Forwarded from ᴛʜᴇ ɢʜᴏꜱᴛ ɪɴ ᴛʜᴇ ᴍᴀᴄʜɪɴᴇ
Curating a GitHub repository of security toolkits while filtering emerging threats and vulnerability disclosures from 4 key intelligence channels.
Toolkits
Toolkits
News
Quotes
#CyberSecurity #InfoSec #ThreatIntelligence #GitHub
Toolkits
Toolkits
News
Quotes
#CyberSecurity #InfoSec #ThreatIntelligence #GitHub
Attackers are chaining two critical MikroTik RouterOS bugs to take full control of any router with SSH exposed to the internet. Polish CERT has confirmed exploitation since at least 2 September.
Saudi Arabia - 𝗞𝗵𝗮𝗹𝗲𝗱 𝗔𝗹𝗳𝗮𝗴𝗶𝗵 𝗘𝗻𝗴𝗶𝗻𝗲𝗲𝗿𝗶𝗻𝗴 𝗖𝗼𝗻𝘀𝘂𝗹𝘁𝗮𝗻𝗰𝘆 𝗖𝗼.
Panzer hacking group claims to have breached Khaled Alfagih Engineering Consultancy Co. and allegedly exfiltrated 22 GB of data. According to the exposed file listing, the dataset appears to include corporate and financial documents, project contracts, engineering files, certifications and other internal business records.
Panzer hacking group claims to have breached Khaled Alfagih Engineering Consultancy Co. and allegedly exfiltrated 22 GB of data. According to the exposed file listing, the dataset appears to include corporate and financial documents, project contracts, engineering files, certifications and other internal business records.
Preemptive Cyber Strike Targets Egyptian Port Authority and "Future of Egypt" Entity
A hacker group has claimed a major cyber breach of Egypt's port authority technical infrastructure, describing the operation as a "preemptive security strike" that "shook the regime's foundations."
The hackers stated they obtained a massive cache of sensitive data, including ship registrations, movement logs, and yacht authorizations. The group specifically named the "Future of Egypt Authority" (Mustaqbal Misr) and the "Armed Forces Land Projects Agency" as the entities responsible for authorizing yacht movements—pointing to a deliberate focus on military-linked economic bodies.
According to the group's statement, the stolen data includes visitor lists to Egyptian islands with names and nationalities, administrative documents, and footage from hacked security cameras inside offices.
The Future of Egypt Authority is a powerful military-affiliated economic entity that has rapidly expanded control over agriculture, land management, and food imports since its transformation by presidential decree in 2022. The hackers framed this operation as exposing corruption within the Egyptian regime.
The group concluded with a warning: "No one should test Egypt"—a nationalist narrative framing the breach as both a revelation and a threat.
A hacker group has claimed a major cyber breach of Egypt's port authority technical infrastructure, describing the operation as a "preemptive security strike" that "shook the regime's foundations."
The hackers stated they obtained a massive cache of sensitive data, including ship registrations, movement logs, and yacht authorizations. The group specifically named the "Future of Egypt Authority" (Mustaqbal Misr) and the "Armed Forces Land Projects Agency" as the entities responsible for authorizing yacht movements—pointing to a deliberate focus on military-linked economic bodies.
According to the group's statement, the stolen data includes visitor lists to Egyptian islands with names and nationalities, administrative documents, and footage from hacked security cameras inside offices.
The Future of Egypt Authority is a powerful military-affiliated economic entity that has rapidly expanded control over agriculture, land management, and food imports since its transformation by presidential decree in 2022. The hackers framed this operation as exposing corruption within the Egyptian regime.
The group concluded with a warning: "No one should test Egypt"—a nationalist narrative framing the breach as both a revelation and a threat.
Adobe patches a Magento zero-day already exploited to deploy malware.
CVE-2026-75650 abuses Magento template processing for unauthenticated code execution. Attacks have delivered a Rust #Linux backdoor and PHP web shell.
CVE-2026-75650 abuses Magento template processing for unauthenticated code execution. Attacks have delivered a Rust #Linux backdoor and PHP web shell.
Grindr will pay £26 million to settle U.K. claims that it shared users’ personal data, including HIV status, with third parties.
The case covers pre-2020 practices and includes no finding or admission of liability.
The case covers pre-2020 practices and includes no finding or admission of liability.
N-central’s 4th hotfix in five weeks fixes CVE-2026-86218, a CVSS 10.0 unauthenticated RCE flaw.
Hotfix 3 servers need updating. N-able’s incident notice reports exploitation; its release notes say it’s unconfirmed.
Hotfix 3 servers need updating. N-able’s incident notice reports exploitation; its release notes say it’s unconfirmed.
JSCeal V8 malware can bypass Google authentication using stolen browser cookies.
It can also modify Binance, Bybit, and Ledger traffic through a local proxy.
It can also modify Binance, Bybit, and Ledger traffic through a local proxy.
Security researchers have demonstrated a new electromagnetic attack that can recover audio playing through ordinary wired and wireless headphones, with intelligible speech captured from as far as 30 meters away.
The technique, called InjectEave, can also operate through walls and expose information from smart-home devices and landline phones.
The research was conducted by researchers from the Hong Kong University of Science and Technology (Guangzhou) and Hong Kong Polytechnic University.
The technique, called InjectEave, can also operate through walls and expose information from smart-home devices and landline phones.
The research was conducted by researchers from the Hong Kong University of Science and Technology (Guangzhou) and Hong Kong Polytechnic University.
Hackers have drained roughly $320 million in Bitcoin from the federation wallet backing the Liquid Network, while claiming to be the good guys.
The wallet held about 4,200 BTC before the incident, meaning whoever was behind the exploit removed roughly 95 percent of its holdings.
Liquid disabled its bridge nodes while federation members investigate and asked exchanges to suspend L-BTC deposits and withdrawals.
The wallet held about 4,200 BTC before the incident, meaning whoever was behind the exploit removed roughly 95 percent of its holdings.
Liquid disabled its bridge nodes while federation members investigate and asked exchanges to suspend L-BTC deposits and withdrawals.
ShinyHunters confirmed to BNR the suspect in the audio clip is a member of their group. “Our team member has our full support—emotionally, mentally, and financially,” the hackers said. “Everything has been arranged, including a criminal defense lawyer. We do not look down on our staff and members; we take excellent care of them.”
Microsoft's patch for Windows Defender zero-day ShieldBreak (CVE-2026-69414) is still bypassable, a new PoC called ShieldCrash was published today by researcher Nightmare-Eclipse. It demonstrates arbitrary file read as SYSTEM on all supported Windows versions running the September 2026 patches.
A group that came together through online gaming platforms stole more than $245 million in cryptocurrency. Its ringleader, a 22-year-old Singaporean living in Miami named Malone Lam, pleaded guilty in Washington.
120 MILLION TELEGRAM USER RECORDS ALLEGEDLY LEAKED
The listing claims the dataset contains fields including:
* Phone numbers and country codes
* First and last names
* Telegram usernames and nicknames
* User IDs
* Email addresses where available
* Country information
* Source metadata
The listing claims the dataset contains fields including:
* Phone numbers and country codes
* First and last names
* Telegram usernames and nicknames
* User IDs
* Email addresses where available
* Country information
* Source metadata
'Do NOT underestimate the power of this tech' — AI researcher Jacob Coxon loudly RESIGNS from Anthropic.
'Could kill us by end of decade. This is not a marketing STUNT'.
'Could kill us by end of decade. This is not a marketing STUNT'.
German Police Access Encrypted Chats
German police intercept WhatsApp, Telegram, and Signal communications by linking Web or Desktop clients to investigated accounts to bypass end-to-end encryption without installing spyware, a technique that raises legal controversies over access to unauthorized historical messages.
German police intercept WhatsApp, Telegram, and Signal communications by linking Web or Desktop clients to investigated accounts to bypass end-to-end encryption without installing spyware, a technique that raises legal controversies over access to unauthorized historical messages.
Apple Now Sends Direct iPhone Alerts for Mercenary Spyware Attacks
Apple has expanded its Threat Notification system to warn users directly on their iPhones when it detects that they may have been individually targeted by sophisticated mercenary spyware.
Apple has expanded its Threat Notification system to warn users directly on their iPhones when it detects that they may have been individually targeted by sophisticated mercenary spyware.