Security Feed
Live posts from mastodon.social on HTTP client vulnerabilities, botnets, JA4 fingerprinting, and network security research.
Library Radar
| Library | Version | CVEs mentioned | Collector | Source |
|---|---|---|---|---|
| axios | 0.30.4 | - | runner exists |
Threat Brief: Widespread Impact of the Axios Supply Chain At… ↗
LevelBlue - Open Threat Exchange ↗ |
| axios | 1.14.1 | - | runner exists |
Threat Brief: Widespread Impact of the Axios Supply Chain At… ↗
LevelBlue - Open Threat Exchange ↗ |
lang
all
en
de
es
fr
it
pl
ru
Showing 92 posts · cached 0 min ago ·
refresh
HIGH severity: CVE-2026-49189 in Acer Connect M6E 5G WiFi Router lets unauthorized local apps invoke admin ops via improper privilege management. No patch yet — restrict local access & monitor for updates. Details: https:// radar.offseq.com/threat/cve-20 26-49189-cwe-269-improper-privilege-manag
🔐 Ultrahuman conferma il furto di dati wellness: anche salute e fitness sono informazioni sensibili. Ora servono trasparenza e sicurezza. # Privacy # Cybersecurity 🔗 https://www. tomshw.it/hardware/ultrahuman- dati-wellness-credenziali-rubate-2026-06-04
Possible Phishing 🎣 on: ⚠️hxxps[:]//compliancerws[.]webflow[.]io 🧬 Analysis at: https:// urldna.io/scan/6a20c0253b77500 002020009 # cybersecurity # phishing # infosec # urldna # scam # infosec
Canada should know better. We have the schools, the engineers, the telecom history, the security expertise, the AI researchers, the policy institutions, and the civic memory to build serious digital sovereignty. Instead, Ottawa keeps mistaking control for competence. I wrote a longer essay on Bill C
🛡️ Coralogix raccoglie 200 milioni per monitorare gli agenti IA: cresce la sfida su sicurezza, controllo e fiducia nell’automazione. # IA # Cybersecurity 🔗 https://www. tomshw.it/hardware/coralogix-2 00-milioni-monitoraggio-agenti-ia-2026-06-04
Google Photos on Android finally gets this handy feature months after iPhone You can finally create a library of custom stickers in Google Photos on Android. https://www. androidauthority.com/google-ph otos-android-saved-stickers-folder-collections-3674327/ # Tech # Technology # TechNews # AI # Gadg
🚨 PHISHING DETECTED 🚨 🔗 Suspicious URL: nowdesktop-live[.]wixstudio[.]com 🔍 Analysis at: https:// phishdestroy.io/domain/nowdesk top-live.wixstudio.com/ # CryptoHacking # malware # PhishingScam # WalletHackers # BlockchainFraud
I used to follow someone here who publish statistics on TLD usage on their website. It's a pretty old website that looks like plain HTML. I think its profile picture is mostly dark. Does this ring a bell for anyone? # CTI # threatintel # tld
The deliverable that decides whether a security finding gets fixed is rarely the finding itself. It is the line under it that says "run this command on this vendor." # cybersecurity # ddos # infosec ddactic.net?ref=mastodon
[SPACEBEARS] - Ransomware Victim: Sicol - https://www. redpacketsecurity.com/spacebea rs-ransomware-victim-sicol/ # spacebears # dark_web # data_breach # OSINT # ransomware # threatintel # tor
Shokz upgraded its open earbuds with better sound and a lighter design The OpenDots 2 are designed to be more comfortable than traditional wireless earbuds that sit inside the ear. | Image: Shokz Shokz has announced two new versions of its open earbuds. Like the original OpenDots One that … https://
CISA to Issue Mandatory AI Security Directive for Federal Agencies by Friday https:// deafnews.it/en/article/cisa-to -issue-mandatory-ai-security-directive-for-federal-agencies-by-friday # Cybersecurity
🚨 CVE du jour : CVE-2026-4800 Lodash _.template : la validation CVE-2021-23337 était borgne — `imports` accepte toujours du code via prototype pollué → RCE. 📊 Indice de Panique™ : 3.1/10 ███░░░░░░░ 🔴 CVSS 8.1 — ça sent mauvais 🔥 EPSS 0% — théorique LinkedIn 😐 Niveau Meh — "LinkedIn va en parler plus
🚨 EUVD-2026-34204 📊 Score: 8.7/10 (CVSS v3.1) 📦 Product: Connect M6E 5G Portable WiFi Router 🏢 Vendor: Acer 📅 Updated: 2026-06-04 📝 The hard-coded APK resource files never expire, and the shared scepter leads to information leaks and potential misuse. 🔗 https:// euvd.enisa.europa.eu/vulnerabi lity/E
🚨 EUVD-2026-34205 📊 Score: 8.7/10 (CVSS v3.1) 📦 Product: Connect M6E 5G Portable WiFi Router 🏢 Vendor: Acer 📅 Updated: 2026-06-04 📝 The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for unauthenticated users to execute arbitrary root c
🟠 CVE-2026-10701 - High (7.5) Incorrect boundary conditions in the Graphics: Text component. This vulnerability was fixed in Firefox 151.0.3. 🔗 https://www. thehackerwire.com/vulnerabilit y/CVE-2026-10701/ # CVE # vulnerability # infosec # cybersecurity # security # Tenda # patchstack
🚨 EUVD-2026-34206 📊 Score: 4.9/10 (CVSS v3.1) 📦 Product: libexpat 🏢 Vendor: libexpat project 📅 Updated: 2026-06-04 📝 libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a p
Possible Phishing 🎣 on: ⚠️hxxps[:]//mansi-html[.]github[.]io/html-css-project/ 🧬 Analysis at: https:// urldna.io/scan/6a211c383b77500 00881301f # cybersecurity # phishing # infosec # urldna # scam # infosec
🚨 EUVD-2026-34207 📊 Score: 6.7/10 (CVSS v3.1) 📅 Updated: 2026-06-04 📝 A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient backend when processing malformed Manufacturer Usage Description (MUD) URLs. A local user can exploit this f
ASN: AS136257 Location: Dhaka, BD Added: 2026-05-28T23:33 # shodansafari # infosec
🚨 EUVD-2026-34208 📊 Score: 8.5/10 (CVSS v3.1) 📦 Product: Connect M6E 5G Portable WiFi Router 🏢 Vendor: Acer 📅 Updated: 2026-06-04 📝 Unchecked public access permissions on a core Broadcast Receiver allow unauthorized local software components to invoke administrative operations. 🔗 https:// euvd.enisa
🔴 CVE-2026-38967 - Critical (9.8) CrowCpp Crow through v1.3.1 HTTP is vulnerable to response header injection via unvalidated response header values. 🔗 https://www. thehackerwire.com/vulnerabilit y/CVE-2026-38967/ # CVE # vulnerability # infosec # cybersecurity # security # Tenda # patchstack
🟠 CVE-2026-42504 - High (7.5) Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU. 🔗 https://www. thehackerwire.com/vulnerabilit y/CVE-2026-42504/ # CVE # vulnerability # infosec # cybersecurity # security # Tenda # patchstack
New configuration detected for DDosia. Hosts: * www.contshipitalia.com * concorsi.difesa.it * cestes.usb.it * tripplanner.veneziaunica.it * adspstretto.it * www.terminalnapoli.it * www.usb.it * www.marina.difesa.it * www.visitvenezia.eu * www.marnavi.it * vtp.it * sua.portsofgenoa.com * www.esteri.i
New configuration detected for DDosia. Hosts: * www.veneziaunica.it * www.marnavi.it * www.marina.difesa.it * www.carabinieri.it * www.terminalnapoli.it * concorsi.difesa.it * maritime-union.com * www.contshipitalia.com * www.esteri.it # ThreatIntel # Ddosia # NoName * https:// witha.name/data/2026-
New configuration detected for DDosia. Hosts: * maritime-union.com * www.terminalnapoli.it * www.contshipitalia.com * www.marnavi.it # ThreatIntel # Ddosia # NoName * https:// witha.name/data/2026-06-04_08- 10-07_DDoSia-target-list-full.json * https:// witha.name/data/2026-06-04_08- 10-07_DDoSia-tar
New configuration detected for DDosia. Hosts: * www.terminalnapoli.it * www.contshipitalia.com # ThreatIntel # Ddosia # NoName * https:// witha.name/data/2026-06-04_08- 05-07_DDoSia-target-list-full.json * https:// witha.name/data/2026-06-04_08- 05-07_DDoSia-target-list.csv
🟠 CVE-2026-9516 - High (7.5) Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM prefixed input when a decode filter callback throws. To skip a leading 3-byte UTF-8 BOM, decode_json() advances the input scalar's string pointer past the mark w... 🔗 https://www. th
🕵️ 𝗜𝗣 𝗰𝗵𝗲𝗹𝗼𝘂 𝗱𝘂 𝗷𝗼𝘂𝗿 🕵️ Fiche : "le Path Traversal Wala de Sector 19" 📍 IN | AS132420 ☠️ CVE-2021-41773 (Apache) 🎯 /cgi-bin/.%2e/.%2e/…/bin/sh Traduction : "Bonjour, je cherche /bin/sh par ici ?" Apache 2.4.49 est patché depuis 2021, ami. Notre honeypot, lui, adore les visiteurs nostalgiques. 🍵 # ho
Sliver C2 Detected - 91[.]236[.]230[.]152:31337 - https://www. redpacketsecurity.com/sliver-c 2-detected-91-236-230-152-port-31337/ # SliverC2 # OSINT # ThreatIntel
Sliver C2 Detected - 66[.]116[.]238[.]103:31337 - https://www. redpacketsecurity.com/sliver-c 2-detected-66-116-238-103-port-31337/ # SliverC2 # OSINT # ThreatIntel
[STORMOUS] - Ransomware Victim: SA2000[.]COM - https://www. redpacketsecurity.com/stormous -ransomware-victim-sa2000-com/ # stormous # dark_web # data_breach # OSINT # ransomware # threatintel # tor
One of the things this paper underscores is that you don’t need a cutting edge model in order to get the #agentic worm to replicate. We have completely underestimated the capabilities of smaller, open-weight models. #malware
Anatomía de una APT simulada. Parte 4 - La noche del cifrado, la negociación y el reparto # apt # cripto # maldev # malware # ransomware https://www. hackplayers.com/2026/06/anatom ia-de-una-apt-simulada-parte-4.html
🚨 PHISHING DETECTED 🚨 🔗 Suspicious URL: royalheritagetrade[.]com 🔍 Analysis at: https:// phishdestroy.io/domain/royalhe ritagetrade.com/ # malware # FraudDetection # fake # BlockchainSafety
48,000 CVEs in 2025—but only 58 were critical. With security noise drowning out real supply chain malware threats, learn why filtering for exploitability matters. https:// jpmellojr.blogspot.com/2026/06 /cve-noise-drowns-out-software-supply.html # Black_Kite # Malware # AppSec # SupplyChainSecurity
🚨 PHISHING DETECTED 🚨 🔗 Suspicious URL: devpiler[.]com 🔍 Analysis at: https:// phishdestroy.io/domain/devpile r.com/ # WalletDrainers # PhishingScam # CryptoThreats # malware # BlockchainSafety # WalletSecurity
🚨 PHISHING DETECTED 🚨 🔗 Suspicious URL: cdcompiler[.]com 🔍 Analysis at: https:// phishdestroy.io/domain/cdcompi ler.com/ # CryptoDrainers # malware # BlockchainFraud # ScamPrevention
🚨 PHISHING DETECTED 🚨 🔗 Suspicious URL: formprism-static[.]pages[.]dev 🔍 Analysis at: https:// phishdestroy.io/domain/formpri sm-static.pages.dev/ # malware # scam # NFT # WalletDrainers # CryptoThreats
May's Topic of the Month recap is up. We asked the community how they approach Zeek sensor placement: https:// zeek.org/2026/06/zeek-sensor-p lacement-in-practice-tapping-what-you-actually-understand/ # Zeek # NetworkSecurity # OpenSource
Over 116,000 # Minecraft systems infected in # WeedHack # malware campaign https://www. bleepingcomputer.com/news/secu rity/over-116-000-mincraft-systems-infected-in-weedhack-malware-campaign/ # cybersecurity # gaming
🚀 Become a Cyber Security Expert & Secure Your Future! With cyber threats growing every day, the demand for skilled cybersecurity professionals is at an all-time high. Learn Ethical Hacking, Network Security, Wireshark, Splunk, Linux, and more with industry-focused training from Network Bulls. S
New. Also known as porn. Kaspersky: Argamal: Malware hidden in hentai games https:// securelist.com/argamal-rat-dis tributed-with-hentai-games/119999/ @ Kaspersky # infosec # malware # threatresearch
Developers are embracing agentic coding tools - but data engineers need tools with specialist scraping skills. https://www. zyte.com/blog/introducing-zyte -web-data-for-claude-code?utm_campaign=blog-posts&utm_activity=ORS&utm_medium=social&utm_source=mastodon # webscraping # webdata # da
Full details available via Spamhaus IP and Domain Checker - simply input the SBL number and hit ENTER ➡️ https:// check.spamhaus.org 🤔 Not using Spamhaus' DROP lists already? You can access them for FREE and gain protection against the worst of the worst IP traffic at the routing level. Lists are av
Я сошёл с ума и сдаю свой браузер ИИ-агентам Я совсем поехал кукухой — начал сдавать в аренду свой браузер за деньги. Началось всё с того, что мои ИИ-агенты не смогли нормально зарегаться из-за капчей и прочего, чужие расширения меня не устраивали — они плохо интегрировались в мой флоу и были завяза
Niederländische Strafverfolger legen Botnet mit 17 Millionen Drohnen lahm | heise online https://www. heise.de/news/Niederlaendische -Strafverfolger-legen-Botnet-mit-17-Millionen-Drohnen-lahm-11313066.html # Cybercrime # Botnet # Botnetz
Stay ahead of cyber threats. Today’s playlist dives deep into network breaches and how to stop them. ⚡ https://www. youtube.com/playlist?list=PLXq x05yil_mc6FyMY-KPn0F1qIDLWOS69 # NetworkSecurity # InfoSec # CyberDefense # Ransomware # OnlineSafety
It is wild to think that a simple home router or smart camera could be part of a global cybercrime network. Dutch police recently stopped a 17 million botnet that was using everyday devices to hide malicious traffic. It is a good time to check your settings and update that firmware. You can read mor
Niederländische Strafverfolger legen # Botnet mit 17 Millionen Drohnen lahm | Security https://www. heise.de/news/Niederlaendische -Strafverfolger-legen-Botnet-mit-17-Millionen-Drohnen-lahm-11313066.html
European Parliament ditches Google for French search firm over privacy concerns https://www.politico.eu/article/european-parliament-ditches-google-for-french-search-engine/?utm_source=RSS_Feed&utm_medium=RSS&utm_campaign=RSS_Syndication #CybersecurityandDataProtection #Criticalinfrastructure
Exploitation of PAN-OS GlobalProtect Authentication Bypass Vulnerability (CVE-2026-0257) In this article, I break down how the vulnerability works, affected configurations, exploitation scenarios, and the mitigation steps organizations should take to protect their remote access infrastructure. https
Modern scraping problem: Your parser is fine. Your response is blocked 😅 I tested Bright Data Web Unlocker API with Python + BeautifulSoup to fetch protected, JS-rendered pages without managing proxies. Full article 👇 https:// medium.com/gitconnected/how-i- scraped-modern-protected-websites-in-pytho
I spent 3 days building a LinkedIn scraper. Then I found the dataset already existed 😅 Sometimes the best engineering decision is not to scrape more — but to check whether structured data is already available. Full article 👇 https:// medium.com/gitconnected/i-spen t-3-days-building-a-linkedin-scrape
Security Tip: Prevent lateral movement using micro-segmentation. 🛡️ In traditional 'castle and moat' security, once an attacker is inside, they have the run of the place. Zero Trust changes this by creating granular zones. If one segment is compromised, the rest remains isolated. It is about limitin
AI-assisted coding is a revelation. But are you getting the most out of your IDE’s sidebar sidekick? https://www. zyte.com/blog/copilot-pro-tips -workflow?utm_campaign=blog-posts&utm_activity=ORS&utm_medium=social&utm_source=mastodon # webscraping # webdata # data # web
Boost your skills with today’s cybersecurity playlist: exploits, defenses, and real-world lessons. 🔒 https://www. youtube.com/playlist?list=PLXq x05yil_mfPIYFeo6QiHe8Eeb-CT0Wu # CyberAwareness # NetworkSecurity # ZeroTrust # ThreatIntelligence # Malware
Boost your skills with today’s cybersecurity playlist: exploits, defenses, and real-world lessons. 🔒 https://www. youtube.com/playlist?list=PLXq x05yil_mdsegWasDQwQsdrTZ0A-3jI # CyberAwareness # NetworkSecurity # ZeroTrust # ThreatIntelligence # Malware
Last week my # website saw an insane amount of requests from a # botnet . I've taken counter measurements to combat this botnet. Read everything about this in my new # blogpost https:// blog.boykisser.nl/2026/06/01/a ctual-insanity-ddos-on-boykissernl/
Nuevo producto de nuestra factoría "GallecIA Media HackLab", de la asignatura de Periodismo Automatizado Inteligente que coordino en la USC. 👏 👏 👏 👏 👏 👏 👏 👏 👏 https:// ia.xornalismo.gal/proxectos/cu rso_actual/2025-26/ana_iglesias_cabarcos/index.html # Periodismo # TrueCrime # VisualizaciónDeDatos #
Boost your skills with today’s cybersecurity playlist: exploits, defenses, and real-world lessons. 🔒 https://www. youtube.com/playlist?list=PLXq x05yil_mf_HIz2eh1Oa4K6_hxd6rf4 # CyberAwareness # NetworkSecurity # ZeroTrust # ThreatIntelligence # Malware
Dutch prosecutors disable botnet with 17 million drones The Dutch NCSC and police have shut down a botnet with 200 servers and 17 million infected devices. https://www. heise.de/en/news/Dutch-prosecu tors-disable-botnet-with-17-million-drones-11313253.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitra
Niederländische Strafverfolger legen Botnet mit 17 Millionen Drohnen lahm Das niederländische NCSC und die Polizei haben ein Botnet mit 200 Servern und 17 Millionen infizierten Geräten ausgeknipst. https://www. heise.de/news/Niederlaendische -Strafverfolger-legen-Botnet-mit-17-Millionen-Drohnen-lahm
Holenderska policja odłącza wtyczkę. Zlikwidowano botnet liczący 17 milionów urządzeń Twój stary router, zapomniana kamera IP albo smartfon z przestarzałym Androidem mogły być częścią potężnej, globalnej broni. Holenderskie służby właśnie wyłączyły jeden z największych w his
Your VPS is ready, but now you need to work through the same sequence you have run a dozen times before: apt update, apt install python3-pip, pip install scrapy, playwright install chromium, the Chromium dependency list that never installs cleanly on the first try, Redis, possibly Postgres, whatever
Multi-agent orchestration is having its moment. The diagrams are everywhere now. Boxes for planners, boxes for hands, boxes for daemons, arrows to a shared brain, a human floating at the top. They keep getting prettier. The part where the web pushes back is still the part nobody draws. https://www.
La policía holandesa desmantela una # botnet de 17 millones de dispositivos vinculada al servicio de proxies ASOCKS https:// wwwhatsnew.com/2026/05/31/botn et-17-millones-dispositivos-asocks-policia-holandesa-2026/
Dutch Police Disrupt Major Botnet Linked to 17 Million Infected Devices Dutch authorities have successfully dismantled a massive botnet that had infected a staggering 17 million devices worldwide, turning everyday gadgets into a global attack platform. The operation, led by the Dutch Police and Nati
# Dutch govt disrupts # malware # botnet with 17 million infected devices https://www. bleepingcomputer.com/news/secu rity/dutch-govt-disrupts-malware-botnet-with-17-million-infected-devices/ # cybersecurity # netherlands # cybercrime # police
Why don't the *&^(*& people at Meta / Facebook honour my robots.txt? They are crawling my linked data dereferencer like crazy. I had to block them using a firewall # meta # scraping # ethics # webethics
And another drive by on my Web Server last night from a Google Cloud IP Looking at the logs it they hit the root hostname of the domain and then walked EVERY link from there on down using what looks to be a valid Safari User-Agent. It does appear to be some what rate limited as it spread it out over
@ christianschwaegerl @ amnesty_digital_de wer sagts der politik ? bzw. kontrolliert die Verfahren ? der # Papst_Leo_XIV hatte ja diesbezüglich schon einen Aufschlag gemacht. @ Rainer_Rehak hat nen artikel in # EnergieZukunft ( https://www. energiezukunft.eu/wirtschaft/k i-und-klimaschutz-eine-besta
🕷️ Python scraping tip: If BeautifulSoup returns nothing, the parser may not be the issue. First check what your scraper actually received: 🚫 403 🚫 blocked HTML 🚫 missing rendered content I wrote about using Web Unlocker API as an access layer before parsing with BeautifulSoup. https:// medium.com/g
🔍 # Firecrawl /monitor: keep your # AI # agent in sync with the web. Point it at a URL, describe changes in plain English, get a webhook or email when something meaningful changes ☝️ # webscraping # devtools https:// docs.firecrawl.dev/features/mo nitoring
Beyond robots.txt: Implementing ai.txt and llms.txt for Purpose-Based Scraping Control, by (not on Mastodon or Bluesky): https:// cookie-script.com/guides/beyon d-robots-txt-implementing-ai-txt-and-llms-txt-for-purpose-based-scraping-control?ref=frontenddogma.com # ai # scraping # crawling # llmstxt
Scrapers vs Wikis: Person who runs a bunch of custom Wiki websites writes about abuse from scrapers https:// weirdgloop.org/blog/clankers # via :lobsters # robotstxt # scraping # scaling # wiki # web # ai #+
# Development # Demos WebMCP Demo · How AI agents interact with web pages today and tomorrow https:// ilo.im/16d3mq _____ # Comparisons # AI # AiAgents # Content # Website # AgenticWeb # WebMCP # Scraping # WebDev # Frontend
@ RainbowFrog moi j'utilise l'extension webscraper pour ce genre de truc https:// webscraper.io/ (dans Firefox ou Chrome) # webscraping # scraping @ belett @ Ash_Crow
Meta seems to be doing some truly hostile anti-scraping webdev all HTML classes have random IDs and i would not be surprised to see that they also change frequently (i will find out soon enough) (example: https:// privacycenter.instagram.com/po licy ) is there some sort of "fingerprinting" technique
🎉 Look, another web scraper! 🎉 Because we *definitely* needed one more tool to fetch JSON from # Wikipedia faster than a cheetah on Red Bull. 🐆💨 No doubt, this will revolutionize the already groundbreaking field of # scraping celebrity birthdates. 🙄✨ https:// scrapewithruno.com/ # webscraping # JSON
NO SOUP FOR YOU! Playwright + Ollama ==TRANSLITERATE== BEAUTIFUL DATA Build a self-auditing data pipeline that keeps my MariaDB in perfect sync. Full workflow: https:// dufospy.com/artificial-intelli gence/data-mining-web-scraping-playwright-ollama # Beautifulsoup # Playwright # data # scraping @ pl
"TLS Fingerprinting: the hidden profile of your browser 🚀🔥 Every secure connection reveals more about you than just encryption # security # tlsfingerprinting " https:// medium.datadriveninvestor.com/ what-tls-fingerprinting-is-in-2026-and-why-it-matters-9220e25f2c33
I’m still completely lost with logic of JA4+ patent licensing and actual incompatibility with the copyleft-license. So it seems to be a patent-based license and really risky to implement if you want to keep your actual software open source. Did someone explore alternatives to avoid this? and especia
https://www. olnba.com/883787/ NIKE Ja4|Ja Morant /ジャ・モラント写真公開!スペック予想&5カラーまとめ # バッシュ # nba # shorts # BasketballShoes # JaMorant # Ja4 # NationalBasketballAssociation # NBA # NBAVideos # NBAバッシュ # NikeBasketball # NIKEJa4 # NikeJa4 # Nikeバッシュ # Shorts # ZoomX # シグネチャーシューズ # ジャモラント # スニーカー # ドロップインミッ
We planned one report on Keitaro abuse, but we ran out of pages before we ran out of cases. So here’s Part 2 of 3, a medley of threats that go well beyond AI‑investment scams. Threat actors abuse Keitaro’s traffic distribution, cloaking, and rule engine to hide malicious landing pages behind geo and
Анатомия DPI анализа: что происходит с твоим пакетом за первые 16 КБ Пошаговый разбор того, как ТСПУ анализирует трафик — от первого SYN до поведенческого ML. С конкретными числами, реальными алгоритмами и объяснением почему одни протоколы умирают на первом байте, а другие живут месяцами Большинство
Анатомия DPI анализа: что происходит с твоим пакетом за первые 16 КБ Пошаговый разбор того, как ТСПУ анализирует трафик — от первого SYN до поведенческого ML. С конкретными числами, реальными алгоритмами и объяснением почему одни протоколы умирают на первом байте, а другие живут месяцами Большинство
Как ТСПУ ловит VLESS в 2026 и почему XHTTP — следующий шаг Разбор методов детекции, которые работают прямо сейчас. JA3/JA4-отпечатки, поведенческий анализ и архитектура XHTTP, которая закрывает именно эти дыры Если твой VLESS+Reality сервер лёг в последние месяцы — ты не один. В сообществах фиксирую
Как ТСПУ ловит VLESS в 2026 и почему XHTTP — следующий шаг Разбор методов детекции, которые работают прямо сейчас. JA3/JA4-отпечатки, поведенческий анализ, академическая работа СПбПУ по детекции Reality — и архитектура XHTTP, которая закрывает именно эти дыры Если твой VLESS+Reality сервер лёг в пос
RE: https:// infosec.exchange/@geraldcombs/ 116133603929246605 # Wireshark 4.6.4 resolves 3 denial of service vulnerabilities in the following protocol dissectors: USB HID CVE-2026-3201 NTS-KE CVE-2026-3202 RF4CE Profile CVE-2026-3203 The new release also includes a bug fix for # JA4 fingerprints of
📢 JA4 pour traquer les scrapers IA : guide pratique de fingerprinting TLS 📝 Source: WebDecoy (équipe sécurité). 📖 cyberveille : https:// cyberveille.ch/posts/2026-01-1 0-ja4-pour-traquer-les-scrapers-ia-guide-pratique-de-fingerprinting-tls/ 🌐 source : https:// webdecoy.com/blog/ja4-fingerpr inting-a
http:// blog.foxio.io/ja4+-network-fin gerprinting https:// github.com/FoxIO-LLC/ja4 # ja4 + # blueteam # redteam