Skip to content
  • 0 Votes
    2 Posts
    2 Views
    ifin@infosec.exchangeI
    As a chaser, here are two other CVEs on Ollama from yesterday.https://discourse.ifin.network/t/cve-2026-42248-cve-2026-42249-ollama-on-windows-doesnt-verify-updates-writes-anywhere/378
  • 0 Votes
    1 Posts
    0 Views
    cti_fyi@infosec.exchangeC
    New ransom group blog post!Group name: kairosPost title: Houk Air ConditioningInfo: https://cti.fyi/groups/kairos.html#ransomware #cti #threatintelligence #cybersecurity #infosec
  • New.

    Uncategorized infoec threatintel threatintellige
    1
    0 Votes
    1 Posts
    0 Views
    aakl@infosec.exchangeA
    New.Abnormal Security: Tycoon2FA Rebounds Post-Takedown with 6 Layers of Obfuscation https://abnormal.ai/blog/tycoon2fa-post-takedown-rebuild #infoec #threatintel #threatintelligence
  • 0 Votes
    1 Posts
    3 Views
    ifin@infosec.exchangeI
    It would appears that the DDoS attack affecting #Ubuntu is finally over, with statements from both Canonical and the claimed attackers. While the attackers threaten Cloudflare next, they continue to use their services to protect their booter service. Meanwhile, Canonical has not put anything but security and archive repos behind Cloudflare protection. It's unknown what other measures are in place for other resources.https://discourse.ifin.network/t/ubuntu-services-under-attack/356#ThreatIntel #ThreatIntelligence #IFIN
  • 0 Votes
    1 Posts
    0 Views
    T
    Your home router might be attacking websites right now and you'd never know. Millions are already compromised.Full analysis: https://threatchain.io/mirai-sample-detected-luxzz-mpsl-1a8d5043#cybersecurity #threatintelligence #infosec #SIEM
  • 0 Votes
    1 Posts
    3 Views
    hackerworkspace@infosec.exchangeH
    SSL.com rotates their root certificate today - SANS ISChttps://isc.sans.edu/diary/rss/32956Read on HackerWorkspace: https://hackerworkspace.com/article/ssl-com-rotates-their-root-certificate-today-sans-isc#encryption #cybersecurity #threatintelligence
  • 0 Votes
    1 Posts
    0 Views
    cti_fyi@infosec.exchangeC
    New ransom group blog posts!Group name: spacebearsPost title: Johnson & Johnson Innovative MedicineInfo: https://cti.fyi/groups/spacebears.htmlGroup name: lamashtuPost title: Luna GroupInfo: https://cti.fyi/groups/lamashtu.htmlGroup name: lamashtuPost title: ROYAL M HOTEL BY GEWAN FUJAIRAH LLCInfo: https://cti.fyi/groups/lamashtu.html#ransomware #cti #threatintelligence #cybersecurity #infosec
  • 0 Votes
    1 Posts
    0 Views
    ifin@infosec.exchangeI
    Thanks to Censys, We have confirmed exploitation leading to ransomware for the #cPanel/WHM auth bypass.https://discourse.ifin.network/t/cve-2026-41960-cpanel-auth-bypass-eitw/339#ThreatIntel #ThreatIntelligence #IFIN
  • 0 Votes
    1 Posts
    0 Views
    ifin@infosec.exchangeI
    The worms keep worming, unfortunately. The "Mini Shai-Hulud" attack appears to pivot to #PyPi with a compromise of a #pytorch library:https://discourse.ifin.network/t/pytorch-lightning-library-hit-by-supply-chain-attack/357#ThreatIntel #ThreatIntelligence #IFIN #Python
  • 0 Votes
    1 Posts
    0 Views
    cti_fyi@infosec.exchangeC
    New ransom group blog posts!Group name: qilinPost title: ApothebeautyInfo: https://cti.fyi/groups/qilin.htmlGroup name: nightspirePost title: Progressive Oral Surgery & ImplantologyInfo: https://cti.fyi/groups/nightspire.htmlGroup name: payoutskingPost title: SunSourceInfo: https://cti.fyi/groups/payoutsking.htmlGroup name: payoutskingPost title: Data Exchange CorporationInfo: https://cti.fyi/groups/payoutsking.htmlGroup name: payoutskingPost title: Epcon CommunitiesInfo: https://cti.fyi/groups/payoutsking.htmlGroup name: payoutskingPost title: SCS EngineersInfo: https://cti.fyi/groups/payoutsking.htmlGroup name: payoutskingPost title: Englewood LabInfo: https://cti.fyi/groups/payoutsking.htmlGroup name: payoutskingPost title: Grace Design StudiosInfo: https://cti.fyi/groups/payoutsking.htmlGroup name: worldleaksPost title: SMTA Sherwood Mutual Telephone AssociationInfo: https://cti.fyi/groups/worldleaks.html#ransomware #cti #threatintelligence #cybersecurity #infosec
  • 0 Votes
    1 Posts
    0 Views
    T
    That email attachment your coworker just opened? It's copying every password they've ever saved. Right now.Full analysis: https://threatchain.io/agenttesla-sample-detected-nota-de-credito-a12345-045-20260403-pdf-scr-exe-4a2b467d#cybersecurity #threatintelligence #infosec #SIEM
  • 0 Votes
    1 Posts
    5 Views
    hackerworkspace@infosec.exchangeH
    Analyzing the Silver Fox tax campaign and the new ABCDoor backdoorhttps://hackerworkspace.com/article/analyzing-the-silver-fox-tax-campaign-and-the-new-abcdoor-backdoor#malware #cybersecurity #threatintelligence
  • 0 Votes
    1 Posts
    0 Views
    hackerworkspace@infosec.exchangeH
    Police dismantles 9 crypto scam centers, arrests 276 suspectshttps://www.bleepingcomputer.com/news/security/police-dismantles-9-crypto-investment-scam-centers-arrests-276-suspects/Read on HackerWorkspace: https://hackerworkspace.com/article/police-dismantles-9-crypto-scam-centers-arrests-276-suspects#cybersecurity #incidentresponse #threatintelligence
  • 0 Votes
    1 Posts
    1 Views
    infobloxthreatintel@infosec.exchangeI
    "Run a quick DNS speed test" they said… One click on dns-speed.tail-f[.]de and your browser helpfully fans out ~5,000 HTTPS handshakes to "random" Cisco Top 1M domains in ~30 seconds.That randomness is doing a lot of work.Across a handful of runs we saw clients touching:- Government + defence: *.uscourts.gov, multiple .gov TLDs, and .mil hosts (incl. disa[.]mil, onr[.]navy[.]mil)- Microsoft sovereign/GCC High endpoints (dodsuite, usgovcloudapi, etc.)- Enterprise collaboration: 100+ Webex, Zoom infra, SharePoint/OneDrive tenants- Identity surfaces: 130+ auth/login patterns, Okta/Auth0/Duo tenants- Autodiscover for named orgs (useful for pre‑populating phish kits)- ~150 banking domains, globally distributedAll from a page load. No content fetched, just "harmless" handshakes.What's interesting isn't malice so much as side‑effects. A "neutral" performance test becomes:- A spray of client IPs into sensitive identity and gov endpoints- Noisy, hard‑to‑explain telemetry for defenders ("why is this workstation touching DISA?")- Occasional redirects into less friendly corners of the web, courtesy of the long tailThe stated aim is realism (avoid vendor‑optimised test servers). In practice, you inherit the internet's entire distribution of good, bad, and broken—and push it through end‑user browsers.It's a reminder that at scale, "just measuring" can look a lot like reconnaissance… or at least generate it for someone else.#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel
  • Regarding #CopyFail,

    Uncategorized copyfail threatintel threatintellige ifin
    1
    0 Votes
    1 Posts
    1 Views
    ifin@infosec.exchangeI
    Regarding #CopyFail,It is worth noting that the exploit can target any file and overwrite its contents. That's not just privilege escalation; that's the potential for stealthy persistence.Our thread now has more technical discussion and also some clever detections.https://discourse.ifin.network/t/copy-fail-732-bytes-to-root-on-every-major-linux-distributions/342/26#ThreatIntel #ThreatIntelligence #IFIN
  • What is going on today??

    Uncategorized copyfail threatintel threatintellige ifin
    1
    0 Votes
    1 Posts
    0 Views
    ifin@infosec.exchangeI
    What is going on today??We're also tracking #CopyFail.https://discourse.ifin.network/t/copy-fail-732-bytes-to-root-on-every-major-linux-distributions/342#ThreatIntel #ThreatIntelligence #IFIN
  • New.

    Uncategorized threatintel threatintellige infosec security surveillance
    1
    0 Votes
    1 Posts
    0 Views
    aakl@infosec.exchangeA
    New.Group-IB:Phoenix Rising: Exposing the PhaaS Kit Behind Global Mass Phishing Campaigns https://www.group-ib.com/blog/phoenix-phaas-kit-smishing/ Securonix:Deep#Door Stealer: Stealthy Python Backdoor and Credential Stealer Leveraging Tunneling, Multi-Layer Persistence, and In-Memory Surveillance Capabilities https://www.securonix.com/blog/deepdoor-python-backdoor-and-credential-stealer/#threatintel #threatintelligence @threatresearch #infosec #security #surveillance #Python #phishing #smishing
  • 0 Votes
    1 Posts
    4 Views
    ifin@infosec.exchangeI
    Looks like we have another #supplychain attack underway, this time facing #SAP-related NPM packages.https://discourse.ifin.network/t/sap-npm-packages-targeted-with-credential-stealing-malware/340#ThreatIntel #ThreatIntelligence #IFIN
  • 0 Votes
    1 Posts
    1 Views
    cti_fyi@infosec.exchangeC
    New ransom group blog post!Group name: interlockPost title: Winona CountyInfo: https://cti.fyi/groups/interlock.html#ransomware #cti #threatintelligence #cybersecurity #infosec
  • 0 Votes
    1 Posts
    2 Views
    cti_fyi@infosec.exchangeC
    New ransom group blog post!Group name: chaosPost title: cadencepetroleum.comInfo: https://cti.fyi/groups/chaos.html#ransomware #cti #threatintelligence #cybersecurity #infosec