Security Feed

Live posts from mastodon.social on HTTP client vulnerabilities, botnets, JA4 fingerprinting, and network security research.

Sourced from the Mastodon public API - no account required. Cached 1 hour.
Library Radar
Library Version CVEs mentioned Collector Source
requests 2.34.2 CVE-2017-9841 runner exists 🌍 Pew Pew CH (Infomaniak) — Honeypot · @Bobe_bot@mastobot.ping.moi
axios 0.30.4 - runner exists Threat Brief: Widespread Impact of the Axios Supply Chain At… · @orlysec@swecyb.com
LevelBlue - Open Threat Exchange · @techbot@social.raytec.co
axios 1.14.1 - runner exists Threat Brief: Widespread Impact of the Axios Supply Chain At… · @orlysec@swecyb.com
LevelBlue - Open Threat Exchange · @techbot@social.raytec.co
all #ja4 #tlsfingerprinting #networkfingerprinting #botnet #malware #infosec #cybersecurity #vulnerability #cve #threatintel #networksecurity #scraping #webscraping
lang all en de fr pt ru
Showing 92 posts · cached 0 min ago · refresh
Marcus Schuler
@schuler
#cybersecurity en
OpenAI says its Astra model hit a 'Critical' cybersecurity risk threshold—a first for the company. The strongest cyber capabilities will stay with alpha testers rather than general release. No outside party has verified these claims yet. https://www. implicator.ai/openai-gates-ast ra-cyber-a
0 0 2026-09-02 view →
Threadlinqs
@threadlinqs
#threatintel en
One malicious XML request turns Switchvox's PBX into a root shell - no login required. 9 detections, 7 IOCs. Full analysis + IOCs: https:// intel.threadlinqs.com/threat/T L-2026-2300 # ThreatIntel # CVE_2026_9586 # Netcat # curl # Switchvox # Sangoma
0 0 2026-09-02 view →
Analyst207
@Analyst207
#botnet en
Law Enforcement Disrupts 23-Year-Old Russia-Based Botnet Sality In a major cybercrime sting, law enforcement has dismantled a 23-year-old Russia-based botnet that had infected over 11 million devices worldwide. By cleverly tricking the network into cutting off access to its own devices, CrowdStrike
0 0 2026-09-02 view →
Threadlinqs
@threadlinqs
#threatintel en
Your AI coding assistant just typed a package name that doesn't exist. An attacker already registered it. 9 detections, 18 IOCs. Full analysis + IOCs: https:// intel.threadlinqs.com/threat/T L-2026-2299 # ThreatIntel # Python # Claude # Cursor # Slopsquatting # AIAgents
0 0 2026-09-02 view →
urlDNA.io :verified:
@urldna@infosec.exchange
#infosec en
Possible Phishing 🎣 on: ⚠️hxxps[:]//docs[.]google[.]com/presentation/d/e/2PACX-1vT3x8uKQ-hK7-g1cEFerZIYaoaP5MTCCKZlmoWCXmSDKPxd1Y2AdFwRaQTmHZmiVDFErUwg3ulVm3rl/pub?start=false&loop=false&delayms=3000 🧬 Analysis at: https:// urldna.io/scan/6a9880643b77500 0066c7325 # cybersecurity # phishing
0 1 2026-09-02 view →
Ivy Cyber
@ivycyber@privacysafe.social
#cybersecurity en
🛡️ # Cybersecurity news & tips across the # fediverse “…Despite the seriousness of the accusations against ⌗EricSwalwell, many aspects of the FBI’s request to the Federal ⌗AirMarshal Service were unusual, current & former officials said․ For one thing, the ⌗FBI do…” https:// masto.ai/@Nonile
0 1 2026-09-02 view →
Hacker News
@h4ckernews
#cybersecurity en
METR Report on OpenAI / Hugging Face Hacking Incident https:// metr.org/blog/2026-08-26-opena i-hugging-face-incident-investigation/#core-takeaways-about-this-incident Comments: https:// news.ycombinator.com/item?id=4 9543841 # HackerNews # METRReport # OpenAI # HuggingFace # HackingIncident # Cyber
0 0 2026-09-02 view →
Cloud 🤖
@cloud@infosec.exchange
#infosec en
🤖 CVE-2026-83548 + CVE-2026-83549: two SonicWall SMA 1000 zero-days (pre-auth SSRF, CVSS 10.0, chained with an OS command injection) enable unauthenticated RCE. Actively exploited; both added to CISA KEV (due Sep 5). 🔗 https://www. darkreading.com/vulnerabilitie s-threats/sonicwall-sma-1000-zero-day
0 1 2026-09-02 view →
PhishDestroy Alert
@phishdestroy
#malware en
🚨 PHISHING DETECTED 🚨 🔗 Suspicious URL: chikmagalur[.]shop 🔍 Analysis at: https:// phishdestroy.io/domain/chikmag alur.shop/ # BlockchainFraud # SecureYourWallet # malware # NFT # ScamDetection
0 0 2026-09-02 view →
TheHackerWire
@thehackerwire
#infosec en
🔴 CVE-2026-19117 - Critical (9.8) Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as that user. This issue affects on-premises deployments only. 🔗 https://www. thehackerwire.com/vulnerabilit y/CVE-2026-19117/
0 0 2026-09-02 view →
TheHackerWire
@thehackerwire
#infosec en
🟠 CVE-2026-84382 - High (7.5) HTTPX2 is a next generation HTTP client for Python. Prior to 2.12.0, the HTTPX2 content decoders in src/httpx2/httpx2/_decoders.py fully inflate each gzip, deflate, br, or zstd network chunk before iter_bytes() or aiter_bytes() yields bounded piec... 🔗 https://www. theh
0 0 2026-09-02 view →
TheHackerWire
@thehackerwire
#infosec en
🟠 CVE-2026-84381 - High (8.1) HTTPX2 is a next generation HTTP client for Python. Prior to 2.10.0, httpcore2 fails to start TLS in src/httpcore2/httpcore2/_sync/socks_proxy.py and src/httpcore2/httpcore2/_async/socks_proxy.py when the remote origin uses wss through a SOCKS5 pr... 🔗 https://www. theh
0 0 2026-09-02 view →
PhishDestroy Alert
@phishdestroy
#malware en
🚨 PHISHING DETECTED 🚨 🔗 Suspicious URL: fiscalizacaoreceita[.]com 🔍 Analysis at: https:// phishdestroy.io/domain/fiscali zacaoreceita.com/ # malware # ScamPrevention # scamalert # CryptoThreats # BlockchainFraud # CyberFraud
0 0 2026-09-02 view →
James Sargent
@SargentJamesA
#infosec en
Security is not what you tell a system. It is what you make impossible. The sandbox held until the model found a zero day in the one sanctioned exit. The headline said a model escaped. Assumptions are not controls. # InfoSec # AI # Governance # Security # AIAgents
0 0 2026-09-02 view →
urlDNA.io :verified:
@urldna@infosec.exchange
#infosec en
Possible Phishing 🎣 on: ⚠️hxxps[:]//heygunjan[.]github[.]io/Netflix-Clone 🧬 Analysis at: https:// urldna.io/scan/6a980ff13b77500 006f91e66 # cybersecurity # phishing # infosec # urldna # scam # infosec
0 1 2026-09-02 view →
Shodan Safari
@shodansafari@infosec.exchange
#infosec en
ASN: AS12353 Location: Loulé, PT Added: 2026-08-28T17:53 # shodansafari # infosec
0 1 2026-09-02 view →
PhishDestroy Alert
@phishdestroy
#malware en
🚨 PHISHING DETECTED 🚨 🔗 Suspicious URL: mparoguestapartments[.]com 🔍 Analysis at: https:// phishdestroy.io/domain/mparogu estapartments.com/ # WalletDrainers # BlockchainFraud # CryptoDrainers # ScamDetection # PhishingWarning # ProtectCrypto # malware
0 0 2026-09-02 view →
TheHackerWire
@thehackerwire
#infosec en
🟠 CVE-2026-84292 - High (7.5) fast-uri serializes the port component of a URI without validating it. When recomposing the authority, the userinfo and host components are escaped but the port is concatenated verbatim, so a port value that is not a sequence of digits can inject ... 🔗 https://www. theh
0 0 2026-09-02 view →
PhishDestroy Alert
@phishdestroy
#malware en
🚨 PHISHING DETECTED 🚨 🔗 Suspicious URL: copelouzosgroupgr[.]com 🔍 Analysis at: https:// phishdestroy.io/domain/copelou zosgroupgr.com/ # PhishingWarning # Web3Hacking # malware # Web3Awareness # scam
0 0 2026-09-02 view →
Threadlinqs
@threadlinqs
#threatintel en
Ransomware crews load signed but vulnerable drivers to blind your EDR before encrypting everything. 9 detections, 29 IOCs. Full analysis + IOCs: https:// intel.threadlinqs.com/threat/T L-2026-2297 # ThreatIntel # CVE_2013_3900 # HiddenGh0st # LockBit # MedusaLocker # BYOVD
0 0 2026-09-02 view →
PhishDestroy Alert
@phishdestroy
#malware en
🚨 PHISHING DETECTED 🚨 🔗 Suspicious URL: blockchaintumbler[.]com 🔍 Analysis at: https:// phishdestroy.io/domain/blockch aintumbler.com/ # SecureYourWallet # ProtectCrypto # malware # CryptoDrainers # Web3Awareness # scam
0 0 2026-09-02 view →
Chum1ng0 - Security Research :verified:
@chum1ng0@infosec.exchange
#cybersecurity en
Rutify case: attacks on institutions in April and one person arrested by the PDI https://www. security-chu.com/2026/09/Rutif y-Chile-ataques-ciberneticos-desde-abril-.html # Chile # cybersecurity # cybercrime # hacking
0 2 2026-09-02 view →
PhishDestroy Alert
@phishdestroy
#malware en
🚨 PHISHING DETECTED 🚨 🔗 Suspicious URL: immediateanredex[.]com 🔍 Analysis at: https:// phishdestroy.io/domain/immedia teanredex.com/ # malware # scamalert # WalletDrainers # NFT # PhishingWarning
0 0 2026-09-02 view →
urlDNA.io :verified:
@urldna@infosec.exchange
#infosec en
Possible Phishing 🎣 on: ⚠️hxxp[:]//revoke-cash-lahana[.]vercel[.]app 🧬 Analysis at: https:// urldna.io/scan/6a987a143b77500 0066c70e5 # cybersecurity # phishing # infosec # urldna # scam # infosec
0 1 2026-09-02 view →
Threadlinqs
@threadlinqs
#threatintel en
NodeStealer just leveled up: keylogger, clipboard sniffer, screen capture - stealing more than passwords now. 9 detections, 30 IOCs. Full analysis + IOCs: https:// intel.threadlinqs.com/threat/T L-2026-2296 # ThreatIntel # NodeStealer # ScriptPythonInfostealer # TrojanStealer130 # Facebook # Spyware
0 1 2026-09-02 view →
PhishDestroy Alert
@phishdestroy
#malware en
🚨 PHISHING DETECTED 🚨 🔗 Suspicious URL: institutobushido[.]org[.]br 🔍 Analysis at: https:// phishdestroy.io/domain/institu tobushido.org.br/ # ScamDetection # malware # NFT
0 0 2026-09-02 view →
PhishDestroy Alert
@phishdestroy
#malware en
🚨 PHISHING DETECTED 🚨 🔗 Suspicious URL: ezebra[.]outleca[.]com 🔍 Analysis at: https:// phishdestroy.io/domain/ezebra. outleca.com/ # ScamPrevention # Web3Security # CryptoSafety # CryptoAwareness # malware # WalletSecurity # scam
0 0 2026-09-02 view →
PhishDestroy Alert
@phishdestroy
#malware en
🚨 PHISHING DETECTED 🚨 🔗 Suspicious URL: healthvoyageistanbul[.]xyz 🔍 Analysis at: https:// phishdestroy.io/domain/healthv oyageistanbul.xyz/ # Web3Security # NFT # DigitalFraud # WalletDrainers # CryptoThreats # WalletSecurity # malware
0 0 2026-09-02 view →
PhishDestroy Alert
@phishdestroy
#malware en
🚨 PHISHING DETECTED 🚨 🔗 Suspicious URL: doyledefence[.]com 🔍 Analysis at: https:// phishdestroy.io/domain/doylede fence.com/ # BlockchainSafety # BlockchainFraud # CyberFraud # scamalert # DigitalFraud # FraudDetection # malware
0 0 2026-09-02 view →
CyberIntel News
@cyberintelnews
#threatintel en
From the CyberIntel archive: Significant Infrastructure Breaches and AI Threats Highlighted in Check Point Research Report https:// cyberintelnews.com/ # Malware # ThreatIntel # Cybersecurity # Infosec
0 0 2026-09-02 view →
Threadlinqs
@threadlinqs
#threatintel en
This RAT looks up its C2 server on the TON blockchain - sinkhole the domain and it just rotates. 9 detections, 22 IOCs. Full analysis + IOCs: https:// intel.threadlinqs.com/threat/T L-2026-2295 # ThreatIntel # TrojanSpyJSTONRESOLVERA # TrojanPS1TONRESOLVERA # TONResolver # BlockchainC2 # JapanHotels
0 0 2026-09-02 view →
Threadlinqs
@threadlinqs
#threatintel en
North Korea weaponized npm's install hook into a self-spreading credential-stealing worm. 9 detections, 18 IOCs. Full analysis + IOCs: https:// intel.threadlinqs.com/threat/T L-2026-2294 # ThreatIntel # ZshBucket # CanisterWorm # TeamPCPCloudStealer # Lazarus # npm
0 0 2026-09-02 view →
RedPacket Security
@RedPacketSecurity
#threatintel en
[SILENTRANSOMGROUP] - Ransomware Victim: S[.][.][.] M[.][.][.] - https://www. redpacketsecurity.com/silentra nsomgroup-ransomware-victim-s-m/ # silentransomgroup # dark_web # data_breach # OSINT # ransomware # threatintel # tor
0 0 2026-09-02 view →
RedPacket Security
@RedPacketSecurity
#threatintel en
[WALLSTREET] - Ransomware Victim: Ormond Beach Florida - https://www. redpacketsecurity.com/wallstre et-ransomware-victim-ormond-beach-florida/ # wallstreet # dark_web # data_breach # OSINT # ransomware # threatintel # tor
0 1 2026-09-02 view →
RedPacket Security
@RedPacketSecurity
#threatintel en
[DIREWOLF] - Ransomware Victim: PTT Oil and Retail Business - https://www. redpacketsecurity.com/direwolf -ransomware-victim-ptt-oil-and-retail-business/ # direwolf # dark_web # data_breach # OSINT # ransomware # threatintel # tor
0 0 2026-09-02 view →
Cloud 🤖
@cloud@infosec.exchange
#cve en
🤖 CVE-2026-9586: unauthenticated SQL injection in Sangoma Switchvox (VoIP PBX) actively exploited in the wild, leading to remote code execution. Attackers deploy reverse shells on exposed instances. 🔗 https://www. bleepingcomputer.com/news/secu rity/hackers-exploit-sangoma-switchvox-flaw-to-deploy-r
0 1 2026-09-02 view →
Byte0x90
@Byte0x90
#vulnerability de
Eine kritische SQL-Injection im weit verbreiteten WordPress-Plugin „All-in-One WP Migration and Backup“ bedroht Millionen Webseiten. Unauthentifizierte Angreifer können die Schwachstelle ausnutzen, um Schadcode einzuschleusen und die vollständige Kontrolle über betroffene Systeme zu erlangen. Betrof
0 0 2026-09-02 view →
StemShop | CVE Research
@stemshop
#vulnerability en
🚨 CVE-2026-19117 — CVSS 9.8 CRITICAL Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as that user. This issue affects on-premises deployments only. 🔎 Details: https:// stemshop.top/cve/CVE-2026-19117 # CVE # C
0 0 2026-09-02 view →
StemShop | CVE Research
@stemshop
#vulnerability en
🚨 CVE-2026-66786 — CVSS 9.1 CRITICAL A flaw was found in submariner. In cert-auth mode, the connection configuration is built using free-form strings from the Custom Resource Definition (CRD) without proper validation. A malicious cluster can exploit this by publishing a CableName that includes newl
0 0 2026-09-02 view →
StemShop | CVE Research
@stemshop
#vulnerability en
🚨 CVE-2026-53671 — CVSS 9.3 CRITICAL PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Interpretation Layer. Prior to version 0.2.4, the abstract transformer in prevail treats writes through a T_CTX-typed base register as a silent no-op: do_mem_store in src/crab/ebpf_transformer.cpp on
0 0 2026-09-02 view →
StemShop | CVE Research
@stemshop
#vulnerability en
🚨 CVE-2026-53670 — CVSS 9.3 CRITICAL PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Interpretation Layer. Prior to version 0.2.4, in the Prevail eBPF verifier, EbpfTransformer::add() silently skips offset-variable updates when the destination register carries a non-singleton typeset
0 0 2026-09-02 view →
StemShop | CVE Research
@stemshop
#vulnerability en
🚨 CVE-2026-53649 — CVSS 9.6 CRITICAL Joro is a web exploitation framework. Prior to version 1.1.1, Joro's default proxy mode exposes a local API on 127.0.0.1:9090 that performs no authentication and applies a wildcard CORS policy. Because plugin uploads use the CORS-safelisted multipart/form-dat
0 0 2026-09-02 view →
The Zeek Network Security Monitor
@zeek@infosec.exchange
#networksecurity en
An attacker can hide an exploit in encrypted traffic, but they cannot hide that they had to look around your network first. In a new blog post, Aashish Sharma breaks down the mechanics of scan detection in Zeek. https:// zeek.org/2026/09/how-attackers -learn-your-network-before-they-attack-it/ # Zee
0 1 2026-09-02 view →
OTX Bot
@techbot@social.raytec.co
#botnet en
One leftover build path links an infostealer, a remote-access tool, and a ransomware family A compilation artifact, specifically a developer's home directory path (/home/tcherber/.cargo/), linked multiple malware families including a Rust-based infostealer named Zer0day Stealer, an HVNC remote-contr
0 1 2026-09-02 view →
Random RfC Bot
@randomrfcbot
#networksecurity de
📜 Random RFC: RFC 7402 Using the Encapsulating Security Payload (ESP) Transport Format with the Host Identity Protocol (HIP) 🔗 https://www. rfc-editor.org/info/rfc7402 # RFC # HIP # IPsec # NetworkSecurity
0 0 2026-09-02 view →
AA
@AAKL@infosec.exchange
#botnet en
The Record: Sality, one of the longest-running botnets, finally gets disrupted https:// therecord.media/sality-botnet- cyber-doj @ therecord_media # infosec # botnet # cybercrime
0 1 2026-09-02 view →
Ranova
@Ranovam
#webscraping en
AI Competitor & SEO Intelligence Synthesizes a competitor's SERP, content and social signals with AI into a manager-ready intelligence report: threat level, strengths/weaknesses, content gaps, social momentum, and a prioritized plan of strategic moves. Bring your own data or connect a scrape
0 0 2026-09-02 view →
Daily CyberSecurity
@DailyCyberSecurity@infosec.exchange
#botnet en
Europol and CrowdStrike disrupted the Sality botnet, a 20-year P2P malware network, using a peer-to-peer sinkhole to cut its operator off from infected machines. # Sality # Botnet # Europol # CrowdStrike # Malware https:// securityonline.info/sality-bot net-disruption/?utm_source=mastodon&utm_me
0 1 2026-09-02 view →
Zyte
@ZyteData
#webscraping en
A personal take on Claude Fable 5.1 and GLM-5.3-Flash: real benchmarks, a live extraction test, and the model I guessed before Zhipu confirmed it. https://www. zyte.com/blog/fable-5-1-shippe d-and-glm-5-3-flash-turned-out-to-be-someone-i-already-met/?utm_campaign=blog-posts&utm_activity=ORS&
0 0 2026-09-02 view →
Habr
@habr@zhub.link
#scraping ru
Я не откликаюсь на вакансии. Я пишу людям — и написал программу, которая их находит 24 коллектора, 111 ATS-досок компаний, 345 тестов, ноль API-ключей и ноль ИИ. Windows-exe, который считает совпадение резюме с вакансией и приносит 1–3 живых человека, которым можно написать самому. Внутри — архитект
0 1 2026-09-02 view →
WowHow
@wowhow_blogs
#webscraping en
Web Scraping with Node.js: Puppeteer vs Cheerio (Complete 2026 Guide) Puppeteer controls a real browser. Cheerio parses raw HTML. Knowing when to reach for each tool — and how to combine them — is the difference between a scraper that ... https:// wowhow.cloud/blogs/web-scrapin g
0 0 2026-09-02 view →
OTX Bot
@techbot@social.raytec.co
#botnet en
Sality's P2P Network Turned Against Itself, Cutting Off New Malware Payloads On August 31, 2026, U.S., Bulgarian, Hungarian, and Romanian authorities, collaborating with CrowdStrike and Shadowserver Foundation, successfully disrupted the Sality botnet through a peer-to-peer sinkhole operation. Activ
0 1 2026-09-02 view →
Zyte
@ZyteData
#webscraping en
marimo is a reactive Python notebook that reruns only affected cells. Learn to scrape web data with Zyte API, chart prices, and cache costly API calls. https://www. zyte.com/blog/web-data-in-a-re active-notebook-an-introduction-to-marimo/?utm_campaign=blog-posts&utm_activity=ORS&utm_medium=s
0 0 2026-09-02 view →
Zyte
@ZyteData
#webscraping en
Three in four of the world's top sites publish a robots.txt, yet few name individual crawlers. A look inside the web's advisory layer: coverage, sophistication and limits. https://www. zyte.com/blog/robots-txt-overv iew/?utm_campaign=blog-posts&utm_activity=ORS&utm_medium=social&
0 0 2026-09-02 view →
WWW-CD.ORG Christophe Demay
@wwwcdorg@mamot.fr
#scraping fr
Nitter et XCancel sont mort, et l'explication est dans leur code https:// korben.info/x-bloque-nitter-xc ancel-lecture-tweets.html?utm_source=rss&utm_medium=feed&utm_campaign=flux-principal Le 24 août dernier, X Corp. a envoyé une lettre de mise en demeure au développeur de Nitter et un # ac
0 1 2026-09-02 view →
Byte0x90
@Byte0x90
#botnet de
Globaler Schlag gegen Cyberkriminalität: Internationale Strafverfolgungsbehörden haben die Infrastruktur des berüchtigten Sality-Botnets zerschlagen. Mit Unterstützung von IT-Sicherheitsfirmen gelang eine koordinierte P2P-Sinkhole-Operation, um das dezentrale Schadnetzwerk lahmzulegen. Seit Jahren i
0 0 2026-09-02 view →
Pluralistic: Daily links from Cory Doctorow – No trackers, no ads. Black type, white background. Privacy policy: we don't collect or retain any data at all ever period. [Unofficial]
@pluralistic.net@web.brid.gy
#scraping en
Pluralistic: Unpermissioned research (02 Sep 2026) https:// fed.brid.gy/r/https://pluralis tic.net/2026/09/02/scrape-scrope-scrap/
0 0 2026-09-02 view →
TugaTech 🖥️
@tugatech@masto.pt
#botnet pt
Operação internacional desmantela botnet Sality com mais de 20 anos de atividade. Uma ação conjunta de autoridades policiais e parceiros do setor privado interrompeu a infraestrutura da botnet P2P Sality. 🔗  https:// tugatech.com.pt/t90320-operaca o-internacional-desmantela-botnet-sality-com-ma
0 0 2026-09-02 view →
PPC Land
@ppcland
#networksecurity en
FYI: Scanners posing as ClaudeBot hunt credential files from 824 addresses: Six forged names crossed 795 separate networks in a month, and allowlists keyed on names cannot see them. What replaces the user agent as proof of identity now? https:// ppc.land/scanners-posing-as-cl audebot-hunt-credential
1 0 2026-09-02 view →
AllAboutSecurity
@allaboutsecurity
#botnet de
Sality-Botnetz nach mehr als 20 Jahren durch Sinkhole-Aktion gestoppt Ein Peer-to-Peer-Netzwerk aus infizierten Rechnern, das seit dem Jahr 2003 bestand, ist nicht mehr unter der Kontrolle seines Betreibers. https://www. all-about-security.de/sality-b otnetz-nach-mehr-als-20-jahren-durch-sinkhole-ak
0 0 2026-09-02 view →
Threadlinqs
@threadlinqs
#botnet en
A decades-old botnet just got sinkholed live on stage as CrowdStrike poisoned its own peer list. 9 detections, 11 IOCs. Full analysis + IOCs: https:// intel.threadlinqs.com/threat/T L-2026-2284 # ThreatIntel # Sality # EggJagger # CrowdStrike # Botnet # CryptoTheft
0 0 2026-09-02 view →
Zyte
@ZyteData
#webscraping en
Extract Podcast Ep 11 - AI Agents, Custom Tools and the Future of Web Scraping https://www. youtube.com/watch?v=odB14wahOQ c?utm_campaign=blog-posts&utm_activity=ORS&utm_medium=social&utm_source=mastodon # webscraping # webdata # data # web
0 0 2026-09-01 view →
Bobe'bot on security
@Bobe_bot@mastobot.ping.moi
#networksecurity fr
China's 'Fire Ant' campaign used compromised Cisco routers as stepping stones for deeper network intrusions. Routers are a classic pivot point: they're persistent, often under-monitored, and sit at the edge of trust boundaries. The real question isn't just "which CVE" — it's how long these devices w
0 0 2026-09-01 view →
CyberVeille.ch
@cyberveille@mastobot.ping.moi
#botnet fr
📢 SuperBox et appareils de streaming pirates : vecteurs de réseaux proxy résidentiels et botnets 📰 Source : Ars Technica (Dan Goodin), publié le 31 août 2026. L'article s'appuie sur une recherche publiée par la société de sécurité Plume, focalisée sur le lecteur multimédia SuperBox S7 Pro et son éco
0 0 2026-09-01 view →
Roberto Di Cosmo
@rdicosmo@mstdn.social
#webscraping en
In 2024 the bill for the wasteful web exploded: the software archive I direct buckled under AI crawlers, and our engineers spent their days blocking addresses instead of building. We are not Google. 👉 https://www. dicosmo.org/good-enough/ # GoodEnoughIsNotGoodEnough # WebScraping # SysAdmin # AI
0 13 2026-09-01 view →
Bug404Found
@bug404found@infosec.exchange
#networksecurity en
Watch for periodic beaconing in NetFlow: short, fixed-size flows every 60–300s often mean C2. IDS evasion via fragmentation, encoding, or jitter can hide it, so pivot to flow metadata. Lateral movement: look for SMB/PsExec, RDP, or WinRM from atypical hosts. tshark: -Y 'smb2.cmd==0x05 || smb2.cmd==0
0 1 2026-09-01 view →
Ranova
@Ranovam
#webscraping en
AI Lead Enricher & Personalizer Enriches a lead list, VERIFIES emails, and writes send-ready personalized outreach messages — each grounded in a stated fact, with a send-readiness verdict for every lead. https:// dev.to/ranova/ai-lead-enricher -personalizer-3a5h # buildinpublic # webdev # api #
2 1 2026-09-01 view →
Zyte
@ZyteData
#webscraping en
Want to use traditional browser automation frameworks without infrastructure headaches? Tap our new CDP support to run scripts on Zyte’s powerful infrastructure. https://www. zyte.com/blog/introducing-zyte -cdp-support/?utm_campaign=blog-posts&utm_activity=ORS&utm_medium=social&utm_sourc
0 0 2026-09-01 view →
Analyst207
@Analyst207
#networksecurity en
BGP Hijack Targets Softaculous Traffic, Delivers Malware In a shocking 33-hour heist, a BGP hijack diverted traffic meant for Softaculous, delivering malware to unsuspecting users via a valid TLS certificate issued to the attacker. The clever hack exploited a weakness in internet routing, allowing t
0 0 2026-09-01 view →
Zyte
@ZyteData
#webscraping en
Stop running browsers locally (use ours with CDP) https://www. youtube.com/watch?v=XI1mpXmK1z s?utm_campaign=blog-posts&utm_activity=ORS&utm_medium=social&utm_source=mastodon # webscraping # webdata # data # web
0 0 2026-09-01 view →
The Zeek Network Security Monitor
@zeek@infosec.exchange
#networksecurity en
How do we secure network monitors against emerging AI and quantum threats? Phuong Cao (NCSA) is joining us in Berkeley to share lessons from massive testbeds on bug-hunting with AI Agent Harness and analyzing cryptographic parsers. Save your seat: https:// zeek.org/zeek-workshop-berkele y-2026/ # Ze
0 1 2026-08-31 view →
Byte0x90
@Byte0x90
#networksecurity de
Chinesische APT-Akteure („Fire Ant“) rüsten Cisco-IOS-XR-Router zu Spionage-Plattformen um. Die Angreifer etablierten unbemerkt GRE-Tunnel-Interfaces, manipulierten Befehlsausgaben sowie Syslogs zur Spurenverwischung und fingen TACACS-Zugangsdaten ab. Statt Daten nur weiterzuleiten, werden Core-Rout
0 0 2026-08-31 view →
PPC Land
@ppcland
#networksecurity en
ICYMI: Scanners posing as ClaudeBot hunt credential files from 824 addresses: Six forged names crossed 795 separate networks in a month, and allowlists keyed on names cannot see them. What replaces the user agent as proof of identity now? https:// ppc.land/scanners-posing-as-cl audebot-hunt-credenti
0 0 2026-08-31 view →
Habr
@habr@zhub.link
#ja4 ru
Вы подменили User-Agent, и сервер всё равно знает, что это curl. Он понял это до того, как получил заголовки Разговор, который у меня повторяется примерно раз в квартал. Интеграция ходит к партнёрскому API, партнёр её режет. Разработчик ставит в запрос User-Agent от Chrome. Не помогает. Дальше идут
0 0 2026-08-31 view →
N-gated Hacker News
@ngate
#scraping en
🐛🤖 Konstantin's latest tizzy is about # AI crawlers hogging # CPU cycles like # digital # parasites , draining resources faster than a toddler in a candy store. 🙄 Apparently, it's a groundbreaking revelation that # scraping # data uses servers... next, he'll tell us water is wet. 💧 Who k
1 0 2026-08-30 view →
Some Bits: Nelson's Linkblog
@somebitslinks@tech.lgbt
#scraping en
AI scrapers versus Linux: Hard data on how bad AI scraping is from someone who runs the Linux kernel source repository. 98% of requests are bot junk, many coming from a botnet. https:// people.kernel.org/monsieuricon /creepy-crawlies # scraping # botnet # llm # ai #-
2 2 2026-08-30 view →
PPC Land
@ppcland
#networksecurity en
Scanners posing as ClaudeBot hunt credential files from 824 addresses: Six forged names crossed 795 separate networks in a month, and allowlists keyed on names cannot see them. What replaces the user agent as proof of identity now? https:// ppc.land/scanners-posing-as-cl audebot-hunt-credential-file
0 0 2026-08-30 view →
Jörn Franke
@jornfranke@social.anoxinon.de
#scraping en
published scrapy-contrib-bigexporter 1.2.0 export scraped data using Scrapy into big data formats, such as Iceberg, Parquet, Orc, Avro Changelog: https:// codeberg.org/ZuInnoTe/scrapy-c ontrib-bigexporters/src/branch/main/CHANGELOG.md # python # scrapy # parquet # iceberg # scraping # web
0 1 2026-08-29 view →
CyberVeille.ch
@cyberveille@mastobot.ping.moi
#scraping fr
📢 Suisse : scraping massif de données de propriétaires de véhicules via eAutoIndex 🔍 Nature de l'incident : À la mi-août 2026, des données publiques relatives aux propriétaires de véhicules ont été récupérées de manière automatisée via la plateforme eAutoIndex. L'attaquant a contourné les mécanismes
0 0 2026-08-29 view →
PPC Land
@ppcland
#scraping en
FYI: SerpApi asks judge to end Google's scraping case over three unseen contracts: Google dropped its Shopping and Maps theories on August 10, narrowing what search-data vendors face. A September 29 hearing decides whether any claim survives. https:// ppc.land/serpapi-asks-judge-to -end-googles-
0 0 2026-08-28 view →
Arint - SEO+KI
@Arint@arint.info
#scraping de
RT @natzir9: [Hack] Googles neue /goto-URLs sind verschlüsselt, um das Scraping zu verhindern. Stelle deinen Browser auf eine andere Sprache als die Ergebnisse und der Link "Diese Seite übersetzen" erscheint mit der sauberen URL. Verwende Latein und du bekommst es 99,99% der Zeit :D Scraper: drehe d
0 0 2026-08-28 view →
Alexander S. Kunz
@alexskunz@mas.to
#scraping en
If you have a website or are a # webmaster then ASN 48090 "TECHOFF SRV LIMITED" might be worth blocking... just saying... 🥴 What a world... EDIT: IP blocks are 45.148.10.0/24 93.123.109.0/24 195.178.110.0/24 # Firewall # Scraping # Cloudflare
5 2 2026-08-27 view →
dch :flantifa: :flan_hacker:
@dch@bsd.network
#ja4 en
# HAProxy vs The LLM Bot army Because it’s holidays I am off thinking of crazy hacking ideas.. What about combining # JA4 + TLS fingerprinting with HAProxy to try to drop residential bot swarms? https:// github.com/FoxIO-LLC/ja4 The idea is that a bot lies about its identity - the TLS library and th
2 9 2026-08-08 view →
Habr
@habr@zhub.link
#ja4 ru
По обе стороны антибота: как я имитирую Chrome при скрейпинге и ловлю ботов по тем же сигналам Я собираю афишу города в одну карту из пяти источников. Два из них — Яндекс.Афиша и afisha.ru — собирать себя не хотят. И режут не так, как ждешь: ни логина, ни капчи на входе, ни «подтвердите, что вы не р
0 0 2026-07-27 view →
Habr
@habr@zhub.link
#ja4 ru
IP, браузер, TLS: три слоя, на которых палится парсер С чего все началось Хотел простую вещь: отслеживать цену на пару товаров, которые ждал со скидкой. Чтобы не заходить руками каждый день, а получить уведомление, когда подешевело. Думал, это вечер работы. requests.get() , выдрать цену, сравнить, о
0 0 2026-07-01 view →
Habr 25+
@habr25@zhub.link
#ja4 ru
Заморозка по fingerprint: как ТСПУ в июне 2026 ломает соединения по поведению, а не по протоколу Полгода назад я написал здесь разбор «почему VLESS работает» — он собрал 169 тысяч просмотров и под тысячу закладок. Я тогда уверенно заявил: REALITY не отличить от обычного HTTPS, поэтому он держится та
0 0 2026-06-15 view →
Habr
@habr@zhub.link
#ja4 ru
Заморозка по fingerprint: как ТСПУ в июне 2026 ломает соединения по поведению, а не по протоколу Полгода назад я написал здесь разбор «почему VLESS работает» — он собрал 169 тысяч просмотров и под тысячу закладок. Я тогда уверенно заявил: REALITY не отличить от обычного HTTPS, поэтому он держится та
0 0 2026-06-15 view →
Aleksei Aleinikov
@aleksei_aleinikov
#tlsfingerprinting en
"TLS Fingerprinting: the hidden profile of your browser 🚀🔥 Every secure connection reveals more about you than just encryption # security # tlsfingerprinting " https:// medium.datadriveninvestor.com/ what-tls-fingerprinting-is-in-2026-and-why-it-matters-9220e25f2c33
0 0 2026-05-10 view →
Alexandre Dulaunoy
@adulau@infosec.exchange
#ja4 en
I’m still completely lost with logic of JA4+ patent licensing and actual incompatibility with the copyleft-license. So it seems to be a patent-based license and really risky to implement if you want to keep your actual software open source. Did someone explore alternatives to avoid this? and especia
8 6 2026-05-07 view →
Online NBA
@olnba@jforo.com
#ja4 en
https://www. olnba.com/883787/ NIKE Ja4|Ja Morant /ジャ・モラント写真公開!スペック予想&5カラーまとめ # バッシュ # nba # shorts # BasketballShoes # JaMorant # Ja4 # NationalBasketballAssociation # NBA # NBAVideos # NBAバッシュ # NikeBasketball # NIKEJa4 # NikeJa4 # Nikeバッシュ # Shorts # ZoomX # シグネチャーシューズ # ジャモラント # スニーカー # ドロップインミッ
0 0 2026-04-26 view →
Infoblox Threat Intel
@InfobloxThreatIntel@infosec.exchange
#ja4 en
We planned one report on Keitaro abuse, but we ran out of pages before we ran out of cases. So here’s Part 2 of 3, a medley of threats that go well beyond AI‑investment scams. Threat actors abuse Keitaro’s traffic distribution, cloaking, and rule engine to hide malicious landing pages behind geo and
1 1 2026-03-26 view →
Habr 25+
@habr25@zhub.link
#ja4 ru
Анатомия DPI анализа: что происходит с твоим пакетом за первые 16 КБ Пошаговый разбор того, как ТСПУ анализирует трафик — от первого SYN до поведенческого ML. С конкретными числами, реальными алгоритмами и объяснением почему одни протоколы умирают на первом байте, а другие живут месяцами Большинство
0 1 2026-03-14 view →