Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

RelayShieldAdmin

@relayshieldadmin@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

25-year telecom security veteran. Building @RelayShield — real-time SIM swap detection, infostealer credential monitoring, and domain threat intelligence via API. Watching the Telegram channels where your credentials are being sold. Security Insights: https://t.me/RelayShield

5 Followers
40 Following
24 Posts
Joined June 11, 2026
Open post
RelayShieldAdmin @relayshieldadmin@infosec.exchange
· 3mo ago
Supply chain attacks leave a signal trail in credential intelligence before malicious code fires — usually days to weeks before breach day. The Polymarket incident ($2.9M, June 26) is a documented case study: compromised vendor → stolen CI/CD tokens → malicious JS injected to frontend → $2.9M drained while everything looked normal to users. We mapped each precursor signal and the monitoring layer that catches it: [https://relayshield.hashnode.dev/how-relayshield-would-have-caught-the-polymarket-attack-before-it-cost-2-9-million?utm_source=hashnode&utm_medium=feed] #threatintel #supplychain #defi #infosec #cybersecurity
relayshield.hashnode.dev
2
1
0
0
Open post
RelayShieldAdmin @relayshieldadmin@infosec.exchange
· 3mo ago

RelayShield: breach, SIM swap, infostealer, domain lookalike, OAuth supply chain, and live IOC threat intel database lookup with REST API + verified n8n node.

75K+ IOCs from criminal Telegram channels, ThreatFox, URLhaus, CISA KEV, Feodo Tracker, and MalwareBazaar. Infostealer signal runs 24-72h ahead of public aggregators.

$499/mo — in-house SOC teams and lean security environments $999/mo — MSSPs and multi-client enrichment pipelines

api.relayshield.net/developers

#infosec #threatintelligence #cybersecurity #n8n #SOAR

infosec.exchange

Infosec Exchange

2
0
0
0
Open post
RelayShieldAdmin @relayshieldadmin@infosec.exchange
· 3mo ago

Crypto Shield Mobile is now live on the Solana dApp Store. It includes read-only wallet security monitoring (Solana, EVM, TON, BTC, XRP), address poisoning detection, NFT drainer/scam detection, and criminal-Telegram-sourced threat intel.

This release adds Mobile Wallet Adapter connect. Never asks for a seed phrase or private key — it's watch-only by design.

https://cryptoshieldmobile.relayshield.net

#infoSec #Solana #WalletSecurity

cryptoshieldmobile.relayshield.net
1
0
0
0
Open post
RelayShieldAdmin @relayshieldadmin@infosec.exchange
· 3mo ago
UNC4221 / UAC-0185 (Russia-aligned) has been silently reading Telegram, WhatsApp, and Signal messages via fake device-linking QR codes since 2022. Confirmed active June 2026. Attack chain: phishing message → fake device-link page → attacker's device linked → silent real-time message copy. No alerts, no notifications. IOC set from CERT-UA#12414 (32 indicators) ingested in RelayShield TI corpus. Check your linked devices now. Full breakdown: [https://hashnode.com/edit/cmr0ystn900010ajghg2v55pt] #OPSEC #Telegram #InfoSec #UAC0185 #ThreatIntel
Hashnode
Hashnode

Hashnode

Hashnode is the blogging platform for builders in tech. Start a blog on your own domain and get found in search and AI engines from day one. Free to start.

1
0
1
0
Open post
RelayShieldAdmin @relayshieldadmin@infosec.exchange
· 3mo ago

425,000+ rug pulls detected. 54% of all crypto threats. A rising chart and a loud Telegram community are not signal — they're part of the attack.

AI-generated phishing now delivers 53% of crypto scam attempts via email. Your inbox is the primary vector, not Discord or Twitter.

https://relayshield.hashnode.dev/rug-pulls-are-now-54-of-all-crypto-threats-here-s-how-they-stay-hidden-until-it-s-too-late?utm_source=hashnode&utm_medium=feed

#infosec #crypto #web3security #rugpull #DeFi #cybersecurity #scam

relayshield.hashnode.dev
1
0
0
0
Open post
RelayShieldAdmin @relayshieldadmin@infosec.exchange
· 3mo ago
11.1 million devices infected with infostealers in 2025. 3.3 billion credentials now circulating in criminal markets. Vidar surged to 73% of infected hosts by early 2026. Lumma dropped to 1.1%. The ecosystem rotates tools faster than detection catches up. MaaS entry point: $60/month. Less than most SaaS subscriptions. The ransomware connection that gets overlooked: stolen VPN/RDP credentials are how attackers enter the perimeter as legitimate users, weeks before the payload fires. Full breakdown: https://relayshield.hashnode.dev/infostealers-credential-theft-2025#infosec #infostealer #malware #threatintel #ransomware #cybersecurity
relayshield.hashnode.dev
0
1
0
0
Open post
RelayShieldAdmin @relayshieldadmin@infosec.exchange
· 3mo ago
RelayShield's Threat Intelligence & Identity Security API is now live on AWS Marketplace — 2M+ IOC corpus, 37+ monitored criminal Telegram channels, STIX/TAXII 2.1 and MISP feed export. https://aws.amazon.com/marketplace/pp/prodview-z3izf6val3jb2 #cybersecurity #threatIntel #AWS #MSP #MSSP
aws.amazon.com

AWS Marketplace: RelayShield - Threat Intelligence & Identity Security API

RelayShield delivers threat intelligence and identity security via REST API - 4.5M+ IOC corpus, breach detection, SIM swap monitoring, infostealer exposure, ransomware victim tracking, and session hijack detection. Built for MSPs, MSSPs, and security-forward development teams.

0
0
0
0
Open post
RelayShieldAdmin @relayshieldadmin@infosec.exchange
· 2mo ago
Shipped today: RelayShield's AI-agent security checks are live as an MCP server on Hugging Face including MCP server risk, prompt-injection breach detection, agent framework CVE monitoring, and bulk agent-identity risk scoring. Same "Agentic Attack Surface" thesis behind our AgentCore/x402 work: security built for how agents actually get compromised, not humans. Live now: https://huggingface.co/blog/relayshieldadmin/relayshield-agentic-attack-surface-mcp #AIAgents #MCP #AgentSecurity #CyberSecurity
Agent Security Checks You Didn't Know You Needed: MCP Server Risk & Prompt-Injection Breach Detection
huggingface.co

Agent Security Checks You Didn't Know You Needed: MCP Server Risk & Prompt-Injection Breach Detection

A Blog post by relayshield on Hugging Face

0
0
0
0
Open post
RelayShieldAdmin @relayshieldadmin@infosec.exchange
· 2mo ago

New from RelayShield: four #AIsecurity checks for agents built with smolagents, published as an MCP server on @huggingface.

  • MCP server reputation check before your agent connects
  • Prompt-injection pattern detection on ingested content
  • Tech-stack CVE monitoring (covers agent frameworks themselves — Langflow's CVE-2025-3248 was the initial-access vector in the first documented autonomous-agent ransomware op)
  • Bulk identity-risk scoring

Self-serve, pay-per-call, no subscription.

https://huggingface.co/blog/relayshieldadmin/smolagents-agent-security-tools

#InfoSec #MCP #AgentSecurity #ThreatIntel

Giving agent frameworks a threat-intel safety check: RelayShield's smolagents tools
huggingface.co

Giving agent frameworks a threat-intel safety check: RelayShield's smolagents tools

A Blog post by relayshield on Hugging Face

0
0
0
0
Open post
RelayShieldAdmin @relayshieldadmin@infosec.exchange
· 2mo ago

An AI agent on AWS Bedrock AgentCore just autonomously found and paid for one of our security APIs via Coinbase's x402 Bazaar. Real on-chain payment, zero custom code, verifiable tx:

0x1cb95ce37d54201b4def745269c42790fdb9bc7255f102aa648cf6f91fab0e3a (Base)

As agents start transacting autonomously, they become an attack surface. We built the security layer to be agent-native too witih 23 endpoints now agent-discoverable + payable.

#infosec #AI #x402

api.relayshield.net/developers

infosec.exchange

Infosec Exchange

0
0
1
0
Open post
RelayShieldAdmin @relayshieldadmin@infosec.exchange
· 3mo ago

Remus Stealer: new MaaS infostealer, $250-$1,000/mo tiers, Lumma-derived code, ships with Google OAuth cookie restoration (regenerates session access even after a password change). Streams stolen logs straight to Telegram.

Wrote up what it does and what to actually check if you suspect compromise: [https://www.linkedin.com/pulse/remus-stealer-new-250-a-month-infostealer-renting-out-your-e1goc/?trackingId=1qeb%2Bv0Gd2NBf6e%2B3%2B%2BZig%3D%3D]

#infoSec #threatIntel #malware

linkedin.com
0
0
0
0
Open post
RelayShieldAdmin @relayshieldadmin@infosec.exchange
· 3mo ago

For the DeFi/prediction markets folks here:

We ingested the full UNC4221/UAC-0185 IOC set (June 2026 bulletin — 32 indicators, CERT-UA#12414) and launched a free public badge endpoint that DeFi protocols can embed to show live credential-layer risk status.

`https://api.relayshield.net/v1/badge?domain=example.com`

The credential/supply chain attack vector is real, it's active, and it's unmonitored by most DeFi security tooling.

t.me/RelayShield

api.relayshield.net
0
1
0
0
Open post
RelayShieldAdmin @relayshieldadmin@infosec.exchange
· 3mo ago

We've been quietly building a threat intel API for MSPs and security teams.

Current corpus: 600K+ IOCs, 1,000+ malware families, 17 live feeds (C2IntelFeeds, Feodo Tracker, PhishTank, criminal Telegram channels).

New this month: identity graph correlation from criminal dumps, ransomware victim signals, NHI/token exposure detection, GitHub secret scanning.

REST API, n8n node, MCP server. Free IOC lookup at api.relayshield.net/developers

#threatintel #infosec #cybersecurity #MSP #MSSP #API

infosec.exchange

Infosec Exchange

0
0
0
0
Open post
RelayShieldAdmin @relayshieldadmin@infosec.exchange
· 3mo ago

400,000+ indicators of compromise. One API. Pay per call.

RelayShield is now a verified node on n8n Cloud — breach check, infostealer exposure, SIM swap detection, session risk, IOC lookup, ransomware risk, identity graph, supply chain risk. 12 actions total.

Submitted to Zapier App Directory this week.

$0.10/breach check. No subscription required.

relayshield.net/developers

#infosec #threatintel #n8n #automation #cybersecurity

infosec.exchange

Infosec Exchange

0
0
0
0
Open post
RelayShieldAdmin @relayshieldadmin@infosec.exchange
· 3mo ago

Cybernews found a 24 billion record credential database sourced from 30+ criminal Telegram channels.

Most records: infostealer logs with plaintext passwords and active session cookies.

The owner was actively updating it using CVE trackers and breach news monitoring.

Full writeup:

https://relayshield.hashnode.dev/24-billion-credentials-just-leaked-is-yours-in-there?utm_source=hashnode&utm_medium=feed

#infosec #infostealer #databreach #threatintel #opsec

relayshield.hashnode.dev
0
0
0
0
Open post
RelayShieldAdmin @relayshieldadmin@infosec.exchange
· 3mo ago

OnyxC2 MaaS: $250/month, 0/71 AV detections, 4,717 session cookies stolen from a single device. Refund policy included. The stolen VPN credentials are the ransomware entry point that comes weeks later.

Full breakdown: https://relayshield.hashnode.dev/onyxc2-when-250-month-buys-everything-on-your-employees-devices?utm_source=hashnode&utm_medium=feed

#infosec #malware #infostealer #ransomware #MaaS #SMBSecurity #cybersecurity

relayshield.hashnode.dev
0
0
0
0
Open post
RelayShieldAdmin @relayshieldadmin@infosec.exchange
· 2mo ago
We checked 24 DeFi/fintech/prediction-market brands for lookalike domains: 341 found, registered and resolving right now. Only 1 is currently blocklist-flagged. That's a floor, not a ceiling: blocklists catch domains after they're weaponized, not before. We cross-check registration age + TLS cert issuance timing instead. That's the leading indicator. Full writeup: [https://relayshield.hashnode.dev/341-lookalikes-1-alarm-domain-hygiene-research?utm_source=hashnode&utm_medium=feed] Free self-check: badge.relayshield.net #infosec #phishing #DomainSecurity
relayshield.hashnode.dev
0
0
0
0
Open post
RelayShieldAdmin @relayshieldadmin@infosec.exchange
· 2mo ago
New reference implementation shipped today: #LangChain middleware that gates AI agents from connecting to unfamiliar MCP servers behind a mandatory security check. It is not an optional tool call the agent is free to skip. https://github.com/nzdsf2-gif/relayshield-langchain-gate #InfoSec #MCP #AgentSecurity #AIsecurity
GitHub

GitHub - nzdsf2-gif/relayshield-langchain-gate: Reference mandatory pre-execution gate (LangChain wrap_tool_call) for MCP server connect/install risk checks

Reference mandatory pre-execution gate (LangChain wrap_tool_call) for MCP server connect/install risk checks - nzdsf2-gif/relayshield-langchain-gate

0
0
0
0
Open post
RelayShieldAdmin @relayshieldadmin@infosec.exchange
· 2mo ago
If one of your AI agents leaked its LLM API key tomorrow, the first signal you'd get is the bill. No endpoint compromised, so EDR sees nothing. No anomalous login, so the SIEM sees nothing. No data left, so DLP sees nothing. Sysdig measured $46,000/day from compromised Bedrock creds. We match 19 key formats across 14 providers, including DeepSeek, Qwen and Moonshot, which most scanners miss entirely. Free check, no API key: https://blog.relayshield.net/your-ai-agents-have-credentials-someone-is-already-looking-for-them #LLMjacking
Your AI agents have credentials. Someone is already looking for them. | RelayShield
blog.relayshield.net

Your AI agents have credentials. Someone is already looking for them. | RelayShield

RelayShield

0
0
0
0
Open post
RelayShieldAdmin @relayshieldadmin@infosec.exchange
· 2mo ago
We searched public GitHub for AWS keys leaked against a domain. 4,240 hits. The top five results: a docs table, a literal AKIA.... placeholder, a redaction tool's own README, a link list, and a domain allowlist. Five out of five. Not one contained a credential. Any scanner that treats a search hit as a finding calls all five a CRITICAL exposure. Free local scanner, MIT: #infosec #devsecops #appsec #opensource
blog.relayshield.net
0
0
0
0
Open post
RelayShieldAdmin @relayshieldadmin@infosec.exchange
· 2mo ago
MFA worked, so attackers stopped attacking it. Two stealer families this month, same shift: don't beat the login, occupy the session after it. One drives a real browser on an invisible desktop on the victim's own machine. Impossible-travel, device fingerprinting, behavioural scoring all pass honestly. Password = delivery mechanism. Session cookie and cloud token = payload. #infosec #threatintel
blog.relayshield.net
0
0
0
0
Open post
RelayShieldAdmin @relayshieldadmin@infosec.exchange
· 2mo ago
12.08M autonomous agent payments last month. Average: $0.0635. At six cents nobody approves anything. The agent finds a service, gets a 402, signs, pays. Nothing in that flow checks who received the money. x402 verifies the payment and has no opinion on the recipient. A correct payment to a drainer is still a correct payment. https://blog.relayshield.net/your-agent-has-a-wallet-nothing-asks-who-it-is-paying #infosec #AIagents #x402
Your Agent Has a Wallet Now. Nothing in the Flow Asks Who It Is Paying. | RelayShield
blog.relayshield.net

Your Agent Has a Wallet Now. Nothing in the Flow Asks Who It Is Paying. | RelayShield

12.08 million autonomous agent payments in 30 days, averaging $0.0635. At six cents a call nobody approves anything, and nothing in the x402 flow checks who received the money. Measured network data and the five counterparty checks that close the gap.

0
2
0
0
Open post
RelayShieldAdmin @relayshieldadmin@infosec.exchange
· 1mo ago
Anthropic: infostealers stole Claude login sessions and drained user usage. Not LLMjacking. That is API key theft, fixed by rotating the key. This is session cookie theft, and per Anthropic the attacker may skip password and 2FA entirely. Change your password on an infected machine and you just minted them a new cookie. Clean first, revoke second, rotate third. [https://blog.relayshield.net/this-is-not-llmjacking-and-rotating-your-key-will-not-fix-it]
blog.relayshield.net
0
0
0
0
Open post
RelayShieldAdmin @relayshieldadmin@infosec.exchange
· 2mo ago
Replying to
@eduzsh@mastodon.social That is a better way to put it. The approval step was doing identity work nobody wrote down, so nothing looked like it was removed. The first check we'd add is not wallet screening. A fresh scam has a clean address by definition. It should be the service entry: registered days ago, name one character off something popular. Typosquatting a discovery listing is the cheapest attack in this ecosystem and nothing currently stops it.
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 21:40:42 UTC