technadu@infosec.exchange
@technadu@infosec.exchange
Topics
-
-
GlassWorm update:• Solana dead drop C2 + DHT fallback• Fake Chrome extension → full browser exfil• HW wallet phishing (Ledger/Trezor)• HVNC + SOCKS modules• Targets npm, PyPI, MCPDecentralized infra = stealth persistence.
Uncategorized
1
-
-
-
Surfshark launches HeyPolo 📍• No always-on tracking• Share exact / approx / none• Granular visibility controlsPrivacy-first location sharing.
Uncategorized
1
-
FriendlyDealer scam abusing PWAs:• 1,500+ fake app store domains• Browser-based installs bypass OS checks• Apps appear legit• Fake MrBeast affiliations usedShift to stealth mobile delivery.
Uncategorized
1
-
DarkSword iOS exploit kit leaked on GitHub.• 6-vuln chain• Targets iOS 18 and older• Enables full spyware deployment• Now usable by low-skill actorsShift from targeted espionage → scalable threat.
Uncategorized
1
-
-
Kenya + Singapore deepen cybersecurity collaborationFocus: digital governance, policing tech, ICT capacity
Uncategorized
1
-
Foster City ransomware attack disrupts municipal ops.• Non-emergency services halted• Public data exposure risk• 911 systems unaffected
Uncategorized
1
-
Navia Benefit Solutions breach2.6M+ affectedSSNs + health data exposedWeeks-long accessThird-party risk 🔺
Uncategorized
1
-
NordVPN launches Scam Text CheckerAI + threat intelScans text, links, screenshotsUser-side phishing defense ↑Source: https://nordvpn.com/blog/nordvpn-scam-text-checker💬 Worth using?
Uncategorized
1
-
-
-
Darksword exploit kit chains 6 iOS flaws to achieve full device compromise.• RCE → kernel access• Used by multiple threat actors• High-risk data exfiltration
Uncategorized
1
-
-
-
-
New KEV addition by CISA:CVE-2025-47813 (Wing FTP Server)• Information disclosure flaw• Actively exploited• High remediation priorityKEV = real-world threat signal.
Uncategorized
1
-
The EU has sanctioned Chinese and Iranian firms over cyberattacks targeting European networks and infrastructure.
Uncategorized
1