#secops — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #secops, aggregated by home.social.
-
🖼️ RCE a WordPress via PNG maliciosos. CVE-2026-65640, fix a 7.0.4.
Atacant amb rol Autor puja `EPS:innocent.png` o un PNG amb PostScript ocult. `Imagick::load()` confiava en l'extensió; ImageMagick llegeix el contingut real → Ghostscript executa. XML-RPC i portades MP3 saltaven la validació.
El patch inspecciona bytes reals: bloqueja PostScript/EPS, PDF sense `%PDF-` i gzip/bzip2.
https://blog.elhacker.net/2026/08/vulnerabilidad-rce-en-wordpress-imagick.html
#WordPress #SecOps #ImageMagick -
🖼️ RCE a WordPress via PNG maliciosos. CVE-2026-65640, fix a 7.0.4.
Atacant amb rol Autor puja `EPS:innocent.png` o un PNG amb PostScript ocult. `Imagick::load()` confiava en l'extensió; ImageMagick llegeix el contingut real → Ghostscript executa. XML-RPC i portades MP3 saltaven la validació.
El patch inspecciona bytes reals: bloqueja PostScript/EPS, PDF sense `%PDF-` i gzip/bzip2.
https://blog.elhacker.net/2026/08/vulnerabilidad-rce-en-wordpress-imagick.html
#WordPress #SecOps #ImageMagick -
2026-08-12 RDP #Honeypot IOCs - 3636 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
88.198.2.157 - 2847
155.117.13.211 - 390
103.178.235.50 - 150Top ASNs:
AS24940 - 2847
AS16276 - 390
AS140810 - 150Top Accounts:
hello - 3516
Domain - 27
Test - 18Top ISPs:
Hetzner Online GmbH - 2847
OVH SAS - 390
VPSTTT - 150Top Clients:
Unknown - 3636Top Software:
Unknown - 3636Top Keyboards:
Unknown - 3636Top IP Classification:
hosting - 3072
Unknown - 393
hosting & proxy - 153Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-08-12 RDP #Honeypot IOCs - 2424 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
88.198.2.157 - 1898
155.117.13.211 - 260
103.178.235.50 - 100Top ASNs:
AS24940 - 1898
AS16276 - 260
AS140810 - 100Top Accounts:
hello - 2344
Domain - 18
Test - 12Top ISPs:
Hetzner Online GmbH - 1898
OVH SAS - 260
VPSTTT - 100Top Clients:
Unknown - 2424Top Software:
Unknown - 2424Top Keyboards:
Unknown - 2424Top IP Classification:
hosting - 2048
Unknown - 262
hosting & proxy - 102Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-08-12 RDP #Honeypot IOCs - 1212 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
88.198.2.157 - 949
155.117.13.211 - 130
103.178.235.50 - 50Top ASNs:
AS24940 - 949
AS16276 - 130
AS140810 - 50Top Accounts:
hello - 1172
Domain - 9
Test - 6Top ISPs:
Hetzner Online GmbH - 949
OVH SAS - 130
VPSTTT - 50Top Clients:
Unknown - 1212Top Software:
Unknown - 1212Top Keyboards:
Unknown - 1212Top IP Classification:
hosting - 1024
Unknown - 131
hosting & proxy - 51Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
CVE-2026-57858: CRITICAL stored XSS in Cal.com Self-Hosted (v2.1.1 – 6.2.0). Exploited via BookingPageTagManager by authenticated event owners; affects all booking page visitors. Patch status unknown. Restrict privileges. https://radar.offseq.com/threat/cve-2026-57858-improper-neutralization-of-input-during-web-page-generation-cross-site-scripting-in-953e719dabfd2c11 #OffSeq #XSS #SecOps
-
2026-08-11 RDP #Honeypot IOCs - 1338 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
155.117.13.211 - 822
178.128.32.226 - 330
157.66.48.32 - 60Top ASNs:
AS16276 - 822
AS14061 - 360
AS150895 - 60Top Accounts:
hello - 1260
Test - 18
Administr - 9Top ISPs:
OVH SAS - 822
DigitalOcean, LLC - 360
VPSPA - 60Top Clients:
Unknown - 1338Top Software:
Unknown - 1338Top Keyboards:
Unknown - 1338Top IP Classification:
Unknown - 834
hosting & proxy - 336
hosting - 156Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-08-11 RDP #Honeypot IOCs - 892 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
155.117.13.211 - 548
178.128.32.226 - 220
157.66.48.32 - 40Top ASNs:
AS16276 - 548
AS14061 - 240
AS150895 - 40Top Accounts:
hello - 840
Test - 12
Administr - 6Top ISPs:
OVH SAS - 548
DigitalOcean, LLC - 240
VPSPA - 40Top Clients:
Unknown - 892Top Software:
Unknown - 892Top Keyboards:
Unknown - 892Top IP Classification:
Unknown - 556
hosting & proxy - 224
hosting - 104Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-08-11 RDP #Honeypot IOCs - 446 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
155.117.13.211 - 274
178.128.32.226 - 110
157.66.48.32 - 20Top ASNs:
AS16276 - 274
AS14061 - 120
AS150895 - 20Top Accounts:
hello - 420
Test - 6
Administr - 3Top ISPs:
OVH SAS - 274
DigitalOcean, LLC - 120
VPSPA - 20Top Clients:
Unknown - 446Top Software:
Unknown - 446Top Keyboards:
Unknown - 446Top IP Classification:
Unknown - 278
hosting & proxy - 112
hosting - 52Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-08-10 RDP #Honeypot IOCs - 3084 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
155.117.13.211 - 1098
206.189.58.63 - 825
134.199.148.184 - 591Top ASNs:
AS14061 - 1908
AS16276 - 1098
AS396982 - 36Top Accounts:
hello - 3015
Test - 12
Domain - 9Top ISPs:
DigitalOcean, LLC - 1908
OVH SAS - 1098
Google LLC - 36Top Clients:
Unknown - 3084Top Software:
Unknown - 3084Top Keyboards:
Unknown - 3084Top IP Classification:
hosting - 1533
Unknown - 1101
hosting & proxy - 444Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-08-10 RDP #Honeypot IOCs - 2056 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
155.117.13.211 - 732
206.189.58.63 - 550
134.199.148.184 - 394Top ASNs:
AS14061 - 1272
AS16276 - 732
AS396982 - 24Top Accounts:
hello - 2010
Test - 8
Domain - 6Top ISPs:
DigitalOcean, LLC - 1272
OVH SAS - 732
Google LLC - 24Top Clients:
Unknown - 2056Top Software:
Unknown - 2056Top Keyboards:
Unknown - 2056Top IP Classification:
hosting - 1022
Unknown - 734
hosting & proxy - 296Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-08-10 RDP #Honeypot IOCs - 1028 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
155.117.13.211 - 366
206.189.58.63 - 275
134.199.148.184 - 197Top ASNs:
AS14061 - 636
AS16276 - 366
AS396982 - 12Top Accounts:
hello - 1005
Test - 4
Domain - 3Top ISPs:
DigitalOcean, LLC - 636
OVH SAS - 366
Google LLC - 12Top Clients:
Unknown - 1028Top Software:
Unknown - 1028Top Keyboards:
Unknown - 1028Top IP Classification:
hosting - 511
Unknown - 367
hosting & proxy - 148Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
Le chef du renseignement militaire néerlandais a pu être suivi à la trace via l’application sportive Strava
-
2026-08-09 RDP #Honeypot IOCs - 4638 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
206.189.58.63 - 2286
134.199.148.184 - 1020
155.117.13.211 - 621Top ASNs:
AS14061 - 3381
AS16276 - 621
AS8075 - 510Top Accounts:
hello - 4530
Administr - 15
eltons - 15Top ISPs:
DigitalOcean, LLC - 3381
OVH SAS - 621
Microsoft Corporation - 510Top Clients:
Unknown - 4638Top Software:
Unknown - 4638Top Keyboards:
Unknown - 4638Top IP Classification:
hosting - 3939
Unknown - 684
hosting & proxy - 15Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-08-09 RDP #Honeypot IOCs - 3092 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
206.189.58.63 - 1524
134.199.148.184 - 680
155.117.13.211 - 414Top ASNs:
AS14061 - 2254
AS16276 - 414
AS8075 - 340Top Accounts:
hello - 3020
Administr - 10
eltons - 10Top ISPs:
DigitalOcean, LLC - 2254
OVH SAS - 414
Microsoft Corporation - 340Top Clients:
Unknown - 3092Top Software:
Unknown - 3092Top Keyboards:
Unknown - 3092Top IP Classification:
hosting - 2626
Unknown - 456
hosting & proxy - 10Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
2026-08-09 RDP #Honeypot IOCs - 1546 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
206.189.58.63 - 762
134.199.148.184 - 340
155.117.13.211 - 207Top ASNs:
AS14061 - 1127
AS16276 - 207
AS8075 - 170Top Accounts:
hello - 1510
Administr - 5
eltons - 5Top ISPs:
DigitalOcean, LLC - 1127
OVH SAS - 207
Microsoft Corporation - 170Top Clients:
Unknown - 1546Top Software:
Unknown - 1546Top Keyboards:
Unknown - 1546Top IP Classification:
hosting - 1313
Unknown - 228
hosting & proxy - 5Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
Autonomous AI agents introduce a dangerous logic vulnerability: Semantic Poisoning. Here is how adversaries subvert defensive policy. https://hackernoon.com/the-vulnerability-of-intent #secops
-
2026-08-05 RDP #Honeypot IOCs - 29778 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
27.71.229.97 - 29670
134.199.168.195 - 30
45.142.193.18 - 12Top ASNs:
AS38731 - 29670
AS14061 - 30
AS396982 - 27Top Accounts:
hello - 29712
Test - 18
Domain - 9Top ISPs:
VIETTEL - 29670
DigitalOcean, LLC - 30
Google LLC - 27Top Clients:
Unknown - 29778Top Software:
Unknown - 29778Top Keyboards:
Unknown - 29778Top IP Classification:
Unknown - 29679
hosting - 78
proxy - 12Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
⚠️ Under the #CRA, integrating a broken or insecure third-party component into your software counts as a compliance failure for your company.
Software manufacturers are legally required to exercise meticulous attention when selecting and integrating third-party components, whether they are proprietary or #OpenSource.
🌐 Read the community guidelines for executing #SoftwareDueDiligence: https://cra.orcwg.org/faq/due-diligence/
-
Uncensor any LLM with abliteration. The „easiest“ way to bypass the safety mechanisms of LLMs.
#llm #security #vulnerability #ai #ki #kuenstlicheintelligenz #secops
-
2026-07-22 RDP #Honeypot IOCs - 236 scans
Thread with top 3 features in each category and links to the full dataset
#DFIR #InfoSecTop IPs:
51.77.190.75 - 199
31.70.99.149 - 5
45.142.193.145 - 4Top ASNs:
AS16276 - 199
AS396982 - 12
AS63949 - 6Top Accounts:
hello - 207
Test - 4
07va67qh - 4Top ISPs:
OVH SAS - 199
Google LLC - 12
IONOS SE - 5Top Clients:
Unknown - 236Top Software:
Unknown - 236Top Keyboards:
Unknown - 236Top IP Classification:
hosting - 225
Unknown - 6
hosting & proxy - 5Pastebin links with full 24-hr RDP Honeypot IOC Lists:
Bad API request, invalid api_dev_key -
💭 Did you know? Your CrowdSec Security Engine already knows when something unusual is happening.
Am I Under Attack turns those signals into a simple answer, notifying you when your instance is likely facing a targeted attack—so you can investigate immediately instead of discovering it later.
Learn how to enable it 👇
https://www.crowdsec.net/blog/am-i-under-attack -
Security team in emergency mode to investigate who loaded an EICAR test file in the dev environment.
Downstairs they're holding a mime on imaginary gun possession charges.
We're expanding beyond security circus, this is security street performance
#itsecurity #secops #security -
Aww, I remember when #Cribl was just a lil thorn in #Splunk 's side.
Now look at it -- rumored to be headed for an #IPO and buying #CardinalOps to branch out into #SecOps.
They grow up so fast. 🥲
Check out my write-up of the acquisition and what it means for the ever-dizzying competitive market dynamics in #AI data management here: https://lnkd.in/g-grPEgy
-
🦅🔒 Wireshark 4.6.7 a fost lansat: Analizorul de pachete repară 12 vulnerabilități de securitate critice
Wireshark, cel mai popular și utilizat analizor de protocoale de rețea din lume, a primit o actualizare critică de securitate prin lansarea versiunii Wireshark 4.6.7. Această ediție este una de maximă importanță pentru administratorii de rețea, inginerii DevOps și experții în securitate cibernetică, deoarece adresează și repară nu mai puțin de 12 vulnerabilități care puteau pune în pericol stabilitatea și siguranța sistemelor.
Fiind un instrument care procesează pachete de date brute direct din rețea sau din fișiere de captură (pcap), Wireshark este o țintă preferată pentru atacatori, care pot folosi pachete special modificate pentru a prăbuși aplicația sau pentru a executa cod malițios.
Iată detaliile esențiale despre această lansare și de ce upgrade-ul este obligatoriu:
🔹 Repararea vulnerabilităților de tip DoS (Denial of Service):
Majoritatea celor 12 breșe de securitate rezolvate în versiunea 4.6.7 erau legate de erori de tip dissector (modulele interne care decodifică protocoalele specifice). Atacatorii puteau trimite pachete de rețea malițioase (sau puteau injecta date compromise într-un fișier de captură) pentru a declanșa bucle infinite, scurgeri de memorie (memory leaks) sau prăbușiri instantanee ale aplicației (crashes), blocând monitorizarea traficului.🔹 Protocoalele afectate și curățate:
Erorile au fost identificate și corectate într-o gamă largă de dissectoare de protocoale, de la cele utilizate în mediul enterprise până la cele din infrastructurile industriale și de telecomunicații. Printre protocoalele care au primit patch-uri critice se numără:GQUIC, HTTP/2 și TLS (pentru traficul web securizat).
Protocoale de comunicații mobile și industriale specifice.
🔹 Remedieri de bug-uri și îmbunătățirea stabilității:
Pe lângă rezolvarea problemelor stricte de securitate, Wireshark 4.6.7 aduce și o serie de corecții pentru bug-uri raportate de comunitate. Au fost optimizate funcțiile de filtrare a pachetelor (Display Filters), a fost îmbunătățită acuratețea randării grafice a fluxurilor de date și s-a asigurat o performanță mai stabilă la analizarea fișierelor de captură de mari dimensiuni (de ordinul gigabyților).🔹 Recomandare fermă de upgrade:
Deoarece Wireshark rulează adesea cu privilegii ridicate pe sistem (pentru a putea accesa direct plăcile de rețea în modul promiscuu), expunerea la aceste vulnerabilități reprezintă un risc major. Utilizatorilor de pe toate platformele (Linux, Windows, macOS) li se recomandă să facă actualizarea la versiunea 4.6.7 cât mai curând posibil prin intermediul managerelor de pachete oficiale sau descărcând kitul direct de pe site-ul oficial.#Security #Wireshark #CyberSecurity #NetworkAnalysis #SysAdmin #SecOps #TechNews #Linuxiac
-
💀 #TheGentlemen prova fins a 21 mètodes d'execució remota diferents per objectiu: PsExec, tasques programades, serveis Windows, còpia remota de fitxers, PowerShell...
Només necessita que UN tingui èxit per seguir propagant-se. Cada mètode és independent.
Abans, debilita defenses: desactiva Microsoft Defender, obre el firewall i reactiva SMBv1 insegur.
https://blog.elhacker.net/2026/07/el-ransomware-gentlemen-usa-21-tecnicas.html
-
A healthy security stack doesn't happen by accident.
Configuration issues and broken integrations can quietly reduce your visibility.
Stack Health continuously checks your CrowdSec deployment so you can spot and fix problems before they impact protection.
-
AI is reshaping cyber defense, but it’s *not* fixing burnout: 80%+ use AI, yet most security pros say the job got harder and stress is soaring. https://jpmellojr.blogspot.com/2026/07/ai-use-in-cybersecurity-is-on-rise-and.html #cybersecurity #AI #infosec #SecOps #burnout #ISSA #Omdia
-
📰 Ontinue Awarded 'Most Innovative XDR Platform' for AI-Driven Security
Ontinue's ION platform wins 'Most Innovative XDR' award for its AI-powered 'Agentic SOC' model. The solution uses agentic AI to automate threat investigation and response, tackling the 'Autonomous Threat Era'. 🏆 #XDR #AI #CyberSecurity #SecOps
🌐 cyber[.]netsecops[.]io
-
„Magst du vielleicht kurz auf die Bühne kommen damit zukünftige Arbeitgeber sehen wenn sie nicht einstellen wollen?“
@leyrer 2026Ja ich befinde mich im ÖPNV
Ja der lachflash hat Blicke ausgelöst
Nein ich bereue nichtsSelten so gut gelacht. Das lass ich Montag mal in unseen configs suchen.
https://media.ccc.de/v/gpn24-660-besser-tunneln-mit-ssh#t=2276
#gpn24 #secops-was-here-looking-for-you #netops-hates-this-simple-trick -
If you're doing #SecOps across multiple orgs with @limacharlieio (💪), you'll definitely want to learn about this: https://blog.reconinfosec.com/cross-org-visibility-for-limacharlie
(If you just want to sleep better knowing someone else is worrying about security operations, let's talk 😉)
-
New CVE? The clock starts immediately ⏱️
How do you validate impact, assess exploitability, and deploy protections fast enough?
Watch the full session 👇 https://youtube.com/live/oedE1_ycS4o
-
Ruby 4.0.5 fresh out today! Security release, bump it! https://www.ruby-lang.org/en/news/2026/05/20/ruby-4-0-5-released/ #Ruby #Programming #SecOps
-
Фишинг с подменой URI: или как один хитрый редирект может угнать ваши пароли
Всем привет! Хочу поделиться, возможно, не новым, но, на мой взгляд, довольно изощренным видом фишинга. Кто-то уже наверняка сталкивался с таким методом, а для кого-то он окажется в новинку.
-
KI - Segen und Fluch zugleich!
#satire #image #ki #ai #it #devops #secops #grafik #karikatur #alltag #zukunft #angst #fortschritt #segen #fluch #arbeitsalltag #arbeitsbedingungen
-
Most AI SecOps vendors ship a fixed platform: the architecture, the workflows, the pricing model are all decided for you.
LimaCharlie's position has always been the opposite. Build the capabilities and the value first, then give operators the freedom to modify, assemble, and build on top of them however their operation requires.
That extends all the way up the stack, from automated agents to deployable AI SOCs you define and run across thousands of tenants as infrastructure as code.
Your toolkit, built on real SecOps infrastructure.
See how it works: https://limacharlie.io/