๐จ Hackers Exploit Microsoft Teams' Collaboration Features to Impersonate IT Helpdesk Staff
Source: https://t.co/YZ2Iaruf2b
A growing wave of vishing (voice phishing) campaigns in which threat actors abuse Microsoft Teamsโ external collaboration features to impersonate IT helpdesk personnel and investigators is now turning to the Microsoft 365 Unified Audit Log (UAL) as a critical forensic data source to reconstruct attack timelines.
The attack chain begins when a threat actor operating from an external or cross-tenant Teams account initiates an unsolicited call or message to a targeted employee, presenting as internal IT support.
#cybersecuritynews
How I use AI to Track Images
Most people try to geolocate images by scrolling Google Maps for hours or zooming in on random places hoping to get lucky
AI has changed that a lot โก
When I work on OSINT cases, one of the most useful skills is figuring out where a photo was taken ๐ธ
even when there is no context or metadata
One tool I use for this is PlaceSpotter
It uses AI to read visual clues from images and help identify locations much faster than manual searching
With it you can:
๐ Find possible locations from a single image
๐ Get GPS coordinates in seconds
๐ Recognize buildings, landmarks, and terrain patterns
โก Still work even when metadata is stripped out
I had one case where I only had a social media image with no location info at all
there was nothing obvious at first glance
but after running it through the tool and comparing architectural patterns and coastline features
it narrowed it down to a specific coastal region
that small clue became the turning point for the rest of the investigation ๐
This kind of geolocation work is very useful for:
๐ต๏ธ OSINT investigations
๐ก geolocation challenges and verification
๐ checking if online content is real or manipulated
In OSINT speed matters but accuracy matters more and tools like this help you get both ๐ง
๐ https://t.co/bDM0pMQgQO
๐ฆ Assemblyline 4 โ Open Source Malware Analysis Framework
Scalable malware analysis & file triage platform built for SOCs, DFIR teams & large-scale security operations.
โข Automated malware analysis using Docker & Kubernetes
โข REST API + web UI for enterprise integrations
โข Supports AV engines, sandboxes & threat intel feeds
โข Analyze millions of files daily with scalable architecture
โข Extend functionality with custom Python services
Built by the Canadian Centre for Cyber Security.
https://t.co/XHMcabXmIP
#MalwareAnalysis #DFIR #ThreatIntel #SOC #CyberSecurity
๐งฉ Mephisto โ a scanner and exploitation framework for WordPress vulnerabilities
A tool for automated detection and exploitation of known (CVE) vulnerabilities in WordPress.
Features:
๐ Support for typical modules targeting plugin and theme exploits.
๐ Generation of reports on detected and exploited vulnerabilities.
๐ CLI interface with options for test configuration and customization.
Unlike "WPScan" and "CMSmap", it focuses not only on information gathering but also on practical CVE exploitation.
๐ Tool: https://t.co/NTpCao16pJ
#dbugs_tools
โ ๏ธHackers Actively Exploiting Critical NGINX RCE Vulnerability in the Wild
Source: https://t.co/7FVnJNpPPW
Hackers are wasting no time exploiting a newly disclosed critical vulnerability in NGINX, with security researchers already observing real-world attacks just days after its public release.
Threat actors are actively targeting CVE-2026-42945, a heap buffer overflow flaw affecting both NGINX Open Source and NGINX Plus. According to Censys data, around 5.7 million internet-facing NGINX servers could be running vulnerable versions.
#cybersecuritynews
Mr_Rot13โs Filemanager backdoor changes root password to 123Qwe123C, adds a custom SSH key, drops a PHP webshell, and injects ROT13-obfuscated JS that serves a fake cPanel login โ stealing creds and sending them to wrned[.]com.
Also exfils bash history, DB passwords & valiases to Telegram group 0xWR.
Act now:
๐ธ Patch cPanel/WHM
๐ธ Block cp.dene[.]de[.]com, wpsock[.]com, wrned[.]com
๐ก๏ธ Mozilla Patches 423 Firefox Flaws with Claude Mythos and Other AI Models
Source: https://t.co/c1jpIn0Gy0
Mozilla has fixed a total of 423 Firefox security bugs in April 2026 alone, a figure nearly 20 times higher than its monthly average of about 21 bugs throughout 2025, driven by a groundbreaking agentic AI pipeline built around Anthropic's Claude Mythos Preview and other large language models.
Beyond the 271 AI-identified bugs, the remaining 152 fixes included 41 externally reported bugs and 111 discovered through internal techniques, split roughly equally between Claude Mythos fixes shipped in other releases, bugs found with other AI models, and conventional fuzzing.
#cybersecuritynews
Mobile telecom systems power our calls, internet, and even critical ICS communications. Theyโre also a prime target for attackers.
Understanding how these networks work is key to protecting them.
This article from @three_cube is a great starting point
https://t.co/4Ix6u4ofOc
In the last month alone weโve seen auth bypasses, RCEs, heap corruption bugs and protocol-level vulnerabilities back-to-back. The attack surface of internet-facing services is getting out of control. Everyone is asking the same question:
Which software is next for a critical CVE?
๐๐จ๐ฌ๐ญ ๐ฉ๐๐จ๐ฉ๐ฅ๐ ๐ข๐ง๐ฏ๐๐ฌ๐ญ๐ข๐ ๐๐ญ๐ ๐๐ง ๐๐ฆ๐๐ข๐ฅ ๐ฎ๐ฌ๐ข๐ง๐ ๐ญ๐ก๐ ๐ฌ๐๐ฆ๐ ๐ฐ๐๐ฅ๐ฅ-๐ค๐ง๐จ๐ฐ๐ง ๐๐๐๐๐ ๐ญ๐จ๐จ๐ฅ๐ฌโฆ ๐๐ฎ๐ญ ๐ญ๐ก๐๐ฒ ๐ฆ๐ข๐ฌ๐ฌ ๐ง๐๐ฐ๐๐ซ ๐ฉ๐ฅ๐๐ญ๐๐จ๐ซ๐ฆ๐ฌ ๐ญ๐ก๐๐ญ ๐ ๐จ ๐๐๐๐ฉ๐๐ซ ๐๐ง
Email addresses are one of the best pivot points in OSINT investigations ๐ง
People reuse the same email across many websites, services, and accounts
which means one lookup can expose a large part of someoneโs online footprint ๐
One of my favorite tools for this is Minerva OSINT ๐
It builds a detailed intelligence profile starting from just a single email
It can help you discover:
๐ฑ Accounts linked to the email
๐งฉ Usernames and digital footprints
๐ Platform associations across different services
๐ New pivot points to continue your investigation
What I like about it is how it ๐จ๐ซ๐ ๐๐ง๐ข๐ณ๐๐ฌ ๐ซ๐๐ฌ๐ฎ๐ฅ๐ญ๐ฌ ๐๐ฅ๐๐๐ซ๐ฅ๐ฒ, making it easy to move from one lead to another
For example, during an OSINT investigation I started with only an email addressโฆ
The results revealed usernames and linked platforms that helped me pivot into social media accounts ๐
From there, the investigation became much easier to expand
Of course, no single tool is perfect
But this one is definitely a strong addition to any OSINT toolkit ๐งฐ
My tip: always combine multiple email lookup tools to maximize coverage
๐ Website link: https://t.co/ePwq0aJGO5
There is another method you can use to uncover hidden accounts from emails which I will share in a future post ๐
but sometimes less popular platforms reveal even more data ๐
๐ GIVEAWAY TIME! ๐
2 lucky people get the 900 Endless Bundle โ ALL cybersecurity courses, certs & future ones โ for FREE! ๐๐ฅ
โ Every current course
โ Every future course
โ All certs (CNWPP, CAPIE, CxWAP)
โ Discord access
โ Lifetime updates
Use code RATPACK100 at checkout โ only 2 spots, first come first served! ๐
๐ https://t.co/SJCVm5c7Xm
After the 2 spots are gone, coupon drops to 95% off โ still a massive deal! ๐ฅ