Facebook Twitter Instagram
    • Privacy Policy
    • Contact Us
    Facebook Twitter Instagram Pinterest Vimeo
    AI Home SecurityAI Home Security
    • Home
    • Home Security
    • Cyber Security
    • Biometric Technology
    Contact
    AI Home SecurityAI Home Security
    Cyber Security

    Reddit Suffers Security Breach Exposing Internal Documents and Source Code

    justmattgBy justmattgFebruary 10, 2023No Comments2 Mins Read

    [ad_1]

    Feb 10, 2023Ravie LakshmananData Breach / Source Code

    Reddit

    Popular social news aggregation platform Reddit has disclosed that it was the victim of a security incident that enabled unidentified threat actors to gain unauthorized access to internal documents, code, and some unspecified business systems.

    The company blamed it on a “sophisticated and highly-targeted phishing attack” that took place on February 5, 2023, targeting its employees.

    The attack entailed sending out “plausible-sounding prompts” that redirected to a website masquerading as Reddit’s intranet portal in an attempt to steal credentials and two-factor authentication (2FA) tokens.

    A single employee’s credentials is said to have been phished in this manner, enabling the threat actor to access Reddit’s internal systems. The affected employee self-reported the hack, it further added.

    The company, however, stressed that there is no evidence to suggest that its production systems were breached or that users’ non-public data has been compromised. There is no indication that the accessed information has been published or distributed online.

    “Exposure included limited contact information for (currently hundreds of) company contacts and employees (current and former), as well as limited advertiser information,” Reddit said.

    It further noted “similar phishing attacks have been recently reported” without taking any specific names. It did not disclose what source code was accessed following the security lapse.

    The development is yet another indication as to how threat actors are increasingly finding ways to defeat 2FA by setting up lookalike pages that are capable of pulling off adversary-in-the-middle (AitM) attacks.

    Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.



    [ad_2]

    Source link

    Previous ArticleCritical Infrastructure at Risk from New Vulnerabilities Found in Wireless IIoT Devices
    Next Article Getting Developers and Security Teams to Work Together
    justmattg
    • Website

    Related Posts

    Cyber Security

    Name That Toon: Last Line of Defense

    April 16, 2024
    Cyber Security

    OpenJS Foundation Targeted in Potential JavaScript Project Takeover Attempt

    April 16, 2024
    Cyber Security

    Middle East Cyber Ops Intensify, With Israel the Main Target

    April 16, 2024
    Add A Comment

    Leave A Reply Cancel Reply

    Facebook Twitter Instagram Pinterest
    • Privacy Policy
    • Contact Us
    AI Home Security © 2025 All rights reserved | Designed By ESmartsSolution

    Type above and press Enter to search. Press Esc to cancel.

    ↑