search
InfoSec
Trends
- 1Hacker known as Rey arrested in Jordan, reported cooperation with FBI●By now, many of you may have already read the news that Saif al-Din Khader, aka “Rey” and “Hikki-Chan,” has been arreste
Saif al-Din Khader, known online as "Rey" and "Hikki-Chan," has been arrested in Jordan, according to reporting by Reuters journalists Raphael Satter, Dana Winter and Aj Vicens. Accounts in the cybersecurity community are circulating the news, saying he is allegedly cooperating with the FBI. Details about the charges remain limited so far.
- 2Meta Rushed to Fix VM Escape Flaw Before Muse Launch▼Is this related to one of our fellow Mastodonians running a server off their systems? # MetaMuse # Meta # Infosec # Tech
Meta reportedly patched a virtual machine escape vulnerability in its MetaMuse product immediately before launch, according to 404 Media reporting. A VM escape flaw would let code break out of an isolated virtual machine, a serious security risk. Users in infosec and tech communities are discussing the fix and whether it connects to a fellow Mastodon user known to run servers from their own systems.
- 3Phishing Alert Raised Over Suspicious Weebly Site▼Possible Phishing 🎣 on: ⚠️hxxps[:]//u-t-p-ac-pa[.]weebly[.]com/ 🧬 Analysis at: https:// urldna.io/scan/6ac7a2303b77500 0
Security researchers have flagged a website hosted on a Weebly subdomain as a likely phishing operation, warning users to avoid interacting with it. The site has been submitted for URL analysis, and the warning is circulating among infosec specialists who track scam infrastructure. The defanged link format suggests researchers are deliberately limiting accidental clicks while sharing indicators with the wider security community.
- 4Chrome extension for migrating Goodreads to StoryGraph flagged as malicious●# chrome extension Goodreads to StoryGraph - CSV Migrate seems malicious. Its # cybersecurity badness score is 100/100!
A Chrome extension called Goodreads to StoryGraph - CSV Migrate, used to move reading data between the two book-tracking platforms, has been flagged as malicious with a perfect 100/100 badness score in automated cybersecurity analysis. Security watchers are warning users to uninstall it and avoid granting it browser permissions while the finding circulates among infosec communities.
- 5Fediverse users asked for advice on studying US law●Hi # Fediverse # lawyers . What is your advice/recommendations (classes? certifications?) for a non-lawyer who wants to
A user asked lawyers on the Fediverse for recommendations on how a non-lawyer can gain practical knowledge of US and state law, including classes or certifications. The question drew engagement from the infosec community and touched on self-education in legal matters.
- 6Man posing as cybersecurity engineer exposed for doxxing women●This self-described "cybersecurity engineer" managed to trick women into providing their personal info, which he then po
A self-described cybersecurity engineer has been arrested after tricking women into handing over personal information, which he then published online. The case is drawing attention in information security circles, with commenters noting that a booking photo released last week is hardly the image the profession wants, and highlighting the harm caused by online harassment and data misuse against women.
- 7GrapheneOS adds Secure Paste to block clipboard snooping●RE: https:// infosec.exchange/@lacze/117332 720535130953 System GrapheneOS otrzymał nową funkcję, która uniemożliwia apl
GrapheneOS, the privacy-focused Android operating system, has rolled out a new feature called Secure Paste, which prevents apps from reading the contents of the clipboard. The system now lets users approve pasting on a per-app basis, blocking apps from silently harvesting clipboard data. The change is described as a significant security improvement, and it has drawn attention in the privacy and infosec community, where users welcome tighter control over what apps can access.
- 8Security Researchers Flag Suspected Phishing Site on Framer▼Possible Phishing 🎣 on: ⚠️hxxps[:]//able-lily-193337[.]framer[.]app 🧬 Analysis at: https:// urldna.io/scan/6ac7317d3b775
Cybersecurity watchers are warning about a suspected phishing page hosted on a Framer.app subdomain, sharing the masked link and a technical analysis via the URLDNA scanning service. The alert circulates among infosec professionals, who use defanged links to prevent accidental clicks. Hosted phishing pages on legitimate website builders remain a common tactic because the domains often pass basic reputation checks.
- 9Security researchers flag fake Coinbase phishing domain▼Possible Phishing 🎣 on: ⚠️hxxps[:]//392847-coinbase[.]com 🧬 Analysis at: https:// urldna.io/scan/6ac867093b77500 0057b85
Cybersecurity specialists have identified a fraudulent domain impersonating Coinbase, the major cryptocurrency exchange, designed to trick users into handing over login credentials. The domain is defanged to prevent accidental visits, and a technical analysis of the site has been published for other researchers. The alert circulated among infosec communities monitoring phishing and scam activity.
- 10SEC-T conference badge powers on with a safety pin●The SEC-T badge this year was so cool! Instead of turning on with a switch, closing the safety pin on the back is what l
Attendees at the SEC-T security conference are praising this year's attendee badge, which lights up when a safety pin on its back is closed rather than using a power switch. The clever hardware design has drawn delighted reactions from the infosec community, with hackers sharing the inventive touch online.
- 11Bubble Share app to add NFC pairing for file sharing●RE: https:// infosec.exchange/@S1m/11731094 6301924196 Next version of Bubble Share will be able to use NFC to do the pa
A developer of the Bubble Share file-sharing app says the next version will use NFC for device pairing instead of checking a PIN. The change would let users receive files without opening the app and support devices that lack other protocols. The developer called the approach more fun than PIN verification.
- 12Security Researchers Flag Possible Phishing Site on GoDaddy●Possible Phishing 🎣 on: ⚠️hxxps[:]//e7d6055ce047[.]godaddysites[.]com 🧬 Analysis at: https:// urldna.io/scan/6ac844633b7
Cybersecurity observers are warning about a possible phishing website hosted on a GoDaddy Sites domain, sharing the address in defanged form so readers cannot accidentally click it. A technical scan of the page has been published on the URL analysis service urlDNA for others to inspect. Such warnings circulate quickly among information security professionals tracking new scam infrastructure.
- 13Security researcher flags possible phishing site tgxnh.com▼Possible Phishing 🎣 on: ⚠️hxxp[:]//tgxnh[.]com 🧬 Analysis at: https:// urldna.io/scan/6ac723843b77500 005524155 # cybers
A cybersecurity researcher has flagged the website tgxnh.com as a possible phishing domain, sharing an automated analysis of the URL on the UrlDNA scanning platform. The warning, circulated with defanged link formatting to prevent accidental clicks, has drawn attention from the infosec community. Details about the site's infrastructure or specific victims have not been disclosed.
- 14Security researchers flag possible phishing site on Weebly▼Possible Phishing 🎣 on: ⚠️hxxps[:]//twfrfh[.]weebly[.]com 🧬 Analysis at: https:// urldna.io/scan/6ac73fa83b77500 0073113
Cybersecurity observers are warning about a possible phishing site hosted on a Weebly subdomain, sharing the address in defused form and linking to a public URL analysis for inspection. The alert circulated among infosec accounts, who urged others to avoid the link. Little is known about who is behind the site or what it impersonates, and Weebly has not commented. The warning serves as a reminder that free website builders are often abused for phishing campaigns.
- 15Security researchers flag voice message phishing page▼Possible Phishing 🎣 on: ⚠️hxxps[:]//voicemessage-memo[.]pages[.]dev/?error=login_required 🧬 Analysis at: https:// urldna
A fraudulent website posing as a voicemail message service is circulating, designed to trick users into entering login credentials. The page is hosted on a Google Pages subdomain to appear legitimate. Cybersecurity analysts have published a technical scan of the URL, warning others in the infosec community to block it and watch for similar credential-harvesting campaigns.
- 16ChainKeep targets timestamp tracking in digital investigations▼Every second matters in an investigation. ChainKeep makes sure every one of them is accounted for. ⏳ # ChainKeep # InfoS
ChainKeep, a tool aimed at digital forensics and incident response professionals, is being promoted with the message that every second matters in an investigation and that the software ensures every timestamp is accounted for. The pitch highlights chain-of-custody concerns in cybersecurity investigations, where accurate time records can determine whether evidence holds up. Discussion so far appears limited to infosec circles.
- 17Security Researchers Flag New Phishing Site Hosted on Cloud Storage▼Possible Phishing 🎣 on: ⚠️hxxps[:]//pub-98040ea363724ccebacba31c3ad69f60[.]r2[.]dev/index[.]html 🧬 Analysis at: https://
Cybersecurity researchers are warning of a suspected phishing page hosted on a Cloudflare R2 storage subdomain, sharing the address in defanged form so readers do not accidentally visit it. A link to an automated URL analysis service was included so others can inspect the page's behaviour. The alert circulated among infosec practitioners, who commonly share such indicators to help block and track new scam infrastructure.
- 18Comparing Ireland's MyGovID with Denmark's CPR ID system●RE: https:// infosec.exchange/@cyberseckyle /117389340967928437 "Ireland's MyGovID and Denmark's CPR: A comparative anal
A cybersecurity commentator has published a comparative analysis of Ireland's MyGovID and Denmark's CPR personal identifier systems, examining how the two countries handle digital identity. The piece touches on age verification, digital rights, GDPR and data protection, prompting discussion among privacy and security professionals about how national ID schemes balance convenience against citizen data risks.
- 19Security Analysts Flag Suspected Phishing Site on Sugumail▼Possible Phishing 🎣 on: ⚠️hxxps[:]//m[.]sugumail[.]com/m/boj/mail-user/entry/qgcth4c5v3ym5xqgcth4c5v3ym5xqgct 🧬 Analysis
Cybersecurity researchers are warning about a suspected phishing page hosted on sugumail.com, a webmail service. The alert was shared with a defanged link and an automated URL analysis scan on the platform URLDNA, which examines sites for malicious behavior. The warning circulated among infosec communities tagged under phishing, scam, and cybersecurity. No victims or specific campaign details have been reported so far.
- 20Fake HSBC domain flagged as phishing site▼Possible Phishing 🎣 on: ⚠️hxxps[:]//hsbc-sec[.]com 🧬 Analysis at: https:// urldna.io/scan/6ac696e63b77500 009319118 # cy
Security researchers are warning about a suspected phishing domain impersonating HSBC, registered at hsbc-sec.com. The suspicious site was shared with a defanged link so others would not accidentally visit it, and an analysis has been published on the URLDNA scanning service. Infosec communities on Mastodon are circulating the warning with tags for phishing, scams and cybersecurity.
- 2116-Year-Old Ransomware Kingpin Tops a Rough Week in Cybersecurity●A 16-Year-Old Ransomware Kingpin, FBI Patch Fails, and Leaked Pentagon Records: Another Bad Week in Infosec
A weekly roundup from PCMag highlights a turbulent stretch for information security. The report covers the alleged unmasking of a 16-year-old ransomware gang leader, an FBI security patch that reportedly failed to work as intended, and the leak of sensitive Pentagon records. Together, the stories underscore how both young criminal actors and institutional missteps are straining cybersecurity defenses across government and industry.
- 22Security researchers flag nycenergy.info as possible phishing site▼Possible Phishing 🎣 on: ⚠️hxxps[:]//nycenergy[.]info 🧬 Analysis at: https:// urldna.io/scan/6ac6744b3b77500 005c4592e #
Cybersecurity observers are warning about a suspected phishing website at nycenergy.info, sharing a technical analysis of the domain via the URLdna scanning service. The alert, circulating in infosec communities, urges people to avoid interacting with the site. No details on the campaign's targets or scale have been confirmed yet.
- 23Fake Facebook Blogspot Link Flagged as Phishing▼Possible Phishing 🎣 on: ⚠️hxxp[:]//www[.]faceb0k-facebook[.]blogspot[.]com/ 🧬 Analysis at: https:// urldna.io/scan/6ac5a
Cybersecurity researchers are warning about a phishing site impersonating Facebook at a lookalike blogspot address that swaps characters in the domain to trick users. The link is being shared in defanged form so people cannot click it accidentally, and a full technical analysis has been published on URLDNA showing the site's characteristics. The warning circulates among infosec communities as a reminder to check domain spelling before entering login credentials.
- 24Security researchers flag fake Facebook phishing page▼Possible Phishing 🎣 on: ⚠️hxxps[:]//facebookbigeronline[.]blogspot[.]com/?m=1 🧬 Analysis at: https:// urldna.io/scan/6ac
Cybersecurity observers are warning about a suspected phishing site hosted on a Blogspot address impersonating Facebook, with the domain name combining "facebook" and "bigeronline". The malicious link has been defanged and shared alongside a URL analysis report so others can inspect it. The alert circulates in infosec communities, where users are urging caution against similar fake login pages.
- 25New ransomware group Bavacai publishes post titled Balaqah▼🚨New ransom group blog post!🚨 Group name: Bavacai Post title: BALAQAH Info: https:// cti.fyi/groups/Bavacai.html # ranso
Cybersecurity researchers are tracking a new ransomware group calling itself Bavacai, which has published a blog post titled 'Balaqah' on its leak site. Threat intelligence monitors flagged the activity, and a tracking page with details on the group has been made available to the infosec community. Details about the group's victims and operations remain limited while analysts assess the new threat.
- 26Security Researchers Flag Suspected Phishing Site on Wix▼Possible Phishing 🎣 on: ⚠️hxxps[:]//caitlinstrategyfir[.]wixsite[.]com/outreachmesagin 🧬 Analysis at: https:// urldna.io
Cybersecurity observers are warning about a suspected phishing page hosted on a Wix domain masquerading as a strategy firm outreach message. The warning, shared with the wider infosec community, includes a link to an analysis of the site on the URLDNA scanning platform, which breaks down the page's infrastructure and behavior. Users are advised to avoid the link and verify unsolicited outreach before responding.
- 27SilentRansomGroup emerges as new ransomware threat▼🚨New ransom group blog post!🚨 Group name: SilentRansomGroup Post title: A...n Sector: Unknown Info: https:// cti.fyi/gro
A new ransomware group calling itself SilentRansomGroup has been profiled in a fresh threat intelligence write-up. The post lists the group's name and activity but leaves its targeted sector unknown, and details remain limited. Cybersecurity researchers are circulating the alert among threat intelligence and infosec communities as they track the group's emergence.
- 28Cybersecurity Researchers Flag Phishing Site on Google Pages●Possible Phishing 🎣 on: ⚠️hxxps[:]//sites[.]google[.]com/view/qsqqqy/home 🧬 Analysis at: https:// urldna.io/scan/6ac6b31
Security researchers have identified a suspected phishing website hosted on a Google Sites page, sharing the address in defanged form so others cannot accidentally click it. A scan of the page has been published on URLDNA for analysis. The warning circulates within the infosec community, which regularly exchanges such alerts to help defenders block malicious pages and alert potential victims quickly.
- 29Moderate authentication bypass flaw disclosed in Red Hat maestro gRPC broker▼CVE-2026-71297 is a moderate authentication bypass in the maestro gRPC broker used by Red Hat Advanced Cluster Managemen
CVE-2026-71297 describes a moderate authentication bypass in the maestro gRPC broker used by Red Hat Advanced Cluster Management and the Multicluster Engine. An attacker holding a valid client certificate could read other consumers' event streams or forge agent status reports. Security trackers and infosec communities are circulating the disclosure, with no confirmed exploitation reported so far.
- 30Developer seeks feedback on age-rt low-latency encryption▼age-rt: seeking feedback on low-latency, variable-chunk, age-like encryption https:// infosec.pub/post/53217267
A developer is asking the security community for feedback on age-rt, an encryption design inspired by the age file encryption format but built for low-latency streaming with variable chunk sizes. The proposal is being shared on Infosec Exchange, with discussion expected to focus on whether the design is sound and how it might fit real-time use cases.
- 31Security researchers flag possible phishing via Google Forms link▼Possible Phishing 🎣 on: ⚠️hxxps[:]//docs[.]google[.]com/forms/d/e/1FAIpQLSdG7yXu_ZDhf6QvaUs82ZmhpdKddCu-go7ASE_KaMFLVqwe
Cybersecurity analysts are warning about a possible phishing campaign hosted through a Google Forms link. The alert, shared on the social platform Mastodon, defuses the link and points to an automated URL analysis service so others can inspect the page before interacting with it. The warning is being circulated under phishing and infosec tags among the security community.
- 32OVH ASN flagged in cybersecurity watch update●ASN: AS16276 Location: Vaudreuil-Dorion, CA Added: 2026-10-02T17:20 # shodansafari # infosec
Autonomous system AS16276, the network range operated by French hosting provider OVHcloud, was added to a cybersecurity tracking log on 2 October 2026 with a listed location of Vaudreuil-Dorion, Canada. The entry circulated among infosec observers who follow hosting infrastructure. No further details about the reason for the addition were given.
- 33Security researcher flags possible phishing site on Gitbook●Possible Phishing 🎣 on: ⚠️hxxps[:]//kuconlegen[.]gitbook[.]io 🧬 Analysis at: https:// urldna.io/scan/6ac83ca23b77500 004
A cybersecurity account on Mastodon is warning of a possible phishing page hosted on a Gitbook subdomain, kuconlegen.gitbook.io. The link has been defanged and a technical analysis of the URL has been published on the urlscan service UrlDNA. The Gitbook domain is commonly abused by scammers because it lets anyone host free pages that look legitimate. Users are advised to be cautious with unfamiliar links.
- 34Security researcher flags fake Facebook phishing site in Kazakhstan●Possible Phishing 🎣 on: ⚠️hxxps[:]//facebook[.]meweb[.]kz 🧬 Analysis at: https:// urldna.io/scan/6ac812903b77500 0063100
Cybersecurity observers are warning about a fraudulent website, facebook.meweb.kz, that imitates Facebook and is suspected of being used for phishing. The site's domain is registered in Kazakhstan, and a technical analysis of the URL has been published so that others can inspect it and avoid falling victim. Alerts like this circulate regularly in infosec communities to help people spot scam pages that harvest login credentials.
- 35New server entry appears in Shodan index in Falkenstein, Germany●ASN: AS24940 Location: Falkenstein, DE Added: 2026-10-02T17:16 # shodansafari # infosec
A newly indexed server assigned to autonomous system AS24940, hosted in Falkenstein, Germany, was logged on 2 October 2026 and flagged with cybersecurity hashtags. AS24940 is the network of German hosting provider Hetzner, and Falkenstein is home to one of its data centres. The entry is being shared among information security watchers who track newly exposed systems in Shodan's internet-wide scans.
- 36Infosec researchers probe Swedish network AS44034●ASN: AS44034 Location: Stenkullen, SE Added: 2026-09-29T20:50 # shodansafari # infosec
Cybersecurity researchers are highlighting AS44034, an autonomous system registered in Stenkullen, Sweden, as part of an ongoing network-mapping exercise in the information security community. The ASN was added to a tracking list on 29 September 2026, prompting discussion among professionals who scan and catalogue internet-exposed infrastructure using Shodan data.
- 37Actor 'BYOD' claims breach tied to Liberty X ransomware●🛡 THREAT INTEL | Some semi-samples Of Liberty X TMO cause we got yappatrons on twitter 🟢 Actor "BYOD" claims Undisclosed
A threat actor using the name 'BYOD' has posted an undisclosed claim of a compromise apparently linked to Liberty X and TMO, with partial samples circulated among dark-web watchers. Security sources flag the claim as unverified, and analysts on infosec forums are debating its credibility while awaiting confirmation from the named organisations.
- 38Infosec newcomer introduces themselves on Mastodon▼Hello Mastodon! I'm into Computer # Security , # Programming , # ReverseEngineering , # Hacking , # Linux , # AmateurRad
A newcomer has introduced themselves to Mastodon's infosec community, listing interests including computer security, programming, reverse engineering, hacking, Linux, cryptography, privacy, open source and amateur radio, with a focus on technology that helps people communicate. The post is drawing modest engagement from the security-focused corner of the decentralized social network.
- 39Security Researchers Flag New Phishing Site●Possible Phishing 🎣 on: ⚠️hxxps[:]//free-5285816[.]webadorsite[.]com 🧬 Analysis at: https:// urldna.io/scan/6ac84aa93b77
Cybersecurity observers are warning about a suspected phishing website hosted on a free Webador subdomain. The site's address has been deliberately defused to prevent accidental clicks, and a link to a URLdna scan was shared so others can inspect hosting and content details. The warning circulates in infosec communities, where members routinely swap indicators of new scam pages targeting credentials or personal data.
- 40Flock camera filesystem leak sparks reversing guide●Heard about the Flock camera filesystem leak and wanted to take a peek for yourself? I took a quick look and decided to
A leak of Flock Safety camera filesystem data has drawn attention from security researchers. Following reports of issues such as hardcoded API keys in the devices, one researcher has published a beginner-friendly guide to reverse-engineering the camera's Android firmware so others can verify the findings themselves. The story is spreading among the infosec community, where Flock's surveillance network is already a contested topic.