search
cybersecurity community
Trends
- 1ShinyHunters Claims Breach Exposing FBI Medical Recordsโ(malwarebytes.com) ShinyHunters Exposes Highly Sensitive FBI Medical Records in Extortion-Driven Cyberattack In brief -
The extortion group ShinyHunters claims it breached the FBI and obtained highly sensitive medical records of personnel, reportedly leaked as part of an attempted extortion scheme. Malwarebytes reports on the alleged theft of medical and other private data. The FBI has not been confirmed as commenting, and the scale and authenticity of the claimed leak remain unverified, but the targeting of a US law enforcement agency is drawing close attention in the cybersecurity community.
- 2Gyazo breach exposes data of 23.6 million usersโผWeek in review: Gyazo breach exposes 23.6M user data, TASK#STOMP steals documents
Screenshot service Gyazo suffered a data breach affecting 23.6 million users, with personal information exposed. The incident is reported alongside a separate malware operation called TASK#STOMP that steals documents from infected machines. Security observers are treating both as reminders of growing risks around stored user data and targeted document theft, as details of the breach's scope continue to circulate.
- 3Gyazo Data Breach Exposes 23.6 Million User RecordsโผGyazo Data Breach Exposes 23.6 Million User Records and Nearly Half a Billion Image Metadata
Screen-capture service Gyazo has suffered a data breach affecting 23.6 million user records and close to half a billion image metadata entries. The exposed data reportedly relates to user accounts and information about screenshots stored through the service. The incident raises questions about how the Japan-based company secures its systems and what steps affected users should take, with further details on the scope and cause still emerging.
- 4Twizzit Data Breach Exposes 1.2 Million UsersโผTwizzit Management Platform Breach Exposes Data of 1.2 Million Users Twizzit suffered a data breach after attackers expl
Management platform Twizzit has suffered a data breach after attackers exploited a vulnerability to steal personal details of more than 1.2 million users across roughly 5,500 organizations. The stolen data reportedly includes names, email addresses, and other personal information. Security communities are discussing the incident as a further example of how a single platform vulnerability can put large numbers of users at risk.
- 5New Cross-Platform Attack Tracks Users Without Elevated PrivilegesโNew Attack Can Track You Across Operating Systems Without Elevated Privileges https://www. privacyguides.org/news/2026/0
Privacy Guides reports a newly disclosed attack capable of tracking users across different operating systems, including Linux, Windows, macOS, Android and iOS, without requiring elevated privileges. The finding is drawing attention in cybersecurity and privacy communities, where users are discussing what the technique means for device tracking and how effectively current system protections can defend against it.
- 6Zero-day in third-party vendor exposed Belgian research network Belnet emails for two monthsโโจ Due mesi di silenzio: uno zero-day su un fornitore terzo apre le caselle email della rete belga Belnet # CyberSecurity
A zero-day vulnerability in a third-party supplier allowed attackers to open email mailboxes on Belnet, Belgium's national research and education network, with the intrusion reportedly going unnoticed for two months. The case is drawing attention from the cybersecurity community as a reminder of supply-chain risk, since the flaw sat outside Belnet's own systems while its users' communications were exposed.
- 7AI giants accused of hypocrisy over warnings on open modelsโThe new AI conglomerates are publishing documents warning about the dangers of semi-open models that defenders can actua
AI conglomerates are publishing documents warning about the dangers of semi-open models that defenders can actually use, while restricting defenders' access to their own proprietary models. Security researchers say the stance undermines the cybersecurity community, which relies on open access to study and defend against model vulnerabilities. Critics see it as a double standard: open models are framed as risky precisely when they enable independent defence work.
- 8
A new model focused on cyber open-source intelligence has been released, according to a security researcher announcing it online. The release is being shared among cybersecurity and OSINT practitioners, who are taking note of what a purpose-built model for intelligence gathering could offer. Details on the model's capabilities, creators and intended use were not immediately available.
- 9Security Researchers Flag Possible Phishing Site on WeeblyโผPossible Phishing ๐ฃ on: โ ๏ธhxxps[:]//nnbxv[.]weebly[.]com ๐งฌ Analysis at: https:// urldna.io/scan/6abc7b5a3b77500 00653a6c
Cybersecurity observers are warning about a suspected phishing page hosted at a Weebly web address, sharing a link to a detailed technical analysis of the site on the URLDNA scanning platform. The address has been defanged to prevent accidental clicks. The warning is being circulated in information security communities alongside standard scam and phishing alert tags.
- 10Humble Bundle offers O'Reilly cybersecurity book deal for charityโ๐จ BOOK BUNDLE DEAL! Fortify your digital world and knowledge with these cybersecurity books from O'Reilly while supporti
A limited-time Humble Bundle is offering a collection of O'Reilly cybersecurity books, with part of the proceeds going to the nonprofit Code for America. The bundle, tied to Cybersecurity Month 2026, is being shared in technology and book communities online, where readers are encouraging others to pick up the deal before it expires.
- 11Security researchers flag phishing site hosted on WeeblyโผPossible Phishing ๐ฃ on: โ ๏ธhxxps[:]//esnetdeskfreenetserverservicesdkx[.]weebly[.]com ๐งฌ Analysis at: https:// urldna.io/s
Cybersecurity researchers are warning about a possible phishing site operating through a Weebly-hosted page that impersonates network or helpdesk services. The suspicious link has been defused and shared with a technical analysis via urldna.io so that other security professionals can inspect the domain and its infrastructure. The report has circulated in infosec communities, which frequently post such alerts to warn the public about scam pages before they spread more widely.
- 12Fake Wells Fargo login page flagged as phishing siteโผPossible Phishing ๐ฃ on: โ ๏ธhxxps[:]//sites[.]google[.]com/view/wellsfargologinu ๐งฌ Analysis at: https:// urldna.io/scan/6a
Security researchers are flagging a fraudulent Wells Fargo login page hosted on a Google Sites address, designed to steal customers' banking credentials. The link has been defanged to prevent accidental clicks, and a public scan on URLDNA lets others inspect the site's characteristics. The warning has circulated among infosec community members tracking phishing campaigns.
- 13New Windows NCSI proxy authentication flaw detailed by researchersโผMicrosoft Windows NCSI Cross-Context Proxy Authentication Coercion - ZDI-26-708 - Part 1: https:// pgj11.com/posts/Windo
Security researchers have published a two-part technical write-up of a Windows vulnerability tracked as ZDI-26-708, described as a cross-context proxy authentication coercion in the Network Connectivity Status Indicator (NCSI). The disclosure is circulating among security professionals sharing the detailed analysis. Details on affected versions and patches remain unclear from the discussion so far.
- 14Security researchers flag possible phishing site on weebly.comโผPossible Phishing ๐ฃ on: โ ๏ธhxxps[:]//general-trading[.]weebly[.]com ๐งฌ Analysis at: https:// urldna.io/scan/6abc66db3b7750
Cybersecurity observers are warning about a suspected phishing page hosted at general-trading.weebly.com, sharing the address in defanged form so others do not accidentally visit it. A technical scan of the URL has been published on urldna.io for analysts to review. The alerts are circulating in infosec communities with tags for phishing, scams and general cybersecurity awareness.
- 15BSidesVI cybersecurity conference wraps up with community thanksโผBut most of allโฆ Thank you to everyone who showed up. BSidesVI isnโt a corporation putting on a conference. Itโs a commu
Organisers of BSidesVI, a community-run cybersecurity conference in the US Virgin Islands, have thanked attendees for turning out, stressing that the event is built by a community of security professionals rather than a corporation. They described Friday's gathering as a strong showing of people who care about the industry coming together to build something themselves.
- 16Security researchers flag suspected Amazon phishing domainโPossible Phishing ๐ฃ on: โ ๏ธhxxp[:]//amazoninvit[.]com ๐งฌ Analysis at: https:// urldna.io/scan/6abb5baf3b77500 0050fcbb3 #
Cybersecurity researchers are warning about a suspected phishing site at the domain amazoninvit.com, which impersonates Amazon, likely luring victims through fake invitation or delivery messages. The domain has been submitted for technical analysis on the URLdna scanning platform, and the warning is circulating in information security communities with phishing and scam alerts.
- 17Critical CVSS 10 flaw CVE-2026-71379 allows unauthenticated data exportโ๐จ CVE-2026-71379 โ CVSS 10 CRITICAL The file export endpoint allows any unauthenticated attacker to export arbitrary dat
A vulnerability tracked as CVE-2026-71379, rated CVSS 10, is drawing attention in the cybersecurity community. The flaw lies in a file export endpoint that lets any unauthenticated attacker export arbitrary database tables via a crafted POST request. Security feeds are flagging it as maximum-severity, urging organizations to check whether their systems are affected and patch promptly.
- 18Security researchers flag possible phishing linkโผPossible Phishing ๐ฃ on: โ ๏ธhxxps[:]//tinyurl[.]com/e7exuktd ๐งฌ Analysis at: https:// urldna.io/scan/6abbd2873b77500 0034a0
Cybersecurity analysts are warning about a possible phishing campaign distributed through a shortened TinyURL link. A link-analysis service has published a scan of the address so that users can inspect where the redirect leads before clicking. Alerts like this circulate in information-security communities to warn people off suspicious links and demonstrate how shortened URLs can hide malicious destinations.
- 19Security Researchers Flag Phishing Site Hosted on Google SitesโผPossible Phishing ๐ฃ on: โ ๏ธhxxps[:]//sites[.]google[.]com/view/oiuiruieor98490krejjkljklejkef/home ๐งฌ Analysis at: https:/
Cybersecurity researchers are warning about a phishing page hosted on Google Sites, sharing a defanged link and a scan report on urlDNA for analysis. The alerts circulated in infosec channels, with warnings that the site is designed to deceive visitors into handing over credentials or personal data. The use of a legitimate Google domain highlights how attackers exploit trusted hosting services.
- 20Security researchers flag possible phishing site 21argarena4.comโผPossible Phishing ๐ฃ on: โ ๏ธhxxp[:]//21argarena4[.]com ๐งฌ Analysis at: https:// urldna.io/scan/6abb5baa3b77500 004b4aab1 #
Cybersecurity observers are warning about a possible phishing website at 21argarena4.com. The domain, which imitates the Arena of Valor ARG Arena branding, has been defanged in warnings and submitted to the URLdna scanning service for analysis. The alert is being shared within infosec communities alongside tags for phishing, scams and general cybersecurity awareness.
- 21Interlock ransomware group lists Tekko Enterprises as new victimโผ๐จNew ransom group blog posts!๐จ Group name: interlock Post title: Tekko Enterprises, Inc Info: https:// cti.fyi/groups/in
Cybersecurity trackers report that the Interlock ransomware group has posted Tekko Enterprises, Inc. on its leak blog, claiming a new breach. A separate post by the Wallstreet ransomware group lists Gibson Area Hospital & Health Services as a victim. Ransomware leak-site monitoring is widely shared among threat intelligence watchers, who use such listings to warn potential targets and track which criminal groups are actively extorting organisations.
- 22Spanish-Language Delivery Phishing Link Flagged by ResearchersโผPossible Phishing ๐ฃ on: โ ๏ธhxxps[:]//qrco[.]de/modifica-tu-entrega ๐งฌ Analysis at: https:// urldna.io/scan/6abb155a3b77500
Security researchers have flagged a phishing link circulating via a QR-code shortener service, with a Spanish-language address ("modifica tu entrega", meaning "modify your delivery") suggesting a fake parcel-delivery scam. The link has been submitted for technical analysis on a URL-scanning platform. Cybersecurity observers warn that such QR-code delivery scams trick recipients into entering payment or personal details on fake courier sites.
- 23New CVE issued for U-Boot bootloaderโCVE Alert: CVE-2026-74222 - u-boot - u-boot - https://www. redpacketsecurity.com/cve-aler t-cve-2026-74222-u-boot-u-boot
A new vulnerability identifier, CVE-2026-74222, has been published concerning U-Boot, the widely used open-source bootloader for embedded systems. Threat-intelligence feeds are circulating the alert, though technical details about the flaw, its severity, and affected versions remain sparse in initial reporting. Security teams monitoring U-Boot deployments are advised to track the advisory for updates as more information becomes available.
- 24New cyber-OSINT model released to public attentionโNew Cyber-OSINT model released https://twitter.com/0x0SojalSec/status/2104736980768866439 # HackerNews # Tech # CyberSec
A new OSINT-focused artificial intelligence model for cybersecurity work has been released, according to an announcement circulating among hackers and security researchers. The release is being shared in tech and cybersecurity circles, though details about who built the model, what it can do, and how it performs have not been made widely available yet.
- 25OnePlus OxygenOS zero-permission root flaw sparks controversyโDiscover how a zero-permission OnePlus OxygenOS root vulnerability was found and why the company threatened the research
A cybersecurity researcher has disclosed a zero-permission root vulnerability in OnePlus's OxygenOS, which would let a malicious app gain root access on affected Android phones without requesting any dangerous permissions. Reports say OnePlus threatened the researcher rather than quickly patching the flaw, prompting criticism from the security community over the company's disclosure handling.
- 26Newly exposed host spotted in Fremont data centreโASN: 63949 Location: Fremont, US Added: 2026-09-29T13:59 # shodansafari # infosec
Security researchers are flagging an internet-facing host registered to ASN 63949, a network range operated by Linode in Fremont, California, that was indexed on 29 September 2026. The finding circulated in information security circles under the shodansafari hashtag, where practitioners share and discuss newly exposed servers, open ports and misconfigured devices discovered through internet-wide scanning.
- 27Privacy-minded users shifting from Firefox to hardened Chromium browsersโOne day you're using a Firefox-based browser for โprivacy,โ and the next day you're using Chrome + hardening or a Chromi
Some privacy-conscious users say they are abandoning Firefox-based browsers in favor of Chrome or hardened Chromium derivatives such as Vanadium and Trivalent, arguing these now offer better real-world privacy and security. The claim reflects an ongoing debate in the cybersecurity community over which browser foundation best protects users, and whether Firefox's direction still justifies its privacy-focused reputation.
- 28Google warns hackers are using AI agents for attacksโ"Google Threat Intelligence Group reported this week that it has observed adversaries moving beyond basic prompting into
Google Threat Intelligence Group reported this week that adversaries are moving beyond basic prompting into agentic workflows and AI-enabled automation. The finding suggests cyber attackers are now deploying autonomous AI systems to carry out parts of their operations, not just relying on simple AI queries. Security professionals are sharing the report as a signal that AI-driven threats are escalating.
- 29Jakarta IP flagged for exploiting known CVEsโ๐ต๏ธ ๐๐ฃ ๐ฐ๐ต๐ฒ๐น๐ผ๐ ๐ฑ๐ ๐ท๐ผ๐๐ฟ ๐ต๏ธ **Fiche : "Le Brocanteur de CVEs de Jakarta"** ๐ 103.63.101.24 | AS150273 ๐ฎ๐ฉ ๐ซ 5 frappes : Think
A cybersecurity observer has published a profile of IP address 103.63.101.24, hosted on Indonesian network AS150273 in Jakarta, dubbing it 'the CVE broker of Jakarta'. The address is said to have launched five attacks targeting known flaws in ThinkPHP, PHPUnit's eval-stdin, and Apache path traversal vulnerabilities CVE-2021-41773 and CVE-2021-42013, using the libredtail-http user agent and encoded traversal sequences seeking a shell.
- 30New PowerShell toolkit targets Windows endpoint security gapsโPowerShell - wbMSPSecurity 1.0 PowerShell for Endpoint Security. 45 commands that will close up endpoint issues that are
A security practitioner has released wbMSPSecurity 1.0, a PowerShell toolkit offering 45 commands that address endpoint security issues flagged in Microsoft's Secure Score and other Windows security products. The tool is aimed at helping administrators and managed service providers harden Windows endpoints quickly, and is drawing attention among security professionals sharing tooling updates.
- 31BSides Luxembourg publishes talk on LLM guardrailsโ# BSidesLuxembourg2026 recording: "๐๐ฏ๐๐ซ๐ฒ ๐๐ฎ๐๐ซ๐๐ซ๐๐ข๐ฅ ๐๐ฏ๐๐ซ๐ฒ๐ฐ๐ก๐๐ซ๐ ๐๐ฅ๐ฅ ๐๐ญ ๐๐ง๐๐: ๐๐๐ฌ๐ข๐ ๐ง๐ข๐ง๐ ๐๐ง๐ ๐๐๐ฌ๐ญ๐ข๐ง๐ ๐๐ฎ๐๐ซ๐๐ซ๐๐ข๐ฅ๐ฌ ๐ ๐จ๐ซ ๐๐๐ ๐๐ฉ๐ฉ๐ฅ
A recorded talk from BSides Luxembourg 2026, titled 'Every Guardrail Everywhere All At Once: Designing And Testing Guardrails For LLM Applications', is now available online. The talk was given by security researcher Donato Capitrella and covers how to design and test safety guardrails for applications built on large language models. The conference has also released the full track recordings through its public archive.
- 32Anthropic releases new Sonnet 5.5 AI modelโDiscover the new Anthropic Sonnet 5.5 model. Explore its faster processing speeds, lower operational costs, and enhanced
Anthropic has unveiled its new Sonnet 5.5 model, which the company says offers faster processing speeds, lower operational costs and improved capabilities for autonomous coding agents. Tech and cybersecurity commentators are sharing the announcement, with attention focused on what the performance and cost improvements mean for developers building AI-powered tools.
- 33Security Researchers Flag Facebook Phishing Site on BlogspotโPossible Phishing ๐ฃ on: โ ๏ธhxxps[:]//facebok-facebook[.]blogspot[.]com/?m=1 ๐งฌ Analysis at: https:// urldna.io/scan/6abae3
Cybersecurity observers are warning about a suspected phishing site impersonating Facebook, hosted at a lookalike Blogspot address. The domain 'facebok-facebook.blogspot.com' uses a misspelling of the platform's name to trick users. A scan of the URL has been published on URLDNA so others can review the technical details. The warning is circulating among infosec communities, with users urged to treat the link as a scam and avoid entering any credentials.
- 34Ransomware group m3rx lists new alleged victimsโ๐จNew ransom group blog posts!๐จ Group name: m3rx Post title: iccsi.com Info: https:// cti.fyi/groups/m3rx.html Group name
The ransomware group m3rx has published new entries on its leak blog, naming iccsi.com, noonsugar.com and somasolucoes.com among its latest alleged victims. Cybersecurity threat-intelligence monitors flagged the posts, adding the group to tracked victim feeds. The listings imply the affected organisations now face data extortion demands, though the extent of the breaches and the companies' responses are not yet known.
- 35Microsoft-linked network spotted announcing IP space from OsloโASN: AS8075 Location: Oslo, NO Added: 2026-09-25T18:01 # shodansafari # infosec
Autonomous System 8075, the network operated by Microsoft, was observed announcing IP address space located in Oslo, Norway. The observation was logged and shared on 25 September 2026 with the cybersecurity community under the tag #shodansafari. This type of sighting is used by security researchers to track how large cloud and technology providers extend their network presence into new regions and data centre locations.