Exclusive: Fast16 malware has raised questions about what it was designed to do. Researchers at @symantec finally confirm that it was subverting software used to simulate nuclear weapons explosions. Nuclear experts tell me Iran was the likely target https://t.co/oZf609ESSL
🚨 Critical Linux Kernel Vulnerability Alert
Qualys has disclosed ssh-keysign-pwn: a 6-year race condition in __ptrace_may_access() that lets unprivileged local users read root-owned files.
A privileged process (e.g. ssh-keysign or chage) opens sensitive FDs. During do_exit(), after exit_mm() (mm=NULL) but before exit_files(), pidfd_getfd() can steal those FDs.
Impact: • Theft of host SSH private keys → real impersonation & MitM risk until keys are rotated • Full read access to /etc/shadow → offline password cracking
Affected: All kernels before 31e62c2ebbfd (May 14, 2026) — Ubuntu, Debian, Arch, CentOS, Raspberry Pi OS and more.
Immediate action required: Apply the kernel patch NOW.
🔗 PoC: https://t.co/UZJyKb6Szj 🔗 Patch: https://t.co/rNU2YB4mVv…/31e62c2ebbfd 🔗 Full analysis: Phoronix & Qualys oss-security
#LinuxSecurity #KernelVulnerability #CyberSecurity #InfoSec #OpenSSH #PrivilegeEscalation #ThreatIntelligence #Linux #CyberThreat #PatchNow
We published a "Shadowserver-in-a-box" platform based on IntelMQ + ELK that can ingest, process and visualize our threat/vulnerability/victim data feeds. Available as a VM or Docker image for free download. Use it for training or in production!
https://t.co/nBPIbUqXGV
One of the Russian GPS spoofers around St Petersburg sports what looks like an aim function.
There is a realistic possibility this has been used to drive Ukrainian attack drones into NATO territory.
So far, I only have two anecdotes to show for it, data collection ongoing.
🧵
Google Threat Intelligence Group is dropping our latest AI Threat Tracker report today, which covers several threats we are watching through a variety of means. The report includes some details of the first 0day exploit we've found developed with AI. 1/x https://t.co/klvOrX31xv
Another great example of AI-driven vuln research finding high-impact bugs in a heavily audited open-source project.
Where human analysts give up or move on to a more interesting attack surface, AI keeps going until the end. Context, prompts, and skills still matter, but it’s not a magic box you ask “find me a 0-day.”
VR was always artisanal. Not just running tools in sequence, but deep understanding of the problem space, historical knowledge of prior findings, and intuition for where bugs persist. Malware analysis got commoditized years ago with sandbox automation. VR resisted.
Now AI has outpaced human analysts in throughput. Still needs guidance and direction, but it’s a completely new era. Some people I know still dismiss the progress, but hard to argue with results.
Howdy folks! Taking a break from my twitter break to let yall know that we released a new @GreyNoiseIO product yesterday. It's called Project Swarm. We've been quietly not-so-quietly working on it for a few years. You can buy it now. It costs $1.
There are lots of vulnerabilities on edge-facing apps. To catch in-the-wild exploitation of them, we @ GreyNoise run sensors on the internet. New AI models means more vulnerabilities being identified and exploited, and FASTER. Long term, software and hardware will probably get better, but in the meantime we're gonna have to deal with A LOT of vulnerabilities.
At GreyNoise, the sensors we run are basically honeypots- we bait attackers to scan and exploit them which enables us to learn where the attackers are, which vulnerabilities they are exploiting, what it drops, and what it looks like on the wire. From ~2020-now it took us years to build up our fleet. Now anyone can use our new product to deploy their own sensors on their own networks, or an entire fleet of any size, in a day. You can rip back the data and do whatever you want with it. You can resell it, put it into your product, or just stare at it- whatever you want! On our side, we aggregate the data and pour it into a community dataset that everyone shares. As more people join, the data gets bigger and better.
Couple neat features:
- Sensor deployment is a single bash command on any modern linux distro that supports iptables and wireguard.
- Sensors and vulnerable software (profiles) are abstracted into different logical concepts, which means the "what" and "where" are different things, and the sensor is not constrained by the compute required to run the vulnerable software. Also, no matter how hacked the profile (honeypot) gets, it can't touch your host sensor or the rest of your network.
- Sensors can run fake honeypots, real software, or even real hardware (bridged with a raspberry pi) like old crappy routers and modems (or expensive firewalls and VPN gateways 👀)
- You can create dynamic blocklists that block IPs sourced from your own sensors in real time, so if a remote IP address *looks at your network* the wrong way, you block them instantly.
- All the PCAP data is available to you in a gorgeous and intuitive interface at near real time and fully enriched against all of our (thousands of) rules. We're working on the host metadata (malware, syscalls, host behaviors) as well, but this will come later.
- If we don't tag a CVE that's interesting to you, you can write a Suricata rule to tag it yourself once and your data gets tagged with it in real time forever.
- You can instantly download PCAPs of any exploits that hit your sensors.
- If you don't want your data shared with the community dataset, you can talk to our team and we'll work out rights to make it private.
Check it out! There's a lot of moving pieces to make this work and we expect bugs, but it's available right now. Join the fight!
https://t.co/erAWtX1l7B
We investigated a CN #APT that targeted multiple governments and companies with government contracts in Asia. In half of the targets we found a second group with different malware toolkit but sharing the infection vector and some post-exploitation tools https://t.co/IN12VBv5k4
New research drop 🚨
We're diving deep into Chinese-language phishing-as-a-service ecosystems powering large-scale global campaigns. From infrastructure to operations, this series uncovers how these platforms scale and evade detection. Starting May 4th:
https://t.co/mJfli7zYHI
I spent some time this week digging into Kaspersky's report on Lotus Wiper & its likely connection to the December attack on the Venezuelan oil company PDVSA. In this post, I explain my findings & speculate about U.S. involvement & potential implications
https://t.co/Y9gTi1ehEk
Yesterday, the DOJ made a press release confirming a coordinated crackdown against a massive Southeast Asian scam compound
Two Chinese nationals ran a forced-labor fraud factory in Myanmar called the Shunda compound. Trafficked workers, beaten and held against their will, were forced to run cryptocurrency investment and romance scams targeting Americans. One worker's team stole 3 million dollars from a single victim. When a militia seized the compound in late 2025, the FBI flew to Thailand, reviewed over 1,300 desktop computers and thousands of phones, and interviewed former workers. They tracked the two managers to Cambodia, where they tried to keep operating, then arrested them in Thailand on immigration charges. They are now facing federal wire fraud conspiracy charges in the US.
Separately, the Feds seized a Telegram channel with around 6,000 members that was recruiting English speakers with American accents for fake jobs in Cambodia. Once there, workers were held against their will and forced to impersonate JPMorgan Chase, customer service reps, and NYPD detectives over WhatsApp and Microsoft Teams, telling victims their bank accounts were used to buy illegal firearms, then draining their savings.
The Strike Force also seized 503 fake crypto investment websites in a single operation, seized over 700 million dollars in cryptocurrency tied to money laundering, and sanctioned Cambodian officials linked to scam center operations.
🚨 TURQUIE DEVIENT LE NOUVEAU PARADIS FISCAL : 20 ANS D’EXONÉRATION POUR LES ÉTRANGERS !
Erdoğan vient de dégainer une bombe attractive : les étrangers qui n’ont pas été résidents fiscaux en Turquie ces 3 dernières années pourront s’installer et ne payer aucun impôt sur leurs revenus et plus-values provenant de l’étranger pendant 20 ans. Seuls les revenus générés en Turquie seront imposés.
Objectif clair : piquer une grosse part de la clientèle dorée de Dubaï et attirer les talents européens qui fuient la sur-réglementation et la fiscalité étouffante. Des posts viraux sur X parlent déjà d’un « Sovereign Individual thesis » en action et d’un coup de maître pour capter les capitaux fuyant le Moyen-Orient instable.
⚡️Les bonus qui font mal à la concurrence :
• Succession : impôt réduit à seulement 1 % sur les transferts de biens.
• Rapatriement d’actifs (argent, or, titres) pour les Turcs et entreprises avec imposition ultra-réduite.
• Cadre plus large : baisses de taxes pour les exportateurs (jusqu’à 9 % pour les fabricants) et avantages pour les sièges régionaux de multinationales.
Pendant que l’Europe et l’Occident alourdissent les charges, la Turquie ouvre grand les portes avec ce package « Türkiye Century Strong Center for Investment ». Istanbul pourrait bien devenir le nouveau hub fiscal que tout le monde regarde.
Qui va sauter sur l’occasion ? Les digital nomads, entrepreneurs et HNWI fuient déjà vers des cieux plus cléments… et Ankara leur déroule le tapis rouge. 🇹🇷💰
⭐️ Abonnez-vous à @Camille_Moscow
We are hiring for vulnerability research in Singapore!!
Ping me on DM if you wanna apply (or your application will get auto rejected because idk why).
I'm also in Singapore this week if you wanna chat about the role!!
hostednowhere[.]com : A groundbreaking platform that encodes an entire website into a single URL (specifically the fragment part after #).
github:
https://t.co/MN2HS6yXC8
Like:
https://nowhr[.]xyz/s#PZJhb9owEIaVf-JkXyExMNq1GkhQykrFKA1t2SZEnTlHYpHEqW0IFNTfvnNb9sXv3evn7mzZcfNlMpwP5uV69dSb5-GffbgdtXSzvhs9izCaNtMbHg8eX581JEmNufcXzL1WR7c1djzmjkPWmzD0rhXrbZeu7ElFmNt7dHwr9bfBcR3FwKEwKspqZFNgqKWCmLz1nQDhpRyyH-dOjbCzKzDcv1xkepuQXZ4VuuOlxpSXQVBVlV-1fKmSoEkpDZDwyFZA1Ze7jkcJJQ3S8LqLjAvFMyAcXb_tEb7_UPUhx80vp-N9-dqg9Bv3AuQN7Az5hD_Z2GqrDTnyfe7Uj7KNRey24XhkeWucOutP0chlIXUZcTi5vym655SecjPA3D9r_h97Ea9WuN0dPiyywLbG-fYm3e9Ph_Hhhh5E43A3kVUKChaLsi8Ml6LAaCyS1BSiSDC-inS6QZ1IbRTqz0jl0lg8k1rLHKMHaTdG0-EMZQZ8o4DM-MaYDP7iahvKMLK1oFMTaSO4BQuI1qAKsMBUiW3E93be-3PpVJQkBC20geLdvzN4THL6Ds4_
🇨🇳 Massive China Housing Fund Data Leak Claim Surfaces
A threat actor has shared a dataset allegedly linked to China’s Housing Provident Fund (住房公积金), a government-backed housing benefit system.
The data reportedly includes information on over 25 million individuals, with claims that the full dataset may reach nearly 77 million records.
Exposed data appears to include:
Full names
National ID numbers
Phone numbers
Employer/company details
While the dataset structure appears consistent with real records, the exact source and breach method remain unclear, and even the actor notes limited ability to verify the origin.
⚠️ Status: Unverified — high impact, moderate confidence
#CyberSecurity #DataLeak #ThreatIntel #DarkWeb