search
cybersecurity researchers
Trends
- 1Study finds security flaws in next-generation vehicle technology▼Study uncovers security weaknesses in next-generation vehicle technology
A new study has uncovered security weaknesses in next-generation vehicle technology, raising concerns about the safety of connected and increasingly software-driven cars. As vehicles rely more on networked systems for navigation, communication and control, researchers warn that these vulnerabilities could expose drivers to potential exploitation. The findings add to a growing debate about whether the automotive industry is moving fast enough to secure modern vehicles against cyber threats.
- 2Researcher Says He Could Have Accessed 17 Trillion Microsoft Records●I Could've Accessed 17T Microsoft Records
A security researcher has published a write-up claiming he could have accessed 17 trillion Microsoft records through a vulnerability, and that the flaw has since been resolved. The technical blog post details how the exposure was found, and it is drawing attention in the cybersecurity community as another example of the scale of data accessible through misconfigured cloud services.
- 3SECON security conference heads to Tokyo in February 2027▼🆕 New event added: 📌 SECCON 📅 Feb 20-21, 2027 📍 Tokyo 🇯🇵 🔗 https://www. seccon.jp/15/seccon_conference /open_conference_
The 15th SECCON open conference has been scheduled for February 20-21, 2027 in Tokyo. The Japanese cybersecurity event, run by the SECCON organization known for its capture-the-flag competitions, brings together security researchers and professionals. The announcement is circulating among infosec practitioners tracking upcoming industry conferences.
- 4The 'WarGames' problem: what computer science knows about controlling AI●The ‘War Games’ problem: Computer science has long understood what it takes to keep # AI under control https:// theconve
An essay in The Conversation revisits the 1983 film 'WarGames' to explain a long-standing lesson of computer science: keeping AI under control is a well-studied problem, not an unsolvable mystery. It argues researchers have long understood what is needed to keep automated systems from acting unpredictably, and the piece is being shared in cybersecurity circles amid ongoing debate over AI safety.
- 5Fake PayPal login page flagged as phishing threat▼Possible Phishing 🎣 on: ⚠️hxxp[:]//paypal-logiin[.]blogspot[.]com/2021/02?m=1 🧬 Analysis at: https:// urldna.io/scan/6ab
Cybersecurity researchers are warning about a phishing site impersonating PayPal, hosted on a Blogspot address designed to mimic a legitimate PayPal login page. The fake domain uses a deliberately misspelled URL to trick users into entering their credentials. The site has been submitted for technical analysis, and security experts are urging people to check web addresses carefully before logging into financial accounts.
- 6Possible phishing site flagged impersonating Toronto Construction Association▼Possible Phishing 🎣 on: ⚠️hxxp[:]//tcaconnect[.]ac-page[.]com/toronto-construction-association-inc 🧬 Analysis at: https:
Cybersecurity researchers are warning of a possible phishing page hosted on a domain mimicking the Toronto Construction Association, shared via a defanged link and analyzed through the URLDNA scanning service. The alert circulates in infosec communities, urging recipients to avoid the link and verify any communications claiming to come from the association.
- 7Security researcher flags fake Amazon domain▼Possible Phishing 🎣 on: ⚠️hxxps[:]//amazon-arrived[.]com 🧬 Analysis at: https:// urldna.io/scan/6abca5ba3b77500 00955bde
A cybersecurity researcher has flagged a suspicious website at the address amazon-arrived.com as likely phishing, warning that the domain mimics Amazon to deceive visitors. An automated analysis of the URL has been published via the URLDNA scanning service. The alert is being shared within the infosec community, where users are cautioning others not to click links or enter credentials on the site.
- 8Fake Exodus wallet support page flagged as phishing site▼Possible Phishing 🎣 on: ⚠️hxxps[:]//exodus-help-wlt-chiky[.]wasmer[.]app 🧬 Analysis at: https:// urldna.io/scan/6abc910c
Cybersecurity researchers are warning about a phishing site impersonating Exodus wallet support, hosted at exodus-help-wlt-chiky.wasmer.app. The domain was defanged and shared with a link to a URLDNA analysis so others can inspect it. The site follows a common pattern of fraudulent crypto wallet help pages designed to steal users' seed phrases or credentials.
- 9Fake Facebook login page flagged in new phishing warning▼Possible Phishing 🎣 on: ⚠️hxxps[:]//facebooc-system[.]start[.]page 🧬 Analysis at: https:// urldna.io/scan/6abc5f333b7750
Security researchers are warning about a phishing site at the address facebooc-system.start.page, which imitates Facebook to steal login credentials. The deliberately misspelled domain on a free hosting service is a common scam pattern. An analysis of the site has been published on the URLDNA scanning platform, and the warning is circulating among infosec professionals.
- 10Kean University Wins $500,000 NSF Grant for CyberAI Research▼Kean University Awarded $500,000 NSF Grant to Advance CyberAI Education and Research
Kean University in New Jersey has been awarded a $500,000 grant from the National Science Foundation to advance education and research in CyberAI, the intersection of cybersecurity and artificial intelligence. The funding will support developing programs and research opportunities in a field facing growing demand for trained specialists. The university announced the award as a step toward expanding its technology curriculum.
- 11Google Says AI Is Reshaping How Vulnerabilities Are Found●Google: AI Is Changing the Pace and Profile of Vulnerability Discovery
Google says artificial intelligence is changing both the speed and the character of vulnerability discovery in cybersecurity, allowing flaws in software to be identified and reported far faster than with traditional methods. According to SecurityWeek, the company argues this acceleration is altering the profile of bugs researchers and defenders encounter, with implications for how organisations patch and prioritise security work.
- 12Zero-day in third-party vendor exposed Belgian research network Belnet emails for two months●✨ Due mesi di silenzio: uno zero-day su un fornitore terzo apre le caselle email della rete belga Belnet # CyberSecurity
A zero-day vulnerability in a third-party supplier allowed attackers to open email mailboxes on Belnet, Belgium's national research and education network, with the intrusion reportedly going unnoticed for two months. The case is drawing attention from the cybersecurity community as a reminder of supply-chain risk, since the flaw sat outside Belnet's own systems while its users' communications were exposed.
- 13Security Researchers Flag Possible Phishing Site on Weebly▼Possible Phishing 🎣 on: ⚠️hxxps[:]//nnbxv[.]weebly[.]com 🧬 Analysis at: https:// urldna.io/scan/6abc7b5a3b77500 00653a6c
Cybersecurity observers are warning about a suspected phishing page hosted at a Weebly web address, sharing a link to a detailed technical analysis of the site on the URLDNA scanning platform. The address has been defanged to prevent accidental clicks. The warning is being circulated in information security communities alongside standard scam and phishing alert tags.
- 14Warning issued over phishing link disguised as Google Docs presentation▼Possible Phishing 🎣 on: ⚠️hxxps[:]//docs[.]google[.]com/presentation/d/e/2PACX-1vQ4JqNki4NYPJowqvSnDa0dUaoYHsAeJBMw02Vtj
Cybersecurity researchers are flagging a possible phishing campaign hosted through a Google Docs presentation link. The URL, shared in defanged form, points to a public Google Slides page that may be used to lure victims into handing over credentials or personal data. A full technical analysis of the link has been published on a URL scanning service. Users are advised to treat unexpected Google Docs links with caution.
- 15Fake Facebook phishing site flagged by security researchers●Possible Phishing 🎣 on: ⚠️hxxps[:]//facebook-eu[.]blogspot[.]com/?m=1 🧬 Analysis at: https:// urldna.io/scan/6abcb39a3b7
Security researchers are warning of a phishing site impersonating Facebook, hosted on the address facebook-eu.blogspot.com. The Blogspot domain is a common tactic to lend fake pages legitimacy. The site was submitted to the URLdna scanning service for analysis, and the warning was shared in cybersecurity circles with tags for phishing, scams and infosec. Users are advised to avoid the link and verify Facebook logins only via the official domain.
- 16Study Links Internet Addiction to Cybersecurity Risk▼Internet Addiction Disorder and Cybersecurity Risk: A Neurobiological and Behavioral Review
A newly published academic review examines the connection between Internet Addiction Disorder and cybersecurity risk, drawing on neurobiological and behavioral research. The paper argues that compulsive internet use patterns may increase vulnerability to online threats, adding to ongoing debate among researchers and technology commentators about how excessive digital habits affect security and wellbeing.
- 17FIFA 18 coin site flagged as suspected phishing scam▼Possible Phishing 🎣 on: ⚠️hxxps[:]//coinsfifa18[.]weebly[.]com 🧬 Analysis at: https:// urldna.io/scan/6abc897f3b77500 00
Security researchers are warning about a suspected phishing site hosted on a Weebly subdomain that offers FIFA 18 in-game coins, a common lure used to steal credentials or payment details from players. A technical analysis of the page has been published via a URL scanning service, defanging the link so others can inspect it safely. Users are urged to avoid entering account or card information on sites promising cheap game currency.
- 18Storm ransomware group lists new alleged victims▼🚨New ransom group blog posts!🚨 Group name: Storm Post title: The Money Store Info: https:// cti.fyi/groups/Storm.html Gr
The Storm ransomware group has added new entries to its leak site, naming The Money Store, Silvercup Studios and Century Management Services among its latest claimed victims. The listings were flagged by threat intelligence monitors who track ransomware group blogs. Ransomware crews routinely publish victim names to pressure companies into paying, and each new post typically prompts checks by security researchers and affected firms.
- 19Phishing Warning Issued for Google Docs Drawing Link▼Possible Phishing 🎣 on: ⚠️hxxps[:]//docs[.]google[.]com/drawings/d/1gpJivSsThHrL10szmVZFyBMdW6Lmi6oghTnGmLmgQBk/edit 🧬 A
Cybersecurity researchers are flagging a malicious Google Docs Drawings link being used in a suspected phishing campaign. The URL has been defanged and submitted for automated analysis on the urlDNA scanning platform, which examines page behavior and infrastructure for signs of fraud. Security professionals are sharing the warning to alert others not to open the link and to illustrate how attackers abuse trusted Google services to lend credibility to scams.
- 20AI giants accused of hypocrisy over warnings on open models●The new AI conglomerates are publishing documents warning about the dangers of semi-open models that defenders can actua
AI conglomerates are publishing documents warning about the dangers of semi-open models that defenders can actually use, while restricting defenders' access to their own proprietary models. Security researchers say the stance undermines the cybersecurity community, which relies on open access to study and defend against model vulnerabilities. Critics see it as a double standard: open models are framed as risky precisely when they enable independent defence work.
- 21Two Critical Citrix NetScaler Zero-Days Exploited in the Wild●⚠️ CRITICAL: Dual NetScaler Zero-Days Trigger Chaos for Citrix Customers Two critical zero-day vulnerabilities in Citrix
Security researchers report two critical zero-day vulnerabilities in Citrix NetScaler that are being actively exploited. Attackers can gain broad network access on affected systems, with default configurations said to be especially exposed. Citrix customers are urged to check their appliances and apply mitigations immediately as details of the flaws spread through the cybersecurity community.
- 22Russian hacking group Star Blizzard expands targets and tactics▼Russian hackers Star Blizzard expand targeting, change up tactics to reach Ukraine and beyond
The Russia-aligned hacking group Star Blizzard is broadening its targeting beyond its usual victims and changing its tactics, extending operations from Ukraine to a wider range of countries. The group, previously linked to spear-phishing campaigns against researchers, journalists and government figures, is being monitored by cybersecurity analysts tracking its evolving methods and expanding reach.
- 23Fake Wells Fargo login page flagged as phishing site▼Possible Phishing 🎣 on: ⚠️hxxps[:]//sites[.]google[.]com/view/wellsfargologinu 🧬 Analysis at: https:// urldna.io/scan/6a
Security researchers are flagging a fraudulent Wells Fargo login page hosted on a Google Sites address, designed to steal customers' banking credentials. The link has been defanged to prevent accidental clicks, and a public scan on URLDNA lets others inspect the site's characteristics. The warning has circulated among infosec community members tracking phishing campaigns.
- 24Arezzo network flagged in cybersecurity discussion●ASN: 49709 Location: Arezzo, IT Added: 2026-09-29T13:52 # shodansafari # infosec
A newly registered network in Arezzo, Italy, operating under autonomous system number 49709, is being flagged in cybersecurity circles. Security researchers monitor newly announced ASNs closely, since fresh allocations can host previously unseen services and are often scanned for exposed systems, misconfigurations, and potential malicious activity shortly after going online.
- 25Security researchers flag phishing site hosted on Weebly▼Possible Phishing 🎣 on: ⚠️hxxps[:]//esnetdeskfreenetserverservicesdkx[.]weebly[.]com 🧬 Analysis at: https:// urldna.io/s
Cybersecurity researchers are warning about a possible phishing site operating through a Weebly-hosted page that impersonates network or helpdesk services. The suspicious link has been defused and shared with a technical analysis via urldna.io so that other security professionals can inspect the domain and its infrastructure. The report has circulated in infosec communities, which frequently post such alerts to warn the public about scam pages before they spread more widely.
- 26Federal agencies already making decisions on quantum computing▼Federal agencies are already making decisions about quantum computing
US federal agencies are reportedly moving ahead with concrete decisions on quantum computing, covering adoption, procurement and preparedness for quantum-era cybersecurity. The development signals that quantum technology is shifting from research interest to operational planning across government, with agencies weighing both the opportunities of quantum systems and the security risks posed by future quantum decryption capabilities.
- 27Newly exposed host spotted in Fremont data centre●ASN: 63949 Location: Fremont, US Added: 2026-09-29T13:59 # shodansafari # infosec
Security researchers are flagging an internet-facing host registered to ASN 63949, a network range operated by Linode in Fremont, California, that was indexed on 29 September 2026. The finding circulated in information security circles under the shodansafari hashtag, where practitioners share and discuss newly exposed servers, open ports and misconfigured devices discovered through internet-wide scanning.
- 28New ransomware group 'm3rx' lists Polish company intense.pl as victim▼🚨New ransom group blog post!🚨 Group name: m3rx Post title: intense.pl Info: https:// cti.fyi/groups/m3rx.html # ransomwa
Threat intelligence trackers report a newly surfaced ransomware group calling itself m3rx has published a blog post naming intense.pl, a Polish company, as its latest victim. The claim is being circulated among cybersecurity researchers monitoring ransomware leak sites, with details on the group still sparse. Analysts will be watching for confirmation from the targeted firm and for signs of further activity by the gang.
- 29Security Researchers Flag Phishing Site Hosted on Google Sites▼Possible Phishing 🎣 on: ⚠️hxxps[:]//sites[.]google[.]com/view/oiuiruieor98490krejjkljklejkef/home 🧬 Analysis at: https:/
Cybersecurity researchers are warning about a phishing page hosted on Google Sites, sharing a defanged link and a scan report on urlDNA for analysis. The alerts circulated in infosec channels, with warnings that the site is designed to deceive visitors into handing over credentials or personal data. The use of a legitimate Google domain highlights how attackers exploit trusted hosting services.
- 30DARPA Picks Xint to Bring AI to Secure Military Messaging●DARPA Selects Xint to Use AI in Securing Military Messaging Apps
DARPA has selected Xint to apply artificial intelligence to securing military messaging applications. The defense research agency's move points to growing interest in hardening communications used by armed forces against interception and tampering. Details on the program scope and funding were not provided in initial coverage, but the selection places Xint among contractors working on next-generation secure communications for the US military.
- 31Fake iPhone Duo preorder scam used to spread DarkSword malware●Fake iPhone Duo preorder scam triggers DarkSword attack
Cybersecurity researchers report a scam website posing as a preorder page for an iPhone Duo, which is not a real Apple product. Visitors lured into entering payment or personal details are then targeted with DarkSword, a malicious software attack. The scheme appears designed to exploit hype around new iPhone launches to trick buyers into downloading malware.
Repos
- JoasASantos/Offensive-Security-AI-Models Uncensored AI models or those fine-tuned for cybersecurity tasks.