Elektrine lite

← Feed

Reput.io

reput_io@infosec.exchange

<p>Whitelist intelligence API for SOC teams. We tell you what&#39;s already legit so you stop chasing false positives.</p><p>Weekly Reputation Radar: how attackers borrow the reputation of trusted infra. Plus build-in-public notes.</p><p>1.4M indicators, 200+ sources.</p>

Posts

  • Post #4278423

    New backdoor TELESHIM runs its command-and-control straight through Telegram. The reason is boring and effective: most security filters whitelist telegram.org, so the traffic just blends in. That&#39;s the trap with allowlists. &quot;Trusted domain&quot; and &quot;safe right now&quot; are not the same thing. A messaging platform can be legitimate AND the exact channel a backdoor is using this week. We do not blanket-allow telegram.org. We flag it investigate and keep the reason attached: heavi...

  • Post #4192884

    Last week Hugging Face got breached by an autonomous AI agent. This week we found out who it was: OpenAI&#39;s own models, during an eval, escaping the sandbox through a self-hosted package proxy. The escape hatch was the most trusted, least-watched box in the building. That&#39;s the pattern this week: not the destination, the intermediary. Proxy, gov portal, naming service. https://www.reput.io/blog/reputation-radar-04

  • Post #4013330

    A theme worth sitting with from this week&#39;s reporting: the malicious traffic wasn&#39;t hiding near trusted infrastructure, it was flowing through it. Group-IB&#39;s HollowGraph runs its C2 inside a compromised Microsoft 365 calendar. Operators plant tasking as calendar events, and stolen files come back out as events, all over the real Graph API. https://www.reput.io/blog/reputation-radar-03 #blueteam #threatintel #infosec

  • Post #3983813

    HollowGraph runs its entire C2 over Microsoft Graph: calendar events dated to the year 2050, used as a dead-drop. All the malicious traffic looks like normal Microsoft 365. The one thing it can&#39;t hide behind Microsoft&#39;s brand: refreshing the stolen Azure credentials. That goes out over DNS to cloudlanecdn[.]com, a domain dressed up as a CDN. Solid write-up from Group-IB: https://www.group-ib.com/blog/hollowgraph-microsoft-365/ #threatintel #blueteam #infosec

  • Post #3833661

    This week an AI agent stood up a working command-and-control server in about six minutes, with the human doing roughly 11% of the work (Trend Micro&#39;s writeup on &quot;Patriot Bait&quot;). The reputation angle: its old C&amp;C ran through Cloudflare tunnels until firewalls caught on. The infra keeps hiding behind trusted names, now AI just builds it faster. Reputation Radar #2: https://www.reput.io/blog/reputation-radar-02 #blueteam #threatintel #infosec

  • Post #3782325

    Supply chain reminder from Socket: five malicious versions of the jscrambler npm package shipped a Rust infostealer via a preinstall hook. The catch with these: the package was already trusted, so nothing in its reputation warns you. The tell is in the behavior, a sudden preinstall hook dropping a native binary. https://socket.dev/blog/jscrambler-supply-chain-attack #blueteam #threatintel #infosec

  • Post #3715761

    ORB networks are borrowed reputation at the network layer. Cisco Talos is tracking UAT-7810 expanding its &quot;LapDogs&quot; relay network by compromising internet-facing Ruckus and ASUS routers. Espionage traffic exits through a real device on a real ISP, so the source IP carries a home&#39;s or small business&#39;s clean reputation, not the attacker&#39;s. A reputation lookup on the relay tells a defender almost nothing; what&#39;s off is the traffic pattern. https://thehackernews.com/2026/...

  • Post #3674969

    This week&#39;s infosec news had one shape: attackers barely built any infrastructure of their own. They borrowed everyone else&#39;s good name instead. Agentic botnets riding trusted AI tools. The NetNut residential-proxy takedown. Fake Google/Cloudflare pages. 81M logins against M365. All of it wearing reputation that reads clean. So we started a weekly read on exactly that. Reputation Radar #1: https://www.reput.io/blog/reputation-radar-01 #blueteam #threatintel #SOC

  • Post #3628679

    Most alert triage starts at the blocklist. We think that&#39;s backwards. A blocklist miss doesn&#39;t mean benign, it means &quot;not on a list I checked&quot;. So the faster first question is &quot;is this known-good?&quot; Clear the legit infra, and what&#39;s left is a smaller, higher-signal pile. We wrote up an order of operations that does that, and where it&#39;s NOT safe to auto-clear (hint: cloud and CDN). https://www.reput.io/blog/soc-alert-triage-known-good-first #blueteam #SOC #t...

  • Post #3551672

    Small thing we just shipped: every new Reput.io account gets full data for 15 days, whatever plan you pick. That means the complete response on every lookup: provider detection, the reasons behind a verdict, geo, investigation hints. The context that helps you actually clear or escalate an alert. Free tier stays free after. https://reput.io #blueteam #threatintel #infosec