Cyber threat intelligence for the modern threat landscape.
Tracking threat actors, incidents & geopolitical cyber operations worldwide.
Know your adversaries.intelfusions.comJoined March 2026
🚨 Update to our Jul 17 SharePoint report: we now assess the undocumented deserialization vector on our honeypots as likely CVE-2026-50522.
The captured requests carry no authentication material, matching 50522's unauthenticated profile. Microsoft describes the paired CVE-2026-58644 as requiring Site Owner auth, which does not fit unauthenticated traffic.
CVE-2026-50522 is currently not known to be exploited in-the-wild.
Track SharePoint exploitation live console.defusedcyber.com/signup
⚠️ An undocumented SharePoint deserialization vector is being exploited on our honeypots during the current SharePoint CVE wave.
An actor is delivering a .NET deserialization payload to a SharePoint sign-in endpoint that matches no published PoC.
We are not assigning a CVE and
A newly disclosed flaw in WordPress Core lets an attacker take full control of a website without any password, account, or user interaction, and the researchers who found it warn that a working exploit could appear within days.
CVE-2026-63030
intelfusions.com/news/wordpress…
Microsoft has detailed a destructive new backdoor called GigaWiper that bundles three separate strains of wiping and fake-ransomware malware into a single tool, giving an attacker a menu of ways to destroy a compromised network on command.
intelfusions.com/news/gigawiper…
@inf0stache Nice catch. We pulled the thread a bit further and mapped the wider cluster it belongs to: ~10 near-identical packages, Taiwan aviation/aerospace lures, and the redirect domain (microcloud[.]homes) still live. Full breakdown + indicators, credit to you 👇
intelfusions.com/news/china-air…
@blackorbird@AndreGironda This is where agentic AI becomes interesting. Generating code is one thing; executing reconnaissance, exploitation, persistence, and extortion end-to-end is a different level.
New group to watch. So far these are leak-site claims, not confirmed breaches, but the targeting of law enforcement and healthcare is worth keeping an eye on. Curious if anyone has seen additional activity tied to Wallstreet.
intelfusions.com/news/wallstree…
A new phishing campaign is doing something more dangerous than stealing passwords: it hijacks the browser sessions you are already logged into.
intelfusions.com/news/phishing-…
An initial access broker linked to the Payouts King ransomware operation has been caught using a clever new trick to break into corporate computers
intelfusions.com/news/ransomwar…
Hackers rigged South Asian University's official site to push malware disguised as a free "Doom: The Dark Ages" download.
Classic ClickFix: it tells you to paste a command into PowerShell. No legit site ever asks that.
intelfusions.com/news/south-asi…
Sprawling fraud ecosystem aimed at the 2026 FIFA World Cup.
More than 4,300 fraudulent domains impersonating FIFA's official web presence registered since August 2025
intelfusions.com/news/ghost-sta…
340 Million OnlyFans Records for Sale: Seller Admits No Platform Was Breached
A threat actor operating under the alias Euphoric_Reply_5727 is selling what they describe as a 340-million-record database of OnlyFans user data
intelfusions.com/news/onlyfans-…
Glassworm hid malware inside invisible Unicode characters. Zero-width whitespace that renders as blank space in every editor, every diff tool, every GitHub review interface.
151+ GitHub repos compromised. npm packages. VS Code extensions. Solana blockchain used as C2. AI-generated cover commits to blend in.
You cannot see the malicious code. That is the point.
#IntelFusions#Glassworm#AikidoSecurityintelfusions.com/news/glassworm…
OnePlus websites are loading JavaScript from an abandoned AWS S3 bucket now controlled by a security researcher.
Stored XSS active across multiple domains. Reported twice since July 2025. Zero response. 8 months unpatched.
Session tokens, cookies, payment flows, all exposed to takeover.
→ intelfusions.com/news/oneplus-s…
3K Followers 3K Following📊 Data Analyst | Turning complex data into business strategy.
💼 Finance Insights|⚽️Football enthusiast.
📩 DM or [email protected] for collabs
131 Followers 3K FollowingCuriosity. Adventure. Life Long Learner. Explorer. Researcher. Humanity. Abundance via Openness Unlocks The Stars. Long Live The Great Opensource Revolution.
34 Followers 155 Followingsecurity engineer living in Japan. My main expertise is in server and network infrastructure security. セキュリティエンジニア。とある都内のITセキュリティ系の会社でエンジニア兼管理職をしてます。
1K Followers 3K FollowingDevOps, SecOps , AI Implementation AI is more than just intel, it's your new SysAdmin. Automating workflows, securing the stack, and redefining Red/Blue teaming
61K Followers 3K FollowingEvery day I write about #osint (Open Source Intelligence) tools and techniques. Also little bit about forensics and cybersecurity in general. Work in @netlas_io
4K Followers 501 FollowingThreat Intel Specialist and Incident Responder. Private account. All opinions expressed here are mine only.
https://t.co/7dQQO1JwUd
53K Followers 83 FollowingThe Australian Signals Directorate provides intelligence, cyber security and offensive operations in support of the Australian Government and the ADF.
13K Followers 386 FollowingStay ahead with Daily CyberSecurity. We deliver rapid zero-hour alerts and expert analysis on critical vulnerabilities, CVEs, and emerging cyber threats.
4K Followers 13 Following📣 We tweet malicious packages detected on npm in real-time. 🚨 Not affiliated with @npmjs or @github. 🛡 Powered by the @SocketSecurity threat feed. ✨
622K Followers 23 FollowingSignal is a nonprofit end-to-end encrypted communications app. Privacy isn’t an optional mode, it’s the way Signal works. Every message, every call, every time.
1K Followers 3K FollowingDevOps, SecOps , AI Implementation AI is more than just intel, it's your new SysAdmin. Automating workflows, securing the stack, and redefining Red/Blue teaming
22K Followers 3 FollowingCyberDefenders™ is a training platform for #SOC analysts to learn, validate & advance #BlueTeam/#DFIR skills.
Join community @https://cyberdefenders.org/discord
143K Followers 20K FollowingEmpowering people and families to feel safer in your digital life with the latest news, tips, & trends. Opt-in to Cyber Safety. For help tweet @NortonSupport 🙂
58K Followers 1K FollowingONE autonomous platform to prevent, detect, respond, and hunt. Do more, save time, secure your enterprise: https://t.co/N75g1HAnCs 🐱💻
72K Followers 400 FollowingProving that cybersecurity is everyone's business. We research what others skip, expose what's buried, and know that the real story is never on the surface.
331K Followers 2K FollowingIndependent investigative journalist. Author of 'Spam Nation,' a NYT bestseller. Former Washington Post reporter. Mastodon: https://t.co/fTKNavlMwp
124 Followers 20 FollowingAssalamu Alaikum we are Akatsuki cyber team We work in cyber world for the sake of Allah and we have been doing various protests through our cyber attacks Suppo
68K Followers 2 FollowingThis is an unofficial HackerOne public disclosure watcher who keeps you up to date about the recently disclosed bugs. By @NOBBD