search
InfoSec
Trends
- 1Security Researchers Flag Suspected Phishing Site on Wix▼Possible Phishing 🎣 on: ⚠️hxxps[:]//caitlinstrategyfir[.]wixsite[.]com/outreachmesagin 🧬 Analysis at: https:// urldna.io
Cybersecurity observers are warning about a suspected phishing page hosted on a Wix domain masquerading as a strategy firm outreach message. The warning, shared with the wider infosec community, includes a link to an analysis of the site on the URLDNA scanning platform, which breaks down the page's infrastructure and behavior. Users are advised to avoid the link and verify unsolicited outreach before responding.
- 2Man posing as cybersecurity engineer exposed for doxxing women●This self-described "cybersecurity engineer" managed to trick women into providing their personal info, which he then po
A self-described cybersecurity engineer has been arrested after tricking women into handing over personal information, which he then published online. The case is drawing attention in information security circles, with commenters noting that a booking photo released last week is hardly the image the profession wants, and highlighting the harm caused by online harassment and data misuse against women.
- 3SilentRansomGroup emerges as new ransomware threat▼🚨New ransom group blog post!🚨 Group name: SilentRansomGroup Post title: A...n Sector: Unknown Info: https:// cti.fyi/gro
A new ransomware group calling itself SilentRansomGroup has been profiled in a fresh threat intelligence write-up. The post lists the group's name and activity but leaves its targeted sector unknown, and details remain limited. Cybersecurity researchers are circulating the alert among threat intelligence and infosec communities as they track the group's emergence.
- 4Security researchers flag possible phishing site on Vercel●Possible Phishing 🎣 on: ⚠️hxxps[:]//pgsegofic[.]vercel[.]app/ 🧬 Analysis at: https:// urldna.io/scan/6ac514c43b77500 005
Cybersecurity accounts are warning about a suspected phishing website hosted on a Vercel subdomain, sharing the address in defanged form so readers cannot accidentally click it. A link to an automated scan on URLDNA lets others inspect the page's behaviour. The warning has circulated in infosec communities, with users urged to treat the domain as unsafe.
- 5Security researcher flags suspected phishing site imitating HSBC●Possible Phishing 🎣 on: ⚠️hxxps[:]//hsbcpress[.]com 🧬 Analysis at: https:// urldna.io/scan/6ac5af6b3b77500 0053105c6 # c
A cybersecurity researcher is warning of a suspected phishing website at hsbcpress.com, a domain designed to look like it belongs to HSBC. The site has been submitted for technical analysis on the URLDNA scanning service. The warning circulated among infosec communities, with observers urged to avoid interacting with the domain and to treat similar bank-themed sites with caution.
- 6Developer seeks feedback on age-rt low-latency encryption▼age-rt: seeking feedback on low-latency, variable-chunk, age-like encryption https:// infosec.pub/post/53217267
A developer is asking the security community for feedback on age-rt, an encryption design inspired by the age file encryption format but built for low-latency streaming with variable chunk sizes. The proposal is being shared on Infosec Exchange, with discussion expected to focus on whether the design is sound and how it might fit real-time use cases.
- 7Meta Rushed to Fix VM Escape Flaw Before Muse Launch▼Is this related to one of our fellow Mastodonians running a server off their systems? # MetaMuse # Meta # Infosec # Tech
Meta reportedly patched a virtual machine escape vulnerability in its MetaMuse product immediately before launch, according to 404 Media reporting. A VM escape flaw would let code break out of an isolated virtual machine, a serious security risk. Users in infosec and tech communities are discussing the fix and whether it connects to a fellow Mastodon user known to run servers from their own systems.
- 8Security researchers flag possible phishing via Google Forms link▼Possible Phishing 🎣 on: ⚠️hxxps[:]//docs[.]google[.]com/forms/d/e/1FAIpQLSdG7yXu_ZDhf6QvaUs82ZmhpdKddCu-go7ASE_KaMFLVqwe
Cybersecurity analysts are warning about a possible phishing campaign hosted through a Google Forms link. The alert, shared on the social platform Mastodon, defuses the link and points to an automated URL analysis service so others can inspect the page before interacting with it. The warning is being circulated under phishing and infosec tags among the security community.
- 9Fediverse users asked for advice on studying US law●Hi # Fediverse # lawyers . What is your advice/recommendations (classes? certifications?) for a non-lawyer who wants to
A user asked lawyers on the Fediverse for recommendations on how a non-lawyer can gain practical knowledge of US and state law, including classes or certifications. The question drew engagement from the infosec community and touched on self-education in legal matters.
- 10Security researchers flag fake Facebook tips blog as phishing●Possible Phishing 🎣 on: ⚠️hxxps[:]//facebook-astuces-news[.]blogspot[.]com/?m=1 🧬 Analysis at: https:// urldna.io/scan/6
Cybersecurity observers are warning about a phishing site posing as a Facebook news and tips page, hosted on a Blogspot domain and shared with a deliberately defanged link to avoid accidental clicks. An automated analysis of the URL has been published on urldna.io, and warnings are circulating under phishing and infosec tags among security professionals.
- 11AT&T network asset in Santa Clara flagged in security scans●ASN: AS7018 Location: Santa Clara, US Added: 2026-09-30T06:22 # shodansafari # infosec
A cybersecurity observation tagged the AT&T-owned autonomous system AS7018 at a Santa Clara, US location, logged in late September 2026. Information security practitioners circulate such findings to track exposed or notable internet-facing infrastructure, with internet service provider networks remaining a frequent subject of scanning and discussion.
- 12Phishing site flagged impersonating Roundcube webmail●Possible Phishing 🎣 on: ⚠️hxxps[:]//roundcube-808[.]weebly[.]com 🧬 Analysis at: https:// urldna.io/scan/6ac488213b77500
Security researchers have flagged a suspected phishing page hosted on a weebly.com subdomain mimicking Roundcube webmail. The URL has been defanged to prevent accidental clicks, and a public scan of the site has been published for others to review. The warning circulated among infosec communities, who shared it with tags for phishing, scam and cybersecurity awareness.
- 13Security researcher flags phishing site on Weebly●Possible Phishing 🎣 on: ⚠️hxxps[:]//3433ww45[.]weebly[.]com/ 🧬 Analysis at: https:// urldna.io/scan/6ac522c53b77500 0053
A cybersecurity analyst has flagged a possible phishing page hosted on a Weebly subdomain and published a scan of the URL on the analysis platform urlDNA. The address was defanged in the warning to prevent accidental clicks. The report circulated among infosec practitioners, who routinely share indicators of compromise like fake login pages, though details about the campaign or its targets were not disclosed.
- 14Shodan safari highlights network AS3269 in Bompensiere, Italy●ASN: AS3269 Location: Bompensiere, IT Added: 2026-09-30T20:35 # shodansafari # infosec
Cybersecurity observers are flagging AS3269, an autonomous system number registered in Bompensiere, Italy, in ongoing network reconnaissance discussions. The system is associated with Telecom Italia, and such posts typically track newly indexed or newly observed network activity. The brief mention has drawn modest attention within the infosec community.
- 15wolfSSH flaw CVE-2026-16516 flagged over data authenticity●wolfSSH https:// radar.offseq.com/threat/cve-20 26-16516-cwe-345-insufficient-verification-of-data-authenticity-in-wolfs
A new vulnerability, CVE-2026-16516, has been catalogued in wolfSSH, the SSH library from wolfSSL Inc. The flaw is classified as CWE-345, insufficient verification of data authenticity, meaning the library may accept data without properly confirming it comes from a trusted source. The listing is circulating among security researchers, who are tracking it as a potential concern for products embedding wolfSSH.
- 16ASN AS8708 spotted in Bucharest raises eyebrows●ASN: AS8708 Location: Bucharest, RO Added: 2026-10-02T16:48 # shodansafari # infosec
A cybersecurity note flags ASN AS8708, an autonomous system number, as located in Bucharest, Romania, with a timestamp of 2 October 2026. The observation was shared with the infosec community as part of an internet-wide scanning exercise tagged shodansafari, where researchers track how network infrastructure is registered and geolocated. Little detail accompanies the entry, so it reads as a routine intelligence find rather than a confirmed incident.
- 17Researcher launches account on neurodiversity in cybersecurity●Hey everyone, I've started a alt account, @ neurodiversity , to post my research in # Neurodiversity in # Infosec . You'
A security researcher who posts on infosec platforms has started a dedicated account to share research on neurodiversity within the information security field, inviting others to follow for updates. The move highlights growing interest in how neurodivergent professionals experience and contribute to cybersecurity, a topic increasingly discussed in industry communities.
- 18WordPress sites warned over exposed uploads and scraping●TL;DR: If your WordPress uploads are public and enumerable, scrapers will find them. Lock down directory listing, REST A
A cybersecurity warning is circulating that WordPress sites with public and enumerable upload directories are easy targets for scrapers. The advice: disable directory listing, restrict media enumeration through the REST API, and block hotlinking. The tip is being shared in infosec circles as a simple hardening step for site owners.
- 19Open-source engine runs 125-billion parameter model on 12GB GPUs●Discover how the Strata open-source AI engine allows users to run the 125-billion parameter Qwen3.8-Flash-Next model on
An article circulating on Mastodon describes Strata, an open-source AI engine that reportedly lets users run the 125-billion parameter Qwen3.8-Flash-Next model on consumer GPUs with just 12GB of memory. The claim, shared via the infosec and tech community, is drawing attention for suggesting high-end models can run on ordinary hardware without expensive setups.
- 20Comparing Ireland's MyGovID with Denmark's CPR ID system●RE: https:// infosec.exchange/@cyberseckyle /117389340967928437 "Ireland's MyGovID and Denmark's CPR: A comparative anal
A cybersecurity commentator has published a comparative analysis of Ireland's MyGovID and Denmark's CPR personal identifier systems, examining how the two countries handle digital identity. The piece touches on age verification, digital rights, GDPR and data protection, prompting discussion among privacy and security professionals about how national ID schemes balance convenience against citizen data risks.
- 21BSidesLimburg security conference set for March 2027 in Hasselt▼🆕 New event added: 📌 BSidesLimburg 📅 Mar 12, 2027 📍 Hasselt 🇧🇪 🔗 https://www. bsides-limburg.be # infosec # cybersecurit
A new edition of BSidesLimburg has been announced for March 12, 2027 in Hasselt, Belgium. The community-run cybersecurity conference is part of the global BSides series of information security events, and the announcement is circulating among infosec professionals tracking upcoming conferences.
- 22Security Researchers Flag Suspected Phishing Site Impersonating University of Padua●Possible Phishing 🎣 on: ⚠️hxxps[:]//unipd[.]godaddysites[.]com 🧬 Analysis at: https:// urldna.io/scan/6ac4b8cb3b77500 00
Cybersecurity observers are warning about a suspected phishing site at unipd.godaddysites.com, a domain mimicking the University of Padua but hosted on a free GoDaddy site builder rather than the university's own infrastructure. The site has been submitted for technical analysis, and warnings are circulating in infosec communities urging users to avoid entering credentials on lookalike academic login pages.
- 23Moderate authentication bypass flaw disclosed in Red Hat maestro gRPC broker▼CVE-2026-71297 is a moderate authentication bypass in the maestro gRPC broker used by Red Hat Advanced Cluster Managemen
CVE-2026-71297 describes a moderate authentication bypass in the maestro gRPC broker used by Red Hat Advanced Cluster Management and the Multicluster Engine. An attacker holding a valid client certificate could read other consumers' event streams or forge agent status reports. Security trackers and infosec communities are circulating the disclosure, with no confirmed exploitation reported so far.
- 24Fastweb host in Milan flagged on Shodan Safari●ASN: AS12874 Location: Milan, IT Added: 2026-09-30T16:12 # shodansafari # infosec
A newly added entry on the Shodan Safari watchlist points to AS12874, the network of Italian provider Fastweb, located in Milan, Italy, logged on 30 September 2026. Security watchers circulating the entry are highlighting freshly exposed or newly indexed systems on Italian infrastructure as part of ongoing discussions about what internet-wide scanning reveals.
- 25Suspected Amazon phishing site flagged by security analysts●Possible Phishing 🎣 on: ⚠️hxxps[:]//amazon-ten-gamma[.]vercel[.]app 🧬 Analysis at: https:// urldna.io/scan/6ac4c6d83b775
Cybersecurity researchers are warning about a suspected phishing site impersonating Amazon, hosted on a Vercel app domain. The URL has been defanged to prevent accidental clicks, and a technical analysis of the page has been published on UrlDNA. The warning circulates in infosec communities, with users urged to avoid entering Amazon credentials on unfamiliar domains and to verify URLs before logging in.
- 26New ASN AS206314 spotted in Gorzów Wielkopolski●ASN: AS206314 Location: Gorzów Wielkopolski, PL Added: 2026-10-02T17:13 # shodansafari # infosec
Autonomous system number AS206314 has been registered in Gorzów Wielkopolski, Poland, with records dating it to 2 October 2026. Cybersecurity watchers track newly announced ASNs because they can reveal fresh network infrastructure before it is fully characterised, and newly seen ranges are often scanned, mapped and assessed for security exposure.
- 27Spell Orsterra challenge solved on Hack The Box●I just solved Spell Orsterra on Hack The Box! https:// labs.hackthebox.com/achievemen t/challenge/2026525/443 # HackTheB
A user has solved the Spell Orsterra challenge on Hack The Box, the online platform for cybersecurity and penetration testing practice. Completing individual challenges is a common milestone ethical hackers share publicly as proof of their skills, and such announcements circulate regularly in infosec communities.
- 28Security researchers flag phishing site impersonating Caixa▼Possible Phishing 🎣 on: ⚠️hxxps[:]//kolkatadekho[.]com/wp-content/plugins/webarx/es/caixa-vbvfinal/home 🧬 Analysis at: h
Cybersecurity researchers are warning about a phishing page hosted on a compromised WordPress site, mimicking Caixa's card verification service. The malicious page, found under a plugins directory, is designed to steal banking credentials. A full analysis of the fraudulent infrastructure has been published, and the warning is circulating among infosec professionals tracking scams targeting banking customers in Spanish-speaking regions.
- 29ChainKeep targets timestamp tracking in digital investigations▼Every second matters in an investigation. ChainKeep makes sure every one of them is accounted for. ⏳ # ChainKeep # InfoS
ChainKeep, a tool aimed at digital forensics and incident response professionals, is being promoted with the message that every second matters in an investigation and that the software ensures every timestamp is accounted for. The pitch highlights chain-of-custody concerns in cybersecurity investigations, where accurate time records can determine whether evidence holds up. Discussion so far appears limited to infosec circles.
- 30BSides Barcelona cybersecurity event set for October 2026●🆕 New event added: 📌 BSidesBarcelona 📅 Oct 30, 2026 📍 Barcelona 🇪🇸 🔗 https:// bsides.barcelona # infosec # cybersecurity
A new BSides Barcelona event has been added to the cybersecurity conference calendar, scheduled for October 30, 2026 in Barcelona, Spain. BSides events are community-run security conferences that take place in cities worldwide, offering talks and workshops for information security professionals. The announcement is being shared across infosec community channels as attendees plan for the event.
- 31Mumbai network AS18229 flagged in infosec monitoring●ASN: AS18229 Location: Mumbai, IN Added: 2026-10-03T06:34 # shodansafari # infosec
Information security researchers are discussing AS18229, an autonomous system based in Mumbai, India, after it was added to monitoring feeds on 3 October 2026. The asn entry circulated among cybersecurity practitioners tracking newly visible networks and exposed internet-facing services, prompting conversations about what assets the network hosts and whether proper security configuration is in place.
- 32GrapheneOS adds Secure Paste to block clipboard snooping●RE: https:// infosec.exchange/@lacze/117332 720535130953 System GrapheneOS otrzymał nową funkcję, która uniemożliwia apl
GrapheneOS, the privacy-focused Android operating system, has rolled out a new feature called Secure Paste, which prevents apps from reading the contents of the clipboard. The system now lets users approve pasting on a per-app basis, blocking apps from silently harvesting clipboard data. The change is described as a significant security improvement, and it has drawn attention in the privacy and infosec community, where users welcome tighter control over what apps can access.
- 33Security researcher flags phishing site on Weebly●Possible Phishing 🎣 on: ⚠️hxxps[:]//vfyflfcuon[.]weebly[.]com/ 🧬 Analysis at: https:// urldna.io/scan/6ac43a133b77500 00
A cybersecurity researcher has flagged a possible phishing page hosted on a Weebly subdomain, sharing the link in defanged form along with a public URL analysis on urldna.io. The post serves as a warning to the infosec community, allowing others to inspect the site's infrastructure without exposing themselves to the scam. Details about the phishing campaign's targets or scale were not provided.
- 34Ph0wn cybersecurity conference set for Sophia Antipolis in March 2027●🆕 New event added: @ ph0wn 📌 Ph0wn 📅 Mar 12-13, 2027 📍 Sophia Antipolis 🇫🇷 🔗 https:// ph0wn.org # infosec # cybersecurit
The Ph0wn cybersecurity conference has been announced for March 12-13, 2027 in Sophia Antipolis, France. Organisers say the dates and location are confirmed on the event's website. The announcement is being shared among information security professionals tracking upcoming industry conferences in Europe.
- 35Atlanta-hosted network AS63410 surfaces in internet scans●ASN: AS63410 Location: Atlanta, US Added: 2026-10-02T19:19 # shodansafari # infosec
The autonomous system AS63410, based in Atlanta in the United States, has been added to an internet-wide infrastructure scanning index as of 2 October 2026. Security researchers track such additions to spot newly exposed or re-registered networks. Little is known publicly about what services the network hosts or who operates it.
- 36Security researchers flag suspected phishing site on Weebly●Possible Phishing 🎣 on: ⚠️hxxps[:]//jpalominoh[.]weebly[.]com/ 🧬 Analysis at: https:// urldna.io/scan/6ac3fba73b77500 00
Cybersecurity observers are warning about a suspected phishing page hosted on a Weebly subdomain, jpalominoh.weebly.com. The site has been submitted for automated analysis via the URLDNA scanning service, with the alert circulating among infosec communities tagged under phishing, scam and cybersecurity. Details about who is targeted or what the fake page impersonates have not yet been disclosed.
- 37New ASN entry spots AS6167 in San Luis Obispo●ASN: AS6167 Location: San Luis Obispo, US Added: 2026-10-02T16:16 # shodansafari # infosec
Cybersecurity watchers are logging network AS6167, registered to San Luis Obispo, California, after its addition to internet scanning records on 2 October 2026. The sighting was shared under infosec hashtags, as part of a routine pastime of tracking newly added autonomous system numbers to spot changes in internet infrastructure.
- 38New Warsaw network listing flags Polish ASN in cybersecurity circles●ASN: AS12912 Location: Warsaw, PL Added: 2026-10-02T15:32 # shodansafari # infosec
A newly registered entry for AS12912, an autonomous system based in Warsaw, Poland, dated 2 October 2026, is circulating among cybersecurity researchers who track internet-exposed devices and network infrastructure. The item carries the tags shodansafari and infosec, suggesting analysts are monitoring the network's exposure as part of routine scanning of newly added assets.
- 39Security researchers flag phishing site imitating Google domain●Possible Phishing 🎣 on: ⚠️hxxps[:]//googlelogos[.]com 🧬 Analysis at: https:// urldna.io/scan/6ac3f3d93b77500 002971c7b #
Cybersecurity researchers are warning about a phishing operation hosted at googlelogos.com, a domain designed to look like it belongs to Google. A public analysis of the URL has been shared on urlDNA, allowing other security professionals to inspect the site's behaviour. The warning is circulating in infosec communities, with users urged to treat the domain as unsafe and avoid entering credentials on it.
- 40AT&T-linked ASN AS7018 logged in Santa Clara●ASN: AS7018 Location: Santa Clara, US Added: 2026-09-30T05:27 # shodansafari # infosec
AS7018, the autonomous system number associated with AT&T, was logged with a location of Santa Clara, United States, with the entry timestamped 30 September 2026. The notation circulated among cybersecurity practitioners who track internet-exposed devices and network assets using Shodan, the search engine for connected hardware.