Подтвердите e-mail

Для публикаций, комментариев, реакций и сообщений подтвердите адрес.

Профиль

IFIN

Профиль Vively

The Independent Federated Intelligence Network. Our mission: Empower organizations to independently collect, analyze, and disseminate relevant cyber threat intelligence through training, open source tools, and a decentralized intelligence sharing network.

New packages are still being discovered with malicious payloads. Package adoption remains disabled.

IFIN

Yet another attack against the Arch User Repository is underway. We are monitoring and analyzing the malware samples. discourse.ifin.netwo... #ThreatIntel #ThreatIntelligence #IFIN

031

Yet another attack against the Arch User Repository is underway. We are monitoring and analyzing the malware samples. discourse.ifin.netwo... #ThreatIntel #ThreatIntelligence #IFIN

New AUR Attack Prompts Adoption LockLast Updated: 2026-07-30T19:59:19Z (UTC) What’s Happening A new round of Arch User Repository malware has prompted the disabling of package adoption. The first package with confirmed malware appears to be openconnect-sso. User ysf has performed initial analysis of the payloads. Stage 1: AUR validator.malware (stage 1) · GitHub Stage 2: AUR validator.malware (stage2 agent linux x86_64) · GitHub Interestingly, many of the behaviors (especially Tor exfil) look similar to the last campaig...discourse.ifin.network
153

We've compiled the latest information regarding the Minnesota water systems attacks. discourse.ifin.netwo... #ThreatIntel #ThreatIntelligence #IFIN

Minnesota water system suffers a breach due to exposed access keysLast Updated: 2026-07-30T00:16:10Z (UTC) What’s Happening On July 27, 2026, threat actors exploited a known vulnerability on a Rockwell Automation device and disrupted water treatment facilities in four counties in Minnesota, US. This activity is consistent with prior activity with Iran-aligned actors under the guise of “CyberAv3ngers,” although no direct evidence has yet emerged tying this activity to that group or any other. Actions The CVE used for initial access is CVE-2021-22681. This ...discourse.ifin.network
021

We caught a sample of ACR Stealer and went deep on it. Lots of sophistication for "just" an infostealer. discourse.ifin.netwo... #ThreatIntel #ThreatIntelligence #IFIN

ACR Stealer: ClickFix, Etherhiding, and Stego, Oh My!Last Updated: 2026-07-29T21:28:50Z (UTC) What’s Happening Earlier this month, Microsoft reported on ACR Stealer, a new campaign leveraging both Steganography and Etherhiding techniques for delivery. Yesterday, I caught myself a sample. Mine doesn’t have Etherhiding, but the rest makes for a fun exploration anyhow. Let’s dive in. ▶ Recommended Musical Accompaniment Disclaimer: A LLM assisted with deobfuscation/decryption of later stages. Stage 1: Initial Access via ClickFix While the infect...discourse.ifin.network
044

There are security patches available for Discourse so the forum will go down shortly for updates. Be back soon!

120

We continue to use our own RSS-Filter project to curate our feed aggregator. We've removed "Startups" from the other-wise excellent TechCrunch security news feed to keep the feed relevant and actionable. Our Newsfeed: news.ifin.network

131

Following up on a Fediverse tip, we found a new use for fake software download sites: the referral program hustle. Mirror FOSS, get cash. There are almost certainly more of these out there. discourse.ifin.netwo... #ThreatIntel #ThreatIntelligence #IFIN

PDF Arranger and TeraBox Referrals: Lamer Than MalwareLast Updated: 2026-07-24T18:46:25Z (UTC) What’s Happening PDF Arranger, a legitimate FOSS application, has picked up a fake download site at pdfarranger[.]net. We’ve seen instances before of fake installer sites. Usually the payload is directly observable. Not so in this case. In fact, the hashes for the downloaded files match what’s on GitHub. So what’s the catch? The linked downloads files are hosted on TeraBox, a “legitimate” Japan-based file hosting/sharing service that offers 1T...discourse.ifin.network
132

Fantastic research by our community here on a continuing Lua-based campaign that uses Prometheus obfuscation and our old friend Etherhiding for C2 configuration acquisition. discourse.ifin.netwo... #ThreatIntel #ThreatIntelligence #IFIN

LuaJIT Loader Uses Prometheus Obfuscation and EtherhidingLast Updated: 2026-07-23T17:18:49Z (UTC) What’s Happening I spent quite a bit of time investigating and reversing a malware sample I found in the wild. The initial malware sample, which I’ll explain in depth below, caught my attention because of the usage of a Lua obfuscator that I could not find a publicly available deobfuscator for. I am relatively new to malware reverse engineering and, with full disclosure, a lot of the work done here was with the assistance of AI. Late into the investig...discourse.ifin.network
042

The critical SharePoint vulnerability CVE-2026-50522 now appears to be under massive exploitation. We have context and current IOCs in this post. We've also updated the MISP feed with the same. #ThreatIntel #ThreatIntelligence #IFIN

Microsoft SharePoint CVE-2026-50522Last Updated: 2026-07-23T15:22:41Z (UTC) What’s Happening Microsoft SharePoint Remote Code Execution Vulnerability CVE-2026-50522 is actively exploited in the wild since 2026-07-17T00:00:00Z (UTC). This is an unauthenticated deserialisation vulnerability. A public proof-of-concept has been available since 2026-07-20T05:53:56Z (UTC). A patch is available since 2026-07-14T00:00:00Z (UTC) (Patch Tuesday). Actions Update Microsoft SharePoint to a patched version or limit external access until a...discourse.ifin.network
031

With confirmed exploit sources, we've now added this one to our MISP feed. discourse.ifin.netwo... #ThreatIntel #ThreatIntelligence #IFIN

Microsoft SharePoint CVE-2026-50522CTI from the raw TLP:CLEAR sources. Everything related to a time between 2026-07-19 and 2026-07-22. Indicator Indicator type Comments 45.63.58.216 ipv4-addr Exploit source IPv4. AS20473 Vultr 103.114.161.6 ipv4-addr Exploit source IPv4. AS142036 Hosteons Pte. Ltd. 146.19.216.119 ipv4-addr Exploit source IPv4. AS134677 Dromatics Systems Pte Ltd. 77.110.123.40 ipv4-addr Exploit source IPv4 and callback IPv4. AS203273 NetCrafters OU 149.102.254.84 ipv4-addr Exploit source IPv4. AS2...discourse.ifin.network
121

If you pirate games, you should expect malware. That's a tale as old as 1970-01-01T00:00:00.000Z. But using Etherhiding as the second stage source? Well that's slightly newer. discourse.ifin.netwo... #ThreatIntel #ThreatIntelligence #IFIN

Pirated Games Come with a Side of Amatera StealerLast Updated: 2026-07-20T16:00:07Z (UTC) What’s Happening Malwarebytes is reporting on a new infostealer campaign using pirated games (shocker) as a watering hole. What’s notable about this campaign is the continued use of Etherhiding for second-stage loading. We’re going to be talking a lot about Etherhiding in the next couple of weeks. Some other fun malware analysis in the post as well for those interested. Actions Don’t pirate games! Don’t let your employees pirate games! Pro tip: if y...discourse.ifin.network
132

This has been confirmed exploited in the wild. Updated with IoCS.

IFIN

Apparently (?) there's a Pre-Auth RCE (!) in core WordPress (?!), but there are extremely few details as yet. If it's as gnarly as it sounds, a lot of sites are going to have a very bad time. We'll keep this story updated as details emerge.

11110

Apparently (?) there's a Pre-Auth RCE (!) in core WordPress (?!), but there are extremely few details as yet. If it's as gnarly as it sounds, a lot of sites are going to have a very bad time. We'll keep this story updated as details emerge.

WP2Shell: Pre-Auth RCE in WordPress (No CVE)CVSSv3: N/A This is mostly a placeholder as the hype site has no details. But the claim is: Searchlight Cyber’s security research team has discovered a pre-authentication RCE in WordPress Core. The attack has no preconditions and can be exploited by an anonymous user in a stock install of WordPress with no plugins. Affected Versions Version Status < 6.9.0 not affected 6.9.0 - 6.9.4 affected, fixed in 6.9.5 7.0.0 - 7.0.1 affected, fixed in 7.0.2 Actions Update to the fixe...discourse.ifin.network
2114

UPDATE: We've tracked this down to Copilot Chat's "Enable AI Feature" setting.

IFIN

Cursor will run anything called git.exe when you open it, but it isn't the only one. As a fork of VS Code, Cursor has inherited this behavior from its questionable parentage.

010

Cursor will run anything called git.exe when you open it, but it isn't the only one. As a fork of VS Code, Cursor has inherited this behavior from its questionable parentage.

Remember that Cursor git.exe bug? It's in VSCode tooCVSSv3: 7.5 The Cursor Bug is in VSCode Earlier this week, a potential vulnerability was discovered in Cursor, the AI-enabled development platform that is a fork of VSCode. This vulnerability is a file called get.exe in the root of a repo or any project folder will be automatically executed without user interaction. That was viewed as a potential flaw in the software, but apparently Cursor was told about it in December and has really had no response at all to it. Fast forward to today, when I...discourse.ifin.network
075

The latest supply chain attack has some novelty, but the techniques should have long been mitigated in your network. IPFS, cryptocurrency, and Nostr have no place in a professional network. discourse.ifin.netwo... #ThreatIntel #ThreatIntelligence #IFIN

Latest Miasma Attack Uses Blockchain Garbage You Should Have Already BlockedLast Updated: 2026-07-14T22:16:54Z (UTC) What’s Happening I was trying to come up with a framing for this story other than “Oh look another supply chain attack, whoopty-doo.” But yeah, asyncapi packages were hit today. Actions Of course you want to do the usual package checks, rotations, say three Hail Marys, turn around three times and throw salt over your shoulder. But also, this payload presents some good reminders about goofy attacker techniques that should not survive a mature netwo...discourse.ifin.network
053

Are you using jscrambler to obfuscate your JS code? Forget scrambling—depending on version, you might be cooked a different way. discourse.ifin.netwo... #ThreatIntel #ThreatIntelligence #IFIN

Popular JS Obfuscator jscrambler CompromisedLast Updated: 2026-07-12T12:51:42Z (UTC) What’s Happening jscrambler, a popular JavaScript obfuscation library, has been compromised with stealer malware. Socket reports that the compromised versions begin with 8.14. The malware seeks common secret-containing files, including cryptocurrency wallets, SSH key libraries, AI configuration folders, cloud configuration folders, and even Steam configs. All detected compromised version: 8.14 8.16 8.17 8.18 8.20 Those are not typos. 8.15 and 8.19 ...discourse.ifin.network
042

We regret to inform you that yes, the models continue to produce kernel exploits leading to privilege escalation and container escapes. This one is part of a two-vuln chain with a public PoC that escapes Firefox and roots the host.

CVE-2026-43499: GhostLock, Yet Another Linux LPE/Container EscapeLast Updated: 2026-07-09T20:49:44Z (UTC) CVSSv3: 7.8 What’s Happening Nebula Security has disclosed “GhostLock,” another Linux kernel exploit leading to local privilege escalation and container escape. This one was found by their VEGA vuln research AI model. GhostLock affects Linux kernel versions from 2.6.39 to 7.1. Patches are being backported by distributions. This vulnerability is the second part of a two-part attack chain which Nebula calls “IonStack.” The first part was CVE-2026-1070...discourse.ifin.network
120

We need to talk about AWS S3 abuse and anti-patterns. Loose association between brands and buckets leads to easy prey for spoofers and squatters.

Why Is an S3 URL Used Like a Domain? | IFINS3 URLs are a pervasive anti-pattern across the enterprise landscape.ifin-intel.org
153
Показать ещё