search
infosec
Trends
- 1Hacker known as Rey arrested in Jordan, reported cooperation with FBI●By now, many of you may have already read the news that Saif al-Din Khader, aka “Rey” and “Hikki-Chan,” has been arreste
Saif al-Din Khader, known online as "Rey" and "Hikki-Chan," has been arrested in Jordan, according to reporting by Reuters journalists Raphael Satter, Dana Winter and Aj Vicens. Accounts in the cybersecurity community are circulating the news, saying he is allegedly cooperating with the FBI. Details about the charges remain limited so far.
- 2GrapheneOS adds Secure Paste to block clipboard snooping●RE: https:// infosec.exchange/@lacze/117332 720535130953 System GrapheneOS otrzymał nową funkcję, która uniemożliwia apl
GrapheneOS, the privacy-focused Android operating system, has rolled out a new feature called Secure Paste, which prevents apps from reading the contents of the clipboard. The system now lets users approve pasting on a per-app basis, blocking apps from silently harvesting clipboard data. The change is described as a significant security improvement, and it has drawn attention in the privacy and infosec community, where users welcome tighter control over what apps can access.
- 3ChainKeep targets timestamp tracking in digital investigations▼Every second matters in an investigation. ChainKeep makes sure every one of them is accounted for. ⏳ # ChainKeep # InfoS
ChainKeep, a tool aimed at digital forensics and incident response professionals, is being promoted with the message that every second matters in an investigation and that the software ensures every timestamp is accounted for. The pitch highlights chain-of-custody concerns in cybersecurity investigations, where accurate time records can determine whether evidence holds up. Discussion so far appears limited to infosec circles.
- 4SEC-T conference badge powers on with a safety pin●The SEC-T badge this year was so cool! Instead of turning on with a switch, closing the safety pin on the back is what l
Attendees at the SEC-T security conference are praising this year's attendee badge, which lights up when a safety pin on its back is closed rather than using a power switch. The clever hardware design has drawn delighted reactions from the infosec community, with hackers sharing the inventive touch online.
- 5Researchers flag suspected phishing site on Cloudways-hosted domain▼Possible Phishing 🎣 on: ⚠️hxxps[:]//wordpress-1644952-6533726[.]cloudwaysapps[.]com 🧬 Analysis at: https:// urldna.io/sc
Cybersecurity researchers are warning about a suspected phishing website hosted on a Cloudways application domain (wordpress-1644952-6533726.cloudwaysapps.com). A link analysis of the address has been published on URLDNA so others can inspect the site's infrastructure. The warning is being circulated in infosec communities with the standard advice to treat the domain as unsafe.
- 6Cybersecurity researchers flag fake DocuSign phishing site●Possible Phishing 🎣 on: ⚠️hxxp[:]//docusign-altroncommunications[.]webflow[.]io/ 🧬 Analysis at: https:// urldna.io/scan/
Security researchers are warning about a phishing site impersonating DocuSign, hosted on a Webflow domain that mimics the e-signature service. The suspicious link has been defanged to prevent accidental clicks, and a public URL analysis has been shared so others can inspect the site's infrastructure. Infosec communities are circulating the alert to help people avoid credential theft scams that use fake document-signing pages.
- 7Infosec newcomer introduces themselves on Mastodon▼Hello Mastodon! I'm into Computer # Security , # Programming , # ReverseEngineering , # Hacking , # Linux , # AmateurRad
A newcomer has introduced themselves to Mastodon's infosec community, listing interests including computer security, programming, reverse engineering, hacking, Linux, cryptography, privacy, open source and amateur radio, with a focus on technology that helps people communicate. The post is drawing modest engagement from the security-focused corner of the decentralized social network.
- 8Shodan hunt flags Tokyo network ASN AS2514●ASN: AS2514 Location: Tokyo, JP Added: 2026-09-29T21:49 # shodansafari # infosec
A newly indexed entry on the Shodan search engine lists AS2514, an autonomous system number located in Tokyo, Japan, added on 29 September 2026. Infosec practitioners use such ASN listings to track exposed services across a network operator's address space and assess what is publicly reachable.
- 9Security flaw disclosed in AhsayCBS backup software●AhsayCBS https:// radar.offseq.com/threat/a-flaw -has-been-found-in-ahsay-ahsaycbs-up-to-1032-cve-2026-105134-a9f0def985
A vulnerability, tracked as CVE-2026-105134, has been reported in AhsayCBS, the backup software from Ahsay, affecting versions up to 10.3.2. The flaw was published on a threat-tracking service and is circulating among infosec communities, with security professionals flagging it for administrators who run Ahsay backup infrastructure. Details on severity and exploitation remain limited so far.
- 10Hackfest cybersecurity event returns to Quebec City in October 2026●HACKFEST 18e ÉDITION : LES FORMATIONS SONT LÀ ! 📅 Du 26 au 29 octobre 2026, à l'Hôtel Palace Royal à Québec 💡 Pourquoi H
Hackfest, a cybersecurity conference, has announced its 18th edition, taking place October 26-29, 2026 at the Hôtel Palace Royal in Quebec City. Organizers say the training sessions are built by and for the community, with modules aimed at both curious beginners and seasoned professionals. Registration details for the hands-on courses are now being shared with the infosec community.
- 11New Shodan entry flags network AS5410 in Chartres●ASN: AS5410 Location: Chartres, FR Added: 2026-10-03T07:31 # shodansafari # infosec
A newly registered entry in the Shodan internet-exposure database records AS5410, an autonomous system located in Chartres, France, added on 3 October 2026. Security researchers share such sightings under the shodansafari hashtag to track new networks and exposed devices appearing online.
- 12Security experts vent over yet another default-password breach●Another breach writeup, another root cause that turns out to be a default password. Every single time. # infosec
Information security professionals are once again discussing a breach whose root cause was a device or account left running with its default password, expressing frustration that the same basic mistake keeps recurring across incident writeups. Commenters echo the sentiment that default credentials remain one of the most common and preventable causes of major security incidents, renewing calls for mandatory password changes and hardened defaults from vendors.
- 13Sarcastic jab at 'trusted' cybersecurity profiles in Poland●Profil taki Zaufany, profesjonalnie mocno, bardzo bezpieczeństwo, wow uszanowanko. # Polska # InfoSec
A Polish social media post is mocking self-important security-professional profiles, using exaggerated praise like 'trusted', 'very professional', 'super secure' and the ironic 'wow uszanowanko'. The sarcastic tone, tagged with Poland and InfoSec, plays on the trend of inflated credentials and buzzword-laden bios in the cybersecurity community, drawing amusement from readers.
- 14AS24940 in Falkenstein flagged on Shodan●ASN: AS24940 Location: Falkenstein, DE Added: 2026-10-01T18:57 # shodansafari # infosec
Autonomous system AS24940, hosted in Falkenstein, Germany, was added to a Shodan watchlist on October 1, 2026, drawing attention in information security circles. The ASN is associated with Hetzner Online, a major German hosting provider frequently cited in discussions about exposed servers and internet scanning. Security researchers are tracking the network for newly exposed devices and services.
- 15Security researcher flags fake Facebook login page●Possible Phishing 🎣 on: ⚠️hxxp[:]//facebooksecure[.]blogspot[.]com 🧬 Analysis at: https:// urldna.io/scan/6ac312f23b7750
Cybersecurity researchers are warning about a suspected phishing site operating at facebooksecure.blogspot.com, which imitates Facebook to steal login credentials. The domain, hosted on Blogspot, has been submitted for analysis on UrlDNA, where its scan results are being shared across infosec communities. Experts advise users to check web addresses carefully before entering Facebook passwords, as attackers frequently use free hosting services for such scams.
- 16Fake Facebook video share page flagged as phishing●Possible Phishing 🎣 on: ⚠️hxxps[:]//facebook-video-share[.]blogspot[.]com/?m=1 🧬 Analysis at: https:// urldna.io/scan/6a
Security researchers are warning about a phishing site hosted on a Blogspot domain impersonating Facebook video sharing. The URL, shared with defanged notation to prevent accidental clicks, has been submitted for automated analysis. Cybersecurity communities are circulating the alert to warn users not to enter Facebook credentials on the fake page.
- 17Security researchers flag possible phishing link on hipcv.com●Possible Phishing 🎣 on: ⚠️hxxps[:]//hipcv[.]com/r/G5VmpNMkFVpePKURdDtlG 🧬 Analysis at: https:// urldna.io/scan/6ac158733
Cybersecurity observers are warning about a suspected phishing link hosted on hipcv.com, a résumé and CV-related service. The URL has been defanged and shared with a link-analysis report on urldna.io so others can inspect its behaviour safely. People in the infosec community are urging caution before clicking such links, which are often spread through job or recruitment messages.
- 18OnePlus 15 root exploit via audio debug service detailed●I'm reading Ramsus Moorats' article on how to "Getting root on OnePlus 15 from an untrusted app, via an audio debug serv
Security researcher Rasmus Moorats has published an article describing how to gain root on the OnePlus 15 from an untrusted app, exploiting an audio debug service and a vendor HAL. The write-up includes a notably dismissive response from OnePlus' PSIRT security team, which reportedly told the researcher that without official written authorisation the issue would not be addressed, sparking criticism of the company's vulnerability handling.
- 19Shodan data flags Deutsche Telekom network in Reichenau●ASN: AS3320 Location: Reichenau, DE Added: 2026-10-03T01:34 # shodansafari # infosec
Network observers are discussing AS3320, the autonomous system number operated by Deutsche Telekom, with a data point logged in Reichenau, Germany. The entry, shared under security-research hashtags, is part of ongoing efforts to map exposed internet-connected devices by network and location. Little detail accompanies the record, so its significance for security researchers remains unclear.
- 20Japanese network AS2514 in Fukuoka draws security attention●ASN: AS2514 Location: Fukuoka, JP Added: 2026-10-02T14:31 # shodansafari # infosec
Cybersecurity observers are flagging AS2514, an autonomous system based in Fukuoka, Japan, noting its recent addition to network monitoring on 2 October 2026. Autonomous systems are large blocks of internet routing infrastructure, and new entries like this are often tracked by researchers scanning for exposed or misconfigured services. Details beyond the network's identifier and location are limited so far.
- 21Fake Roblox domain flagged as phishing campaign●Possible Phishing 🎣 on: ⚠️hxxps[:]//www[.]roblox[.]com[.]mu/communities/3145481831/BRAZILLIAN-SPYDER 🧬 Analysis at: http
Cybersecurity researchers are warning about a phishing site impersonating Roblox, hosted on the lookalike domain roblox.com.mu and advertising a community called 'BRAZILLIAN SPYDER'. An automated URL analysis of the address has been shared with the infosec community, which is passing the alert along so users avoid entering credentials on the fake page.
- 22Cybersecurity Researchers Examine Bellevue-Based Network AS18530●ASN: AS18530 Location: Bellevue, US Added: 2026-10-02T15:10 # shodansafari # infosec
Security researchers are cataloguing AS18530, an autonomous system number registered in Bellevue, United States, as part of ongoing internet infrastructure mapping efforts. The entry was logged in an open network-registry watchlist used by infosec practitioners to track newly observed or noteworthy networks. Such listings typically help analysts monitor hosting providers, spot suspicious infrastructure, and share reconnaissance data with the wider security community.
- 23AS4134 network in Nanjing flagged on threat feed●ASN: AS4134 Location: Nanjing, CN Added: 2026-09-30T10:48 # shodansafari # infosec
A cybersecurity feed entry lists AS4134, the autonomous system number operated by Chinanet, with a location in Nanjing, China, timestamped 30 September 2026. The entry carries no further detail on why the network was added or what activity was observed on it. AS4134 is one of China's largest backbone networks, so listing it as a location marker rather than a threat indicator is unusual.
- 24Security researchers flag phishing site disguised as Kindle page●Possible Phishing 🎣 on: ⚠️hxxp[:]//onlineseminary[.]info/kindle/8mobile_firefox[.]html 🧬 Analysis at: https:// urldna.io
Cybersecurity watchers are warning about a phishing link hosted on the domain onlineseminary.info, which appears to target mobile Firefox users under a Kindle-themed lure. The warning includes a link to a public URL analysis report so others can inspect the site's behaviour. The domain name suggests the attackers may be impersonating a religious education institution to appear trustworthy.
- 25Paris-based network AS12876 surfaces in security scans●ASN: AS12876 Location: Paris, FR Added: 2026-09-30T14:45 # shodansafari # infosec
AS12876, an autonomous system based in Paris, France, was logged in an internet-wide network scan entry dated 30 September 2026. The autonomous system is associated with Scaleway, a French cloud and hosting provider. Cybersecurity practitioners track such networks to map exposed services and infrastructure, and the entry circulated among information security observers who follow scan-based reconnaissance of internet-facing systems.
- 26Security Researchers Flag Suspected Phishing Domain●Possible Phishing 🎣 on: ⚠️hxxps[:]//messagerlev0cal8883900[.]fo[.]team 🧬 Analysis at: https:// urldna.io/scan/6ac0ee8f3b
Cybersecurity observers are warning about a suspected phishing site operating under the domain messagerlev0cal8883900.fo.team, a name that mimics Facebook Messenger's legitimate local addresses. The domain has been defanged and submitted to the URLdna scanning service for analysis, with the warning shared under cybersecurity and phishing tags. The deliberately confusing hostname suggests an attempt to trick users into entering login credentials on a fake page.
- 27Shodan entry flags OVH network node in Bexley●ASN: AS16276 Location: Bexley, GB Added: 2026-09-29T22:18 # shodansafari # infosec
Cybersecurity observers are sharing a Shodan monitoring entry for AS16276, the network of French hosting provider OVHcloud, showing a location in Bexley in the United Kingdom, added on 29 September 2026. The listing is circulating among infosec practitioners as part of routine network reconnaissance and exposure-tracking activity.
- 28GrapheneOS update sparks privacy discussion among iPhone users▼@ GrapheneOS Thanks for the update👌🏼 GOS👍🏼 Is this true? 🤔 # iphone # apple # iOS # privacy # Security # infosec :ablobc
The privacy-focused Android project GrapheneOS has released an update, prompting users in the information security community to ask whether its claims about iPhone and Apple iOS privacy and security hold up. The update was shared alongside a 404 Media report, fuelling debate about how Apple's security practices compare with hardened custom Android systems.
- 29New Dhaka-Based Autonomous System Registered in Bangladesh●ASN: AS200740 Location: Dhaka, BD Added: 2026-10-02T16:00 # shodansafari # infosec
Autonomous system AS200740, registered to a location in Dhaka, Bangladesh, was added to the internet routing table on 2 October 2026. Cybersecurity researchers who track newly announced networks using Shodan are flagging the registration, a routine practice for spotting infrastructure that could be repurposed for hosting, proxies or malicious activity. No confirmed operator or purpose has been disclosed yet.
- 30Security researchers flag new phishing site using Weebly▼Possible Phishing 🎣 on: ⚠️hxxps[:]//securefirstjackson[.]weebly[.]com/ 🧬 Analysis at: https:// urldna.io/scan/6ac093c03b
Cybersecurity observers are warning about a suspected phishing site hosted on a Weebly subdomain imitating First Jackson, with a link-out to a URL analysis report. Alerts like this circulate regularly in infosec communities so defenders can block or take down malicious pages. The defanged link is shared to prevent accidental clicks while allowing others to verify the finding.
- 31Security researchers flag possible phishing site on Weebly▼Possible Phishing 🎣 on: ⚠️hxxps[:]//firstcsblog[.]weebly[.]com 🧬 Analysis at: https:// urldna.io/scan/6ac1205b3b77500 00
Cybersecurity observers are warning about a suspected phishing website hosted on a Weebly subdomain, firstcsblog.weebly.com. The alert was shared with a defanged link to prevent accidental visits, alongside a URL analysis report from urldna.io documenting the site's characteristics. The warning circulated with tags covering phishing, scams and infosec, urging others to avoid the address.
- 32Suspected ShinyHunters member 'Rey' reportedly arrested in Jordan●Word is that "Rey," a suspected ShinyHunters member, was picked up in Jordan and is talking to the FBI; the CISO boards
Reports circulating in the cybersecurity community claim that a suspected member of the ShinyHunters hacking group, known online as 'Rey,' was detained in Jordan and is now cooperating with the FBI. The news is being shared among infosec professionals, with commenters noting it looks like a significant step forward against the group.
- 33Security researchers flag shortened phishing link●Possible Phishing 🎣 on: ⚠️hxxps[:]//ppt[.]cc/fgcMAx 🧬 Analysis at: https:// urldna.io/scan/6ac28de63b77500 00925838c # c
Cybersecurity watchers are circulating a warning about a possible phishing site hidden behind the shortened URL ppt.cc/fgcMAx, advising people not to click it. The link has been submitted to URLDNA for analysis, and the alert is being shared in infosec circles under phishing, scam and cybersecurity tags.
- 34Phishing site impersonating Air Miles rewards service flagged●Possible Phishing 🎣 on: ⚠️hxxps[:]//airmilesrewardsserviceoauth[.]weebly[.]com 🧬 Analysis at: https:// urldna.io/scan/6a
A security researcher has flagged a suspected phishing website hosted on a Weebly domain that impersonates an Air Miles rewards service login. The fake address, airmilesrewardsserviceoauth.weebly.com, was defanged to prevent accidental clicks, and a technical analysis of the site has been published via URLDNA. The warning is circulating among cybersecurity and infosec communities, who are urging users to avoid entering credentials on such pages.
- 35Security researchers flag possible phishing site on premiumisp.net●Possible Phishing 🎣 on: ⚠️hxxps[:]//s[.]eu[.]premiumisp[.]net/107519/8af662/475d964a-0243-46bf-aefd-66da26254efa/ 🧬 Anal
Cybersecurity analysts are circulating a warning about a suspected phishing page hosted on a subdomain of premiumisp.net, sharing a defanged link and pointing followers to a URL analysis scan for details. The alert is being passed around infosec circles, with little additional context about who is being targeted or how the link is spreading.
- 36German Green politician's infosec idea draws support online●RE: https:// gruene.social/@sven/1173781578 04337854 Ui das klingt doch nach einer mega Idee o.O Geren # rt für mehr Fee
Sven, a member of the German Greens posting on gruene.social, has floated an idea in the infosec and sysadmin field that a fellow administrator is publicly endorsing as a strong one. The supporter is calling for more feedback and greater reach for the proposal, using the hashtags admin and infosec. The details of the idea itself are not spelled out in the exchange.
- 37Bandung network ASN AS9341 flagged by security researchers●ASN: AS9341 Location: Bandung, ID Added: 2026-10-01T17:03 # shodansafari # infosec
Cybersecurity watchers are sharing details on AS9341, an autonomous system number registered in Bandung, Indonesia, listed on 1 October 2026 under the Shodan Safari tag. The hashtag refers to browsing Shodan, the search engine for internet-exposed devices, to spot vulnerable hosts by network. No specific vulnerability or incident has been named publicly so far.
- 38Security Researchers Flag Possible Phishing Site●Possible Phishing 🎣 on: ⚠️hxxps[:]//site235744746[.]fo[.]team 🧬 Analysis at: https:// urldna.io/scan/6ac10ab53b77500 008
Cybersecurity watchers are warning about a possible phishing site hosted on a suspiciously numbered subdomain of fo.team, a service often used to spin up quick temporary websites. The address has been shared in defanged form so others cannot accidentally click it, alongside a link to an automated URL analysis so people can inspect the site's behaviour. The alert is spreading through infosec communities where researchers routinely exchange indicators of compromise, scanning results, and warnings about newly created scam pages.
- 39CloudSEK to feature at BSides VI 2026 security conference●🌐 Learn more about CloudSEK: https://www. cloudsek.com # BSidesVI2026 # CyberSecurity # InfoSec # ThreatIntelligence
CloudSEK, a threat intelligence company, is promoting its participation in BSides VI 2026, a community-run cybersecurity conference. The company, which specializes in AI-driven threat intelligence and digital risk protection, is inviting attendees to learn more about its work ahead of the event. The announcement is circulating among information security professionals online.
- 40Security researchers flag weebly-hosted webmail phishing page●Possible Phishing 🎣 on: ⚠️hxxps[:]//webmailaclyonfriwcstaticc11nalldomainlayoufr[.]weebly[.]com 🧬 Analysis at: https://
Cybersecurity analysts are warning of a suspected phishing site hosted on weebly.com that impersonates a French webmail login page, apparently designed to steal email credentials. The suspicious URL was shared defanged with a link to an automated analysis on the URLdna scanning service. The warning circulated among infosec practitioners with the standard advice to treat such login pages with caution.