Sorry to disappoint, but there will be no IFIN Threat Actor Taxonomy. Here's why:
Профиль
IFIN
Профиль VivelyThe Independent Federated Intelligence Network. Our mission: Empower organizations to independently collect, analyze, and disseminate relevant cyber threat intelligence through training, open source tools, and a decentralized intelligence sharing network.
New packages are still being discovered with malicious payloads. Package adoption remains disabled.
IFINYet another attack against the Arch User Repository is underway. We are monitoring and analyzing the malware samples. discourse.ifin.netwo... #ThreatIntel #ThreatIntelligence #IFIN
Yet another attack against the Arch User Repository is underway. We are monitoring and analyzing the malware samples. discourse.ifin.netwo... #ThreatIntel #ThreatIntelligence #IFIN
We've compiled the latest information regarding the Minnesota water systems attacks. discourse.ifin.netwo... #ThreatIntel #ThreatIntelligence #IFIN
We caught a sample of ACR Stealer and went deep on it. Lots of sophistication for "just" an infostealer. discourse.ifin.netwo... #ThreatIntel #ThreatIntelligence #IFIN
We continue to use our own RSS-Filter project to curate our feed aggregator. We've removed "Startups" from the other-wise excellent TechCrunch security news feed to keep the feed relevant and actionable. Our Newsfeed: news.ifin.network
Following up on a Fediverse tip, we found a new use for fake software download sites: the referral program hustle. Mirror FOSS, get cash. There are almost certainly more of these out there. discourse.ifin.netwo... #ThreatIntel #ThreatIntelligence #IFIN
Fantastic research by our community here on a continuing Lua-based campaign that uses Prometheus obfuscation and our old friend Etherhiding for C2 configuration acquisition. discourse.ifin.netwo... #ThreatIntel #ThreatIntelligence #IFIN
The critical SharePoint vulnerability CVE-2026-50522 now appears to be under massive exploitation. We have context and current IOCs in this post. We've also updated the MISP feed with the same. #ThreatIntel #ThreatIntelligence #IFIN
With confirmed exploit sources, we've now added this one to our MISP feed. discourse.ifin.netwo... #ThreatIntel #ThreatIntelligence #IFIN
If you pirate games, you should expect malware. That's a tale as old as 1970-01-01T00:00:00.000Z. But using Etherhiding as the second stage source? Well that's slightly newer. discourse.ifin.netwo... #ThreatIntel #ThreatIntelligence #IFIN
This has been confirmed exploited in the wild. Updated with IoCS.
IFINApparently (?) there's a Pre-Auth RCE (!) in core WordPress (?!), but there are extremely few details as yet. If it's as gnarly as it sounds, a lot of sites are going to have a very bad time. We'll keep this story updated as details emerge.
Apparently (?) there's a Pre-Auth RCE (!) in core WordPress (?!), but there are extremely few details as yet. If it's as gnarly as it sounds, a lot of sites are going to have a very bad time. We'll keep this story updated as details emerge.
UPDATE: We've tracked this down to Copilot Chat's "Enable AI Feature" setting.
IFINCursor will run anything called git.exe when you open it, but it isn't the only one. As a fork of VS Code, Cursor has inherited this behavior from its questionable parentage.
Cursor will run anything called git.exe when you open it, but it isn't the only one. As a fork of VS Code, Cursor has inherited this behavior from its questionable parentage.
The latest supply chain attack has some novelty, but the techniques should have long been mitigated in your network. IPFS, cryptocurrency, and Nostr have no place in a professional network. discourse.ifin.netwo... #ThreatIntel #ThreatIntelligence #IFIN
Are you using jscrambler to obfuscate your JS code? Forget scrambling—depending on version, you might be cooked a different way. discourse.ifin.netwo... #ThreatIntel #ThreatIntelligence #IFIN
We regret to inform you that yes, the models continue to produce kernel exploits leading to privilege escalation and container escapes. This one is part of a two-vuln chain with a public PoC that escapes Firefox and roots the host.
We need to talk about AWS S3 abuse and anti-patterns. Loose association between brands and buckets leads to easy prey for spoofers and squatters.