home.social

#edge — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #edge, aggregated by home.social.

  1. #Chrome, #safari and #Edge are built for and serve the goals of Google, Apple, and Microsoft. Any benefits for the user existing solely because they serve the developer goals or are temporarily needed for competitive purposes. This is why #Firefox matters and why there is concern about #mozilla management behaving like corporate enshifitfiers. We need to maintain a real alternative to restraint the most rapacious tendencies of the corporate browser providers.

  2. Privacy-by-design: что наш edge не пишет на диск и почему это сложнее, чем кажется

    Я пилю VantageDNS — рекурсивный DNS-резолвер с фильтрацией. NextDNS-clone, если коротко: юзер настраивает роутер на наш DoH endpoint, а мы рекурсивно резолвим и заодно режем рекламу, трекеры и malware. Privacy-фокус для такого продукта это не маркетинговая фича, а архитектурное ограничение, которое надо тащить с первого дня. Privacy policy без архитектурных гарантий — это обещание не лезть в твою тумбочку, ключи от которой ты сам отдал. В этой статье конкретика: что edge-нода не пишет на диск, как устроен кольцевой буфер для query log, что делать с crash dumps, и как юзер может проверить, что мы не врём, через strace . Что мы не пишем на диск

    habr.com/ru/articles/1035640/

    #privacy #DNS #retention #GDPR #edge #query_log #inmemory #EU #anonymization #ClickHouse

  3. Privacy-by-design: что наш edge не пишет на диск и почему это сложнее, чем кажется

    Я пилю VantageDNS — рекурсивный DNS-резолвер с фильтрацией. NextDNS-clone, если коротко: юзер настраивает роутер на наш DoH endpoint, а мы рекурсивно резолвим и заодно режем рекламу, трекеры и malware. Privacy-фокус для такого продукта это не маркетинговая фича, а архитектурное ограничение, которое надо тащить с первого дня. Privacy policy без архитектурных гарантий — это обещание не лезть в твою тумбочку, ключи от которой ты сам отдал. В этой статье конкретика: что edge-нода не пишет на диск, как устроен кольцевой буфер для query log, что делать с crash dumps, и как юзер может проверить, что мы не врём, через strace . Что мы не пишем на диск

    habr.com/ru/articles/1035640/

    #privacy #DNS #retention #GDPR #edge #query_log #inmemory #EU #anonymization #ClickHouse

  4. Privacy-by-design: что наш edge не пишет на диск и почему это сложнее, чем кажется

    Я пилю VantageDNS — рекурсивный DNS-резолвер с фильтрацией. NextDNS-clone, если коротко: юзер настраивает роутер на наш DoH endpoint, а мы рекурсивно резолвим и заодно режем рекламу, трекеры и malware. Privacy-фокус для такого продукта это не маркетинговая фича, а архитектурное ограничение, которое надо тащить с первого дня. Privacy policy без архитектурных гарантий — это обещание не лезть в твою тумбочку, ключи от которой ты сам отдал. В этой статье конкретика: что edge-нода не пишет на диск, как устроен кольцевой буфер для query log, что делать с crash dumps, и как юзер может проверить, что мы не врём, через strace . Что мы не пишем на диск

    habr.com/ru/articles/1035640/

    #privacy #DNS #retention #GDPR #edge #query_log #inmemory #EU #anonymization #ClickHouse

  5. Privacy-by-design: что наш edge не пишет на диск и почему это сложнее, чем кажется

    Я пилю VantageDNS — рекурсивный DNS-резолвер с фильтрацией. NextDNS-clone, если коротко: юзер настраивает роутер на наш DoH endpoint, а мы рекурсивно резолвим и заодно режем рекламу, трекеры и malware. Privacy-фокус для такого продукта это не маркетинговая фича, а архитектурное ограничение, которое надо тащить с первого дня. Privacy policy без архитектурных гарантий — это обещание не лезть в твою тумбочку, ключи от которой ты сам отдал. В этой статье конкретика: что edge-нода не пишет на диск, как устроен кольцевой буфер для query log, что делать с crash dumps, и как юзер может проверить, что мы не врём, через strace . Что мы не пишем на диск

    habr.com/ru/articles/1035640/

    #privacy #DNS #retention #GDPR #edge #query_log #inmemory #EU #anonymization #ClickHouse

  6. Adam Copeland and Christian Cage have officially become 8-time Tag Team Champions after winning the AEW World Tag Team Titles, adding another chapter to their legendary journey following multiple iconic WWE tag team title reigns.
    #AEWWorldTagTeamChampions #Edge #Christian #Wrestling

  7. Adam Copeland and Christian Cage have officially become 8-time Tag Team Champions after winning the AEW World Tag Team Titles, adding another chapter to their legendary journey following multiple iconic WWE tag team title reigns.
    #AEWWorldTagTeamChampions #Edge #Christian #Wrestling

  8. Well, I did not expect to be impressed by Edge.

    BACKGROUND: I uninstalled Google Chrome, which was my primary browser for years. For the last year or so I’ve been using LibreWolf as my primary browser, but its security settings are strict enough that some sites won’t work unless you tinker with it on a site-by-site basis. Instead of doing that, I just used Chrome for a few sites.

    BUT NOW: Since I uninstalled Chrome, I needed a browser that would work with a particular site, LibreWolf wouldn’t work, and so I used Edge.

    Oh. My. Gosh. Edge looked nimble compared to the same site on Chrome. This is a site that I visit several times a month, work related. It was never this fast on Chrome.

    So now I have to wonder, WTH was Chrome doing?

    #Chrome #Edge #browser

  9. Critical Vulnerability in KnowledgeDeliver LMS Has Been Patched

    A zero-day (CVE-2026-5426) in KnowledgeDeliver LMS is being actively exploited due to reused ASP.NET machine keys.

    Pulse ID: 6a164033c76e927d4afb9278
    Pulse Link: otx.alienvault.com/pulse/6a164
    Pulse Author: cryptocti
    Created: 2026-05-27 00:52:03

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Edge #InfoSec #Mac #NET #OTX #OpenThreatExchange #Vulnerability #ZeroDay #bot #cryptocti

  10. Critical Vulnerability in KnowledgeDeliver LMS Has Been Patched

    A zero-day (CVE-2026-5426) in KnowledgeDeliver LMS is being actively exploited due to reused ASP.NET machine keys.

    Pulse ID: 6a164033c76e927d4afb9278
    Pulse Link: otx.alienvault.com/pulse/6a164
    Pulse Author: cryptocti
    Created: 2026-05-27 00:52:03

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Edge #InfoSec #Mac #NET #OTX #OpenThreatExchange #Vulnerability #ZeroDay #bot #cryptocti

  11. Critical Vulnerability in KnowledgeDeliver LMS Has Been Patched

    A zero-day (CVE-2026-5426) in KnowledgeDeliver LMS is being actively exploited due to reused ASP.NET machine keys.

    Pulse ID: 6a164033c76e927d4afb9278
    Pulse Link: otx.alienvault.com/pulse/6a164
    Pulse Author: cryptocti
    Created: 2026-05-27 00:52:03

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Edge #InfoSec #Mac #NET #OTX #OpenThreatExchange #Vulnerability #ZeroDay #bot #cryptocti

  12. Critical Vulnerability in KnowledgeDeliver LMS Has Been Patched

    A zero-day (CVE-2026-5426) in KnowledgeDeliver LMS is being actively exploited due to reused ASP.NET machine keys.

    Pulse ID: 6a164033c76e927d4afb9278
    Pulse Link: otx.alienvault.com/pulse/6a164
    Pulse Author: cryptocti
    Created: 2026-05-27 00:52:03

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Edge #InfoSec #Mac #NET #OTX #OpenThreatExchange #Vulnerability #ZeroDay #bot #cryptocti

  13. Critical Vulnerability in KnowledgeDeliver LMS Has Been Patched

    A zero-day (CVE-2026-5426) in KnowledgeDeliver LMS is being actively exploited due to reused ASP.NET machine keys.

    Pulse ID: 6a164033c76e927d4afb9278
    Pulse Link: otx.alienvault.com/pulse/6a164
    Pulse Author: cryptocti
    Created: 2026-05-27 00:52:03

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Edge #InfoSec #Mac #NET #OTX #OpenThreatExchange #Vulnerability #ZeroDay #bot #cryptocti

  14. Critical Vulnerability in KnowledgeDeliver LMS Has Been Patched

    A zero-day (CVE-2026-5426) in KnowledgeDeliver LMS is being actively exploited due to reused ASP.NET machine keys.

    Pulse ID: 6a15820b3e17a040b5f904e1
    Pulse Link: otx.alienvault.com/pulse/6a158
    Pulse Author: cryptocti
    Created: 2026-05-26 11:20:43

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Edge #InfoSec #Mac #NET #OTX #OpenThreatExchange #Vulnerability #ZeroDay #bot #cryptocti

  15. Critical Vulnerability in KnowledgeDeliver LMS Has Been Patched

    A zero-day (CVE-2026-5426) in KnowledgeDeliver LMS is being actively exploited due to reused ASP.NET machine keys.

    Pulse ID: 6a15820b3e17a040b5f904e1
    Pulse Link: otx.alienvault.com/pulse/6a158
    Pulse Author: cryptocti
    Created: 2026-05-26 11:20:43

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Edge #InfoSec #Mac #NET #OTX #OpenThreatExchange #Vulnerability #ZeroDay #bot #cryptocti

  16. Critical Vulnerability in KnowledgeDeliver LMS Has Been Patched

    A zero-day (CVE-2026-5426) in KnowledgeDeliver LMS is being actively exploited due to reused ASP.NET machine keys.

    Pulse ID: 6a15820b3e17a040b5f904e1
    Pulse Link: otx.alienvault.com/pulse/6a158
    Pulse Author: cryptocti
    Created: 2026-05-26 11:20:43

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Edge #InfoSec #Mac #NET #OTX #OpenThreatExchange #Vulnerability #ZeroDay #bot #cryptocti

  17. Critical Vulnerability in KnowledgeDeliver LMS Has Been Patched

    A zero-day (CVE-2026-5426) in KnowledgeDeliver LMS is being actively exploited due to reused ASP.NET machine keys.

    Pulse ID: 6a15820b3e17a040b5f904e1
    Pulse Link: otx.alienvault.com/pulse/6a158
    Pulse Author: cryptocti
    Created: 2026-05-26 11:20:43

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Edge #InfoSec #Mac #NET #OTX #OpenThreatExchange #Vulnerability #ZeroDay #bot #cryptocti

  18. Critical Vulnerability in KnowledgeDeliver LMS Has Been Patched

    A zero-day (CVE-2026-5426) in KnowledgeDeliver LMS is being actively exploited due to reused ASP.NET machine keys.

    Pulse ID: 6a15820b3e17a040b5f904e1
    Pulse Link: otx.alienvault.com/pulse/6a158
    Pulse Author: cryptocti
    Created: 2026-05-26 11:20:43

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Edge #InfoSec #Mac #NET #OTX #OpenThreatExchange #Vulnerability #ZeroDay #bot #cryptocti

  19. «Chrome, #Edge, #Opera — Google-#Panne macht Millionen Internetnutzer angreifbar:
    Eine Schwachstelle in Browsern wie Chrome und #Microsoft Edge wird zur Gefahr für die User. #Google hat versehentlich einen «Exploit» veröffentlicht, mit dem Hacker die Lücke ausnutzen können»

    Nicht das erste und sicherlich auch nicht das letzte mal. Den wenigsten User*innen ist es bewusst, dass so gut wie alle popl. #Browser auf #Chrome aufbauen. #Firefox ist eine der wenigen Ausnahmen.

    🌐 watson.ch/digital/google/98516

  20. «Chrome, #Edge, #Opera — Google-#Panne macht Millionen Internetnutzer angreifbar:
    Eine Schwachstelle in Browsern wie Chrome und #Microsoft Edge wird zur Gefahr für die User. #Google hat versehentlich einen «Exploit» veröffentlicht, mit dem Hacker die Lücke ausnutzen können»

    Nicht das erste und sicherlich auch nicht das letzte mal. Den wenigsten User*innen ist es bewusst, dass so gut wie alle popl. #Browser auf #Chrome aufbauen. #Firefox ist eine der wenigen Ausnahmen.

    🌐 watson.ch/digital/google/98516

  21. «Chrome, #Edge, #Opera — Google-#Panne macht Millionen Internetnutzer angreifbar:
    Eine Schwachstelle in Browsern wie Chrome und #Microsoft Edge wird zur Gefahr für die User. #Google hat versehentlich einen «Exploit» veröffentlicht, mit dem Hacker die Lücke ausnutzen können»

    Nicht das erste und sicherlich auch nicht das letzte mal. Den wenigsten User*innen ist es bewusst, dass so gut wie alle popl. #Browser auf #Chrome aufbauen. #Firefox ist eine der wenigen Ausnahmen.

    🌐 watson.ch/digital/google/98516

  22. «Chrome, #Edge, #Opera — Google-#Panne macht Millionen Internetnutzer angreifbar:
    Eine Schwachstelle in Browsern wie Chrome und #Microsoft Edge wird zur Gefahr für die User. #Google hat versehentlich einen «Exploit» veröffentlicht, mit dem Hacker die Lücke ausnutzen können»

    Nicht das erste und sicherlich auch nicht das letzte mal. Den wenigsten User*innen ist es bewusst, dass so gut wie alle popl. #Browser auf #Chrome aufbauen. #Firefox ist eine der wenigen Ausnahmen.

    🌐 watson.ch/digital/google/98516

  23. «Chrome, #Edge, #Opera — Google-#Panne macht Millionen Internetnutzer angreifbar:
    Eine Schwachstelle in Browsern wie Chrome und #Microsoft Edge wird zur Gefahr für die User. #Google hat versehentlich einen «Exploit» veröffentlicht, mit dem Hacker die Lücke ausnutzen können»

    Nicht das erste und sicherlich auch nicht das letzte mal. Den wenigsten User*innen ist es bewusst, dass so gut wie alle popl. #Browser auf #Chrome aufbauen. #Firefox ist eine der wenigen Ausnahmen.

    🌐 watson.ch/digital/google/98516

  24. RemotePE: The Lazarus RAT that lives in memory

    A sophisticated memory-only toolset used by a North Korean Lazarus subgroup targeting financial and cryptocurrency organizations consists of three malware families forming a chain. DPAPILoader decrypts and loads RemotePELoader from disk using Windows Data Protection API. RemotePELoader beacons to command-and-control servers and retrieves RemotePE, a fully-fledged remote access trojan executed entirely in memory without filesystem artifacts. The toolset employs environmental keying via DPAPI, EDR evasion through HellsGate technique and ETW patching, actor-in-the-loop payload delivery, and shared hosting infrastructure on Namecheap. RemotePE features comprehensive RAT capabilities including file operations, process management, command execution, and a plugin system for dynamically loading additional payloads, while maintaining persistence through masquerading as legitimate Windows services.

    Pulse ID: 6a1447f25db6bc082d5093cb
    Pulse Link: otx.alienvault.com/pulse/6a144
    Pulse Author: AlienVault
    Created: 2026-05-25 13:00:34

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #EDR #Edge #InfoSec #Korea #Lazarus #Malware #Namecheap #NorthKorea #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #Windows #bot #cryptocurrency #AlienVault

  25. RemotePE: The Lazarus RAT that lives in memory

    A sophisticated memory-only toolset used by a North Korean Lazarus subgroup targeting financial and cryptocurrency organizations consists of three malware families forming a chain. DPAPILoader decrypts and loads RemotePELoader from disk using Windows Data Protection API. RemotePELoader beacons to command-and-control servers and retrieves RemotePE, a fully-fledged remote access trojan executed entirely in memory without filesystem artifacts. The toolset employs environmental keying via DPAPI, EDR evasion through HellsGate technique and ETW patching, actor-in-the-loop payload delivery, and shared hosting infrastructure on Namecheap. RemotePE features comprehensive RAT capabilities including file operations, process management, command execution, and a plugin system for dynamically loading additional payloads, while maintaining persistence through masquerading as legitimate Windows services.

    Pulse ID: 6a1447f25db6bc082d5093cb
    Pulse Link: otx.alienvault.com/pulse/6a144
    Pulse Author: AlienVault
    Created: 2026-05-25 13:00:34

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #EDR #Edge #InfoSec #Korea #Lazarus #Malware #Namecheap #NorthKorea #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #Windows #bot #cryptocurrency #AlienVault

  26. RemotePE: The Lazarus RAT that lives in memory

    A sophisticated memory-only toolset used by a North Korean Lazarus subgroup targeting financial and cryptocurrency organizations consists of three malware families forming a chain. DPAPILoader decrypts and loads RemotePELoader from disk using Windows Data Protection API. RemotePELoader beacons to command-and-control servers and retrieves RemotePE, a fully-fledged remote access trojan executed entirely in memory without filesystem artifacts. The toolset employs environmental keying via DPAPI, EDR evasion through HellsGate technique and ETW patching, actor-in-the-loop payload delivery, and shared hosting infrastructure on Namecheap. RemotePE features comprehensive RAT capabilities including file operations, process management, command execution, and a plugin system for dynamically loading additional payloads, while maintaining persistence through masquerading as legitimate Windows services.

    Pulse ID: 6a1447f25db6bc082d5093cb
    Pulse Link: otx.alienvault.com/pulse/6a144
    Pulse Author: AlienVault
    Created: 2026-05-25 13:00:34

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #EDR #Edge #InfoSec #Korea #Lazarus #Malware #Namecheap #NorthKorea #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #Windows #bot #cryptocurrency #AlienVault

  27. RemotePE: The Lazarus RAT that lives in memory

    A sophisticated memory-only toolset used by a North Korean Lazarus subgroup targeting financial and cryptocurrency organizations consists of three malware families forming a chain. DPAPILoader decrypts and loads RemotePELoader from disk using Windows Data Protection API. RemotePELoader beacons to command-and-control servers and retrieves RemotePE, a fully-fledged remote access trojan executed entirely in memory without filesystem artifacts. The toolset employs environmental keying via DPAPI, EDR evasion through HellsGate technique and ETW patching, actor-in-the-loop payload delivery, and shared hosting infrastructure on Namecheap. RemotePE features comprehensive RAT capabilities including file operations, process management, command execution, and a plugin system for dynamically loading additional payloads, while maintaining persistence through masquerading as legitimate Windows services.

    Pulse ID: 6a1447f25db6bc082d5093cb
    Pulse Link: otx.alienvault.com/pulse/6a144
    Pulse Author: AlienVault
    Created: 2026-05-25 13:00:34

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #EDR #Edge #InfoSec #Korea #Lazarus #Malware #Namecheap #NorthKorea #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #Windows #bot #cryptocurrency #AlienVault

  28. RemotePE: The Lazarus RAT that lives in memory

    A sophisticated memory-only toolset used by a North Korean Lazarus subgroup targeting financial and cryptocurrency organizations consists of three malware families forming a chain. DPAPILoader decrypts and loads RemotePELoader from disk using Windows Data Protection API. RemotePELoader beacons to command-and-control servers and retrieves RemotePE, a fully-fledged remote access trojan executed entirely in memory without filesystem artifacts. The toolset employs environmental keying via DPAPI, EDR evasion through HellsGate technique and ETW patching, actor-in-the-loop payload delivery, and shared hosting infrastructure on Namecheap. RemotePE features comprehensive RAT capabilities including file operations, process management, command execution, and a plugin system for dynamically loading additional payloads, while maintaining persistence through masquerading as legitimate Windows services.

    Pulse ID: 6a1447f25db6bc082d5093cb
    Pulse Link: otx.alienvault.com/pulse/6a144
    Pulse Author: AlienVault
    Created: 2026-05-25 13:00:34

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #EDR #Edge #InfoSec #Korea #Lazarus #Malware #Namecheap #NorthKorea #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Trojan #Windows #bot #cryptocurrency #AlienVault

  29. Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability

    In late 2025, an unknown threat actor exploited a critical zero-day vulnerability in KnowledgeDeliver, a Learning Management System widely used in Japan. The vulnerability, tracked as CVE-2026-5426, allowed unauthenticated remote code execution through ViewState deserialization attacks. The issue stemmed from identical hardcoded ASP.NET machine keys distributed across multiple customer deployments in the vendor's configuration files. Attackers obtained these keys from one deployment and used them to compromise other internet-facing instances. Following initial access, threat actors deployed the BLUEBEAM in-memory web shell, modified JavaScript files to display fake security alerts, and tricked users into installing malicious software that delivered Cobalt Strike BEACON backdoors. The attack demonstrates the severe risks of shared secrets in deployment templates and highlights the importance of unique cryptographic keys per installation.

    Pulse ID: 6a140384686e44f07358066d
    Pulse Link: otx.alienvault.com/pulse/6a140
    Pulse Author: AlienVault
    Created: 2026-05-25 08:08:36

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CobaltStrike #CyberSecurity #Edge #InfoSec #Japan #Java #JavaScript #Mac #NET #OTX #OpenThreatExchange #RAT #RemoteCodeExecution #Vulnerability #ZeroDay #bot #AlienVault

  30. From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5 and Confluence

    A sophisticated multi-stage intrusion began with the compromise of an internet-facing F5 BIG-IP load balancer running an end-of-life version. The threat actor established SSH access to a Linux server using privileged credentials, then conducted extensive reconnaissance including network scanning with Nmap and service enumeration with gowitness. Following horizontal and vertical scanning operations, the actor identified and compromised an unpatched internal Atlassian Confluence server via remote code execution. Credentials extracted from Confluence configuration files were subsequently used to attempt Kerberos relay attacks against Active Directory infrastructure and exploit CVE-2025-33073. The incident demonstrates how edge device compromises enable lateral movement across hybrid environments, bypassing traditional security controls through trusted relationships and exploiting insufficient monitoring of non-Windows systems and internal applications.

    Pulse ID: 6a10949191ce7d3c3f2f8105
    Pulse Link: otx.alienvault.com/pulse/6a109
    Pulse Author: AlienVault
    Created: 2026-05-22 17:38:25

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Atlassian #Confluence #CyberSecurity #Edge #InfoSec #Linux #OTX #OpenThreatExchange #RAT #RemoteCodeExecution #Rust #SSH #Windows #bot #AlienVault

  31. From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5 and Confluence

    A sophisticated multi-stage intrusion began with the compromise of an internet-facing F5 BIG-IP load balancer running an end-of-life version. The threat actor established SSH access to a Linux server using privileged credentials, then conducted extensive reconnaissance including network scanning with Nmap and service enumeration with gowitness. Following horizontal and vertical scanning operations, the actor identified and compromised an unpatched internal Atlassian Confluence server via remote code execution. Credentials extracted from Confluence configuration files were subsequently used to attempt Kerberos relay attacks against Active Directory infrastructure and exploit CVE-2025-33073. The incident demonstrates how edge device compromises enable lateral movement across hybrid environments, bypassing traditional security controls through trusted relationships and exploiting insufficient monitoring of non-Windows systems and internal applications.

    Pulse ID: 6a10949191ce7d3c3f2f8105
    Pulse Link: otx.alienvault.com/pulse/6a109
    Pulse Author: AlienVault
    Created: 2026-05-22 17:38:25

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Atlassian #Confluence #CyberSecurity #Edge #InfoSec #Linux #OTX #OpenThreatExchange #RAT #RemoteCodeExecution #Rust #SSH #Windows #bot #AlienVault

  32. From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5 and Confluence

    A sophisticated multi-stage intrusion began with the compromise of an internet-facing F5 BIG-IP load balancer running an end-of-life version. The threat actor established SSH access to a Linux server using privileged credentials, then conducted extensive reconnaissance including network scanning with Nmap and service enumeration with gowitness. Following horizontal and vertical scanning operations, the actor identified and compromised an unpatched internal Atlassian Confluence server via remote code execution. Credentials extracted from Confluence configuration files were subsequently used to attempt Kerberos relay attacks against Active Directory infrastructure and exploit CVE-2025-33073. The incident demonstrates how edge device compromises enable lateral movement across hybrid environments, bypassing traditional security controls through trusted relationships and exploiting insufficient monitoring of non-Windows systems and internal applications.

    Pulse ID: 6a10949191ce7d3c3f2f8105
    Pulse Link: otx.alienvault.com/pulse/6a109
    Pulse Author: AlienVault
    Created: 2026-05-22 17:38:25

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Atlassian #Confluence #CyberSecurity #Edge #InfoSec #Linux #OTX #OpenThreatExchange #RAT #RemoteCodeExecution #Rust #SSH #Windows #bot #AlienVault

  33. From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5 and Confluence

    A sophisticated multi-stage intrusion began with the compromise of an internet-facing F5 BIG-IP load balancer running an end-of-life version. The threat actor established SSH access to a Linux server using privileged credentials, then conducted extensive reconnaissance including network scanning with Nmap and service enumeration with gowitness. Following horizontal and vertical scanning operations, the actor identified and compromised an unpatched internal Atlassian Confluence server via remote code execution. Credentials extracted from Confluence configuration files were subsequently used to attempt Kerberos relay attacks against Active Directory infrastructure and exploit CVE-2025-33073. The incident demonstrates how edge device compromises enable lateral movement across hybrid environments, bypassing traditional security controls through trusted relationships and exploiting insufficient monitoring of non-Windows systems and internal applications.

    Pulse ID: 6a10949191ce7d3c3f2f8105
    Pulse Link: otx.alienvault.com/pulse/6a109
    Pulse Author: AlienVault
    Created: 2026-05-22 17:38:25

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Atlassian #Confluence #CyberSecurity #Edge #InfoSec #Linux #OTX #OpenThreatExchange #RAT #RemoteCodeExecution #Rust #SSH #Windows #bot #AlienVault

  34. From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5 and Confluence

    A sophisticated multi-stage intrusion began with the compromise of an internet-facing F5 BIG-IP load balancer running an end-of-life version. The threat actor established SSH access to a Linux server using privileged credentials, then conducted extensive reconnaissance including network scanning with Nmap and service enumeration with gowitness. Following horizontal and vertical scanning operations, the actor identified and compromised an unpatched internal Atlassian Confluence server via remote code execution. Credentials extracted from Confluence configuration files were subsequently used to attempt Kerberos relay attacks against Active Directory infrastructure and exploit CVE-2025-33073. The incident demonstrates how edge device compromises enable lateral movement across hybrid environments, bypassing traditional security controls through trusted relationships and exploiting insufficient monitoring of non-Windows systems and internal applications.

    Pulse ID: 6a10949191ce7d3c3f2f8105
    Pulse Link: otx.alienvault.com/pulse/6a109
    Pulse Author: AlienVault
    Created: 2026-05-22 17:38:25

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Atlassian #Confluence #CyberSecurity #Edge #InfoSec #Linux #OTX #OpenThreatExchange #RAT #RemoteCodeExecution #Rust #SSH #Windows #bot #AlienVault

  35. #Mastodon 画像の取得に失敗したままになってる。
    #Firefox のキャッシュの問題か?と思って、画像のURLに #Edge で直接アクセスしたら同じだったので、取得に失敗してそのままなんだと思う。

  36. #Mastodon 画像の取得に失敗したままになってる。
    #Firefox のキャッシュの問題か?と思って、画像のURLに #Edge で直接アクセスしたら同じだったので、取得に失敗してそのままなんだと思う。

  37. Sólo Firefox te permite copiar datos de tablas tan fácil

    Edición: Me refiero a datos de una sola columna dentro de las tablas.

    Es una función que descubrí hace 2 años y me ha ahorrado infinidad de tiempo y de problemas de túnel carpiano. No la tiene ningún otro navegador que conozca, sólo #Firefox y sin necesidad de extensiones o configuraciones raras 😎🔥🦊

    Bueno, de Vivaldi no estoy tan seguro, ¿me ayudan a verificar?

    #TiddlyBlog de leoperbo — Una bitácora no lineal
    tiddlyblog.welhaba.mx/static/S

    #chromium #edge #brave #vivaldi #safari

  38. Sólo Firefox te permite copiar datos de tablas tan fácil

    Edición: Me refiero a datos de una sola columna dentro de las tablas.

    Es una función que descubrí hace 2 años y me ha ahorrado infinidad de tiempo y de problemas de túnel carpiano. No la tiene ningún otro navegador que conozca, sólo #Firefox y sin necesidad de extensiones o configuraciones raras 😎🔥🦊

    Bueno, de Vivaldi no estoy tan seguro, ¿me ayudan a verificar?

    #TiddlyBlog de leoperbo — Una bitácora no lineal
    tiddlyblog.welhaba.mx/static/S

    #chromium #edge #brave #vivaldi #safari

  39. Sólo Firefox te permite copiar datos de tablas tan fácil

    Edición: Me refiero a datos de una sola columna dentro de las tablas.

    Es una función que descubrí hace 2 años y me ha ahorrado infinidad de tiempo y de problemas de túnel carpiano. No la tiene ningún otro navegador que conozca, sólo #Firefox y sin necesidad de extensiones o configuraciones raras 😎🔥🦊

    Bueno, de Vivaldi no estoy tan seguro, ¿me ayudan a verificar?

    #TiddlyBlog de leoperbo — Una bitácora no lineal
    tiddlyblog.welhaba.mx/static/S

    #chromium #edge #brave #vivaldi #safari

  40. Sólo Firefox te permite copiar datos de tablas tan fácil

    Edición: Me refiero a datos de una sola columna dentro de las tablas.

    Es una función que descubrí hace 2 años y me ha ahorrado infinidad de tiempo y de problemas de túnel carpiano. No la tiene ningún otro navegador que conozca, sólo #Firefox y sin necesidad de extensiones o configuraciones raras 😎🔥🦊

    Bueno, de Vivaldi no estoy tan seguro, ¿me ayudan a verificar?

    #TiddlyBlog de leoperbo — Una bitácora no lineal
    tiddlyblog.welhaba.mx/static/S

    #chromium #edge #brave #vivaldi #safari

  41. Sólo Firefox te permite copiar datos de tablas tan fácil

    Edición: Me refiero a datos de una sola columna dentro de las tablas.

    Es una función que descubrí hace 2 años y me ha ahorrado infinidad de tiempo y de problemas de túnel carpiano. No la tiene ningún otro navegador que conozca, sólo #Firefox y sin necesidad de extensiones o configuraciones raras 😎🔥🦊

    Bueno, de Vivaldi no estoy tan seguro, ¿me ayudan a verificar?

    #TiddlyBlog de leoperbo — Una bitácora no lineal
    tiddlyblog.welhaba.mx/static/S

    #chromium #edge #brave #vivaldi #safari