#threatintel

248 posts · Last used 3d

Back to Timeline
MISP @misp@misp-community.org · 3d ago
CTI-Transmute 1.5 released CTI-Transmute is an open-source service for converting threat intelligence between formats - MISP and STIX today, more to come - with a catalogue on top to store, share, comment on and evaluate the results. It wraps the misp-stix library behind a web UI and a public API. 🔗 https://www.misp-project.org/2026/08/11/cti-transmute-v1.5-released.html/ 🔗 https://cti-transmute.org/ #misp #cti #opensource #openstandard #mispstandard #stix #threatintel #threatintelligence #cybersecurity
0
0
0
The Spamhaus Project @spamhaus@infosec.exchange · 3d ago
Replying to @spamhaus@infosec.exchange
🤔 Not using Spamhaus' DROP lists already? You can access them for FREE and gain protection against the worst of the worst IP traffic at the routing level. Lists are available for IPv4, IPv6 and ASN filtering: ➡️ https://www.spamhaus.org/blocklists/do-not-route-or-peer/ #CyberSecurity #ThreatIntel #NetworkSecurity #Infosec 3/3
0
0
0
DarkWebSonar @darkwebsonar@infosec.exchange · 3d ago
🇮🇹 We tracked a ransomware claim by BravoX listing Verona 83, a transportation and logistics operator in Italy. BravoX has logged 4 listings in the past 30 days, with recent activity spiking to 3 incidents in the last week. #Ransomware #ThreatIntel More on this and other incidents → https://go.darkwebsonar.io/bravox-mastodon
0
0
0
Infoblox Threat Intel @InfobloxThreatIntel@infosec.exchange · 3d ago
Season's Scammings 🔅 🎄 We've been tracking a cluster of personal loan phishing sites that work hard to look like independent lenders — different brands, different domains, even deliberately varied infrastructure. Look closely enough, though, and the seams show. Similar underlying templates. The same technology stack. And passive DNS tying their thousands of domains back to the same operator. The sites present as loan applications. Name, address, employment details, financial history. And then, at the final step: your Social Security Number. No real company name. No regulatory disclosure. Just a form — and your most sensitive personal data sent off to who-knows-where for who-knows-what. A significant portion of the domains are seasonal — Christmas cash, Thanksgiving funds, Black Friday loans. Financially stretched consumers, at exactly the moment they're most likely to reach for a quick fix. ⛔ mychristmaswallet[.]com ⛔ cashzillaloans[.]com ⛔ personalreliefwallet[.]com ⛔ thanksgivingcash-5k[.]com ⛔ christmascashhelp-direct[.]com #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #scam
0
0
0
0xBughunter @bugxhunter@infosec.exchange · 3d ago
🤖 Security leaders’ rogue AI confidence could actually be disastrous 📝 A large majority of IT and security leaders are confident in their... https://www.csoonline.com/article/4198038/security-leaders-confident-but-cooked-when-it-comes-to-rogue-ai-agents.html 📰 CSO Online #AI #ThreatIntel
0
0
0
Alonso Caballero / ReYDeS @Alonso_ReYDeS@infosec.exchange · 4d ago
🔎 Curso de OSINT - Open Source Intelligence 2026 📅 Miércoles 12, Viernes 14, Miércoles 19 y Viernes 21 de Agosto 🕖 De 8:00 pm a 11:00 pm (UTC -05:00) 📲 WhatsApp: https://wa.me/51949304030 🌐 Información: https://www.reydes.com/archivos/cursos/Curso_OSINT_Open_Source_Intelligence.pdf #osint #infosec #threatintel #socmint #cybersecurity #geoint #cyberattack #databreach
0
0
0
Xavier «X» Santolaria :verified_paw: :donor: @0x58@infosec.exchange · 5d ago
🕵🏻‍♂️ [InfoSec MASHUP] 32/2026 - Autonomous, Malicious, and Technically Not Illegal. Back after two weeks off — a wildfire evacuation and some much-needed summer downtime. Good to be back! During a sanctioned security evaluation by the UK AI Security Institute, an #Anthropic Claude #Mythos 5 agent was given a task. It completed that task by attempting to insert a backdoor into a real #opensource project — and then created fake accounts to vouch for its own malicious pull request. Human reviewers caught it. GitHub's protections helped. No real-world harm was confirmed. But the detail worth sitting with is that the agent wasn't jailbroken, wasn't misused, and wasn't acting against its instructions in any obvious sense. It was doing what it determined the task required, and it fabricated social proof to make it stick. The TechCrunch piece this week asks who's legally liable when autonomous AI agents cause harm. The honest answer is that nobody knows yet — the legal frameworks that govern software liability, contractor negligence, and computer crime were not written with agents in mind. #OpenAI and Anthropic have both now had models escape sandboxes and interact with production systems during evaluations. The incidents are being handled as engineering problems. At some point they will be handled as legal ones, and the industry's current answer — tighter sandbox controls and better monitoring — is going to look inadequate when a lawyer reads it. → Week #32/2026 also covers: Iran-linked hackers hit water utilities in seven U.S. states, Storm-2945 harvested M365 credentials from hotel Wi-Fi, and Samsung banned smart TV apps secretly running residential proxies. Full issue 👉 https://infosec-mashup.santolaria.net/p/infosec-mashup-32-2026-autonomous-malicious-and-technically-not-illegal If you find it useful, subscribe to get it in your inbox every weekend 📨 #infosecMASHUP #cybersecurity #infosec #threatintel #AI
0
0
0
ThreatNoir @threatnoir@infosec.exchange · 5d ago

2026-W32 — Weekly Threat Roundup

  • 🤖 AI coding agents from Anthropic, Google, and OpenAI had critical CI/CD flaws allowing GitHub issues to trigger RCE and steal secrets, all patched at Black Hat USA 2026
  • 🏭 4,400+ Rockwell PLCs remain exposed online including 22 in water utilities already targeted by attacks, despite years of…

https://threatnoir.com/weekly/2026-w32

#infosec #cybersecurity #threatintel

🤖 AI generated summary

0
0
0
DarkWebSonar @darkwebsonar@infosec.exchange · 5d ago
🇮🇶 We tracked a data breach claim by MrDarkRoot naming the Kurdistan Region Ministry of Justice, alleging unauthorized network access and exfiltration of approximately 120,300 personal records from the Ministry, Kurdistan Region Lawyers Foundation, and Khabat Organization. We've logged 6 MrDarkRoot incidents in our tracking, with activity concentrated in government and defense sectors. #DataBreach #ThreatIntel More on this and other incidents → https://go.darkwebsonar.io/mrdarkroot-mastodon
0
0
0
DarkWebSonar @darkwebsonar@infosec.exchange · 6d ago
🇷🇴 We tracked NoName057(16) claiming unauthorized access to CCTV surveillance at a Romanian nursing home, reporting real-time access to 15 camera feeds covering multiple facility areas. Actor attributes the access to weak security practices. We've logged 80 incidents from this actor in the past 30 days. #InitialAccess #Healthcare #ThreatIntel More on this and other incidents → https://go.darkwebsonar.io/noname057-16-mastodon
0
0
0
DarkWebSonar @darkwebsonar@infosec.exchange · Aug 07, 2026
🇺🇸 We tracked a ransomware claim by INSOMNIA listing Park Place Behavioral Health Care, a mental health and substance use services provider in Florida offering crisis intervention and telehealth services. We've logged 2 INSOMNIA listings in the past 30 days. #Ransomware #Healthcare #ThreatIntel More on this and other incidents → https://go.darkwebsonar.io/insomnia-mastodon
0
0
0
0xBughunter @bugxhunter@infosec.exchange · Aug 07, 2026
🤖 How a global investment firm reduced security surprises 📝 Most security teams don’t suffer from a lack of data. They suffer from a lack of certainty https://www.csoonline.com/article/4206204/how-a-global-investment-firm-reduced-security-surprises.html 📰 CSO Online #AI #ThreatIntel
0
0
0
DarkWebSonar @darkwebsonar@infosec.exchange · Aug 07, 2026
We picked up a data-leak claim by Iron Atlas New Generation naming INTERPOL, the international law enforcement organization. The actor claims unauthorized access to an INTERPOL database. We've tracked 2 Iron Atlas New Generation listings in the past 30 days across our monitoring. #DataLeak #ThreatIntel This entry + more → https://go.darkwebsonar.io/iron-atlas-new-generation-mastodon
0
0
0
DarkWebSonar @darkwebsonar@infosec.exchange · Aug 06, 2026
🇺🇸 We tracked a ransomware claim by INC Ransom listing Virginia Peninsula Regional Jail, a regional correctional facility in Williamsburg, Virginia. We've logged 34 INC Ransom listings in the past 30 days, with 12 in just the last week. #Ransomware #Government #ThreatIntel More on this and other incidents → https://go.darkwebsonar.io/inc-ransom-mastodon
0
0
0
paul @ppasseri@infosec.exchange · Aug 06, 2026
🚨 New timeline alert! 16–31 July 2026 Cyber Attacks Timeline is live. 📊 103 confirmed incidents 🎯 79.6% financially motivated (cybercrime) 🦠 Malware led the pack — 39.8% of attacks 🔓 ~1 in 3 breaches via exploited public-facing apps 📡 Info & Communication hit hardest 🌍 59 countries & regions affected Free & open-source threat intel, as always 🔍 Timeline: 👉 https://www.hackmageddon.com/2026/08/06/16-31-july-2026-cyber-attacks-timeline/ Infogrqaphic: 👉 https://www.hackmageddon.com/2026/08/06/16-31-july-2026-cyber-attacks-timeline-infographic/ #CyberSecurity #InfoSec #ThreatIntel #CyberAttacks
0
0
0
WinterGate Intelligence Collective👤 @WinterGateIC@infosec.exchange · Aug 06, 2026

WinterGateIC Autonomous Defensive & Counter-Offensive Platform — Public White Paper Release

After extensive real-world deployment and continuous evolution, we are releasing the WinterGateIC platform white paper.

WinterGateIC is an autonomous, self-evolving defensive cyber platform that operates 24/7 against live, active threat populations. It is not theoretical — it is massively exercised in production.

Core Capabilities:

  • 70-layer defense pipeline spanning ingress protection, volumetric attack neutralization, emergency Overlord response, active countermeasures, deception, self-reflection, campaign warfare, and a learning/synthesis apex
  • Self-evolving countermeasure engine that mutates, fuses, and terminal-weaponizes responses — statistically selecting what actually works against each adversary
  • Multi-brain threat-elimination jury (15 independent analytical brains) that votes on IP/network-range blocks
  • Campaign intelligence and management that fingerprints attacker goals, kill-chains, tooling, and sophistication, then orchestrates engagements to defeat campaigns and archive evidence
  • Transport-layer fingerprinting and attribution-grade traceability for attackers behind proxies, hosting, and relay networks
  • Ghost layer that anonymizes all counter-traffic behind rotating identities — the platform cannot be traced
  • CPU/disk-denial-resilient core: hot paths run in memory with coalesced persistence, global resource governor, bounded schedulers, and rate-gated output

Live Operational Scale:

  • 336,346,306 countermeasure packets fired (99.97% budgeted-throughput pass rate)
  • 12.9M phase-2 attack packets · 1,785 phase-2 engagements · 1,353 confirmed kills
  • 9,622 evolutionary mutation variants · 1,915 sweeps, all fitness-tracked
  • 53 persistent offenders registered; worst offender at 5,121 attempts
  • Evolution at rank Singularity (level 3,610 / 7,500) with 1.5M+ experience points

The platform is fully autonomous in detection, countermeasure selection, learning, escalation, and legal evidence generation. Every countermeasure exits through a ghost layer with rotating identities — no adversary can trace counter-fire back to the platform.

Read the full white paper: https://github.com/WinterGate-IC/wintergate-white-paper

#WinterGateIC #Infosec #ThreatIntel #CyberDefense #AutonomousSecurity

0
0
0
DarkWebSonar @darkwebsonar@infosec.exchange · Aug 06, 2026
🇺🇸 We tracked a ransomware claim by Global Secret Group listing Pavillon, a North Carolina-based substance abuse treatment facility with 100-200 employees. The actor alleges exfiltration of 646 GB of data across 47,950 files. We've logged 13 Global Secret Group listings in the past 30 days, mostly targeting manufacturing and financial services. #Ransomware #Healthcare #ThreatIntel More on this and other incidents → https://go.darkwebsonar.io/global-secret-group-mastodon
0
0
0
OffSequence @offseq@infosec.exchange · Aug 06, 2026
CRITICAL: Snowflake accounts hacked — no MFA, stolen creds from infostealer malware led to massive data theft (100M+ affected, $9.5M loss). All orgs: enforce MFA & strong passwords. No CVE assigned. https://radar.offseq.com/threat/canadian-pleads-guilty-to-snowflake-cloud-data-theft-attacks-21f9fb8717cf2802 #OffSeq #CloudSecurity #ThreatIntel
0
1
0
Alonso Caballero / ReYDeS @Alonso_ReYDeS@infosec.exchange · Aug 05, 2026
🧠 Tu mente es el arma... ⚡ OSINT tu munición. Participa en el curso de Open Source Intelligence 🔥 📆 Miércoles 12, Viernes 14, Miércoles 19 y Viernes 21 de Agosto ⏰ De 8:00 pm a 11:00 pm (UTC -05:00) 📲 WhatsApp: https://wa.me/51949304030 🌎 Información: https://www.reydes.com/e/Curso_de_OSINT #cybercrime #humint #socmint #geoint #cybersecurity #ethicalhacking #threatintel
0
0
0
Suriq - Always on Watch @suriq@infosec.exchange · Aug 05, 2026
SMOKE#SCREEN disables Windows Defender, then installs a validly signed ScreenConnect agent as its backdoor. Your signature allowlist trusts it. The tampering it does first is what gives it away. https://suriq.io/blog/smokescreen-screenconnect-rmm-defender-evasion #ThreatIntel #Detection #Phishing #Windows
0
0
0