home.social

#infosec — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #infosec, aggregated by home.social.

  1. Healthcare is currently sitting at number three on the targeting list, with 143 stories hitting the wire this week. That's not a fluke or a seasonal spike. It's a targeted harvest.

    theperimetersite.com/report/218

    #ransomware #databreach #infosec

  2. Healthcare is currently sitting at number three on the targeting list, with 143 stories hitting the wire this week. That's not a fluke or a seasonal spike. It's a targeted harvest.

    theperimetersite.com/report/218

    #ransomware #databreach #infosec

  3. Internxt Launches Encrypted Email: What It Promises and Why I'd Wait for Now

    The Spanish company Internxt launched its own email service, Internxt Mail, this week. On the map of European alternatives that I’m gradually putting together here,…

    vsx.global/internxt-has-launch

    #infosec #privacy #opensource #digitalsovereignty

  4. Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon

    Pulse ID: 6a9a4728dfdc2d354395a4f4
    Pulse Link: otx.alienvault.com/pulse/6a9a4
    Pulse Author: Tr1sa111
    Created: 2026-09-04 04:20:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Brazil #Chinese #CyberSecurity #Government #InfoSec #OTX #OpenThreatExchange #bot #Tr1sa111

  5. Inside Knight Office, a New M365 AiTM Phishing Kit

    Pulse ID: 6a9a48876db04f833178b957
    Pulse Link: otx.alienvault.com/pulse/6a9a4
    Pulse Author: Tr1sa111
    Created: 2026-09-04 04:26:47

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AitM #CyberSecurity #InfoSec #Knight #OTX #Office #OpenThreatExchange #Phishing #bot #Tr1sa111

  6. Attack Cases in Korea Involving the Installation of Radmin and UltraVNC

    Indicators extracted from public reporting. Source: feedly.com/i/subscription/feed

    Pulse ID: 6a9a414a0f65ae585f70692c
    Pulse Link: otx.alienvault.com/pulse/6a9a4
    Pulse Author: CyberHunter_NL
    Created: 2026-09-04 03:55:54

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #2FA #ASEC #AhnLab #CyberSecurity #HTTP #HTTPS #InfoSec #Korea #OTX #OpenThreatExchange #RCE #VNC #bot #CyberHunter_NL

  7. BengalSEO Part 1: Anatomy of the Operation

    Indicators extracted from public reporting. Source: dfirlabs.thedfirreport.com/dfi

    Pulse ID: 6a9a3336375de6b39a966a54
    Pulse Link: otx.alienvault.com/pulse/6a9a3
    Pulse Author: CyberHunter_NL
    Created: 2026-09-04 02:55:50

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #NATO #OTX #OpenThreatExchange #RAT #RCE #bot #CyberHunter_NL

  8. The Gentlemen Ransomware Targets Organizations for Data Theft and Extortion

    The Gentlemen is a rapidly expanding ransomware-as-a-service operation
    using affiliates to compromise organizations, steal sensitive data, evadesecurity controls, disable backups and encrypt systems. The campaign relieson legitimate tools, compromised credentials and rapid attacks to maximize disruption and increase ransom pressure.

    Pulse ID: 6a9a17a5c7f0fd2a8fc9184d
    Pulse Link: otx.alienvault.com/pulse/6a9a1
    Pulse Author: cryptocti
    Created: 2026-09-04 00:58:13

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DataTheft #Extortion #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #RansomwareAsAService #bot #cryptocti

  9. The Gentlemen Ransomware Targets Organizations for Data Theft and Extortion

    The Gentlemen is a rapidly expanding ransomware-as-a-service operation
    using affiliates to compromise organizations, steal sensitive data, evadesecurity controls, disable backups and encrypt systems. The campaign relieson legitimate tools, compromised credentials and rapid attacks to maximize disruption and increase ransom pressure.

    Pulse ID: 6a9a17a5c7f0fd2a8fc9184d
    Pulse Link: otx.alienvault.com/pulse/6a9a1
    Pulse Author: cryptocti
    Created: 2026-09-04 00:58:13

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DataTheft #Extortion #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #RansomwareAsAService #bot #cryptocti

  10. The Gentlemen Ransomware Targets Organizations for Data Theft and Extortion

    The Gentlemen is a rapidly expanding ransomware-as-a-service operation
    using affiliates to compromise organizations, steal sensitive data, evadesecurity controls, disable backups and encrypt systems. The campaign relieson legitimate tools, compromised credentials and rapid attacks to maximize disruption and increase ransom pressure.

    Pulse ID: 6a9a17a5c7f0fd2a8fc9184d
    Pulse Link: otx.alienvault.com/pulse/6a9a1
    Pulse Author: cryptocti
    Created: 2026-09-04 00:58:13

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DataTheft #Extortion #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #RansomwareAsAService #bot #cryptocti

  11. The Gentlemen Ransomware Targets Organizations for Data Theft and Extortion

    The Gentlemen is a rapidly expanding ransomware-as-a-service operation
    using affiliates to compromise organizations, steal sensitive data, evadesecurity controls, disable backups and encrypt systems. The campaign relieson legitimate tools, compromised credentials and rapid attacks to maximize disruption and increase ransom pressure.

    Pulse ID: 6a9a17a5c7f0fd2a8fc9184d
    Pulse Link: otx.alienvault.com/pulse/6a9a1
    Pulse Author: cryptocti
    Created: 2026-09-04 00:58:13

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DataTheft #Extortion #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #RansomwareAsAService #bot #cryptocti

  12. The Gentlemen Ransomware Targets Organizations for Data Theft and Extortion

    The Gentlemen is a rapidly expanding ransomware-as-a-service operation
    using affiliates to compromise organizations, steal sensitive data, evadesecurity controls, disable backups and encrypt systems. The campaign relieson legitimate tools, compromised credentials and rapid attacks to maximize disruption and increase ransom pressure.

    Pulse ID: 6a9a17a5c7f0fd2a8fc9184d
    Pulse Link: otx.alienvault.com/pulse/6a9a1
    Pulse Author: cryptocti
    Created: 2026-09-04 00:58:13

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DataTheft #Extortion #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #RansomwareAsAService #bot #cryptocti

  13. 🐧 SIGINT // Ubuntu Watch — 2026-09-04

    Nearly 150 CVEs in one day across eight distros spanning kernels, parsers, and browsers. If you run mixed Debian/Ubuntu/Fedora boxes in your homelab, this is your cue to stop deferring updates and actually patch tonight.

    🔗 linuxcompatible.org/story/linu

  14. 🚨New ransom group blog posts!🚨

    Group name: spacebears
    Post title: Schwartz, Giannini, Lantsberger & Adamson (SGLA)
    Info: cti.fyi/groups/spacebears.html

    Group name: spacebears
    Post title: Studio Oculistico Ciraci
    Info: cti.fyi/groups/spacebears.html

    #ransomware #cti #threatintelligence #cybersecurity #infosec

  15. 🚨New ransom group blog posts!🚨

    Group name: spacebears
    Post title: Schwartz, Giannini, Lantsberger & Adamson (SGLA)
    Info: cti.fyi/groups/spacebears.html

    Group name: spacebears
    Post title: Studio Oculistico Ciraci
    Info: cti.fyi/groups/spacebears.html

    #ransomware #cti #threatintelligence #cybersecurity #infosec

  16. 🚨New ransom group blog posts!🚨

    Group name: spacebears
    Post title: Schwartz, Giannini, Lantsberger & Adamson (SGLA)
    Info: cti.fyi/groups/spacebears.html

    Group name: spacebears
    Post title: Studio Oculistico Ciraci
    Info: cti.fyi/groups/spacebears.html

    #ransomware #cti #threatintelligence #cybersecurity #infosec

  17. 🚨New ransom group blog posts!🚨

    Group name: spacebears
    Post title: Schwartz, Giannini, Lantsberger & Adamson (SGLA)
    Info: cti.fyi/groups/spacebears.html

    Group name: spacebears
    Post title: Studio Oculistico Ciraci
    Info: cti.fyi/groups/spacebears.html

    #ransomware #cti #threatintelligence #cybersecurity #infosec

  18. 🚨New ransom group blog posts!🚨

    Group name: spacebears
    Post title: Schwartz, Giannini, Lantsberger & Adamson (SGLA)
    Info: cti.fyi/groups/spacebears.html

    Group name: spacebears
    Post title: Studio Oculistico Ciraci
    Info: cti.fyi/groups/spacebears.html

    #ransomware #cti #threatintelligence #cybersecurity #infosec

  19. 🚨 SIGINT // Cybersecurity Watch — 2026-09-04
    CISA adds 7 actively exploited flaws to its KEV catalog; attackers deploying reverse shells & crypto miners. Patch immediately.
    thehackernews.com/2026/09/cisa

  20. 🚨 SIGINT // Cybersecurity Watch — 2026-09-04
    CISA adds 7 actively exploited flaws to its KEV catalog; attackers deploying reverse shells & crypto miners. Patch immediately.
    thehackernews.com/2026/09/cisa
    #CVE #CISA #InfoSec #Cybersecurity

  21. 🟠 CVE-2026-64200 - High (7.8)

    There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read a past the end of an allocated heap buffer during string conversion.  Successful exploitation requires an attacker...

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  22. 🟠 CVE-2026-64199 - High (7.8)

    There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read outside the bounds of an allocated data structure.  Successful exploitation requires an attacker to get a user to ...

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  23. 🟠 CVE-2026-64198 - High (7.8)

    There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read a few bytes past the end of an allocated heap buffer during file handling.  Successful exploitation requires an at...

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  24. 🟠 CVE-2026-64197 - High (7.8)

    There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated data structure. Successful exploitation requires an attacker to get a user to open a spec...

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  25. 🔴 CVE-2026-85224 - Critical (9.1)

    A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affects an unknown part of the file /cgi/file_sharing.cgi of the component File Sharing. Executing a manipulation of the argument fileurl can lead to os command injection. ...

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  26. 🔴 CVE-2026-85223 - Critical (9.9)

    A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functionality of the file /cgi-bin/dropbox.cgi of the component CGI Handler. Performing a manipulation of the argument callback_url/sync_interval results ...

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  27. 🚨New ransom group blog posts!🚨

    Group name: incransom
    Post title: myglobal.com
    Info: cti.fyi/groups/incransom.html

    Group name: insomnia
    Post title: Maglin, Miskiv & Associates
    Info: cti.fyi/groups/insomnia.html

    Group name: nightspire
    Post title: Transportes Montejo S.A.S.
    Info: cti.fyi/groups/nightspire.html

    Group name: nightspire
    Post title: Truckworx
    Info: cti.fyi/groups/nightspire.html

    Group name: nightspire
    Post title: Easyoga
    Info: cti.fyi/groups/nightspire.html

    #ransomware #cti #threatintelligence #cybersecurity #infosec

  28. 🔒 OpenVPN 2.7.7 a fost lansat cu șapte remedieri critice de securitate!Publicația Linuxiac detaliază lansarea versiunii de mentenanță OpenVPN 2.7.7, o actualizare esențială pentru una dintre cele mai utilizate soluții open-source de rețele private virtuale (VPN), adresată direct eliminării mai multor vulnerabilități și îmbunătățirii stabilității generale.✨ Punctele cheie ale versiunii OpenVPN 2.7.7:🛡️ Șapte corecții de securitate (Security Fixes):• Lansarea rezolvă șapte vulnerabilități separate ce puteau duce la blocarea serviciului (Denial of Service / DoS), scurgeri neintenționate de date de sesiune sau manipularea pachetelor de control în anumite condiții de rețea.⚡ Tratare optimizată a erorilor de conexiune:• Îmbunătățiri la nivelul gestionării pachetelor malformate primite de la clienți, prevenind prăbușirea daemon-ului de server în timpul tentativelor de scanare sau atac.🛠️ Optimizare TLS și gestionare a certificatelor:• Corecții în procesul de negociere a cheilor de criptare TLS, asigurând o mai bună compatibilitate cu bibliotecile OpenSSL recente și remedierea unor erori de memorie (memory leaks) minore la rebalansarea sesiunilor.🔄 Recomandare fermă de actualizare:• Administratorii de rețea sunt sfătuiți să aplice actualizarea pe serverele și clienții OpenVPN cât mai curând posibil pentru a menține un nivel ridicat de protecție.🔗 Sursă și articol complet:Linuxiac - OpenVPN 2.7.7 Released with Seven Security Fixes📌 Concluzie:Această lansare subliniază importanța menținerii la zi a soluțiilor de acces la distanță, oferind patch-uri cruciale pentru protejarea infrastructurilor VPN împotriva posibilelor exploatări! 🚀#OpenVPN #CyberSecurity #VPN #SysAdmin #Linuxiac #OpenSource #TechNews #Networking #InfoSec

  29. Coder's registry infrastructure compromised to push malicious modules

    Indicators extracted from public reporting. Source: bleepingcomputer.com/news/secu

    Pulse ID: 6a99dec79581ad186b15ab7e
    Pulse Link: otx.alienvault.com/pulse/6a99d
    Pulse Author: CyberHunter_NL
    Created: 2026-09-03 20:55:35

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  30. 🔴 CVE-2026-85391 - Critical (9.8)

    Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. Attackers can use the published secret to mint valid tokens for arbitrary user ID...

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  31. 🔴 CVE-2026-85391 - Critical (9.8)

    Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. Attackers can use the published secret to mint valid tokens for arbitrary user ID...

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  32. 🔴 CVE-2026-85391 - Critical (9.8)

    Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. Attackers can use the published secret to mint valid tokens for arbitrary user ID...

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  33. 🔴 CVE-2026-85391 - Critical (9.8)

    Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. Attackers can use the published secret to mint valid tokens for arbitrary user ID...

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  34. Broadcom Patches Critical VM-Escape Flaws in VMware Workstation and Fusion

    Broadcom patched two critical VM-escape vulnerabilities in VMware Workstation and Fusion (CVE-2026-59346 and CVE-2026-59347) that allow attackers with guest admin privileges to execute code on the host system.

    **If you use VMware Workstation or Fusion (versions 25H2 or 26H1), update to 26H1u1 ASAP. Tthere is no workaround or setting that protects you from these flaws. Prioritize the machines that run untrusted code, malware analysis as well as any third party hosting, since an attacker inside a VM can break out and take over your host and from there reach your network.**
    #cybersecurity #infosec #advisory #vulnerability
    beyondmachines.net/event_detai

  35. 🟠 CVE-2026-85388 - High (8.1)

    Worklenz through 3.0.0 fails to properly validate the sort-field query parameter in pagination helper functions, allowing authenticated users to inject arbitrary PostgreSQL expressions into ORDER BY clauses. Attackers can use time-based and boolea...

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  36. 🟠 CVE-2026-85388 - High (8.1)

    Worklenz through 3.0.0 fails to properly validate the sort-field query parameter in pagination helper functions, allowing authenticated users to inject arbitrary PostgreSQL expressions into ORDER BY clauses. Attackers can use time-based and boolea...

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  37. 🟠 CVE-2026-85388 - High (8.1)

    Worklenz through 3.0.0 fails to properly validate the sort-field query parameter in pagination helper functions, allowing authenticated users to inject arbitrary PostgreSQL expressions into ORDER BY clauses. Attackers can use time-based and boolea...

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  38. 🟠 CVE-2026-85388 - High (8.1)

    Worklenz through 3.0.0 fails to properly validate the sort-field query parameter in pagination helper functions, allowing authenticated users to inject arbitrary PostgreSQL expressions into ORDER BY clauses. Attackers can use time-based and boolea...

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  39. 🟠 CVE-2026-85028 - High (7.8)

    Creation of a temporary file in a directory with insecure permissions in the FPGA management tool installation component in AWS FPGA Development Kit (aws-fpga) before 2.3.4 might allow local users to execute arbitrary code with root privileges via...

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  40. 🟠 CVE-2026-85028 - High (7.8)

    Creation of a temporary file in a directory with insecure permissions in the FPGA management tool installation component in AWS FPGA Development Kit (aws-fpga) before 2.3.4 might allow local users to execute arbitrary code with root privileges via...

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  41. 🟠 CVE-2026-85028 - High (7.8)

    Creation of a temporary file in a directory with insecure permissions in the FPGA management tool installation component in AWS FPGA Development Kit (aws-fpga) before 2.3.4 might allow local users to execute arbitrary code with root privileges via...

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  42. 🟠 CVE-2026-85028 - High (7.8)

    Creation of a temporary file in a directory with insecure permissions in the FPGA management tool installation component in AWS FPGA Development Kit (aws-fpga) before 2.3.4 might allow local users to execute arbitrary code with root privileges via...

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  43. 🟠 CVE-2026-85396 - High (7.5)

    rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators. Attackers can craft archive entries with names like .....

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  44. 🟠 CVE-2026-85396 - High (7.5)

    rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators. Attackers can craft archive entries with names like .....

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  45. 🟠 CVE-2026-85396 - High (7.5)

    rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators. Attackers can craft archive entries with names like .....

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  46. 🟠 CVE-2026-85396 - High (7.5)

    rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators. Attackers can craft archive entries with names like .....

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  47. 🔴 CVE-2026-85394 - Critical (9.1)

    python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes. Attackers holding the service's public key can forge HS256 tokens that pass verific...

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  48. 🔴 CVE-2026-85394 - Critical (9.1)

    python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes. Attackers holding the service's public key can forge HS256 tokens that pass verific...

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  49. 🔴 CVE-2026-85394 - Critical (9.1)

    python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes. Attackers holding the service's public key can forge HS256 tokens that pass verific...

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack