MikeTrendsTrends right now

search

infosec

Trends

  1. 1
    Hacker known as Rey arrested in Jordan, reported cooperation with FBI●By now, many of you may have already read the news that Saif al-Din Khader, aka “Rey” and “Hikki-Chan,” has been arresteMmastodonTechnologyCybersecurity42 d ago

    Saif al-Din Khader, known online as "Rey" and "Hikki-Chan," has been arrested in Jordan, according to reporting by Reuters journalists Raphael Satter, Dana Winter and Aj Vicens. Accounts in the cybersecurity community are circulating the news, saying he is allegedly cooperating with the FBI. Details about the charges remain limited so far.

  2. 2
    Meta Rushed to Fix VM Escape Flaw Before Muse Launch▼Is this related to one of our fellow Mastodonians running a server off their systems? # MetaMuse # Meta # Infosec # TechMmastodonTechnology97 h ago

    Meta reportedly patched a virtual machine escape vulnerability in its MetaMuse product immediately before launch, according to 404 Media reporting. A VM escape flaw would let code break out of an isolated virtual machine, a serious security risk. Users in infosec and tech communities are discussing the fix and whether it connects to a fellow Mastodon user known to run servers from their own systems.

  3. 3
    SEC-T conference badge powers on with a safety pin●The SEC-T badge this year was so cool! Instead of turning on with a switch, closing the safety pin on the back is what lMmastodonTechnology32 d ago

    Attendees at the SEC-T security conference are praising this year's attendee badge, which lights up when a safety pin on its back is closed rather than using a power switch. The clever hardware design has drawn delighted reactions from the infosec community, with hackers sharing the inventive touch online.

  4. 4
    GrapheneOS adds Secure Paste to block clipboard snooping●RE: https:// infosec.exchange/@lacze/117332 720535130953 System GrapheneOS otrzymał nową funkcję, która uniemożliwia aplMmastodonTechnologyMobile51 d ago

    GrapheneOS, the privacy-focused Android operating system, has rolled out a new feature called Secure Paste, which prevents apps from reading the contents of the clipboard. The system now lets users approve pasting on a per-app basis, blocking apps from silently harvesting clipboard data. The change is described as a significant security improvement, and it has drawn attention in the privacy and infosec community, where users welcome tighter control over what apps can access.

  5. 5
    ChainKeep targets timestamp tracking in digital investigations▼Every second matters in an investigation. ChainKeep makes sure every one of them is accounted for. ⏳ # ChainKeep # InfoSMmastodonTechnologyCybersecurity220 h ago

    ChainKeep, a tool aimed at digital forensics and incident response professionals, is being promoted with the message that every second matters in an investigation and that the software ensures every timestamp is accounted for. The pitch highlights chain-of-custody concerns in cybersecurity investigations, where accurate time records can determine whether evidence holds up. Discussion so far appears limited to infosec circles.

  6. 6
    Infosec newcomer introduces themselves on Mastodon▼Hello Mastodon! I'm into Computer # Security , # Programming , # ReverseEngineering , # Hacking , # Linux , # AmateurRadMmastodonTechnologyCybersecurity173 d ago

    A newcomer has introduced themselves to Mastodon's infosec community, listing interests including computer security, programming, reverse engineering, hacking, Linux, cryptography, privacy, open source and amateur radio, with a focus on technology that helps people communicate. The post is drawing modest engagement from the security-focused corner of the decentralized social network.

  7. 7
    Comparing Ireland's MyGovID with Denmark's CPR ID system●RE: https:// infosec.exchange/@cyberseckyle /117389340967928437 "Ireland's MyGovID and Denmark's CPR: A comparative analMmastodonTechnologyCybersecurity34 h ago

    A cybersecurity commentator has published a comparative analysis of Ireland's MyGovID and Denmark's CPR personal identifier systems, examining how the two countries handle digital identity. The piece touches on age verification, digital rights, GDPR and data protection, prompting discussion among privacy and security professionals about how national ID schemes balance convenience against citizen data risks.

  8. 8
    ATLSECCON cybersecurity conference set for Halifax in April 2027▼🆕 New event added: @ atlseccon 📌 ATLSECCON 📅 Apr 8-9, 2027 📍 Halifax (NS) 🇨🇦 🔗 https://www. atlseccon.com # infosec # cyMmastodonTechnologyCybersecurity15 d ago

    A new entry has been added to cybersecurity conference listings: ATLSECCON, taking place April 8-9, 2027 in Halifax, Nova Scotia, Canada. The Atlantic Canada security gathering is now on the calendar for infosec professionals planning next year's event schedule, with details available on its official website.

  9. 9
    Fake Facebook login page flagged in new phishing warning▼Possible Phishing 🎣 on: ⚠️hxxps[:]//facebooc-system[.]start[.]page 🧬 Analysis at: https:// urldna.io/scan/6abc5f333b7750MmastodonTechnologyCybersecurity15 d ago

    Security researchers are warning about a phishing site at the address facebooc-system.start.page, which imitates Facebook to steal login credentials. The deliberately misspelled domain on a free hosting service is a common scam pattern. An analysis of the site has been published on the URLDNA scanning platform, and the warning is circulating among infosec professionals.

  10. 10
    Moderate authentication bypass flaw disclosed in Red Hat maestro gRPC broker▼CVE-2026-71297 is a moderate authentication bypass in the maestro gRPC broker used by Red Hat Advanced Cluster ManagemenMmastodonTechnologyCybersecurity11 h ago

    CVE-2026-71297 describes a moderate authentication bypass in the maestro gRPC broker used by Red Hat Advanced Cluster Management and the Multicluster Engine. An attacker holding a valid client certificate could read other consumers' event streams or forge agent status reports. Security trackers and infosec communities are circulating the disclosure, with no confirmed exploitation reported so far.

  11. 11
    Discussion of claimed proof that memory hardness is irreversible▼Mathematical Proof that memory hardness is not reversible? https:// infosec.pub/post/52958081MmastodonBusinessCrypto15 d ago

    A claim of a mathematical proof that memory hardness cannot be reversed is circulating among cryptography and information security enthusiasts. The discussion centers on whether such a result would hold, since it would have implications for password hashing and memory-hard functions used to slow brute-force attacks. Details of the argument itself remain thin, and experts have yet to weigh in publicly on its validity.

  12. 12
    Security Researchers Flag Possible Phishing Site on GitBook▼Possible Phishing 🎣 on: ⚠️hxxp[:]//mtmskchrpmxtnsion[.]gitbook[.]io 🧬 Analysis at: https:// urldna.io/scan/6ac375363b775MmastodonTechnologyCybersecurity19 h ago

    Cybersecurity accounts are warning about a suspected phishing page hosted on a GitBook subdomain, sharing the address in defanged form so readers cannot accidentally click it. A scan link from the URL analysis service urlDNA has been attached, letting other researchers inspect the domain's infrastructure, hosting details and behaviour. The warning is circulating with standard tags like #phishing and #infosec.

  13. 13
    OnePlus 15 root exploit via audio debug service detailed●I'm reading Ramsus Moorats' article on how to "Getting root on OnePlus 15 from an untrusted app, via an audio debug servMmastodonTechnologyMobile02 d ago

    Security researcher Rasmus Moorats has published an article describing how to gain root on the OnePlus 15 from an untrusted app, exploiting an audio debug service and a vendor HAL. The write-up includes a notably dismissive response from OnePlus' PSIRT security team, which reportedly told the researcher that without official written authorisation the issue would not be addressed, sparking criticism of the company's vulnerability handling.

  14. 14
    Researchers flag suspected phishing site on Cloudways-hosted domain▼Possible Phishing 🎣 on: ⚠️hxxps[:]//wordpress-1644952-6533726[.]cloudwaysapps[.]com 🧬 Analysis at: https:// urldna.io/scMmastodonTechnologyCybersecurity114 h ago

    Cybersecurity researchers are warning about a suspected phishing website hosted on a Cloudways application domain (wordpress-1644952-6533726.cloudwaysapps.com). A link analysis of the address has been published on URLDNA so others can inspect the site's infrastructure. The warning is being circulated in infosec communities with the standard advice to treat the domain as unsafe.

  15. 15
    BitShot app promo video showcases crypto tracking process●And here is promo video for BitShot app, similar to an article I wrote earlier but showcasing the whole process with scrMmastodonBusinessCrypto05 d ago

    A security researcher has shared a promotional video for BitShot, an app demonstrating a complete screen-recorded process tied to bitcoin, OSINT and data scraping. The demo follows an earlier written article by the same person and highlights the tool's open-source approach to cryptocurrency monitoring and privacy-related security research.

  16. 16
    Security Researcher Flags Possible Phishing Site▼Possible Phishing 🎣 on: ⚠️hxxps[:]//mailer05-tra[.]mdbgo[.]io 🧬 Analysis at: https:// urldna.io/scan/6abff8ed3b77500 006MmastodonTechnologyCybersecurity13 d ago

    A cybersecurity researcher has raised an alert over a suspected phishing site hosted on the domain mailer05-tra.mdbgo.io, defanging the link to prevent accidental clicks. A scan report from URLDNA was shared alongside the warning so others can inspect the domain's technical details. The post circulated among infosec communities under phishing and scam tags.

  17. 17
    SECON security conference heads to Tokyo in February 2027▼🆕 New event added: 📌 SECCON 📅 Feb 20-21, 2027 📍 Tokyo 🇯🇵 🔗 https://www. seccon.jp/15/seccon_conference /open_conference_MmastodonTechnologyCybersecurity15 d ago

    The 15th SECCON open conference has been scheduled for February 20-21, 2027 in Tokyo. The Japanese cybersecurity event, run by the SECCON organization known for its capture-the-flag competitions, brings together security researchers and professionals. The announcement is circulating among infosec practitioners tracking upcoming industry conferences.

  18. 18
    Cisco security advisory flags zero-day SD-WAN web authentication flaw▼https:// sec.cloudapps.cisco.com/securi ty/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU # ZeroDaMmastodonTechnologyCybersecurity15 d ago

    A new Cisco security advisory is circulating among cybersecurity professionals, describing a vulnerability in Cisco SD-WAN's web authentication component labelled as a zero-day. Security commentators are sharing the advisory link on Infosec forums, tagging it with zero-day and SD-WAN hashtags, urging network administrators to review their Cisco SD-WAN deployments for the flaw and apply recommended mitigations or patches.

  19. 19
    Cybersecurity researchers flag fake DocuSign phishing site●Possible Phishing 🎣 on: ⚠️hxxp[:]//docusign-altroncommunications[.]webflow[.]io/ 🧬 Analysis at: https:// urldna.io/scan/MmastodonTechnologyCybersecurity119 h ago

    Security researchers are warning about a phishing site impersonating DocuSign, hosted on a Webflow domain that mimics the e-signature service. The suspicious link has been defanged to prevent accidental clicks, and a public URL analysis has been shared so others can inspect the site's infrastructure. Infosec communities are circulating the alert to help people avoid credential theft scams that use fake document-signing pages.

  20. 20
    Security Researchers Flag Suspected Phishing Domain●Possible Phishing 🎣 on: ⚠️hxxps[:]//messagerlev0cal8883900[.]fo[.]team 🧬 Analysis at: https:// urldna.io/scan/6ac0ee8f3bMmastodonTechnologyCybersecurity22 d ago

    Cybersecurity observers are warning about a suspected phishing site operating under the domain messagerlev0cal8883900.fo.team, a name that mimics Facebook Messenger's legitimate local addresses. The domain has been defanged and submitted to the URLdna scanning service for analysis, with the warning shared under cybersecurity and phishing tags. The deliberately confusing hostname suggests an attempt to trick users into entering login credentials on a fake page.

  21. 21
    Security researchers flag phishing site hosted on Weebly▼Possible Phishing 🎣 on: ⚠️hxxps[:]//esnetdeskfreenetserverservicesdkx[.]weebly[.]com 🧬 Analysis at: https:// urldna.io/sMmastodonTechnologyCybersecurity15 d ago

    Cybersecurity researchers are warning about a possible phishing site operating through a Weebly-hosted page that impersonates network or helpdesk services. The suspicious link has been defused and shared with a technical analysis via urldna.io so that other security professionals can inspect the domain and its infrastructure. The report has circulated in infosec communities, which frequently post such alerts to warn the public about scam pages before they spread more widely.

  22. 22
    Possible phishing site flagged impersonating Toronto Construction Association▼Possible Phishing 🎣 on: ⚠️hxxp[:]//tcaconnect[.]ac-page[.]com/toronto-construction-association-inc 🧬 Analysis at: https:MmastodonTechnologyCybersecurity15 d ago

    Cybersecurity researchers are warning of a possible phishing page hosted on a domain mimicking the Toronto Construction Association, shared via a defanged link and analyzed through the URLDNA scanning service. The alert circulates in infosec communities, urging recipients to avoid the link and verify any communications claiming to come from the association.

  23. 23
    Security researchers flag new phishing site using Weebly▼Possible Phishing 🎣 on: ⚠️hxxps[:]//securefirstjackson[.]weebly[.]com/ 🧬 Analysis at: https:// urldna.io/scan/6ac093c03bMmastodonTechnologyCybersecurity22 d ago

    Cybersecurity observers are warning about a suspected phishing site hosted on a Weebly subdomain imitating First Jackson, with a link-out to a URL analysis report. Alerts like this circulate regularly in infosec communities so defenders can block or take down malicious pages. The defanged link is shared to prevent accidental clicks while allowing others to verify the finding.

  24. 24
    Sarcastic jab at 'trusted' cybersecurity profiles in Poland●Profil taki Zaufany, profesjonalnie mocno, bardzo bezpieczeństwo, wow uszanowanko. # Polska # InfoSecMmastodonTechnologyCybersecurity131 d ago

    A Polish social media post is mocking self-important security-professional profiles, using exaggerated praise like 'trusted', 'very professional', 'super secure' and the ironic 'wow uszanowanko'. The sarcastic tone, tagged with Poland and InfoSec, plays on the trend of inflated credentials and buzzword-laden bios in the cybersecurity community, drawing amusement from readers.

  25. 25
    GrapheneOS update sparks privacy discussion among iPhone users▼@ GrapheneOS Thanks for the update👌🏼 GOS👍🏼 Is this true? 🤔 # iphone # apple # iOS # privacy # Security # infosec :ablobcMmastodonTechnologyCybersecurity31 d ago

    The privacy-focused Android project GrapheneOS has released an update, prompting users in the information security community to ask whether its claims about iPhone and Apple iOS privacy and security hold up. The update was shared alongside a 404 Media report, fuelling debate about how Apple's security practices compare with hardened custom Android systems.

  26. 26
    Security researchers flag possible phishing link on hipcv.com●Possible Phishing 🎣 on: ⚠️hxxps[:]//hipcv[.]com/r/G5VmpNMkFVpePKURdDtlG 🧬 Analysis at: https:// urldna.io/scan/6ac158733MmastodonTechnologyCybersecurity21 d ago

    Cybersecurity observers are warning about a suspected phishing link hosted on hipcv.com, a résumé and CV-related service. The URL has been defanged and shared with a link-analysis report on urldna.io so others can inspect its behaviour safely. People in the infosec community are urging caution before clicking such links, which are often spread through job or recruitment messages.

  27. 27
    Security Researchers Flag Phishing Page Hosted on GitHub Pages▼Possible Phishing 🎣 on: ⚠️hxxp[:]//cryptgmxnavigator[.]github[.]io/Pages/gx[.]html 🧬 Analysis at: https:// urldna.io/scaMmastodonTechnologyCybersecurity14 d ago

    Cybersecurity observers are warning about a suspected phishing site hosted on a GitHub Pages address, flagged as an attempt to trick users into handing over credentials or sensitive data. The alert includes a link to a URL analysis so others can inspect the page's behaviour. The warnings, shared in infosec circles, underline how attackers continue to abuse legitimate free hosting services to distribute scams.

  28. 28
    Phishing warning issued over malicious Google Slides link●Possible Phishing 🎣 on: ⚠️hxxps[:]//docs[.]google[.]com/presentation/d/e/2PACX-1vQtDdGcOPhuzmqinl-zROR_QZmTkYHXgVq8TEmqXMmastodonTechnologyCybersecurity23 d ago

    Cybersecurity researchers are flagging a phishing campaign hosted through a Google Slides sharing link. The URL has been defanged and submitted to a URL analysis service for inspection, and warnings are circulating among infosec accounts urging users not to open such links. The case highlights how attackers continue to abuse trusted Google-hosted pages to deliver scams.

  29. 29
    Tanuki open-source tool brings protocol-first Linux AD triage to AI agents●Excited to share a new open-source project: Tanuki 🦝 Protocol-first Linux Active Directory triage for AI coding agents &MmastodonTechnologyCybersecurity22 d ago

    A security researcher has released Tanuki, a new open-source tool described as protocol-first Linux Active Directory triage built for AI coding agents and operators. The developer says most coding agents hallucinate or propose noisy, dangerous tactics when handling Linux AD environments, such as recommending weak crypto settings. The project is being shared with the infosec community.

  30. 30
    InfoCon updates security conference talk archives●A big batch of updates in our Security Conferences Archives at # InfoCon , everything should be up and seeding + web strMmastodonTechnologyCybersecurity28 h ago

    InfoCon, an archive of security conference presentations, has added a large batch of updates covering talks from hacker and infosec events. The organisation says everything is now available for download and web streaming, with improved streaming performance. It plans to update its skills and documentaries collections next. The archive is free to access at infocon.org.

  31. 31
    Security flaw disclosed in AhsayCBS backup software●AhsayCBS https:// radar.offseq.com/threat/a-flaw -has-been-found-in-ahsay-ahsaycbs-up-to-1032-cve-2026-105134-a9f0def985MmastodonTechnologyCybersecurity315 h ago

    A vulnerability, tracked as CVE-2026-105134, has been reported in AhsayCBS, the backup software from Ahsay, affecting versions up to 10.3.2. The flaw was published on a threat-tracking service and is circulating among infosec communities, with security professionals flagging it for administrators who run Ahsay backup infrastructure. Details on severity and exploitation remain limited so far.

  32. 32
    ThreatsDay bulletin maps 16 mundane system operations turned attack vectors●The October 1 ThreatsDay bulletin maps 16 stories where ordinary system operations become attack vectors. The real riskMmastodonTechnologyCybersecurity12 d ago

    The October 1 ThreatsDay bulletin from Italian security outlet Deafnews compiles 16 cybersecurity stories showing how routine system operations can be weaponised as attack vectors. The piece argues the real danger lies in how banal such threats can be, prompting discussion among infosec professionals about overlooked everyday risks.

  33. 33
    Security researchers flag possible phishing site on Weebly▼Possible Phishing 🎣 on: ⚠️hxxps[:]//firstcsblog[.]weebly[.]com 🧬 Analysis at: https:// urldna.io/scan/6ac1205b3b77500 00MmastodonTechnologyCybersecurity21 d ago

    Cybersecurity observers are warning about a suspected phishing website hosted on a Weebly subdomain, firstcsblog.weebly.com. The alert was shared with a defanged link to prevent accidental visits, alongside a URL analysis report from urldna.io documenting the site's characteristics. The warning circulated with tags covering phishing, scams and infosec, urging others to avoid the address.

  34. 34
    Shodan hunt flags Tokyo network ASN AS2514●ASN: AS2514 Location: Tokyo, JP Added: 2026-09-29T21:49 # shodansafari # infosecMmastodonTechnologyCybersecurity212 h ago

    A newly indexed entry on the Shodan search engine lists AS2514, an autonomous system number located in Tokyo, Japan, added on 29 September 2026. Infosec practitioners use such ASN listings to track exposed services across a network operator's address space and assess what is publicly reachable.

  35. 35
    Security researchers flag phishing campaign hosted on Google Drawings●Possible Phishing 🎣 on: ⚠️hxxps[:]//docs[.]google[.]com/drawings/d/1mhjJHXA_69uh993SRr5QvxWSN1yYnDNolBbiror8T0c/edit 🧬 AMmastodonTechnologyCybersecurity13 d ago

    Cybersecurity analysts are warning about a suspected phishing link distributed through a Google Drawings document, with a scan published on the URLDNA analysis platform showing details of the flagged address. The warning circulated among infosec communities, with observers urged to treat unexpected Google Docs or Drawings links as potentially malicious and to verify such links before opening them.

  36. 36
    Hackfest cybersecurity event returns to Quebec City in October 2026●HACKFEST 18e ÉDITION : LES FORMATIONS SONT LÀ ! 📅 Du 26 au 29 octobre 2026, à l'Hôtel Palace Royal à Québec 💡 Pourquoi HMmastodonTechnologyCybersecurity220 h ago

    Hackfest, a cybersecurity conference, has announced its 18th edition, taking place October 26-29, 2026 at the Hôtel Palace Royal in Quebec City. Organizers say the training sessions are built by and for the community, with modules aimed at both curious beginners and seasoned professionals. Registration details for the hands-on courses are now being shared with the infosec community.

  37. 37
    Unistar-TELECOM network in Mexico City flagged on Shodan●ASN: AS8151 Location: Mexico City, MX Added: 2026-10-03T06:28 # shodansafari # infosecMmastodonTechnologyCybersecurity13 h ago

    A newly indexed entry on the Shodan search service lists AS8151, the autonomous system operated by Unistar-TELECOM in Mexico City, Mexico, with an addition timestamp of 6:28 UTC on October 3, 2026. The note circulated among cybersecurity practitioners using Shodan to browse for freshly exposed networks and services, a routine practice for spotting infrastructure changes.

  38. 38
    Security researchers flag suspected Amazon phishing domain●Possible Phishing 🎣 on: ⚠️hxxp[:]//amazoninvit[.]com 🧬 Analysis at: https:// urldna.io/scan/6abb5baf3b77500 0050fcbb3 #MmastodonTechnologyCybersecurity16 d ago

    Cybersecurity researchers are warning about a suspected phishing site at the domain amazoninvit.com, which impersonates Amazon, likely luring victims through fake invitation or delivery messages. The domain has been submitted for technical analysis on the URLdna scanning platform, and the warning is circulating in information security communities with phishing and scam alerts.

  39. 39
    Security Researchers Flag Phishing Site Impersonating Bancolombia▼Possible Phishing 🎣 on: ⚠️hxxps[:]//segurocardiffbancolh360[.]vercel[.]app/ 🧬 Analysis at: https:// urldna.io/scan/6abc9MmastodonTechnologyCybersecurity15 d ago

    Cybersecurity observers are warning of a phishing site hosted on a Vercel subdomain that imitates Bancolombia's customer portal, using a URL designed to look like the Colombian bank's official 'seguro' security page. The link has been defanged and shared with a public URL analysis scan so people can review its infrastructure. The alert circulates with standard infosec and scam warnings.

  40. 40
    Fake Wells Fargo login page flagged as phishing site▼Possible Phishing 🎣 on: ⚠️hxxps[:]//sites[.]google[.]com/view/wellsfargologinu 🧬 Analysis at: https:// urldna.io/scan/6aMmastodonTechnologyCybersecurity15 d ago

    Security researchers are flagging a fraudulent Wells Fargo login page hosted on a Google Sites address, designed to steal customers' banking credentials. The link has been defanged to prevent accidental clicks, and a public scan on URLDNA lets others inspect the site's characteristics. The warning has circulated among infosec community members tracking phishing campaigns.