🚨 İddiaya göre bir güvenlik araştırmacısı, CrowdStrike, SentinelOne, Cortex XDR ve Sophos'un tespit mekanizmalarını tersine mühendislikle yeniden oluşturdu.
Bu sayede dosyaların VirusTotal'e yüklenmeden, tamamen çevrimdışı ortamda bu EDR çözümlerine yakalanıp yakalanmayacağı test edilebiliyor. Bu gelişme hem güvenlik araştırmacılarının hem de maalesef saldırganlar açısından dikkat çekici.
İddia eğer doğruysa, siber saldırganların, kendi zararlı yazılımlarını EDR'lere yakalanmadan önce test edip, optimize etmesine neden olabilir.
🚨 GRAVE: Bug en FreeBSD de 7 años afectó Netflix CDN, PlayStation OS y WhatsApp. Descubierto recién el año pasado, este exploit tenía un impacto masivo en infraestructuras críticas. Impresionante cómo pasó desapercibido tanto tiempo #FreeBSD#cybersecur…
software engineering in 2026:
- your package manager is compromised
- your cloud provider blocks your account
- github itself is hacked
software is solved
Uuu, grubiutko. GitHub zhackowany. Zaczęło się od pracownika który zainstalował zainfekowany dodatek do VS Code.
Wykradziono kod wewnętrznych repozytoriów. Dane są aktualnie sprzedawane przez grupę teamPCP.
W wielu firmach programiści są - tak samo jak w Githubie - już dawno trzaśnięci..Tylko jeszcze o tym nie wiedzą.
‼️🚨 The Mini Shai-Hulud npm worm has hit again. Hundreds of antv packages compromised (Alibaba's data visualization suite) along with echarts-for-react, timeago.js, size-sensor, and canvas-nest.js.
It all started today with the compromise of npm account atool ([email protected]). In a 22-minute window between 01:39 and 02:06 UTC, the attacker published 631 malicious versions across 314 packages, all carrying the same payload.
Top affected packages by monthly downloads:
- [email protected] - 4.2M dl/mo
- [email protected] - 3.8M dl/mo
- @antv/[email protected] - 2.2M dl/mo
- [email protected] - 1.15M dl/mo
- @antv/[email protected] - 1.0M dl/mo
- @antv/[email protected] - 1.1M dl/mo
- @antv/[email protected] - 975K dl/mo
- @antv/[email protected] - 883K dl/mo
- @antv/[email protected] - 751K dl/mo
What the payload does (498KB obfuscated Bun script, runs via preinstall hook):
- Harvests 20+ secret types: GitHub PATs, npm tokens, AWS keys, GCP service accounts, Azure creds, DB connection strings, Stripe keys, Slack tokens, SSH keys, Docker auth, Kubernetes configs, Vault tokens
- Attempts Docker container escape if the host socket is reachable, spinning up a Privileged container with host filesystem bind mounts
- Pulls a secondary payload via optional dependency antv/setup from antvis/G2 commit 1916faa, which was pushed 19 minutes before the npm publishes started
🚨 فيديو إثبات (PoC) يُظهر استغلال ثغرة جديدة باسم "YellowKey" تتجاوز حماية BitLocker كاملةً على نظام Windows.
🔹 الفيديو يوضّح خطوة بخطوة طريقة الاستغلال:
1- نسخ مجلد FsTx إلى ذاكرة USB
2- الدخول إلى وضع Windows Recovery Environment
3- تنفيذ تركيبة مفاتيح (SHIFT + CTRL) للحصول على Shell بصلاحيات كاملة على القرص المشفّر
دون الحاجة لكلمة مرور أو مفتاح استرداد
Credit: @DarkWebInformer
🇫🇷 An underground platform called “ARGUS LOOKUP/SPYWARE” is being advertised as a French doxxing, geolocation, and surveillance-style intelligence tool allegedly aggregating data from multiple sources in real time.
The interface shown in the underground advertisement appears to include capabilities such as:
• identity lookup
• phone and email correlation
• geolocation tracking
• facial recognition
• dossier creation
• IP intelligence
• historical activity analysis
• social and financial correlation mapping
The post also references alleged access to multiple French-related data sources and administrative-style datasets.
At this stage, the legitimacy, functionality, and actual access level of the platform remain unverified.
However, platforms marketed as “lookup” or “spyware” ecosystems often combine:
• leaked databases
• scraped information
• OSINT aggregation
• credential dumps
• telecom metadata
• social engineering tools
• and doxxing-focused analytics
Even when exaggerated, these types of services can significantly increase risks related to:
• privacy violations
• stalking and harassment
• doxxing campaigns
• identity theft
• extortion
• targeted surveillance
• and criminal intelligence gathering
The commercialization of real-time identity correlation and geolocation tooling continues to blur the line between cybercrime, spyware ecosystems, and underground intelligence-as-a-service operations.
Daily Dark Web is continuing to monitor the situation.
#France#French#CyberSecurity#Spyware#Doxxing#ThreatIntelligence#DDW#Intelligence
🪟 New Windows challenge: JanelaRAT
Reverse a real-world RAT, from the initial dropper down to the final C2.
📦 Installer triage
🔍 17 questions
🧬 Multi-stage unpacking
🔐 Config decryption
🌐 C2 hunting
🔗 malops.io/challenges/jan…
💬 discord.gg/PHRd7xPUUt
By @P4nd3m1cb0y
Acaba de confirmarse: Un exploit de zero-day llamado 'MiniPlasma' permite a los atacantes obtener acceso de SYSTEM en sistemas Windows completamente actualizados.
El exploit afecta a Microsoft Windows, específicamente al servicio de impresión y manejo de colas de impresión, y permite una elevación de privilegios locales (LPE) a NT AUTHORITY\SYSTEM.
La vulnerabilidad es de tipo zero-day, sin parche oficial disponible, y se ha publicado un proof-of-concept (PoC) que demuestra su explotación en sistemas Windows totalmente parcheados.
El impacto es grave, ya que permite a los atacantes obtener acceso de SYSTEM a los sistemas afectados, lo que podría llevar a daños.
¿Hay parche? No, por ahora. ¿Qué deben hacer los afectados HOY? Revisar los logs de seguridad y monitorear el sistema para detectar cualquier actividad sospechosa. ¿Estás en riesgo? Revisa esto: actualiza tus sistemas lo antes posible y aplica las medidas de seguridad recomendadas.
bleepingcomputer.com/news/microsoft…
🚨 Microsoft hesaplarını hedef alan yeni bir siber tehdit dalgası tespit edildi.
Saldırganlar, Microsoft’un “şifresiz giriş” özelliğini kötüye kullanarak sızdırılmış e-posta veritabanlarıyla hesap keşfi yapıyor
linkedin.com/posts/sibergae…
LinkedIn Search leads to #CastleLoader delivering #AsyncRAT. Attackers use Clickfix lures with fake verification popups to mask PowerShell activity. The loader decrypts the payload via RC4, using the first 64 bytes as a key to bypass filters. Details: bit.ly/4uOIqka
Nueva vulnerabilidad en #Linux que permite a usuarios locales sin privilegios leer archivos propiedad de root.
Se llama ssh-keysign-pwn fue descubierta por Qualys ayer 14 de mayo pero ya fue corregida hoy por la mañana y está disponible para las distribuciones.
lore.kernel.org/lkml/202605150…
589 Followers 626 FollowingThreat intelligence as data: a REST API, free IOC and MISP feeds and an MCP server. Over 20,000+ sources and ransomware leak sites.
7K Followers 3K Followingaka Drego. Head of Cyber Threat Intelligence at @D3LabIT! @PhishingArmy, #meioc is my projects and @backbox_org dev! My passions are #F1 and #Running!
5K Followers 184 FollowingFounder of SAFAR Mobile App | Cybersecurity|AI | DFIR ⚔️ Awareness & Digital Safety 🛡️ Authorized Use Only ⚖️| وَقُلْ رَبِّ زِدْنِي عِلْمًا
57K Followers 99 FollowingHacker | Hall of Fame: Google, Apple, X, NASA | BlackHat x1 | CVE ×4 | HTB SME (Guru) | BC: P1 warrior | Featured in NASA’s IT Talk | OSCP+ | Consultant at EY
7K Followers 5K FollowingCybersecurity Specialist/ InfoSec Rockstar / Business Intelligence / AML / Co-host Podcast “Pláticas de Ciberseguridad” / Tweets are on my own. 🇲🇽
65K Followers 6K FollowingPeriodista | Premio The Merck Foundation (2020) | Coautor «Ópticas de la Corrupción» (2022) y «Desmontar a los Montadeudas» (2023) | Premio AMCS (2025).
19K Followers 915 FollowingSWE at @Google / @Virustotal. Based in Málaga. Mathematics & Computer Science. Writing about software engineering, AI and security.
91K Followers 971 FollowingProgrammer, #malware analyst. Author of #PEbear, #PEsieve, #TinyTracer. Private account. All opinions expressed here are mine only (not of my employer etc)
119K Followers 514 FollowingMITRE ATT&CK® - A knowledge base for describing the behavior of adversaries. Replying/Following/Re-tweeting ≠ endorsement. @ https://t.co/wt46ArkZVt
1K Followers 0 FollowingEnterprise threat intelligence platform to monitor cyber incidents, hackers, dark web, vulnerabilities, data leaks and more.
For trial access-
785 Followers 1K FollowingJust a random cyber guy
#ThreatIntelligence | #MalwareAnalysis | #DarkWebResearch | #Geopolitics Student | Views and tweets are my own :)
12K Followers 196 Following🚀Bringing China's AI & tech trends, voices and perspectives to the global stage.
⚡️Powered by 知乎/https://t.co/OkIemRZdcj, China's leading knowledge community.
2K Followers 376 FollowingStop threats before they start. Our PTEM platform unifies ASM & dark web intelligence to help defenders prioritize what's exploitable — not just what's exposed.
1K Followers 83 FollowingIntelOwl: analyze files and observables with multiple services and malware analysis tools via a single API at scale
#ThreatIntel #OpenSource #SecurityTools
2K Followers 58 FollowingEuropean Internet Intelligence Company.
Understand the intent behind internet infrastructure before it is weaponised.
Check it out on https://t.co/8w3bQOWmRv