Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

ifin@infosec.exchangeI

ifin@infosec.exchange

@ifin@infosec.exchange
About
Posts
38
Topics
28
Shares
0
Groups
0
Followers
0
Following
0

View Original

Posts

Recent Best Controversial

  • After careful analysis, we believe the best option for remediation is to turn off the computers and go for a nice walk.
    ifin@infosec.exchangeI ifin@infosec.exchange

    After careful analysis, we believe the best option for remediation is to turn off the computers and go for a nice walk. Maybe call your mother.

    Uncategorized

  • What is going on today??
    ifin@infosec.exchangeI ifin@infosec.exchange

    What is going on today??

    We're also tracking #CopyFail.

    Link Preview Image
    Copy Fail: 732 Bytes to Root on Every Major Linux Distributions

    CVE-2026-31431 Confirmed the exploit. It’s real.

    favicon

    IFIN (discourse.ifin.network)

    #ThreatIntel #ThreatIntelligence #IFIN

    Uncategorized copyfail threatintel threatintellige ifin

  • We have a CVE and confirmed exploitation for the cPanel vulnerability.
    ifin@infosec.exchangeI ifin@infosec.exchange

    We have a CVE and confirmed exploitation for the cPanel vulnerability.

    CVE-2026-41960. Action is to patch affected versions and review access logs.

    Link Preview Image
    CVE-2026-41960: cPanel auth bypass EITW

    This is gonna burn some folks. https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026

    favicon

    IFIN (discourse.ifin.network)

    Uncategorized

  • Looks like we have another #supplychain attack underway, this time facing #SAP-related NPM packages.
    ifin@infosec.exchangeI ifin@infosec.exchange

    Looks like we have another #supplychain attack underway, this time facing #SAP-related NPM packages.

    Link Preview Image
    SAP npm Packages targeted with Credential-stealing Malware

    So far, four SAP-related npm packages have been compromised where the preinstall scripts inject malicious preinstall hooks that bootstrap the Bun JavaScript runtime and executes an obfuscated credential stealer payload (…

    favicon

    IFIN (discourse.ifin.network)

    #ThreatIntel #ThreatIntelligence #IFIN

    Uncategorized supplychain sap threatintel threatintellige ifin

  • This is why we're saying we have to look out for each other:
    ifin@infosec.exchangeI ifin@infosec.exchange

    This is why we're saying we have to look out for each other:

    https://fed.brid.gy/r/https://bsky.app/profile/did:plc:gdxiuhym6fvbhxo5uhiohmyy/post/3mkncgm5xuk26

    Uncategorized

  • Did you know our Threat Intel channel publishes to #ActivityPub?
    ifin@infosec.exchangeI ifin@infosec.exchange

    Did you know our Threat Intel channel publishes to #ActivityPub? We're serious about the "Federated" in "Independent Federated Intelligence Network!" This is the firehose of all posts in our "Threat Intel" category.

    @threatintel

    Uncategorized activitypub

  • Tell your friends.
    ifin@infosec.exchangeI ifin@infosec.exchange

    Tell your friends. Mess around with the single field we ask for during onboarding, and we will toss you. If you don't take this seriously, we have no reason to expect you to respect our community's safety.

    Uncategorized

  • We've been on a tear adding new sources to our RSS aggregator!
    ifin@infosec.exchangeI ifin@infosec.exchange

    We've been on a tear adding new sources to our RSS aggregator! All the cyber news that's fit to print, in one place: https://news.ifin.network

    Uncategorized

  • Got a certificate of achievement from the bot on @ifin after leveling up and I'm shocked at the psychology going on behind the scenes
    ifin@infosec.exchangeI ifin@infosec.exchange

    @stroz Yessssss

    Uncategorized

  • Bitwarden's CLI NPM package was hijacked and used to spread credential stealer malware.
    ifin@infosec.exchangeI ifin@infosec.exchange

    Bitwarden's CLI NPM package was hijacked and used to spread credential stealer malware. This is related to the previous Checkmarx compromise.

    We'll be updating this thread as always with new information. Come join the effort!

    Link Preview Image
    TeamPCP Campaign Spreads to npm via a Hijacked Bitwarden CLI

    From: Kill Chain: The root package.json advertises @bitwarden/cli version 2026.4.0, while the embedded application metadata in build/bw.js still references 2026.3.0. That mismatch strongly suggests the malicious pac…

    favicon

    IFIN (discourse.ifin.network)

    Uncategorized

  • The best time to block api
    ifin@infosec.exchangeI ifin@infosec.exchange

    @julie New-ish. We had a report of some ClickFix activity that used it, and was related to a recent Elastic report.

    https://discourse.ifin.network/t/phantompulse-rat-macos-using-clickfix/302

    Uncategorized threatintel threatintellige ifin

  • The best time to block api
    ifin@infosec.exchangeI ifin@infosec.exchange

    The best time to block api.telegram[.]org was like, I dunno, five years ago? The second best time to do it is now.

    Seriously. Cross that one off the easy wins list today.

    #ThreatIntel #ThreatIntelligence #IFIN

    Uncategorized threatintel threatintellige ifin

  • Thanks to some excellent reporting from Infostealers by Hudson Rock, we know a context[.]ai employee was seeking Roblox cheats when they got hit with LummaStealer, leading to the initial breach which impacted Vercel.
    ifin@infosec.exchangeI ifin@infosec.exchange

    RE: https://infosec.exchange/@ifin/116432853020620365

    Thanks to some excellent reporting from Infostealers by Hudson Rock, we know a context[.]ai employee was seeking Roblox cheats when they got hit with LummaStealer, leading to the initial breach which impacted Vercel.

    https://discourse.ifin.network/t/vercel-confirms-breach-as-hackers-claim-to-be-selling-stolen-data/293/7

    Uncategorized

  • Today we're talking about another (???) issue in the Cursor AI IDE.
    ifin@infosec.exchangeI ifin@infosec.exchange

    Today we're talking about another (???) issue in the Cursor AI IDE. Well actually it's two issues, one of which is simple command injection; the other is takeover via Dev tunnels. Don't know what dev tunnels are? Come find out—then block them with extreme prejudice.

    https://discourse.ifin.network/t/cursors-remote-tunnel-capability-is-vulnerable-to-malicious-prompt-injection/295

    #IFIN #ThreatIntel #ThreatIntelligence

    Uncategorized ifin threatintel threatintellige

  • #Vercel update.
    ifin@infosec.exchangeI ifin@infosec.exchange

    #Vercel update. We now know, thanks to Vercel's CEO, that the compromise came by way of the context[.]ai Office Suite, using OAuth tokens collected from a breach last month. Details here:

    https://discourse.ifin.network/t/vercel-confirms-breach-as-hackers-claim-to-be-selling-stolen-data/293/6

    Uncategorized vercel

  • #Vercel customers: don't wait.
    ifin@infosec.exchangeI ifin@infosec.exchange

    We're actively tracking developments here: https://discourse.ifin.network/t/vercel-confirms-breach-as-hackers-claim-to-be-selling-stolen-data/293

    Uncategorized vercel

  • #Vercel customers: don't wait.
    ifin@infosec.exchangeI ifin@infosec.exchange

    #Vercel customers: don't wait. Proactively rotate keys, passwords and environment variables ASAP.

    https://vercel.com/kb/bulletin/vercel-april-2026-security-incident

    Uncategorized vercel

  • We've been tracking #Iran cyber activity since the beginning of March, consolidating high-value intelligence into a single thread.
    ifin@infosec.exchangeI ifin@infosec.exchange

    We've been tracking #Iran cyber activity since the beginning of March, consolidating high-value intelligence into a single thread. One of the most comprehensive resources on the topic, if we do say so ourselves.

    Link Preview Image
    Iran Conflict: Cyber Threat Activity

    Let’s do the thing, shall we? Questions to consider: What are the current cyber capabilities of Iran and its proxies? What are the exigent cyber risks of retaliation in response to the US/Israel attacks? Most public …

    favicon

    IFIN (discourse.ifin.network)

    #ThreatIntel #ThreatIntelligence #IFIN

    Uncategorized iran threatintel threatintellige ifin

  • Seems like we all want to care for and protect each other.
    ifin@infosec.exchangeI ifin@infosec.exchange

    Seems like we all want to care for and protect each other. We just needed a place and permission.

    Let's change cyber threat intelligence for the better.

    Uncategorized

  • After working on it a bit, we have a fix for a recent #ClickFix attack against #macOS that leverages AppleScript.
    ifin@infosec.exchangeI ifin@infosec.exchange

    After working on it a bit, we have a fix for a recent #ClickFix attack against #macOS that leverages AppleScript. Here's the writeup, and a link to the forum thread!

    https://ifin-intel.org/blog/applescript/

    #ThreatIntel ThreatIntelligence #IFIN

    Uncategorized clickfix macos threatintel ifin
  • Login

  • Login or register to search.
  • First post
    Last post
0
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups