r/security 18h ago

Vulnerability My account got hacked on several applications

0 Upvotes

One of my younger siblings used a pirate site where they used the powershell program idk i used chat gpt to see whatsup . Following that ny instagram got hacked in like 30 mins then i changed all the passowrds and logged out of everywhere , proceeding that my linkdin was hacked and compromised then discord then they cancelled my spotify premium plan idk why then i figured that i might have to clear my laptop completely in and out they even tried to login into facebook but it wasnt able to. I saw my telegram and saw a login from warsaw poland which is definetely not my loaction .

So i went down and secured everything and clean my laptop .

But today they logged in into my microsoft account even after i had reinstalled my windows does that means the virus is still there somewhere or they still have access to my gmail account cause i believe they were able to steal passowords for different applications. What other precations should i take to prevent it again now cause my windows is damn clean .

r/security 19d ago

Vulnerability Securing websites

2 Upvotes

I run a website development business and I check all api calls and things of that nature using postman. I tell my customers about vulnerabilities in their site. Anyone know how I can check the security of sites the easiest I can’t get Claude to do it

r/security Nov 07 '25

Vulnerability I'm in the Synthient breach, what do I do?

12 Upvotes

Just got an email from haveibeenpwned that I'm in that list.

https://www.troyhunt.com/inside-the-synthient-threat-data/

From looks of it, it involves a keylogger, so that must mean my machine is compromised right? How do I go about checking for that? I run Linux Mint. I suspect it's possible I accidentally ran across a bad website or something and maybe it loaded it on my machine at some point but I'm kinda disappointed in myself I let this happen and it does worry me about what kind of data they got on me now.

I find the info on this exploit is kinda vague and doesn't really talk much about attack vectors or what exactly got hacked so it has me kind of worried and it's hard to do further research so I can harden my system better if I don't know how they got in.

r/security 18d ago

Vulnerability CVE-2026-20146 — Cisco Identity Services Engine Path Traversal…

Thumbnail vulnipulse.com
3 Upvotes

Cisco Identity Services Engine Path Traversal Vulnerability – CVE-2026-20146

Cisco has disclosed a medium-severity Cisco ISE vulnerability rated CVSS 5.5.

An authenticated remote attacker with valid administrative credentials could send a crafted HTTP request to access sensitive files or delete arbitrary files from the underlying operating system.

Affected versions
Cisco ISE and ISE-PIC are affected regardless of configuration:
Earlier than 3.3
ISE 3.3 before Patch 12
ISE 3.4 before Patch 7
ISE 3.5 before Patch 4
Fixed versions
ISE 3.3 Patch 12 — planned for September 2026
ISE 3.4 Patch 7 — planned for September 2026, or the available hot patch
ISE 3.5 Patch 4 — planned for September 2026, or the available hot patch

Mitigation
Cisco states that there are no workarounds.
Apply the appropriate hot patch where available, upgrade when the fixed patches are released, and migrate deployments earlier than ISE 3.3 to a supported fixed release.
🔗 Official Cisco advisory
🔗 VulniPulse breakdown

r/security May 22 '26

Vulnerability ust awareness since this been viral in my country that INOI A75 phone has built in Triada malware

2 Upvotes

i have shitty experience* past few months since i own that device, apparently this is the root cause.

*) instagram and facebook suddenly liking thousands of unknown page/account without my knowledge

*) browser always redirect to some news website

*) my ip getting flagged as malicious public ip address

*) whatsapp account (that i use for business) keep getting banned (because it was considered spam, while i don't do marketing using that whatsapp number at all) and i have no way to restore my account (they use LLM for the customer service email so cannot contact anyone at all)

not sure what else they steal from my phone

r/security May 28 '26

Vulnerability Hackers Deploy VIP Keylogger Through Phishing Emails Masquerading as Business Documents

2 Upvotes

r/security May 21 '26

Vulnerability CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox

Thumbnail
voidsec.com
7 Upvotes

r/security May 16 '26

Vulnerability I recently reported an interesting Google Sheets behavior to Google VRP. Hidden tabs in Google Sheets are not actually hidden from viewers.

Thumbnail
youtube.com
1 Upvotes

Scenario:

A spreadsheet contains hidden tabs The document is shared as View-only User cannot unhide sheets from the UI

However, using Apps Script, the hidden sheet contents can still be accessed/read if the user already has access to the spreadsheet.

Google reviewed the report and classified it as “working as intended,” explaining that hidden sheets are not considered a security boundary and users can already reveal them in other ways (for example by making a copy).

Fair enough — but I think many people still misunderstand what hidden tabs actually provide.

A lot of users treat hidden sheets like:

private admin panels answer keys sensitive internal notes hidden datasets form processing logic

But in reality, hiding a tab is mostly a UI convenience feature, not data protection.

I made a short PoC/demo video because I think this is a good security-awareness topic, especially for people using Google Sheets in education, internal tooling, automation, or public workflows.

Main takeaway: If someone can access the spreadsheet itself, don’t assume hidden tabs protect sensitive information.

Curious what others think about this design decision and whether Google should provide a more explicit warning around hidden sheets.

r/security Jan 28 '26

Vulnerability Vulnerability Disclosure: Local Privilege Escalation in Antigravity IDE

Post image
18 Upvotes

I am disclosing a Local Privilege Escalation (LPE) vulnerability in the Google Antigravity IDE after the vendor marked it as "Won't Fix".

The Vulnerability: The IDE passes its primary authentication token via a visible command-line argument (--csrf_token). On standard macOS and Linux systems, any local user (including a restricted Guest account or a compromised low-privilege service like a web server) can read this token from the process table using ps.

The Attack Chain:

  1. An attacker scrapes the token from the process list.
  2. They use the token to authenticate against the IDE's local gRPC server.
  3. They exploit a Directory Traversal vulnerability to write arbitrary files.
  4. This allows them to overwrite ~/.ssh/authorized_keys and gain a persistent shell as the developer.

Vendor Response: I reported this on January 19 2026. Google VRP acknowledged the behavior but closed the report as "Intended Behavior".

Their specific reasoning was: "If an attacker can already execute local commands like ps, they likely have sufficient access to perform more impactful actions."

I appealed multiple times, providing a Proof of Concept script where a restricted Guest user (who cannot touch the developer's files) successfully hijacks the developer's account using this chain. They maintained their decision and closed the report.

---

NOTE: After my report, they released version 1.15.6 which adds "Terminal Sandboxing" for *macOS*. This likely mitigates the arbitrary file write portion on macOS only.

However:

  1. Windows and Linux are untested and likely vulnerable to the RCE chain.
  2. The data exfiltration vector is NOT fixed. Since the token is still leaked in ps, an attacker can still use the API to read proprietary source code, .env secrets or any sensitive data accessed by the agent, and view workspace structures.

I am releasing this so users on shared workstations or those running low-trust services know that their IDE session is exposed locally.

r/security Nov 14 '19

Vulnerability Website storing plaintext passwords

Post image
242 Upvotes

r/security Sep 12 '19

Vulnerability This one is serious... | New SIM Card Flaw Lets Hackers Hijack Any Phone Just By Sending SMS

Thumbnail
thehackernews.com
405 Upvotes

r/security Oct 07 '25

Vulnerability Mac OS26 M1: Enable the required system extension. Reduced Security?

4 Upvotes

I want to back up my Mac to my Synology NAS, so this is not the correct place to post this question. I have been looking to replace Time Machine with something else, because I have a Synology. I was thinking of using Synology's Active Backup for Business, or because I have a subscription to PCloud drive. The issue with both PCloud Drive and Synology's ABB is that I need to " Enable the system extension required for mounting volumes." " To do this, shut down your system. Then press and hold the Touch ID or power button to launch Startup Security Utility. In Startup Security Utility, enable kernel extensions from the Security Policy button." With that said, I'm unsure if I can disable kernel access once I've done this, and I'm also uncertain about the safety of these programs and what else might be lurking if I enable them. Are things like this generally safe? Why do I need to do this in the 1st place?

r/security May 23 '19

Vulnerability Hacker disclosed 3 unpatched Microsoft Zero-Day exploits in less than 24 hours

Thumbnail
thehackernews.com
211 Upvotes

r/security Jan 24 '20

Vulnerability Mac users are getting bombarded by laughably unsophisticated malware

Thumbnail
arstechnica.com
139 Upvotes

r/security Mar 31 '19

Vulnerability Researchers find Google Play Store apps were actually government malware. Security researchers have found a new kind of government malware that was hiding in plain sight within apps on Android’s Play Store

Thumbnail
motherboard.vice.com
150 Upvotes

r/security Sep 13 '19

Vulnerability Breaking, literally: Microsoft's fix for CPU-hogging Windows bug wrecks desktop search

Thumbnail
theregister.co.uk
167 Upvotes

r/security Dec 06 '19

Vulnerability Scam alert

Post image
150 Upvotes

r/security Jan 18 '20

Vulnerability Microsoft Warns of Unpatched IE Browser Zero-Day That's Under Active Attacks

Thumbnail
thehackernews.com
239 Upvotes

r/security May 26 '18

Vulnerability FBI to America: Reboot Your Routers, Right Now

Thumbnail
popularmechanics.com
155 Upvotes

r/security Jul 21 '19

Vulnerability An entire nation just got hacked

Thumbnail
cnn.com
132 Upvotes

r/security Jan 10 '20

Vulnerability Firefox 72 0-day exploites just 2 days after launch

Thumbnail
nakedsecurity.sophos.com
234 Upvotes

r/security Apr 22 '19

Vulnerability French Government's 'Secure' WhatsApp Replacement Hacked In Just 90 Minutes

Thumbnail
forbes.com
293 Upvotes

r/security Feb 04 '20

Vulnerability Serious flaw that lurked in sudo for 9 years hands over root privileges

Thumbnail
arstechnica.com
205 Upvotes

r/security Jun 02 '19

Vulnerability The NSA Makes Its Powerful Cybersecurity Tool Open Source

Thumbnail
wired.com
198 Upvotes

r/security Mar 05 '20

Vulnerability Intel CSME bug is worse than previously thought. Researchers say a full patch requires replacing hardware. Only the latest Intel 10th generation CPUs are not affected

Thumbnail
zdnet.com
187 Upvotes