search
InfoSec
Trends
- 1Hacker known as Rey arrested in Jordan, reported cooperation with FBI●By now, many of you may have already read the news that Saif al-Din Khader, aka “Rey” and “Hikki-Chan,” has been arreste
Saif al-Din Khader, known online as "Rey" and "Hikki-Chan," has been arrested in Jordan, according to reporting by Reuters journalists Raphael Satter, Dana Winter and Aj Vicens. Accounts in the cybersecurity community are circulating the news, saying he is allegedly cooperating with the FBI. Details about the charges remain limited so far.
- 2Meta Rushed to Fix VM Escape Flaw Before Muse Launch▼Is this related to one of our fellow Mastodonians running a server off their systems? # MetaMuse # Meta # Infosec # Tech
Meta reportedly patched a virtual machine escape vulnerability in its MetaMuse product immediately before launch, according to 404 Media reporting. A VM escape flaw would let code break out of an isolated virtual machine, a serious security risk. Users in infosec and tech communities are discussing the fix and whether it connects to a fellow Mastodon user known to run servers from their own systems.
- 3SEC-T conference badge powers on with a safety pin●The SEC-T badge this year was so cool! Instead of turning on with a switch, closing the safety pin on the back is what l
Attendees at the SEC-T security conference are praising this year's attendee badge, which lights up when a safety pin on its back is closed rather than using a power switch. The clever hardware design has drawn delighted reactions from the infosec community, with hackers sharing the inventive touch online.
- 4GrapheneOS adds Secure Paste to block clipboard snooping●RE: https:// infosec.exchange/@lacze/117332 720535130953 System GrapheneOS otrzymał nową funkcję, która uniemożliwia apl
GrapheneOS, the privacy-focused Android operating system, has rolled out a new feature called Secure Paste, which prevents apps from reading the contents of the clipboard. The system now lets users approve pasting on a per-app basis, blocking apps from silently harvesting clipboard data. The change is described as a significant security improvement, and it has drawn attention in the privacy and infosec community, where users welcome tighter control over what apps can access.
- 5Fediverse users asked for advice on studying US law●Hi # Fediverse # lawyers . What is your advice/recommendations (classes? certifications?) for a non-lawyer who wants to
A user asked lawyers on the Fediverse for recommendations on how a non-lawyer can gain practical knowledge of US and state law, including classes or certifications. The question drew engagement from the infosec community and touched on self-education in legal matters.
- 6ChainKeep targets timestamp tracking in digital investigations▼Every second matters in an investigation. ChainKeep makes sure every one of them is accounted for. ⏳ # ChainKeep # InfoS
ChainKeep, a tool aimed at digital forensics and incident response professionals, is being promoted with the message that every second matters in an investigation and that the software ensures every timestamp is accounted for. The pitch highlights chain-of-custody concerns in cybersecurity investigations, where accurate time records can determine whether evidence holds up. Discussion so far appears limited to infosec circles.
- 7Man posing as cybersecurity engineer exposed for doxxing women●This self-described "cybersecurity engineer" managed to trick women into providing their personal info, which he then po
A self-described cybersecurity engineer has been arrested after tricking women into handing over personal information, which he then published online. The case is drawing attention in information security circles, with commenters noting that a booking photo released last week is hardly the image the profession wants, and highlighting the harm caused by online harassment and data misuse against women.
- 8Infosec newcomer introduces themselves on Mastodon▼Hello Mastodon! I'm into Computer # Security , # Programming , # ReverseEngineering , # Hacking , # Linux , # AmateurRad
A newcomer has introduced themselves to Mastodon's infosec community, listing interests including computer security, programming, reverse engineering, hacking, Linux, cryptography, privacy, open source and amateur radio, with a focus on technology that helps people communicate. The post is drawing modest engagement from the security-focused corner of the decentralized social network.
- 9Comparing Ireland's MyGovID with Denmark's CPR ID system●RE: https:// infosec.exchange/@cyberseckyle /117389340967928437 "Ireland's MyGovID and Denmark's CPR: A comparative anal
A cybersecurity commentator has published a comparative analysis of Ireland's MyGovID and Denmark's CPR personal identifier systems, examining how the two countries handle digital identity. The piece touches on age verification, digital rights, GDPR and data protection, prompting discussion among privacy and security professionals about how national ID schemes balance convenience against citizen data risks.
- 10ATLSECCON cybersecurity conference set for Halifax in April 2027▼🆕 New event added: @ atlseccon 📌 ATLSECCON 📅 Apr 8-9, 2027 📍 Halifax (NS) 🇨🇦 🔗 https://www. atlseccon.com # infosec # cy
A new entry has been added to cybersecurity conference listings: ATLSECCON, taking place April 8-9, 2027 in Halifax, Nova Scotia, Canada. The Atlantic Canada security gathering is now on the calendar for infosec professionals planning next year's event schedule, with details available on its official website.
- 11Fake Facebook login page flagged in new phishing warning▼Possible Phishing 🎣 on: ⚠️hxxps[:]//facebooc-system[.]start[.]page 🧬 Analysis at: https:// urldna.io/scan/6abc5f333b7750
Security researchers are warning about a phishing site at the address facebooc-system.start.page, which imitates Facebook to steal login credentials. The deliberately misspelled domain on a free hosting service is a common scam pattern. An analysis of the site has been published on the URLDNA scanning platform, and the warning is circulating among infosec professionals.
- 12Moderate authentication bypass flaw disclosed in Red Hat maestro gRPC broker▼CVE-2026-71297 is a moderate authentication bypass in the maestro gRPC broker used by Red Hat Advanced Cluster Managemen
CVE-2026-71297 describes a moderate authentication bypass in the maestro gRPC broker used by Red Hat Advanced Cluster Management and the Multicluster Engine. An attacker holding a valid client certificate could read other consumers' event streams or forge agent status reports. Security trackers and infosec communities are circulating the disclosure, with no confirmed exploitation reported so far.
- 13Fake Facebook Blogspot Link Flagged as Phishing▼Possible Phishing 🎣 on: ⚠️hxxp[:]//www[.]faceb0k-facebook[.]blogspot[.]com/ 🧬 Analysis at: https:// urldna.io/scan/6ac5a
Cybersecurity researchers are warning about a phishing site impersonating Facebook at a lookalike blogspot address that swaps characters in the domain to trick users. The link is being shared in defanged form so people cannot click it accidentally, and a full technical analysis has been published on URLDNA showing the site's characteristics. The warning circulates among infosec communities as a reminder to check domain spelling before entering login credentials.
- 14Security Researchers Flag Suspected Phishing Site on Wix▼Possible Phishing 🎣 on: ⚠️hxxps[:]//caitlinstrategyfir[.]wixsite[.]com/outreachmesagin 🧬 Analysis at: https:// urldna.io
Cybersecurity observers are warning about a suspected phishing page hosted on a Wix domain masquerading as a strategy firm outreach message. The warning, shared with the wider infosec community, includes a link to an analysis of the site on the URLDNA scanning platform, which breaks down the page's infrastructure and behavior. Users are advised to avoid the link and verify unsolicited outreach before responding.
- 15Developer seeks feedback on age-rt low-latency encryption▼age-rt: seeking feedback on low-latency, variable-chunk, age-like encryption https:// infosec.pub/post/53217267
A developer is asking the security community for feedback on age-rt, an encryption design inspired by the age file encryption format but built for low-latency streaming with variable chunk sizes. The proposal is being shared on Infosec Exchange, with discussion expected to focus on whether the design is sound and how it might fit real-time use cases.
- 16SilentRansomGroup emerges as new ransomware threat▼🚨New ransom group blog post!🚨 Group name: SilentRansomGroup Post title: A...n Sector: Unknown Info: https:// cti.fyi/gro
A new ransomware group calling itself SilentRansomGroup has been profiled in a fresh threat intelligence write-up. The post lists the group's name and activity but leaves its targeted sector unknown, and details remain limited. Cybersecurity researchers are circulating the alert among threat intelligence and infosec communities as they track the group's emergence.
- 17Security researchers flag possible phishing via Google Forms link▼Possible Phishing 🎣 on: ⚠️hxxps[:]//docs[.]google[.]com/forms/d/e/1FAIpQLSdG7yXu_ZDhf6QvaUs82ZmhpdKddCu-go7ASE_KaMFLVqwe
Cybersecurity analysts are warning about a possible phishing campaign hosted through a Google Forms link. The alert, shared on the social platform Mastodon, defuses the link and points to an automated URL analysis service so others can inspect the page before interacting with it. The warning is being circulated under phishing and infosec tags among the security community.
- 18Security researchers flag fake Facebook phishing page▼Possible Phishing 🎣 on: ⚠️hxxps[:]//facebookbigeronline[.]blogspot[.]com/?m=1 🧬 Analysis at: https:// urldna.io/scan/6ac
Cybersecurity observers are warning about a suspected phishing site hosted on a Blogspot address impersonating Facebook, with the domain name combining "facebook" and "bigeronline". The malicious link has been defanged and shared alongside a URL analysis report so others can inspect it. The alert circulates in infosec communities, where users are urging caution against similar fake login pages.
- 19Security researchers flag possible phishing site on Vercel●Possible Phishing 🎣 on: ⚠️hxxps[:]//pgsegofic[.]vercel[.]app/ 🧬 Analysis at: https:// urldna.io/scan/6ac514c43b77500 005
Cybersecurity accounts are warning about a suspected phishing website hosted on a Vercel subdomain, sharing the address in defanged form so readers cannot accidentally click it. A link to an automated scan on URLDNA lets others inspect the page's behaviour. The warning has circulated in infosec communities, with users urged to treat the domain as unsafe.
- 20Phishing site flagged impersonating Roundcube webmail●Possible Phishing 🎣 on: ⚠️hxxps[:]//roundcube-808[.]weebly[.]com 🧬 Analysis at: https:// urldna.io/scan/6ac488213b77500
Security researchers have flagged a suspected phishing page hosted on a weebly.com subdomain mimicking Roundcube webmail. The URL has been defanged to prevent accidental clicks, and a public scan of the site has been published for others to review. The warning circulated among infosec communities, who shared it with tags for phishing, scam and cybersecurity awareness.
- 21BSidesLimburg security conference set for March 2027 in Hasselt▼🆕 New event added: 📌 BSidesLimburg 📅 Mar 12, 2027 📍 Hasselt 🇧🇪 🔗 https://www. bsides-limburg.be # infosec # cybersecurit
A new edition of BSidesLimburg has been announced for March 12, 2027 in Hasselt, Belgium. The community-run cybersecurity conference is part of the global BSides series of information security events, and the announcement is circulating among infosec professionals tracking upcoming conferences.
- 22Discussion of claimed proof that memory hardness is irreversible▼Mathematical Proof that memory hardness is not reversible? https:// infosec.pub/post/52958081
A claim of a mathematical proof that memory hardness cannot be reversed is circulating among cryptography and information security enthusiasts. The discussion centers on whether such a result would hold, since it would have implications for password hashing and memory-hard functions used to slow brute-force attacks. Details of the argument itself remain thin, and experts have yet to weigh in publicly on its validity.
- 23Security Researchers Flag Possible Phishing Site on GitBook▼Possible Phishing 🎣 on: ⚠️hxxp[:]//mtmskchrpmxtnsion[.]gitbook[.]io 🧬 Analysis at: https:// urldna.io/scan/6ac375363b775
Cybersecurity accounts are warning about a suspected phishing page hosted on a GitBook subdomain, sharing the address in defanged form so readers cannot accidentally click it. A scan link from the URL analysis service urlDNA has been attached, letting other researchers inspect the domain's infrastructure, hosting details and behaviour. The warning is circulating with standard tags like #phishing and #infosec.
- 24OnePlus 15 root exploit via audio debug service detailed●I'm reading Ramsus Moorats' article on how to "Getting root on OnePlus 15 from an untrusted app, via an audio debug serv
Security researcher Rasmus Moorats has published an article describing how to gain root on the OnePlus 15 from an untrusted app, exploiting an audio debug service and a vendor HAL. The write-up includes a notably dismissive response from OnePlus' PSIRT security team, which reportedly told the researcher that without official written authorisation the issue would not be addressed, sparking criticism of the company's vulnerability handling.
- 25Researchers flag suspected phishing site on Cloudways-hosted domain▼Possible Phishing 🎣 on: ⚠️hxxps[:]//wordpress-1644952-6533726[.]cloudwaysapps[.]com 🧬 Analysis at: https:// urldna.io/sc
Cybersecurity researchers are warning about a suspected phishing website hosted on a Cloudways application domain (wordpress-1644952-6533726.cloudwaysapps.com). A link analysis of the address has been published on URLDNA so others can inspect the site's infrastructure. The warning is being circulated in infosec communities with the standard advice to treat the domain as unsafe.
- 26BitShot app promo video showcases crypto tracking process●And here is promo video for BitShot app, similar to an article I wrote earlier but showcasing the whole process with scr
A security researcher has shared a promotional video for BitShot, an app demonstrating a complete screen-recorded process tied to bitcoin, OSINT and data scraping. The demo follows an earlier written article by the same person and highlights the tool's open-source approach to cryptocurrency monitoring and privacy-related security research.
- 27Security Researcher Flags Possible Phishing Site▼Possible Phishing 🎣 on: ⚠️hxxps[:]//mailer05-tra[.]mdbgo[.]io 🧬 Analysis at: https:// urldna.io/scan/6abff8ed3b77500 006
A cybersecurity researcher has raised an alert over a suspected phishing site hosted on the domain mailer05-tra.mdbgo.io, defanging the link to prevent accidental clicks. A scan report from URLDNA was shared alongside the warning so others can inspect the domain's technical details. The post circulated among infosec communities under phishing and scam tags.
- 28Hacker CFP Tracker shared among cybersecurity community●https:// github.com/INIT6Source/Hacker_ CFPs/blob/main/README.md#hacker-cfp-tracker # Cybersecurity # HackthePlanet # cy
A GitHub repository collecting calls for papers and speaking opportunities for hackers and security researchers, called the Hacker CFP Tracker, is being circulated within the infosec community. The tracker is being highlighted during Cybersecurity Awareness Month, with users sharing it as a resource for researchers looking to present at security conferences.
- 29SECON security conference heads to Tokyo in February 2027▼🆕 New event added: 📌 SECCON 📅 Feb 20-21, 2027 📍 Tokyo 🇯🇵 🔗 https://www. seccon.jp/15/seccon_conference /open_conference_
The 15th SECCON open conference has been scheduled for February 20-21, 2027 in Tokyo. The Japanese cybersecurity event, run by the SECCON organization known for its capture-the-flag competitions, brings together security researchers and professionals. The announcement is circulating among infosec practitioners tracking upcoming industry conferences.
- 30Security researcher flags suspected phishing site imitating HSBC●Possible Phishing 🎣 on: ⚠️hxxps[:]//hsbcpress[.]com 🧬 Analysis at: https:// urldna.io/scan/6ac5af6b3b77500 0053105c6 # c
A cybersecurity researcher is warning of a suspected phishing website at hsbcpress.com, a domain designed to look like it belongs to HSBC. The site has been submitted for technical analysis on the URLDNA scanning service. The warning circulated among infosec communities, with observers urged to avoid interacting with the domain and to treat similar bank-themed sites with caution.
- 31Cisco security advisory flags zero-day SD-WAN web authentication flaw▼https:// sec.cloudapps.cisco.com/securi ty/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU # ZeroDa
A new Cisco security advisory is circulating among cybersecurity professionals, describing a vulnerability in Cisco SD-WAN's web authentication component labelled as a zero-day. Security commentators are sharing the advisory link on Infosec forums, tagging it with zero-day and SD-WAN hashtags, urging network administrators to review their Cisco SD-WAN deployments for the flaw and apply recommended mitigations or patches.
- 32Security researcher flags phishing site on Weebly●Possible Phishing 🎣 on: ⚠️hxxps[:]//vfyflfcuon[.]weebly[.]com/ 🧬 Analysis at: https:// urldna.io/scan/6ac43a133b77500 00
A cybersecurity researcher has flagged a possible phishing page hosted on a Weebly subdomain, sharing the link in defanged form along with a public URL analysis on urldna.io. The post serves as a warning to the infosec community, allowing others to inspect the site's infrastructure without exposing themselves to the scam. Details about the phishing campaign's targets or scale were not provided.
- 33Cybersecurity researchers flag fake DocuSign phishing site●Possible Phishing 🎣 on: ⚠️hxxp[:]//docusign-altroncommunications[.]webflow[.]io/ 🧬 Analysis at: https:// urldna.io/scan/
Security researchers are warning about a phishing site impersonating DocuSign, hosted on a Webflow domain that mimics the e-signature service. The suspicious link has been defanged to prevent accidental clicks, and a public URL analysis has been shared so others can inspect the site's infrastructure. Infosec communities are circulating the alert to help people avoid credential theft scams that use fake document-signing pages.
- 34Shodan adds Istanbul-based network AS15897 to its index●ASN: AS15897 Location: Istanbul, TR Added: 2026-09-30T12:10 # shodansafari # infosec
The network AS15897, located in Istanbul, Turkey, was added to Shodan's internet-wide scanning database on 30 September 2026. Security researchers use these ASN additions to track newly visible networks and exposed devices. The listing is being shared within the infosec community as part of routine monitoring of newly indexed internet infrastructure.
- 35Security Researchers Flag Suspected Phishing Domain●Possible Phishing 🎣 on: ⚠️hxxps[:]//messagerlev0cal8883900[.]fo[.]team 🧬 Analysis at: https:// urldna.io/scan/6ac0ee8f3b
Cybersecurity observers are warning about a suspected phishing site operating under the domain messagerlev0cal8883900.fo.team, a name that mimics Facebook Messenger's legitimate local addresses. The domain has been defanged and submitted to the URLdna scanning service for analysis, with the warning shared under cybersecurity and phishing tags. The deliberately confusing hostname suggests an attempt to trick users into entering login credentials on a fake page.
- 36Security researchers flag phishing site impersonating Caixa▼Possible Phishing 🎣 on: ⚠️hxxps[:]//kolkatadekho[.]com/wp-content/plugins/webarx/es/caixa-vbvfinal/home 🧬 Analysis at: h
Cybersecurity researchers are warning about a phishing page hosted on a compromised WordPress site, mimicking Caixa's card verification service. The malicious page, found under a plugins directory, is designed to steal banking credentials. A full analysis of the fraudulent infrastructure has been published, and the warning is circulating among infosec professionals tracking scams targeting banking customers in Spanish-speaking regions.
- 37Security researchers flag phishing site hosted on Weebly▼Possible Phishing 🎣 on: ⚠️hxxps[:]//esnetdeskfreenetserverservicesdkx[.]weebly[.]com 🧬 Analysis at: https:// urldna.io/s
Cybersecurity researchers are warning about a possible phishing site operating through a Weebly-hosted page that impersonates network or helpdesk services. The suspicious link has been defused and shared with a technical analysis via urldna.io so that other security professionals can inspect the domain and its infrastructure. The report has circulated in infosec communities, which frequently post such alerts to warn the public about scam pages before they spread more widely.
- 38Possible phishing site flagged impersonating Toronto Construction Association▼Possible Phishing 🎣 on: ⚠️hxxp[:]//tcaconnect[.]ac-page[.]com/toronto-construction-association-inc 🧬 Analysis at: https:
Cybersecurity researchers are warning of a possible phishing page hosted on a domain mimicking the Toronto Construction Association, shared via a defanged link and analyzed through the URLDNA scanning service. The alert circulates in infosec communities, urging recipients to avoid the link and verify any communications claiming to come from the association.
- 39Sherpa Intelligence Releases October 7 Security Briefing●Basecamp Briefing for October 7th 🏔️ # InfoSec , # GRC , # OSINT and more curated for you by Sherpa Intelligence: Your G
Sherpa Intelligence has published its Basecamp Briefing for October 7th, a curated roundup covering information security, governance, risk and compliance, and open-source intelligence topics. The briefing is part of the firm's regular effort to package key cybersecurity developments into one digest for practitioners.
- 40Security researchers flag new phishing site using Weebly▼Possible Phishing 🎣 on: ⚠️hxxps[:]//securefirstjackson[.]weebly[.]com/ 🧬 Analysis at: https:// urldna.io/scan/6ac093c03b
Cybersecurity observers are warning about a suspected phishing site hosted on a Weebly subdomain imitating First Jackson, with a link-out to a URL analysis report. Alerts like this circulate regularly in infosec communities so defenders can block or take down malicious pages. The defanged link is shared to prevent accidental clicks while allowing others to verify the finding.