An investigation by Channel 12 found that about half of politically active Israeli social media accounts are bots, with many amplifying posts by PM Benjamin Netanyahu and other members of his coalition.
These bot networks rapidly like and repost pro-Israel content moments after posting to hijack platform algorithms and give the impression of a bigger reach.
These bot networks rapidly like and repost pro-Israel content moments after posting to hijack platform algorithms and give the impression of a bigger reach.
Black Cat is running an SEO poisoning campaign that ranks fake software sites in search results.
The group impersonates tools like Notepad++, tricking users into installing trojanized installers that drop a backdoor stealing browser data, keystrokes, clipboard contents, and enabling remote access.
The group impersonates tools like Notepad++, tricking users into installing trojanized installers that drop a backdoor stealing browser data, keystrokes, clipboard contents, and enabling remote access.
Researchers disclosed multiple critical flaws in Coolify that let authenticated users run commands as root, enabling full server compromise.
The issues span 11 CVEs rated up to 10.0 and impact 52,890 internet-exposed hosts.
The issues span 11 CVEs rated up to 10.0 and impact 52,890 internet-exposed hosts.
Ransomware has moved past simple extortion.
Stolen data is now auctioned when ransoms fail, turning breaches into repeat revenue. Data auctions expand profits, attract more actors, and scale attacks faster.
Stolen data is now auctioned when ransoms fail, turning breaches into repeat revenue. Data auctions expand profits, attract more actors, and scale attacks faster.
Warning - Yet another n8n vulnerability.
n8n disclosed a CVSS 10.0 RCE flaw allowing authenticated users to execute untrusted code and fully compromise an instance.
CVE-2026-21877 affects cloud and self-hosted deployments running versions ≥0.123.0 and <1.121.3.
n8n disclosed a CVSS 10.0 RCE flaw allowing authenticated users to execute untrusted code and fully compromise an instance.
CVE-2026-21877 affects cloud and self-hosted deployments running versions ≥0.123.0 and <1.121.3.
Forwarded from 𝐺𝑟𝑎𝑦 𝐻𝑎𝑡𝑠
Mehrdad Rahimi's Secure Phone Contact List
Mehrdad Rahimi, the leading officer of the Mossad actors inside IRAN, has used intelligence techniques, has coded all his agents and assigned a separate name for each of them, now you can see this list, more than 600 Iranian Leaders who are responsible for killing projects in IRAN, are now available for anyone to see. All the elements of the anarchists know, for months, from the origin, they've been in our intelligence trap.
https://filebin.net/zpscsip54ub013rr
#Handala
Mehrdad Rahimi, the leading officer of the Mossad actors inside IRAN, has used intelligence techniques, has coded all his agents and assigned a separate name for each of them, now you can see this list, more than 600 Iranian Leaders who are responsible for killing projects in IRAN, are now available for anyone to see. All the elements of the anarchists know, for months, from the origin, they've been in our intelligence trap.
https://filebin.net/zpscsip54ub013rr
#Handala
Forwarded from 𝐺𝑟𝑎𝑦 𝐻𝑎𝑡𝑠
Thousands of #Israeli phones received a message that read:
"We are coming, look to the sky in the middle of the night."
"We are coming, look to the sky in the middle of the night."
Bluetooth headphones built on Airoha chips have flaws that let attackers connect without pairing and control device functions over the air.
The issue sits in the RACE protocol and requires vendor firmware updates to fix.
The issue sits in the RACE protocol and requires vendor firmware updates to fix.
Veeam fixed a critical Backup & Replication flaw enabling remote code execution as the postgres user.
CVE-2025-59470 can be abused by authenticated Backup or Tape Operators via crafted parameters.
The update also fixes two additional RCE flaws and a root-level file write issue.
CVE-2025-59470 can be abused by authenticated Backup or Tape Operators via crafted parameters.
The update also fixes two additional RCE flaws and a root-level file write issue.
AdonisJS users are being advised to patch a critical flaw in adonisjs/bodyparser.
CVE-2026-21440 (CVSS 9.2) allows arbitrary file writes via path traversal when upload filenames aren’t explicitly sanitized.
CVE-2026-21440 (CVSS 9.2) allows arbitrary file writes via path traversal when upload filenames aren’t explicitly sanitized.
Popular workflow automation platform n8n disclosed a critical flaw that lets authenticated users with workflow edit rights execute OS commands on the host.
Tracked as CVE-2025-68668, the issue carries a CVSS score of 9.9.
Tracked as CVE-2025-68668, the issue carries a CVSS score of 9.9.
Chinese-speaking attackers hijacked a SonicWall VPN to escape VMware ESXi guest VMs.
Huntress stopped it before ransomware, but the chain abused 3 VMware zero-days now on CISA’s KEV list.
Huntress stopped it before ransomware, but the chain abused 3 VMware zero-days now on CISA’s KEV list.
CISA closed 10 Emergency Directives issued between 2019–2024.
The required security actions for risks such as SolarWinds, Microsoft Exchange, and VMware were completed or are now enforced under Binding Operational Directive 22-01.
The required security actions for risks such as SolarWinds, Microsoft Exchange, and VMware were completed or are now enforced under Binding Operational Directive 22-01.
Handala hackers post Mossad 'secure phone' footage syncing Iran rioters with USA cell numbers.
Iranians have succeeded in disrupting Musk’s Starlink internet technology.
Hacker leaks 200,000 user + employee records from Israeli hosting provider Infocenters Ltd
Target: Infocenters Ltd (Hosting, Cloud Services, Data Centers, IT Solutions)
Leaked data includes:
1. Individual Demographic Data
Full names (Hebrew + English)
Previous family names
CodeAlias names used
Place of birth (Israel/Lithuania)
Year of birth (1928–1943)
Current age (2024-based)
2. Contact & Identification Data
Email addresses (http://gov.il, http://ac.il, http://net.il, gmail, etc.)
Physical addresses
Phone numbers
City & postal codes
3. Historical Data
WWII-era records
Target: Infocenters Ltd (Hosting, Cloud Services, Data Centers, IT Solutions)
Leaked data includes:
1. Individual Demographic Data
Full names (Hebrew + English)
Previous family names
CodeAlias names used
Place of birth (Israel/Lithuania)
Year of birth (1928–1943)
Current age (2024-based)
2. Contact & Identification Data
Email addresses (http://gov.il, http://ac.il, http://net.il, gmail, etc.)
Physical addresses
Phone numbers
City & postal codes
3. Historical Data
WWII-era records
Europol says Spanish police arrested 34 suspects linked to Black Axe, a Nigeria-origin crime syndicate.
The 🕵️♂️ group is tied to cyber fraud, trafficking, and violent crime worldwide. Investigators estimate €5.93M in fraud losses, with cash and bank funds seized in Spain.
The 🕵️♂️ group is tied to cyber fraud, trafficking, and violent crime worldwide. Investigators estimate €5.93M in fraud losses, with cash and bank funds seized in Spain.
Trend Micro patched a critical flaw in on-prem Apex Central for Windows that can lead to SYSTEM-level code execution.
CVE-2025-69258 (CVSS 9.8) allows a remote, unauthenticated attacker with endpoint access to load a malicious DLL via MsgReceiver.exe.
On-prem builds below 7190 are affected.
CVE-2025-69258 (CVSS 9.8) allows a remote, unauthenticated attacker with endpoint access to load a malicious DLL via MsgReceiver.exe.
On-prem builds below 7190 are affected.
Russian state-linked APT28 targeted Turkish energy and nuclear staff, a European think tank, and organizations in North Macedonia and Uzbekistan.
Fake Microsoft, Google, and VPN login pages harvested credentials, then redirected victims to real sites to stay hidden.
Fake Microsoft, Google, and VPN login pages harvested credentials, then redirected victims to real sites to stay hidden.