IFIN - The Independent Federated Intelligence Network
ifin@infosec.exchange
<p>The Independent Federated Intelligence Network. </p><p>IFIN is a 501(c)(3) not-for-profit public benefit corporation incorporated in California.</p><p>Our mission: Empower organizations to independently collect, analyze, and disseminate relevant cyber threat intelligence through training, open source tools, and a decentralized intelligence sharing network.</p>
Posts
-
Post #4398487
Ah, I see the fear-mongering around the "open source" (not a thing; they mean open-weights, but actually really they mean "Chinese") models has kicked into high gear. https://www.cybersecuritydive.com/news/openai-hugging-face-hack-ai-models-black-hat/827167/
-
Post #4378398
We're thrilled to announce IFIN has achieved 501(c)(3) recognition! Now we can get down to business. https://ifin-intel.org/blog/nonprofit/ #IFIN
-
Post #4376059
RE: https://mastodon.social/@zackwhittaker/117037185272316538 Folks fighting for ad blockers in your orgs: https://ifin-intel.org/blog/ad-blocker/
-
Post #4259283
The critical SharePoint vulnerability CVE-2026-50522 now appears to be under massive exploitation. We have context and current IOCs in this post. We've also updated the MISP feed with the same. #ThreatIntel #ThreatIntelligence #IFIN https://discourse.ifin.network/t/microsoft-sharepoint-cve-2026-50522/678
-
Post #4259282
Fantastic research by our community here on a continuing Lua-based campaign that uses Prometheus obfuscation and our old friend Etherhiding for C2 configuration acquisition. https://discourse.ifin.network/t/luajit-loader-uses-prometheus-obfuscation-and-etherhiding/679 #ThreatIntel #ThreatIntelligence #IFIN
-
Post #4251819
Yet another attack against the Arch User Repository is underway. We are monitoring and analyzing the malware samples. https://discourse.ifin.network/t/new-aur-attack-prompts-adoption-lock/698 #ThreatIntel #ThreatIntelligence #IFIN
-
Post #4245499
We've compiled the latest information regarding the Minnesota water systems attacks. https://discourse.ifin.network/t/minnesota-water-system-suffers-a-breach-due-to-exposed-access-keys/695 #ThreatIntel #ThreatIntelligence #IFIN
-
Post #4214705
We caught a sample of ACR Stealer and went deep on it. Lots of sophistication for "just" an infostealer. https://discourse.ifin.network/t/acr-stealer-clickfix-etherhiding-and-stego-oh-my/694 #ThreatIntel #ThreatIntelligence #IFIN
-
Post #4182821
There are security patches available for Discourse so the forum will go down shortly for updates. Be back soon!
-
Post #4142178
We continue to use our own RSS-Filter project to curate our feed aggregator. We've removed "Startups" from the other-wise excellent TechCrunch security news feed to keep the feed relevant and actionable. Our Newsfeed: https://news.ifin.network RSS-Filter: https://codeberg.org/ifin/rss-filter
-
Post #4070324
Following up on a Fediverse tip, we found a new use for fake software download sites: the referral program hustle. Mirror FOSS, get cash. There are almost certainly more of these out there. https://discourse.ifin.network/t/pdf-arranger-and-terabox-referrals-lamer-than-malware/683 #ThreatIntel #ThreatIntelligence #IFIN
-
Post #4019150
With confirmed exploit sources, we've now added this one to our MISP feed. https://discourse.ifin.network/t/microsoft-sharepoint-cve-2026-50522/678/2 #ThreatIntel #ThreatIntelligence #IFIN
-
Post #3963998
If you pirate games, you should expect malware. That's a tale as old as 1970-01-01T00:00:00.000Z. But using Etherhiding as the second stage source? Well that's slightly newer. In case you couldn't tell, we're declaring war on #Etherhiding. More to come. https://discourse.ifin.network/t/pirated-games-come-with-a-side-of-amatera-stealer/675 #ThreatIntel #ThreatIntelligence #IFIN
-
Post #3914521
RE: https://infosec.exchange/@ifin/116941087829918408 This has been confirmed exploited in the wild. Updated with IoCS.
-
Post #3910866
Apparently (?) there's a Pre-Auth RCE (!) in core WordPress (?!), but there are extremely few details as yet. If it's as gnarly as it sounds, a lot of sites are going to have a very bad time. We'll keep this story updated as details emerge. https://discourse.ifin.network/t/wp2shell-pre-auth-rce-in-wordpress-no-cve/672
-
Post #3841213
Cursor will run anything called git.exe when you open it, but it isn't the only one. As a fork of VS Code, Cursor has inherited this behavior from its questionable parentage. https://discourse.ifin.network/t/remember-that-cursor-git-exe-bug-its-in-vscode-too/665
-
Post #3819768
The latest supply chain attack has some novelty, but the techniques should have long been mitigated in your network. IPFS, cryptocurrency, and Nostr have no place in a professional network. https://discourse.ifin.network/t/latest-miasma-attack-uses-blockchain-garbage-you-should-have-already-blocked/663 #ThreatIntel #ThreatIntelligence #IFIN
-
Post #3702875
We regret to inform you that yes, the models continue to produce kernel exploits leading to privilege escalation and container escapes. This one is part of a two-vuln chain with a public PoC that escapes Firefox and roots the host. https://discourse.ifin.network/t/cve-2026-43499-ghostlock-yet-another-linux-lpe-container-escape/653
-
Post #3656106
Soooo Tenda devices have an admin backdoor. Potential redeployment locations: a wood chipper, the nearest active volcano, or that really annoying neighbor's house. No patch; have fun! https://discourse.ifin.network/t/cve-2026-11405-multiple-tenda-routers-have-an-admin-backdoor/646
-
Post #3540837
We're shocked, shocked I say that Claude Cowork is vulnerable to DLL sideloading. Well, not that shocked. https://discourse.ifin.network/t/claude-cowork-for-windows-vulnerable-to-dll-sideloading-closed-as-wont-fix/640
-
Post #3527243
Our Discourse will briefly be going down for maintenance. Should be back shortly!
-
Post #3526955
An IFIN community member caught this #ClickFix campaign, followed it, reversed the payload, and brought the IOCs. This is the juice right here. A perfect example that #ThreatIntelIsMutualAid https://discourse.ifin.network/t/compromised-website-hosting-clickfix-payload-leads-to-netsupport-rat-infection/633 #ThreatIntel #ThreatIntelligence #IFIN
-
Post #3496153
If you're running a SimpleHelp server, it's patch o'clock. Also maybe incident-response-o'clock. (It's always incident-response-o'clock somewhere) https://discourse.ifin.network/t/stealers-exploit-cve-2026-in-simplehelp-attack/629 #ThreatIntel #ThreatIntelligence #IFIN
-
Post #3473898
Maaaaybe just block the whole dot garden top-level domain. https://discourse.ifin.network/t/garden-tlds-change-to-a-bad-neighborhood/627 #ThreatIntel #ThreatIntelligence #IFIN
-
Post #3429968
If you're running Lantronix gear on the internet, you might want to check your logs for suspicious logins and command execution. https://discourse.ifin.network/t/lantronix-openwrt-luci-attacks/625 #ThreatIntel #ThreatIntelligence #IFIN
-
Post #3411906
Even if Chrome is nerfing old ones, ad blockers still matter. Get them on your users' systems for one of the most impactful one-move security wins available. https://ifin-intel.org/blog/ad-blocker/
-
Post #3360455
Let's talk about ClickFix. https://discourse.ifin.network/t/lets-talk-about-clickfix/603/1
-
Post #2489753
We are tracking the new Nightmare Eclipse exploits, and we even have some listed IoCs from the code/repo files for you. https://discourse.ifin.network/t/chaotic-eclipse-nightmare-eclipse-drops-two-windows-0days/437 #ThreatIntel #ThreatIntelligence #IFIN
-
Post #2450618
TanStack, a popular web UI framework has had its NPM packages compromised by another installment of Mini Shai-Hulud. https://discourse.ifin.network/t/mini-shai-hulud-strikes-again-tanstack-npm-packages-compromised/428 #ThreatIntel #ThreatIntelligence #IFIN
-
Post #2450616
RE: https://infosec.exchange/@ifin/116558531955700753 This has evolved to impact 170 packages, including those from Mistral and OpenSearch.