Latest posts

Sys-Admin InfoSec
15 Sept, 11:10
Open SysConf'26 - Доклад: поиск уязвимостей в эпоху AIКибербезопасность, AI - сегодня идут нога в ногу, в качестве союзников, иногда в качестве врагов.Доклад от @Thatskriptkid - Malware analyst, threat hunter, vulnerability researcher, автора множества интерейснейших ресерчей и интересных докладов, автора канала Order of Six Angles - https://t.me/orderofsixangles, хорошего друга, человека, который поддерживает и с первого Open SysConf с нами.Рассказ автора про свою хоум лабу, про проекты которые крутятся на ней, как были найдены баги в Pixel, Xiaomi, Mediatek в результате подготовки ресерча, опыт автора с локальными ЛЛМ, Android Exploitation, Фаззинг драйверов Windows и не только...10 Октября, в 10 утра, SmartPoint зал "Freedom Amphitheatre", Алматы.https://sysconf.io/2026
1,150Open in Telegram
Sys-Admin InfoSec
11 Sept, 18:02
An AI-Assisted Cyber Attack: Inside a Unit 42 Investigationinjecting backdoor in to terraformhttps://unit42.paloaltonetworks.com/ai-assisted-cyber-attack-inside-a-unit-42-investigation/Unit 42An AI-Assisted Cyber Attack: Inside a Unit 42 InvestigationUsing autonomous AI agents, an attacker breached an enterprise network in a matter of hours. Understand how to address and defend against agentic attacks.1,480Open in Telegram
Sys-Admin InfoSec
9 Sept, 10:03
Threat Spotlight: Phishing pages that exist only inside the victim’s browserhttps://blog.barracuda.com/2026/09/09/browser-based-phishing-blob-urls-microsoft-redirectsBarrcuda BlogBrowser-based phishing hides pages inside victims’ browsersLearn how attackers are using blob URLs, service workers, and Microsoft redirects to create browser-based phishing pages that evade traditional URL-based detection.1,580Open in Telegram
Sys-Admin InfoSec
7 Sept, 10:29
Critical vulnerabilities in MikroTik RouterOS are being actively exploited. Immediate update recommendedThe CERT Polska team has identified and coordinated the disclosure of six vulnerabilities in MikroTik RouterOS. Combining two of them allows an attacker to take full control of the device without authentication if the device supports remote access using the SSH protocol. To make this chain easier to identify, we have given it a common name, MikroTrick:https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/cert.plCritical vulnerabilities in MikroTik RouterOS are being actively exploited. Immediate update recommendedThe CERT Polska team has identified and coordinated the disclosure of six vulnerabilities in MikroTik RouterOS, including two critical ones. The vulnerabilities are already being actively exploited to take over devices whose SSH service is accessible from…1,750Open in Telegram
Sys-Admin InfoSec
4 Sept, 15:28
forwarded from @securixy_kz
1,500Open in Telegram
Sys-Admin InfoSec
3 Sept, 15:20
forwarded from @sysadm_in_up
ChatGPT Is Throwing 404
1,420Open in Telegram
Sys-Admin InfoSec
3 Sept, 02:38
🦄️️️️️️ Open SysConf'26. Спикер - ты нам нужен.Начало сентября означает не только начало учебного года, но и, что Open SysConf'26 ближе чем ты думаешь!Мы ищем доклады и докладчиков, заявки оставлять здесь.В этом году места ограничены, поэтому фиксируйся, что бы точно попасть здесь.Какие доклады мы ищем - интересные, бизнесовые, технические, ресерчи - все то, что поможет каждому развиться и сделать шаг вперед.Передай друзьям, знакомым - мы рады видеть всех, кто готов развиваться и показывать дела, а "не пиздеть - не мешки ворочить".Будут вопросы - смело пиши.Всем Мир ✌️
1,660Open in Telegram
Sys-Admin InfoSec
27 Aug, 11:43
Building Linux eBPF/XDP apps on macOS (Apple Silicon)I spend a lot of time building high-performance DNS filters and network tools in Go. My primary development machine is an Apple Silicon Mac, but all the production deployments target Linux/AMD64 servers.Recently, I started heavily integrating eBPF and XDP to drop abusive traffic (like random subdomain attacks) before it even hits the Go networking stack. However, compiling C eBPF code locally on macOS has always been a pain due to the missing Linux headers and the architectural differences...I wrote down the exact step-by-step process, including a workaround for the notorious Debian multiarch header issue (asm/types.h) and a neat little smoke test using bpftool inside the container..:https://openbld.net/blog/build-xdp-ebpf-macos-guide/openbld.netA practical guide to building, inspecting, cross-compiling, and running Linux eBPF/XDP applications on macOS using Colima, Docker, Clang, bpf2go, and Go.2,050Open in Telegram
Sys-Admin InfoSec
26 Aug, 04:22
forwarded from @sysadm_in_up
Survey: 56% of AI enthusiasts (and a third of all users) tell chatbots things they keep from other peoplehttps://spreadprivacy.com/ai-privacy-survey-aug26/Spread PrivacySurvey: 56% of AI enthusiasts (and a third of all users) tell chatbots things they keep from other peopleNew survey found 56% of AI enthusiasts (and a third of all users) tell chatbots things they keep from other people. How safe are their secrets?1,740Open in Telegram
Sys-Admin InfoSec
21 Aug, 05:16
Manic: Blend between Banking Malware & Spywareis a new Android banking malware and mobile spyware:https://www.threatfabric.com/blogs/manic-blend-between-banking-malware-and-spywareThreatFabricManic: Blend between Banking Malware & SpywareManic is a newly identified Android malware family with broad surveillance and remote-control capabilities, introducing an unusual Wi‑Fi mesh technique.2,400Open in Telegram
Sys-Admin InfoSec
19 Aug, 11:24
Clop Returns with Custom Implant in Mass-Extortion Campaign..“Clop's” exploitation of CVE-2026-12569 in PTC Windchill has returned the group to mass exploitation, delivering a custom web shell that provides full data-theft capability from the moment of deployment, with no additional tooling required..:https://reliaquest.com/blog/clop-returns-with-custom-implant-in-mass-extortion-campaign/ReliaQuestClop Returns with Custom Implant in Mass-Extortion CampaignClop's exploitation of CVE-2026-12569 in PTC Windchill returns the group to mass exploitation with a custom web shell built for full data theft.2,100Open in Telegram
Sys-Admin InfoSec
13 Aug, 11:40
forwarded from @openbld
3 BILLION DNS queries.Almost +1 billion in one week.OpenBLD started in 2019 as a homegrown project handling around 35K DNS queries a day.Today:→ ~15M queries/hour → 4K+ queries/second → servers distributed around the world → billions of DNS queries processedAnd it still runs mostly on regular VPS infrastructure - with plenty of performance headroom left.Getting here required years of optimizing the entire stack: networking, DNS processing, caching, filtering, load balancing, observability, and the Go code itself.Now the growth is public too:Real-time OpenBLD network statistics are live on OpenBLD.net.
2,440Open in Telegram
Sys-Admin InfoSec
6 Aug, 16:16
Claude in Chrome: From alert(1) to Full Account Takeoverhttps://labs.zenity.io/post/claude-in-chrome-from-alert-to-full-account-takeover
2,680Open in Telegram
Sys-Admin InfoSec
5 Aug, 12:36
7-Zip Leaves Extracted Malware Without Mark-of-the-Web, Bypassing Windows SmartScreenevil 7-zip)https://cyberpress.org/7-zip-bypasses-smartscreen-protections/Cyber Security News7-Zip Leaves Extracted Malware Without Mark-of-the-Web, Bypassing Windows SmartScreenA 7-Zip flaw can allow malware extracted from a specially crafted archive to lose Windows’ Mark-of-the-Web (MotW) label. Without that label2,760Open in Telegram
Sys-Admin InfoSec
4 Aug, 13:37
Threat Actors Abuse Trusted Software Lures and Cloudflare Tunnels to Deploy ScreenConnect RMM Agents Across Windows and macOSScreenConnect RMM Agents Across Windows and macOSAnalyzing SMOKE#SCREEN:https://www.securonix.com/blog/smoke-screen-screenconnect-rmm-abuse-cloudflare-tunnels/SecuronixSMOKE#SCREEN: ScreenConnect RMM Abuse, Cloudflare Tunnels, and Trusted Software LuresSecuronix Threat Research: Analyze the SMOKE#SCREEN campaign abusing ScreenConnect RMM, Cloudflare Tunnels, and trusted software lures to gain persistent access across Windows and macOS.2,410Open in Telegram
Sys-Admin InfoSec
30 Jul, 12:23
Welcome to DanglegeddonSilent Push Simulation Demonstrates Why Dangling Dns Domains Continue To Pose Global Threats..:https://www.silentpush.com/blog/danglegeddon/Silent PushWelcome to DanglegeddonSilent Push conducted a simulation of dangling DNS subdomain takeovers; the cascading impact potential could reach global proportions.2,730Open in Telegram
Sys-Admin InfoSec
21 Jul, 11:37edited
ClickLock Stealer: Paste Once, Lose EverythingUpon execution of the ClickFix command, the malicious script shows a terminal-based loading animation mimicking Cloudflare progress bar with browser verification flow..:https://www.group-ib.com/blog/clicklock-stealer-macos-malware/Group-IBClickLock Stealer: Paste Once, Lose EverythingAnalysis of ClickLock, a modular macOS stealer delivered via ClickFix that uses fake dialogs, kill loops, and a GSocket backdoor to steal passwords, browser data, and crypto wallets.3,140Open in Telegram
Sys-Admin InfoSec
16 Jul, 04:24
Coordinated AsyncAPI Supply Chain Attack: Miasma RAT Delivered via Compromised CI/CD Pipelines in Two Repositorieshttps://www.stepsecurity.io/blog/compromised-next-branch-pushes-malicious-asyncapi-generator-generator-helpers-and-generator-components-to-npmwww.stepsecurity.ioCoordinated AsyncAPI Supply Chain Attack: Miasma RAT Delivered via Compromised CI/CD Pipelines in Two Repositories - StepSecurityOn July 14, 2026 at 07:10 UTC, three packages in the AsyncAPI generator monorepo (@asyncapi/generator@3.3.1, @asyncapi/generator-helpers@1.1.1, and @asyncapi/generator-components@0.7.1) were published to npm carrying an obfuscated dropper that fires the moment…2,940Open in Telegram
Sys-Admin InfoSec
15 Jul, 20:53
Cursor 0day: When Full Disclosure Becomes the Only Protection Lefthttps://mindgard.ai/blog/cursor-0day-when-full-disclosure-becomes-the-only-protection-leftmindgard.aiCursor 0day: When Full Disclosure Becomes the Only Protection Left - MindgardThe vulnerability nobody seems interested in fixing2,400Open in Telegram
Sys-Admin InfoSec
13 Jul, 16:23
Inside Forg365: A Telegram-Distributed Sneaky 2FA-Style PhaaS Targetinghttps://zerobec.com/blog/inside-forg365-telegram-distributed-sneaky2fa-style-phaasZeroBECInside Forg365: A Telegram-Distributed Sneaky 2FA-Style PhaaS Targeting Microsoft 365 | ZeroBECZeroBEC threat research on Forg365, a Kali365-class Microsoft 365 PhaaS that combines Telegram distribution, AI-assisted lure generation, device-auth phishing, AiTM routing, AntiBot evasion, token vaulting, and a Manifest V3 browser extension (ForgCookie)…2,470Open in Telegram
Related Channels
Other channels in the same section of the catalogue.
