We're thrilled to announce IFIN has achieved 501(c)(3) recognition! Now we can get down to business.
https://ifin-intel.org/blog/nonprofit/
#IFIN
About This Hashtag
#ifin
13 posts
Last used Aug 04
#ifin
13 posts· Last used Aug 04
Really exciting news about IFIN and being a non-profit.
IFIN has multiple offerings including a curated news feed / rss. You should check it out.
https://ifin-intel.org/blog/nonprofit/
#threatIntel #infosec #cybersecurity #ifin
Yet another attack against the Arch User Repository is underway. We are monitoring and analyzing the malware samples.
https://discourse.ifin.network/t/new-aur-attack-prompts-adoption-lock/698
#ThreatIntel #ThreatIntelligence #IFIN
We've compiled the latest information regarding the Minnesota water systems attacks.
https://discourse.ifin.network/t/minnesota-water-system-suffers-a-breach-due-to-exposed-access-keys/695
#ThreatIntel #ThreatIntelligence #IFIN
We caught a sample of ACR Stealer and went deep on it. Lots of sophistication for "just" an infostealer.
https://discourse.ifin.network/t/acr-stealer-clickfix-etherhiding-and-stego-oh-my/694
#ThreatIntel #ThreatIntelligence #IFIN
Following up on a Fediverse tip, we found a new use for fake software download sites: the referral program hustle. Mirror FOSS, get cash.
There are almost certainly more of these out there.
https://discourse.ifin.network/t/pdf-arranger-and-terabox-referrals-lamer-than-malware/683
#ThreatIntel #ThreatIntelligence #IFIN
With confirmed exploit sources, we've now added this one to our MISP feed.
https://discourse.ifin.network/t/microsoft-sharepoint-cve-2026-50522/678/2
#ThreatIntel #ThreatIntelligence #IFIN
If you pirate games, you should expect malware. That's a tale as old as 1970-01-01T00:00:00.000Z. But using Etherhiding as the second stage source? Well that's slightly newer.
In case you couldn't tell, we're declaring war on #Etherhiding. More to come.
https://discourse.ifin.network/t/pirated-games-come-with-a-side-of-amatera-stealer/675
#ThreatIntel #ThreatIntelligence #IFIN
The latest supply chain attack has some novelty, but the techniques should have long been mitigated in your network. IPFS, cryptocurrency, and Nostr have no place in a professional network.
https://discourse.ifin.network/t/latest-miasma-attack-uses-blockchain-garbage-you-should-have-already-blocked/663
#ThreatIntel #ThreatIntelligence #IFIN
An IFIN community member caught this #ClickFix campaign, followed it, reversed the payload, and brought the IOCs. This is the juice right here. A perfect example that #ThreatIntelIsMutualAid
https://discourse.ifin.network/t/compromised-website-hosting-clickfix-payload-leads-to-netsupport-rat-infection/633
#ThreatIntel #ThreatIntelligence #IFIN
If you're running a SimpleHelp server, it's patch o'clock. Also maybe incident-response-o'clock.
(It's always incident-response-o'clock somewhere)
https://discourse.ifin.network/t/stealers-exploit-cve-2026-in-simplehelp-attack/629
#ThreatIntel #ThreatIntelligence #IFIN
Maaaaybe just block the whole dot garden top-level domain.
https://discourse.ifin.network/t/garden-tlds-change-to-a-bad-neighborhood/627
#ThreatIntel #ThreatIntelligence #IFIN
If you're running Lantronix gear on the internet, you might want to check your logs for suspicious logins and command execution.
https://discourse.ifin.network/t/lantronix-openwrt-luci-attacks/625
#ThreatIntel #ThreatIntelligence #IFIN
You've seen all posts