buc.ci is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
Kritische Sicherheitslücken in SvxLink – sofort aktualisieren
Das SvxLink-Projekt hat vor wenigen Stunden die Version 26.05.1 veröffentlicht. Sie schließt vierzehn Sicherheitslücken, von denen zwei als kritisch eingestuft sind – die schwerste mit 9,8 von 10 möglichen Punkten. Betroffen sind alle Versionen bis einschließlich 26.05, und zwar rückwirkend über mehr als ein Jahrzehnt. Seit heute sind die technischen Einzelheiten über die Sicherheits-Mailingliste oss-security öffentlich bekannt; damit steht jedem, der es darauf anlegt, eine genaue Anleitung zur Verfügung.
Zur Einordnung der Zahl 9,8: Sicherheitslücken werden weltweit nach einem einheitlichen Schema bewertet, dem Common Vulnerability Scoring System (CVSS). Es vergibt Punkte von 0 bis 10. Ab 9,0 gilt eine Lücke als kritisch – das ist die höchste von vier Stufen, und dort landen nur wenige Prozent aller je gemeldeten Schwachstellen. Der Wert 9,8 bedeutet konkret: Der Angriff kommt über das Netz, er braucht kein Passwort, der Sysop muss nichts anklicken oder bestätigen, und der Aufwand ist gering. Was ein Angreifer im Erfolgsfall anrichten kann, reicht je nach System vom Absturz der Relaissteuerung bis zur Ausführung eigenen Programmcodes mit den Rechten des SvxLink-Prozesses.
Die schwerste Lücke steckt im EchoLink-Verzeichnisdienst. Beim Einlesen der Stationsliste wird die Stationsbeschreibung ungeprüft in einen zu kleinen Speicherbereich kopiert; ein manipulierter oder unterwegs abgefangener Verzeichnisserver kann darüber fremden Code auf dem Relaisrechner ausführen. Die Verbindung zum Verzeichnisserver läuft unverschlüsselt, ein Mitschneiden und Verändern ist also technisch unaufwendig. Betroffen sind SvxLink mit EchoLink-Modul ebenso wie der Client Qtel auf dem heimischen PC.
Die zweite kritische Lücke betrifft RemoteTrx: Ist kein AUTH_KEY konfiguriert, erhält jeder erreichbare Rechner ohne jede Anmeldung vollen Zugriff auf den Transceiver, einschließlich Sendetastung. Wer dann unter dem Rufzeichen der Relaisfunkstelle sendet, entscheidet nicht mehr der Sysop.
#hamradio #amateurfunk #svxlink #echolink #cybersecurity #securityadvisory #infosec #linux #remotetrx
This dumb password rule is from University of Western Australia (Pheme).
Passwords:
1. Must contain at least 8 characters;
2. Must contain at least 3 out of 4 types of characters
(uppercase letters, lowercase letters, digits, special characters);
and
3. Must not contain
"the user's account name or parts of the user's full name
that exceed two consecutive characters".
...
https://dumbpasswordrules.com/sites/university-of-western-australia-pheme/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
Plexfiltration update: the AI work zone compliance tool has started emailing me thousands of pictures from a (I think) Saudi industrial facility again, to my internaluser.com domain. #infosec
🚨 U.S. folks. There is one day left to comment on the FCC proposed rule to eradicate anonymity on all phone lines!
If they pass this rule government ID, physical address, and alternative phone number will be required for every new phone line. Anonymous phone lines and burner phones will cease to exist. That means no connected privacy via cellular at protests.
** Please add your comment! **
For the first field (proceedings) use these two:
17-59 and 02-278
🙏 New Blog Post
The Pope's official prayer app has an IDOR that lets anyone pull user data for all 719,517 accounts. One GET request per user. No auth check.
What's exposed:
Also found:
Reported January 3rd. Emailed 9 people. A journalist also contacted them. Zero responses. Still live six months later. Vow of silence I guess.
Full writeup: https://bobdahacker.com/blog/click-to-pray
#InfoSec #BugBounty #ResponsibleDisclosure #IDOR #Security #CyberSecurity #Privacy #DataExposure #ClickToPray #Vatican #APISecurity
Possible Phishing 🎣
on: ⚠️hxxps[:]//sdgf9af72f31706769d32bf1ff66cdec1d1gkj5jg95jg5k0hkg95kg0tk[.]pages[.]dev/NHQ031202LETTER[.]pdf
🧬 Analysis at: https://urldna.io/scan/6a630d963b77500004f5906f
#cybersecurity #phishing #infosec #urldna #scam #infosec
Possible Phishing 🎣
on: ⚠️hxxps[:]//santandervyg[.]transcom-fs[.]com
🧬 Analysis at: https://urldna.io/scan/6a61ca1d3b77500006ce137b
#cybersecurity #phishing #infosec #urldna #scam #infosec
Possible Phishing 🎣
on: ⚠️hxxps[:]//weizihua[.]github[.]io/MyEtherWallet/
🧬 Analysis at: https://urldna.io/scan/6a6183d73b775000051d00a3
#cybersecurity #phishing #infosec #urldna #scam #infosec
🔒 Security News Digest - 2026-07-23
📊 8 updates from 5 sources:
🔹 SecurityWeek: Upbound Group Says Data Breach Led to $13 Million in Fraudulent Contract Losses
https://www.securityweek.com/upbound-group-says-data-breach-led-to-13-million-in-fraudulent-contract-losses/
🔹 darkreading: Agentic AI Challenges Progress in Confidential Computing
https://www.darkreading.com/endpoint-security/agentic-ai-challenges-progress-in-confidential-computing
🦠 Malwarebytes: WhatsApp Web chats exposed by Adobe’s Acrobat extension flaw
https://www.malwarebytes.com/blog/bugs/2026/07/whatsapp-web-chats-exposed-by-adobes-acrobat-extension-flaw
🦠 Malwarebytes: Millions of cars could be tracked and unlocked by a hidden security flaw
https://www.malwarebytes.com/blog/bugs/2026/07/millions-of-cars-could-be-tracked-and-unlocked-by-a-hidden-security-flaw
🔹 The Hacker News: Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers
https://thehackernews.com/2026/07/attackers-weaponize-github-actions.html
🔹 The Hacker News: How Synthetic Identity Fraud is Coming for Machine Identities
https://thehackernews.com/2026/07/how-synthetic-identity-fraud-is-coming.html
🔹 SecurityWeek: Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models
https://www.securityweek.com/nuclear-sabotage-malware-benchmark-trips-up-most-frontier-ai-models/
🔹 The Record from Recorded Future News: Major Australian energy supplier confirms customer data compromised
https://therecord.media/australia-origin-energy-data-breach
A public proof-of-concept for CVE-2026-57239 turns a Foxit PDF Reader vulnerability into full SYSTEM privileges via local privilege escalation.
Possible Phishing 🎣
on: ⚠️hxxps[:]//webhfjfhfjrj[.]weebly[.]com/
🧬 Analysis at: https://urldna.io/scan/6a6161613b775000051cfc14
#cybersecurity #phishing #infosec #urldna #scam #infosec
🚨 We're disclosing a macOS security bug that Apple says is not an issue.
Using a simple archive-and-restore trick, an attacker can silently replace the main executable of virtually any application downloaded from the web—no password or warning is required.
Here's a demo using Signal to steal its encryption key.
📝 Blog with technical details: link in the replies.
Do you think this should be considered a security bug?
🎬👇
#Apple #privacy #infosec #security #macOS
Read what @simon has to say about OpenAI/Hugging Face situation.
It’s pretty clear what happened here. OpenAI removed safety filters for an in-progress model, locked it up in a sandbox and told it to solve the ExploitGym problems. Given the absence of guardrails there was nothing to prevent the model from attempting to break out of that sandbox, break into Hugging Face, and read the answers from there instead.
Kelly Bissell (former CVP, Fraud & Abuse, Microsoft) pushes back on headline-driven threat prioritization: nation-state attribution generates press coverage, but fraud is what actually costs organizations money.
Full discussion in IWG Rewind, our on-demand series of exclusive talks.
❗️ Kratos, one of the major M365 PhaaS operations, has been disrupted by German & US law enforcement. 200+ servers were taken down, according to BKA.
Good news, but PhaaS operators rebrand, affiliates switch kits, and the same workflows return in new campaigns 🚨
🔍 Our report breaks down the phishing flow, infrastructure patterns, artifacts, and detection logic analysts can reuse when investigating similar campaigns: https://any.run/cybersecurity-blog/kratos-phaas-account-takeover/?utm_source=mastodon&utm_medium=post&utm_campaign=kratos_phaas_takedown&utm_content=linktoblog&utm_term=230726
Hot take:
I hate how all these articles talk about how OpenAI’s clanker “broke out” and attacked Hugging Face.
No, OpenAI’s dog slipped its chain because they don’t know what the hell they’re doing, and it bit another dog.
🔴 EXPLOITED
Check Point's SmartConsole flaw (CVE-2026-16232) lets an unauthenticated attacker log in as full admin. It is being exploited now.
Affects Security Management servers reachable over the network.
Fix: limit management access to your admin IPs, then patch.
https://suriq.io/blog/check-point-smartconsole-cve-2026-16232-exploited
🚨New ransom group blog posts!🚨
Group name: blacknevas
Post title: L'azurde
Info: https://cti.fyi/groups/blacknevas.html
Group name: kairos
Post title: LR Reed
Info: https://cti.fyi/groups/kairos.html
Group name: nova
Post title: VNSO
Info: https://cti.fyi/groups/nova.html
#ransomware #cti #threatintelligence #cybersecurity #infosec
Possible Phishing 🎣
on: ⚠️hxxp[:]//www[.]match[.]lookatmynewphotos[.]com/
🧬 Analysis at: https://urldna.io/scan/6a60cd0e3b77500003fd1142
#cybersecurity #phishing #infosec #urldna #scam #infosec
This is a great list of tips for improving your Signal privacy from @yaelwrites.
I found this part especially meaningful:
“Turning off biometrics makes it annoying to use your phone…If that’s you, remember that both Android and iOS have a quick lockout that forces a passcode and disables biometrics until you re-enter it: on iPhone, hold the side + volume button until the power-off screen appears, then cancel; on most Androids, hold power and tap Lockdown.”
https://blog.yaelwrites.com/how-to-keep-the-feds-out-of-your-signal-messages
Just over one week left for our call for papers! It ends on July 31, 2026.
The CFP submission URL is https://forms.office.com/r/EybwVVfigX
We accept first time as well as veteran speakers and encourage submissions from diverse perspectives—whether you're proposing a talk about AI, blue teaming, red teaming, or anything in between.
We look forward to your proposals.
#BSidesYXE #BSides #Saskatoon #CallForPapers #infosec #Conference
Possible Phishing 🎣
on: ⚠️hxxps[:]//webmail-senacsa-gov-py-8082[.]weebly[.]com
🧬 Analysis at: https://urldna.io/scan/6a61135f3b775000020ba0d3
#cybersecurity #phishing #infosec #urldna #scam #infosec
🤖 CVE-2026-48294 (CVSS 7.4): The Adobe Acrobat Chrome extension (314M users) allowed malicious sites to read private WhatsApp Web data via HermeticReader attack chain. Now patched.
🔗 https://www.bleepingcomputer.com/news/security/adobe-chrome-extension-flaw-let-sites-access-private-whatsapp-chats/
#CVE #CyberSec #InfoSec
Think of it like starting a new RPG and discovering your starting village was already burned down during the loading screen. You never had the option to stop it. You do, however, have the option to stop what comes next: apply SonicWall's security updates for the SMA zero-days immediately.
Reward: You've been assigned the permanent passive debuff "Rootkitted On Day Zero." It does not come off.
#ZeroDay #SonicWall #CyberSecurity #Vulnerability #InfoSec #PatchedOrPerish (2/2)
Possible Phishing 🎣
on: ⚠️hxxps[:]//docs[.]google[.]com/presentation/d/e/2PACX-1vRwN5bDXk4y5mkOxLhTGvEJh6VbEPPzltoidJr74d1iyWxd_I_0bTw-EAYghiM64T-bwapZZkzI7U6a/pub?start=false&loop=false&delayms=3000
🧬 Analysis at: https://urldna.io/scan/6a60c6a93b77500003fd105d
#cybersecurity #phishing #infosec #urldna #scam #infosec
Just ran across this deep dive by @jolek78
into a malicious intrusion run by agentic AI, and as an infosec nerd, this is both fascinating and completely terrifying. We are so fucked.
https://jolek78.writeas.com/the-attacker-who-never-sleeps
"No one told the model “breach Hugging Face”. Had they done so, it would have been a test gone wrong but predictable. They told it “get a good grade on this exam” – and the model autonomously decided that the best route there ran through a real cyber-intrusion against a third-party company that had nothing to do with the exam. The attack was designed by no one: it was the path the optimiser chose towards an innocuous goal. Someone had written “maximise the score” into the objective function; no one had written “...without committing federal crimes”."
#agent #agentic #AI #infosec #cybersec #breach #HuggingFace #OpenAI
Possible Phishing 🎣
on: ⚠️hxxps[:]//steampowered-zhcn[.]hl[.]cn
🧬 Analysis at: https://urldna.io/scan/6a60644c3b775000036b01e2
#cybersecurity #phishing #infosec #urldna #scam #infosec
Possible Phishing 🎣
on: ⚠️hxxps[:]//vxcvngfdthfdxzwe[.]weebly[.]com
🧬 Analysis at: https://urldna.io/scan/6a60326f3b77500006cde294
#cybersecurity #phishing #infosec #urldna #scam #infosec
Hello #Fediverse! I am a Systems Analyst and student from Pakistan doing my #Introduction. My primary focus is on dissecting complex systems and digital forensics.
I recently published my research on a custom SQLite WAL parser I built for the legacy WhatsApp Desktop client. By bypassing OS file-lock race conditions, it acted as a completely passive "shadow client" to extract un-checkpointed transaction frames directly from active RAM. #DFIR #ReverseEngineering #InfoSec
Technical Workflow⚠️: By targeting the messages.db-wal file directly, I extracted un-checkpointed transaction frames. Using DPAPI and decoding Google ProtoBuf allowed me to CAPTURE mesgs states with millisecond precision—including ␡ mesgs, edited mesgs + reaction timelines & bypassng privacy on *"View Once" 💣
All of this was done acting as a completely passive "shadow client of WhatsApp" resulting in zero digital+Netwrk footprint.🥷
#DFIR #InfoSec #Forensic #Redteam #reddit #whatsapp
While the legacy UWP client is deprecated, this exact vector is patched in modern Electron builds, it remains a critical historical case study (i recently Resposibly Disclosed it, after ~8.5 Months) in application abstraction bypasses and low-level parsing.
Full Architectural Breakdown + Methodology 👇
https://rahimgujjar.github.io/research
Looking forward to connecting with the #DFIR #InfoSec #ReverseEngineering #Forensic #Redteam #reddit #whatsapp community here! Let me know your thoughts.
Possible Phishing 🎣
on: ⚠️hxxps[:]//banxicomx[.]com/nosotros/index[.]html
🧬 Analysis at: https://urldna.io/scan/6a6086953b775000036b060e
#cybersecurity #phishing #infosec #urldna #scam #infosec
ASN: AS17252
Location: Los Angeles, US
Added: 2026-07-22T10:26
Qualys discloses CVE-2026-64600 (RefluXFS), an XFS privilege escalation to root affecting 16.4M+ Linux systems. Patch the kernel and reboot now.
#RefluXFS #CVE202664600 #LinuxKernel #PrivilegeEscalation #XFS #InfoSec
🚨 EUVD-2026-47464
📊 Score: 7.2/10 (CVSS v3.1)
📦 Product: Oracle Process Manufacturing Systems
🏢 Vendor: Oracle Corporation
📅 Published: 2026-07-21 | Updated: 2026-07-22
📝 Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.11-12.2.15. Easily e...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-47464
🚨 EUVD-2026-47011
📊 Score: 9.1/10 (CVSS v3.1)
📦 Product: AIT-Core, AIT-Core
🏢 Vendor: NASA-AMMOS
📅 Published: 2026-07-21 | Updated: 2026-07-22
📝 The AMMOS Instrument Toolkit (Formerly the Bespoke Links to Instruments for Surface and Space (BLISS)) is a Python-based software suite developed to handle Ground Data System (GDS), Electronic Ground Support Equipment (E...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-47011
This dumb password rule is from NetBank (Commonwealth Bank of Australia).
When resetting your NetBank password, the website only informs you that you can create an alphanumeric password, despite the fact that you can use special characters.
And also, it's password strength calculation is shit.
An 155 bits of entropy password is "weak."
Additionally, passwords are case-...
https://dumbpasswordrules.com/sites/netbank-commonwealth-bank-of-australia/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
New reference implementation shipped today: #LangChain middleware that gates AI agents from connecting to unfamiliar MCP servers behind a mandatory security check. It is not an optional tool call the agent is free to skip.
Third on-prem SharePoint RCE this month: CVE-2026-50522 (CVSS 9.8) went from public PoC to active exploitation in hours.
All three July flaws steal the server machine key. Patch, then ROTATE the key, or a patched box is still owned.
https://suriq.io/blog/sharepoint-cve-2026-50522-rotate-machine-keys
Possible Phishing 🎣
on: ⚠️hxxps[:]//zenithpars[.]weebly[.]com/
🧬 Analysis at: https://urldna.io/scan/6a6086963b775000036b0611
#cybersecurity #phishing #infosec #urldna #scam #infosec
#defcontickets #defcon #defcon34 #infosec #cybersecurity #LasVegas #LVCC
Due to unforeseen circumstances I won't be able to make it out to Def Con 34 in Las Vegas. I have a single ticket that I'm willing to sell / transfer at a steep discount, but I'm not sure just how to do that here. I would like to have my ticket go to someone else since it seems like a real waste to me if I just hold on to my ticket and not have another person use it to attend Def Con at a discount so that they can better afford overnight lodgings, go to LV's silly museums, maybe gamble, and so on.
It's not so much about the money in my particular case — I'm pretty flexible on setting a price point. The people at Def Con are cool and giving or selling tickets to others is allowed because #infosec is made up of a lot of anarchist lite thinking.
Def Con 34 is from Thursday, August 6th to Sunday August 9th, 2026 at the LVCC in their West Hall building(s).
You may PM me.
Possible Phishing 🎣
on: ⚠️hxxps[:]//webmailserver5steadyturtle-com2096[.]weebly[.]com
🧬 Analysis at: https://urldna.io/scan/6a6040563b77500006cdecd7
#cybersecurity #phishing #infosec #urldna #scam #infosec
About time.
New.
KrebsonSecurity: LG to Ban Residential Proxies from Smart TV Apps https://krebsonsecurity.com/2026/07/lg-to-ban-residential-proxies-from-smart-tv-apps/ @briankrebs #infosec #LG #botnets #IoT
A third SharePoint vulnerability is now being actively exploited.
CVE-2026-50522 (CVSS 9.8) is a critical .NET deserialization vulnerability affecting on-premises SharePoint Server. Following the release of a public PoC, researchers observed attackers exploiting the flaw to extract ASP.NET machine keys, enabling persistent access beyond simply achieving RCE.
One important point: applying Microsoft's patch may not be sufficient if a server was already compromised. Incident response should include reviewing IIS logs, investigating potential machine key exposure, and rotating compromised cryptographic secrets where necessary.
I published a technical deep dive covering everything.
Read here:
https://thecybersecguru.com/news/sharepoint-cve-2026-50522-active-exploitation/
#InfoSec #CyberSecurity #SharePoint #Microsoft #DFIR #ThreatHunting #BlueTeam #Vulnerability
This was posted yesterday.
Infoblox: The Procurement Trap: Inside an AiTM Campaign Targeting Global Institutions https://www.infoblox.com/blog/threat-intelligence/the-procurement-trap-inside-an-aitm-campaign-targeting-global-institutions/ @InfobloxThreatIntel #infosec #threatintel #threatintelligence #cybercrime
Broadcom has a very long list of updates for vulnerabilities published yesterday, one of them critical https://support.broadcom.com/web/ecx/security-advisory #infosec #Broadcom #vulnerability
Palo Alto released the statement yesterday:
Palo Alto Networks to Extend Leading Observability Platform with Innovative Digital Experience Monitoring https://www.paloaltonetworks.com/company/press/2026/palo-alto-networks-to-extend-leading-observability-platform-with-innovative-digital-experience-monitoring
More:
Security Week: Palo Alto Networks to Acquire Observability Platform Provider Embrace https://www.securityweek.com/palo-alto-networks-to-acquire-observability-platform-provider-embrace/ @SecurityWeek #infosec #PaloAlto
Possible Phishing 🎣
on: ⚠️hxxps[:]//my-docs-jet[.]firebaseapp[.]com
🧬 Analysis at: https://urldna.io/scan/6a6040493b77500006cdecaf
#cybersecurity #phishing #infosec #urldna #scam #infosec
Nolan's Odyssey just hit theaters, and honestly, Odysseus had it easy. Ten years, one long trip, and he was done.
ISO 27001 wants the trilogy every single year: detection, validation, remediation. Three-year cycle, a surveillance audit checking your homework annually. No one-and-done epic here.
Pentest-Tools.com is ISO/IEC 27001:2022 certified. We run the same evidence trail on ourselves:
✅ Detection - CVE, severity, date, logged automatically
✅ Validation - confirmed findings, not just a score
✅ Remediation - retests prove the fix held
✅ Monitoring - scheduled scans, all three years long
No sirens, no Cyclops, just a surveillance audit that stays a review instead of turning into its own odyssey.
Full ISO 27001 evidence chain: https://pentest-tools.com/usage/compliance/iso-27001
🚨 𝗔𝘁𝘁𝗮𝗰𝗸𝗲𝗿 𝗖𝟮 𝗖𝗼𝗻𝘁𝗿𝗼𝗹 𝗖𝗮𝘂𝗴𝗵𝘁 𝗼𝗻 𝗮 𝗟𝗶𝘃𝗲 𝗦𝘆𝘀𝘁𝗲𝗺. Interactive analysis let us capture what static detonation misses ⚠️
𝗢𝗯𝘀𝗲𝗿𝘃𝗲𝗱 𝘁𝗮𝗿𝗴𝗲𝘁𝗶𝗻𝗴: 𝗚𝗲𝗿𝗺𝗮𝗻𝘆 𝗮𝗻𝗱 𝗨𝗞 ❗️ The operator connected to the infected system, uploaded the next-stage payload, and triggered a full chain: we.exe PythonRAT ➡️ exo.exe dropper ➡️ Lenovo FnHotkeyUtility.exe ➡️ spkvol.dll sideloading ➡️ Rust loader ➡️ In-memory OVERLORD RAT.
🔥 The initial implant was only the entry point. The real risk appeared later: DLL sideloading, in-memory execution, encrypted C2, and active data exfiltration.
1️⃣ we.exe connects to live[.]rnsn[.]live:8585 (rn/m visual impersonation) using a custom HTTP-like C2 protocol with commands hidden in HTML comments and a spoofed porsche[.]com Host header.
2️⃣ exo.exe unpacks to C:\ProgramData\DeepSkyBlueIndianRed\, launches the legitimate Lenovo binary, sideloads spkvol.dll, and delivers a fileless overlord-client Go agent.
📌 OVERLORD connects to lord[.]kirkdridebridge[.]com:5173 over mTLS-encrypted C2. During 45 minutes of analysis, the agent emitted ~86 MB of data, confirming active collection and exfiltration.
Observed capabilities include remote access, HVNC, keylogging, audio recording, SOCKS proxying, file management, browser/messenger/wallet data theft, and Solana drainer activity.
👨💻 See the full execution chain and collect #IOCs:
https://app.any.run/tasks/926b4df0-e4c6-4250-be8f-6a4fdc845916/?utm_source=mastodon&utm_medium=post&utm_campaign=pythonrat_overlord&utm_content=linktoservice&utm_term=220726
⚡️ Learn how #ANYRUN helps SOC teams detect complex threats early: https://any.run/enterprise/?utm_source=mastodon&utm_medium=post&utm_campaign=pythonrat_overlord&utm_content=linktoenterpriselanding&utm_term=220726
Malcolm v26.07.1 adds a few minor changes on top of Malcolm v26.07.0, the most notable being a fix for a crash in the strelka-backend container on arm64 platforms. Malcolm v26.07.0 added IEC 60870-5-104 (IEC 104) protocol support using CERT.LV's Zeek plugin, including Logstash parsing, ECS normalization, Arkime fields, and a new OpenSearch Dashboards dashboard. This release also fixes three archive extraction and authentication security vulnerabilities; improves NetBox enrichment configuration; and addresses PostgreSQL major version upgrade, custom CA certificate for KeyCloak, container health check, privilege-drop signal chaining, and configuration script issues. Arkime, Zeek, Fluent Bit, Filebeat, Logstash, Supercronic, and Alpine-based images have been updated as well.
If you are upgrading from an existing Malcolm installation, run ./scripts/status for Malcolm to migrate some settings prior to running ./scripts/configure, ./scripts/start, or other Malcolm control scripts.
https://github.com/idaholab/Malcolm/compare/v26.06.1...v26.07.1
✨ Features and enhancements
spicy-iec104 Zeek plugin, including Zeek log ingestion, ECS field mapping, Arkime fields, and an IEC 104 dashboard #939LOGSTASH_NETBOX_ENRICHMENT_DATASETS more flexible: it now accepts default, ics/ot, all, explicit provider.dataset values, and combinations such as default,ics #1037LOGSTASH_NETBOX_ENRICHMENT_DATASETS to be configured through checkboxes in the configuration TUI #1033./scripts/start error messages by listing missing or invalid authentication-related files instead of reporting only a generic authentication setup failure #865system-quickstart detect and prepopulate existing time synchronization settings when rerun #992🛡️ Security Remediation & Hardening
🐛 Bug fixes
opencv-python and opencv-contrib-python corrupts cv2.abi3.so, segfaulting strelka-backend at import on arm64 #1046 (fix)docker-uid-gid-setup.sh so signals reach the final process after dropping privileges #1039 to ensure clean shutdown of containersKEYCLOAK_SSL_VERIFY=true #1035curl to the the htadmin container for use by the health check script #1029✅ Component version updates
netbox container) to v12.3.0 to address several security findings🧹 Code and project maintenance
📄 Configuration changes for Malcolm (in environment variables in ./config/). The Malcolm control script (e.g., ./scripts/status, ./scripts/start) automatically handles creation and migration of variables according to ./config/env-var-actions.yml.
LOGSTASH_NETBOX_ENRICHMENT_DATASETS in logstash.env now defaults to default and may contain default, ics/ot, all, explicit provider.dataset values, or a comma-separated combination of these valuesZEEK_DISABLE_ICS_IEC104 in zeek.env controls whether the IEC 104 Zeek plugin is disabledSAFE_EXTRACT_MAX_ENTRIES, SAFE_EXTRACT_MAX_DEPTH, and SAFE_EXTRACT_MAX_BYTES in upload-common.env set archive extraction resource limits for uploaded archive files (e.g., containing Zeek logs for processing); their defaults are 5,000 entries, 20 directory levels, and 4 GiB of expanded dataMalcolm is a powerful, easily deployable network 🖧 traffic analysis tool suite for network security monitoring 🕵🏻♀️.
Malcolm operates as a cluster of containers 📦, isolated sandboxes which each serve a dedicated function of the system. This makes Malcolm deployable with frameworks like Docker 🐋, Podman 🦭, and Kubernetes ⎈. Check out the Quick Start guide for examples on how to get up and running.
Alternatively, dedicated official ISO installer images 💿 for Malcolm and Hedgehog Linux 🦔 can be downloaded from Malcolm's releases page on GitHub. Due to limits on individual files in GitHub releases, these ISO files have been split 🪓 into 2GB chunks and can be reassembled with scripts provided for both Bash 🐧 (release_cleaver.sh) and PowerShell 🪟 (release_cleaver.ps1). See Downloading Malcolm - Installer ISOs for instructions.
As always, join us on the Malcolm discussions board 💬 to engage with the community, or pop some corn 🍿 and watch a video 📼.
#Malcolm #HedgehogLinux #Zeek #Arkime #Strelka #NetBox #OpenSearch #Elasticsearch #Suricata #PCAP #NetworkTrafficAnalysis #networksecuritymonitoring #OT #ICS #icssecurity #CyberSecurity #Cyber #Infosec #INL
Possible Phishing 🎣
on: ⚠️hxxps[:]//redstoneciugafhoureon[.]weebly[.]com
🧬 Analysis at: https://urldna.io/scan/6a60326e3b77500006cde28e
#cybersecurity #phishing #infosec #urldna #scam #infosec
Sliver has dethroned Cobalt Strike as the #1 malware family associated with botnet C&Cs between Jan-Jun 2026. Sliver climbed +58% to 3,008 detections, while Cobalt Strike collapsed -68% to 1,110 - this is the biggest single-period fall we've ever recorded for this malware.
Grab the full report here ⤵️
https://www.spamhaus.org/resource-hub/botnet-c-c/botnet-threat-update-january-to-june-2026/
🚨New ransom group blog posts!🚨
Group name: akira
Post title: University Sprinkler Systems
Info: https://cti.fyi/groups/akira.html
Group name: akira
Post title: Kruse Construction
Info: https://cti.fyi/groups/akira.html
#ransomware #cti #threatintelligence #cybersecurity #infosec
7-Zip still exists?
PC Gamer: It's probably time to update 7-Zip as the app has just been patched to fix a pretty big vulnerability https://www.pcgamer.com/software/security/its-probably-time-to-update-7-zip-as-the-app-has-just-been-patched-to-fix-a-pretty-big-vulnerability/ #infosec #vulnerability
Discover how the HollowGraph malware exploits Microsoft 365 calendars for C2 communication and data exfiltration in targeted espionage attacks.
#HollowGraph #Microsoft365 #Malware #CyberEspionage #InfoSec #GroupIB
A must read #Privacy #Security
Richard Medhurst says his #GrapheneOS-secured phone helped protect his data after #UK #police seized his devices at Heathrow—despite months of password demands. Experts note there’s no “silver bullet” for source safety. 🔒📱 Read: https://www.computerweekly.com/feature/Journalist-Richard-Medhurst-had-his-mobile-phone-seized-Did-using-a-secure-phone-protect-his-dataa #cybersecurity #journalism #infosec
🤖 OpenAI model escape puts enterprise AI defenses on notice
📝 Some of OpenAI’s most powerful AI models teamed up to escape their sandbox and attack system...
📰 CSO Online
Origin Energy Investigates Potential Data Breach After Hacker Claims 2 Million Customer Records Stolen
Origin Energy disclosed a potential data breach after a hacker claimed to have stolen records belonging to approximately two million customers and provided samples to media outlets. The company notified Australian cybersecurity, law enforcement, and privacy authorities and is investigating the scope of the unauthorized access.
****
#cybersecurity #infosec #incident #databreach
https://beyondmachines.net/event_details/origin-energy-investigates-potential-data-breach-after-hacker-claims-2-million-customer-records-stolen-5-4-p-0-x/gD2P6Ple2L
Possible Phishing 🎣
on: ⚠️hxxps[:]//totalpropertycare[.]ae
🧬 Analysis at: https://urldna.io/scan/6a60080b3b775000081012b0
#cybersecurity #phishing #infosec #urldna #scam #infosec
ASN: AS142403
Location: Tseung Kwan O, HK
Added: 2026-07-22T07:02
Starland RAT is new malware from Russian-speaking actor UAT-11795. It steals crypto wallets and credentials via fake Zoom and WebEx installers.
#StarlandRAT #UAT11795 #CiscoTalos #Malware #Cryptocurrency #ClickFix #InfoSec
https://securityonline.info/starland-rat-uat-11795/?utm_source=mastodon&utm_medium=jetpack_social
So, Mullvad made a clarification statement about one of their donator.
I agree with all Mullvad view in this response.
⚠️ THREAT ALERT: CVE-2026-60137 in WordPress Core enables unauthenticated SQL injection that chains for remote code execution! Active exploitation is confirmed. Get the forensic detection queries and hardening strategies you need to protect your web assets now. https://thecybermind.co/12b8
🔒 Security News Digest - 2026-07-22
📊 8 updates from 5 sources:
🔹 The Hacker News: Why Modern SOCs Need Multi-Layered Detections
https://thehackernews.com/2026/07/why-modern-socs-need-multi-layered.html
🔹 SecurityWeek: Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks
https://www.securityweek.com/fourth-sharepoint-vulnerability-exploited-in-past-months-wave-of-attacks/
🔹 darkreading: EU Financial Institutions Leak Data Through Cookie Trackers
https://www.darkreading.com/data-privacy/eu-financial-institutions-cookie-trackers
🦠 Malwarebytes: Paidwork breach exposes data of 23 million users: Check if you’re affected
https://www.malwarebytes.com/blog/data-breaches/2026/07/paidwork-breach-exposes-data-of-23-million-users-check-if-youre-affected
🔹 The Record from Recorded Future News: OpenAI models behind breach of Hugging Face systems, companies say
https://therecord.media/openai-cyberattack-hugging-face
🦠 Malwarebytes: Chick-fil-A loyalty accounts hijacked using stolen passwords
https://www.malwarebytes.com/blog/data-breaches/2026/07/chick-fil-a-loyalty-accounts-hijacked-using-stolen-passwords
🔹 SecurityWeek: StrongestLayer Raises $4.1 Million in Seed Funding Extension
https://www.securityweek.com/strongestlayer-raises-4-1-million-in-seed-funding-extension/
🔹 SecurityWeek: Vibe-Coded Apps Riddled With Exploitable Security Flaws
https://www.securityweek.com/vibe-coded-apps-riddled-with-exploitable-security-flaws/
A theme worth sitting with from this week's reporting: the malicious traffic wasn't hiding near trusted infrastructure, it was flowing through it.
Group-IB's HollowGraph runs its C2 inside a compromised Microsoft 365 calendar. Operators plant tasking as calendar events, and stolen files come back out as events, all over the real Graph API.
The incident signals that #AI's expanding capabilities are already fueling the #security threat experts long feared & even top developers can be caught off-guard by flaws their models can exploit.
The breakout was "an unprecedented cyber incident, involving state-of-the-art cyber capabilities" & #OpenAI is reinforcing its safeguards, the company said in a blog post.
It also drew attention as New York-based #HuggingFace said it had used an open-source Chinese model to contain the attack because leading US models, unable to tell a defender from an attacker, refused to process the data needed for analysis.
The company said in a blog post last week that it used #Zhipu AI's GLM-5.2 for the analysis, which also allowed it to keep attacker data & any credentials within its systems.
Hackers are actively exploiting a critical ServiceNow RCE vulnerability (CVE-2026-6875) to bypass sandbox restrictions and breach corporate networks.
#ServiceNow #Vulnerability #RCE #CVE20266875 #Cybersecurity #Infosec
https://meterpreter.org/servicenow-rce-vulnerability/?utm_source=mastodon&utm_medium=jetpack_social
Possible Phishing 🎣
on: ⚠️hxxps[:]//upgradetelkomaccount[.]weebly[.]com/
🧬 Analysis at: https://urldna.io/scan/6a60b0ea3b77500003fd0dbe
#cybersecurity #phishing #infosec #urldna #scam #infosec
🚨 #BSidesRoc is set for March 20, 2027!
We're now seeking sponsors to help make the event a success. Check out our sponsorship opportunities and download the sponsorship kit:
https://bsidesroc.com/sponsorships/
Unblu Spark suffers a CRITICAL open redirect (CVE-2026-8152) leading to DOM XSS in siteEmbeddedSetup=true config. Attacker can access cookies & APIs of host app. No patch yet — disable this config ASAP. https://radar.offseq.com/threat/cve-2026-8152-cwe-601-url-redirection-to-untrusted-site-open-redirect-in-unblu-inc-unblu-spark-7d13478f5c7eb4ac #OffSeq #XSS #Vulnerability #InfoSec
Moin!
Wie vorangekündigt: 28.7. ist das nächste OWASP-Treffen, bei dem ein bisschen Hamburger Lokalpariotismus mitschwingt 😉
Wie vielleicht vermutet, ist die Rede vom OWASP Juice Shop, a.k.a. "probably the most modern and sophisticated insecure web application". Das ist ein sog. OWASP-Flagship-Projekt, dass vor Kurzem sein 20. Release hatte.
Eckdaten:
---------------
* Lokation: Baumwall 7, New Work SE (danke, New Work, vor allen Dingen: Gerrit)
* Vortrag: Freshly Squeezed: Prompt-Injecting Juice Shops New AI Brain
* Sprecher: Björn Kimminich und Jannik Hollenbach
* Datum: 28.7.2026
* Start: 18:00
* Anmeldung: Wäre hilfreich für die Getränke, die unser Host bestellt. Entweder per Mail oder: https://www.meetup.com/owasp-hamburg-stammtisch/events/315684286
* Presentation Language: TBD. (if you plan to come and English is better for you, let us know)
Abstract
--------------
OWASP Juice Shop's chatbot now runs on real LLM backends, either local models or the major providers' APIs.
And we're not just going to show you the new LLM challenges: we'll solve them with you, live on stage.
You call out the payloads, we fire them at the bot: coaxing it into leaking data it shouldn't, hijacking its behavior with well-placed prompts, and finding out on the spot which attacks land and which ones it shrugs off.
Bring your nastiest prompt-injection ideas!
We maintainers also had a "fun" year fielding large quantities of AI bot contributions of wildly differing quality.
The talk covers how running a popular open-source project has changed since the boom of AI coding agents.
Beyond LLMs, 2026 kept MultiJuicer, the project for managing multiple Juice Shop instances across local or remote hackathons and trainings, busy too.
It now ships with a new CTF / wargames scoreboard for tracking participant scores, which we'll show off along the way.
Nachbereitung
-----------------------
Das Portugiesenviertel könnte uns danach weiter verwöhnen. Wenn du zur Nachbereitung dabei bist, sag mir Bescheid. Dann würde ich für dich mit reservieren.
Sonstiges
----------------
Falls du selbst Lust auf einen Vortrag hast, oder du generell Vorträgen ein werbefreies Dach über dem Kopf bieten kannst, melde dich gerne!
Generelles zum OWASP-Treffen
---------------------------------------------------
Bei unseren für alle offenen Treffen geht es um Software und deren Sicherheit im Internet und/oder #Infosec allgemein. Hier treffen sich Menschen, die sich beruflich oder privat mit IT-Sicherheit beschäftigen: Entwickler, Manager, Pentester und alle an (Web)sicherheit interessierte. Die Atmosphäre ist offen und locker. Uns geht's um den Erfahrungsaustausch, Technikschnack und um's Netzwerken. Wer Produkte oder Dienstleistungen verkaufen will, ist hier falsch. Ihr seid herzlich willkommen, euren Kollegen oder Bekannten einen Hinweis auf unsere Treffen weiterzuleiten. Alle Treffen sind frei, für jeden Menschen offen und kostenlos, mit oder ohne #OWASP-Mitgliedschaft.
Langflow's 'validate' endpoint just produced its SECOND unauthenticated root RCE in 14 months. CVE-2026-0770, CVSS 9.8, now in CISA's KEV list with a 3-day federal deadline. 220+ exploit attempts already logged. Patch, then pull it off the internet.
https://suriq.io/blog/langflow-cve-2026-0770-validate-rce-kev
Discover how the sophisticated Cruciferra crypter service employs BYOVD and Process Ghosting to conceal malware and evade detection across enterprise networks.
#Cruciferra #Crypter #BYOVD #ProcessGhosting #MalwareEvasion #InfoSec
https://meterpreter.org/cruciferra-crypter-service/?utm_source=mastodon&utm_medium=jetpack_social
Ernst & Young Reports Third-Party Data Breach Affecting Tax Clients
Ernst & Young reports a breach of a third-party service management platform that allowed unauthorized access to client tax and financial data between March and April 2026. The firm is providing credit monitoring to affected individuals and has notified law enforcement.
****
#cybersecurity #infosec #incident #databreach
https://beyondmachines.net/event_details/ernst-young-reports-third-party-data-breach-affecting-tax-clients-d-3-9-p-c/gD2P6Ple2L
Possible Phishing 🎣
on: ⚠️hxxps[:]//docs[.]google[.]com/presentation/d/e/2PACX-1vTTJ55NegmW7dN_WwTQD9VxQaUCVarklIqJ9hsLkPgpIcQyNBi7b-dbcIKu6stCGw2-kLZKNBpxjXR2/pub?start=false&loop=false&delayms=3000
🧬 Analysis at: https://urldna.io/scan/6a609c793b77500003fd0afd
#cybersecurity #phishing #infosec #urldna #scam #infosec
🤖 CVE-2026-0770 (CVSS 9.8): Critical unauthenticated RCE in Langflow AI framework actively exploited. Attackers gain root access via validate endpoint, deploying malware and stealing AWS creds. 220+ attempts from 64 IPs observed. CISA added to KEV catalog, orders patching by Friday.
🔗 https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-langflow-rce-flaw/
#CVE #RCE #InfoSec #CyberSec #AI
🎉 AI Subscription Giveaway!
As a thank you to everyone supporting my work, I'm giving away some AI subscriptions (ChatGPT and Claude, Pro and Max Inclusive) exclusively to active Buy Me a Coffee members.
✔️ Any membership tier is eligible
✔️ Winner chosen at random
✔️ Be sure to use the same email address as your Buy Me a Coffee membership when entering, otherwise your entry cannot be verified.
Enter here:
https://thecybersecguru.com/giveaways/ai-subscription-giveaway/
Thank you for helping support independent cybersecurity research, projects, educational content and much much more. ❤️
To support me, please buy me a coffee: https://buymeacoffee.com/thecybersecguru/membership
#InfoSec #CyberSecurity #Giveaway #AI #OpenSource #BlueTeam #RedTeam
TTF Trap Campaign Hides a Low-Detection Lua Loader Inside Fake TrueType Font Files
A global phishing campaign hides a low-detection Lua loader inside fake .ttf font files to drop Remcos, XWorm, Agent Tesla, and a Snake Keylogger. #LuaLoader #TTFTrap #Phishing #FortiGuard #Remcos #AgentTesla #Malware #InfoSec At a glance Malware family Lua/AutoIt loader ("TTF Trap") delivering Remcos, Agent Tesla, XWorm, and Best Private LOGGER Threat actor Unattributed. FortiGuard Labs names no group. Target / victims…
https://securityonline.info/ttf-trap-lua-loader/?utm_source=mastodon&utm_medium=jetpack_social
Possible Phishing 🎣
on: ⚠️hxxps[:]//uyfxgfdfxj[.]weebly[.]com/
🧬 Analysis at: https://urldna.io/scan/6a6086a33b775000036b0627
#cybersecurity #phishing #infosec #urldna #scam #infosec
Siemens Patches Multiple Vulnerabilities in SIDIS Secured SmartPlug
Siemens released security updates for the SIDIS Secured SmartPlug to fix 12 vulnerabilities, including a critical flaw in wireless authentication components. These flaws allow remote code execution, unauthorized access, and sensitive data disclosure in critical manufacturing environments.
**Make sure your SIDIS Secured SmartPlug devices are isolated from the internet and reachable only from trusted networks, behind a firewall separated from your business network. Then update every affected device to version V7.26.0310 or later.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/siemens-patches-multiple-vulnerabilities-in-sidis-secured-smartplug-8-t-0-n-s/gD2P6Ple2L
Possible Phishing 🎣
on: ⚠️hxxps[:]//zim-veri[.]weebly[.]com/
🧬 Analysis at: https://urldna.io/scan/6a6078943b775000036b0436
#cybersecurity #phishing #infosec #urldna #scam #infosec
⚠️ CRITICAL THREAT: CVE-2026-63030 in WordPress Core enables SQL injection and RCE via interpretation conflicts. Active exploitation is confirmed! Get the forensic detection queries and hardening strategies needed to secure your web assets now. https://thecybermind.co/9k20
Possible Phishing 🎣
on: ⚠️hxxps[:]//t[.]co/lvOUaOHAEf
🧬 Analysis at: https://urldna.io/scan/6a6072303b775000036b0354
#cybersecurity #phishing #infosec #urldna #scam #infosec
Microsoft will stop Exchange 2016 & Exchange 2019 security updates in October 2026
Two previously disclosed CVEs are actively-weaponized kernel root exploits. GhostLock CVE-2026-43499, and Bad Epoll CVE-2026-46242, are both public highly reliable exploits. Ghostlock also appears to enable a container escape and Bad Epoll is also working on Android.
Both are fixed in kernel 6.12.96-1.
If you have local users, upgrade the kernel & boot it.
BRB have to reboot :)
#minimalist #Linux #Selfhosting #selfhosted #selfhost #InfoSec #Exploit
🔒 Security News Digest - 2026-07-21
📊 13 updates from 5 sources:
🔹 SecurityWeek: Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack
https://www.securityweek.com/estee-lauder-discloses-impact-from-oracle-ebs-zero-day-hack/
🔹 The Hacker News: New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit
https://thehackernews.com/2026/07/new-bit2watt-attack-could-let-cloud.html
🔹 SecurityWeek: CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG
https://www.securityweek.com/ciso-conversations-andreas-gaetje-from-economics-to-ciso-at-korber-ag/
🦠 Malwarebytes: Don’t trust that “FBI agent” in your DMs
https://www.malwarebytes.com/blog/news/2026/07/dont-trust-that-fbi-agent-in-your-dms
🔹 The Hacker News: N-day is Becoming N-Hour. Patching Faster Won't Save You.
https://thehackernews.com/2026/07/n-day-is-becoming-n-hour-patching.html
🔹 SecurityWeek: New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication
https://www.securityweek.com/new-hollowgraph-malware-abuses-microsoft-365-calendar-for-cc-communication/
🔹 The Hacker News: Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs
https://thehackernews.com/2026/07/open-source-android-ai-agents-could-let.html
🦠 Malwarebytes: New ClickLock Stealer locks your Mac until you hand over your password
https://www.malwarebytes.com/blog/news/2026/07/new-clicklock-stealer-locks-your-mac-until-you-hand-over-your-password
🔹 The Record from Recorded Future News: Kenya probes hack of president's website after bitcoin ransom demand
https://therecord.media/kenya-probes-hack-of-presidents-website-after-ransom-demand
🔹 SecurityWeek: SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity
https://www.securityweek.com/securityweek-launches-critical-impact-awards-to-recognize-excellence-in-industrial-cybersecurity/
🔹 SecurityWeek: Empirical Security Raises $25 Million in Series A Funding
https://www.securityweek.com/empirical-security-raises-25-million-in-series-a-funding/
🔹 darkreading: Choose Wisely: AI-Generated Coding Risk Varies, A Lot
https://www.darkreading.com/application-security/choose-wisely-ai-generated-coding-risk-varies
🔹 The Record from Recorded Future News: Taiwan to slow mobile data during national resilience drills
https://therecord.media/taiwan-mobile-5g-speed-reductions-han-kuang
Hello People.
This is my first fediverse post, featuring my first #assembly64 program in #linux. I am a #student who is just getting into #cybersecurity and love contributing to #infosec, #lowlevel stuffs and #linuxkernel.
I love to program in #c, and use #archlinux btw. Looking for people to connect. I installed LinkedIn a few days ago for connecting with people and figured out that it was a #scam in jobmarket, just data feed into companies. (No offense, just in my opinion).
I was suggested to start learning #assembly64 by a random reddit user when I asked some questions about #c programming and how to get better at it. Currently learning #syscalls in linux, and I guess assembly programming alongside with c programming is helpful - I can understand syscalls and registers (for some extent).
Looking forward for friends to connect. Follow me and I will follow you back - provided that we have same or similar interests. I am also interested in #russian arts, languages and techs - I am not a Russian btw.
I need suggestions \ #help on how to get started in fediverse, cybersecurity and low level stuffs. You can see my profile for more information.
Possible Phishing 🎣
on: ⚠️hxxps[:]//coinbasekr[.]com
🧬 Analysis at: https://urldna.io/scan/6a5d96fb3b7750000442647c
#cybersecurity #phishing #infosec #urldna #scam #infosec
New.
Proofpoint: Unpacking “Cruciferra”: An Analysis of a Sophisticated Crypter Service https://www.proofpoint.com/us/blog/threat-insight/unpacking-cruciferra-analysis-sophisticated-crypter-service #infosec #threatresearch #cybercrime
New.
Picus: CVE-2026-63030 and CVE-2026-60137 (wp2shell): WordPress RCE Explained https://www.picussecurity.com/resource/blog/cve-2026-63030-and-cve-2026-60137-wp2shell-wordpress-rce-explained #infosec #vulnerability #WordPress
🚨New ransom group blog posts!🚨
Group name: akira
Post title: L&A Transport
Info: https://cti.fyi/groups/akira.html
Group name: akira
Post title: McKeever , Varga & Senko
Info: https://cti.fyi/groups/akira.html
#ransomware #cti #threatintelligence #cybersecurity #infosec
282,000+ VEX records are now in Vulnerability-Lookup 🎉
🔎 https://vulnerability.circl.lu/vex
SUSE just joined Red Hat and Microsoft as a VEX source — so from any CVE you can see whether a vendor says a product is affected, fixed, or not affected.
VEX statements are attached directly to each vulnerability and available via the open API.
🧑💻 https://github.com/vulnerability-lookup/vulnerability-lookup
#VEX #CSAF #VulnerabilityManagement #OpenSource #InfoSec #GCVE #CVE #CYberSecurity #Vulnerability
Gitea vulnerability CVE-2026-58443 (CVSS 9.6) lets public-only tokens write to private repos. Details and PoC code are public. Update to v1.27.0.
#Gitea #CVE202658443 #DevSecOps #PoC #InfoSec
https://securityonline.info/gitea-vulnerability/?utm_source=mastodon&utm_medium=jetpack_social
Craneware Discloses Data Breach Involving Employee, Customer, and Partner Records
Craneware PLC disclosed a data breach after unauthorized actors accessed its data environment and stole employee, customer, and partner records. The company contained the incident, notified the FBI and UK Information Commissioner’s Office, and confirmed that customer services and business operations were not disrupted.
****
#cybersecurity #infosec #incident #databreach
https://beyondmachines.net/event_details/craneware-discloses-data-breach-involving-employee-customer-and-partner-records-5-v-b-t-y/gD2P6Ple2L
9to5Linux: NetworkManager 1.58 Officially Released with New Features and Improvements https://9to5linux.com/networkmanager-1-58-officially-released-with-new-features-and-improvements
IPFire 2.29 Core Update 203 Firewall Distro Replaces Unbound with Knot Resolver https://9to5linux.com/ipfire-2-29-core-update-203-firewall-distro-replaces-unbound-with-knot-resolver @9to5linux @mariusnestor #Linux #opensource #infosec
Possible Phishing 🎣
on: ⚠️hxxps[:]//centurybnkt[.]weebly[.]com/
🧬 Analysis at: https://urldna.io/scan/6a5dcf323b7750000282662e
#cybersecurity #phishing #infosec #urldna #scam #infosec
One fake download page ➡️ full remote access to your network ⚠️
SnappyClient shows how quickly a single click can turn into stolen credentials, hijacked payments, and a foothold attackers can exploit long after the initial breach.
👨💻 Learn more: https://any.run/malware-trends/snappyclient/?utm_source=mastodon&utm_medium=post&utm_campaign=snappyclient&utm_content=linktomtt&utm_term=200726
The Record: British company Craneware that provides software to more than 2,000 US hospitals says attackers stole employee and customer data https://therecord.media/software-provider-for-us-hospitals-customer-data-breach @therecord_media #infosec #databreach
If you missed the spectacular news that Ernest & Young has been breached, here's more:
Security Week: Ernst & Young Data Breach Affects Personal, Financial Information https://www.securityweek.com/ernst-young-data-breach-affects-personal-financial-information/ @SecurityWeek #infosec #databreach
New.
Sysdig: JADEPUFFER evolves: The agentic threat actor deploys ransomware built to destroy AI models https://www.sysdig.com/blog/jadepuffer-evolves-the-agentic-threat-actor-deploys-ransomware-built-to-destroy-ai-models
More:
Infosecurity-Magazine: https://www.infosecurity-magazine.com/news/jadepuffer-ai-model-ransomware/ #infosec #ransomware #LLM
If #kernel hackers are now giving #Claude Code unfettered access to do as it pleases on their development computers, what exactly is stopping #Anthropic from performing a supply-chain attack on the entire #Linux ecosystem?
Will there still be human code review going forward, to catch such an attack? And if so, how can that review be meaningful, when the computers used to perform the review are all compromised?
Possible Phishing 🎣
on: ⚠️hxxps[:]//westconsincuorgg[.]weebly[.]com
🧬 Analysis at: https://urldna.io/scan/6a5c760e3b77500007bb2d55
#cybersecurity #phishing #infosec #urldna #scam #infosec
New by me: Security Signal Weekly: July 11-17, 2026
https://www.kylereddoch.me/blog/security-signal-weekly-july-11-17-2026/
Possible Phishing 🎣
on: ⚠️hxxps[:]//urlz[.]fr/uMr7
🧬 Analysis at: https://urldna.io/scan/6a5b3a563b775000081c7235
#cybersecurity #phishing #infosec #urldna #scam #infosec
OpenSSL quietly fixed HollowByte in June: 11 bytes strand a server's memory, no auth needed. No CVE, so your scanner won't flag it, and patching without a reload leaves hit workers bloated.
rm -rf /
GPT 5.6 deleted an AI Bro's files.
Making mistakes or malfunctions isn't surprising—what is surprising is how some AI enthusiasts give unsupervised access to productive systems without backups. 🤦♀️
Here's the reality: AI has no idea what it's doing. It's a highly sophisticated word completion system ≠ a sci-fi thinking machine.
https://x.com/brunolemos/status/2076769881534398974
#AI #MachineLearning #AIRisks #SystemSecurity #DataLoss #LLM #Technology #InfoSec
CVE-2026-16096: Stack-based buffer overflow (CVSS 8.7, HIGH) in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124 (/proc/webmon_recent_domains). Remote exploit possible. Migrate to FreshTomato. https://radar.offseq.com/threat/cve-2026-16096-stack-based-buffer-overflow-in-shibby-tomato-e5419cb0350bdcaf #OffSeq #Vulnerability #Infosec
Possible Phishing 🎣
on: ⚠️hxxps[:]//www[.]powr[.]io/media-gallery/i/41166190
🧬 Analysis at: https://urldna.io/scan/6a5b16633b775000081c6ec9
#cybersecurity #phishing #infosec #urldna #scam #infosec
Possible Phishing 🎣
on: ⚠️hxxps[:]//is[.]gd/bper-Alert002
🧬 Analysis at: https://urldna.io/scan/6a5ad7e83b775000081c679c
#cybersecurity #phishing #infosec #urldna #scam #infosec