2023, Reddit, an American social news aggregation and discussion platform, suffers a cyberattack that allowed hackers to access internal business systems and steal internal documents and source code. As per Reddit, hackers targeted the employees with a phishing landing page impersonating its intranet website via a phishing lure, and the phishing site attempted to steal employee credentials and tokens for two-factor authentication. Further, when one of the employees fell victim to the phishing attack and the threat actor was successful in obtaining the credentials, they breached internal Reddit systems and accessed some internal documents, code, dashboards, and business systems. However, as of now, their primary production systems show no indication of a security breach. Moreover, Reddit became aware of the breach after the employee self-reported the incident to the company's security team. According to Reddit, the stolen data includes limited contact information for current and former employees, company contacts, as well as the details of the company's advertisers, but credit card information, passwords, and ad performance were not accessed. Also, Reddit says it does not appear that the threat actors breached the website's production systems.
The financially motivated threat actor Toy Ghouls, also known as Bearlyfy, Laboo.boo, and Feral Wolf, has developed two custom Windows backdoors that use legitimate communication i...
Panzer has surfaced as a new Ransomware-as-a-Service (RaaS) operation, claiming responsibility for attacks against 16 organizations spanning 11 countries. According to CyberXtron, ...
PostgreSQL faces a critical vulnerability dubbed PostGREShell, tracked as CVE-2026-6471, that could allow low-privileged replication accounts to execute arbitrary code, escalate pr...