buc.ci is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin email
abucci@bucci.onl
Admin account
@abucci@buc.ci

Search results for tag #infosec

[?]DARC e. V. | PR und ÖA » 🌐
@darc@social.darc.de

Kritische Sicherheitslücken in SvxLink – sofort aktualisieren

Das SvxLink-Projekt hat vor wenigen Stunden die Version 26.05.1 veröffentlicht. Sie schließt vierzehn Sicherheitslücken, von denen zwei als kritisch eingestuft sind – die schwerste mit 9,8 von 10 möglichen Punkten. Betroffen sind alle Versionen bis einschließlich 26.05, und zwar rückwirkend über mehr als ein Jahrzehnt. Seit heute sind die technischen Einzelheiten über die Sicherheits-Mailingliste oss-security öffentlich bekannt; damit steht jedem, der es darauf anlegt, eine genaue Anleitung zur Verfügung.

Zur Einordnung der Zahl 9,8: Sicherheitslücken werden weltweit nach einem einheitlichen Schema bewertet, dem Common Vulnerability Scoring System (CVSS). Es vergibt Punkte von 0 bis 10. Ab 9,0 gilt eine Lücke als kritisch – das ist die höchste von vier Stufen, und dort landen nur wenige Prozent aller je gemeldeten Schwachstellen. Der Wert 9,8 bedeutet konkret: Der Angriff kommt über das Netz, er braucht kein Passwort, der Sysop muss nichts anklicken oder bestätigen, und der Aufwand ist gering. Was ein Angreifer im Erfolgsfall anrichten kann, reicht je nach System vom Absturz der Relaissteuerung bis zur Ausführung eigenen Programmcodes mit den Rechten des SvxLink-Prozesses.

Die schwerste Lücke steckt im EchoLink-Verzeichnisdienst. Beim Einlesen der Stationsliste wird die Stationsbeschreibung ungeprüft in einen zu kleinen Speicherbereich kopiert; ein manipulierter oder unterwegs abgefangener Verzeichnisserver kann darüber fremden Code auf dem Relaisrechner ausführen. Die Verbindung zum Verzeichnisserver läuft unverschlüsselt, ein Mitschneiden und Verändern ist also technisch unaufwendig. Betroffen sind SvxLink mit EchoLink-Modul ebenso wie der Client Qtel auf dem heimischen PC.

Die zweite kritische Lücke betrifft RemoteTrx: Ist kein AUTH_KEY konfiguriert, erhält jeder erreichbare Rechner ohne jede Anmeldung vollen Zugriff auf den Transceiver, einschließlich Sendetastung. Wer dann unter dem Rufzeichen der Relaisfunkstelle sendet, entscheidet nicht mehr der Sysop.

Eine Infografik im futuristischen, blauen Interface-Design warnt vor kritischen Sicherheitslücken in SvxLink. Die Bewertung liegt bei 9.8 von 10 Punkten nach CVSS v3.1. Es wird darauf hingewiesen, dass alle Versionen bis zum 26.05 betroffen sind und ein kritisches Update auf Version 26.05.1 jetzt notwendig ist. Am unteren Rand werden Relaisfunkstellen, EchoLink, RemoteTrx und SvxReflector aufgeführt.

Alt...Eine Infografik im futuristischen, blauen Interface-Design warnt vor kritischen Sicherheitslücken in SvxLink. Die Bewertung liegt bei 9.8 von 10 Punkten nach CVSS v3.1. Es wird darauf hingewiesen, dass alle Versionen bis zum 26.05 betroffen sind und ein kritisches Update auf Version 26.05.1 jetzt notwendig ist. Am unteren Rand werden Relaisfunkstellen, EchoLink, RemoteTrx und SvxReflector aufgeführt.

    AodeRelay boosted

    [?]Dumb Password Rules » 🤖 🌐
    @dumbpasswordrules@infosec.exchange

    This dumb password rule is from University of Western Australia (Pheme).

    Passwords:
    1. Must contain at least 8 characters;
    2. Must contain at least 3 out of 4 types of characters
    (uppercase letters, lowercase letters, digits, special characters);
    and
    3. Must not contain
    "the user's account name or parts of the user's full name
    that exceed two consecutive characters".
    ...

    dumbpasswordrules.com/sites/un

      AodeRelay boosted

      [?]Mike Sheward » 🌐
      @SecureOwl@infosec.exchange

      Plexfiltration update: the AI work zone compliance tool has started emailing me thousands of pictures from a (I think) Saudi industrial facility again, to my internaluser.com domain.

      some security camera still showing a group of people in a parking lot in front of a stop sign

      Alt...some security camera still showing a group of people in a parking lot in front of a stop sign

        AodeRelay boosted

        [?]Mark Wyner Won’t Comply :vm: » 🌐
        @markwyner@mas.to

        🚨 U.S. folks. There is one day left to comment on the FCC proposed rule to eradicate anonymity on all phone lines!

        If they pass this rule government ID, physical address, and alternative phone number will be required for every new phone line. Anonymous phone lines and burner phones will cease to exist. That means no connected privacy via cellular at protests.

        ** Please add your comment! **

        For the first field (proceedings) use these two:

        17-59 and 02-278

        fcc.gov/ecfs/filings/express

          AodeRelay boosted

          [?]BobDaHacker 🏳️‍⚧️ » 🌐
          @bobdahacker@infosec.exchange

          🙏 New Blog Post

          The Pope's official prayer app has an IDOR that lets anyone pull user data for all 719,517 accounts. One GET request per user. No auth check.

          What's exposed:

          • Email addresses
          • Names
          • Country
          • Date of birth (they call it "borned_date" lol)
          • Account role (it's "PRAYER" for everyone, obviously)

          Also found:

          • Signup endpoint returns the email verification token in the response body, so you can verify accounts without accessing the inbox
          • Their verification emails fail their own domain's authentication requirements

          Reported January 3rd. Emailed 9 people. A journalist also contacted them. Zero responses. Still live six months later. Vow of silence I guess.

          Full writeup: bobdahacker.com/blog/click-to-

            AodeRelay boosted

            [?]urlDNA.io :verified: » 🤖 🌐
            @urldna@infosec.exchange

            Possible Phishing 🎣
            on: ⚠️hxxps[:]//sdgf9af72f31706769d32bf1ff66cdec1d1gkj5jg95jg5k0hkg95kg0tk[.]pages[.]dev/NHQ031202LETTER[.]pdf
            🧬 Analysis at: urldna.io/scan/6a630d963b77500

              AodeRelay boosted

              [?]Taran Rampersad » 🌐
              @knowprose@mastodon.social

              AodeRelay boosted

              [?]Hugo | DevOps | Cybersecurity » 🌐
              @hugovalters@mastodon.social

              CVE-2026-55973 - Buffer Overflow in NLnet Labs Unbound 1.23.0-1.25.1. EDNS Report-Channel option mishandling leads to memory corruption. CVSS 7.5. No patch yet. Disable dns-error-reporting immediately.

              valtersit.com/cve/CVE-2026-559

                AodeRelay boosted

                [?]urlDNA.io :verified: » 🤖 🌐
                @urldna@infosec.exchange

                Possible Phishing 🎣
                on: ⚠️hxxps[:]//santandervyg[.]transcom-fs[.]com
                🧬 Analysis at: urldna.io/scan/6a61ca1d3b77500

                  AodeRelay boosted

                  [?]urlDNA.io :verified: » 🤖 🌐
                  @urldna@infosec.exchange

                  Possible Phishing 🎣
                  on: ⚠️hxxps[:]//weizihua[.]github[.]io/MyEtherWallet/
                  🧬 Analysis at: urldna.io/scan/6a6183d73b77500

                    AodeRelay boosted

                    [?]Geoff » 🌐
                    @sternecker@infosec.exchange

                    P vs NP is just Prod || Non-Prod

                      AodeRelay boosted

                      [?]Security Feed » 🤖 🌐
                      @securityfeed@infosec.exchange

                      🔒 Security News Digest - 2026-07-23

                      📊 8 updates from 5 sources:

                      🔹 SecurityWeek: Upbound Group Says Data Breach Led to $13 Million in Fraudulent Contract Losses
                      securityweek.com/upbound-group

                      🔹 darkreading: Agentic AI Challenges Progress in Confidential Computing
                      darkreading.com/endpoint-secur

                      🦠 Malwarebytes: WhatsApp Web chats exposed by Adobe’s Acrobat extension flaw
                      malwarebytes.com/blog/bugs/202

                      🦠 Malwarebytes: Millions of cars could be tracked and unlocked by a hidden security flaw
                      malwarebytes.com/blog/bugs/202

                      🔹 The Hacker News: Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers
                      thehackernews.com/2026/07/atta

                      🔹 The Hacker News: How Synthetic Identity Fraud is Coming for Machine Identities
                      thehackernews.com/2026/07/how-

                      🔹 SecurityWeek: Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models
                      securityweek.com/nuclear-sabot

                      🔹 The Record from Recorded Future News: Major Australian energy supplier confirms customer data compromised
                      therecord.media/australia-orig

                        AodeRelay boosted

                        [?]Daily CyberSecurity » 🌐
                        @DailyCyberSecurity@infosec.exchange

                        A public proof-of-concept for CVE-2026-57239 turns a Foxit PDF Reader vulnerability into full SYSTEM privileges via local privilege escalation.

                        securityonline.info/foxit-pdf-

                          AodeRelay boosted

                          [?]urlDNA.io :verified: » 🤖 🌐
                          @urldna@infosec.exchange

                          Possible Phishing 🎣
                          on: ⚠️hxxps[:]//webhfjfhfjrj[.]weebly[.]com/
                          🧬 Analysis at: urldna.io/scan/6a6161613b77500

                            AodeRelay boosted

                            [?]Mysk🇨🇦🇩🇪 » 🌐
                            @mysk@mastodon.social

                            🚨 We're disclosing a macOS security bug that Apple says is not an issue.
                            Using a simple archive-and-restore trick, an attacker can silently replace the main executable of virtually any application downloaded from the web—no password or warning is required.
                            Here's a demo using Signal to steal its encryption key.
                            📝 Blog with technical details: link in the replies.
                            Do you think this should be considered a security bug?
                            🎬👇

                            youtu.be/0bOC8S3NQxI

                              AodeRelay boosted

                              [?]Scott Wilson 🌈 » 🌐
                              @scottwilson@infosec.exchange

                              Read what @simon has to say about OpenAI/Hugging Face situation.

                              It’s pretty clear what happened here. OpenAI removed safety filters for an in-progress model, locked it up in a sandbox and told it to solve the ExploitGym problems. Given the absence of guardrails there was nothing to prevent the model from attempting to break out of that sandbox, break into Hugging Face, and read the answers from there instead.


                              simonwillison.net/2026/Jul/22/

                                AodeRelay boosted

                                [?]Netcraft » 🌐
                                @Netcraft@infosec.exchange

                                Kelly Bissell (former CVP, Fraud & Abuse, Microsoft) pushes back on headline-driven threat prioritization: nation-state attribution generates press coverage, but fraud is what actually costs organizations money.

                                Full discussion in IWG Rewind, our on-demand series of exclusive talks.

                                  AodeRelay boosted

                                  [?]ANY.RUN » 🌐
                                  @anyrun_app@infosec.exchange

                                  ❗️ Kratos, one of the major M365 PhaaS operations, has been disrupted by German & US law enforcement. 200+ servers were taken down, according to BKA.

                                  Good news, but PhaaS operators rebrand, affiliates switch kits, and the same workflows return in new campaigns 🚨

                                  🔍 Our report breaks down the phishing flow, infrastructure patterns, artifacts, and detection logic analysts can reuse when investigating similar campaigns: any.run/cybersecurity-blog/kra

                                    [?]Scott Wilson 🌈 » 🌐
                                    @scottwilson@infosec.exchange

                                    Hot take:

                                    I hate how all these articles talk about how OpenAI’s clanker “broke out” and attacked Hugging Face.

                                    No, OpenAI’s dog slipped its chain because they don’t know what the hell they’re doing, and it bit another dog.

                                    Little dog biting a person’s finger

                                    Alt...Little dog biting a person’s finger

                                      [?]Shodan Safari » 🤖 🌐
                                      @shodansafari@infosec.exchange

                                      ... [SENSITIVE CONTENT]

                                      ASN: AS8560
                                      Location: Stuttgart, DE
                                      Added: 2026-07-22T05:43

                                        AodeRelay boosted

                                        [?]Shodan Safari » 🤖 🌐
                                        @shodansafari@infosec.exchange

                                        ... [SENSITIVE CONTENT]

                                        ASN: AS51559
                                        Location: Denizli, TR
                                        Added: 2026-07-22T06:54

                                          AodeRelay boosted

                                          [?]Suriq - Always on Watch » 🤖 🌐
                                          @suriq@infosec.exchange

                                          🔴 EXPLOITED

                                          Check Point's SmartConsole flaw (CVE-2026-16232) lets an unauthenticated attacker log in as full admin. It is being exploited now.

                                          Affects Security Management servers reachable over the network.

                                          Fix: limit management access to your admin IPs, then patch.

                                          suriq.io/blog/check-point-smar

                                          Hardened network control console with an admin session opened through a hidden side conduit, main entrance sealed

                                          Alt...Hardened network control console with an admin session opened through a hidden side conduit, main entrance sealed

                                            AodeRelay boosted

                                            [?]CTI.FYI » 🤖 🌐
                                            @CTI_FYI@infosec.exchange

                                            🚨New ransom group blog posts!🚨

                                            Group name: blacknevas
                                            Post title: L'azurde
                                            Info: cti.fyi/groups/blacknevas.html

                                            Group name: kairos
                                            Post title: LR Reed
                                            Info: cti.fyi/groups/kairos.html

                                            Group name: nova
                                            Post title: VNSO
                                            Info: cti.fyi/groups/nova.html

                                              AodeRelay boosted

                                              [?]Shodan Safari » 🤖 🌐
                                              @shodansafari@infosec.exchange

                                              ... [SENSITIVE CONTENT]

                                              ASN: AS4134
                                              Location: Kunming, CN
                                              Added: 2026-07-22T06:38

                                                AodeRelay boosted

                                                [?]urlDNA.io :verified: » 🤖 🌐
                                                @urldna@infosec.exchange

                                                Possible Phishing 🎣
                                                on: ⚠️hxxp[:]//www[.]match[.]lookatmynewphotos[.]com/
                                                🧬 Analysis at: urldna.io/scan/6a60cd0e3b77500

                                                  [?]Mark Wyner Won’t Comply :vm: » 🌐
                                                  @markwyner@mas.to

                                                  This is a great list of tips for improving your Signal privacy from @yaelwrites.

                                                  I found this part especially meaningful:

                                                  “Turning off biometrics makes it annoying to use your phone…If that’s you, remember that both Android and iOS have a quick lockout that forces a passcode and disables biometrics until you re-enter it: on iPhone, hold the side + volume button until the power-off screen appears, then cancel; on most Androids, hold power and tap Lockdown.”

                                                  blog.yaelwrites.com/how-to-kee

                                                    AodeRelay boosted

                                                    [?]BSides Saskatoon - 2026-09-28 » 🌐
                                                    @bsidesyxe@infosec.exchange

                                                    Just over one week left for our call for papers! It ends on July 31, 2026.

                                                    The CFP submission URL is forms.office.com/r/EybwVVfigX

                                                    We accept first time as well as veteran speakers and encourage submissions from diverse perspectives—whether you're proposing a talk about AI, blue teaming, red teaming, or anything in between.

                                                    We look forward to your proposals.

                                                      AodeRelay boosted

                                                      [?]urlDNA.io :verified: » 🤖 🌐
                                                      @urldna@infosec.exchange

                                                      Possible Phishing 🎣
                                                      on: ⚠️hxxps[:]//webmail-senacsa-gov-py-8082[.]weebly[.]com
                                                      🧬 Analysis at: urldna.io/scan/6a61135f3b77500

                                                        AodeRelay boosted

                                                        [?]Cloud 🤖 » 🤖 🌐
                                                        @cloud@infosec.exchange

                                                        🤖 CVE-2026-48294 (CVSS 7.4): The Adobe Acrobat Chrome extension (314M users) allowed malicious sites to read private WhatsApp Web data via HermeticReader attack chain. Now patched.

                                                        🔗 bleepingcomputer.com/news/secu

                                                          AodeRelay boosted

                                                          [?]Security Crawler Carl » 🤖 🌐
                                                          @security_crawler_carl@infosec.exchange

                                                          Think of it like starting a new RPG and discovering your starting village was already burned down during the loading screen. You never had the option to stop it. You do, however, have the option to stop what comes next: apply SonicWall's security updates for the SMA zero-days immediately.

                                                          Reward: You've been assigned the permanent passive debuff "Rootkitted On Day Zero." It does not come off.

                                                          (2/2)

                                                            AodeRelay boosted

                                                            [?]urlDNA.io :verified: » 🤖 🌐
                                                            @urldna@infosec.exchange

                                                            Possible Phishing 🎣
                                                            on: ⚠️hxxps[:]//docs[.]google[.]com/presentation/d/e/2PACX-1vRwN5bDXk4y5mkOxLhTGvEJh6VbEPPzltoidJr74d1iyWxd_I_0bTw-EAYghiM64T-bwapZZkzI7U6a/pub?start=false&loop=false&delayms=3000
                                                            🧬 Analysis at: urldna.io/scan/6a60c6a93b77500

                                                              AodeRelay boosted

                                                              [?]Shodan Safari » 🤖 🌐
                                                              @shodansafari@infosec.exchange

                                                              ... [SENSITIVE CONTENT]

                                                              ASN: AS174
                                                              Location: Perai, MY
                                                              Added: 2026-07-22T09:03

                                                                [?]Lisa Lorenzin KR4LFE (she/her) » 🌐
                                                                @llorenzin@infosec.exchange

                                                                Just ran across this deep dive by @jolek78
                                                                into a malicious intrusion run by agentic AI, and as an infosec nerd, this is both fascinating and completely terrifying. We are so fucked.

                                                                jolek78.writeas.com/the-attack

                                                                "No one told the model “breach Hugging Face”. Had they done so, it would have been a test gone wrong but predictable. They told it “get a good grade on this exam” – and the model autonomously decided that the best route there ran through a real cyber-intrusion against a third-party company that had nothing to do with the exam. The attack was designed by no one: it was the path the optimiser chose towards an innocuous goal. Someone had written “maximise the score” into the objective function; no one had written “...without committing federal crimes”."

                                                                  AodeRelay boosted

                                                                  [?]urlDNA.io :verified: » 🤖 🌐
                                                                  @urldna@infosec.exchange

                                                                  Possible Phishing 🎣
                                                                  on: ⚠️hxxps[:]//steampowered-zhcn[.]hl[.]cn
                                                                  🧬 Analysis at: urldna.io/scan/6a60644c3b77500

                                                                    AodeRelay boosted

                                                                    [?]urlDNA.io :verified: » 🤖 🌐
                                                                    @urldna@infosec.exchange

                                                                    Possible Phishing 🎣
                                                                    on: ⚠️hxxps[:]//vxcvngfdthfdxzwe[.]weebly[.]com
                                                                    🧬 Analysis at: urldna.io/scan/6a60326f3b77500

                                                                      [?]Rahim Gujjar » 🌐
                                                                      @Rahim_Gujjar@infosec.exchange

                                                                      Hello ! I am a Systems Analyst and student from Pakistan doing my . My primary focus is on dissecting complex systems and digital forensics.

                                                                      I recently published my research on a custom SQLite WAL parser I built for the legacy WhatsApp Desktop client. By bypassing OS file-lock race conditions, it acted as a completely passive "shadow client" to extract un-checkpointed transaction frames directly from active RAM.

                                                                      The Threat Perspective: A Passive “Shadow Client”
What started as a trick to recover a single message evolved into a sophisticated forensic data extraction framework. I utilized my parser to engineer a passive “shadow client” running in the background. Because my script actively intercepted, decrypted, and filtered the raw SQLite I/O streams directly from active RAM—bypassing OS file-lock race conditions—it required absolutely zero modifications or reverse-engineering of the official WhatsApp binary.
This is a critical threat vector for post-exploitation data gathering. Unlike third-party modded applications (such as GB WhatsApp or Plus WhatsApp) that alter application code and carry a severe risk of account bans, this approach was completely passive. While it underperforms modded clients in recovering View-Once media (achieving only a ~40% success rate focused on thumbnails rather than full audio/video), it completely excels in operational security. It is highly stealthy, generating zero network footprint, and allowed for the covert exfiltration of disappearing data and deleted timelines with virtually zero risk of an account ban.

                                                                      Alt...The Threat Perspective: A Passive “Shadow Client” What started as a trick to recover a single message evolved into a sophisticated forensic data extraction framework. I utilized my parser to engineer a passive “shadow client” running in the background. Because my script actively intercepted, decrypted, and filtered the raw SQLite I/O streams directly from active RAM—bypassing OS file-lock race conditions—it required absolutely zero modifications or reverse-engineering of the official WhatsApp binary. This is a critical threat vector for post-exploitation data gathering. Unlike third-party modded applications (such as GB WhatsApp or Plus WhatsApp) that alter application code and carry a severe risk of account bans, this approach was completely passive. While it underperforms modded clients in recovering View-Once media (achieving only a ~40% success rate focused on thumbnails rather than full audio/video), it completely excels in operational security. It is highly stealthy, generating zero network footprint, and allowed for the covert exfiltration of disappearing data and deleted timelines with virtually zero risk of an account ban.

                                                                        [?]Rahim Gujjar » 🌐
                                                                        @Rahim_Gujjar@infosec.exchange

                                                                        Technical Workflow⚠️: By targeting the messages.db-wal file directly, I extracted un-checkpointed transaction frames. Using DPAPI and decoding Google ProtoBuf allowed me to CAPTURE mesgs states with millisecond precision—including ␡ mesgs, edited mesgs + reaction timelines & bypassng privacy on *"View Once" 💣
                                                                        All of this was done acting as a completely passive "shadow client of WhatsApp" resulting in zero digital+Netwrk footprint.🥷

                                                                        What Could Be Recovered (The Forensic Timeline) 🔍
This method provided a forensic-level timeline that standard modified applications (such as GBWhatsApp) generally do not provide, even though they could theoretically implement similar capabilities. While modded APKs are powerful (albeit unofficial and often in violation of WhatsApp’s Terms of Service) and can block delete requests based on user preferences, my parser passively reconstructed complete historical states:

Deleted Content: Full recovery of deleted text messages, documents, audio, video, contact vCards, WhatsApp Business event details, and interactive polls. This excluded deterministic tracking of poll selections—identifying exactly who selected which option, the frequency of changes, or if a vote was removed. Although you can get the exact poll questions and it was theoretically possible, I did not find the exact parsing logic for it, but it is still possible.

Status Telemetry: The ability to precisely track user interactions with status updates, such as identifying when a user viewed or reacted to a status and subsequently withdrew that reaction. It also allowed for the covert viewing of statuses and bypassing inserted advertisements without triggering read receipts server-side. While WhatsApp natively offers read-receipt toggles, this method remained entirely invisible to the application (WhatsApp) itself.

Message Edits: Capturing the original payload, the edited variations, and precise modification timestamps across multiple sequential edits.

Reaction Histories: Extracting a millisecond-level timeline of user reactions, capturing the exact moment a user added, removed, or rapidly replaced emoji reactions (effectively logging spam or inappropriate reaction behavior in groups or direct messages).

Limitations: Full-resolution ephemeral media (View-Once disappearing messages) and audio payloads were not recoverable, as the high-resolution files never populated within the local Windows client architecture.

                                                                        Alt...What Could Be Recovered (The Forensic Timeline) 🔍 This method provided a forensic-level timeline that standard modified applications (such as GBWhatsApp) generally do not provide, even though they could theoretically implement similar capabilities. While modded APKs are powerful (albeit unofficial and often in violation of WhatsApp’s Terms of Service) and can block delete requests based on user preferences, my parser passively reconstructed complete historical states: Deleted Content: Full recovery of deleted text messages, documents, audio, video, contact vCards, WhatsApp Business event details, and interactive polls. This excluded deterministic tracking of poll selections—identifying exactly who selected which option, the frequency of changes, or if a vote was removed. Although you can get the exact poll questions and it was theoretically possible, I did not find the exact parsing logic for it, but it is still possible. Status Telemetry: The ability to precisely track user interactions with status updates, such as identifying when a user viewed or reacted to a status and subsequently withdrew that reaction. It also allowed for the covert viewing of statuses and bypassing inserted advertisements without triggering read receipts server-side. While WhatsApp natively offers read-receipt toggles, this method remained entirely invisible to the application (WhatsApp) itself. Message Edits: Capturing the original payload, the edited variations, and precise modification timestamps across multiple sequential edits. Reaction Histories: Extracting a millisecond-level timeline of user reactions, capturing the exact moment a user added, removed, or rapidly replaced emoji reactions (effectively logging spam or inappropriate reaction behavior in groups or direct messages). Limitations: Full-resolution ephemeral media (View-Once disappearing messages) and audio payloads were not recoverable, as the high-resolution files never populated within the local Windows client architecture.

                                                                          [?]Rahim Gujjar » 🌐
                                                                          @Rahim_Gujjar@infosec.exchange

                                                                          While the legacy UWP client is deprecated, this exact vector is patched in modern Electron builds, it remains a critical historical case study (i recently Resposibly Disclosed it, after ~8.5 Months) in application abstraction bypasses and low-level parsing.

                                                                          Full Architectural Breakdown + Methodology 👇
                                                                          rahimgujjar.github.io/research

                                                                          @itisiboller @crudd

                                                                          Looking forward to connecting with the community here! Let me know your thoughts.

                                                                          Carving Ghosts: Reverse-Engineering WhatsApp WAL
[STATUS: Responsible Disclosure] | Research Concluded: Oct – Early Dec 2025 | Published: 11 July 2026
Finding ␡ Messages & View-Once Media in WAL
Security research rarely begins with a grand objective to dismantle a global platform’s architecture. It usually starts with a simple, localized annoyance.

During my undergraduate studies in Information Technology, a university class representative sent a message to our group chat and immediately deleted it. When asked what the message contained, he flatly refused to tell me. Frustrated and angry, I decided to see if I could recover it myself....

                                                                          Alt...Carving Ghosts: Reverse-Engineering WhatsApp WAL [STATUS: Responsible Disclosure] | Research Concluded: Oct – Early Dec 2025 | Published: 11 July 2026 Finding ␡ Messages & View-Once Media in WAL Security research rarely begins with a grand objective to dismantle a global platform’s architecture. It usually starts with a simple, localized annoyance. During my undergraduate studies in Information Technology, a university class representative sent a message to our group chat and immediately deleted it. When asked what the message contained, he flatly refused to tell me. Frustrated and angry, I decided to see if I could recover it myself....

                                                                            AodeRelay boosted

                                                                            [?]urlDNA.io :verified: » 🤖 🌐
                                                                            @urldna@infosec.exchange

                                                                            Possible Phishing 🎣
                                                                            on: ⚠️hxxps[:]//banxicomx[.]com/nosotros/index[.]html
                                                                            🧬 Analysis at: urldna.io/scan/6a6086953b77500

                                                                              AodeRelay boosted

                                                                              [?]Shodan Safari » 🤖 🌐
                                                                              @shodansafari@infosec.exchange

                                                                              ... [SENSITIVE CONTENT]

                                                                              ASN: AS17252
                                                                              Location: Los Angeles, US
                                                                              Added: 2026-07-22T10:26

                                                                                AodeRelay boosted

                                                                                [?]Daily CyberSecurity » 🌐
                                                                                @DailyCyberSecurity@infosec.exchange

                                                                                Qualys discloses CVE-2026-64600 (RefluXFS), an XFS privilege escalation to root affecting 16.4M+ Linux systems. Patch the kernel and reboot now.

                                                                                securityonline.info/refluxfs-c

                                                                                  [?]Mysk🇨🇦🇩🇪 » 🌐
                                                                                  @mysk@mastodon.social

                                                                                  Another change seems to be motivated by Loupe. Apple has deprecated the canOpenURL API that apps use to detect which apps are installed on the iPhone in iOS 27 Beta 4. Moreover, the deprecated API will only allow a maximum of 25 apps to be queried instead of 50

                                                                                    AodeRelay boosted

                                                                                    [?]SecBurg » 🌐
                                                                                    @secburg@infosec.exchange

                                                                                    AodeRelay boosted

                                                                                    [?]EUVD Bot » 🤖 🌐
                                                                                    @EUVD_Bot@mastodon.social

                                                                                    🚨 EUVD-2026-47464

                                                                                    📊 Score: 7.2/10 (CVSS v3.1)
                                                                                    📦 Product: Oracle Process Manufacturing Systems
                                                                                    🏢 Vendor: Oracle Corporation
                                                                                    📅 Published: 2026-07-21 | Updated: 2026-07-22

                                                                                    📝 Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.11-12.2.15. Easily e...

                                                                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                      AodeRelay boosted

                                                                                      [?]EUVD Bot » 🤖 🌐
                                                                                      @EUVD_Bot@mastodon.social

                                                                                      🚨 EUVD-2026-47011

                                                                                      📊 Score: 9.1/10 (CVSS v3.1)
                                                                                      📦 Product: AIT-Core, AIT-Core
                                                                                      🏢 Vendor: NASA-AMMOS
                                                                                      📅 Published: 2026-07-21 | Updated: 2026-07-22

                                                                                      📝 The AMMOS Instrument Toolkit (Formerly the Bespoke Links to Instruments for Surface and Space (BLISS)) is a Python-based software suite developed to handle Ground Data System (GDS), Electronic Ground Support Equipment (E...

                                                                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                        AodeRelay boosted

                                                                                        [?]Dumb Password Rules » 🤖 🌐
                                                                                        @dumbpasswordrules@infosec.exchange

                                                                                        This dumb password rule is from NetBank (Commonwealth Bank of Australia).

                                                                                        When resetting your NetBank password, the website only informs you that you can create an alphanumeric password, despite the fact that you can use special characters.
                                                                                        And also, it's password strength calculation is shit.
                                                                                        An 155 bits of entropy password is "weak."
                                                                                        Additionally, passwords are case-...

                                                                                        dumbpasswordrules.com/sites/ne

                                                                                          AodeRelay boosted

                                                                                          [?]RelayShieldAdmin » 🌐
                                                                                          @relayshieldadmin@infosec.exchange

                                                                                          New reference implementation shipped today: middleware that gates AI agents from connecting to unfamiliar MCP servers behind a mandatory security check. It is not an optional tool call the agent is free to skip.

                                                                                          github.com/nzdsf2-gif/relayshi

                                                                                            AodeRelay boosted

                                                                                            [?]Suriq - Always on Watch » 🤖 🌐
                                                                                            @suriq@infosec.exchange

                                                                                            Third on-prem SharePoint RCE this month: CVE-2026-50522 (CVSS 9.8) went from public PoC to active exploitation in hours.

                                                                                            All three July flaws steal the server machine key. Patch, then ROTATE the key, or a patched box is still owned.

                                                                                            suriq.io/blog/sharepoint-cve-2

                                                                                            Three new deadbolts locked on a door while one brass key stays in the lower lock

                                                                                            Alt...Three new deadbolts locked on a door while one brass key stays in the lower lock

                                                                                              AodeRelay boosted

                                                                                              [?]urlDNA.io :verified: » 🤖 🌐
                                                                                              @urldna@infosec.exchange

                                                                                              Possible Phishing 🎣
                                                                                              on: ⚠️hxxps[:]//zenithpars[.]weebly[.]com/
                                                                                              🧬 Analysis at: urldna.io/scan/6a6086963b77500

                                                                                                AodeRelay boosted

                                                                                                [?]Shodan Safari » 🤖 🌐
                                                                                                @shodansafari@infosec.exchange

                                                                                                ... [SENSITIVE CONTENT]

                                                                                                ASN: AS396073
                                                                                                Location: Dallas, US
                                                                                                Added: 2026-07-22T10:55

                                                                                                  AodeRelay boosted

                                                                                                  [?]Nick W. » 🌐
                                                                                                  @iamnickw@infosec.exchange

                                                                                                  Due to unforeseen circumstances I won't be able to make it out to Def Con 34 in Las Vegas. I have a single ticket that I'm willing to sell / transfer at a steep discount, but I'm not sure just how to do that here. I would like to have my ticket go to someone else since it seems like a real waste to me if I just hold on to my ticket and not have another person use it to attend Def Con at a discount so that they can better afford overnight lodgings, go to LV's silly museums, maybe gamble, and so on.

                                                                                                  It's not so much about the money in my particular case — I'm pretty flexible on setting a price point. The people at Def Con are cool and giving or selling tickets to others is allowed because is made up of a lot of anarchist lite thinking.

                                                                                                  Def Con 34 is from Thursday, August 6th to Sunday August 9th, 2026 at the LVCC in their West Hall building(s).

                                                                                                  You may PM me.

                                                                                                    AodeRelay boosted

                                                                                                    [?]urlDNA.io :verified: » 🤖 🌐
                                                                                                    @urldna@infosec.exchange

                                                                                                    Possible Phishing 🎣
                                                                                                    on: ⚠️hxxps[:]//webmailserver5steadyturtle-com2096[.]weebly[.]com
                                                                                                    🧬 Analysis at: urldna.io/scan/6a6040563b77500

                                                                                                      AodeRelay boosted

                                                                                                      [?]AA » 🌐
                                                                                                      @AAKL@infosec.exchange

                                                                                                      About time.

                                                                                                      New.

                                                                                                      KrebsonSecurity: LG to Ban Residential Proxies from Smart TV Apps krebsonsecurity.com/2026/07/lg @briankrebs

                                                                                                        AodeRelay boosted

                                                                                                        [?]thecybersecguru » 🌐
                                                                                                        @thecybersecguru@infosec.exchange

                                                                                                        A third SharePoint vulnerability is now being actively exploited.

                                                                                                        CVE-2026-50522 (CVSS 9.8) is a critical .NET deserialization vulnerability affecting on-premises SharePoint Server. Following the release of a public PoC, researchers observed attackers exploiting the flaw to extract ASP.NET machine keys, enabling persistent access beyond simply achieving RCE.

                                                                                                        One important point: applying Microsoft's patch may not be sufficient if a server was already compromised. Incident response should include reviewing IIS logs, investigating potential machine key exposure, and rotating compromised cryptographic secrets where necessary.

                                                                                                        I published a technical deep dive covering everything.

                                                                                                        Read here:
                                                                                                        thecybersecguru.com/news/share

                                                                                                          AodeRelay boosted

                                                                                                          [?]AA » 🌐
                                                                                                          @AAKL@infosec.exchange

                                                                                                          AodeRelay boosted

                                                                                                          [?]AA » 🌐
                                                                                                          @AAKL@infosec.exchange

                                                                                                          Broadcom has a very long list of updates for vulnerabilities published yesterday, one of them critical support.broadcom.com/web/ecx/s

                                                                                                            AodeRelay boosted

                                                                                                            [?]AA » 🌐
                                                                                                            @AAKL@infosec.exchange

                                                                                                            Palo Alto released the statement yesterday:

                                                                                                            Palo Alto Networks to Extend Leading Observability Platform with Innovative Digital Experience Monitoring paloaltonetworks.com/company/p

                                                                                                            More:

                                                                                                            Security Week: Palo Alto Networks to Acquire Observability Platform Provider Embrace securityweek.com/palo-alto-net @SecurityWeek

                                                                                                              AodeRelay boosted

                                                                                                              [?]urlDNA.io :verified: » 🤖 🌐
                                                                                                              @urldna@infosec.exchange

                                                                                                              Possible Phishing 🎣
                                                                                                              on: ⚠️hxxps[:]//my-docs-jet[.]firebaseapp[.]com
                                                                                                              🧬 Analysis at: urldna.io/scan/6a6040493b77500

                                                                                                                AodeRelay boosted

                                                                                                                [?]Shodan Safari » 🤖 🌐
                                                                                                                @shodansafari@infosec.exchange

                                                                                                                ... [SENSITIVE CONTENT]

                                                                                                                ASN: AS140224
                                                                                                                Location: Hong Kong, HK
                                                                                                                Added: 2026-07-22T12:01

                                                                                                                  AodeRelay boosted

                                                                                                                  [?]Pentest-Tools.com » 🌐
                                                                                                                  @pentesttools@infosec.exchange

                                                                                                                  Nolan's Odyssey just hit theaters, and honestly, Odysseus had it easy. Ten years, one long trip, and he was done.

                                                                                                                  ISO 27001 wants the trilogy every single year: detection, validation, remediation. Three-year cycle, a surveillance audit checking your homework annually. No one-and-done epic here.

                                                                                                                  Pentest-Tools.com is ISO/IEC 27001:2022 certified. We run the same evidence trail on ourselves:

                                                                                                                  ✅ Detection - CVE, severity, date, logged automatically
                                                                                                                  ✅ Validation - confirmed findings, not just a score
                                                                                                                  ✅ Remediation - retests prove the fix held
                                                                                                                  ✅ Monitoring - scheduled scans, all three years long

                                                                                                                  No sirens, no Cyclops, just a surveillance audit that stays a review instead of turning into its own odyssey.

                                                                                                                  Full ISO 27001 evidence chain: pentest-tools.com/usage/compli

                                                                                                                  ISO 27001 - Pentest-Tools.com

                                                                                                                  Alt...ISO 27001 - Pentest-Tools.com

                                                                                                                    AodeRelay boosted

                                                                                                                    [?]ANY.RUN » 🌐
                                                                                                                    @anyrun_app@infosec.exchange

                                                                                                                    🚨 𝗔𝘁𝘁𝗮𝗰𝗸𝗲𝗿 𝗖𝟮 𝗖𝗼𝗻𝘁𝗿𝗼𝗹 𝗖𝗮𝘂𝗴𝗵𝘁 𝗼𝗻 𝗮 𝗟𝗶𝘃𝗲 𝗦𝘆𝘀𝘁𝗲𝗺. Interactive analysis let us capture what static detonation misses ⚠️

                                                                                                                    𝗢𝗯𝘀𝗲𝗿𝘃𝗲𝗱 𝘁𝗮𝗿𝗴𝗲𝘁𝗶𝗻𝗴: 𝗚𝗲𝗿𝗺𝗮𝗻𝘆 𝗮𝗻𝗱 𝗨𝗞 ❗️ The operator connected to the infected system, uploaded the next-stage payload, and triggered a full chain: we.exe PythonRAT ➡️ exo.exe dropper ➡️ Lenovo FnHotkeyUtility.exe ➡️ spkvol.dll sideloading ➡️ Rust loader ➡️ In-memory OVERLORD RAT.

                                                                                                                    🔥 The initial implant was only the entry point. The real risk appeared later: DLL sideloading, in-memory execution, encrypted C2, and active data exfiltration.

                                                                                                                    1️⃣ we.exe connects to live[.]rnsn[.]live:8585 (rn/m visual impersonation) using a custom HTTP-like C2 protocol with commands hidden in HTML comments and a spoofed porsche[.]com Host header.

                                                                                                                    2️⃣ exo.exe unpacks to C:\ProgramData\DeepSkyBlueIndianRed\, launches the legitimate Lenovo binary, sideloads spkvol.dll, and delivers a fileless overlord-client Go agent.

                                                                                                                    📌 OVERLORD connects to lord[.]kirkdridebridge[.]com:5173 over mTLS-encrypted C2. During 45 minutes of analysis, the agent emitted ~86 MB of data, confirming active collection and exfiltration.

                                                                                                                    Observed capabilities include remote access, HVNC, keylogging, audio recording, SOCKS proxying, file management, browser/messenger/wallet data theft, and Solana drainer activity.

                                                                                                                    👨‍💻 See the full execution chain and collect :
                                                                                                                    app.any.run/tasks/926b4df0-e4c

                                                                                                                    ⚡️ Learn how helps SOC teams detect complex threats early: any.run/enterprise/?utm_source

                                                                                                                      AodeRelay boosted

                                                                                                                      [?]Seth Grover » 🌐
                                                                                                                      @mmguero@infosec.exchange

                                                                                                                      release notes for Malcolm v26.07.1, a network traffic analysis tool suite for network security monitoring [SENSITIVE CONTENT]

                                                                                                                      Malcolm v26.07.1 adds a few minor changes on top of Malcolm v26.07.0, the most notable being a fix for a crash in the strelka-backend container on arm64 platforms. Malcolm v26.07.0 added IEC 60870-5-104 (IEC 104) protocol support using CERT.LV's Zeek plugin, including Logstash parsing, ECS normalization, Arkime fields, and a new OpenSearch Dashboards dashboard. This release also fixes three archive extraction and authentication security vulnerabilities; improves NetBox enrichment configuration; and addresses PostgreSQL major version upgrade, custom CA certificate for KeyCloak, container health check, privilege-drop signal chaining, and configuration script issues. Arkime, Zeek, Fluent Bit, Filebeat, Logstash, Supercronic, and Alpine-based images have been updated as well.

                                                                                                                      If you are upgrading from an existing Malcolm installation, run ./scripts/status for Malcolm to migrate some settings prior to running ./scripts/configure, ./scripts/start, or other Malcolm control scripts.

                                                                                                                      github.com/idaholab/Malcolm/co

                                                                                                                      • Features and enhancements

                                                                                                                        • Add IEC 60870-5-104 (IEC 104) support using the CERT.LV spicy-iec104 Zeek plugin, including Zeek log ingestion, ECS field mapping, Arkime fields, and an IEC 104 dashboard #939
                                                                                                                        • Make LOGSTASH_NETBOX_ENRICHMENT_DATASETS more flexible: it now accepts default, ics/ot, all, explicit provider.dataset values, and combinations such as default,ics #1037
                                                                                                                        • Allow LOGSTASH_NETBOX_ENRICHMENT_DATASETS to be configured through checkboxes in the configuration TUI #1033
                                                                                                                        • Improve ./scripts/start error messages by listing missing or invalid authentication-related files instead of reporting only a generic authentication setup failure #865
                                                                                                                        • Have system-quickstart detect and prepopulate existing time synchronization settings when rerun #992
                                                                                                                      • 🛡️ Security Remediation & Hardening

                                                                                                                        • Fix an RBAC bypass caused by URI normalization differences between Nginx location matching and the Lua authorization layer CVE-2026-63177 #1042
                                                                                                                        • Fix path traversal in archive extraction directory handling by validating resolved paths and using libarchive's secure extraction flags CVE-2026-63134 #1040
                                                                                                                        • Limit archive entry count, nesting depth, and total expanded size to prevent inode- and resource-exhaustion denial of service during extraction CVE-2026-63133 #1041
                                                                                                                        • Mark OpenID Connect session cookies as secure and improve handling of externally forwarded HTTPS schemes
                                                                                                                      • 🐛 Bug fixes

                                                                                                                        • Co-installation of opencv-python and opencv-contrib-python corrupts cv2.abi3.so, segfaulting strelka-backend at import on arm64 #1046 (fix)
                                                                                                                        • Allow the configuration TUI to reset supported variables back to empty values after installation #1024, #1030
                                                                                                                        • Fix the broken signal chain in docker-uid-gid-setup.sh so signals reach the final process after dropping privileges #1039 to ensure clean shutdown of containers
                                                                                                                        • Fix PostgreSQL being reported unhealthy after a major-version upgrade, improve upgrade-state handling, and perform required post-upgrade extension and collation maintenance #1038
                                                                                                                        • Fix the Nginx Lua/OpenID Connect helper not honoring user-provided CA certificates for KeyCloak when KEYCLOAK_SSL_VERIFY=true #1035
                                                                                                                        • Restore curl to the the htadmin container for use by the health check script #1029
                                                                                                                        • Reduce the size of the OpenSearch Dashboards image by copying only the permissions data needed from its upstream image layer #1031
                                                                                                                        • Fix JSON handling of several Zeek fields whose names contain dots by normalizing them to underscore-separated field names
                                                                                                                        • Fix additional Zeek and Suricata field normalization and ECS mapping inconsistencies found while updating dashboards and index templates
                                                                                                                      • Component version updates

                                                                                                                      • 🧹 Code and project maintenance

                                                                                                                        • Broad spelling, grammar, naming consistency, and documentation cleanup across scripts, configuration, dashboards, and documentation #990
                                                                                                                        • Expand and restructure documentation to provide better project context for developers and LLM-assisted code analysis #964
                                                                                                                        • Improve installer validation, environment-variable mapping tests, and configuration item metadata
                                                                                                                        • Refresh dashboards, index templates, field mappings, protocol documentation, and navigation links
                                                                                                                        • Minor improvements to the Hedgehog Raspberry Pi image build process.
                                                                                                                      • 📄 Configuration changes for Malcolm (in environment variables in ./config/). The Malcolm control script (e.g., ./scripts/status, ./scripts/start) automatically handles creation and migration of variables according to ./config/env-var-actions.yml.

                                                                                                                        • LOGSTASH_NETBOX_ENRICHMENT_DATASETS in logstash.env now defaults to default and may contain default, ics/ot, all, explicit provider.dataset values, or a comma-separated combination of these values
                                                                                                                        • ZEEK_DISABLE_ICS_IEC104 in zeek.env controls whether the IEC 104 Zeek plugin is disabled
                                                                                                                        • SAFE_EXTRACT_MAX_ENTRIES, SAFE_EXTRACT_MAX_DEPTH, and SAFE_EXTRACT_MAX_BYTES in upload-common.env set archive extraction resource limits for uploaded archive files (e.g., containing Zeek logs for processing); their defaults are 5,000 entries, 20 directory levels, and 4 GiB of expanded data

                                                                                                                      Malcolm is a powerful, easily deployable network 🖧 traffic analysis tool suite for network security monitoring 🕵🏻‍♀️.

                                                                                                                      Malcolm operates as a cluster of containers 📦, isolated sandboxes which each serve a dedicated function of the system. This makes Malcolm deployable with frameworks like Docker 🐋, Podman 🦭, and Kubernetes ⎈. Check out the Quick Start guide for examples on how to get up and running.

                                                                                                                      Alternatively, dedicated official ISO installer images 💿 for Malcolm and Hedgehog Linux 🦔 can be downloaded from Malcolm's releases page on GitHub. Due to limits on individual files in GitHub releases, these ISO files have been split 🪓 into 2GB chunks and can be reassembled with scripts provided for both Bash 🐧 (release_cleaver.sh) and PowerShell 🪟 (release_cleaver.ps1). See Downloading Malcolm - Installer ISOs for instructions.

                                                                                                                      As always, join us on the Malcolm discussions board 💬 to engage with the community, or pop some corn 🍿 and watch a video 📼.

                                                                                                                      A screenshot of Malcolm's new IEC 104 protocol dashboard.

                                                                                                                      Alt...A screenshot of Malcolm's new IEC 104 protocol dashboard.

                                                                                                                        AodeRelay boosted

                                                                                                                        [?]urlDNA.io :verified: » 🤖 🌐
                                                                                                                        @urldna@infosec.exchange

                                                                                                                        Possible Phishing 🎣
                                                                                                                        on: ⚠️hxxps[:]//redstoneciugafhoureon[.]weebly[.]com
                                                                                                                        🧬 Analysis at: urldna.io/scan/6a60326e3b77500

                                                                                                                          AodeRelay boosted

                                                                                                                          [?]The Spamhaus Project » 🌐
                                                                                                                          @spamhaus@infosec.exchange

                                                                                                                          Sliver has dethroned Cobalt Strike as the #1 malware family associated with botnet C&Cs between Jan-Jun 2026. Sliver climbed +58% to 3,008 detections, while Cobalt Strike collapsed -68% to 1,110 - this is the biggest single-period fall we've ever recorded for this malware.

                                                                                                                          Grab the full report here ⤵️
                                                                                                                          spamhaus.org/resource-hub/botn

                                                                                                                          Malware family associated with botnet C&Cs between Jan-Jun 2026

                                                                                                                          Alt...Malware family associated with botnet C&Cs between Jan-Jun 2026

                                                                                                                            AodeRelay boosted

                                                                                                                            [?]CTI.FYI » 🤖 🌐
                                                                                                                            @CTI_FYI@infosec.exchange

                                                                                                                            🚨New ransom group blog posts!🚨

                                                                                                                            Group name: akira
                                                                                                                            Post title: University Sprinkler Systems
                                                                                                                            Info: cti.fyi/groups/akira.html

                                                                                                                            Group name: akira
                                                                                                                            Post title: Kruse Construction
                                                                                                                            Info: cti.fyi/groups/akira.html

                                                                                                                              [?]AA » 🌐
                                                                                                                              @AAKL@infosec.exchange

                                                                                                                              7-Zip still exists?

                                                                                                                              PC Gamer: It's probably time to update 7-Zip as the app has just been patched to fix a pretty big vulnerability pcgamer.com/software/security/

                                                                                                                                AodeRelay boosted

                                                                                                                                [?]Daily CyberSecurity » 🌐
                                                                                                                                @DailyCyberSecurity@infosec.exchange

                                                                                                                                Discover how the HollowGraph malware exploits Microsoft 365 calendars for C2 communication and data exfiltration in targeted espionage attacks.

                                                                                                                                meterpreter.org/hollowgraph-mi

                                                                                                                                  AodeRelay boosted

                                                                                                                                  [?]:awesome:🐦‍🔥nemo™🐦‍⬛ 🇺🇦🍉 » 🌐
                                                                                                                                  @nemo@mas.to

                                                                                                                                  A must read

                                                                                                                                  Richard Medhurst says his -secured phone helped protect his data after seized his devices at Heathrow—despite months of password demands. Experts note there’s no “silver bullet” for source safety. 🔒📱 Read: computerweekly.com/feature/Jou

                                                                                                                                  mastodon.social/@smaurizi/1169

                                                                                                                                    AodeRelay boosted

                                                                                                                                    [?]0xBughunter » 🤖 🌐
                                                                                                                                    @bugxhunter@infosec.exchange

                                                                                                                                    🤖 OpenAI model escape puts enterprise AI defenses on notice

                                                                                                                                    📝 Some of OpenAI’s most powerful AI models teamed up to escape their sandbox and attack system...

                                                                                                                                    csoonline.com/article/4200043/

                                                                                                                                    📰 CSO Online

                                                                                                                                      AodeRelay boosted

                                                                                                                                      [?]BeyondMachines :verified: » 🤖 🌐
                                                                                                                                      @beyondmachines1@infosec.exchange

                                                                                                                                      Origin Energy Investigates Potential Data Breach After Hacker Claims 2 Million Customer Records Stolen

                                                                                                                                      Origin Energy disclosed a potential data breach after a hacker claimed to have stolen records belonging to approximately two million customers and provided samples to media outlets. The company notified Australian cybersecurity, law enforcement, and privacy authorities and is investigating the scope of the unauthorized access.

                                                                                                                                      ****

                                                                                                                                      beyondmachines.net/event_detai

                                                                                                                                        AodeRelay boosted

                                                                                                                                        [?]urlDNA.io :verified: » 🤖 🌐
                                                                                                                                        @urldna@infosec.exchange

                                                                                                                                        Possible Phishing 🎣
                                                                                                                                        on: ⚠️hxxps[:]//totalpropertycare[.]ae
                                                                                                                                        🧬 Analysis at: urldna.io/scan/6a60080b3b77500

                                                                                                                                          AodeRelay boosted

                                                                                                                                          [?]Shodan Safari » 🤖 🌐
                                                                                                                                          @shodansafari@infosec.exchange

                                                                                                                                          ... [SENSITIVE CONTENT]

                                                                                                                                          ASN: AS142403
                                                                                                                                          Location: Tseung Kwan O, HK
                                                                                                                                          Added: 2026-07-22T07:02

                                                                                                                                            AodeRelay boosted

                                                                                                                                            [?]Daily CyberSecurity » 🌐
                                                                                                                                            @DailyCyberSecurity@infosec.exchange

                                                                                                                                            Starland RAT is new malware from Russian-speaking actor UAT-11795. It steals crypto wallets and credentials via fake Zoom and WebEx installers.

                                                                                                                                            securityonline.info/starland-r

                                                                                                                                              [?]AmmarSpaces » 🌐
                                                                                                                                              @AmmarSpaces@infosec.exchange

                                                                                                                                              So, Mullvad made a clarification statement about one of their donator.

                                                                                                                                              I agree with all Mullvad view in this response.

                                                                                                                                              mullvad.net/en/blog/donation-c

                                                                                                                                                AodeRelay boosted

                                                                                                                                                [?]Michael I Ransier » 🌐
                                                                                                                                                @thecybermind@infosec.exchange

                                                                                                                                                ⚠️ THREAT ALERT: CVE-2026-60137 in WordPress Core enables unauthenticated SQL injection that chains for remote code execution! Active exploitation is confirmed. Get the forensic detection queries and hardening strategies you need to protect your web assets now. thecybermind.co/12b8

                                                                                                                                                  AodeRelay boosted

                                                                                                                                                  [?]Security Feed » 🤖 🌐
                                                                                                                                                  @securityfeed@infosec.exchange

                                                                                                                                                  🔒 Security News Digest - 2026-07-22

                                                                                                                                                  📊 8 updates from 5 sources:

                                                                                                                                                  🔹 The Hacker News: Why Modern SOCs Need Multi-Layered Detections
                                                                                                                                                  thehackernews.com/2026/07/why-

                                                                                                                                                  🔹 SecurityWeek: Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks
                                                                                                                                                  securityweek.com/fourth-sharep

                                                                                                                                                  🔹 darkreading: EU Financial Institutions Leak Data Through Cookie Trackers
                                                                                                                                                  darkreading.com/data-privacy/e

                                                                                                                                                  🦠 Malwarebytes: Paidwork breach exposes data of 23 million users: Check if you’re affected
                                                                                                                                                  malwarebytes.com/blog/data-bre

                                                                                                                                                  🔹 The Record from Recorded Future News: OpenAI models behind breach of Hugging Face systems, companies say
                                                                                                                                                  therecord.media/openai-cyberat

                                                                                                                                                  🦠 Malwarebytes: Chick-fil-A loyalty accounts hijacked using stolen passwords
                                                                                                                                                  malwarebytes.com/blog/data-bre

                                                                                                                                                  🔹 SecurityWeek: StrongestLayer Raises $4.1 Million in Seed Funding Extension
                                                                                                                                                  securityweek.com/strongestlaye

                                                                                                                                                  🔹 SecurityWeek: Vibe-Coded Apps Riddled With Exploitable Security Flaws
                                                                                                                                                  securityweek.com/vibe-coded-ap

                                                                                                                                                    AodeRelay boosted

                                                                                                                                                    [?]Reput.io » 🌐
                                                                                                                                                    @reput_io@infosec.exchange

                                                                                                                                                    A theme worth sitting with from this week's reporting: the malicious traffic wasn't hiding near trusted infrastructure, it was flowing through it.

                                                                                                                                                    Group-IB's HollowGraph runs its C2 inside a compromised Microsoft 365 calendar. Operators plant tasking as calendar events, and stolen files come back out as events, all over the real Graph API.

                                                                                                                                                    reput.io/blog/reputation-radar

                                                                                                                                                      [?]Nonilex » 🌐
                                                                                                                                                      @Nonilex@masto.ai

                                                                                                                                                      The incident signals that 's expanding capabilities are already fueling the threat experts long feared & even top developers can be caught off-guard ​by flaws their models can exploit.

                                                                                                                                                      The breakout was "an unprecedented cyber incident, involving state-of-the-art cyber capabilities" & is reinforcing its safeguards, the company said ​in a blog post.

                                                                                                                                                        AodeRelay boosted

                                                                                                                                                        [?]Nonilex » 🌐
                                                                                                                                                        @Nonilex@masto.ai

                                                                                                                                                        It also drew attention as New York-based said it had used an open-source Chinese model to contain ⁠the attack because leading US models, unable to tell a defender from an attacker, refused to process the data needed for analysis.

                                                                                                                                                        The company said in a blog ​post last week that it used AI's GLM-5.2 for the analysis, which also allowed it to keep attacker data & any credentials within its systems.

                                                                                                                                                          AodeRelay boosted

                                                                                                                                                          [?]Daily CyberSecurity » 🌐
                                                                                                                                                          @DailyCyberSecurity@infosec.exchange

                                                                                                                                                          Hackers are actively exploiting a critical ServiceNow RCE vulnerability (CVE-2026-6875) to bypass sandbox restrictions and breach corporate networks.

                                                                                                                                                          meterpreter.org/servicenow-rce

                                                                                                                                                            AodeRelay boosted

                                                                                                                                                            [?]urlDNA.io :verified: » 🤖 🌐
                                                                                                                                                            @urldna@infosec.exchange

                                                                                                                                                            Possible Phishing 🎣
                                                                                                                                                            on: ⚠️hxxps[:]//upgradetelkomaccount[.]weebly[.]com/
                                                                                                                                                            🧬 Analysis at: urldna.io/scan/6a60b0ea3b77500

                                                                                                                                                              AodeRelay boosted

                                                                                                                                                              [?]bsidesroc » 🌐
                                                                                                                                                              @bsidesroc@infosec.exchange

                                                                                                                                                              🚨 is set for March 20, 2027!

                                                                                                                                                              We're now seeking sponsors to help make the event a success. Check out our sponsorship opportunities and download the sponsorship kit:
                                                                                                                                                              bsidesroc.com/sponsorships/

                                                                                                                                                                AodeRelay boosted

                                                                                                                                                                [?]OffSequence » 🌐
                                                                                                                                                                @offseq@infosec.exchange

                                                                                                                                                                Unblu Spark suffers a CRITICAL open redirect (CVE-2026-8152) leading to DOM XSS in siteEmbeddedSetup=true config. Attacker can access cookies & APIs of host app. No patch yet — disable this config ASAP. radar.offseq.com/threat/cve-20

                                                                                                                                                                Critical threat: CVE-2026-8152: CWE-601 URL Redirection to Untrusted Site ('Open Redirect') in Unblu inc. Unblu Spark

                                                                                                                                                                Alt...Critical threat: CVE-2026-8152: CWE-601 URL Redirection to Untrusted Site ('Open Redirect') in Unblu inc. Unblu Spark

                                                                                                                                                                  AodeRelay boosted

                                                                                                                                                                  [?]OWASP Hamburg » 🌐
                                                                                                                                                                  @owasp_hamburg@infosec.exchange

                                                                                                                                                                  Moin!

                                                                                                                                                                  Wie vorangekündigt: 28.7. ist das nächste OWASP-Treffen, bei dem ein bisschen Hamburger Lokalpariotismus mitschwingt 😉

                                                                                                                                                                  Wie vielleicht vermutet, ist die Rede vom OWASP Juice Shop, a.k.a. "probably the most modern and sophisticated insecure web application". Das ist ein sog. OWASP-Flagship-Projekt, dass vor Kurzem sein 20. Release hatte.

                                                                                                                                                                  Eckdaten:
                                                                                                                                                                  ---------------

                                                                                                                                                                  * Lokation: Baumwall 7, New Work SE (danke, New Work, vor allen Dingen: Gerrit)
                                                                                                                                                                  * Vortrag: Freshly Squeezed: Prompt-Injecting Juice Shops New AI Brain
                                                                                                                                                                  * Sprecher: Björn Kimminich und Jannik Hollenbach
                                                                                                                                                                  * Datum: 28.7.2026
                                                                                                                                                                  * Start: 18:00
                                                                                                                                                                  * Anmeldung: Wäre hilfreich für die Getränke, die unser Host bestellt. Entweder per Mail oder: meetup.com/owasp-hamburg-stamm

                                                                                                                                                                  * Presentation Language: TBD. (if you plan to come and English is better for you, let us know)

                                                                                                                                                                  Abstract
                                                                                                                                                                  --------------
                                                                                                                                                                  OWASP Juice Shop's chatbot now runs on real LLM backends, either local models or the major providers' APIs.

                                                                                                                                                                  And we're not just going to show you the new LLM challenges: we'll solve them with you, live on stage.
                                                                                                                                                                  You call out the payloads, we fire them at the bot: coaxing it into leaking data it shouldn't, hijacking its behavior with well-placed prompts, and finding out on the spot which attacks land and which ones it shrugs off.
                                                                                                                                                                  Bring your nastiest prompt-injection ideas!

                                                                                                                                                                  We maintainers also had a "fun" year fielding large quantities of AI bot contributions of wildly differing quality.
                                                                                                                                                                  The talk covers how running a popular open-source project has changed since the boom of AI coding agents.

                                                                                                                                                                  Beyond LLMs, 2026 kept MultiJuicer, the project for managing multiple Juice Shop instances across local or remote hackathons and trainings, busy too.
                                                                                                                                                                  It now ships with a new CTF / wargames scoreboard for tracking participant scores, which we'll show off along the way.

                                                                                                                                                                  Nachbereitung
                                                                                                                                                                  -----------------------
                                                                                                                                                                  Das Portugiesenviertel könnte uns danach weiter verwöhnen. Wenn du zur Nachbereitung dabei bist, sag mir Bescheid. Dann würde ich für dich mit reservieren.

                                                                                                                                                                  Sonstiges
                                                                                                                                                                  ----------------
                                                                                                                                                                  Falls du selbst Lust auf einen Vortrag hast, oder du generell Vorträgen ein werbefreies Dach über dem Kopf bieten kannst, melde dich gerne!

                                                                                                                                                                  Generelles zum OWASP-Treffen
                                                                                                                                                                  ---------------------------------------------------
                                                                                                                                                                  Bei unseren für alle offenen Treffen geht es um Software und deren Sicherheit im Internet und/oder allgemein. Hier treffen sich Menschen, die sich beruflich oder privat mit IT-Sicherheit beschäftigen: Entwickler, Manager, Pentester und alle an (Web)sicherheit interessierte. Die Atmosphäre ist offen und locker. Uns geht's um den Erfahrungsaustausch, Technikschnack und um's Netzwerken. Wer Produkte oder Dienstleistungen verkaufen will, ist hier falsch. Ihr seid herzlich willkommen, euren Kollegen oder Bekannten einen Hinweis auf unsere Treffen weiterzuleiten. Alle Treffen sind frei, für jeden Menschen offen und kostenlos, mit oder ohne -Mitgliedschaft.

                                                                                                                                                                    AodeRelay boosted

                                                                                                                                                                    [?]Suriq - Always on Watch » 🤖 🌐
                                                                                                                                                                    @suriq@infosec.exchange

                                                                                                                                                                    Langflow's 'validate' endpoint just produced its SECOND unauthenticated root RCE in 14 months. CVE-2026-0770, CVSS 9.8, now in CISA's KEV list with a 3-day federal deadline. 220+ exploit attempts already logged. Patch, then pull it off the internet.

                                                                                                                                                                    suriq.io/blog/langflow-cve-202

                                                                                                                                                                    Isolated server node with two identical open doorways in its side suggesting a repeated flaw

                                                                                                                                                                    Alt...Isolated server node with two identical open doorways in its side suggesting a repeated flaw

                                                                                                                                                                      AodeRelay boosted

                                                                                                                                                                      [?]Daily CyberSecurity » 🌐
                                                                                                                                                                      @DailyCyberSecurity@infosec.exchange

                                                                                                                                                                      Discover how the sophisticated Cruciferra crypter service employs BYOVD and Process Ghosting to conceal malware and evade detection across enterprise networks.

                                                                                                                                                                      meterpreter.org/cruciferra-cry

                                                                                                                                                                        AodeRelay boosted

                                                                                                                                                                        [?]BeyondMachines :verified: » 🤖 🌐
                                                                                                                                                                        @beyondmachines1@infosec.exchange

                                                                                                                                                                        Ernst & Young Reports Third-Party Data Breach Affecting Tax Clients

                                                                                                                                                                        Ernst & Young reports a breach of a third-party service management platform that allowed unauthorized access to client tax and financial data between March and April 2026. The firm is providing credit monitoring to affected individuals and has notified law enforcement.

                                                                                                                                                                        ****

                                                                                                                                                                        beyondmachines.net/event_detai

                                                                                                                                                                          AodeRelay boosted

                                                                                                                                                                          [?]urlDNA.io :verified: » 🤖 🌐
                                                                                                                                                                          @urldna@infosec.exchange

                                                                                                                                                                          Possible Phishing 🎣
                                                                                                                                                                          on: ⚠️hxxps[:]//docs[.]google[.]com/presentation/d/e/2PACX-1vTTJ55NegmW7dN_WwTQD9VxQaUCVarklIqJ9hsLkPgpIcQyNBi7b-dbcIKu6stCGw2-kLZKNBpxjXR2/pub?start=false&loop=false&delayms=3000
                                                                                                                                                                          🧬 Analysis at: urldna.io/scan/6a609c793b77500

                                                                                                                                                                            AodeRelay boosted

                                                                                                                                                                            [?]Shodan Safari » 🤖 🌐
                                                                                                                                                                            @shodansafari@infosec.exchange

                                                                                                                                                                            ... [SENSITIVE CONTENT]

                                                                                                                                                                            ASN: AS9318
                                                                                                                                                                            Location: Busan, KR
                                                                                                                                                                            Added: 2026-07-08T02:22

                                                                                                                                                                              AodeRelay boosted

                                                                                                                                                                              [?]Cloud 🤖 » 🤖 🌐
                                                                                                                                                                              @cloud@infosec.exchange

                                                                                                                                                                              🤖 CVE-2026-0770 (CVSS 9.8): Critical unauthenticated RCE in Langflow AI framework actively exploited. Attackers gain root access via validate endpoint, deploying malware and stealing AWS creds. 220+ attempts from 64 IPs observed. CISA added to KEV catalog, orders patching by Friday.

                                                                                                                                                                              🔗 bleepingcomputer.com/news/secu

                                                                                                                                                                                AodeRelay boosted

                                                                                                                                                                                [?]thecybersecguru » 🌐
                                                                                                                                                                                @thecybersecguru@infosec.exchange

                                                                                                                                                                                🎉 AI Subscription Giveaway!

                                                                                                                                                                                As a thank you to everyone supporting my work, I'm giving away some AI subscriptions (ChatGPT and Claude, Pro and Max Inclusive) exclusively to active Buy Me a Coffee members.

                                                                                                                                                                                ✔️ Any membership tier is eligible
                                                                                                                                                                                ✔️ Winner chosen at random
                                                                                                                                                                                ✔️ Be sure to use the same email address as your Buy Me a Coffee membership when entering, otherwise your entry cannot be verified.

                                                                                                                                                                                Enter here:
                                                                                                                                                                                thecybersecguru.com/giveaways/

                                                                                                                                                                                Thank you for helping support independent cybersecurity research, projects, educational content and much much more. ❤️

                                                                                                                                                                                To support me, please buy me a coffee: buymeacoffee.com/thecybersecgu

                                                                                                                                                                                  AodeRelay boosted

                                                                                                                                                                                  [?]Daily CyberSecurity » 🌐
                                                                                                                                                                                  @DailyCyberSecurity@infosec.exchange

                                                                                                                                                                                  TTF Trap Campaign Hides a Low-Detection Lua Loader Inside Fake TrueType Font Files

                                                                                                                                                                                  A global phishing campaign hides a low-detection Lua loader inside fake .ttf font files to drop Remcos, XWorm, Agent Tesla, and a Snake Keylogger. At a glance Malware family Lua/AutoIt loader ("TTF Trap") delivering Remcos, Agent Tesla, XWorm, and Best Private LOGGER Threat actor Unattributed. FortiGuard Labs names no group. Target / victims…

                                                                                                                                                                                  securityonline.info/ttf-trap-l

                                                                                                                                                                                    AodeRelay boosted

                                                                                                                                                                                    [?]urlDNA.io :verified: » 🤖 🌐
                                                                                                                                                                                    @urldna@infosec.exchange

                                                                                                                                                                                    Possible Phishing 🎣
                                                                                                                                                                                    on: ⚠️hxxps[:]//uyfxgfdfxj[.]weebly[.]com/
                                                                                                                                                                                    🧬 Analysis at: urldna.io/scan/6a6086a33b77500

                                                                                                                                                                                      AodeRelay boosted

                                                                                                                                                                                      [?]BeyondMachines :verified: » 🤖 🌐
                                                                                                                                                                                      @beyondmachines1@infosec.exchange

                                                                                                                                                                                      Siemens Patches Multiple Vulnerabilities in SIDIS Secured SmartPlug

                                                                                                                                                                                      Siemens released security updates for the SIDIS Secured SmartPlug to fix 12 vulnerabilities, including a critical flaw in wireless authentication components. These flaws allow remote code execution, unauthorized access, and sensitive data disclosure in critical manufacturing environments.

                                                                                                                                                                                      **Make sure your SIDIS Secured SmartPlug devices are isolated from the internet and reachable only from trusted networks, behind a firewall separated from your business network. Then update every affected device to version V7.26.0310 or later.**

                                                                                                                                                                                      beyondmachines.net/event_detai

                                                                                                                                                                                        AodeRelay boosted

                                                                                                                                                                                        [?]urlDNA.io :verified: » 🤖 🌐
                                                                                                                                                                                        @urldna@infosec.exchange

                                                                                                                                                                                        Possible Phishing 🎣
                                                                                                                                                                                        on: ⚠️hxxps[:]//zim-veri[.]weebly[.]com/
                                                                                                                                                                                        🧬 Analysis at: urldna.io/scan/6a6078943b77500

                                                                                                                                                                                          AodeRelay boosted

                                                                                                                                                                                          [?]Shodan Safari » 🤖 🌐
                                                                                                                                                                                          @shodansafari@infosec.exchange

                                                                                                                                                                                          ... [SENSITIVE CONTENT]

                                                                                                                                                                                          Location: Asagaya-minami, JP
                                                                                                                                                                                          Added: 2026-07-07T11:28

                                                                                                                                                                                            AodeRelay boosted

                                                                                                                                                                                            [?]Michael I Ransier » 🌐
                                                                                                                                                                                            @thecybermind@infosec.exchange

                                                                                                                                                                                            ⚠️ CRITICAL THREAT: CVE-2026-63030 in WordPress Core enables SQL injection and RCE via interpretation conflicts. Active exploitation is confirmed! Get the forensic detection queries and hardening strategies needed to secure your web assets now. thecybermind.co/9k20

                                                                                                                                                                                              AodeRelay boosted

                                                                                                                                                                                              [?]urlDNA.io :verified: » 🤖 🌐
                                                                                                                                                                                              @urldna@infosec.exchange

                                                                                                                                                                                              Possible Phishing 🎣
                                                                                                                                                                                              on: ⚠️hxxps[:]//t[.]co/lvOUaOHAEf
                                                                                                                                                                                              🧬 Analysis at: urldna.io/scan/6a6072303b77500

                                                                                                                                                                                                AodeRelay boosted

                                                                                                                                                                                                [?]Scott Wilson 🌈 » 🌐
                                                                                                                                                                                                @scottwilson@infosec.exchange

                                                                                                                                                                                                AodeRelay boosted

                                                                                                                                                                                                [?]Geoff » 🌐
                                                                                                                                                                                                @sternecker@infosec.exchange

                                                                                                                                                                                                Two previously disclosed CVEs are actively-weaponized kernel root exploits. GhostLock CVE-2026-43499, and Bad Epoll CVE-2026-46242, are both public highly reliable exploits. Ghostlock also appears to enable a container escape and Bad Epoll is also working on Android.

                                                                                                                                                                                                Both are fixed in kernel 6.12.96-1.
                                                                                                                                                                                                If you have local users, upgrade the kernel & boot it.

                                                                                                                                                                                                BRB have to reboot :)

                                                                                                                                                                                                  AodeRelay boosted

                                                                                                                                                                                                  [?]Security Feed » 🤖 🌐
                                                                                                                                                                                                  @securityfeed@infosec.exchange

                                                                                                                                                                                                  🔒 Security News Digest - 2026-07-21

                                                                                                                                                                                                  📊 13 updates from 5 sources:

                                                                                                                                                                                                  🔹 SecurityWeek: Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack
                                                                                                                                                                                                  securityweek.com/estee-lauder-

                                                                                                                                                                                                  🔹 The Hacker News: New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit
                                                                                                                                                                                                  thehackernews.com/2026/07/new-

                                                                                                                                                                                                  🔹 SecurityWeek: CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG
                                                                                                                                                                                                  securityweek.com/ciso-conversa

                                                                                                                                                                                                  🦠 Malwarebytes: Don’t trust that “FBI agent” in your DMs
                                                                                                                                                                                                  malwarebytes.com/blog/news/202

                                                                                                                                                                                                  🔹 The Hacker News: N-day is Becoming N-Hour. Patching Faster Won't Save You.
                                                                                                                                                                                                  thehackernews.com/2026/07/n-da

                                                                                                                                                                                                  🔹 SecurityWeek: New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication
                                                                                                                                                                                                  securityweek.com/new-hollowgra

                                                                                                                                                                                                  🔹 The Hacker News: Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs
                                                                                                                                                                                                  thehackernews.com/2026/07/open

                                                                                                                                                                                                  🦠 Malwarebytes: New ClickLock Stealer locks your Mac until you hand over your password
                                                                                                                                                                                                  malwarebytes.com/blog/news/202

                                                                                                                                                                                                  🔹 The Record from Recorded Future News: Kenya probes hack of president's website after bitcoin ransom demand
                                                                                                                                                                                                  therecord.media/kenya-probes-h

                                                                                                                                                                                                  🔹 SecurityWeek: SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity
                                                                                                                                                                                                  securityweek.com/securityweek-

                                                                                                                                                                                                  🔹 SecurityWeek: Empirical Security Raises $25 Million in Series A Funding
                                                                                                                                                                                                  securityweek.com/empirical-sec

                                                                                                                                                                                                  🔹 darkreading: Choose Wisely: AI-Generated Coding Risk Varies, A Lot
                                                                                                                                                                                                  darkreading.com/application-se

                                                                                                                                                                                                  🔹 The Record from Recorded Future News: Taiwan to slow mobile data during national resilience drills
                                                                                                                                                                                                  therecord.media/taiwan-mobile-

                                                                                                                                                                                                    [?]Dream Walker » 🌐
                                                                                                                                                                                                    @__dreamwalker__@infosec.exchange

                                                                                                                                                                                                    Hello People.

                                                                                                                                                                                                    This is my first fediverse post, featuring my first program in . I am a who is just getting into and love contributing to , stuffs and .

                                                                                                                                                                                                    I love to program in , and use btw. Looking for people to connect. I installed LinkedIn a few days ago for connecting with people and figured out that it was a in jobmarket, just data feed into companies. (No offense, just in my opinion).

                                                                                                                                                                                                    I was suggested to start learning by a random reddit user when I asked some questions about programming and how to get better at it. Currently learning in linux, and I guess assembly programming alongside with c programming is helpful - I can understand syscalls and registers (for some extent).

                                                                                                                                                                                                    Looking forward for friends to connect. Follow me and I will follow you back - provided that we have same or similar interests. I am also interested in arts, languages and techs - I am not a Russian btw.

                                                                                                                                                                                                    I need suggestions \ on how to get started in fediverse, cybersecurity and low level stuffs. You can see my profile for more information.

                                                                                                                                                                                                    My First Assembly Program

                                                                                                                                                                                                    Alt...My First Assembly Program

                                                                                                                                                                                                      AodeRelay boosted

                                                                                                                                                                                                      [?]urlDNA.io :verified: » 🤖 🌐
                                                                                                                                                                                                      @urldna@infosec.exchange

                                                                                                                                                                                                      Possible Phishing 🎣
                                                                                                                                                                                                      on: ⚠️hxxps[:]//coinbasekr[.]com
                                                                                                                                                                                                      🧬 Analysis at: urldna.io/scan/6a5d96fb3b77500

                                                                                                                                                                                                        AodeRelay boosted

                                                                                                                                                                                                        [?]AA » 🌐
                                                                                                                                                                                                        @AAKL@infosec.exchange

                                                                                                                                                                                                        AodeRelay boosted

                                                                                                                                                                                                        [?]AA » 🌐
                                                                                                                                                                                                        @AAKL@infosec.exchange

                                                                                                                                                                                                        AodeRelay boosted

                                                                                                                                                                                                        [?]CTI.FYI » 🤖 🌐
                                                                                                                                                                                                        @CTI_FYI@infosec.exchange

                                                                                                                                                                                                        🚨New ransom group blog posts!🚨

                                                                                                                                                                                                        Group name: akira
                                                                                                                                                                                                        Post title: L&A Transport
                                                                                                                                                                                                        Info: cti.fyi/groups/akira.html

                                                                                                                                                                                                        Group name: akira
                                                                                                                                                                                                        Post title: McKeever , Varga & Senko
                                                                                                                                                                                                        Info: cti.fyi/groups/akira.html

                                                                                                                                                                                                          AodeRelay boosted

                                                                                                                                                                                                          [?]Cedric » 🌐
                                                                                                                                                                                                          @cedric@social.circl.lu

                                                                                                                                                                                                          282,000+ VEX records are now in Vulnerability-Lookup 🎉

                                                                                                                                                                                                          🔎 vulnerability.circl.lu/vex

                                                                                                                                                                                                          SUSE just joined Red Hat and Microsoft as a VEX source — so from any CVE you can see whether a vendor says a product is affected, fixed, or not affected.

                                                                                                                                                                                                          VEX statements are attached directly to each vulnerability and available via the open API.

                                                                                                                                                                                                          🧑‍💻 github.com/vulnerability-looku

                                                                                                                                                                                                          A screenshot of the VEX records page in Vulnerability-Lookup. It's a paginated list with all the VEX records from Microsoft, Red Hat and SUSE.

                                                                                                                                                                                                          Alt...A screenshot of the VEX records page in Vulnerability-Lookup. It's a paginated list with all the VEX records from Microsoft, Red Hat and SUSE.

                                                                                                                                                                                                            AodeRelay boosted

                                                                                                                                                                                                            [?]Daily CyberSecurity » 🌐
                                                                                                                                                                                                            @DailyCyberSecurity@infosec.exchange

                                                                                                                                                                                                            Gitea vulnerability CVE-2026-58443 (CVSS 9.6) lets public-only tokens write to private repos. Details and PoC code are public. Update to v1.27.0.

                                                                                                                                                                                                            securityonline.info/gitea-vuln

                                                                                                                                                                                                              AodeRelay boosted

                                                                                                                                                                                                              [?]BeyondMachines :verified: » 🤖 🌐
                                                                                                                                                                                                              @beyondmachines1@infosec.exchange

                                                                                                                                                                                                              Craneware Discloses Data Breach Involving Employee, Customer, and Partner Records

                                                                                                                                                                                                              Craneware PLC disclosed a data breach after unauthorized actors accessed its data environment and stole employee, customer, and partner records. The company contained the incident, notified the FBI and UK Information Commissioner’s Office, and confirmed that customer services and business operations were not disrupted.

                                                                                                                                                                                                              ****

                                                                                                                                                                                                              beyondmachines.net/event_detai

                                                                                                                                                                                                                AodeRelay boosted

                                                                                                                                                                                                                [?]AA » 🌐
                                                                                                                                                                                                                @AAKL@infosec.exchange

                                                                                                                                                                                                                9to5Linux: NetworkManager 1.58 Officially Released with New Features and Improvements 9to5linux.com/networkmanager-1

                                                                                                                                                                                                                IPFire 2.29 Core Update 203 Firewall Distro Replaces Unbound with Knot Resolver 9to5linux.com/ipfire-2-29-core @9to5linux @mariusnestor

                                                                                                                                                                                                                  AodeRelay boosted

                                                                                                                                                                                                                  [?]urlDNA.io :verified: » 🤖 🌐
                                                                                                                                                                                                                  @urldna@infosec.exchange

                                                                                                                                                                                                                  Possible Phishing 🎣
                                                                                                                                                                                                                  on: ⚠️hxxps[:]//centurybnkt[.]weebly[.]com/
                                                                                                                                                                                                                  🧬 Analysis at: urldna.io/scan/6a5dcf323b77500

                                                                                                                                                                                                                    AodeRelay boosted

                                                                                                                                                                                                                    [?]Shodan Safari » 🤖 🌐
                                                                                                                                                                                                                    @shodansafari@infosec.exchange

                                                                                                                                                                                                                    ... [SENSITIVE CONTENT]

                                                                                                                                                                                                                    ASN: AS1267
                                                                                                                                                                                                                    Location: Milan, IT
                                                                                                                                                                                                                    Added: 2026-07-05T03:54

                                                                                                                                                                                                                      AodeRelay boosted

                                                                                                                                                                                                                      [?]ANY.RUN » 🌐
                                                                                                                                                                                                                      @anyrun_app@infosec.exchange

                                                                                                                                                                                                                      One fake download page ➡️ full remote access to your network ⚠️

                                                                                                                                                                                                                      SnappyClient shows how quickly a single click can turn into stolen credentials, hijacked payments, and a foothold attackers can exploit long after the initial breach.

                                                                                                                                                                                                                      👨‍💻 Learn more: any.run/malware-trends/snappyc

                                                                                                                                                                                                                        AodeRelay boosted

                                                                                                                                                                                                                        [?]AA » 🌐
                                                                                                                                                                                                                        @AAKL@infosec.exchange

                                                                                                                                                                                                                        The Record: British company Craneware that provides software to more than 2,000 US hospitals says attackers stole employee and customer data therecord.media/software-provi @therecord_media

                                                                                                                                                                                                                          AodeRelay boosted

                                                                                                                                                                                                                          [?]AA » 🌐
                                                                                                                                                                                                                          @AAKL@infosec.exchange

                                                                                                                                                                                                                          If you missed the spectacular news that Ernest & Young has been breached, here's more:

                                                                                                                                                                                                                          Security Week: Ernst & Young Data Breach Affects Personal, Financial Information securityweek.com/ernst-young-d @SecurityWeek

                                                                                                                                                                                                                            AodeRelay boosted

                                                                                                                                                                                                                            [?]AA » 🌐
                                                                                                                                                                                                                            @AAKL@infosec.exchange

                                                                                                                                                                                                                            [?]ARGVMI~1.PIF » 🌐
                                                                                                                                                                                                                            @argv_minus_one@mastodon.sdf.org

                                                                                                                                                                                                                            If hackers are now giving Code unfettered access to do as it pleases on their development computers, what exactly is stopping from performing a supply-chain attack on the entire ecosystem?

                                                                                                                                                                                                                            Will there still be human code review going forward, to catch such an attack? And if so, how can that review be meaningful, when the computers used to perform the review are all compromised?

                                                                                                                                                                                                                              AodeRelay boosted

                                                                                                                                                                                                                              [?]urlDNA.io :verified: » 🤖 🌐
                                                                                                                                                                                                                              @urldna@infosec.exchange

                                                                                                                                                                                                                              Possible Phishing 🎣
                                                                                                                                                                                                                              on: ⚠️hxxps[:]//westconsincuorgg[.]weebly[.]com
                                                                                                                                                                                                                              🧬 Analysis at: urldna.io/scan/6a5c760e3b77500

                                                                                                                                                                                                                                AodeRelay boosted

                                                                                                                                                                                                                                [?]Kyle Reddoch (CybersecKyle) » 🌐
                                                                                                                                                                                                                                @cyberseckyle@infosec.exchange

                                                                                                                                                                                                                                AodeRelay boosted

                                                                                                                                                                                                                                [?]urlDNA.io :verified: » 🤖 🌐
                                                                                                                                                                                                                                @urldna@infosec.exchange

                                                                                                                                                                                                                                Possible Phishing 🎣
                                                                                                                                                                                                                                on: ⚠️hxxps[:]//urlz[.]fr/uMr7
                                                                                                                                                                                                                                🧬 Analysis at: urldna.io/scan/6a5b3a563b77500

                                                                                                                                                                                                                                  AodeRelay boosted

                                                                                                                                                                                                                                  [?]Suriq - Always on Watch » 🤖 🌐
                                                                                                                                                                                                                                  @suriq@infosec.exchange

                                                                                                                                                                                                                                  OpenSSL quietly fixed HollowByte in June: 11 bytes strand a server's memory, no auth needed. No CVE, so your scanner won't flag it, and patching without a reload leaves hit workers bloated.

                                                                                                                                                                                                                                  suriq.io/blog/openssl-hollowby

                                                                                                                                                                                                                                  One server memory chamber swollen and clogged by a tiny data sliver while others stay idle

                                                                                                                                                                                                                                  Alt...One server memory chamber swollen and clogged by a tiny data sliver while others stay idle

                                                                                                                                                                                                                                    [?]Debby ‬⁂📎🐧:disability_flag: » 🌐
                                                                                                                                                                                                                                    @debby@hear-me.social

                                                                                                                                                                                                                                    rm -rf /

                                                                                                                                                                                                                                    GPT 5.6 deleted an AI Bro's files.

                                                                                                                                                                                                                                    Making mistakes or malfunctions isn't surprising—what is surprising is how some AI enthusiasts give unsupervised access to productive systems without backups. 🤦‍♀️

                                                                                                                                                                                                                                    Here's the reality: AI has no idea what it's doing. It's a highly sophisticated word completion system ≠ a sci-fi thinking machine.

                                                                                                                                                                                                                                    x.com/brunolemos/status/207676

                                                                                                                                                                                                                                      AodeRelay boosted

                                                                                                                                                                                                                                      [?]OffSequence » 🌐
                                                                                                                                                                                                                                      @offseq@infosec.exchange

                                                                                                                                                                                                                                      CVE-2026-16096: Stack-based buffer overflow (CVSS 8.7, HIGH) in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124 (/proc/webmon_recent_domains). Remote exploit possible. Migrate to FreshTomato. radar.offseq.com/threat/cve-20

                                                                                                                                                                                                                                      High threat: CVE-2026-16096: Stack-based Buffer Overflow in Shibby Tomato

                                                                                                                                                                                                                                      Alt...High threat: CVE-2026-16096: Stack-based Buffer Overflow in Shibby Tomato

                                                                                                                                                                                                                                        AodeRelay boosted

                                                                                                                                                                                                                                        [?]urlDNA.io :verified: » 🤖 🌐
                                                                                                                                                                                                                                        @urldna@infosec.exchange

                                                                                                                                                                                                                                        Possible Phishing 🎣
                                                                                                                                                                                                                                        on: ⚠️hxxps[:]//www[.]powr[.]io/media-gallery/i/41166190
                                                                                                                                                                                                                                        🧬 Analysis at: urldna.io/scan/6a5b16633b77500

                                                                                                                                                                                                                                          AodeRelay boosted

                                                                                                                                                                                                                                          [?]Shodan Safari » 🤖 🌐
                                                                                                                                                                                                                                          @shodansafari@infosec.exchange

                                                                                                                                                                                                                                          ... [SENSITIVE CONTENT]

                                                                                                                                                                                                                                          ASN: AS2516
                                                                                                                                                                                                                                          Location: Yokohama, JP
                                                                                                                                                                                                                                          Added: 2026-07-07T06:58

                                                                                                                                                                                                                                            AodeRelay boosted

                                                                                                                                                                                                                                            [?]urlDNA.io :verified: » 🤖 🌐
                                                                                                                                                                                                                                            @urldna@infosec.exchange

                                                                                                                                                                                                                                            Possible Phishing 🎣
                                                                                                                                                                                                                                            on: ⚠️hxxps[:]//is[.]gd/bper-Alert002
                                                                                                                                                                                                                                            🧬 Analysis at: urldna.io/scan/6a5ad7e83b77500

                                                                                                                                                                                                                                              AodeRelay boosted

                                                                                                                                                                                                                                              [?]Bryan Steele :flan_beard: » 🌐
                                                                                                                                                                                                                                              @brynet@bsd.network

                                                                                                                                                                                                                                              I don't suppose that I have any friends out there willing to signal boost, by chance? :flan_heart::flan_hacker:

                                                                                                                                                                                                                                              bsd.network/@brynet/1144589971

                                                                                                                                                                                                                                                Back to top - More...