Elektrine
EN
Log in Register
Paige Chat Timeline Gallery Friends Lists Email Drive DNS Resolver Domains VPN Kairo Nerve
Remote

IFIN - The Independent Federated Intelligence Network

@ifin@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

The Independent Federated Intelligence Network.

IFIN is a 501(c)(3) not-for-profit public benefit corporation incorporated in California.

Our mission: Empower organizations to independently collect, analyze, and disseminate relevant cyber threat intelligence through training, open source tools, and a decentralized intelligence sharing network.

1174 Followers
48 Following
50 Posts
Joined December 18, 2025
Website:
https://ifin-intel.org
Community:
https://ifin.network
Support:
https://donorbox.org/ifin
News Feed:
https://news.ifin.network
Open post
IFIN - The Independent Federated Intelligence Network @ifin@infosec.exchange
· 5d ago
Our new project: IFIN Lists is a curated set of permanent blocks and perennial hunts that go beyond traditional indicators to include abused "legitimate" services that most organizations should not tolerate. https://ifin-intel.org/blog/lists/ #ThreatIntel #ThreatIntelligence #TIIMA
Announcing IFIN Lists | IFIN

Announcing IFIN Lists | IFIN

IFIN Lists is a project to build a well curated, community driven set of permanent block lists for all to use.

18
0
21
0
Open post
IFIN - The Independent Federated Intelligence Network @ifin@infosec.exchange
· 1mo ago
We're thrilled to announce IFIN has achieved 501(c)(3) recognition! Now we can get down to business. https://ifin-intel.org/blog/nonprofit/ #IFIN
It's Official: We're a Recognized Non-Profit | IFIN

It's Official: We're a Recognized Non-Profit | IFIN

IFIN has achieved 501(c)(3) status. What this means for us, and for you.

44
9
22
0
Open post
IFIN - The Independent Federated Intelligence Network @ifin@infosec.exchange
· 2mo ago
We're shocked, shocked I say that Claude Cowork is vulnerable to DLL sideloading. Well, not that shocked. https://discourse.ifin.network/t/claude-cowork-for-windows-vulnerable-to-dll-sideloading-closed-as-wont-fix/640
41
0
25
0
Open post
IFIN - The Independent Federated Intelligence Network @ifin@infosec.exchange
· 1mo ago
RE: https://mastodon.social/@zackwhittaker/117037185272316538 Folks fighting for ad blockers in your orgs: https://ifin-intel.org/blog/ad-blocker/
15
0
16
0
Open post
IFIN - The Independent Federated Intelligence Network @ifin@infosec.exchange
· 1mo ago
We caught a sample of ACR Stealer and went deep on it. Lots of sophistication for "just" an infostealer. https://discourse.ifin.network/t/acr-stealer-clickfix-etherhiding-and-stego-oh-my/694 #ThreatIntel #ThreatIntelligence #IFIN
15
0
14
0
Open post
IFIN - The Independent Federated Intelligence Network @ifin@infosec.exchange
· 2mo ago
If you pirate games, you should expect malware. That's a tale as old as 1970-01-01T00:00:00.000Z. But using Etherhiding as the second stage source? Well that's slightly newer. In case you couldn't tell, we're declaring war on #Etherhiding. More to come. https://discourse.ifin.network/t/pirated-games-come-with-a-side-of-amatera-stealer/675 #ThreatIntel #ThreatIntelligence #IFIN
17
0
14
0
Open post
IFIN - The Independent Federated Intelligence Network @ifin@infosec.exchange
· 2mo ago
Soooo Tenda devices have an admin backdoor. Potential redeployment locations: a wood chipper, the nearest active volcano, or that really annoying neighbor's house. No patch; have fun! https://discourse.ifin.network/t/cve-2026-11405-multiple-tenda-routers-have-an-admin-backdoor/646
21
2
11
0
Open post
IFIN - The Independent Federated Intelligence Network @ifin@infosec.exchange
· 2mo ago
Cursor will run anything called git.exe when you open it, but it isn't the only one. As a fork of VS Code, Cursor has inherited this behavior from its questionable parentage. https://discourse.ifin.network/t/remember-that-cursor-git-exe-bug-its-in-vscode-too/665
17
2
19
2
Open post
IFIN - The Independent Federated Intelligence Network @ifin@infosec.exchange
· 2mo ago
An IFIN community member caught this #ClickFix campaign, followed it, reversed the payload, and brought the IOCs. This is the juice right here. A perfect example that #ThreatIntelIsMutualAid https://discourse.ifin.network/t/compromised-website-hosting-clickfix-payload-leads-to-netsupport-rat-infection/633 #ThreatIntel #ThreatIntelligence #IFIN
23
0
17
0
Open post
IFIN - The Independent Federated Intelligence Network @ifin@infosec.exchange
· 1mo ago
Replying to @ifin@infosec.exchange
The easiest way to stop this attack (and the last one, btw) is to deny outbound Tor traffic and block downloads from archive.torproject[.]org in your environment. If the payloads can't do that, they can't continue past the first stage.
10
0
5
0
Open post
IFIN - The Independent Federated Intelligence Network @ifin@infosec.exchange
· 1mo ago
We continue to use our own RSS-Filter project to curate our feed aggregator. We've removed "Startups" from the other-wise excellent TechCrunch security news feed to keep the feed relevant and actionable. Our Newsfeed: https://news.ifin.network RSS-Filter: https://codeberg.org/ifin/rss-filter
10
0
5
0
Open post
IFIN - The Independent Federated Intelligence Network @ifin@infosec.exchange
· 2mo ago
The latest supply chain attack has some novelty, but the techniques should have long been mitigated in your network. IPFS, cryptocurrency, and Nostr have no place in a professional network. https://discourse.ifin.network/t/latest-miasma-attack-uses-blockchain-garbage-you-should-have-already-blocked/663 #ThreatIntel #ThreatIntelligence #IFIN
14
1
12
0
Open post
IFIN - The Independent Federated Intelligence Network @ifin@infosec.exchange
· 1mo ago
We've compiled the latest information regarding the Minnesota water systems attacks. https://discourse.ifin.network/t/minnesota-water-system-suffers-a-breach-due-to-exposed-access-keys/695 #ThreatIntel #ThreatIntelligence #IFIN
8
0
5
0
Open post
IFIN - The Independent Federated Intelligence Network @ifin@infosec.exchange
· 2mo ago
Maaaaybe just block the whole dot garden top-level domain. https://discourse.ifin.network/t/garden-tlds-change-to-a-bad-neighborhood/627 #ThreatIntel #ThreatIntelligence #IFIN
16
1
10
0
Open post
IFIN - The Independent Federated Intelligence Network @ifin@infosec.exchange
· 1mo ago
Replying to @ifin@infosec.exchange
This is what we're here for! If you see something suspicious and want someone else to check it out, drop us a tip! We take care of each other by sharing what we see.
6
0
3
0
Open post
IFIN - The Independent Federated Intelligence Network @ifin@infosec.exchange
· 1mo ago

Fantastic research by our community here on a continuing Lua-based campaign that uses Prometheus obfuscation and our old friend Etherhiding for C2 configuration acquisition.

https://discourse.ifin.network/t/luajit-loader-uses-prometheus-obfuscation-and-etherhiding/679

#ThreatIntel #ThreatIntelligence #IFIN

6
0
3
0
Open post
IFIN - The Independent Federated Intelligence Network @ifin@infosec.exchange
· 1mo ago
Replying to @ifin@infosec.exchange
Back!
5
0
1
0
Open post
IFIN - The Independent Federated Intelligence Network @ifin@infosec.exchange
· 1mo ago

The critical SharePoint vulnerability CVE-2026-50522 now appears to be under massive exploitation. We have context and current IOCs in this post. We've also updated the MISP feed with the same.

#ThreatIntel #ThreatIntelligence #IFIN

https://discourse.ifin.network/t/microsoft-sharepoint-cve-2026-50522/678

5
0
7
0
Open post
IFIN - The Independent Federated Intelligence Network @ifin@infosec.exchange
· 2mo ago
Replying to @ifin@infosec.exchange
This now has a CVE: CVE-2026-63030
5
0
1
0
Open post
IFIN - The Independent Federated Intelligence Network @ifin@infosec.exchange
· 1mo ago
Replying to @AnachronistJohn@zia.io
@AnachronistJohn@zia.io We use exactly one cookie for self-hosted, privacy-respecting site analytics via Plausible.
2
1
0
0
Open post
IFIN - The Independent Federated Intelligence Network @ifin@infosec.exchange
· 2mo ago
Replying to @ifin@infosec.exchange
A reminder that we have a MISP feed! https://misp.ifin.network/feed (/manifest.json for validation)
3
2
2
0
Open post
IFIN - The Independent Federated Intelligence Network @ifin@infosec.exchange
· 2mo ago
Replying to @tdelmas@mamot.fr
@tdelmas@mamot.fr Yes, and route confusion! https://www.tenable.com/cve/CVE-2026-63030
3
0
0
0
Open post
IFIN - The Independent Federated Intelligence Network @ifin@infosec.exchange
· 2mo ago
Replying to @ajn142@infosec.exchange
@ajn142@infosec.exchange @Sempf@infosec.exchange Fixed, thanks!
2
1
0
0
Open post
IFIN - The Independent Federated Intelligence Network @ifin@infosec.exchange
· 1mo ago
Replying to @fuzzychef@m6n.io
@fuzzychef@m6n.io It has the mission statement in the post!
1
0
0
0
Open post
IFIN - The Independent Federated Intelligence Network @ifin@infosec.exchange
· 1mo ago
Replying to @ifin@infosec.exchange
@AAKL@infosec.exchange @cR0w@infosec.exchange Well, sorta locally. The filesystem ("container") in this setup uses Durable Objects. https://developers.cloudflare.com/durable-objects/concepts/what-are-durable-objects/
What are Durable Objects?
Cloudflare Docs

What are Durable Objects?

Durable Objects provide globally unique, single-threaded compute instances with persistent storage on Cloudflare.

1
1
1
0
Open post
IFIN - The Independent Federated Intelligence Network @ifin@infosec.exchange
· 1mo ago
Replying to @jti42@infosec.exchange
@jti42@infosec.exchange @ysf@chaos.social @sodiboo@gaysex.cloud @archlinux@fosstodon.org @Antiz@fosstodon.org Thank you all! Here's our post in case you wish to contribute there: https://discourse.ifin.network/t/new-aur-attack-prompts-adoption-lock/698
1
0
0
0
Open post
IFIN - The Independent Federated Intelligence Network @ifin@infosec.exchange
· 1mo ago
Replying to @ysf@chaos.social
@ysf@chaos.social @jti42@infosec.exchange @sodiboo@gaysex.cloud Sorry, missed it. Yes, it's the same address, despite a different SHA256.
1
2
0
0
Open post
IFIN - The Independent Federated Intelligence Network @ifin@infosec.exchange
· 1mo ago
Replying to @jti42@infosec.exchange
@jti42@infosec.exchange @sodiboo@gaysex.cloud @ysf@chaos.social Thanks for the tip! We'll look into it and get this written up.
1
8
0
0
Open post
IFIN - The Independent Federated Intelligence Network @ifin@infosec.exchange
· 2mo ago
Replying to @iampytest1@infosec.exchange
@iampytest1@infosec.exchange Thanks! We'll play with other non-slop alternatives, but these are easy and uhhhh directly appealing to our target audience.
1
0
0
0
Open post
IFIN - The Independent Federated Intelligence Network @ifin@infosec.exchange
· 2mo ago
Replying to @Spartan_1986@infosec.exchange
@Spartan_1986@infosec.exchange @gayint@infosec.exchange 👀 Post it to the forum so we can work it!
1
1
0
0
Open post
IFIN - The Independent Federated Intelligence Network @ifin@infosec.exchange
· 1mo ago
Replying to @ifin@infosec.exchange
https://misp.ifin.network/feed/manifest.json
0
0
1
0
Open post
IFIN - The Independent Federated Intelligence Network @ifin@infosec.exchange
· 2mo ago
Replying to @AAKL@infosec.exchange
@AAKL@infosec.exchange We have this one a week ago! https://discourse.ifin.network/t/libssh2-vulnerability-before-1-11-1-cve-2026-55200/617
0
0
0
0
Open post
IFIN - The Independent Federated Intelligence Network @ifin@infosec.exchange
· 2mo ago
Our Discourse will briefly be going down for maintenance. Should be back shortly!
0
0
0
0
Open post
IFIN - The Independent Federated Intelligence Network @ifin@infosec.exchange
· 1mo ago
Replying to @AAKL@infosec.exchange
@AAKL@infosec.exchange @cR0w@infosec.exchange This isn't really about GitHub other than hosting the code. At present, the project runs locally on your compute. However, it is the height of hubris to release a sandboxing tool after the parade of sandboxing escapes we've seen. And to write it all in...TypeScript, no less.
0
1
0
0
Open post
IFIN - The Independent Federated Intelligence Network @ifin@infosec.exchange
· 2mo ago
Replying to @galaxis@mastodon.infra.de
@galaxis@mastodon.infra.de Thanks! Not sure how that happened but the CVE number was incorrect. It has been fixed. https://discourse.ifin.network/t/cve-2026-11405-multiple-tenda-routers-have-an-admin-backdoor/646
0
0
0
0
Open post
IFIN - The Independent Federated Intelligence Network @ifin@infosec.exchange
· 2mo ago
Replying to @ifin@infosec.exchange
Also, y'know, to reduce slop.
0
0
0
0
Open post
IFIN - The Independent Federated Intelligence Network @ifin@infosec.exchange
· 2mo ago
Replying to @ifin@infosec.exchange
Are we using a Trek title generator for our posts? Yes, yes we are. We don't want to take credit for someone else's art in previews.
0
0
0
0
Open post
IFIN - The Independent Federated Intelligence Network @ifin@infosec.exchange
· 1mo ago
Ah, I see the fear-mongering around the "open source" (not a thing; they mean open-weights, but actually really they mean "Chinese") models has kicked into high gear. https://www.cybersecuritydive.com/news/openai-hugging-face-hack-ai-models-black-hat/827167/
0
0
0
0
Open post
IFIN - The Independent Federated Intelligence Network @ifin@infosec.exchange
· 2mo ago
Replying to @Sempf@infosec.exchange
@Sempf@infosec.exchange @winterknight1337@infosec.exchange @mttaggart@infosec.exchange @neurovagrant@masto.deoan.org That's what really gets me. They went to the trouble of signing the binary, why not sign the library? Oh, is writing the code hard? I thought you fixed that problem Anthropic!
0
0
0
0
Open post
IFIN - The Independent Federated Intelligence Network @ifin@infosec.exchange
· 2mo ago
Replying to @Sempf@infosec.exchange
@Sempf@infosec.exchange @sternecker@infosec.exchange We have a thread ready and waiting! https://discourse.ifin.network/t/bad-epoll-lpe-linux-kernel-cve-2026-46242/641
0
1
0
0
Open post
IFIN - The Independent Federated Intelligence Network @ifin@infosec.exchange
· 1mo ago
Replying to @ysf@chaos.social
@ysf@chaos.social @jti42@infosec.exchange @sodiboo@gaysex.cloud The nnn-nerd package appears to be the same stager. Did you have the Tor address from your samples? It'd be good to compare.
0
1
0
0
Open post
IFIN - The Independent Federated Intelligence Network @ifin@infosec.exchange
· 2mo ago
Replying to @ifin@infosec.exchange
Does it bother anyone else that Nebula's logo is not in fact a nebula, but the planet Jupiter
0
1
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)
  • Source code

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 14:34:12 UTC