Elektrine
EN
Log in Register
Paige Chat Timeline Gallery Friends Lists Email Drive DNS Resolver Domains VPN Kairo Nerve
Remote

tomcat

@tomcat@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

If olive oil comes from olives 🫒 where does baby oil come from? 🤔 🥸

76 Followers
20 Following
32 Posts
Joined November 12, 2022
webpage:
https://tomcat-links.surge.sh
Status:
@tomcat.stateofus.eth
Open post
tomcat @tomcat@infosec.exchange
· 1d ago
⚠️ Transparent Tribe is targeting government and defense entities in India and Afghanistan with a new Rust backdoor. RUSTYSHADE uses private GitHub repos for encrypted C2, while post-compromise activity includes Windows and Linux file stealers. Read more about Operation RapidRust: https://thehackernews.com/2026/09/transparent-tribe-deploys-new-rust.html

Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2

1
0
0
0
Open post
tomcat @tomcat@infosec.exchange
· 1mo ago
🛑 Atlassian's AI assistant Rovo can be tricked into sending Jira and Confluence data to attackers. Two prompt-injection paths can make Rovo pull data the signed-in user can access and send it to an attacker-controlled server. See how both chains work: https://thehackernews.com/2026/08/atlassian-rovo-can-be-tricked-into.html

Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

2
0
0
0
Open post
tomcat @tomcat@infosec.exchange
· 1mo ago
🚨 Same URL. Malware for Macs, decoys for scanners. Microsoft tracked over 250 ClickFix domains using browser fingerprinting to decide who sees the fake GitHub download and who sees nothing suspicious. Inside the cloaking system: https://thehackernews.com/2026/08/over-250-clickfix-domains-use-browser.html

Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures

1
0
0
0
Open post
tomcat @tomcat@infosec.exchange
· 2mo ago

CrashStealer uses a signed and Apple-notarized macOS dropper to pass Gatekeeper checks.

Once launched, it can steal browser credentials, wallet data, password manager records, files, and keychain material.

How the attack chain works: https://thehackernews.com/2026/07/crashstealer-macos-malware-uses.html

2
0
0
0
Open post
tomcat @tomcat@infosec.exchange
· 2mo ago

🛑 A newly found 15-year-old #Linux kernel flaw, GhostLock (CVE-2026-43499), could let any logged-in user gain root on unpatched distributions.

A working exploit code is now public, and it escaped containers in tests.

Read details here: https://thehackernews.com/2026/07/15-year-old-ghostlock-flaw-enables-root.html

Infosec Exchange

2
0
0
0
Open post
tomcat @tomcat@infosec.exchange
· 1mo ago
🚨 Microsoft 365 Copilot can quietly alter figures during a Word drafting or editing operation, then copy the hidden instructions into the document it creates. That generated file can carry the manipulation into a later Copilot session. Here’s how the chain works: https://thehackernews.com/2026/07/microsoft-copilot-for-word-can-copy.html

Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents

1
0
0
0
Open post
tomcat @tomcat@infosec.exchange
· 1mo ago
⚠️ Two compromised joyfill npm beta packages run malware as soon as Node.js imports them. No install hook needed. The implant fetches a DEV#POPPER-linked RAT through three blockchains, while a detached branch can keep running after builds or tests exit. Read the full story: https://thehackernews.com/2026/07/two-compromised-joyfill-npm-packages.html

Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js

1
0
0
0
Open post
tomcat @tomcat@infosec.exchange
· 1mo ago
🚨 After law enforcement disrupted JackSkid, Dysphoria shifted its IoT botnet C2 to blockchain name services and infected-device relays. Weak Telnet and SSH passwords remain the main way in. Read how the botnet adapted: https://thehackernews.com/2026/07/dysphoria-iot-botnet-adds-blockchain-c2.html

Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption

1
0
0
0
Open post
tomcat @tomcat@infosec.exchange
· 1mo ago
🚨 Cl0p-linked attackers are actively exploiting a critical unauthenticated RCE in internet-exposed PTC Windchill and FlexPLM systems. They chain two flaws, drop hex-named JSP webshells, and steal engineering data for double extortion. Manufacturing, automotive, aerospace, and retail firms are the main targets. Full details → https://thehackernews.com/2026/07/cl0p-affiliates-target-internet-exposed.html
1
0
0
0
Open post
tomcat @tomcat@infosec.exchange
· 1mo ago
🛑 No link. No attachment. Just viewing the email. A Russian state-supported espionage group exploited a Zimbra zero-day for at least 5 months to steal passwords, 2FA recovery codes, organization directories, and 90 days of mail. Read how ZimReaper worked - https://thehackernews.com/2026/07/russian-espionage-group-exploited.html
1
0
0
0
Open post
tomcat @tomcat@infosec.exchange
· 1mo ago

https://hunt.io/blog/thailand-ministry-finance-targeted-with-hermes-ai-agent

1
0
0
0
Open post
tomcat @tomcat@infosec.exchange
· 1mo ago
🚨 A flaw in Ubuntu’s snap-confine could turn local user access into root. CVE-2026-8933 chains FUSE and symlink race conditions to plant malicious udev rules and execute commands as root. Default Ubuntu #Linux Desktop 24.04, 25.10, and 26.04 installations are affected. Read how the exploit works: https://thehackernews.com/2026/07/ubuntu-snap-confine-flaw-could-give.html
1
0
0
0
Open post
tomcat @tomcat@infosec.exchange
· 2mo ago
🛑 MFA didn’t stop Kratos. The phishing kit stole Microsoft 365 session cookies, letting attackers enter accounts without another MFA check. Police took 200+ servers offline and arrested the alleged operator in Indonesia. But about 1,800 customers may still have the code. Read: https://thehackernews.com/2026/07/police-dismantle-kratos-phishing-kit.html
1
0
0
0
Open post
tomcat @tomcat@infosec.exchange
· 2mo ago
🚨 A malware operator left its server wide open, exposing a 1,048-file phishing toolkit. A live campaign used a fake Mexican government site and WebDAV to drop an in-memory infostealer. The recovered files point to an AI-assisted build-and-test workflow. Read more: https://thehackernews.com/2026/07/exposed-server-reveals-ai-assisted.html
1
0
0
0
Open post
tomcat @tomcat@infosec.exchange
· 2mo ago
It appears the bridge TeleSwap had a $735K+ exploit on July 15, 2026 and still has not disclosed the incident publicly after five days. Shortly after the suspicious outflows its Bitcoin hot wallet stopped processing transactions. Two hours ago the attacker deposited the funds to Tornado. Theft addresses bc1pz95zv3qhpmt52yezs84a5zrddrk5jsxm8a60rln5kzlk06e87a3q8pf79l 0x2448cbaee50a67030692b7519a954e5550dc2718 0xfc5048fbba2f74ed482ffcd7663601f818c5bb47 0xf8706a51f8df01a71f408e50c901dd14916a12c7 TeleSwap Bitcoin hot wallet bc1q5wnpn4k99wc587maaaa6eqnx27g4r6mduxg2s5
1
0
0
0
Open post
tomcat @tomcat@infosec.exchange
· 2mo ago
🛑 Hugging Face, the world’s largest AI model repository, says an autonomous AI agent breached its production systems through a malicious dataset. It accessed internal data and service credentials, then moved across several clusters through thousands of actions in short-lived sandboxes. Full story: https://thehackernews.com/2026/07/worlds-largest-ai-model-repository.html
1
0
0
0
Open post
tomcat @tomcat@infosec.exchange
· 2mo ago
🕷 Bugs Alerts ━━━━━━━━━━━━━━━━━━━━━ 🚨 New Vulnerability! 🆔 CVE ID: CVE-2026-12228 📊 Severity: 🟠 HIGH 📈 CVSS Score: 8.7 📅 Published: 2026-07-18 21:17 UTC 📝 Description: A stored cross-site scripting (XSS) vulnerability exists in the POST /api/prompts/share endpoint of parisneo/lollms (latest version). The endpoint stores attacker-controlled prompt_content into DBDirectMessage.content without server-side sanitization. When a victim opens the direct message (DM) thread, the message is rendered by the DM UI through MessageContentRenderer, which uses v-html... ━━━━━━━━━━━━━━━━━━━━━ 👨‍💻
1
0
0
0
Open post
tomcat @tomcat@infosec.exchange
· 2mo ago

⚡ UPDATE: #wp2shell now has two CVEs, and a working proof-of-concept is public.

CVE-2026-63030 breaks REST batch routing CVE-2026-60137 injects SQL

Chained, they give an anonymous attacker code execution on affected WordPress sites.

How the exploit path works: https://thehackernews.com/2026/07/new-wp2shell-wordpress-core-flaw-lets.html

1
0
0
0
Open post
tomcat @tomcat@infosec.exchange
· 2mo ago
🛑 URGENT - A single anonymous HTTP request can run code on an unpatched #WordPress 6.9 or 7.0 site, even on a default install with zero plugins. The new wp2shell flaw sits in core and still has no CVE for scanners to match. Affected releases and mitigations 🠖 https://thehackernews.com/2026/07/new-wp2shell-wordpress-core-flaw-lets.html
1
0
0
0
Open post
tomcat @tomcat@infosec.exchange
· 2mo ago

🛑 Two Scattered Spider hackers have been sentenced to 5.5 years each for the £29 million TfL attack.

The intrusion left 148 systems inoperable, disrupted Dial-a-Ride and payment services, and forced all 27,000 employees into the office for password resets.

Here's how investigators tied them to the attack: https://thehackernews.com/2026/07/two-scattered-spider-hackers-get-55.html

1
0
0
0
Open post
tomcat @tomcat@infosec.exchange
· 2mo ago

⚠️ Researchers found raw LLM reasoning and an AI safety disclaimer left inside TuxBot v3 Evolution.

The unfinished IoT botnet packs 1,496 Telnet credential pairs and exploit code for more than 30 device families.

What already works: https://thehackernews.com/2026/07/tuxbot-v3-evolution-shows-signs-of-llm.html

1
0
0
0
Open post
tomcat @tomcat@infosec.exchange
· 2mo ago

🔥 Microsoft patched a record 622 CVEs, including two exploited zero-days in SharePoint Server and AD FS.

The SharePoint flaw allows remote, unauthenticated privilege escalation. The AD FS bug lets authenticated attackers elevate privileges locally.

Here's what to patch first: https://thehackernews.com/2026/07/microsoft-patches-record-622-flaws.html

1
0
0
0
Open post
tomcat @tomcat@infosec.exchange
· 2mo ago
🚨 Four malware clusters targeted Pakistani police with PlugX, ShadowPad, Remcos, and Cobalt Strike. At Balochistan Police, attackers used a hacked complaint portal to deliver malware. Read the full report: https://thehackernews.com/2026/07/hackers-weaponize-balochistan-police.html
1
0
0
0
Open post
tomcat @tomcat@infosec.exchange
· 2mo ago

🚨 Zimbra has fixed a critical stored XSS flaw in its Classic Web Client.

A crafted email could run malicious code when opened and expose mailbox information, session data, or account settings.

Read the full story on THN 🠖 https://thehackernews.com/2026/07/critical-zimbra-flaw-could-let-crafted_0483473395.html

Zimbra has not reported in-the-wild exploitation. Update to version 10.1.19.

1
0
0
0
Open post
tomcat @tomcat@infosec.exchange
· 2mo ago
🛑 WARNING - Hackers exploited the "Ill Bloom" flaw to drain $3.1 million from 431 #cryptocurrency wallets. Weak recovery phrase generation left some older mobile wallets created between 2016 and 2018 exposed, potentially allowing attackers to reconstruct private keys and gain unauthorized access. Check the details on THN 🠖 https://thehackernews.com/2026/07/attackers-exploit-ill-bloom.html
1
0
0
0
Open post
tomcat @tomcat@infosec.exchange
· 2mo ago

🛑 WARNING - Meta’s new Muse Image tool can let others use your public #Instagram photos in AI-generated images UNLESS you opt out.

Users can @-mention public Instagram accounts in Meta AI to pull public photos into new visuals, and existing AI creations may not be deleted after you disable reuse.

Here’s how to turn it off 🠖 https://thehackernews.com/2026/07/metas-new-ai-image-tool-lets-others-use.html

1
0
0
0
Open post
tomcat @tomcat@infosec.exchange
· 2mo ago
EvilTokens phishing can look clean during URL checks. The real page stays encrypted until it opens in the victim’s browser, then uses Microsoft device-code phishing to push toward Microsoft 365 account takeover. The blind spot is browser visibility, not just email scanning. Read: https://thehackernews.com/2026/07/new-ghost-phishing-wave-is-breaking.html
1
0
0
0
Open post
tomcat @tomcat@infosec.exchange
· 2mo ago
https://thehackernews.com/2026/07/ransomware-groups-turn-to-citrix-bleed.html
1
0
0
0
Open post
tomcat @tomcat@infosec.exchange
· 2mo ago
🔥 Google disrupted #NetNut, a proxy network spanning at least 2 million home devices. In one June week, GTIG saw 316 threat clusters using suspected NetNut exit nodes to hide location and guess passwords. The simple risk: your home IP becomes someone else’s relay. Learn more: https://thehackernews.com/2026/07/google-disrupts-netnut-residential.html
0
0
0
0
Open post
tomcat @tomcat@infosec.exchange
· 1mo ago
⚠️ DevMan RaaS now runs a full affiliate portal. Experts (tracking it as Funky Mantis) say the platform handles payload builds, victim records, chat, teams, support, and payouts in one place. Affiliates get structured workflows, deadlines, and an 80/20 cut. 184 victims claimed so far. Read: https://thehackernews.com/2026/07/devman-raas-portal-centralizes-payload.html
0
0
0
0
Open post
tomcat @tomcat@infosec.exchange
· 1mo ago
‼️ WARNING -- Critical Rails flaw CVE-2026-66066 could let unauthenticated attackers read server files through crafted image uploads. The bug affects apps using Active Storage with Vips. Stolen Rails keys, database credentials, cloud keys, and API tokens could enable RCE. Patch now. Read the full story - https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html
0
0
0
0
Open post
tomcat @tomcat@infosec.exchange
· 1mo ago
‼️ BREAKING - A newly discovered #WordPress pre-auth XSS affects every version. XSS2Shell (CVE-2026-64638) can run attacker-controlled JS in a site's origin without a login. With a logged-in Administrator, one click, and required deployment conditions, it can be chained to PHP code execution. Update your WordPress sites ASAP 🠖 https://thehackernews.com/2026/08/new-wordpress-pre-auth-xss-could-lead.html
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)
  • Source code

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 14:55:37 UTC