We released first detection rules for Copy Fail / CVE-2026-31431.
YARA rules by me:
https://t.co/PrkIOIihA6
It covers public PoC artifacts, including known payloads, exploit code fragments and URLs seen in shared material.
More generic rules for customer environments are still in testing.
Sigma rules by @_swachchhanda_:
https://t.co/UTZgDhtsqg
They cover suspicious Copy Fail-related exploitation patterns, including setuid binary execution behavior and NULL argv shell execution.
More updates soon.
La fiabilidad de este exploit es increíble. Y ni siquiera toca disco. Sin condiciones de carrera o desbordamiento. Problemas de lógica (introducidos por partes de 2011 a 2017) en el kernel permiten elevar privilegios. Ninguna distro está a salvo. Ni el kernel de Windows en WSL.
MongoBleed (CVE-2025-14847) is basically Heartbleed for MongoDB
- unauthenticated memory disclosure
- public POC, trivial to exploit
- leaks creds, tokens, cloud keys straight from RAM
- huge exposed surface on the internet
Good writeups and technical details here:
https://t.co/LgK4RABmJu
https://t.co/DWtByJQ3au
https://t.co/LUwfnF6uXG
Patch fast, rotate secrets, and assume exposed instances were scanned(!)
Lockbit ransomware group has been compromised. Their backend panel was dumped.
You can see my build logs in the data dump.
Lockbit gave me access after I sent him a bunch of cat pictures.
Herramientas de espionaje usadas en ataque de Ransomware.
Los atacantes desplegaron el ransomware RA World utilizando métodos atribuidos al grupo Mustang Panda, especializado en el espionaje de organizaciones no gubernamentales.
https://t.co/qKiZ25Y7CS
Ghidra 11.3 is OUT!
PyGhidra is the new feature to be excited about.
It’s a Python library providing direct access to the Ghidra API.
I expect this to massively increase Reverse Engineering tool development, as it significantly reduces the barrier to entry.
The world’s most breathtaking abandoned sites: From Pakistan’s Bibi Jawindi to Italy’s Palazzo Athena | Fotos | Travel | EL PAÍS English https://t.co/rMy9RcSyZL
Análisis de Lynx ransomware. El grupo destaca por la profesionalización de sus operaciones, desde su proceso de reclutamiento a sus métodos de cifrado y extorsión
https://t.co/ea71IN5zG7
We are aware that our X account @FalconFeedsio has been compromised despite having 2FA enabled. We are actively investigating the incident and apologize for any inconvenience caused. Please note that recent crypto-related posts are scams, and we are in no way associated with us.
We are working to regain access and will provide updates as soon as we have more information. Thank you for your support and patience during this time.
@vxunderground@DarkWebInformer@X@XCorpIndia@Support
Campaña masiva contra Microsoft 365. Detectado un gran volumen de ataques de fuerza bruta para robar credenciales de Microsoft utilizando la librería FastHTTP.
https://t.co/pK9rLPpYEl
Rsync expone miles de servidores. Seis vulnerabilidades, una de ellas crítica, afectan a la popular herramienta de sincronización de archivos.
https://t.co/oGM9an4stD
Evolución de Banshee Stealer. El malware para macOS se actualiza dificultando su detección con el cifrado de XProtect y ampliando los países objetivo
https://t.co/R3uvvo2I4s