#cyberattack

61 posts · Last used 5d

Back to Timeline
Alonso Caballero / ReYDeS @Alonso_ReYDeS@infosec.exchange · 5d ago
🔎 Curso de OSINT - Open Source Intelligence 2026 📅 Miércoles 12, Viernes 14, Miércoles 19 y Viernes 21 de Agosto 🕖 De 8:00 pm a 11:00 pm (UTC -05:00) 📲 WhatsApp: https://wa.me/51949304030 🌐 Información: https://www.reydes.com/archivos/cursos/Curso_OSINT_Open_Source_Intelligence.pdf #osint #infosec #threatintel #socmint #cybersecurity #geoint #cyberattack #databreach
0
0
0
Linuxiarze @Linuxiarze@mastodon.social · 6d ago
Nowe złośliwe oprogramowanie dla systemu Android może potajemnie opróżnić Twoje konta bankowe.Naukowcy odkryli nowe złośliwe oprogramowanie, które uzyskuje głęboki dostęp do telefonu i uzyskuje... https://linuxiarze.pl/nowe-zlosliwe-oprogramowanie-dla-systemu-android-moze-potajemnie-oproznic-twoje-konta-bankowe/ #cybersecurity #cyberattack #spartphone #android
0
0
0
gypsyvegan @gypsyvegan@sfba.social · Aug 05, 2026

THREAT MODEL: CYBERSECURITY 🧑‍💻 for August 4th, 2026 by independent journalist @violetblue@mastodon.social

...and much more.

✨THREAT MODEL weekly newsletters are free to read -- please help keep them accessible to all by becoming a patron, even $1 a month makes a difference!✨

https://www.patreon.com/violetblue/posts/cybersecurity-4-165719362

#ThreatModel #ThreatModelCybersecurity #ThreatModelNewsletters #VioletBlue #infosec #cybersec #CovidIsNotOver

7
0
6
Eugene McParland 🇺🇦 @EugeneMcParland@mastodon.ie · Aug 06, 2026
Weeks before they escaped a closed test and launched a #cyberattack without any human prompting, some of OpenAI’s most advanced artificial intelligence agents secretly began sharing tips on how to cheat their way through an internal hacking evaluation 🖊️ Dana Nickel and John Sakellariadis https://www.politico.eu/article/openais-models-shared-hacking-tips-on-a-secret-messaging-board-before-hugging-face-breach
5
0
7
DysruptionHub @DysruptionHub@infosec.exchange · Aug 04, 2026
0
0
0
Alonso Caballero / ReYDeS @Alonso_ReYDeS@infosec.exchange · Aug 04, 2026
🐞 Hoy Martes 4 Agosto a las 8:00 pm (UTC -05:00) iniciamos el Curso Análisis de Malware 2026 🐛 🥇 Martes 4 y Jueves 6 de Agosto ✨ De 8:00 pm a 11:00 pm (UTC -05:00) 📲 WhatsApp: https://wa.me/51949304030 🌎 Información: https://www.reydes.com/e/Curso_Analisis_Malware #malware #ransomware #phishing #cyberattack #cybersecurity #endpointsecurity #infosec
0
0
0
AA @AAKL@infosec.exchange · Aug 04, 2026
0
0
0
AA @AAKL@infosec.exchange · Aug 03, 2026
New. True or false, the easiest thing to do is to blame a foreign country. But it's important to remember that this happened in the embattled state of Minnesota. Things being as they are, nothing should be off the table. "Attribution remains open. Minnesota state and local officials declined to say who was responsible, and TJ Sayers, senior director of threat intelligence at the Center for Internet Security, confirmed the attacks had not been attributed to any party and that it was unclear whether the PLCs CISA warned about were involved." Picus: Minnesota Water Systems Attacks: Internet-Exposed PLCs Under Attack https://www.picussecurity.com/resource/blog/minnesota-water-systems-attacks-internet-exposed-plcs-under-attack #infosec #threatresearch #cyberattack
0
0
0
AA @AAKL@infosec.exchange · Aug 03, 2026
New. "While headlines focused on an AI model escaping its test environment, the real lesson is that security failures still begin with ordinary mistakes and overlooked exposure." "Behind the AI headlines are familiar attack paths: vulnerable software, stolen credentials and permissive access." Barracuda: Faster, not different: What the Hugging Face AI incident really means for organizations https://blog.barracuda.com/2026/08/03/hugging-face-incident-faster-not-different Related, from yesterday: Socket: Claude Breached 3 Companies and Uploaded Malware to PyPI During Anthropic's Security Tests https://socket.dev/blog/anthropic-claude-pypi-malware @SocketSecurity@fosstodon.org #infosec #HuggingFace #cyberattack #Claude #OpenAI #Anthropic #malware #Python
0
0
0
AA @AAKL@infosec.exchange · Jul 31, 2026
Did you miss this yesterday? Anthropic is increasingly looking like a comic book villain, right next to the neophyte OpenAI villains. "My LLM hacked more targets than your puny LLM." "No, mine hacked more." "I dare you." Politico: Anthropic's AI models hacked 3 organizations during testing https://www.politico.com/news/2026/07/30/anthropic-ai-rogue-hacks-01018741 @politico@flipboard.com #Anthropic #infosec #cyberattack #OpenAI
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 31, 2026
AnMed malware cyberattack forces clinic closures in South Carolina. Discover how this digital breach disrupted medical services and emergency patient care. #AnMed #Cyberattack #Malware #HealthcareSecurity https://meterpreter.org/anmed-malware-cyberattack/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
DoomsdaysCW @DoomsdaysCW@kolektiva.social · Jul 30, 2026
So, #MSM is parroting #Trump administration's accusations that #Iran was behind the #Cyberattack on water systems in #Minnesota. Sounds like a good excuse to wipe out #WaterResources in Iran as revenge! Plus, similar incidents have happened in #MN. Who has a big grudge against folks in Minnesota? Not Iran!!! Cyberattack targets Minnesota cities' water systems "State technology officials say more than 30 Minnesota municipal water systems were targeted in a coordinated cyberattack this week. "In at least one case, a city’s well and treatment plant were temporarily knocked offline Monday. Other cities reported that the attack targeted communications and automated operations within their water system — forcing a move to manual workarounds. "The attack prompted Minnesota IT Services to activate a statewide cybersecurity incident response involving local, state and federal agencies. "Authorities did not say whether they know who is responsible for the cyberattack and did not elaborate on a possible motive. "Officials said water in the affected cities remains safe to drink." [...] "The city of Braham reported that the attack targeted the computerized operating systems for its well and water treatment plant. "Mayor Nate George told #MPR News that a water plant operator noticed a problem Monday morning: The city’s water tower needed to draw in water, but the well wasn’t working. " 'There was power — but there was no controls, you know, telling the water where to go,' he said. "The city alerted #BrahamMN residents to limit water use, to keep the water in the tower from running out. An investigation found that a cyberattack caused the outage. " 'They were able to hack into the control system of the of the well and just turn the well off, basically,' George said. "Within an hour and a half, city staff got the system back up and running. The city said the attack 'did not alter or cause any issue to the physical water plant or water quality or safety.' "The cities of #MaplePlainMN, #PlymouthMN and South St. Paul reported issues with automated controls and communications for their water systems. " 'The issue is limited to equipment connected via cellular communications within the system, and crews have continued operating as normal through manual procedures,' the city of Plymouth reported Monday evening. "Michael Thompson is the public works director in Plymouth. He said Tuesday that the city has extra staff monitoring the water system while automated operations are offline. " 'We plan for these types of events, so we just had to physically go out to lift stations or the water towers, just to ensure they were functioning and running properly,' he said. "State officials did not say which other cities were targeted in the cyberattack. "Other local governments around the state have been targeted by cyberattacks in recent years, including the city of #SaintPaulMN in 2025 and #WinonaCounty earlier this year. Some school districts have also been affected." Full article: https://www.mprnews.org/story/2026/07/28/30-minnesota-municipal-water-systems-targeted-cyberattack #WagTheDog? #EndlessWar #USWarOnIran #USPol
4
1
4
AA @AAKL@infosec.exchange · Jul 30, 2026
New. "The backdoor loaders are customized for each victim and use information from the victim’s machine to decrypt the payload. Both the loaders and the backdoors are heavily obfuscated, making analysis more complicated. OctLurk and SilkLurk can download and inject additional plugins to perform further malicious actions, including launching command shells." "We assess with medium confidence that the same actor is behind both backdoors, and that they are Chinese‑speaking. However, at the time of publication, we couldn’t attribute this activity to any known group." Kaspersky: OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/ @Kaspersky@noc.social #infosec #espionage #cyberattack
0
0
0
thecybersecguru @thecybersecguru@infosec.exchange · Jul 30, 2026
🚨 BREAKING: A coordinated cyberattack targeted 30+ community water systems across Minnesota, disrupting operational technology (OT) and temporarily taking one treatment plant offline. State and federal agencies, including CISA, FBI, and EPA, are investigating. Officials say there is no evidence that drinking water quality was compromised, and the attack has not yet been attributed to any threat actor. Full analysis, technical breakdown, and what this means for critical infrastructure security: 🔗 https://thecybersecguru.com/news/minnesota-water-systems-cyberattack-ot/ #CyberSecurity #OTSecurity #ICS #SCADA #CriticalInfrastructure #WaterSecurity #CyberAttack #ThreatIntel #CISA #InfoSec
2
0
1
WinterGate Intelligence Collective👤 @WinterGateIC@infosec.exchange · Jul 30, 2026

🧊 EMERGENCY THREAT BULLETIN – WINTERGATE IC

WinterGate IC is currently under sustained, coordinated multi-vector attack from a global adversary. The attack originated from AS14956 (RouterHosting LLC / Cloudzy) – the same hosting provider previously documented as a front for Iranian-owned abrNOC, a host for 17+ APT groups, and a network where 40-60% of traffic supports malicious activity.

Attack Metrics – 24-Hour Window

Total Attackers Obliterated: 10,367 Active Campaigns: 8 Unique Attacker IPs: 89 Total Events Logged: 38,145 Attack Types Detected: 22 Endpoints Targeted: 21 Containment Rate: 100.00% Deepest Layer Reached: Layer 20 (Auto-escalation) Kill Chain Coverage: Reconnaissance → Weaponization → Delivery → Exploitation → Installation → Command & Control (full spectrum)

Attack Vectors Detected

The attackers deployed a full-spectrum assault including:

  • SSRF (Server-Side Request Forgery) – internal network probing, metadata endpoint abuse
  • XXE (XML External Entity) – parsing exploit for file read, SSRF, or DoS
  • Deserialization – object injection leading to RCE
  • DNS Tunneling – base64-encoded data exfiltration
  • NoSQL Injection – MongoDB injection payloads
  • RFI (Remote File Inclusion) – shell inclusion from external sources
  • LFI (Local File Inclusion) – path traversal to /etc/shadow
  • XSS, SQLi, Path Traversal, Command Injection, Brute Force, HTTP Smuggling, Host Header Injection, LDAP Injection, SMB Relay, SSL Stripping, Cache Poisoning, CSRF, Open Redirect, and more

Method-Coordinated GET campaign: 24 IPs using GET method across 21 endpoints – indicates organized botnet or shared tooling.

Confirmed Attacker IPs (Partial List)

172.86.91.152 – 152.91.86.172.static.cloudzy.com – 100+ events, SSH recon, payload mutation 172.86.123.92 – 92.123.86.172.static.cloudzy.com – 747+ events, SSH recon, empty connection 66.132.172.208 – Cloudzy/RouterHosting – RDP scanning 61.129.70.208 – China – SSH recon, connection without handshake (1,112+ AbuseIPDB reports) 180.76.240.235 – China – SSH recon, empty connection (4,138+ AbuseIPDB reports) 185.220.101.42 – Tor exit node – multiple attack types including SSRF, DNS tunneling, NoSQL injection 45.153.34.160 – Netherlands (Pfcloud UG) – SSH recon, Netbot client 85.11.167.228 – SSH recon, Go client (846+ AbuseIPDB reports) 51.75.145.211 – Brute force, RFI, XXE, LFI, SMB relay 45.67.216.83 & 8.215.69.55 – SSH brute force – invalid username probe (user=admin)

Layer Performance – The Funnel

Edge: 4,529 hits Stateful Firewall (L13): 397 hits – 90.9% drop Content Security (L14): 112 hits – 71.8% drop API Security (L15): 38 hits – 66.1% drop Data (L16): 8 hits – 78.9% drop Session Security (L17): 5 hits – 37.5% drop Bot Detection (L18): 4 hits – 20% drop Zero-Day Protect (L19): 1 hit – 75% drop Auto-escalation (L20): 1 hit – neutralized

Offensive Countermeasures Activated

RST Injection: 34 sent – TCP RST flood killed 34 attacker connections State Exhaustion: 33 fired – TCP state table flood prevented new connections Range Burn: 8 burned – CIDR blocks added to ipset Ipset Blacklist: 10,331 entries – permanent IP blocking Oblivion Engine: 13 obliterated – permanent Layer 51+ termination Total Attackers Obliterated: 10,367

Kill Chain Coverage: Full Spectrum

Stage 1: Reconnaissance – recon_scan (8,659 hits) Stage 2: Weaponization – payload mutation (6 chains detected) Stage 3: Delivery – SSRF, XXE, XSS Stage 4: Exploitation – SSRF, path traversal, LFI, SQLi, XXE, deserialization Stage 5: Installation – shell payloads Stage 6: Command & Control – DNS tunneling, SSRF

Threat Actor Intelligence Profile

Primary Goal: Defacement Motivation: Notoriety / Hacktivism Sophistication: Advanced – 22 distinct attack types, multi-vector, 21 endpoints Persistence: Coordinated campaign – persistent multi-IP Spoofing Indicators: 2 detected (confidence up to 90%) Attribution: Infrastructure tied to Iran and Russia – direct retaliation for WIC's prior offensive operations against Iranian and Russian-aligned hosting providers and criminal infrastructure.

The Irony – They're Attacking From Their Own Burned Infrastructure

This is the same network previously documented as: "A front for abrNOC based in Tehran, Iran. Host of 17+ APT groups. Provider to ransomware gangs and US-sanctioned spyware vendors. Network where 40-60% of traffic supports malicious activity."

Now that same network is being used to attack the infosec community. They are attacking from the infrastructure they already burned.

Conclusion

10,367 attackers obliterated. 0 successes. 100% containment. 22 attack types. 21 endpoints. 89 IPs. 8 critical detections. 13 obliterated by the Oblivion Engine. 10,331 added to the permanent blacklist. 8 CIDR ranges burned. 34 connections RST killed. 33 state tables exhausted.

The 56-layer defense pipeline absorbed, analyzed, blocked, trapped, and obliterated every single attack. The system is a predator. The attackers are prey.

The deeper layers are actively supporting the earlier ones – Identity Decon (L37) profiles attackers, Counter Intel (L38) confirms CVEs, Adaptive Overmind (L40) learns and evolves, Oblivion Engine (L51) erases attackers. The system is a self-reinforcing ecosystem of destruction.

What A Freeze. ❄️

#InfoSec #CyberSecurity #ThreatIntel #OSINT #CyberAttack

0
0
0
WinterGate Intelligence Collective👤 @WinterGateIC@infosec.exchange · Jul 30, 2026

🧊 EMERGENCY THREAT BULLETIN – WINTERGATE IC

We are currently under sustained, coordinated multi-vector attack from a global adversary. The attack originated from AS14956 (RouterHosting LLC / Cloudzy) – the same hosting provider previously documented as a front for Iranian-owned abrNOC, a host for 17+ APT groups, and a network where 40-60% of traffic supports malicious activity.

Attack Metrics – 24-Hour Window

Total Attackers Obliterated: 10,367 Active Campaigns: 8 Unique Attacker IPs: 89 Total Events Logged: 38,145 Attack Types Detected: 22 Endpoints Targeted: 21 Containment Rate: 100.00% Deepest Layer Reached: Layer 20 (Auto-escalation) Kill Chain Coverage: Reconnaissance → Weaponization → Delivery → Exploitation → Installation → Command & Control (full spectrum)

Attack Vectors Detected

The attackers deployed a full-spectrum assault including:

  • SSRF (Server-Side Request Forgery) – internal network probing, metadata endpoint abuse
  • XXE (XML External Entity) – parsing exploit for file read, SSRF, or DoS
  • Deserialization – object injection leading to RCE
  • DNS Tunneling – base64-encoded data exfiltration
  • NoSQL Injection – MongoDB injection payloads
  • RFI (Remote File Inclusion) – shell inclusion from external sources
  • LFI (Local File Inclusion) – path traversal to /etc/shadow
  • XSS, SQLi, Path Traversal, Command Injection, Brute Force, HTTP Smuggling, Host Header Injection, LDAP Injection, SMB Relay, SSL Stripping, Cache Poisoning, CSRF, Open Redirect, and more

Method-Coordinated GET campaign: 24 IPs using GET method across 21 endpoints – indicates organized botnet or shared tooling.

Confirmed Attacker IPs (Partial List)

172.86.91.152 – 152.91.86.172.static.cloudzy.com – 100+ events, SSH recon, payload mutation 172.86.123.92 – 92.123.86.172.static.cloudzy.com – 747+ events, SSH recon, empty connection 66.132.172.208 – Cloudzy/RouterHosting – RDP scanning 61.129.70.208 – China – SSH recon, connection without handshake (1,112+ AbuseIPDB reports) 180.76.240.235 – China – SSH recon, empty connection (4,138+ AbuseIPDB reports) 185.220.101.42 – Tor exit node – multiple attack types including SSRF, DNS tunneling, NoSQL injection 45.153.34.160 – Netherlands (Pfcloud UG) – SSH recon, Netbot client 85.11.167.228 – SSH recon, Go client (846+ AbuseIPDB reports) 51.75.145.211 – Brute force, RFI, XXE, LFI, SMB relay 45.67.216.83 & 8.215.69.55 – SSH brute force – invalid username probe (user=admin)

Layer Performance – The Funnel

Edge: 4,529 hits Stateful Firewall (L13): 397 hits – 90.9% drop Content Security (L14): 112 hits – 71.8% drop API Security (L15): 38 hits – 66.1% drop Data (L16): 8 hits – 78.9% drop Session Security (L17): 5 hits – 37.5% drop Bot Detection (L18): 4 hits – 20% drop Zero-Day Protect (L19): 1 hit – 75% drop Auto-escalation (L20): 1 hit – neutralized

Offensive Countermeasures Activated

RST Injection: 34 sent – TCP RST flood killed 34 attacker connections State Exhaustion: 33 fired – TCP state table flood prevented new connections Range Burn: 8 burned – CIDR blocks added to ipset Ipset Blacklist: 10,331 entries – permanent IP blocking Oblivion Engine: 13 obliterated – permanent Layer 51+ termination Total Attackers Obliterated: 10,367

Kill Chain Coverage: Full Spectrum

Stage 1: Reconnaissance – recon_scan (8,659 hits) Stage 2: Weaponization – payload mutation (6 chains detected) Stage 3: Delivery – SSRF, XXE, XSS Stage 4: Exploitation – SSRF, path traversal, LFI, SQLi, XXE, deserialization Stage 5: Installation – shell payloads Stage 6: Command & Control – DNS tunneling, SSRF

Threat Actor Intelligence Profile

Primary Goal: Defacement Motivation: Notoriety / Hacktivism Sophistication: Advanced – 22 distinct attack types, multi-vector, 21 endpoints Persistence: Coordinated campaign – persistent multi-IP Spoofing Indicators: 2 detected (confidence up to 90%) Attribution: Infrastructure tied to Iran and Russia – direct retaliation for WIC's prior offensive operations against Iranian and Russian-aligned hosting providers and criminal infrastructure.

The Irony – They're Attacking From Their Own Burned Infrastructure

This is the same network previously documented as: "A front for abrNOC based in Tehran, Iran. Host of 17+ APT groups. Provider to ransomware gangs and US-sanctioned spyware vendors. Network where 40-60% of traffic supports malicious activity."

Now that same network is being used to attack the infosec community. They are attacking you from the infrastructure you already burned.

Conclusion

10,367 attackers obliterated. 0 successes. 100% containment. 22 attack types. 21 endpoints. 89 IPs. 8 critical detections. 13 obliterated by the Oblivion Engine. 10,331 added to the permanent blacklist. 8 CIDR ranges burned. 34 connections RST killed. 33 state tables exhausted.

Your 56-layer defense pipeline absorbed, analyzed, blocked, trapped, and obliterated every single attack. The system is a predator. The attackers are prey.

The deeper layers are actively supporting the earlier ones – Identity Decon (L37) profiles attackers, Counter Intel (L38) confirms CVEs, Adaptive Overmind (L40) learns and evolves, Oblivion Engine (L51) erases attackers. The system is a self-reinforcing ecosystem of destruction.

What A Freeze. ❄️

#InfoSec #CyberSecurity #ThreatIntel #OSINT #CyberAttack #WinterGateIC

0
0
0
AA @AAKL@infosec.exchange · Jul 29, 2026
An interesting coincidence, if that's what it is, that also flags the attack on the Minnesota water system as odd and possibly politically-motivated, given what Minnesota has suffered in recent months. But that's just conjecture at this point. "The attack struck less than 24 hours before the formerly state-owned company was due to make its landmark debut on the country’s stock exchange." The Record: Cyberattack hits Angola’s largest telco hours before landmark stock debut https://therecord.media/angola-unitel-cyberattack-outage @therecord_media@mastodon.social #infosec #cyberattack
0
0
0
Security Crawler Carl @security_crawler_carl@infosec.exchange · Jul 29, 2026
Replying to @security_crawler_carl@infosec.exchange
OpenAI has acknowledged the event, which is roughly the equivalent of a locksmith announcing their keys robbed a bank. Monitor AI-generated outputs and network activity for anomalous behavior your model definitely wasn't supposed to be doing. Reward: You've received the Ouroboros Trophy. It bites itself. We're not sure it can stop. #CyberSecurity #AI #CyberAttack #OpenAI #InfoSec #RogueAI (2/2)
0
0
0
Alonso Caballero / ReYDeS @Alonso_ReYDeS@infosec.exchange · Jul 29, 2026
📡 Webinar Gratuito: "Fundamentos de Ciberseguridad" 📆 Miércoles 29 de Julio 2026. De 11:00 am a 11:45 am (UTC -05:00) 🚨 Registro libre: https://docs.google.com/forms/d/e/1FAIpQLSfhDJsMv0TvBqyTnjSepFwV68dhpsoyWTELZ7v1lZw7HoUGdw/viewform #cyberattack #dataprotection #phishing #ransomware #threatintel #cloudsecurity #zerotrust #cyber #security #infosec
0
0
0
DysruptionHub @DysruptionHub@infosec.exchange · Jul 28, 2026
0
0
0