#endpoint — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #endpoint, aggregated by home.social.
-
Expired DMARC reporting endpoint exposed a NYSE Fortune 1000's infrastructure for $10
Indicators extracted from public reporting. Source: https://www.reddit.com/r/netsec/comments/1vlsvsn/expired_dmarc_reporting_endpoint_exposed_a_nyse/
Pulse ID: 6a7b8c9bcdf961230075cfe4
Pulse Link: https://otx.alienvault.com/pulse/6a7b8c9bcdf961230075cfe4
Pulse Author: CyberHunter_NL
Created: 2026-08-11 20:56:59Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Endpoint #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
Expired DMARC reporting endpoint exposed a NYSE Fortune 1000's infrastructure for $10
Indicators extracted from public reporting. Source: https://www.reddit.com/r/netsec/comments/1vlsvsn/expired_dmarc_reporting_endpoint_exposed_a_nyse/
Pulse ID: 6a7b8c9bcdf961230075cfe4
Pulse Link: https://otx.alienvault.com/pulse/6a7b8c9bcdf961230075cfe4
Pulse Author: CyberHunter_NL
Created: 2026-08-11 20:56:59Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Endpoint #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
An Evolution of the Botnet
A new version of the Kimwolf Android/IoT botnet has been identified, targeting Android TV boxes and set-top boxes. The version 7 variant introduces enhanced DDoS capabilities including HTTP/2-based floods with complete browser fingerprinting to mimic legitimate traffic. It employs a resilient three-tier command-and-control infrastructure using Ethereum Name Service resolution through five hard-coded public endpoints, a Tor hidden service backup, and local proxy architecture. The malware spreads by exploiting unauthenticated Android Debug Bridge instances via residential proxy services. The botnet implements 15 DDoS attack methods and utilizes ARM NEON SIMD optimization for high-performance UDP floods. Operators removed scanning and exploitation modules, separating propagation from DDoS functionality. The infrastructure is hosted primarily in Russia, with evidence of operator-controlled Ethereum RPC endpoints.
Pulse ID: 6a7b3ea11dca2e714d4bff8d
Pulse Link: https://otx.alienvault.com/pulse/6a7b3ea11dca2e714d4bff8d
Pulse Author: AlienVault
Created: 2026-08-11 15:24:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Android #Browser #CyberSecurity #DDoS #DoS #Endpoint #HTTP #InfoSec #IoT #Malware #Mimic #OTX #OpenThreatExchange #Proxy #RAT #RPC #Russia #Troll #UDP #bot #botnet #AlienVault
-
An Evolution of the Botnet
A new version of the Kimwolf Android/IoT botnet has been identified, targeting Android TV boxes and set-top boxes. The version 7 variant introduces enhanced DDoS capabilities including HTTP/2-based floods with complete browser fingerprinting to mimic legitimate traffic. It employs a resilient three-tier command-and-control infrastructure using Ethereum Name Service resolution through five hard-coded public endpoints, a Tor hidden service backup, and local proxy architecture. The malware spreads by exploiting unauthenticated Android Debug Bridge instances via residential proxy services. The botnet implements 15 DDoS attack methods and utilizes ARM NEON SIMD optimization for high-performance UDP floods. Operators removed scanning and exploitation modules, separating propagation from DDoS functionality. The infrastructure is hosted primarily in Russia, with evidence of operator-controlled Ethereum RPC endpoints.
Pulse ID: 6a7b3ea11dca2e714d4bff8d
Pulse Link: https://otx.alienvault.com/pulse/6a7b3ea11dca2e714d4bff8d
Pulse Author: AlienVault
Created: 2026-08-11 15:24:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Android #Browser #CyberSecurity #DDoS #DoS #Endpoint #HTTP #InfoSec #IoT #Malware #Mimic #OTX #OpenThreatExchange #Proxy #RAT #RPC #Russia #Troll #UDP #bot #botnet #AlienVault
-
The Permanent Threat: Analyzing Blockchain-Based C2 Operations and Communications
Aeternum is a C++ botnet loader utilizing the Polygon blockchain for command-and-control infrastructure instead of traditional centralized servers. Threat actors write encrypted and plaintext instructions directly to smart contracts, which infected devices query via public RPC endpoints. The malware implements weak PBKDF2HMAC/AES-GCM encryption with self-salting passwords, allowing payload decryption using only the smart contract address. Analysis reveals three related samples: the core Aeternum loader with Telegram-based exfiltration, a blended threat combining XWorm RAT with XMRig cryptocurrency miner, and Python source code revealing anti-analysis checks and cryptocurrency wallet targeting. The botnet demonstrates resilience through decentralized infrastructure, making traditional law enforcement takedowns significantly more challenging while maintaining low operational costs for attackers.
Pulse ID: 6a7a8be76fe0dfa36d01afa0
Pulse Link: https://otx.alienvault.com/pulse/6a7a8be76fe0dfa36d01afa0
Pulse Author: AlienVault
Created: 2026-08-11 02:41:43Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #CyberSecurity #ELF #Encryption #Endpoint #InfoSec #LawEnforcement #Mac #Malware #OTX #OpenThreatExchange #Password #Passwords #Python #RAT #RCE #RPC #Telegram #Word #Worm #XWorm #bot #botnet #cryptocurrency #AlienVault
-
The Permanent Threat: Analyzing Blockchain-Based C2 Operations and Communications
Aeternum is a C++ botnet loader utilizing the Polygon blockchain for command-and-control infrastructure instead of traditional centralized servers. Threat actors write encrypted and plaintext instructions directly to smart contracts, which infected devices query via public RPC endpoints. The malware implements weak PBKDF2HMAC/AES-GCM encryption with self-salting passwords, allowing payload decryption using only the smart contract address. Analysis reveals three related samples: the core Aeternum loader with Telegram-based exfiltration, a blended threat combining XWorm RAT with XMRig cryptocurrency miner, and Python source code revealing anti-analysis checks and cryptocurrency wallet targeting. The botnet demonstrates resilience through decentralized infrastructure, making traditional law enforcement takedowns significantly more challenging while maintaining low operational costs for attackers.
Pulse ID: 6a7a8be76fe0dfa36d01afa0
Pulse Link: https://otx.alienvault.com/pulse/6a7a8be76fe0dfa36d01afa0
Pulse Author: AlienVault
Created: 2026-08-11 02:41:43Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #CyberSecurity #ELF #Encryption #Endpoint #InfoSec #LawEnforcement #Mac #Malware #OTX #OpenThreatExchange #Password #Passwords #Python #RAT #RCE #RPC #Telegram #Word #Worm #XWorm #bot #botnet #cryptocurrency #AlienVault
-
CVE-2026-18577: N-able N-central Authentication Bypass Lets Attackers Reach Managed Endpoints
Indicators extracted from public reporting. Source: https://socprime.com/blog/cve-2026-18577-analysis/
Pulse ID: 6a79ad114505d2fde4906392
Pulse Link: https://otx.alienvault.com/pulse/6a79ad114505d2fde4906392
Pulse Author: CyberHunter_NL
Created: 2026-08-10 10:50:57Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Endpoint #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
CVE-2026-18577: N-able N-central Authentication Bypass Lets Attackers Reach Managed Endpoints
Indicators extracted from public reporting. Source: https://socprime.com/blog/cve-2026-18577-analysis/
Pulse ID: 6a79ad114505d2fde4906392
Pulse Link: https://otx.alienvault.com/pulse/6a79ad114505d2fde4906392
Pulse Author: CyberHunter_NL
Created: 2026-08-10 10:50:57Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Endpoint #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
Authentication Bypass Vulnerability in N-central Exploited In-The-Wild
An authentication bypass vulnerability, CVE-2026-18577, affecting N-able N-central Remote Monitoring and Management platform has been actively exploited since August 1, 2026. This vulnerability emerged after an incomplete fix for a previous authentication bypass issue CVE-2026-18556. The flaw allows remote unauthenticated attackers to bypass authentication mechanisms and gain administrative control over vulnerable N-central servers. Attackers have exploited this vulnerability to leverage the platform's Take Control functionality for remote access to managed endpoints and deployed Cloudflare Tunnel (cloudflared) to establish persistent remote access. Given that N-central is widely used by managed service providers and enterprise IT teams with extensive administrative privileges, successful compromise provides attackers an efficient pathway to compromise downstream managed systems. CISA added this vulnerability to its Known Exploited Vulnerability catalog on August 3, 2026.
Pulse ID: 6a74564f0edb6c8f24fda004
Pulse Link: https://otx.alienvault.com/pulse/6a74564f0edb6c8f24fda004
Pulse Author: AlienVault
Created: 2026-08-06 09:39:27Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CISA #Cloud #CyberSecurity #Endpoint #InfoSec #OTX #OpenThreatExchange #RAT #SMS #Vulnerability #bot #AlienVault
-
Authentication Bypass Vulnerability in N-central Exploited In-The-Wild
An authentication bypass vulnerability, CVE-2026-18577, affecting N-able N-central Remote Monitoring and Management platform has been actively exploited since August 1, 2026. This vulnerability emerged after an incomplete fix for a previous authentication bypass issue CVE-2026-18556. The flaw allows remote unauthenticated attackers to bypass authentication mechanisms and gain administrative control over vulnerable N-central servers. Attackers have exploited this vulnerability to leverage the platform's Take Control functionality for remote access to managed endpoints and deployed Cloudflare Tunnel (cloudflared) to establish persistent remote access. Given that N-central is widely used by managed service providers and enterprise IT teams with extensive administrative privileges, successful compromise provides attackers an efficient pathway to compromise downstream managed systems. CISA added this vulnerability to its Known Exploited Vulnerability catalog on August 3, 2026.
Pulse ID: 6a74564f0edb6c8f24fda004
Pulse Link: https://otx.alienvault.com/pulse/6a74564f0edb6c8f24fda004
Pulse Author: AlienVault
Created: 2026-08-06 09:39:27Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CISA #Cloud #CyberSecurity #Endpoint #InfoSec #OTX #OpenThreatExchange #RAT #SMS #Vulnerability #bot #AlienVault
-
Major Shai Hulud campaign strikes npm again, affecting keyv and 400+ packages
A sophisticated supply-chain attack campaign named Shai-Hulud has compromised over 400 npm packages across 1700+ versions, beginning with keyv and cacheable libraries. The malware operates as a self-propagating worm that collects credentials from local filesystems, CI/CD environments, cloud platforms, Kubernetes clusters, and HashiCorp Vault. It exfiltrates stolen data through dynamic HTTPS endpoints or public GitHub repositories, then uses compromised npm tokens to publish infected versions of all writable packages. The campaign also injects execution hooks into GitHub repositories via VS Code and Claude configuration files, harvests GitHub Actions secrets through injected workflows, and includes a targeted attack against npm trusted publishing flows. Command and control infrastructure leverages Ethereum smart contracts and GitHub commit messages for resilience.
Pulse ID: 6a74570cf5cc7a08cd8e9903
Pulse Link: https://otx.alienvault.com/pulse/6a74570cf5cc7a08cd8e9903
Pulse Author: AlienVault
Created: 2026-08-06 09:42:36Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #ELF #Endpoint #GitHub #HTTP #HTTPS #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #Rust #Worm #bot #AlienVault
-
Major Shai Hulud campaign strikes npm again, affecting keyv and 400+ packages
A sophisticated supply-chain attack campaign named Shai-Hulud has compromised over 400 npm packages across 1700+ versions, beginning with keyv and cacheable libraries. The malware operates as a self-propagating worm that collects credentials from local filesystems, CI/CD environments, cloud platforms, Kubernetes clusters, and HashiCorp Vault. It exfiltrates stolen data through dynamic HTTPS endpoints or public GitHub repositories, then uses compromised npm tokens to publish infected versions of all writable packages. The campaign also injects execution hooks into GitHub repositories via VS Code and Claude configuration files, harvests GitHub Actions secrets through injected workflows, and includes a targeted attack against npm trusted publishing flows. Command and control infrastructure leverages Ethereum smart contracts and GitHub commit messages for resilience.
Pulse ID: 6a74570cf5cc7a08cd8e9903
Pulse Link: https://otx.alienvault.com/pulse/6a74570cf5cc7a08cd8e9903
Pulse Author: AlienVault
Created: 2026-08-06 09:42:36Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #ELF #Endpoint #GitHub #HTTP #HTTPS #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #Rust #Worm #bot #AlienVault
-
Here We Go Again - JavaScript Payload Analysis
A 710 KB JavaScript payload was discovered in the compromised [email protected] package, representing a newer variant of Shai-Hulud with enhanced obfuscation techniques. The malicious code operates with four primary objectives: harvesting credentials from local systems, CI environments, cloud platforms, Kubernetes, and Vault; exfiltrating encrypted data through dynamic HTTPS endpoints or public GitHub repositories; leveraging stolen npm credentials to publish infected patch releases across accessible packages; and exploiting GitHub credentials with GitHub Actions to compromise repositories and extract additional credentials. The campaign demonstrates sophisticated supply chain attack capabilities, targeting the npm ecosystem and development infrastructure. Multiple components were identified including obfuscated JavaScript files, VS Code configuration files, and injected GitHub Actions workflows, indicating a comprehensive approach to credential theft and lateral movement across development environments.
Pulse ID: 6a745746ff40fa3e996fe0ec
Pulse Link: https://otx.alienvault.com/pulse/6a745746ff40fa3e996fe0ec
Pulse Author: AlienVault
Created: 2026-08-06 09:43:34Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #Endpoint #GitHub #HTTP #HTTPS #InfoSec #Java #JavaScript #NPM #OTX #OpenThreatExchange #RAT #SupplyChain #bot #AlienVault
-
Here We Go Again - JavaScript Payload Analysis
A 710 KB JavaScript payload was discovered in the compromised [email protected] package, representing a newer variant of Shai-Hulud with enhanced obfuscation techniques. The malicious code operates with four primary objectives: harvesting credentials from local systems, CI environments, cloud platforms, Kubernetes, and Vault; exfiltrating encrypted data through dynamic HTTPS endpoints or public GitHub repositories; leveraging stolen npm credentials to publish infected patch releases across accessible packages; and exploiting GitHub credentials with GitHub Actions to compromise repositories and extract additional credentials. The campaign demonstrates sophisticated supply chain attack capabilities, targeting the npm ecosystem and development infrastructure. Multiple components were identified including obfuscated JavaScript files, VS Code configuration files, and injected GitHub Actions workflows, indicating a comprehensive approach to credential theft and lateral movement across development environments.
Pulse ID: 6a745746ff40fa3e996fe0ec
Pulse Link: https://otx.alienvault.com/pulse/6a745746ff40fa3e996fe0ec
Pulse Author: AlienVault
Created: 2026-08-06 09:43:34Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #Endpoint #GitHub #HTTP #HTTPS #InfoSec #Java #JavaScript #NPM #OTX #OpenThreatExchange #RAT #SupplyChain #bot #AlienVault
-
How fake signups drive AI fraud
A thriving gray market has emerged offering discounted access to AI models through fraudulent account registrations that exploit free trials and startup credits. Services like Poison Claude and Ecomagent offer 70-90% discounts by creating fake accounts on platforms such as AWS Bedrock and Google Cloud, then reselling access through custom API endpoints. The demand is driven by cost considerations, access restrictions in regions like China, and desire for anonymity. Fraudulent registration campaigns targeting AI video services show over 105,000 brute-force signup attempts using bots, VPNs, and disposable email domains. The operations leverage residential proxies to evade detection and accept cryptocurrency payments. These services operate through sophisticated AI gateways and are advertised on underground forums and messaging platforms, particularly in Chinese-language markets, representing a significant platform abuse challenge for AI service providers.
Pulse ID: 6a7386e5ce9f6bd78c7da52b
Pulse Link: https://otx.alienvault.com/pulse/6a7386e5ce9f6bd78c7da52b
Pulse Author: AlienVault
Created: 2026-08-05 18:54:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #China #Chinese #Cloud #CyberSecurity #EDR #Email #Endpoint #Google #InfoSec #OTX #OpenThreatExchange #RAT #RCE #VPN #bot #cryptocurrency #AlienVault
-
How fake signups drive AI fraud
A thriving gray market has emerged offering discounted access to AI models through fraudulent account registrations that exploit free trials and startup credits. Services like Poison Claude and Ecomagent offer 70-90% discounts by creating fake accounts on platforms such as AWS Bedrock and Google Cloud, then reselling access through custom API endpoints. The demand is driven by cost considerations, access restrictions in regions like China, and desire for anonymity. Fraudulent registration campaigns targeting AI video services show over 105,000 brute-force signup attempts using bots, VPNs, and disposable email domains. The operations leverage residential proxies to evade detection and accept cryptocurrency payments. These services operate through sophisticated AI gateways and are advertised on underground forums and messaging platforms, particularly in Chinese-language markets, representing a significant platform abuse challenge for AI service providers.
Pulse ID: 6a7386e5ce9f6bd78c7da52b
Pulse Link: https://otx.alienvault.com/pulse/6a7386e5ce9f6bd78c7da52b
Pulse Author: AlienVault
Created: 2026-08-05 18:54:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #China #Chinese #Cloud #CyberSecurity #EDR #Email #Endpoint #Google #InfoSec #OTX #OpenThreatExchange #RAT #RCE #VPN #bot #cryptocurrency #AlienVault
-
ENDLESSDOORS Is Phoning Home. Pick Up.
Zbtlink routers, manufactured by Shenzhen Zhibotong Electronics and sold globally under multiple brand names including Wiflyer, contain a pre-installed backdoor implant named ENDLESSDOORS. This implant, based on the open-source rctl tool, runs as disguised userland processes named 'kworker' and continuously attempts to contact command and control servers. The backdoor provides unauthenticated remote root access through plaintext communication on ports 7000 and 7001, allowing attackers to execute arbitrary commands or spawn interactive shells without any verification. Twenty different router models are confirmed affected, all phoning home to four primary endpoints including zbtctl.epplink.net and hardcoded IP addresses hosted on Alibaba Cloud. The vulnerability is assigned CVE-2026-66747. No fixed firmware exists as the backdoor appears intentionally embedded by the manufacturer across multiple firmware versions spanning several years.
Pulse ID: 6a734a554923448bd690f87e
Pulse Link: https://otx.alienvault.com/pulse/6a734a554923448bd690f87e
Pulse Author: AlienVault
Created: 2026-08-05 14:36:05Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Cloud #CyberSecurity #Endpoint #ICS #InfoSec #NET #OTX #OpenThreatExchange #RCE #Vulnerability #bot #AlienVault
-
ENDLESSDOORS Is Phoning Home. Pick Up.
Zbtlink routers, manufactured by Shenzhen Zhibotong Electronics and sold globally under multiple brand names including Wiflyer, contain a pre-installed backdoor implant named ENDLESSDOORS. This implant, based on the open-source rctl tool, runs as disguised userland processes named 'kworker' and continuously attempts to contact command and control servers. The backdoor provides unauthenticated remote root access through plaintext communication on ports 7000 and 7001, allowing attackers to execute arbitrary commands or spawn interactive shells without any verification. Twenty different router models are confirmed affected, all phoning home to four primary endpoints including zbtctl.epplink.net and hardcoded IP addresses hosted on Alibaba Cloud. The vulnerability is assigned CVE-2026-66747. No fixed firmware exists as the backdoor appears intentionally embedded by the manufacturer across multiple firmware versions spanning several years.
Pulse ID: 6a734a554923448bd690f87e
Pulse Link: https://otx.alienvault.com/pulse/6a734a554923448bd690f87e
Pulse Author: AlienVault
Created: 2026-08-05 14:36:05Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Cloud #CyberSecurity #Endpoint #ICS #InfoSec #NET #OTX #OpenThreatExchange #RCE #Vulnerability #bot #AlienVault
-
Fake CAPTCHA, Real Business: Traffic Distribution for Hire
A sophisticated traffic distribution system has been operating for over 14 months, using more than 12,700 structurally similar fake CAPTCHA PDFs hosted on Webflow's CDN. The operation begins with search engine optimization, where victims searching for legitimate content encounter malicious PDFs through Google searches. These documents contain fake CAPTCHA panels that route users through a custom Elixir/Phoenix traffic distribution system employing IP filtering, bot detection, and geographic targeting. The infrastructure sorts visitors and redirects qualifying traffic to three distinct endpoints: Legion Loader distribution, a TDS reseller gate, and premium-SMS subscription scams targeting Spanish-speaking users. Non-qualifying traffic is monetized through search-arbitrage advertising. The operation primarily targets English-speaking countries and has recently been surfaced by AI assistants including Google Gemini and Claude, expanding its reach beyond traditional search engines.
Pulse ID: 6a734a570822e0edf4d1fdb5
Pulse Link: https://otx.alienvault.com/pulse/6a734a570822e0edf4d1fdb5
Pulse Author: AlienVault
Created: 2026-08-05 14:36:07Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CAPTCHA #CDN #CyberSecurity #Endpoint #Google #InfoSec #OTX #OpenThreatExchange #PDF #RAT #SMS #bot #AlienVault
-
Fake CAPTCHA, Real Business: Traffic Distribution for Hire
A sophisticated traffic distribution system has been operating for over 14 months, using more than 12,700 structurally similar fake CAPTCHA PDFs hosted on Webflow's CDN. The operation begins with search engine optimization, where victims searching for legitimate content encounter malicious PDFs through Google searches. These documents contain fake CAPTCHA panels that route users through a custom Elixir/Phoenix traffic distribution system employing IP filtering, bot detection, and geographic targeting. The infrastructure sorts visitors and redirects qualifying traffic to three distinct endpoints: Legion Loader distribution, a TDS reseller gate, and premium-SMS subscription scams targeting Spanish-speaking users. Non-qualifying traffic is monetized through search-arbitrage advertising. The operation primarily targets English-speaking countries and has recently been surfaced by AI assistants including Google Gemini and Claude, expanding its reach beyond traditional search engines.
Pulse ID: 6a734a570822e0edf4d1fdb5
Pulse Link: https://otx.alienvault.com/pulse/6a734a570822e0edf4d1fdb5
Pulse Author: AlienVault
Created: 2026-08-05 14:36:07Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CAPTCHA #CDN #CyberSecurity #Endpoint #Google #InfoSec #OTX #OpenThreatExchange #PDF #RAT #SMS #bot #AlienVault
-
QuickFox Supply Chain Attack Used to Deploy FDMTP Implant
A long-running campaign compromised the QuickFox VPN application, primarily used by Chinese users to access Chinese resources and improve gaming experiences. Active since August 2025, the attack involved trojanized Windows installers (versions 3.0.51.0 through 3.59.5) that deployed malicious JavaScript through modified Electron renderer HTML files. The JavaScript loader fingerprinted victim endpoints using process-based guardrails, checking for specific applications including administrative tools, cryptocurrency wallets, and Chinese translation software while avoiding Steam users. Successfully profiled targets received an FDMTP implant through DLL sideloading techniques using legitimate Microsoft Azure binaries. The infrastructure demonstrates active development with multiple staging domains masquerading as legitimate services. QuickFox removed malicious components from version 3.59.6 following responsible disclosure. Technical overlaps suggest possible connections to Twill Typhoon, though attribution remain
Pulse ID: 6a72f492ee9dc3fc24d86c17
Pulse Link: https://otx.alienvault.com/pulse/6a72f492ee9dc3fc24d86c17
Pulse Author: AlienVault
Created: 2026-08-05 08:30:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Azure #Chinese #CyberSecurity #Endpoint #HTML #InfoSec #Java #JavaScript #Microsoft #OTX #OpenThreatExchange #RAT #RCE #SideLoading #Steam #SupplyChain #Trojan #VPN #Windows #bot #cryptocurrency #AlienVault
-
QuickFox Supply Chain Attack Used to Deploy FDMTP Implant
A long-running campaign compromised the QuickFox VPN application, primarily used by Chinese users to access Chinese resources and improve gaming experiences. Active since August 2025, the attack involved trojanized Windows installers (versions 3.0.51.0 through 3.59.5) that deployed malicious JavaScript through modified Electron renderer HTML files. The JavaScript loader fingerprinted victim endpoints using process-based guardrails, checking for specific applications including administrative tools, cryptocurrency wallets, and Chinese translation software while avoiding Steam users. Successfully profiled targets received an FDMTP implant through DLL sideloading techniques using legitimate Microsoft Azure binaries. The infrastructure demonstrates active development with multiple staging domains masquerading as legitimate services. QuickFox removed malicious components from version 3.59.6 following responsible disclosure. Technical overlaps suggest possible connections to Twill Typhoon, though attribution remain
Pulse ID: 6a72f492ee9dc3fc24d86c17
Pulse Link: https://otx.alienvault.com/pulse/6a72f492ee9dc3fc24d86c17
Pulse Author: AlienVault
Created: 2026-08-05 08:30:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Azure #Chinese #CyberSecurity #Endpoint #HTML #InfoSec #Java #JavaScript #Microsoft #OTX #OpenThreatExchange #RAT #RCE #SideLoading #Steam #SupplyChain #Trojan #VPN #Windows #bot #cryptocurrency #AlienVault
-
A China-Nexus Campaign Against Government Infrastructure
China-nexus threat actors have deployed a highly opportunistic automated spray-and-check campaign to compromise global government and commercial infrastructure across more than 100 countries. The operation utilizes centralized multi-platform attack infrastructure featuring cracked Cobalt-Strike derivatives and a sophisticated loader ecosystem. Attackers leverage primary infrastructure at 130.94.17.180 for scanning, exploitation, command-and-control, and payload hosting. The campaign employs stage-2 and stage-3 payloads delivered through architecture-specific loaders targeting both Linux and Windows systems. Transport variants include TCP, WebSocket, and KCP protocols. The SNOWLIGHT loader panel manages payload delivery through multiple endpoints. Organizations face persistent threats requiring immediate patching of exposed services, implementation of strong multi-factor authentication, and continuous monitoring for compromise indicators.
Pulse ID: 6a706203d3aa16bfed001a51
Pulse Link: https://otx.alienvault.com/pulse/6a706203d3aa16bfed001a51
Pulse Author: AlienVault
Created: 2026-08-03 09:40:19Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#China #CyberSecurity #Endpoint #Government #InfoSec #Linux #OTX #OpenThreatExchange #RAT #TCP #Windows #bot #AlienVault
-
A China-Nexus Campaign Against Government Infrastructure
China-nexus threat actors have deployed a highly opportunistic automated spray-and-check campaign to compromise global government and commercial infrastructure across more than 100 countries. The operation utilizes centralized multi-platform attack infrastructure featuring cracked Cobalt-Strike derivatives and a sophisticated loader ecosystem. Attackers leverage primary infrastructure at 130.94.17.180 for scanning, exploitation, command-and-control, and payload hosting. The campaign employs stage-2 and stage-3 payloads delivered through architecture-specific loaders targeting both Linux and Windows systems. Transport variants include TCP, WebSocket, and KCP protocols. The SNOWLIGHT loader panel manages payload delivery through multiple endpoints. Organizations face persistent threats requiring immediate patching of exposed services, implementation of strong multi-factor authentication, and continuous monitoring for compromise indicators.
Pulse ID: 6a706203d3aa16bfed001a51
Pulse Link: https://otx.alienvault.com/pulse/6a706203d3aa16bfed001a51
Pulse Author: AlienVault
Created: 2026-08-03 09:40:19Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#China #CyberSecurity #Endpoint #Government #InfoSec #Linux #OTX #OpenThreatExchange #RAT #TCP #Windows #bot #AlienVault
-
Shai-Hulud-Style npm Worm Hits
Multiple npm packages across @tanstack, @mistralai, @uipath, @squawk, and safe-action namespaces were compromised in a worm-like attack affecting over 50 packages. The malicious code executes during installation, downloading the Bun runtime and running a payload that harvests GitHub credentials and cloud secrets. The attack specifically targets AWS environments by querying the IMDS and attempting privilege escalation through STS and SSM endpoints across multiple regions. Stolen credentials are automatically used to publish additional malicious package versions across different maintainer accounts, creating a self-propagating infection chain. The attack patterns mirror previous Shai-Hulud compromises, using a drop-and-execute technique and command-and-control infrastructure at git-tanstack.com, a domain designed to mimic legitimate tanstack.com traffic. Organizations should rotate GitHub credentials, audit AWS credentials, and check for suspicious activity.
Pulse ID: 6a69c0698ac8620efa23e8f6
Pulse Link: https://otx.alienvault.com/pulse/6a69c0698ac8620efa23e8f6
Pulse Author: AlienVault
Created: 2026-07-29 08:57:13Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #Cloud #CyberSecurity #ELF #Endpoint #GitHub #InfoSec #Mimic #NPM #OTX #OpenThreatExchange #Worm #bot #AlienVault
-
Shai-Hulud-Style npm Worm Hits
Multiple npm packages across @tanstack, @mistralai, @uipath, @squawk, and safe-action namespaces were compromised in a worm-like attack affecting over 50 packages. The malicious code executes during installation, downloading the Bun runtime and running a payload that harvests GitHub credentials and cloud secrets. The attack specifically targets AWS environments by querying the IMDS and attempting privilege escalation through STS and SSM endpoints across multiple regions. Stolen credentials are automatically used to publish additional malicious package versions across different maintainer accounts, creating a self-propagating infection chain. The attack patterns mirror previous Shai-Hulud compromises, using a drop-and-execute technique and command-and-control infrastructure at git-tanstack.com, a domain designed to mimic legitimate tanstack.com traffic. Organizations should rotate GitHub credentials, audit AWS credentials, and check for suspicious activity.
Pulse ID: 6a69c0698ac8620efa23e8f6
Pulse Link: https://otx.alienvault.com/pulse/6a69c0698ac8620efa23e8f6
Pulse Author: AlienVault
Created: 2026-07-29 08:57:13Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #Cloud #CyberSecurity #ELF #Endpoint #GitHub #InfoSec #Mimic #NPM #OTX #OpenThreatExchange #Worm #bot #AlienVault
-
Technical Advisory: wp2shell — Unauthenticated Remote Code Execution and Full Site Takeover in WordPress Core
Two chained vulnerabilities in WordPress Core enable unauthenticated remote code execution on installations running versions 6.9.0 through 6.9.4 or 7.0.0 through 7.0.1. The first flaw affects the REST API batch endpoint validation, while the second is a SQL injection in the post query layer. When exploited together, attackers achieve full administrator access and deploy webshells. Active exploitation has been confirmed with a public proof-of-concept available. Attackers conduct mass scanning followed by automated compromise sequences that create unauthorized administrator accounts with w2s_ prefixes, upload malicious plugins, and establish persistent remote access. Observed incidents show multiple exploitation attempts before successful compromise. Fixed versions 6.9.5 and 7.0.2 are available, with forced auto-updates deployed. Organizations should patch immediately or implement WAF rules blocking anonymous access to the batch endpoint.
Pulse ID: 6a6823754b2a6d2295eb3330
Pulse Link: https://otx.alienvault.com/pulse/6a6823754b2a6d2295eb3330
Pulse Author: AlienVault
Created: 2026-07-28 03:35:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Endpoint #InfoSec #OTX #OpenThreatExchange #RAT #RCE #RDP #RemoteCodeExecution #SQL #Word #Wordpress #bot #AlienVault
-
Technical Advisory: wp2shell — Unauthenticated Remote Code Execution and Full Site Takeover in WordPress Core
Two chained vulnerabilities in WordPress Core enable unauthenticated remote code execution on installations running versions 6.9.0 through 6.9.4 or 7.0.0 through 7.0.1. The first flaw affects the REST API batch endpoint validation, while the second is a SQL injection in the post query layer. When exploited together, attackers achieve full administrator access and deploy webshells. Active exploitation has been confirmed with a public proof-of-concept available. Attackers conduct mass scanning followed by automated compromise sequences that create unauthorized administrator accounts with w2s_ prefixes, upload malicious plugins, and establish persistent remote access. Observed incidents show multiple exploitation attempts before successful compromise. Fixed versions 6.9.5 and 7.0.2 are available, with forced auto-updates deployed. Organizations should patch immediately or implement WAF rules blocking anonymous access to the batch endpoint.
Pulse ID: 6a6823754b2a6d2295eb3330
Pulse Link: https://otx.alienvault.com/pulse/6a6823754b2a6d2295eb3330
Pulse Author: AlienVault
Created: 2026-07-28 03:35:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Endpoint #InfoSec #OTX #OpenThreatExchange #RAT #RCE #RDP #RemoteCodeExecution #SQL #Word #Wordpress #bot #AlienVault
-
Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass
Device code phishing exploits the OAuth 2.0 device authorization grant, a legitimate authentication feature designed for input-limited devices like smart TVs. Attackers initiate a device-code request with Microsoft, receive a valid code, then trick victims into approving it through social engineering. The victim authenticates on genuine Microsoft pages and completes MFA, but the session tokens are issued to the attacker instead. When targeting the Microsoft Authentication Broker, attackers can register rogue devices and obtain long-lived refresh tokens for persistent access. A recent campaign used sophisticated multi-stage delivery chains involving Google Sites, compromised website redirectors, and fake document-sharing portals. After successful authentication, attackers registered multiple devices, created hidden mailbox rules, and used compromised accounts to send additional phishing emails, all without touching victim endpoints.
Pulse ID: 6a61c32adbac47eb19574196
Pulse Link: https://otx.alienvault.com/pulse/6a61c32adbac47eb19574196
Pulse Author: AlienVault
Created: 2026-07-23 07:30:50Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Email #Endpoint #Google #InfoSec #MFA #Microsoft #OTX #OpenThreatExchange #Phishing #SocialEngineering #bot #AlienVault
-
Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass
Device code phishing exploits the OAuth 2.0 device authorization grant, a legitimate authentication feature designed for input-limited devices like smart TVs. Attackers initiate a device-code request with Microsoft, receive a valid code, then trick victims into approving it through social engineering. The victim authenticates on genuine Microsoft pages and completes MFA, but the session tokens are issued to the attacker instead. When targeting the Microsoft Authentication Broker, attackers can register rogue devices and obtain long-lived refresh tokens for persistent access. A recent campaign used sophisticated multi-stage delivery chains involving Google Sites, compromised website redirectors, and fake document-sharing portals. After successful authentication, attackers registered multiple devices, created hidden mailbox rules, and used compromised accounts to send additional phishing emails, all without touching victim endpoints.
Pulse ID: 6a61c32adbac47eb19574196
Pulse Link: https://otx.alienvault.com/pulse/6a61c32adbac47eb19574196
Pulse Author: AlienVault
Created: 2026-07-23 07:30:50Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Email #Endpoint #Google #InfoSec #MFA #Microsoft #OTX #OpenThreatExchange #Phishing #SocialEngineering #bot #AlienVault
-
Exploitation in the Wild of wp2shell
A critical pre-authentication remote code execution vulnerability chain dubbed "wp2shell" affecting WordPress Core has been actively exploited in the wild. The vulnerability chain, consisting of CVE-2026-63030 and CVE-2026-60137, allows unauthenticated attackers to gain remote code execution on default WordPress installations. Multiple threat actors have been observed exploiting these vulnerabilities almost immediately after public disclosure, deploying persistent webshells and backdoors through malicious plugin uploads. Post-exploitation activities include user enumeration, local file inclusion attempts, and admin panel access. Three distinct PHP webshells have been identified, ranging from simple one-liners to sophisticated 150KB attack platforms disguised as legitimate WordPress plugins. Organizations should prioritize patching or implementing WAF mitigations to block access to WordPress Batch API endpoints.
Pulse ID: 6a61c32bf83a8841dbf45852
Pulse Link: https://otx.alienvault.com/pulse/6a61c32bf83a8841dbf45852
Pulse Author: AlienVault
Created: 2026-07-23 07:30:51Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #Endpoint #InfoSec #OTX #OpenThreatExchange #PHP #RAT #RDP #RemoteCodeExecution #Vulnerability #Word #Wordpress #bot #AlienVault
-
Exploitation in the Wild of wp2shell
A critical pre-authentication remote code execution vulnerability chain dubbed "wp2shell" affecting WordPress Core has been actively exploited in the wild. The vulnerability chain, consisting of CVE-2026-63030 and CVE-2026-60137, allows unauthenticated attackers to gain remote code execution on default WordPress installations. Multiple threat actors have been observed exploiting these vulnerabilities almost immediately after public disclosure, deploying persistent webshells and backdoors through malicious plugin uploads. Post-exploitation activities include user enumeration, local file inclusion attempts, and admin panel access. Three distinct PHP webshells have been identified, ranging from simple one-liners to sophisticated 150KB attack platforms disguised as legitimate WordPress plugins. Organizations should prioritize patching or implementing WAF mitigations to block access to WordPress Batch API endpoints.
Pulse ID: 6a61c32bf83a8841dbf45852
Pulse Link: https://otx.alienvault.com/pulse/6a61c32bf83a8841dbf45852
Pulse Author: AlienVault
Created: 2026-07-23 07:30:51Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #Endpoint #InfoSec #OTX #OpenThreatExchange #PHP #RAT #RDP #RemoteCodeExecution #Vulnerability #Word #Wordpress #bot #AlienVault
-
DATE: July 17, 2026 at 07:40AM
SOURCE: HEALTHCARE INFO SECURITYDirect article link at end of text block below.
#DataBreaches From Lost or Stolen Devices Hit All-Time Low: Experts Say #Encryption, #Endpoint Management Helped Cut Breaches, But #AI Risks Loom https://t.co/VF57Ie1F1x #HIPAA @HHSOCR
Here are any URLs found in the article text:
Articles can be found by scrolling down the page at https://www.healthcareinfosecurity.com/ under the title "Latest"
-------------------------------------------------
Private, vetted email list for mental health professionals: https://www.clinicians-exchange.org
Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.
-------------------------------------------------
#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering
-
DATE: July 17, 2026 at 07:40AM
SOURCE: HEALTHCARE INFO SECURITYDirect article link at end of text block below.
#DataBreaches From Lost or Stolen Devices Hit All-Time Low: Experts Say #Encryption, #Endpoint Management Helped Cut Breaches, But #AI Risks Loom https://t.co/VF57Ie1F1x #HIPAA @HHSOCR
Here are any URLs found in the article text:
Articles can be found by scrolling down the page at https://www.healthcareinfosecurity.com/ under the title "Latest"
-------------------------------------------------
Private, vetted email list for mental health professionals: https://www.clinicians-exchange.org
Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.
-------------------------------------------------
#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering
-
Spirals: New Stealthy Ransomware Deployed Against Asian IT Company
A previously unseen ransomware family named Spirals was deployed in a double extortion attack against an IT services company in South Asia in June 2026. The Rust-based payload demonstrated sophisticated capabilities including defense evasion, encryption, lateral movement, and privilege escalation. Attackers gained initial access through a compromised internet-facing IIS web server via an ASP.NET web shell, moving rapidly to deploy ransomware within 24 hours. They established persistence using multiple tunneling tools, disabled endpoint security, harvested credentials through SAM hive and LSASS dumps, and deployed reverse-SOCKS proxies for covert command-and-control. The ransomware was distributed across the network using PsExec, encrypting files with AES-128 keys and threatening data publication within six days. The skilled execution suggests potential for wider campaigns, though the threat actor remains unidentified.
Pulse ID: 6a58c2ecd43c8e98d4bdd2e0
Pulse Link: https://otx.alienvault.com/pulse/6a58c2ecd43c8e98d4bdd2e0
Pulse Author: AlienVault
Created: 2026-07-16 11:39:23Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #CyberSecurity #Encryption #Endpoint #Extortion #InfoSec #NET #OTX #OpenThreatExchange #PsExec #RAT #RansomWare #Rust #SouthAsia #bot #AlienVault
-
Spirals: New Stealthy Ransomware Deployed Against Asian IT Company
A previously unseen ransomware family named Spirals was deployed in a double extortion attack against an IT services company in South Asia in June 2026. The Rust-based payload demonstrated sophisticated capabilities including defense evasion, encryption, lateral movement, and privilege escalation. Attackers gained initial access through a compromised internet-facing IIS web server via an ASP.NET web shell, moving rapidly to deploy ransomware within 24 hours. They established persistence using multiple tunneling tools, disabled endpoint security, harvested credentials through SAM hive and LSASS dumps, and deployed reverse-SOCKS proxies for covert command-and-control. The ransomware was distributed across the network using PsExec, encrypting files with AES-128 keys and threatening data publication within six days. The skilled execution suggests potential for wider campaigns, though the threat actor remains unidentified.
Pulse ID: 6a58c2ecd43c8e98d4bdd2e0
Pulse Link: https://otx.alienvault.com/pulse/6a58c2ecd43c8e98d4bdd2e0
Pulse Author: AlienVault
Created: 2026-07-16 11:39:23Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #CyberSecurity #Encryption #Endpoint #Extortion #InfoSec #NET #OTX #OpenThreatExchange #PsExec #RAT #RansomWare #Rust #SouthAsia #bot #AlienVault
-
Google Cloud Functions: простой backend без VPS за 10 минут
Думаю, многие хотя бы раз сталкивались с ситуацией, когда для проекта нужно было реализовать совсем небольшой backend: отправку письма с формы обратной связи, обработку webhook, простое REST API или несколько строк серверной логики. В большинстве случаев первым делом арендуют VPS, настраивают сервер, устанавливают Node.js, nginx, HTTPS и настраивают деплой. Хотя для подобных задач это зачастую оказывается избыточным. В таких случаях отличным решением становятся Google Cloud Functions — serverless‑сервис от Google, который позволяет написать небольшую функцию и уже через несколько минут получить готовый публичный HTTP endpoint. Не нужно поднимать собственный сервер, настраивать инфраструктуру или заниматься её поддержкой — достаточно написать код и задеплоить функцию. В этой статье разберём, как за несколько минут развернуть свою первую Google Cloud Function, настроить автоматический деплой через GitHub Actions и использовать её в качестве простого backend для сайта, Telegram‑бота, webhook или любого другого проекта.
https://habr.com/ru/articles/1053330/
#backend_без_сервера #endpoint #Cloud_Run #Google_Cloud_Functions #REST_API #serverless #SMTP #как_сделать_backend #бесплатный_backend #GitHub_Actions
-
USB без магии: устройство протокола
Целью этой статьи не является полный пересказ спецификации USB или книгу по USB. Я хочу приоткрыть магию работы USB и представить информацию таким образом, чтобы вы получили быстрый старт для понимания всего стека USB: от интерфейсов и конечных точек до электрических сигналов.
https://habr.com/ru/companies/ruvds/articles/1048666/
#usb #usb_descriptor #nrzi #bit_stuffing #endpoint #usb_packets #usb_transactions #usb_frames #usb_enumeration #ruvds_статьи
-
🔥 TRENDING
📢 «مانيج إنجن» تعزز منصة Endpoint Central بحلول الأمن الذاتي لنقاط النهاية مع قدرات EDR والوصول الخاص الآمن - alwatan.ae
#Endpoint #Central #GlobalFeed #News #ARABIC
*Automatically posted by Global Feed Bot*
-
🔥 TRENDING
📢 «مانيج إنجن» تعزز منصة Endpoint Central بحلول الأمن الذاتي لنقاط النهاية مع قدرات EDR والوصول الخاص الآمن - alwatan.ae
#Endpoint #Central #GlobalFeed #News #ARABIC
*Automatically posted by Global Feed Bot*
-
CVE-2026-34474: Pre-auth #credential disclosure in #ZTE #H298A / #H108N via #ETHCheat...The short version: an ETHCheat branch returns credential-bearing #HTML before #authentication. The captured fields include the #admin #password, WLAN PSK, and ESSID, and a companion wizard #endpoint #exposes serial data.
-
Does someone here know why #shields.io is blocking github? I am trying to create an #endpoint #badge on #github like so: https://img.shields.io/endpoint?url=https://gist.github.com/mszell/fa90e1bc9a90719944b41f6af03ced49/raw/covbadge.json
The url https://gist.github.com/mszell/fa90e1bc9a90719944b41f6af03ced49/raw/covbadge.json is correct, but shields.io blocks the domain, and I don't understand why. I'm new to this, maybe I just overlook something stupid?
-
Does someone here know why #shields.io is blocking github? I am trying to create an #endpoint #badge on #github like so: https://img.shields.io/endpoint?url=https://gist.github.com/mszell/fa90e1bc9a90719944b41f6af03ced49/raw/covbadge.json
The url https://gist.github.com/mszell/fa90e1bc9a90719944b41f6af03ced49/raw/covbadge.json is correct, but shields.io blocks the domain, and I don't understand why. I'm new to this, maybe I just overlook something stupid?
-
CVE Alert: CVE-2026-6973 - Ivanti - Endpoint Manager Mobile - https://www.redpacketsecurity.com/cve-alert-cve-2026-6973-ivanti-endpoint-manager-mobile/
#OSINT #ThreatIntel #CyberSecurity #cve-2026-6973 #ivanti #endpoint-manager-mobile
-
CVE Alert: CVE-2026-6973 - Ivanti - Endpoint Manager Mobile - https://www.redpacketsecurity.com/cve-alert-cve-2026-6973-ivanti-endpoint-manager-mobile/
#OSINT #ThreatIntel #CyberSecurity #cve-2026-6973 #ivanti #endpoint-manager-mobile
-
todays #VOIP discovery- - found another snakehead at the end of a #trunk - this time I am using #Acrobits #Groundwire #SIP client on #Android for a mobile extension on #cloud #PBX
Works *unless* I use a wifi connection with same external IP address as on-site PBX connected to cloud PBX (registered as PJSIP interPBX trunk and IP authentication).
When Groundwire extension tries to register as #endpoint on #FreePBX, #AOR records get all confused and #Groundwire shows "error"
tried adding external IP address to "Match (Permit)" in FreePBX extension entry - alas - this allows Groundwire to work but hoses outbound calls from the on-site PBX so had to be reverted (not a complete disaster as I can use the other wifi connection or LTE for Groundwire)
-
todays #VOIP discovery- - found another snakehead at the end of a #trunk - this time I am using #Acrobits #Groundwire #SIP client on #Android for a mobile extension on #cloud #PBX
Works *unless* I use a wifi connection with same external IP address as on-site PBX connected to cloud PBX (registered as PJSIP interPBX trunk and IP authentication).
When Groundwire extension tries to register as #endpoint on #FreePBX, #AOR records get all confused and #Groundwire shows "error"
tried adding external IP address to "Match (Permit)" in FreePBX extension entry - alas - this allows Groundwire to work but hoses outbound calls from the on-site PBX so had to be reverted (not a complete disaster as I can use the other wifi connection or LTE for Groundwire)
-
CVE Alert: CVE-2026-1340 - Ivanti - Endpoint Manager Mobile - https://www.redpacketsecurity.com/cve-alert-cve-2026-1340-ivanti-endpoint-manager-mobile/
#OSINT #ThreatIntel #CyberSecurity #cve-2026-1340 #ivanti #endpoint-manager-mobile
-
CVE Alert: CVE-2026-1340 - Ivanti - Endpoint Manager Mobile - https://www.redpacketsecurity.com/cve-alert-cve-2026-1340-ivanti-endpoint-manager-mobile/
#OSINT #ThreatIntel #CyberSecurity #cve-2026-1340 #ivanti #endpoint-manager-mobile
-
My guide for endpoint security startups is out now.
The path between competing against entrenched platforms and becoming a feature they bundle is narrow. The guide walks through the questions that founders, buyers, and investors should answer to tell the difference.
I got to know this space when leading product at Minerva Labs (now part of Rapid7), but much has changed since then.
https://zeltser.com/endpoint-security-startup-questions
#cybersecurity #infosec #startups #productmanagement #endpoint
-
My guide for endpoint security startups is out now.
The path between competing against entrenched platforms and becoming a feature they bundle is narrow. The guide walks through the questions that founders, buyers, and investors should answer to tell the difference.
I got to know this space when leading product at Minerva Labs (now part of Rapid7), but much has changed since then.
https://zeltser.com/endpoint-security-startup-questions
#cybersecurity #infosec #startups #productmanagement #endpoint
-
Cloudflare oznámil, že služba Browser Rendering nyní obsahuje nový endpoint /crawl, který umožňuje procházet (crawlovat) celý web jediným API voláním. Tento nástroj je nyní dostupný v otevřené beta verzi pro uživatele s bezplatnými i placenými plány.
Co umí /crawl:• Stačí poslat URL startovní stránky a Cloudflare automaticky objeví a zpracuje všechny stránky […]
https://zdrojak.cz/zpravicky/cloudflare-spustil-novy-crawl-endpoint-pro-automaticke-prochazeni-webu/