home.social

#infosec — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #infosec, aggregated by home.social.

  1. RE: mastodon.social/@wchr/11665230

    Well, some of us did try to get the point across, but we were being called conspiracy theorists.

    #privacy #infosec

  2. Security Tip: Don't let CVSS scores be your only guide. 🛡️ While a high severity score is important, real-world risk is driven by active exploitation. Integrate the CISA Known Exploited Vulnerabilities (KEV) catalog into your patch management workflow. If an attacker is already using it, it should be at the top of your list, regardless of the score. Track active threats at cvedatabase.com

  3. 🚨New ransom group blog posts!🚨

    Group name: beast
    Post title: Trivantage
    Info: cti.fyi/groups/beast.html

    Group name: kazu
    Post title: Ransom
    Info: cti.fyi/groups/kazu.html

    Group name: kazu
    Post title: Databases
    Info: cti.fyi/groups/kazu.html

    Group name: worldleaks
    Post title: American Battery Factory
    Info: cti.fyi/groups/worldleaks.html

    Group name: titan
    Post title: Compact
    Info: cti.fyi/groups/titan.html

    Group name: titan
    Post title: Quahe Woo & Palmer LLC
    Quahe Woo & Palmer LLC
    Info: cti.fyi/groups/titan.html

    Group name: titan
    Post title: ETM-ELECTROMATIC, INC.
    The files were downloaded & analyzed using TITAN AI.
    Info: cti.fyi/groups/titan.html

    Group name: titan
    Post title: Groupe CRIT SA
    All files encrypted, critical data downloaded & analyzed
    Info: cti.fyi/groups/titan.html

    Group name: titan
    Post title: CRIT Tunisie
    All files encrypted, critical data downloaded & analyzed
    Info: cti.fyi/groups/titan.html

    Group name: titan
    Post title: DFI AMERICA, LLC
    The files were downloaded & analyzed using TITAN AI.
    Info: cti.fyi/groups/titan.html

    Group name: titan
    Post title: Abp Autoricambi Srl
    File riservati trapelati e pronti per il download.
    Info: cti.fyi/groups/titan.html

    Group name: titan
    Post title: Mezta Corporativo, S.A. de C.V.
    dunsguide.com/es/company/fa5e5
    Info: cti.fyi/groups/titan.html

    Group name: krybit
    Post title: smile-siam.com
    Info: cti.fyi/groups/krybit.html

    Group name: krybit
    Post title: motofrenos.com
    Info: cti.fyi/groups/krybit.html

    Group name: krybit
    Post title: ctps.tp.edu.tw
    Info: cti.fyi/groups/krybit.html

    Group name: krybit
    Post title: bangkok.go.th
    Info: cti.fyi/groups/krybit.html

    Group name: krybit
    Post title: lasevillanita.com
    Info: cti.fyi/groups/krybit.html

    Group name: krybit
    Post title: mindmastersg.com
    Info: cti.fyi/groups/krybit.html

    Group name: krybit
    Post title: nacs.com.hk
    Info: cti.fyi/groups/krybit.html

    Group name: krybit
    Post title: SARL CANIS EVENTS SÉCURITÉ PRIVÉE
    Info: cti.fyi/groups/krybit.html

    Group name: krybit
    Post title: wwag.org
    Info: cti.fyi/groups/krybit.html

    Group name: krybit
    Post title: eclagestio360.com
    Info: cti.fyi/groups/krybit.html

    Group name: krybit
    Post title: ovextech.com
    Info: cti.fyi/groups/krybit.html

    Group name: krybit
    Post title: foodsmart.com.do
    Info: cti.fyi/groups/krybit.html

    Group name: krybit
    Post title: asesoriauriel.com
    Info: cti.fyi/groups/krybit.html

    #ransomware #cti #threatintelligence #cybersecurity #infosec

  4. @mclare @pluralistic let me start by saying it's unconscionable that we have to treat items we ostensibly own as hostile.

    These types of situations are a good use for those old phones you've got kicking about. Without a SIM/service, they'll have difficulty sending surveillance data back to our corporate overlords.

    That may not work in this instance, but for a lot of things you just need the app to control the device.

    #InfoSec #BigTech

  5. 🚨 EUVD-2026-33030

    📊 Score: 6.5/10 (CVSS v3.1)
    📦 Product: Kibana, Kibana, Kibana
    🏢 Vendor: Elastic
    📅 Updated: 2026-05-28

    📝 Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user can send a specially crafted compressed request payload that is processed prior to authorization ch...

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  6. 🚨 EUVD-2026-33031

    📊 Score: 6.5/10 (CVSS v3.1)
    📦 Product: Kibana, Kibana
    🏢 Vendor: Elastic
    📅 Updated: 2026-05-28

    📝 Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated low-privileged user can cause Kibana to consume exponentially increasing amounts of memory by submitting a speci...

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  7. 🚨 EUVD-2026-33032

    📊 Score: 7.7/10 (CVSS v3.1)
    📦 Product: Kibana, Kibana
    🏢 Vendor: Elastic
    📅 Updated: 2026-05-28

    📝 Server-Side Request Forgery (CWE-918) in Kibana allows authenticated users with connector management privileges to bypass the operator-configured connection allowlist. By configuring a Webhook connector with a crafted target, an attacker can cause Kib...

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  8. 🚨 EUVD-2026-33033

    📊 Score: 7.2/10 (CVSS v3.1)
    📦 Product: Kibana, Kibana, Kibana
    🏢 Vendor: Elastic
    📅 Updated: 2026-05-28

    📝 Improper Input Validation (CWE-20) in the Kibana Fleet agent policy management feature can lead to privilege escalation. An authenticated user with Fleet management privileges can manipulate agent policy configuration by injecting values into ...

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  9. 🚨 EUVD-2026-33034

    📊 Score: 6.5/10 (CVSS v3.1)
    📦 Product: Kibana
    🏢 Vendor: Elastic
    📅 Updated: 2026-05-28

    📝 Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with viewer-level access can submit a request containing an oversized input value to an analytics collections manag...

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  10. 🚨 EUVD-2026-33035

    📊 Score: 6.3/10 (CVSS v3.1)
    📦 Product: Kibana
    🏢 Vendor: Elastic
    📅 Updated: 2026-05-28

    📝 Server-Side Request Forgery (CWE-918) in Kibana can allow an authenticated user with connector management privileges to bypass the operator-configured connector allowlist, causing the Kibana server to issue outbound requests to destinations the egress control...

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  11. 🚨 EUVD-2026-33036

    📊 Score: 9.8/10 (CVSS v3.1)
    📦 Product: Oracle Hospitality OPERA 5 Property Services, Oracle Hospitality OPERA 5 Property Services, Oracle Hospitality OPERA 5 Property Services (+2 more)
    🏢 Vendor: Oracle Corporation
    📅 Updated: 2026-05-28

    📝 Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications...

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  12. 🚨 EUVD-2026-33037

    📊 Score: 7.9/10 (CVSS v3.1)
    📦 Product: Oracle REST Data Services
    🏢 Vendor: Oracle Corporation
    📅 Updated: 2026-05-28

    📝 Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTPS to compromise ...

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  13. 🚨 EUVD-2026-33038

    📊 Score: 8.1/10 (CVSS v3.1)
    📦 Product: Oracle REST Data Services
    🏢 Vendor: Oracle Corporation
    📅 Updated: 2026-05-28

    📝 Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Or...

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  14. 🚨 EUVD-2026-33039

    📊 Score: 9.9/10 (CVSS v3.1)
    📦 Product: Oracle REST Data Services
    🏢 Vendor: Oracle Corporation
    📅 Updated: 2026-05-28

    📝 Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Or...

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  15. 🚨 EUVD-2026-33040

    📊 Score: 9.8/10 (CVSS v3.1)
    📦 Product: Oracle Payments
    🏢 Vendor: Oracle Corporation
    📅 Updated: 2026-05-28

    📝 Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network...

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  16. 🚨 EUVD-2026-33041

    📊 Score: 7.4/10 (CVSS v3.1)
    📦 Product: Oracle Payments
    🏢 Vendor: Oracle Corporation
    📅 Updated: 2026-05-28

    📝 Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with netwo...

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  17. 🚨 EUVD-2026-33042

    📊 Score: 9.1/10 (CVSS v3.1)
    📦 Product: Oracle Internet Procurement Connector
    🏢 Vendor: Oracle Corporation
    📅 Updated: 2026-05-28

    📝 Vulnerability in the Oracle Internet Procurement Connector product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerabilit...

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  18. 🚨 EUVD-2026-33043

    📊 Score: 8.5/10 (CVSS v3.1)
    📦 Product: Oracle Financials Common Modules
    🏢 Vendor: Oracle Corporation
    📅 Updated: 2026-05-28

    📝 Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low...

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  19. 🚨 EUVD-2026-33044

    📊 Score: 7.7/10 (CVSS v3.1)
    📦 Product: Oracle Financials Common Modules
    🏢 Vendor: Oracle Corporation
    📅 Updated: 2026-05-28

    📝 Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low...

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  20. 🚨 EUVD-2026-33045

    📊 Score: 9.9/10 (CVSS v3.1)
    📦 Product: Oracle iAssets
    🏢 Vendor: Oracle Corporation
    📅 Updated: 2026-05-28

    📝 Vulnerability in the Oracle iAssets product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network ...

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  21. 🚨 EUVD-2026-33046

    📊 Score: 7.7/10 (CVSS v3.1)
    📦 Product: Oracle Public Sector Financials (International)
    🏢 Vendor: Oracle Corporation
    📅 Updated: 2026-05-28

    📝 Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Suite (component: Authorization). Supported versions that are affected are 12.2.6-12.2.15. Easily exploitabl...

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  22. 🚨 EUVD-2026-33047

    📊 Score: 9.9/10 (CVSS v3.1)
    📦 Product: Oracle Universal Work Queue
    🏢 Vendor: Oracle Corporation
    📅 Updated: 2026-05-28

    📝 Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerabilit...

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  23. 🚨 EUVD-2026-33048

    📊 Score: 8.8/10 (CVSS v3.1)
    📦 Product: Oracle Payroll
    🏢 Vendor: Oracle Corporation
    📅 Updated: 2026-05-28

    📝 Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network ...

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  24. 🚨 EUVD-2026-33049

    📊 Score: 8.8/10 (CVSS v3.1)
    📦 Product: Oracle Payroll
    🏢 Vendor: Oracle Corporation
    📅 Updated: 2026-05-28

    📝 Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Self Service Manager). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network...

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  25. 🚨 EUVD-2026-33050

    📊 Score: 8.1/10 (CVSS v3.1)
    📦 Product: Oracle Payroll
    🏢 Vendor: Oracle Corporation
    📅 Updated: 2026-05-28

    📝 Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network ...

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  26. 🚨 EUVD-2026-33051

    📊 Score: 7.5/10 (CVSS v3.1)
    📦 Product: Oracle REST Data Services
    🏢 Vendor: Oracle Corporation
    📅 Updated: 2026-05-28

    📝 Vulnerability in Oracle REST Data Services (component: Mongoapi). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromi...

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  27. 🚨 EUVD-2026-33052

    📊 Score: 5.3/10 (CVSS v3.1)
    📦 Product: Oracle REST Data Services
    🏢 Vendor: Oracle Corporation
    📅 Updated: 2026-05-28

    📝 Vulnerability in Oracle REST Data Services (component: Mongoapi). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromi...

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  28. 🚨 EUVD-2026-33013

    📊 Score: 9.0/10 (CVSS v3.1)
    📦 Product: Oracle Database Server
    🏢 Vendor: Oracle Corporation
    📅 Updated: 2026-05-28

    📝 Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compro...

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  29. 🚨 EUVD-2026-33015

    📊 Score: 7.5/10 (CVSS v3.1)
    📦 Product: Oracle Database Server
    🏢 Vendor: Oracle Corporation
    📅 Updated: 2026-05-28

    📝 Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromi...

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  30. 🚨 EUVD-2026-33014

    📊 Score: 7.5/10 (CVSS v3.1)
    📦 Product: Oracle Database Server
    🏢 Vendor: Oracle Corporation
    📅 Updated: 2026-05-28

    📝 Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromi...

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  31. What is Web Security and Web Penetration Testing Tools

    In this article, I cover essential web penetration testing tools and how they fit into different stages of the assessment process.
    denizhalil.com/2024/12/19/web-

    #CyberSecurity #WebSecurity #Pentesting #BurpSuite #Nmap #SQLMap #BugBounty #RedTeam #InfoSec #EthicalHacking #SecurityTools #DenizHalil

  32. It's news to me that #Microsoft now recommends migrating away from Active Directory. I'm wondering if the #Linux Foundation (or any well-funded competitor to microsoft, who favors Open Source) has noticed this, and has plans to develop or offer an #OpenSource alternative for Active Directory, which isn't owned or controlled by Microsoft in any way? #infosec #eu #germany
    "Retiring Active Directory for Infrastructure with Entra ID":
    https://www.egroup-us.com/news/retiring-active-directory-infrastructure-entra-id/

  33. So i just created an e-mail account at soverin.nl/ and they send me the 2FA recovery code via plain text e-mail... 🤦🏼‍♂️ not very promissing 🙄
    #security #privacy #infosec @soverin

  34. Phishing-Driven Banking Malware Campaign Targeting Windows and Android Devices

    Active malware campaigns targeting Windows and Android users, which use Grandoreiro banking malware and the BTMOB Android RAT in order to steal financial and personal data. Victims are targeted through phishing emails and fake apps that trick them into installing malicious files or granting device access.

    Pulse ID: 6a187c4e9fe60a946730ffb9
    Pulse Link: otx.alienvault.com/pulse/6a187
    Pulse Author: cryptocti
    Created: 2026-05-28 17:33:02

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Android #Bank #CyberSecurity #Email #InfoSec #Malware #OTX #OpenThreatExchange #Phishing #RAT #Windows #bot #cryptocti

  35. Phishing-Driven Banking Malware Campaign Targeting Windows and Android Devices

    Active malware campaigns targeting Windows and Android users, which use Grandoreiro banking malware and the BTMOB Android RAT in order to steal financial and personal data. Victims are targeted through phishing emails and fake apps that trick them into installing malicious files or granting device access.

    Pulse ID: 6a187cbd9fe60a946730ffba
    Pulse Link: otx.alienvault.com/pulse/6a187
    Pulse Author: cryptocti
    Created: 2026-05-28 17:34:53

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Android #Bank #CyberSecurity #Email #InfoSec #Malware #OTX #OpenThreatExchange #Phishing #RAT #Windows #bot #cryptocti

  36. Phishing-Driven Banking Malware Campaign Targeting Windows and Android Devices

    Active malware campaigns targeting Windows and Android users, which use Grandoreiro banking malware and the BTMOB Android RAT in order to steal financial and personal data. Victims are targeted through phishing emails and fake apps that trick them into installing malicious files or granting device access.

    Pulse ID: 6a187cbd6c6d406caeef06a2
    Pulse Link: otx.alienvault.com/pulse/6a187
    Pulse Author: cryptocti
    Created: 2026-05-28 17:34:53

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Android #Bank #CyberSecurity #Email #InfoSec #Malware #OTX #OpenThreatExchange #Phishing #RAT #Windows #bot #cryptocti

  37. Phishing-Driven Banking Malware Campaign Targeting Windows and Android Devices

    Active malware campaigns targeting Windows and Android users, which use Grandoreiro banking malware and the BTMOB Android RAT in order to steal financial and personal data. Victims are targeted through phishing emails and fake apps that trick them into installing malicious files or granting device access.

    Pulse ID: 6a187cbe8cdd31d7f83c8063
    Pulse Link: otx.alienvault.com/pulse/6a187
    Pulse Author: cryptocti
    Created: 2026-05-28 17:34:54

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Android #Bank #CyberSecurity #Email #InfoSec #Malware #OTX #OpenThreatExchange #Phishing #RAT #Windows #bot #cryptocti

  38. Phishing-Driven Banking Malware Campaign Targeting Windows and Android Devices

    Active malware campaigns targeting Windows and Android users, which use Grandoreiro banking malware and the BTMOB Android RAT in order to steal financial and personal data. Victims are targeted through phishing emails and fake apps that trick them into installing malicious files or granting device access.

    Pulse ID: 6a187cd2d4985ecd688b1c12
    Pulse Link: otx.alienvault.com/pulse/6a187
    Pulse Author: cryptocti
    Created: 2026-05-28 17:35:14

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Android #Bank #CyberSecurity #Email #InfoSec #Malware #OTX #OpenThreatExchange #Phishing #RAT #Windows #bot #cryptocti

  39. Phishing-Driven Banking Malware Campaign Targeting Windows and Android Devices

    Active malware campaigns targeting Windows and Android users, which use Grandoreiro banking malware and the BTMOB Android RAT in order to steal financial and personal data. Victims are targeted through phishing emails and fake apps that trick them into installing malicious files or granting device access.

    Pulse ID: 6a187d0757e29bb3897eac46
    Pulse Link: otx.alienvault.com/pulse/6a187
    Pulse Author: cryptocti
    Created: 2026-05-28 17:36:07

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Android #Bank #CyberSecurity #Email #InfoSec #Malware #OTX #OpenThreatExchange #Phishing #RAT #Windows #bot #cryptocti

  40. 🟠 CVE-2026-45047 - High (7.5)

    bird-lg-go is a BIRD looking glass in Go. Prior to 1.4.5, the apiHandler (and similarly webHandlerTelegramBot) processes user-provided JSON payloads by directly using json.NewDecoder(r.Body).Decode(&request) without restricting the maximum read si...

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  41. Credential Stealer EKZ Delivered via FortiClient EMS Exploitation

    Attackers exploited CVE-2026-35616 in FortiClient EMS. Threat actors changes EMS settings and pushed a malicious VPN script to endpoints. The script downloaded EKZ Infostealer, disguised as a Fortinet patch. The malware steals browser passwords, cookies, and autofill data.

    Pulse ID: 6a1879e13827c581e8b73eb4
    Pulse Link: otx.alienvault.com/pulse/6a187
    Pulse Author: cryptocti
    Created: 2026-05-28 17:22:41

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Cookies #CyberSecurity #Endpoint #InfoSec #InfoStealer #Malware #OTX #OpenThreatExchange #Password #Passwords #VPN #Word #bot #cryptocti

  42. Credential Stealer EKZ Delivered via FortiClient EMS Exploitation

    Attackers exploited CVE-2026-35616 in FortiClient EMS. Threat actors changes EMS settings and pushed a malicious VPN script to endpoints. The script downloaded EKZ Infostealer, disguised as a Fortinet patch. The malware steals browser passwords, cookies, and autofill data.

    Pulse ID: 6a1879e15c8f2d2d2cf72b60
    Pulse Link: otx.alienvault.com/pulse/6a187
    Pulse Author: cryptocti
    Created: 2026-05-28 17:22:41

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Cookies #CyberSecurity #Endpoint #InfoSec #InfoStealer #Malware #OTX #OpenThreatExchange #Password #Passwords #VPN #Word #bot #cryptocti

  43. Credential Stealer EKZ Delivered via FortiClient EMS Exploitation

    Attackers exploited CVE-2026-35616 in FortiClient EMS. Threat actors changes EMS settings and pushed a malicious VPN script to endpoints. The script downloaded EKZ Infostealer, disguised as a Fortinet patch. The malware steals browser passwords, cookies, and autofill data.

    Pulse ID: 6a1879e2d85be08873d89445
    Pulse Link: otx.alienvault.com/pulse/6a187
    Pulse Author: cryptocti
    Created: 2026-05-28 17:22:42

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Cookies #CyberSecurity #Endpoint #InfoSec #InfoStealer #Malware #OTX #OpenThreatExchange #Password #Passwords #VPN #Word #bot #cryptocti

  44. Credential Stealer EKZ Delivered via FortiClient EMS Exploitation

    Attackers exploited CVE-2026-35616 in FortiClient EMS. Threat actors changes EMS settings and pushed a malicious VPN script to endpoints. The script downloaded EKZ Infostealer, disguised as a Fortinet patch. The malware steals browser passwords, cookies, and autofill data.

    Pulse ID: 6a187a5035303b62f8e49196
    Pulse Link: otx.alienvault.com/pulse/6a187
    Pulse Author: cryptocti
    Created: 2026-05-28 17:24:32

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Cookies #CyberSecurity #Endpoint #InfoSec #InfoStealer #Malware #OTX #OpenThreatExchange #Password #Passwords #VPN #Word #bot #cryptocti

  45. Credential Stealer EKZ Delivered via FortiClient EMS Exploitation

    Attackers exploited CVE-2026-35616 in FortiClient EMS. Threat actors changes EMS settings and pushed a malicious VPN script to endpoints. The script downloaded EKZ Infostealer, disguised as a Fortinet patch. The malware steals browser passwords, cookies, and autofill data.

    Pulse ID: 6a187acb35f351993fe5e76b
    Pulse Link: otx.alienvault.com/pulse/6a187
    Pulse Author: cryptocti
    Created: 2026-05-28 17:26:35

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Cookies #CyberSecurity #Endpoint #InfoSec #InfoStealer #Malware #OTX #OpenThreatExchange #Password #Passwords #VPN #Word #bot #cryptocti

  46. 🚨New ransom group blog posts!🚨

    Group name: everest
    Post title: AKM
    Info: cti.fyi/groups/everest.html

    Group name: everest
    Post title: VVO Finance
    Info: cti.fyi/groups/everest.html

    Group name: everest
    Post title: Sidra Kuwait Hospital
    Info: cti.fyi/groups/everest.html

    #ransomware #cti #threatintelligence #cybersecurity #infosec

  47. Rich Products Corporation Data Breach Investigation

    Rich Products Corporation reported a data breach affecting approximately 200 individuals after a phishing attack compromised a third-party vendor's employee email account.

    ****
    #cybersecurity #infosec #incident #databreach
    beyondmachines.net/event_detai

  48. Rich Products Corporation Data Breach Investigation

    Rich Products Corporation reported a data breach affecting approximately 200 individuals after a phishing attack compromised a third-party vendor's employee email account.

    ****
    #cybersecurity #infosec #incident #databreach
    beyondmachines.net/event_detai

  49. Rich Products Corporation Data Breach Investigation

    Rich Products Corporation reported a data breach affecting approximately 200 individuals after a phishing attack compromised a third-party vendor's employee email account.

    ****
    #cybersecurity #infosec #incident #databreach
    beyondmachines.net/event_detai