home.social

#proxy — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #proxy, aggregated by home.social.

fetched live
  1. 3 Easy Steps to Integrate Monitoring Tools for #Apache Reverse #Proxy Server

    This article provides a step-by-step guide to integrate monitoring tools for Apache reverse proxy server. Integrating monitoring tools ...
    Continued 👉 #reverseproxy #proxyserver #selfhosting #opensource #selfhosted

    3 Easy Steps to Integrate Moni...

  2. 3 Easy Steps to Integrate Monitoring Tools for #Apache Reverse #Proxy Server

    This article provides a step-by-step guide to integrate monitoring tools for Apache reverse proxy server. Integrating monitoring tools ...
    Continued 👉 #reverseproxy #proxyserver #selfhosting #opensource #selfhosted

    3 Easy Steps to Integrate Moni...

  3. CoolClient backdoor goes deeper: Windows kernel rootkit added

    HoneyMyte APT group (also known as Mustang Panda) has significantly upgraded its CoolClient backdoor with kernel-level rootkit capabilities. The latest variant deploys a signed kernel-mode driver (msagent.sys) as a Windows service, enabling advanced stealth features including process hiding, file and registry protection, and network traffic filtering. The multi-stage malware uses DLL sideloading through a legitimate Sangfor application, establishes persistence via scheduled tasks and AutoRun entries, and implements UAC bypass techniques. CoolClient now injects into synchost.exe and communicates with the kernel driver through IOCTL requests. The driver hooks Nsiproxy to filter C2 addresses from network information. Victims have been identified in Myanmar, Mongolia, Pakistan, and Russia, with PlugX serving as the initial infection vector before CoolClient deployment.

    Pulse ID: 6a7ef2da146fb06724520eb4
    Pulse Link: otx.alienvault.com/pulse/6a7ef
    Pulse Author: AlienVault
    Created: 2026-08-14 10:50:02

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #InfoSec #Malware #Myanmar #OTX #OpenThreatExchange #Pakistan #PlugX #Proxy #Rootkit #Russia #SideLoading #Windows #bot #AlienVault

  4. CoolClient backdoor goes deeper: Windows kernel rootkit added

    HoneyMyte APT group (also known as Mustang Panda) has significantly upgraded its CoolClient backdoor with kernel-level rootkit capabilities. The latest variant deploys a signed kernel-mode driver (msagent.sys) as a Windows service, enabling advanced stealth features including process hiding, file and registry protection, and network traffic filtering. The multi-stage malware uses DLL sideloading through a legitimate Sangfor application, establishes persistence via scheduled tasks and AutoRun entries, and implements UAC bypass techniques. CoolClient now injects into synchost.exe and communicates with the kernel driver through IOCTL requests. The driver hooks Nsiproxy to filter C2 addresses from network information. Victims have been identified in Myanmar, Mongolia, Pakistan, and Russia, with PlugX serving as the initial infection vector before CoolClient deployment.

    Pulse ID: 6a7ef2da146fb06724520eb4
    Pulse Link: otx.alienvault.com/pulse/6a7ef
    Pulse Author: AlienVault
    Created: 2026-08-14 10:50:02

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #InfoSec #Malware #Myanmar #OTX #OpenThreatExchange #Pakistan #PlugX #Proxy #Rootkit #Russia #SideLoading #Windows #bot #AlienVault

  5. Need IPv6 devices on separate L2 segments to share a subnet? ndppd proxies Neighbor Solicitations across interfaces, extending the subnet without a router. Config: interface eth0, rule 2001:db8:1::/64 to eth1. Works on Ubuntu 22.04, Debian 12. #ndp #proxy #ValtersIT

    valtersit.com/vault/ipv6-neigh

  6. Multi-Functional Linux Botnet "Evooo1Bot"

    A previously undocumented Linux botnet named Evooo1Bot has been discovered, actively targeting Internet-facing devices since July 2026. Built upon Mirai's DDoS engine, it extends functionality with encrypted C2 communications, SSH brute-force scanning, SOCKS relay capabilities, credential sniffing, and an integrated exploit arsenal. The malware employs multi-layer string encryption using AES-256-CTR, ChaCha20, and XOR-based key derivation. It exploits numerous vulnerabilities across edge devices, routers, and enterprise applications. The reverse SOCKS relay module transforms compromised devices into persistent proxies, enabling attackers to conceal their origin and pivot into internal networks. The botnet features 28 remote commands organized into modules for persistence, self-update, file transfer, interactive shell, sniffing, proxy relay, SSH scanning, DDoS attacks, and CVE exploitation. Multiple persistence mechanisms ensure continued operation across systemd, SysV init, cron, and shell profiles.

    Pulse ID: 6a7e2be6ba37cc87ae552659
    Pulse Link: otx.alienvault.com/pulse/6a7e2
    Pulse Author: AlienVault
    Created: 2026-08-13 20:41:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ChaCha20 #CyberSecurity #DDoS #DoS #ELF #Edge #Encryption #InfoSec #Linux #Malware #Mirai #OTX #OpenThreatExchange #Proxy #RAT #RCE #SMS #SSH #bot #botnet #AlienVault

  7. Multi-Functional Linux Botnet "Evooo1Bot"

    A previously undocumented Linux botnet named Evooo1Bot has been discovered, actively targeting Internet-facing devices since July 2026. Built upon Mirai's DDoS engine, it extends functionality with encrypted C2 communications, SSH brute-force scanning, SOCKS relay capabilities, credential sniffing, and an integrated exploit arsenal. The malware employs multi-layer string encryption using AES-256-CTR, ChaCha20, and XOR-based key derivation. It exploits numerous vulnerabilities across edge devices, routers, and enterprise applications. The reverse SOCKS relay module transforms compromised devices into persistent proxies, enabling attackers to conceal their origin and pivot into internal networks. The botnet features 28 remote commands organized into modules for persistence, self-update, file transfer, interactive shell, sniffing, proxy relay, SSH scanning, DDoS attacks, and CVE exploitation. Multiple persistence mechanisms ensure continued operation across systemd, SysV init, cron, and shell profiles.

    Pulse ID: 6a7e2be6ba37cc87ae552659
    Pulse Link: otx.alienvault.com/pulse/6a7e2
    Pulse Author: AlienVault
    Created: 2026-08-13 20:41:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ChaCha20 #CyberSecurity #DDoS #DoS #ELF #Edge #Encryption #InfoSec #Linux #Malware #Mirai #OTX #OpenThreatExchange #Proxy #RAT #RCE #SMS #SSH #bot #botnet #AlienVault

  8. Inside a Ukrainian IP Camera Toolkit

    Two open directories hosted on Russian bulletproof infrastructure revealed coordinated operations targeting Ukrainian IP cameras, routers, and government websites. The first server exposed tools exploiting SQL injection against a Ukrainian e-commerce site, used as a proxy for Tor-routed attacks against government councils and military domains. A custom Docker platform named 'camview' cataloged 58 compromised Ukrainian cameras using known Hikvision and Dahua vulnerabilities. The second server deployed similar techniques across 15 European countries, converting compromised edge devices into SOCKS5 proxies. Both operations utilized the open-source Ingram scanner, focused on frontline Ukrainian cities including Kramatorsk, Slavyansk, Odessa, and Kherson, and employed Russian-language scripts. Evidence suggests potential linkage to drone operator infrastructure through role-based access controls, though direct military ties remain unconfirmed.

    Pulse ID: 6a7d8d2b3a8a65f2b1dc0cda
    Pulse Link: otx.alienvault.com/pulse/6a7d8
    Pulse Author: AlienVault
    Created: 2026-08-13 09:23:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Docker #Edge #Europe #Government #InfoSec #Military #OTX #OpenThreatExchange #Proxy #RAT #RCE #Russia #SQL #UK #Ukr #Ukrainian #bot #socks5 #AlienVault

  9. Inside a Ukrainian IP Camera Toolkit

    Two open directories hosted on Russian bulletproof infrastructure revealed coordinated operations targeting Ukrainian IP cameras, routers, and government websites. The first server exposed tools exploiting SQL injection against a Ukrainian e-commerce site, used as a proxy for Tor-routed attacks against government councils and military domains. A custom Docker platform named 'camview' cataloged 58 compromised Ukrainian cameras using known Hikvision and Dahua vulnerabilities. The second server deployed similar techniques across 15 European countries, converting compromised edge devices into SOCKS5 proxies. Both operations utilized the open-source Ingram scanner, focused on frontline Ukrainian cities including Kramatorsk, Slavyansk, Odessa, and Kherson, and employed Russian-language scripts. Evidence suggests potential linkage to drone operator infrastructure through role-based access controls, though direct military ties remain unconfirmed.

    Pulse ID: 6a7d8d2b3a8a65f2b1dc0cda
    Pulse Link: otx.alienvault.com/pulse/6a7d8
    Pulse Author: AlienVault
    Created: 2026-08-13 09:23:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Docker #Edge #Europe #Government #InfoSec #Military #OTX #OpenThreatExchange #Proxy #RAT #RCE #Russia #SQL #UK #Ukr #Ukrainian #bot #socks5 #AlienVault

  10. How to Setup a Reverse #Proxy with HTTPS Using #Nginx and #Certbot (5 Minute Quick-Start Guide)

    This article outlines how to setup a reverse proxy with HTTPS using Nginx and Certbot.
    What is a Reverse Proxy?
    A reverse proxy is a server ...
    Continued 👉 #proxyserver #letsencrypt #reverseproxy

    How to Setup a Reverse Proxy w...

  11. 737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection

    Socket's Threat Research Team identified a campaign of 737 malicious VPN and proxy extensions in the Chrome Web Store, accumulating over 75,000 installs. The extensions, published across 40 developer accounts, target Russian-speaking users seeking access to blocked services. 274 extensions impersonate 66 established VPN brands including Proton VPN, NordVPN, and AmneziaVPN. The extensions route all browser traffic through SOCKS5 proxies controlled by a single operator on port 1082, placing the threat actor in an adversary-in-the-middle position. Premium subscription tiers advertise servers in five countries that do not resolve. The campaign employs DNS-over-HTTPS for evasion, post-approval code substitution, and coordinated review gaming. The operation is linked to a Russian subscription VPN business that names a tax-registered self-employed individual as the contracting party.

    Pulse ID: 6a7c183cfe509b035144c5a6
    Pulse Link: otx.alienvault.com/pulse/6a7c1
    Pulse Author: AlienVault
    Created: 2026-08-12 06:52:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #Browser #Chrome #CyberSecurity #DNS #ELF #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Proxy #RAT #Russia #Troll #VPN #bot #socks5 #AlienVault

  12. 737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection

    Socket's Threat Research Team identified a campaign of 737 malicious VPN and proxy extensions in the Chrome Web Store, accumulating over 75,000 installs. The extensions, published across 40 developer accounts, target Russian-speaking users seeking access to blocked services. 274 extensions impersonate 66 established VPN brands including Proton VPN, NordVPN, and AmneziaVPN. The extensions route all browser traffic through SOCKS5 proxies controlled by a single operator on port 1082, placing the threat actor in an adversary-in-the-middle position. Premium subscription tiers advertise servers in five countries that do not resolve. The campaign employs DNS-over-HTTPS for evasion, post-approval code substitution, and coordinated review gaming. The operation is linked to a Russian subscription VPN business that names a tax-registered self-employed individual as the contracting party.

    Pulse ID: 6a7c183cfe509b035144c5a6
    Pulse Link: otx.alienvault.com/pulse/6a7c1
    Pulse Author: AlienVault
    Created: 2026-08-12 06:52:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #Browser #Chrome #CyberSecurity #DNS #ELF #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Proxy #RAT #Russia #Troll #VPN #bot #socks5 #AlienVault

  13. An Evolution of the Botnet

    A new version of the Kimwolf Android/IoT botnet has been identified, targeting Android TV boxes and set-top boxes. The version 7 variant introduces enhanced DDoS capabilities including HTTP/2-based floods with complete browser fingerprinting to mimic legitimate traffic. It employs a resilient three-tier command-and-control infrastructure using Ethereum Name Service resolution through five hard-coded public endpoints, a Tor hidden service backup, and local proxy architecture. The malware spreads by exploiting unauthenticated Android Debug Bridge instances via residential proxy services. The botnet implements 15 DDoS attack methods and utilizes ARM NEON SIMD optimization for high-performance UDP floods. Operators removed scanning and exploitation modules, separating propagation from DDoS functionality. The infrastructure is hosted primarily in Russia, with evidence of operator-controlled Ethereum RPC endpoints.

    Pulse ID: 6a7b3ea11dca2e714d4bff8d
    Pulse Link: otx.alienvault.com/pulse/6a7b3
    Pulse Author: AlienVault
    Created: 2026-08-11 15:24:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Android #Browser #CyberSecurity #DDoS #DoS #Endpoint #HTTP #InfoSec #IoT #Malware #Mimic #OTX #OpenThreatExchange #Proxy #RAT #RPC #Russia #Troll #UDP #bot #botnet #AlienVault

  14. An Evolution of the Botnet

    A new version of the Kimwolf Android/IoT botnet has been identified, targeting Android TV boxes and set-top boxes. The version 7 variant introduces enhanced DDoS capabilities including HTTP/2-based floods with complete browser fingerprinting to mimic legitimate traffic. It employs a resilient three-tier command-and-control infrastructure using Ethereum Name Service resolution through five hard-coded public endpoints, a Tor hidden service backup, and local proxy architecture. The malware spreads by exploiting unauthenticated Android Debug Bridge instances via residential proxy services. The botnet implements 15 DDoS attack methods and utilizes ARM NEON SIMD optimization for high-performance UDP floods. Operators removed scanning and exploitation modules, separating propagation from DDoS functionality. The infrastructure is hosted primarily in Russia, with evidence of operator-controlled Ethereum RPC endpoints.

    Pulse ID: 6a7b3ea11dca2e714d4bff8d
    Pulse Link: otx.alienvault.com/pulse/6a7b3
    Pulse Author: AlienVault
    Created: 2026-08-11 15:24:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Android #Browser #CyberSecurity #DDoS #DoS #Endpoint #HTTP #InfoSec #IoT #Malware #Mimic #OTX #OpenThreatExchange #Proxy #RAT #RPC #Russia #Troll #UDP #bot #botnet #AlienVault

  15. How to Setup a Reverse #Proxy with HTTPS Using #Nginx and #Certbot (5 Minute Quick-Start Guide)

    This article outlines how to setup a reverse proxy with HTTPS using Nginx and Certbot.
    What is a Reverse Proxy?
    A reverse proxy is a server that sits between client devices and a backend server, forwarding client requests to the backend server and returning the server's response to the clients. Unlike a forward proxy, ...
    Continued 👉 blog.radwebhosting.com/setup-a #letsencrypt #reverseproxy #proxyserver

  16. How to Setup a Reverse #Proxy with HTTPS Using #Nginx and #Certbot (5 Minute Quick-Start Guide)

    This article outlines how to setup a reverse proxy with HTTPS using Nginx and Certbot.
    What is a Reverse Proxy?
    A reverse proxy is a server that sits between client devices and a backend server, forwarding client requests to the backend server and returning the server's response to the clients. Unlike a forward proxy, ...
    Continued 👉 blog.radwebhosting.com/setup-a #letsencrypt #reverseproxy #proxyserver

  17. Install and Configure #SOCKS #Proxy Server on Rocky Linux #VPS

    This article provides a guide for how to install and configure SOCKS proxy server on Rocky Linux VPS.
    What is SOCKS Proxy Server?
    A SOCKS proxy server is a proxy that routes network traffic between your device and the internet using the SOCKS protocol.

    Unlike an HTTP proxy, which is mainly designed for web traffic, a SOCKS proxy ...
    Continued 👉 blog.radwebhosting.com/install #installguide #rockylinux #vpsguide #proxyserver #socks5

  18. История одного архитектурного круга: реактивность Vue

    Vue снова меняет способ обновления интерфейса: теперь на горизонте Vapor и рендеринг без Virtual DOM. Зачем очередная архитектурная перестройка и что не устраивает команду Vue в нынешнем подходе? Чтобы ответить, проследим путь Vue от Object.defineProperty до Proxy и зачем теперь понадобился Vapor. Это поможет лучше понимать поведение ref, reactive и computed, вникнуть в причины архитектурных изменений Vue и подготовиться к дальнейшим изменениям.

    habr.com/ru/companies/first/ar

    #vue #vuejs #vue3 #signals #reactivity #reactivity_javascript #proxy #virtualdom #vapor #dom

  19. 3 Easy Steps to Integrate Monitoring Tools for #Apache Reverse #Proxy Server

    This article provides a step-by-step guide to integrate monitoring tools for Apache reverse proxy server. Integrating monitoring tools with your Apache reverse proxy server setup allows you to track performance, detect issues, and optimize your infrastructure efficiently.
    How to Integrate Monitoring Tools for Apache ...
    Continued 👉 blog.radwebhosting.com/monitor #proxyserver #reverseproxy #opensource #selfhosted #selfhosting

  20. 3 Easy Steps to Integrate Monitoring Tools for #Apache Reverse #Proxy Server

    This article provides a step-by-step guide to integrate monitoring tools for Apache reverse proxy server. Integrating monitoring tools with your Apache reverse proxy server setup allows you to track performance, detect issues, and optimize your infrastructure efficiently.
    How to Integrate Monitoring Tools for Apache ...
    Continued 👉 blog.radwebhosting.com/monitor #proxyserver #reverseproxy #opensource #selfhosted #selfhosting

  21. 7 Steps to Easily Configure #OpenLiteSpeed as a Reverse #Proxy for #Metabase

    This article provides a guide to configure OpenLiteSpeed as a reverse proxy for Metabase.
    What is OpenLiteSpeed?
    OpenLiteSpeed Web Server is great for building and deploying web applications. The WebAdmin Console enables you to quickly configure features that allow you to ...
    Continued 👉 blog.radwebhosting.com/configu #selfhosting #selfhosted #installguide #letsencrypt #reverseproxy #vps #jre #proxyserver #openjdk #debian

  22. Что видит DPI, и что мы попробовали у него отобрать / Хабр

    habr.com/ru/articles/1068156/

    > устойчивая к DPI (Deep Packet Inspection) туннельная инфраструктура — по сути, альтернатива классическому VPN.

    shortnerdcat.navlink.net

    SDK на GitHub: github.com/kostiakhait/tunnelc

    #proxy #vpn #tunnelcat

  23. 7 Steps to Easily Configure #OpenLiteSpeed as a Reverse #Proxy for #Metabase

    This article provides a guide to configure OpenLiteSpeed as a reverse proxy for Metabase.
    What is OpenLiteSpeed?
    OpenLiteSpeed Web Server is great for building and deploying web applications. The WebAdmin Console enables you to quickly configure features that allow you to ...
    Continued 👉 blog.radwebhosting.com/configu #selfhosted #debian #reverseproxy #openjdk #letsencrypt #jre #selfhosting #installguide #proxyserver #vps

  24. 7 Steps to Easily Configure #OpenLiteSpeed as a Reverse #Proxy for #Metabase

    This article provides a guide to configure OpenLiteSpeed as a reverse proxy for Metabase.
    What is OpenLiteSpeed?
    OpenLiteSpeed Web Server is great for building and deploying web applications. The WebAdmin Console enables you to quickly configure features that allow you to ...
    Continued 👉 blog.radwebhosting.com/configu #selfhosted #debian #reverseproxy #openjdk #letsencrypt #jre #selfhosting #installguide #proxyserver #vps

  25. How to Setup a Reverse #Proxy with HTTPS Using #Nginx and #Certbot (5 Minute Quick-Start Guide)

    This article outlines how to setup a reverse proxy with HTTPS using Nginx and Certbot.
    What is a Reverse Proxy?
    A reverse proxy is a server ...
    Continued 👉 #reverseproxy #proxyserver #letsencrypt

    How to Setup a Reverse Proxy w...

  26. Install and Configure #SOCKS #Proxy Server on Rocky Linux #VPS

    This article provides a guide for how to install and configure SOCKS proxy server on Rocky Linux VPS.
    What is SOCKS Proxy Server?
    A SOCKS proxy server is a proxy that routes network traffic between your device and the internet using the SOCKS protocol.

    Unlike an HTTP proxy, which is mainly designed for web traffic, a SOCKS proxy ...
    Continued 👉 blog.radwebhosting.com/install #rockylinux #socks5 #proxyserver #vpsguide #installguide

  27. Install and Configure #SOCKS #Proxy Server on Rocky Linux #VPS

    This article provides a guide for how to install and configure SOCKS proxy server on Rocky Linux VPS.
    What is SOCKS Proxy Server?
    A SOCKS proxy server is a proxy that routes network traffic between your device and the internet using the SOCKS protocol.

    Unlike an HTTP proxy, which is mainly designed for web traffic, a SOCKS proxy ...
    Continued 👉 blog.radwebhosting.com/install #rockylinux #socks5 #proxyserver #vpsguide #installguide

  28. 3 Easy Steps to Integrate Monitoring Tools for #Apache Reverse #Proxy Server

    This article provides a step-by-step guide to integrate monitoring tools for Apache reverse proxy server. Integrating monitoring tools ...
    Continued 👉 #selfhosting #reverseproxy #proxyserver #opensource #selfhosted

    3 Easy Steps to Integrate Moni...

  29. 3 Easy Steps to Integrate Monitoring Tools for #Apache Reverse #Proxy Server

    This article provides a step-by-step guide to integrate monitoring tools for Apache reverse proxy server. Integrating monitoring tools ...
    Continued 👉 #selfhosting #reverseproxy #proxyserver #opensource #selfhosted

    3 Easy Steps to Integrate Moni...

  30. Как я настроил безопасное шифрование данных для сайта с помощью протокола HTTPS и SSL/TLS сертификата

    Представим что у вас есть свой сайт запущенный на VPS на голом HTTP, также вы уже купили домен и связали его со своим IP-адресом. Но спустя время вы решили, что не хотите, чтоб весь трафик между клиентами и сервером был виден любому желающему. Вспомнили, что есть протокол HTTPS, который по сути обычный HTTP, но на 5 и 6 уровне работает протокол SSL/TLS, который занимается шифрованием и аутентификацией. Дело осталось за малым, перевести сайт с HTTP на HTTPS.

    habr.com/ru/articles/1068204/

    #python #https #proxy #networking #FastAPI #middleware #reverseproxy #reverse_proxy

  31. 3 Easy Steps to Integrate Monitoring Tools for #Apache Reverse #Proxy Server

    This article provides a step-by-step guide to integrate monitoring tools for Apache reverse proxy server. Integrating monitoring tools with your Apache reverse proxy server setup allows you to track performance, detect issues, and optimize your infrastructure efficiently.
    How to Integrate Monitoring Tools for Apache ...
    Continued 👉 blog.radwebhosting.com/monitor #selfhosting #selfhosted #opensource #proxyserver #reverseproxy

  32. There are already many ways to run a snowflake proxy, but Bloco and the Tor Project are betting that a dedicated Android app will make it easier for normies to get involved and stay motivated to help out, and early metrics suggest this bet is paying off!

    Using libraries from the Guardian Project, Bloco has built Snowflake Volunteer which can be downloaded from Fdroid and Google Play

    bloco.io/blog/snowflake-volunt

    #tor #snowflake #censorship #proxy #android #fdroid #VPN #volunteer

  33. There are already many ways to run a snowflake proxy, but Bloco and the Tor Project are betting that a dedicated Android app will make it easier for normies to get involved and stay motivated to help out, and early metrics suggest this bet is paying off!

    Using libraries from the Guardian Project, Bloco has built Snowflake Volunteer which can be downloaded from Fdroid and Google Play

    bloco.io/blog/snowflake-volunt

    #tor #snowflake #censorship #proxy #android #fdroid #VPN #volunteer

  34. Analysis of a Modular Cyber Espionage Framework

    Security researchers have uncovered a sophisticated cyber espionage operation deploying two previously undocumented malware families, OctLurk and SilkLurk, targeting government and public-sector organizations across Central Asia and the Middle East. Both modular backdoors utilize victim-specific decryption mechanisms, extensive obfuscation, and in-memory execution to evade detection. The malware enables credential theft, remote access, network reconnaissance, and plugin-based expansion. Operations began in January 2025, affecting entities in Afghanistan, Kazakhstan, Kyrgyzstan, Syria, Tajikistan, and Uzbekistan. Victims include government offices, foreign affairs ministries, law enforcement agencies, healthcare providers, logistics organizations, research institutions, urban planning facilities, and educational establishments. Attackers deployed additional tools including Impacket's SecretsDump, Browser Password Decryptor, Pandora RC, Fscan, WinRAR, 7-Zip, and PlugX. A companion utility, LurkProxy, proxies a

    Pulse ID: 6a75b204c9420179df545451
    Pulse Link: otx.alienvault.com/pulse/6a75b
    Pulse Author: AlienVault
    Created: 2026-08-07 10:23:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Afghanistan #Asia #BackDoor #Browser #CentralAsia #CyberSecurity #Education #Espionage #Government #Healthcare #ICS #InfoSec #Kazakhstan #LawEnforcement #Malware #MiddleEast #OTX #Office #OpenThreatExchange #Password #PlugX #Proxy #RAT #RCE #SMS #Syria #WinRAR #Word #ZIP #bot #AlienVault

  35. Analysis of a Modular Cyber Espionage Framework

    Security researchers have uncovered a sophisticated cyber espionage operation deploying two previously undocumented malware families, OctLurk and SilkLurk, targeting government and public-sector organizations across Central Asia and the Middle East. Both modular backdoors utilize victim-specific decryption mechanisms, extensive obfuscation, and in-memory execution to evade detection. The malware enables credential theft, remote access, network reconnaissance, and plugin-based expansion. Operations began in January 2025, affecting entities in Afghanistan, Kazakhstan, Kyrgyzstan, Syria, Tajikistan, and Uzbekistan. Victims include government offices, foreign affairs ministries, law enforcement agencies, healthcare providers, logistics organizations, research institutions, urban planning facilities, and educational establishments. Attackers deployed additional tools including Impacket's SecretsDump, Browser Password Decryptor, Pandora RC, Fscan, WinRAR, 7-Zip, and PlugX. A companion utility, LurkProxy, proxies a

    Pulse ID: 6a75b204c9420179df545451
    Pulse Link: otx.alienvault.com/pulse/6a75b
    Pulse Author: AlienVault
    Created: 2026-08-07 10:23:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Afghanistan #Asia #BackDoor #Browser #CentralAsia #CyberSecurity #Education #Espionage #Government #Healthcare #ICS #InfoSec #Kazakhstan #LawEnforcement #Malware #MiddleEast #OTX #Office #OpenThreatExchange #Password #PlugX #Proxy #RAT #RCE #SMS #Syria #WinRAR #Word #ZIP #bot #AlienVault

  36. Payroll Pirates: Strange New Tides in Business Email Compromise

    Arctic Wolf is tracking an active, widespread phishing campaign targeting Microsoft 365 accounts using adversary-in-the-middle (AiTM) techniques. The operation employs voicemail-themed phishing emails that redirect victims through multiple legitimate services to AiTM proxy infrastructure, which intercepts authentication sessions even when multi-factor authentication is enabled. Once compromised, threat actors use residential proxies to maintain access, conducting automated sign-ins at eight-hour intervals while collecting email from personnel involved in financial workflows. The campaign uses Microsoft Graph for reconnaissance targeting payroll, HR, and finance users, followed by coordinated mailbox collection. Activity affects organizations across healthcare, education, manufacturing, government, and professional services sectors in the United States, Canada, and Europe. The campaign shares characteristics with Microsoft-tracked Storm-2755 activity cluster.

    Pulse ID: 6a7546d2694489fe6ddddcd5
    Pulse Link: otx.alienvault.com/pulse/6a754
    Pulse Author: AlienVault
    Created: 2026-08-07 02:45:38

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #AitM #Canada #CyberSecurity #Education #Email #Europe #Government #Healthcare #ICS #InfoSec #Manufacturing #Microsoft #OTX #OpenThreatExchange #Phishing #Proxy #RAT #RCE #UnitedStates #bot #AlienVault

  37. Payroll Pirates: Strange New Tides in Business Email Compromise

    Arctic Wolf is tracking an active, widespread phishing campaign targeting Microsoft 365 accounts using adversary-in-the-middle (AiTM) techniques. The operation employs voicemail-themed phishing emails that redirect victims through multiple legitimate services to AiTM proxy infrastructure, which intercepts authentication sessions even when multi-factor authentication is enabled. Once compromised, threat actors use residential proxies to maintain access, conducting automated sign-ins at eight-hour intervals while collecting email from personnel involved in financial workflows. The campaign uses Microsoft Graph for reconnaissance targeting payroll, HR, and finance users, followed by coordinated mailbox collection. Activity affects organizations across healthcare, education, manufacturing, government, and professional services sectors in the United States, Canada, and Europe. The campaign shares characteristics with Microsoft-tracked Storm-2755 activity cluster.

    Pulse ID: 6a7546d2694489fe6ddddcd5
    Pulse Link: otx.alienvault.com/pulse/6a754
    Pulse Author: AlienVault
    Created: 2026-08-07 02:45:38

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #AitM #Canada #CyberSecurity #Education #Email #Europe #Government #Healthcare #ICS #InfoSec #Manufacturing #Microsoft #OTX #OpenThreatExchange #Phishing #Proxy #RAT #RCE #UnitedStates #bot #AlienVault

  38. Install and Configure #SOCKS #Proxy Server on Rocky Linux #VPS

    This article provides a guide for how to install and configure SOCKS proxy server on Rocky Linux VPS.
    What is SOCKS Proxy Server?
    A SOCKS proxy server is a ...
    Continued 👉 #rockylinux #socks5 #installguide #vpsguide #proxyserver

    Install and Configure SOCKS Pr...

  39. Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses

    Indicators extracted from public reporting. Source: mysk.blog/2026/08/04/webkit-pr

    Pulse ID: 6a7484e2d44d166d3f55db5b
    Pulse Link: otx.alienvault.com/pulse/6a748
    Pulse Author: CyberHunter_NL
    Created: 2026-08-06 12:58:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Proxy #RCE #bot #CyberHunter_NL

  40. Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses

    Indicators extracted from public reporting. Source: mysk.blog/2026/08/04/webkit-pr

    Pulse ID: 6a7484e2d44d166d3f55db5b
    Pulse Link: otx.alienvault.com/pulse/6a748
    Pulse Author: CyberHunter_NL
    Created: 2026-08-06 12:58:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Proxy #RCE #bot #CyberHunter_NL

  41. How to Setup a Reverse #Proxy with HTTPS Using #Nginx and #Certbot (5 Minute Quick-Start Guide)

    This article outlines how to setup a reverse proxy with HTTPS using Nginx and Certbot.
    What is a Reverse Proxy?
    A reverse proxy is a server that sits between client devices and a backend server, forwarding client requests to the backend server and returning the server's response to the clients. Unlike a forward proxy, ...
    Continued 👉 blog.radwebhosting.com/setup-a #reverseproxy #letsencrypt #proxyserver

  42. 🚀 New #release · Puter 26.08

    What's Changed
    • perf: try to improve app opens speed by @Salazareo in #3462
    • remove deprecated ai models by @reynaldichernando in #3444
    • add fixes 1 by @ProgrammerIn-wonderland in #3458
    • Replaced Nginx with Caddy by @rowin-C in #3378

    Check and self-host it → selfhost.directory/project/put

    #selfhosting #puter #breaking #proxy #ai

  43. 🚀 New #release · Puter 26.08

    What's Changed
    • perf: try to improve app opens speed by @Salazareo in #3462
    • remove deprecated ai models by @reynaldichernando in #3444
    • add fixes 1 by @ProgrammerIn-wonderland in #3458
    • Replaced Nginx with Caddy by @rowin-C in #3378

    Check and self-host it → selfhost.directory/project/put

    #selfhosting #puter #breaking #proxy #ai

  44. 🛡️ getmeridian/meridian

    One command deploys an undetectable proxy using VLESS+Reality. Automates firewall, TLS, and SNI routing on your VPS.

    ⭐ Stars: 477
    📅 Last Update: Aug 04, 2026

    github.com/getmeridian/meridian

    #selfhosted #homelab #selfhost #selfhosting #opensource #proxy #firewall

  45. Almost Half of Malware Samples Communicate Direct to IP

    Analysis of 4 million dynamic malware reports reveals that 45.32% of malware samples with command-and-control activity establish direct-to-IP (D2IP) connections, bypassing DNS entirely and evading DNS-based security defenses. D2IP traffic accounts for 23.17% of all C2 connection attempts. This behavior is observed across diverse threats including Phorpiex ransomware droppers using hard-coded IP addresses, persistent data exfiltration campaigns employing obfuscated HTTP GET requests, SectopRAT targeting educational institutions with in-browser proxy capabilities, and IoT botnets like Mozi and Boatnet propagating through P2P networks. The research introduces zero trust IP (ZT-IP), a network-level enforcement approach that verifies whether outbound connection destinations were previously sanctioned by DNS responses, effectively blocking malicious D2IP communications that traditional DNS-based security controls cannot detect.

    Pulse ID: 6a71e43a0127c62218b7c365
    Pulse Link: otx.alienvault.com/pulse/6a71e
    Pulse Author: AlienVault
    Created: 2026-08-04 13:08:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #DNS #Education #HTTP #InfoSec #IoT #Malware #OTX #OpenThreatExchange #Phorpiex #Proxy #RAT #RCE #RansomWare #Rust #ZeroTrust #bot #botnet #AlienVault

  46. Almost Half of Malware Samples Communicate Direct to IP

    Analysis of 4 million dynamic malware reports reveals that 45.32% of malware samples with command-and-control activity establish direct-to-IP (D2IP) connections, bypassing DNS entirely and evading DNS-based security defenses. D2IP traffic accounts for 23.17% of all C2 connection attempts. This behavior is observed across diverse threats including Phorpiex ransomware droppers using hard-coded IP addresses, persistent data exfiltration campaigns employing obfuscated HTTP GET requests, SectopRAT targeting educational institutions with in-browser proxy capabilities, and IoT botnets like Mozi and Boatnet propagating through P2P networks. The research introduces zero trust IP (ZT-IP), a network-level enforcement approach that verifies whether outbound connection destinations were previously sanctioned by DNS responses, effectively blocking malicious D2IP communications that traditional DNS-based security controls cannot detect.

    Pulse ID: 6a71e43a0127c62218b7c365
    Pulse Link: otx.alienvault.com/pulse/6a71e
    Pulse Author: AlienVault
    Created: 2026-08-04 13:08:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #DNS #Education #HTTP #InfoSec #IoT #Malware #OTX #OpenThreatExchange #Phorpiex #Proxy #RAT #RCE #RansomWare #Rust #ZeroTrust #bot #botnet #AlienVault

  47. 🔗 kittors/CliRelay

    Aggregates AI CLI tool subscriptions into a single gateway providing multi-tenancy request logging and quota controls

    ⭐ Stars: 881
    📅 Last Update: Aug 04, 2026

    github.com/kittors/CliRelay

    #selfhosted #homelab #selfhost #selfhosting #opensource #proxy #ai

  48. INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws

    Indicators extracted from public reporting. Source: resecurity.com/blog/article/fr

    Pulse ID: 6a70c869a5f154f3d8e2296c
    Pulse Link: otx.alienvault.com/pulse/6a70c
    Pulse Author: CyberHunter_NL
    Created: 2026-08-03 16:57:13

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AWS #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Proxy #RCE #RansomWare #bot #CyberHunter_NL

  49. How to Setup a Reverse #Proxy with HTTPS Using #Nginx and #Certbot (5 Minute Quick-Start Guide)

    This article outlines how to setup a reverse proxy with HTTPS using Nginx and Certbot.
    What is a Reverse Proxy?
    A reverse proxy is a server that sits between client devices and a backend server, forwarding client requests to the backend server and returning the server's response to the clients. Unlike a forward proxy, ...
    Continued 👉 blog.radwebhosting.com/setup-a #letsencrypt #reverseproxy #proxyserver