voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
🚨New ransom group blog post!🚨
Group name: akira
Post title: Centre Ellipse
Info: https://cti.fyi/groups/akira.html
#ransomware #cti #threatintelligence #cybersecurity #infosec
⚠️ In Q1 2026, phishing kits captured sessions using proxy authentication flows in real time.
It's hard to detect, because SOCs see no traditional indicator of compromise.
🎯 Learn how to improve phishing defense in Q1 Cyber Risk Report: https://files.any.run/images/q1_2026_cyber_risk_report_from_anyrun.pdf?utm_source=mastodon&utm_medium=post&utm_campaign=cyber_risk_report_1&utm_content=linktoreport&utm_term=090626
Mini Shai-Hulud, Miasma, and Hades Worms Target Bioinformatics and MCP Developers via Malicious PyPI Wheels
A sophisticated supply chain attack campaign has expanded to 471 affected artifacts across npm and PyPI, targeting developers through malicious packages. The campaign uses three distinct delivery methods: executable .pth startup hooks, trojanized native .abi3.so extensions that execute at import time, and a split loader-payload architecture that searches Python's sys.path. Twenty-three newly identified PyPI packages masquerade as bioinformatics tools, AI frameworks, and popular libraries like requests and Flask. The attack deploys heavily obfuscated JavaScript stealers via Bun runtime, harvesting high-value credentials including GitHub tokens, npm registry access, cloud credentials, SSH keys, and CI/CD secrets. The malware employs anti-analysis techniques with fake LLM prompt-injection headers designed to disrupt AI-assisted security scanners, while targeting developer workstations and automated build environments.
Pulse ID: 6a2719a5f6621cb5014a256d
Pulse Link: https://otx.alienvault.com/pulse/6a2719a5f6621cb5014a256d
Pulse Author: AlienVault
Created: 2026-06-08 19:36:05
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #GitHub #ICS #InfoSec #Java #JavaScript #Malware #NPM #OTX #OpenThreatExchange #PyPI #Python #SSH #SupplyChain #Trojan #Worm #bot #developers #AlienVault
AI brands as bait: How threat actors are using the AI hype in social engineering
Threat actors are increasingly leveraging the global interest in artificial intelligence by impersonating popular AI platforms such as ChatGPT, Copilot, DeepSeek, and Claude in social engineering campaigns. These operations span phishing attacks, malvertising, and search engine optimization-driven tactics that ultimately lead to credential theft, financial fraud, or malware infections. Observed campaigns include ChatGPT-themed phishing collecting credit card data targeting South Africa, Claude-themed adversary-in-the-middle attacks harvesting credentials and access tokens, malvertising campaigns distributing Vidar stealer through fake AI plugin downloads, and fraudulent DeepSeek V4 installers on GitHub. The initial access broker Storm-3075 has been identified employing AI-themed malvertising, while the financially motivated actor Fox Tempest provides malware-signing-as-a-service to enhance payload legitimacy. These campaigns combine traditional social engineering tactics with AI branding to improve success...
Pulse ID: 6a2719a4165e6fddbfbf8f91
Pulse Link: https://otx.alienvault.com/pulse/6a2719a4165e6fddbfbf8f91
Pulse Author: AlienVault
Created: 2026-06-08 19:36:04
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AdversaryInTheMiddle #Africa #ChatGPT #CreditCard #CyberSecurity #FinancialFraud #GitHub #ICS #InfoSec #Mac #Malvertising #Malware #OTX #OpenThreatExchange #Phishing #RAT #SocialEngineering #Vidar #bot #AlienVault
Hacktivists are broadening their scope beyond political motivation
Kaspersky researchers uncovered interconnected hacktivist campaigns attributed to groups including 4BID, Hakerskii Kit, and C.A.S., targeting organizations primarily in Russia and Belarus, but expanding to Kazakhstan, UAE, Syria, and Egypt. Attackers exploited ProxyShell vulnerabilities in Microsoft Exchange servers to deploy fd.aspx web shells and various post-exploitation frameworks including Sliver, Havoc, Mythic Apollo, AdaptixC2, and a custom BlackSalt backdoor. The campaigns deployed ransomware including ClearWater and updated versions of Blackout Locker, alongside EDR killers using BYOVD techniques. Attackers leveraged legitimate RMM tools like AnyDesk, Panorama9, and Tactical RMM for persistence, with AI-generated scripts showing varying quality. The geographical expansion and increased use of ransomware suggest a shift from purely political motivation toward financial gain.
Pulse ID: 6a2699c629b0ddee8d84e7b6
Pulse Link: https://otx.alienvault.com/pulse/6a2699c629b0ddee8d84e7b6
Pulse Author: AlienVault
Created: 2026-06-08 10:30:30
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AnyDesk #BackDoor #Belarus #CyberSecurity #EDR #Hacktivist #InfoSec #Kaspersky #Kazakhstan #Microsoft #Mythic #OTX #OpenThreatExchange #Proxy #RAT #RansomWare #Russia #Sliver #Syria #UAE #bot #AlienVault
Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Open
Two Russia-aligned campaigns continue exploiting CVE-2025-8088, a WinRAR path traversal vulnerability patched in July 2025, against Ukrainian organizations through April 2026. SHADOW-EARTH-066 deploys an evolved GIFTEDCROOK information stealer using in-memory DLL loading via direct NT system calls, harvesting browser credentials, session cookies, and documents across 35 file extensions before self-deleting. Earth Dahu employs an HTA-based infection chain delivering espionage modules through Cloudflare Workers infrastructure. Both campaigns leverage the same CVE-2025-8088 exploit but use distinct tooling: SHADOW-EARTH-066 relies on compiled C++ with RC4-encrypted C&C communication, while Earth Dahu uses script-based approaches with Dynamic DNS. The persistent exploitation nearly a year post-patch demonstrates how unmanaged software lacking centralized update mechanisms creates enduring attack surfaces that threat actors deliberately target.
Pulse ID: 6a2699c6a6badcc8eac21083
Pulse Link: https://otx.alienvault.com/pulse/6a2699c6a6badcc8eac21083
Pulse Author: AlienVault
Created: 2026-06-08 10:30:30
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #CandC #Cloud #Cookies #CyberSecurity #DNS #ELF #Espionage #InfoSec #OTX #OpenThreatExchange #RAT #Russia #SMS #UK #Ukr #Ukraine #Ukrainian #Vulnerability #WinRAR #bot #AlienVault
Fighting Spyware: An Update
WhatsApp successfully identified and disrupted spear phishing attempts linked to NSO Group, a spyware firm blacklisted by the US government. The company is requesting the court to hold NSO in contempt for violating a permanent injunction that prohibited them from targeting WhatsApp and its users. The attacks involved social engineering attempts to trick users into clicking malicious links, as well as creating test accounts and groups on the platform. WhatsApp emphasizes that spyware represents a national security threat and is supporting the Spyware Accountability Initiative through significant contributions. The company continues to protect users through end-to-end encryption and encourages reporting suspicious activity while maintaining updated applications and devices.
Pulse ID: 6a27bbb7afe6bcf1ce69967b
Pulse Link: https://otx.alienvault.com/pulse/6a27bbb7afe6bcf1ce69967b
Pulse Author: AlienVault
Created: 2026-06-09 07:07:35
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Encryption #Government #InfoSec #OTX #OpenThreatExchange #Phishing #SocialEngineering #SpearPhishing #SpyWare #WhatsApp #bot #AlienVault
A First Look at a New Post-Exploitation Red Team Tool
A new post-exploitation red team tool named Splinter has been discovered on customer systems through Advanced WildFire's memory scanning capabilities. Developed in Rust programming language, Splinter is exceptionally large at around 7MB due to statically linked libraries. The tool uses a JSON configuration structure containing implant ID, C2 server details, and operational parameters. It operates through a task-based model with capabilities including Windows command execution, remote process injection, file upload/download, cloud service information gathering, and self-deletion. Communication with the C2 server occurs via HTTPS using specific URL paths for task synchronization, heartbeat connections, and file transfers. While not as sophisticated as Cobalt Strike, Splinter represents a growing variety of penetration testing tools that could potentially be misused by threat actors.
Pulse ID: 6a27af63e5b642f7307b0f6e
Pulse Link: https://otx.alienvault.com/pulse/6a27af63e5b642f7307b0f6e
Pulse Author: AlienVault
Created: 2026-06-09 06:14:59
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CobaltStrike #CyberSecurity #ELF #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RAT #Rust #Windows #bot #AlienVault
I ditched my Kindles, but Amazon could win me back with one launch
I've said it before, and I'll say it again, I want a Scribe in my pocket.
https://www.androidauthority.com/amazon-needs-a-pocket-sized-kindle-scribe-3674745/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
iOS 27 finally gets a basic volume feature that Android has had for years
It's surprising how long it took Apple to catch up to Android on this.
https://www.androidauthority.com/ios-27-independent-volume-controls-3675772/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Possible Phishing 🎣
on: ⚠️hxxps[:]//derpolmvnurty[.]weebly[.]com
🧬 Analysis at: https://urldna.io/scan/6a2452193b775000044d3900
#cybersecurity #phishing #infosec #urldna #scam #infosec
The fastest way to hit Google AI Pro limits (and how to avoid it)
I spent hours pushing Gemini's limits, and the biggest quota killer wasn't what I expected.
https://www.androidauthority.com/google-ai-pro-limits-tested-3674942/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Don't Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency
Between April and May 2026, a likely North Korean threat actor conducted phishing campaigns targeting developers across nearly 100 organizations in finance, cryptocurrency, education, and technology sectors. The attacks used recruitment and code review themes, delivering emails with links to actor-controlled GitHub repositories hosting malicious scripts. The infection chain exploited Visual Studio Code workflows and deployed malicious Visual Studio Extensions (VSIX) requiring minimal user interaction. Cross-platform malware was executed on macOS, Linux, and Windows systems, including the open-source Overlord framework. The campaigns specifically targeted developer assets including API tokens, cryptocurrency wallets, and credentials. Attackers employed fake company personas and professional-looking repositories masquerading as legitimate cryptocurrency and blockchain projects to establish credibility and lure victims.
Pulse ID: 6a2693f169b076341f77f7b6
Pulse Link: https://otx.alienvault.com/pulse/6a2693f169b076341f77f7b6
Pulse Author: AlienVault
Created: 2026-06-08 10:05:37
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #CyberSecurity #Education #Email #GitHub #InfoSec #Korea #Linux #Mac #MacOS #Malware #Nim #NorthKorea #OTX #OpenThreatExchange #Phishing #RCE #Troll #Windows #bot #cryptocurrency #developers #AlienVault
PCPJack Hijacked 230 AWS, GCP, and Azure Servers to Run a Hidden SMTP Relay Network
Pulse ID: 6a279c934de97b301661a1b1
Pulse Link: https://otx.alienvault.com/pulse/6a279c934de97b301661a1b1
Pulse Author: Tr1sa111
Created: 2026-06-09 04:54:43
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #Azure #CyberSecurity #InfoSec #OTX #OpenThreatExchange #bot #Tr1sa111
Impersonation, Click Hijacking, and TDS: Inside a Malware Distribution Ecosystem
Pulse ID: 6a279c8c39dd1384c93bd66a
Pulse Link: https://otx.alienvault.com/pulse/6a279c8c39dd1384c93bd66a
Pulse Author: Tr1sa111
Created: 2026-06-09 04:54:36
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #bot #Tr1sa111
Apple's new Siri AI comes with hidden costs that power users should know of
Apple unveiled a revamped Siri at WWDC, but is it enough to put the company back in the AI race?
https://www.zdnet.com/article/the-new-siri-ai-could-cost-you-heres-why/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
Malware Bugs: 90% of Leaked Samples Contain Exploitable Weaknesses https://deafnews.it/en/article/security-updates-released-for-cve-2026-20230-and-other-vulnerabilities #Cybersecurity
FSB’s matryoshka #2/3 – Gamaredon’s gifts that keeps unpacking – GammaLoad
Pulse ID: 6a279c832090bd784abd62b7
Pulse Link: https://otx.alienvault.com/pulse/6a279c832090bd784abd62b7
Pulse Author: Tr1sa111
Created: 2026-06-09 04:54:27
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Gamaredon #InfoSec #OTX #OpenThreatExchange #bot #Tr1sa111
Error 524 Decoy: Unmasking a Global Smishing Operation Hiding Behind Error Pages
Pulse ID: 6a279c7b68f15b3df89a05df
Pulse Link: https://otx.alienvault.com/pulse/6a279c7b68f15b3df89a05df
Pulse Author: Tr1sa111
Created: 2026-06-09 04:54:19
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #RAT #Smishing #bot #Tr1sa111
Inside DesckVB Rat Analysis: From Malspam to In-Memory RAT
Pulse ID: 6a279c81ab7effd97ab43b55
Pulse Link: https://otx.alienvault.com/pulse/6a279c81ab7effd97ab43b55
Pulse Author: Tr1sa111
Created: 2026-06-09 04:54:25
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #MalSpam #OTX #OpenThreatExchange #RAT #Spam #bot #Tr1sa111
Miasma Worm Campaign Spreads with New PyPI Wave
Pulse ID: 6a279cfe3e158af45588e99b
Pulse Link: https://otx.alienvault.com/pulse/6a279cfe3e158af45588e99b
Pulse Author: Tr1sa111
Created: 2026-06-09 04:56:30
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #PyPI #Worm #bot #Tr1sa111
Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms
Pulse ID: 6a279cf0b00fb57439460595
Pulse Link: https://otx.alienvault.com/pulse/6a279cf0b00fb57439460595
Pulse Author: Tr1sa111
Created: 2026-06-09 04:56:16
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #bot #Tr1sa111
Agentic AI Uncovers New China-Linked Cluster OP-512
Pulse ID: 6a279cf7ca9b8345287c743f
Pulse Link: https://otx.alienvault.com/pulse/6a279cf7ca9b8345287c743f
Pulse Author: Tr1sa111
Created: 2026-06-09 04:56:23
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#China #CyberSecurity #InfoSec #OTX #OpenThreatExchange #bot #Tr1sa111
VerdantBamboo: Just Another BRICKSTORM in the Firewall
Pulse ID: 6a279ce7def8d31266baca3c
Pulse Link: https://otx.alienvault.com/pulse/6a279ce7def8d31266baca3c
Pulse Author: Tr1sa111
Created: 2026-06-09 04:56:07
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #bot #Tr1sa111
Operation TaxShadow: Multi-Region Tax Phishing & In-Memory Malware Campaign
Pulse ID: 6a279cdaad160657470c6e19
Pulse Link: https://otx.alienvault.com/pulse/6a279cdaad160657470c6e19
Pulse Author: Tr1sa111
Created: 2026-06-09 04:55:54
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #Phishing #RAT #bot #Tr1sa111
Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257
Pulse ID: 6a279ce19d071e0cdfd2c3fb
Pulse Link: https://otx.alienvault.com/pulse/6a279ce19d071e0cdfd2c3fb
Pulse Author: Tr1sa111
Created: 2026-06-09 04:56:01
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #bot #Tr1sa111
ClickFix Is Now Hiring: From Job Platform Impersonation to Python-Based RAT Delivery
Pulse ID: 6a279cd433625b15fad36a11
Pulse Link: https://otx.alienvault.com/pulse/6a279cd433625b15fad36a11
Pulse Author: Tr1sa111
Created: 2026-06-09 04:55:48
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #Python #RAT #bot #Tr1sa111
Latest goon squad to use fake helpdesk calls to steal creds
Pulse ID: 6a279cce6725c52996046afc
Pulse Link: https://otx.alienvault.com/pulse/6a279cce6725c52996046afc
Pulse Author: Tr1sa111
Created: 2026-06-09 04:55:42
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #bot #Tr1sa111
ClickFix Deno Abuse to CastleRAT
Pulse ID: 6a279cc7b8d3626c59b0c9a7
Pulse Link: https://otx.alienvault.com/pulse/6a279cc7b8d3626c59b0c9a7
Pulse Author: Tr1sa111
Created: 2026-06-09 04:55:35
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #RAT #bot #Tr1sa111
Matryoshka #3/3: Gamaredon's Gammasteel Infostealer
Pulse ID: 6a279cbf59d363c8e27dfc45
Pulse Link: https://otx.alienvault.com/pulse/6a279cbf59d363c8e27dfc45
Pulse Author: Tr1sa111
Created: 2026-06-09 04:55:27
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Gamaredon #InfoSec #InfoStealer #OTX #OpenThreatExchange #bot #Tr1sa111
Bag a huge $308 saving on a two-year ExpressVPN Advanced sub and get four bonus months on top for free — 78% discoun…
Save over $300 on this two-year ExpressVPN Advanced subscription, with support for 12 simultaneous devices, advanced web protection, and a bunch of other tools for just $83.72, with four months extra for free.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
Possible Phishing 🎣
on: ⚠️hxxps[:]//1inch-extension[.]vercel[.]app
🧬 Analysis at: https://urldna.io/scan/6a25ab873b77500003c142c0
#cybersecurity #phishing #infosec #urldna #scam #infosec
Four suspects identified in Finland undersea cable damage investigation — criminal case referred to prosecutors for consideration of charges
Finland's National Bureau of Investigation has concluded its criminal investigation into the damage to two undersea telecommunications cables in the Gulf of Finland on December 31st.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
🚨 EUVD-2026-35234
📊 Score: n/a
📦 Product: Chrome
🏢 Vendor: Google
📅 Updated: 2026-06-08
📝 Use after free in Gamepad in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-35234
🚨 EUVD-2026-35234
📊 Score: n/a
📦 Product: Chrome
🏢 Vendor: Google
📅 Updated: 2026-06-08
📝 Use after free in Gamepad in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-35234