#infosec — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #infosec, aggregated by home.social.
-
RE: https://mastodon.social/@wchr/116652301416756650
Well, some of us did try to get the point across, but we were being called conspiracy theorists.
-
Security Tip: Don't let CVSS scores be your only guide. 🛡️ While a high severity score is important, real-world risk is driven by active exploitation. Integrate the CISA Known Exploited Vulnerabilities (KEV) catalog into your patch management workflow. If an attacker is already using it, it should be at the top of your list, regardless of the score. Track active threats at https://cvedatabase.com #InfoSec #CyberSecurity #PatchManagement #CVE
-
🚨New ransom group blog posts!🚨
Group name: beast
Post title: Trivantage
Info: https://cti.fyi/groups/beast.htmlGroup name: kazu
Post title: Ransom
Info: https://cti.fyi/groups/kazu.htmlGroup name: kazu
Post title: Databases
Info: https://cti.fyi/groups/kazu.htmlGroup name: worldleaks
Post title: American Battery Factory
Info: https://cti.fyi/groups/worldleaks.htmlGroup name: titan
Post title: Compact
Info: https://cti.fyi/groups/titan.htmlGroup name: titan
Post title: Quahe Woo & Palmer LLC
Quahe Woo & Palmer LLC
Info: https://cti.fyi/groups/titan.htmlGroup name: titan
Post title: ETM-ELECTROMATIC, INC.
The files were downloaded & analyzed using TITAN AI.
Info: https://cti.fyi/groups/titan.htmlGroup name: titan
Post title: Groupe CRIT SA
All files encrypted, critical data downloaded & analyzed
Info: https://cti.fyi/groups/titan.htmlGroup name: titan
Post title: CRIT Tunisie
All files encrypted, critical data downloaded & analyzed
Info: https://cti.fyi/groups/titan.htmlGroup name: titan
Post title: DFI AMERICA, LLC
The files were downloaded & analyzed using TITAN AI.
Info: https://cti.fyi/groups/titan.htmlGroup name: titan
Post title: Abp Autoricambi Srl
File riservati trapelati e pronti per il download.
Info: https://cti.fyi/groups/titan.htmlGroup name: titan
Post title: Mezta Corporativo, S.A. de C.V.
https://www.dunsguide.com/es/company/fa5e54643c8b63d0736
Info: https://cti.fyi/groups/titan.htmlGroup name: krybit
Post title: smile-siam.com
Info: https://cti.fyi/groups/krybit.htmlGroup name: krybit
Post title: motofrenos.com
Info: https://cti.fyi/groups/krybit.htmlGroup name: krybit
Post title: ctps.tp.edu.tw
Info: https://cti.fyi/groups/krybit.htmlGroup name: krybit
Post title: bangkok.go.th
Info: https://cti.fyi/groups/krybit.htmlGroup name: krybit
Post title: lasevillanita.com
Info: https://cti.fyi/groups/krybit.htmlGroup name: krybit
Post title: mindmastersg.com
Info: https://cti.fyi/groups/krybit.htmlGroup name: krybit
Post title: nacs.com.hk
Info: https://cti.fyi/groups/krybit.htmlGroup name: krybit
Post title: SARL CANIS EVENTS SÉCURITÉ PRIVÉE
Info: https://cti.fyi/groups/krybit.htmlGroup name: krybit
Post title: wwag.org
Info: https://cti.fyi/groups/krybit.htmlGroup name: krybit
Post title: eclagestio360.com
Info: https://cti.fyi/groups/krybit.htmlGroup name: krybit
Post title: ovextech.com
Info: https://cti.fyi/groups/krybit.htmlGroup name: krybit
Post title: foodsmart.com.do
Info: https://cti.fyi/groups/krybit.htmlGroup name: krybit
Post title: asesoriauriel.com
Info: https://cti.fyi/groups/krybit.html#ransomware #cti #threatintelligence #cybersecurity #infosec
-
@mclare @pluralistic let me start by saying it's unconscionable that we have to treat items we ostensibly own as hostile.
These types of situations are a good use for those old phones you've got kicking about. Without a SIM/service, they'll have difficulty sending surveillance data back to our corporate overlords.
That may not work in this instance, but for a lot of things you just need the app to control the device.
-
[PODCAST] The Military Wants to Move at Cyber Speed.
https://podcasts.wesfryer.com/episode/GstHvWaLs58FNfsBgUeA
(CyberWire Daily, 28 May 2026)
#cybersecurity #military #CyberSpeed #defense #NationalSecurity #CyberWarfare #technology #DoD #InfoSec #CriticalInfrastructure #edtechSR
-
🚨 EUVD-2026-33030
📊 Score: 6.5/10 (CVSS v3.1)
📦 Product: Kibana, Kibana, Kibana
🏢 Vendor: Elastic
📅 Updated: 2026-05-28📝 Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user can send a specially crafted compressed request payload that is processed prior to authorization ch...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33030
-
🚨 EUVD-2026-33031
📊 Score: 6.5/10 (CVSS v3.1)
📦 Product: Kibana, Kibana
🏢 Vendor: Elastic
📅 Updated: 2026-05-28📝 Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated low-privileged user can cause Kibana to consume exponentially increasing amounts of memory by submitting a speci...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33031
-
🚨 EUVD-2026-33032
📊 Score: 7.7/10 (CVSS v3.1)
📦 Product: Kibana, Kibana
🏢 Vendor: Elastic
📅 Updated: 2026-05-28📝 Server-Side Request Forgery (CWE-918) in Kibana allows authenticated users with connector management privileges to bypass the operator-configured connection allowlist. By configuring a Webhook connector with a crafted target, an attacker can cause Kib...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33032
-
🚨 EUVD-2026-33033
📊 Score: 7.2/10 (CVSS v3.1)
📦 Product: Kibana, Kibana, Kibana
🏢 Vendor: Elastic
📅 Updated: 2026-05-28📝 Improper Input Validation (CWE-20) in the Kibana Fleet agent policy management feature can lead to privilege escalation. An authenticated user with Fleet management privileges can manipulate agent policy configuration by injecting values into ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33033
-
🚨 EUVD-2026-33034
📊 Score: 6.5/10 (CVSS v3.1)
📦 Product: Kibana
🏢 Vendor: Elastic
📅 Updated: 2026-05-28📝 Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with viewer-level access can submit a request containing an oversized input value to an analytics collections manag...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33034
-
🚨 EUVD-2026-33035
📊 Score: 6.3/10 (CVSS v3.1)
📦 Product: Kibana
🏢 Vendor: Elastic
📅 Updated: 2026-05-28📝 Server-Side Request Forgery (CWE-918) in Kibana can allow an authenticated user with connector management privileges to bypass the operator-configured connector allowlist, causing the Kibana server to issue outbound requests to destinations the egress control...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33035
-
🚨 EUVD-2026-33036
📊 Score: 9.8/10 (CVSS v3.1)
📦 Product: Oracle Hospitality OPERA 5 Property Services, Oracle Hospitality OPERA 5 Property Services, Oracle Hospitality OPERA 5 Property Services (+2 more)
🏢 Vendor: Oracle Corporation
📅 Updated: 2026-05-28📝 Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33036
-
🚨 EUVD-2026-33037
📊 Score: 7.9/10 (CVSS v3.1)
📦 Product: Oracle REST Data Services
🏢 Vendor: Oracle Corporation
📅 Updated: 2026-05-28📝 Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTPS to compromise ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33037
-
🚨 EUVD-2026-33038
📊 Score: 8.1/10 (CVSS v3.1)
📦 Product: Oracle REST Data Services
🏢 Vendor: Oracle Corporation
📅 Updated: 2026-05-28📝 Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Or...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33038
-
🚨 EUVD-2026-33039
📊 Score: 9.9/10 (CVSS v3.1)
📦 Product: Oracle REST Data Services
🏢 Vendor: Oracle Corporation
📅 Updated: 2026-05-28📝 Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Or...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33039
-
🚨 EUVD-2026-33040
📊 Score: 9.8/10 (CVSS v3.1)
📦 Product: Oracle Payments
🏢 Vendor: Oracle Corporation
📅 Updated: 2026-05-28📝 Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33040
-
🚨 EUVD-2026-33041
📊 Score: 7.4/10 (CVSS v3.1)
📦 Product: Oracle Payments
🏢 Vendor: Oracle Corporation
📅 Updated: 2026-05-28📝 Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with netwo...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33041
-
🚨 EUVD-2026-33042
📊 Score: 9.1/10 (CVSS v3.1)
📦 Product: Oracle Internet Procurement Connector
🏢 Vendor: Oracle Corporation
📅 Updated: 2026-05-28📝 Vulnerability in the Oracle Internet Procurement Connector product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerabilit...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33042
-
🚨 EUVD-2026-33043
📊 Score: 8.5/10 (CVSS v3.1)
📦 Product: Oracle Financials Common Modules
🏢 Vendor: Oracle Corporation
📅 Updated: 2026-05-28📝 Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33043
-
🚨 EUVD-2026-33044
📊 Score: 7.7/10 (CVSS v3.1)
📦 Product: Oracle Financials Common Modules
🏢 Vendor: Oracle Corporation
📅 Updated: 2026-05-28📝 Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33044
-
🚨 EUVD-2026-33045
📊 Score: 9.9/10 (CVSS v3.1)
📦 Product: Oracle iAssets
🏢 Vendor: Oracle Corporation
📅 Updated: 2026-05-28📝 Vulnerability in the Oracle iAssets product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33045
-
🚨 EUVD-2026-33046
📊 Score: 7.7/10 (CVSS v3.1)
📦 Product: Oracle Public Sector Financials (International)
🏢 Vendor: Oracle Corporation
📅 Updated: 2026-05-28📝 Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Suite (component: Authorization). Supported versions that are affected are 12.2.6-12.2.15. Easily exploitabl...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33046
-
🚨 EUVD-2026-33047
📊 Score: 9.9/10 (CVSS v3.1)
📦 Product: Oracle Universal Work Queue
🏢 Vendor: Oracle Corporation
📅 Updated: 2026-05-28📝 Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerabilit...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33047
-
🚨 EUVD-2026-33048
📊 Score: 8.8/10 (CVSS v3.1)
📦 Product: Oracle Payroll
🏢 Vendor: Oracle Corporation
📅 Updated: 2026-05-28📝 Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33048
-
🚨 EUVD-2026-33049
📊 Score: 8.8/10 (CVSS v3.1)
📦 Product: Oracle Payroll
🏢 Vendor: Oracle Corporation
📅 Updated: 2026-05-28📝 Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Self Service Manager). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33049
-
🚨 EUVD-2026-33050
📊 Score: 8.1/10 (CVSS v3.1)
📦 Product: Oracle Payroll
🏢 Vendor: Oracle Corporation
📅 Updated: 2026-05-28📝 Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33050
-
🚨 EUVD-2026-33051
📊 Score: 7.5/10 (CVSS v3.1)
📦 Product: Oracle REST Data Services
🏢 Vendor: Oracle Corporation
📅 Updated: 2026-05-28📝 Vulnerability in Oracle REST Data Services (component: Mongoapi). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromi...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33051
-
🚨 EUVD-2026-33052
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: Oracle REST Data Services
🏢 Vendor: Oracle Corporation
📅 Updated: 2026-05-28📝 Vulnerability in Oracle REST Data Services (component: Mongoapi). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromi...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33052
-
🚨 EUVD-2026-33013
📊 Score: 9.0/10 (CVSS v3.1)
📦 Product: Oracle Database Server
🏢 Vendor: Oracle Corporation
📅 Updated: 2026-05-28📝 Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compro...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33013
-
🚨 EUVD-2026-33015
📊 Score: 7.5/10 (CVSS v3.1)
📦 Product: Oracle Database Server
🏢 Vendor: Oracle Corporation
📅 Updated: 2026-05-28📝 Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromi...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33015
-
🚨 EUVD-2026-33014
📊 Score: 7.5/10 (CVSS v3.1)
📦 Product: Oracle Database Server
🏢 Vendor: Oracle Corporation
📅 Updated: 2026-05-28📝 Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromi...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33014
-
What is Web Security and Web Penetration Testing Tools
In this article, I cover essential web penetration testing tools and how they fit into different stages of the assessment process.
https://denizhalil.com/2024/12/19/web-penetration-testing-tools/#CyberSecurity #WebSecurity #Pentesting #BurpSuite #Nmap #SQLMap #BugBounty #RedTeam #InfoSec #EthicalHacking #SecurityTools #DenizHalil
-
It's news to me that #Microsoft now recommends migrating away from Active Directory. I'm wondering if the #Linux Foundation (or any well-funded competitor to microsoft, who favors Open Source) has noticed this, and has plans to develop or offer an #OpenSource alternative for Active Directory, which isn't owned or controlled by Microsoft in any way? #infosec #eu #germany
"Retiring Active Directory for Infrastructure with Entra ID":
https://www.egroup-us.com/news/retiring-active-directory-infrastructure-entra-id/ -
So i just created an e-mail account at https://soverin.nl/ and they send me the 2FA recovery code via plain text e-mail... 🤦🏼♂️ not very promissing 🙄
#security #privacy #infosec @soverin -
Phishing-Driven Banking Malware Campaign Targeting Windows and Android Devices
Active malware campaigns targeting Windows and Android users, which use Grandoreiro banking malware and the BTMOB Android RAT in order to steal financial and personal data. Victims are targeted through phishing emails and fake apps that trick them into installing malicious files or granting device access.
Pulse ID: 6a187c4e9fe60a946730ffb9
Pulse Link: https://otx.alienvault.com/pulse/6a187c4e9fe60a946730ffb9
Pulse Author: cryptocti
Created: 2026-05-28 17:33:02Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Android #Bank #CyberSecurity #Email #InfoSec #Malware #OTX #OpenThreatExchange #Phishing #RAT #Windows #bot #cryptocti
-
Phishing-Driven Banking Malware Campaign Targeting Windows and Android Devices
Active malware campaigns targeting Windows and Android users, which use Grandoreiro banking malware and the BTMOB Android RAT in order to steal financial and personal data. Victims are targeted through phishing emails and fake apps that trick them into installing malicious files or granting device access.
Pulse ID: 6a187cbd9fe60a946730ffba
Pulse Link: https://otx.alienvault.com/pulse/6a187cbd9fe60a946730ffba
Pulse Author: cryptocti
Created: 2026-05-28 17:34:53Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Android #Bank #CyberSecurity #Email #InfoSec #Malware #OTX #OpenThreatExchange #Phishing #RAT #Windows #bot #cryptocti
-
Phishing-Driven Banking Malware Campaign Targeting Windows and Android Devices
Active malware campaigns targeting Windows and Android users, which use Grandoreiro banking malware and the BTMOB Android RAT in order to steal financial and personal data. Victims are targeted through phishing emails and fake apps that trick them into installing malicious files or granting device access.
Pulse ID: 6a187cbd6c6d406caeef06a2
Pulse Link: https://otx.alienvault.com/pulse/6a187cbd6c6d406caeef06a2
Pulse Author: cryptocti
Created: 2026-05-28 17:34:53Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Android #Bank #CyberSecurity #Email #InfoSec #Malware #OTX #OpenThreatExchange #Phishing #RAT #Windows #bot #cryptocti
-
Phishing-Driven Banking Malware Campaign Targeting Windows and Android Devices
Active malware campaigns targeting Windows and Android users, which use Grandoreiro banking malware and the BTMOB Android RAT in order to steal financial and personal data. Victims are targeted through phishing emails and fake apps that trick them into installing malicious files or granting device access.
Pulse ID: 6a187cbe8cdd31d7f83c8063
Pulse Link: https://otx.alienvault.com/pulse/6a187cbe8cdd31d7f83c8063
Pulse Author: cryptocti
Created: 2026-05-28 17:34:54Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Android #Bank #CyberSecurity #Email #InfoSec #Malware #OTX #OpenThreatExchange #Phishing #RAT #Windows #bot #cryptocti
-
Phishing-Driven Banking Malware Campaign Targeting Windows and Android Devices
Active malware campaigns targeting Windows and Android users, which use Grandoreiro banking malware and the BTMOB Android RAT in order to steal financial and personal data. Victims are targeted through phishing emails and fake apps that trick them into installing malicious files or granting device access.
Pulse ID: 6a187cd2d4985ecd688b1c12
Pulse Link: https://otx.alienvault.com/pulse/6a187cd2d4985ecd688b1c12
Pulse Author: cryptocti
Created: 2026-05-28 17:35:14Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Android #Bank #CyberSecurity #Email #InfoSec #Malware #OTX #OpenThreatExchange #Phishing #RAT #Windows #bot #cryptocti
-
Phishing-Driven Banking Malware Campaign Targeting Windows and Android Devices
Active malware campaigns targeting Windows and Android users, which use Grandoreiro banking malware and the BTMOB Android RAT in order to steal financial and personal data. Victims are targeted through phishing emails and fake apps that trick them into installing malicious files or granting device access.
Pulse ID: 6a187d0757e29bb3897eac46
Pulse Link: https://otx.alienvault.com/pulse/6a187d0757e29bb3897eac46
Pulse Author: cryptocti
Created: 2026-05-28 17:36:07Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Android #Bank #CyberSecurity #Email #InfoSec #Malware #OTX #OpenThreatExchange #Phishing #RAT #Windows #bot #cryptocti
-
🟠 CVE-2026-45047 - High (7.5)
bird-lg-go is a BIRD looking glass in Go. Prior to 1.4.5, the apiHandler (and similarly webHandlerTelegramBot) processes user-provided JSON payloads by directly using json.NewDecoder(r.Body).Decode(&request) without restricting the maximum read si...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45047/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
Credential Stealer EKZ Delivered via FortiClient EMS Exploitation
Attackers exploited CVE-2026-35616 in FortiClient EMS. Threat actors changes EMS settings and pushed a malicious VPN script to endpoints. The script downloaded EKZ Infostealer, disguised as a Fortinet patch. The malware steals browser passwords, cookies, and autofill data.
Pulse ID: 6a1879e13827c581e8b73eb4
Pulse Link: https://otx.alienvault.com/pulse/6a1879e13827c581e8b73eb4
Pulse Author: cryptocti
Created: 2026-05-28 17:22:41Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Cookies #CyberSecurity #Endpoint #InfoSec #InfoStealer #Malware #OTX #OpenThreatExchange #Password #Passwords #VPN #Word #bot #cryptocti
-
Credential Stealer EKZ Delivered via FortiClient EMS Exploitation
Attackers exploited CVE-2026-35616 in FortiClient EMS. Threat actors changes EMS settings and pushed a malicious VPN script to endpoints. The script downloaded EKZ Infostealer, disguised as a Fortinet patch. The malware steals browser passwords, cookies, and autofill data.
Pulse ID: 6a1879e15c8f2d2d2cf72b60
Pulse Link: https://otx.alienvault.com/pulse/6a1879e15c8f2d2d2cf72b60
Pulse Author: cryptocti
Created: 2026-05-28 17:22:41Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Cookies #CyberSecurity #Endpoint #InfoSec #InfoStealer #Malware #OTX #OpenThreatExchange #Password #Passwords #VPN #Word #bot #cryptocti
-
Credential Stealer EKZ Delivered via FortiClient EMS Exploitation
Attackers exploited CVE-2026-35616 in FortiClient EMS. Threat actors changes EMS settings and pushed a malicious VPN script to endpoints. The script downloaded EKZ Infostealer, disguised as a Fortinet patch. The malware steals browser passwords, cookies, and autofill data.
Pulse ID: 6a1879e2d85be08873d89445
Pulse Link: https://otx.alienvault.com/pulse/6a1879e2d85be08873d89445
Pulse Author: cryptocti
Created: 2026-05-28 17:22:42Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Cookies #CyberSecurity #Endpoint #InfoSec #InfoStealer #Malware #OTX #OpenThreatExchange #Password #Passwords #VPN #Word #bot #cryptocti
-
Credential Stealer EKZ Delivered via FortiClient EMS Exploitation
Attackers exploited CVE-2026-35616 in FortiClient EMS. Threat actors changes EMS settings and pushed a malicious VPN script to endpoints. The script downloaded EKZ Infostealer, disguised as a Fortinet patch. The malware steals browser passwords, cookies, and autofill data.
Pulse ID: 6a187a5035303b62f8e49196
Pulse Link: https://otx.alienvault.com/pulse/6a187a5035303b62f8e49196
Pulse Author: cryptocti
Created: 2026-05-28 17:24:32Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Cookies #CyberSecurity #Endpoint #InfoSec #InfoStealer #Malware #OTX #OpenThreatExchange #Password #Passwords #VPN #Word #bot #cryptocti
-
Credential Stealer EKZ Delivered via FortiClient EMS Exploitation
Attackers exploited CVE-2026-35616 in FortiClient EMS. Threat actors changes EMS settings and pushed a malicious VPN script to endpoints. The script downloaded EKZ Infostealer, disguised as a Fortinet patch. The malware steals browser passwords, cookies, and autofill data.
Pulse ID: 6a187acb35f351993fe5e76b
Pulse Link: https://otx.alienvault.com/pulse/6a187acb35f351993fe5e76b
Pulse Author: cryptocti
Created: 2026-05-28 17:26:35Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Cookies #CyberSecurity #Endpoint #InfoSec #InfoStealer #Malware #OTX #OpenThreatExchange #Password #Passwords #VPN #Word #bot #cryptocti
-
🚨New ransom group blog posts!🚨
Group name: everest
Post title: AKM
Info: https://cti.fyi/groups/everest.htmlGroup name: everest
Post title: VVO Finance
Info: https://cti.fyi/groups/everest.htmlGroup name: everest
Post title: Sidra Kuwait Hospital
Info: https://cti.fyi/groups/everest.html#ransomware #cti #threatintelligence #cybersecurity #infosec
-
Rich Products Corporation Data Breach Investigation
Rich Products Corporation reported a data breach affecting approximately 200 individuals after a phishing attack compromised a third-party vendor's employee email account.
****
#cybersecurity #infosec #incident #databreach
https://beyondmachines.net/event_details/rich-products-corporation-data-breach-investigation-o-3-x-z-m/gD2P6Ple2L -
Rich Products Corporation Data Breach Investigation
Rich Products Corporation reported a data breach affecting approximately 200 individuals after a phishing attack compromised a third-party vendor's employee email account.
****
#cybersecurity #infosec #incident #databreach
https://beyondmachines.net/event_details/rich-products-corporation-data-breach-investigation-o-3-x-z-m/gD2P6Ple2L -
Rich Products Corporation Data Breach Investigation
Rich Products Corporation reported a data breach affecting approximately 200 individuals after a phishing attack compromised a third-party vendor's employee email account.
****
#cybersecurity #infosec #incident #databreach
https://beyondmachines.net/event_details/rich-products-corporation-data-breach-investigation-o-3-x-z-m/gD2P6Ple2L