Cyber Intel Brief: Vect, BreachForums, and TeamPCP Converge
An unprecedented ransomware partnership that mobilizes 300,000 cybercrime forum members and weaponizes stolen supply chain credentials.Hank Schless (Dataminr)
reshared this
An unprecedented ransomware partnership that mobilizes 300,000 cybercrime forum members and weaponizes stolen supply chain credentials.Hank Schless (Dataminr)
reshared this
A Iranian hacktivist group named Harakat Ashab al-Yamin al-Islamia was allegedly the one behind the cyberattack on LA Metro last month
darkowl.com/blog-content/harak…
Explore Harakat Ashab al-Yamin al-Islamia: is it a new distinct organization or part of a broader Iranian-Aligned network?DarkOwl Content Team (DarkOwl, LLC)
reshared this
TL;DR: Use our software if you wanna turn your democracy into a dictatorship! We have a FAQ page!
reshared this
This is literally supervillain shit.
Actually? It's worse than old fashioned supervillain shit. We need a new word for *this* level of villainy...
Hypervillain? idk...
help me out here....
I know everyone's hungering for more cyber reads on Friday afternoon, so we've published a long read on Handala and related MOIS personas, expanding greatly on the shorter post from April 6.
We were originally going to keep this one closely held, but the number of questions we're fielding about IR threat actors, and some trends in current whispernets, convinced us to publish it instead.
#threatintel #cybersecurity #infosec
dti.domaintools.com/research/m…
Explore the evolution of MOIS-linked actors Homeland Justice, Karma, and Handala. Analysis of destructive malware, surveillance integration, and the 2026 Stryker incident.DomainTools
reshared this
Florida capital city Tallahassee has shut down its IT network after a mysterious cyberattack on Friday
The surrounding Leon County disconnected from the city network to prevent contamination (aka ransomware language)
eu.tallahassee.com/story/news/…
The city of Tallahassee has confirmed it was the target of a cyberattack earlier Friday morning, and a county IT administrator says they have disconnected from the internet., Tallahassee Democrat (Tallahassee Democrat)
reshared this
Calif researchers say they found an RCE in the Qmail email transfer agent using one single Claude prompt, and one very dumb one too
"Find vulnerabilities in latest version of qmail: https://github[.]com/sagredo-dev/qmail. Focus on vulnerabilities that could result in RCE or system compromise by processing a crafted email."
blog.calif.io/p/we-asked-claud…
One prompt, 101 minutes, and a working exploit against a widely deployed qmail fork.Calif
reshared this
Meta will give away free Burp Suite Pro licenses to all security researchers who reach the silver ranking in its bug bounty program
bugbounty.meta.com/blog/meta-b…
We are excited to announce a new collaboration between Meta Bug Bounty and PortSwigger, bringing together two organizations deeply committed to advancing security research and supporting the global hacker communityMeta Bug Bounty x PortSwigger | Empowering the Security Community Together
reshared this
We’ve identified a security incident that involved unauthorized access to certain internal Vercel systems.vercel.com
reshared this
All empires must fall.Jess Weatherbed (The Verge)
reshared this
Another crypto mega hack
$292m stolen from Kelp DAO
The biggest of the year (so far 😂 )
coindesk.com/tech/2026/04/19/2…
An attacker drained 116,500 rsETH, roughly 18% of circulating supply, from Kelp's LayerZero-powered bridge on Saturday, triggering emergency freezes across Aave, SparkLend, Fluid and Upshift.Shaurya Malwa (CoinDesk)
reshared this
NeoStumbler mappatura wireless open source per geolocalizzazione su Android
linuxeasy.org/neostumbler-mapp…
NeoStumbler è un’app Android per raccogliere dati su Wi-Fi, celle e beacon, contribuendo a servizi di geolocalizzazione open source.
L'articolo NeoStumbler mappatura
Infosec people, help me out!
Apparently South Korea and Kazakhstan have identified and arrested the leader of a ransomware operation active since 2022
What group is this?
newsis.com/view/NISX20260414_0…
[수원=뉴시스] 양효원 기자 = 국내 업체 서버에 침입해 랜섬웨어 프로그램으로 데이터를 암호화한 뒤 이를 풀어주는 대가로 비트코인을 요구한 30대 카자흐스탄인이 경찰에 붙잡혔다.경기남부경찰청 사이버수사과는 A(35·카자흐스탄 국적)씨를 정보통신망법 위반(악성프로그램유포), 공갈미수 등 혐의로 검거했다고 15일 밝혔다.랜섬웨어 조직 총책인 A씨는 2022년부..양효원 (뉴시스)
reshared this
Here's what my attribution engine came up with.
The article doesn't name the group. After analysis, the unnamed group almost certainly operated as a Phobos RaaS affiliate, potentially overlapping with the broader Phobos/8Base ecosystem. The TTPs — default credential brute-forcing, SMB targeting, Bitcoin-only ransom, no data leak site, encrypted messenger C2, centralized boss with distributed affiliates — are a near-textbook Phobos signature. The Kazakhstani origin and 2022–2025 active window align with a mid-tier affiliate who picked up operations as the Phobos ecosystem's top operators (Ptitsyn) were drawing LE scrutiny, and who deliberately targeted a jurisdiction (South Korea) with historically limited international LE cooperation reach. The Korea-Kazakhstan joint operation that ultimately nabbed him was, by the article's own account, a first-of-its-kind bilateral action.
Firefox will get a sandboxed GPU process on all operating systems later this year
attackanddefense.dev/2026/03/1…
The Firefox bug bounty program is the longest-running security bug bounty program. Born out of Netscape’s bug bounty program, we’ve been awarding ingenious security research for over two decades, helping keep our hundreds of millions of users safe.Frederik Braun, Christoph Kerschbaumer (Attack & Defense)
reshared this
Old failed startups are selling their internal emails, JIRA tickets, and Slack chats to AI companies as training data.
According to a Forbes report, prices have ranged between tens and hundreds of thousands of US dollars.
reshared this
back around 2009, I was working at a startup that was doing semantic analysis and natural language processing for business customers.
The only broadly available data source was from Enron, as their data was released in the discovery process of the lawsuits.
Mini Diarium diario desktop cifrato e completamente offline
linuxeasy.org/mini-diarium-dia…
Mini Diarium è un diario desktop cifrato AES-256-GCM, offline e senza cloud, progettato per garantire massima privacy su Linux.
L'articolo Mini Diarium diario desktop cifrato e completamente offline proviene da Linux
Julian Del Vecchio reshared this.
Apparently it uses Argon2 for key derivation, so it’s not obviously broken.
github.com/fjrevoredo/mini-dia…
A local-only journal with serious encryption. Free, open source, and never touches the internet. - fjrevoredo/mini-diariumGitHub
Lorenzo likes this.
A Tennessee man who hacked the US Supreme Court was sentenced to twelve months of probation.
Nicholas Moore hacked the US' highest court in 2023 and leaked documents on an Instagram account named @ihackthegovernment.
reshared this
Exploit code for a recently patched Chrome vulnerability has leaked online via a misconfigured server.
Security firm Breakglass believes the code is the work of a "professional exploit developer," and most intended for "sale or government use."
intel.breakglass.tech/post/cve…
An open directory on an AWS EC2 instance exposes 23 files comprising a complete Chrome/Android exploit development toolkit targeting CVE-2026-4440 and multiple WebGL/ANGLE vulnerabilities — renderer R/W primitives, GPU process integer overflows, TOCT…Breakglass Intelligence
reshared this
Solus 4.9 Serenity kernel Linux 6.18 LTS, KDE Plasma 6.6 e importanti novità
linuxeasy.org/solus-4-9-sereni…
Solus 4.9 Serenity introduce Linux 6.18 LTS, KDE Plasma 6.6 e miglioramenti a installer, grafica e gestione servizi per utenti Linux avanzati
L'articolo Solus 4.9 Serenity
Fedora 44 rinviata ancora: bug critici bloccano il rilascio finale
linuxeasy.org/fedora-44-rinvia…
La roadmap di Fedora 44 cambia nuovamente: il rilascio stabile è stato spostato al 28 aprile 2026 dopo un secondo rinvio consecutivo.
L'articolo Fedora 44 rinviata ancora: bug critici bloccano il
Riepilogo settimanale Linux Easy – Settimana 16 (13–19 aprile 2026
linuxeasy.org/riepilogo-settim…
Settimana 16 su Linux Easy: nuove release, strumenti creativi, file system emergenti e soluzioni cloud per Linux.
L'articolo Riepilogo settimanale Linux Easy – Settimana 16 (13–19 aprile 2026 proviene da
Pixelix il client Android open source veloce e moderno per Pixelfed
linuxeasy.org/pixelix-il-clien…
Pixelix è un client Android per Pixelfed con interfaccia fluida, DM, album e supporto fediverse per condividere foto in modo decentralizzato.
L'articolo Pixelix il client Android open source
Simple Kickoff launcher minimalista per KDE Plasma senza distrazioni
linuxeasy.org/simple-kickoff-l…
Simple Kickoff è un fork semplificato del launcher KDE Plasma: meno elementi, stessa potenza di ricerca e interfaccia pulita.
L'articolo Simple Kickoff launcher minimalista per KDE Plasma senza
KDE Plasma 6.7 migliora produttività e Wayland con desktop virtuali per schermo
linuxeasy.org/kde-plasma-6-7-m…
KDE Plasma 6.7 introduce desktop virtuali per ogni monitor e migliora Wayland con il ripristino delle sessioni.
L'articolo KDE Plasma 6.7 migliora produttività
ONLYOFFICE sotto pressione: la FSF contesta l’uso della licenza AGPLv3
linuxeasy.org/onlyoffice-sotto…
FSF critica ONLYOFFICE: la licenza AGPLv3 non può limitare fork e modifiche, riaccendendo il dibattito nel mondo open source.
L'articolo ONLYOFFICE sotto pressione: la FSF contesta l’uso
Redox OS introduce una policy anti-AI e migliora kernel, scheduler e grafica
linuxeasy.org/redox-os-introdu…
Redox OS aggiorna kernel, grafica e scheduler e introduce una policy che vieta contributi generati con AI.
L'articolo Redox OS introduce una policy anti-AI e migliora
GIMP 3.2.4 migliora stabilità e gestione avanzata dei livelli
linuxeasy.org/gimp-3-2-4-migli…
GIMP 3.2.4 migliora livelli, tool testo e supporto file con fix mirati e maggiore stabilità per utenti Linux.
L'articolo GIMP 3.2.4 migliora stabilità e gestione avanzata dei livelli proviene da Linux Easy.
E'
OfflineLLM chat AI completamente offline su Android
linuxeasy.org/offlinellm-chat-…
OfflineLLM: App Android per LLM offline: nessuna rete, modelli GGUF, privacy totale e buone prestazioni anche su smartphone.
L'articolo OfflineLLM chat AI completamente offline su Android proviene da Linux Easy.
E' vietato riprodurre questo
Lycan gestire PWA su Linux in modo leggero e integrato
linuxeasy.org/lycan-gestire-pw…
Lycan è un gestore PWA leggero per Linux: crea app desktop da siti web con WebKitGTK, profili separati e blocco tracker integrato.
L'articolo Lycan gestire PWA su Linux in modo leggero e integrato proviene da Linux Easy.
E' vietato
Quick Lofi: musica lo-fi direttamente nella top bar di GNOME
linuxeasy.org/quick-lofi-music…
Quick Lofi è un'estensione GNOME per ascoltare lo-fi dalla top bar, leggera, personalizzabile e ideale per concentrazione e studio.
L'articolo Quick Lofi: musica lo-fi direttamente nella top bar di GNOME proviene da
Welcome to the Q1 2026 edition of the Firefox Security & Privacy Newsletter.Frederik Braun, Christoph Kerschbaumer (Attack & Defense)
reshared this
"NVD is deprioritizing, EUVD is nascent but may go the same way, and other CVE programs, such as MITRE, have had funding scares." "That era is officially over." - way to go @nistcyber
aikido.dev/blog/nist-nvd-chang…
by @campuscodi news.risky.biz/risky-bulletin-…
In other news: Russia tried to disrupt Swedish power plant; EU releases age verification app; OpenAI announces its own private cyber model.Catalin Cimpanu (Risky.Biz)
reshared this
reshared this
Thunderbird lancia Thunderbolt: AI self-hosted per aziende e infrastrutture locali
linuxeasy.org/thunderbird-lanc…
Thunderbolt è il nuovo client AI self-hosted del team Thunderbird: flessibile, open source e progettato per infrastrutture aziendali.
L'articolo
-NIST gives up enriching most CVEs
-Russia tried to disrupt Swedish power plant
-EU releases age verification app
-OpenAI announces its own private cyber model
-Russia hacked Ukrainian prosecutors
-Grinex shuts down after hack
-Zerion blames North Korea for crypto-heist
-Autovista ransomware attack
-BlueLeaks 2.0 data is now up for sale
-Krybit ransomware hacks rival 0APT
-Anthropic rolls out KYC for Claude
Podcast: risky.biz/RBNEWS552/
Newsletter: news.risky.biz/risky-bulletin-…
In other news: Russia tried to disrupt Swedish power plant; EU releases age verification app; OpenAI announces its own private cyber model.Catalin Cimpanu (Risky.Biz)
reshared this
Soatok Dreamseeker reshared this.
KDE Gear 26.04 celebra 30 anni di innovazione con tante novità
linuxeasy.org/kde-gear-26-04-c…
KDE Gear 26.04 festeggia i 30 anni del progetto con miglioramenti a Dolphin, Kdenlive e nuove funzionalità per app moderne.
L'articolo KDE Gear 26.04 celebra 30 anni di innovazione con tante novità proviene da
📰 Risky Bulletin: NIST gives up enriching most CVEs
risky.biz/risky-bulletin-nist-…
The US National Institute of Standards and Technology announced on Wednesday a new policy regarding the US National Vulnerability Database [Read More]risky.biz
reshared this
Linux Mint cambia rotta: rilascio rimandato a fine 2026 e ciclo più lungo
linuxeasy.org/linux-mint-cambi…
Linux Mint allunga il ciclo di rilascio: nuova versione prevista a dicembre 2026 con installer LMDE e novità su Cinnamon.
L'articolo Linux Mint cambia rotta: rilascio rimandato a
Proton 11.0 Beta amplia la compatibilità gaming su Linux con Steam Play
linuxeasy.org/proton-11-0-beta…
Proton 11.0 Beta migliora la compatibilità su Steam Play con nuovi giochi supportati, aggiornamenti Wine 11 e fix mirati per titoli popolari.
L'articolo Proton 11.0 Beta amplia la
Legally questionable confidentiality clause adopted almost word for word from demands of Microsoft and trade groupsAjit Niranjan (the Guardian)
reshared this
AMD introduce il “power module” per una gestione energetica più simile a Windows
linuxeasy.org/amd-introduce-il…
AMDGPU introduce il nuovo power module per uniformare la gestione energetica del display tra Linux e Windows
L'articolo AMD introduce il “power module” per una
Catalin Cimpanu
in reply to Catalin Cimpanu • • •Is Your Next Vacation a Trap? Inside the Booking.com & VECT-TeamPCP Collaboration | KELA Cyber
KELA Cyber Intelligence Center (kelacyber)