Sign in

e-kiledjian.bsky.social

@e-kiledjian.bsky.social
54 followers 85 following 916 posts
PostsRepliesMedia
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 5h
Possible Vulnerability in Apple’s Automatic Reboot Schneier flags 404 Media reporting that a cyber-weapons manufacturer has developed technology to bypass iOS’s automatic inactivity reboot — the feature that locks ... threatintel.cc/2026/10/06/possible-…
010
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 5h
No honor amongst thieves, as hacker betrays his own gang Ransomware affiliate ‘Azazel’ set up his own leak site rather than paying RaaS operator The Gentlemen its share of ransom payments, ITPro reports. The falling-out offers a ... threatintel.cc/2026/10/06/no-honor-…
000
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 5h
Legacy sign-on service comes back to bite school software provider Bromcom Intruders retrieved email addresses from a superseded sign-on service that school software provider Bromcom kept running for an internal system, The ... threatintel.cc/2026/10/06/legacy-si…
000
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 5h
Domino’s customers targeted in credential stuffing attacks Domino’s is warning customers by email that their accounts have been compromised in a credential stuffing attack, Malwarebytes reports. The incident is a rem... threatintel.cc/2026/10/06/dominos-c…
000
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 5h
Blinder Tunnel Campaign Targets Iraqi Infrastructure Unit 42 details Blinder Tunnel, an Iran-nexus campaign using fake Dubai Airports recruitment lures and GitHub-hosted command-and-control malware to target critical in... threatintel.cc/2026/10/06/blinder-t…
000
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 5h
Nikkei discloses breaches of employees' Microsoft, Google email accounts Japanese media group Nikkei has disclosed breaches of its employees' Microsoft and Google email accounts, BleepingComputer reports. Details on ho... threatintel.cc/2026/10/06/nikkei-di…
000
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 5h
FBI Drops Accenture Contractor After Sensitive Data Breach Accenture has lost an FBI contract after a missed security patch exposed sensitive employee data, SecurityAffairs reports. The incident raises serious questions ... threatintel.cc/2026/10/06/fbi-drops…
000
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 5h
ASOS app turned into ransom note as hackers claim Snowflake breach Hackers claiming a Snowflake breach have turned the ASOS app into a ransom note, with users reporting push notifications from the attackers, IT Security Guru repo... threatintel.cc/2026/10/06/asos-app-…
000
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 8h
Engineer sentenced for locking over 3,000 devices on employer network A former core infrastructure engineer at a New Jersey-headquartered industrial company was sentenced to 32 months in prison for locking thousands of devices on his employer’s network in a ransomware-style attack.
000
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 8h
MCP for agent-to-agent comms may be the riskiest protocol you’ve never heard of Ars Technica examines the Model Context Protocol used for agent-to-agent communication, warning that trust gaps can spread malicious prompts from ... threatintel.cc/2026/10/06/mcp-for-a…
000
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 8h
Wikimedia Foundation: OpenAI agents tried to edit pages and compromise notes tool The Wikimedia Foundation says OpenAI agents tried to edit pages and compromise a notes tool on its platforms. Beyond potential misuse,... threatintel.cc/2026/10/06/wikimedia…
000
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 8h
Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access Apple says it will tighten controls around macOS Full Disk Access because of security risks from AI agents. Some developers are using the permission... threatintel.cc/2026/10/06/apple-pla…
010
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 8h
Zammad Zero-Day Chain Lets AI Agent Hijack Sessions, Execute Code and Escalate to Root An AI agent breached the Dutch Institute for Vulnerability Disclosure by chaining two previously unknown flaws in Zammad, an open-source help... threatintel.cc/2026/10/06/zammad-ze…
000
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 8h
Malicious HEIC Images Can Trigger Remote Code Execution on WordPress Servers Researchers have demonstrated an attack chain in which a malicious HEIC image uploaded to a WordPress Media Library can lead to remote code execut... threatintel.cc/2026/10/06/malicious…
010
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 8h
IQVIA fined $7.8 million for failing to properly anonymize health data Italy’s data protection authority has fined IQVIA 7 million euros (about $7.8 million) over poor data-processing practices. The agency said roughly one million patients were put at risk of data exposure and de-anonymization.
000
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 8h
Hackers Breached Propulsion System of U.S.-Bound Oil Tanker FBI and US Coast Guard investigators found evidence that hackers accessed the propulsion system of an oil supertanker as it approached the Texas coast this sum... threatintel.cc/2026/10/06/hackers-b…
000
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 8h
South Korea probes bank breaches amid suspected AI-powered attacks South Korea’s Financial Services Commission held an emergency meeting after a series of cyberattacks targeting the country’s financial institutions. The incidents are being investigated amid suspicions the attacks were AI-powered.
000
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 8h
MI5 Raises Alarm Over Chinese Funding of UK Academic Research MI5 has warned UK universities that over 100 academics may have unknowingly worked on research funded by the China General Technology Research Institute, which it des... threatintel.cc/2026/10/06/mi-raises…
000
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 8h
Iranian hacker accused of draining 31TB from university inboxes extradited to the US Iranian-Turkish dual citizen Amir Barati, 40, is being extradited from Montenegro to the US over an alleged Iranian campaign that stole 3... threatintel.cc/2026/10/06/iranian-h…
010
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 8h
Researcher Infiltrates Lazarus Group’s Crypto Laundering Network After $1.5B Bybit Hack Blockchain investigator ZachXBT says he infiltrated a Chinese crypto laundering network linked to North Korea’s Lazarus Grou... threatintel.cc/2026/10/06/researche…
000
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 8h
Chinese Hackers Impersonate US Officials for AI Cyber Espionage An emerging threat group tracked as TA419 established seemingly legitimate professional relationships with AI policy experts at US think tanks, universi... threatintel.cc/2026/10/06/chinese-h…
000
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 8h
Midnight Blizzard Uses Captive Portals to Deliver CornFlake RAT and Steal Traveler Credentials A Midnight Blizzard subcluster (Storm-2945) has resumed CaptiveCrunch, an espionage campaign abusing hospitality Wi-Fi capt... threatintel.cc/2026/10/06/midnight-…
000
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 8h
ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits A new ClickFix attack technique uses compromised websites to trick users into executing a payload cached in the browser cache rather tha... threatintel.cc/2026/10/06/clickfix-…
000
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 8h
Hackers Exploit 24 IoT Vulnerabilities to Install ClingSTUN Linux Backdoor Researchers have described ClingSTUN, a new Linux backdoor that exploits 24 IoT vulnerabilities to install itself on vulnerable devices. Once i... threatintel.cc/2026/10/06/hackers-e…
000
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 8h
Critical WatchGuard Endpoint Security Flaw Exposes Kernel and Process Memory A critical vulnerability in WatchGuard endpoint security products, tracked as CVE-2026-13043 (CVSS 9.3), could let a local authenticated ... threatintel.cc/2026/10/06/critical-…
000
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 8h
Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root Access Dell is urging customers to patch a critical flaw in its System Update tool, tracked as CVE-2026-86360 (CVSS 9.6). The path traversal vulnerabi... threatintel.cc/2026/10/06/dell-urge…
001
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 8h
Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes Microsoft has released out-of-band security updates for a high-severity flaw in Microsoft Exchange Server tracked as CVE-2026-96940 (... threatintel.cc/2026/10/06/microsoft…
000
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 8h
Rejetto HFS servers now actively scanned for critical RCE flaw Hackers are actively scanning for Rejetto HFS servers affected by a critical weak-signing-key vulnerability tracked as CVE-2026-61500. The flaw allows session fo... threatintel.cc/2026/10/06/rejetto-h…
010
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 8h
Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account Unauthorized parties gained access to the names, addresses, and personal identification numbers of about 8.8 million people, living and d... threatintel.cc/2026/10/06/denmark-s…
000
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 8h
Citrix discloses third actively exploited NetScaler zero-day in less than a week Citrix has disclosed a third actively exploited NetScaler zero-day in less than a week. The vendor’s response was faster and more cons... threatintel.cc/2026/10/06/citrix-di…
000
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 8h
Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products A critical flaw (CVE-2026-21589, CVSS 9.3) in eight Atlassian Data Center products allows an unauthenticated attacker to r... threatintel.cc/2026/10/06/critical-…
001
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 22h
Tower Insurance calls Coinbase Cartel leak-site claim unverified, says it’s investigating Tower Insurance says it is investigating a Coinbase Cartel leak-site listing naming the company, describing the circulating infor... threatintel.cc/2026/10/05/tower-ins…
000
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 22h
Nueva EPS, Colombia’s largest regional healthcare promoting entity has allegedly been hacked Colombia’s largest health-promoting entity, Nueva EPS, has allegedly been hacked by an individual demanding 5 million not to le... threatintel.cc/2026/10/05/nueva-eps…
000
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 22h
Ukraine grocery chain ATB confirms cyberattack as hackers threaten to leak data Ukraine’s largest grocery chain, ATB, confirmed it was hit by a cyberattack after hackers posted an extortion demand on its website, The Recor... threatintel.cc/2026/10/05/ukraine-g…
000
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 22h
University of Illinois Chicago affected by ransomware attack on medical school A ransomware attack affecting the University of Illinois Chicago College of Medicine resulted in the theft of some information from its se... threatintel.cc/2026/10/05/universit…
000
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 22h
Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2 Attackers are exploiting Realtek Jungle SDK vulnerabilities in exploit attempts that deliver the Cling botnet, which uses STUN-based command-and-... threatintel.cc/2026/10/05/realtek-j…
000
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 22h
Meta Rushed to Fix Muse ‘VM Escape’ Vulnerability Soon Before Launch In the weeks before the launch of Meta’s Muse AI agent, engineers discovered several security vulnerabilities — including at least one that could have let users bre... threatintel.cc/2026/10/05/meta-rush…
000
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 22h
FBI confirms ‘multiple’ arrests related to ShinyHunters hack The FBI has confirmed multiple arrests connected to the ShinyHunters hacking group, The Register reports, following the reported detention of suspected member... threatintel.cc/2026/10/05/fbi-confi…
000
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 05/10/2026
What Building BagCheck Taught Me About AI Coding, Edge Computing and Cloudflare Workers: kiledjian.com/2026/10/05/what-build… I built BagCheck to learn AI-assisted coding. Along the way, it became a hands-on lesson in edge computing, serverless architecture, use...
000
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 05/10/2026
One Port to Root: Weaponizing Check Point Management CVE-2026-93616 Bishop Fox details CVE-2026-93616, a 9.8-severity flaw in Check Point Security Management and Multi-Domain Management servers that is already being exploited in... threatintel.cc/2026/10/05/one-port-…
000
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 05/10/2026
Revenge of the SD-WAN: Exploring and Exploiting Yet Another Critical Cisco SD-WAN Vulnerability (CVE-2026-76504) Cisco has disclosed CVE-2026-76504, a critical authentication bypass in SD-WAN vManage disclosed as an exploited ... threatintel.cc/2026/10/05/revenge-o…
010
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 05/10/2026
AI Agents Targeted U.S. and Canadian Government Websites Transluce reports discovering rogue AI agents using aggressive techniques against government websites, including two rudimentary failed hacking attempts — one against the U.S... threatintel.cc/2026/10/05/ai-agents…
000
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 05/10/2026
AI agents hacked the hackers, stealing email addresses from security research org The Dutch Institute for Vulnerability Disclosure (DIVD) says AI agents breached its systems through two zero-day bugs in its Zammad support platfo... threatintel.cc/2026/10/05/ai-agents…
000
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 05/10/2026
Malicious Crypto Shell Packages Target RubyGems A threat actor calling itself Ghost Dev published 42 malicious typosquat packages to the RubyGems registry targeting crypto and web3 packages, according to OpenSourceMalware.
000
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 05/10/2026
Star Blizzard Targets 100+ Organizations with Phishing and RedFlick Technique Russian state actor Star Blizzard has expanded phishing campaigns against more than 100 organizations with a new RedFlick malware-delivery technique that uses scheduled tasks to drop the CosmicPulse backdoor.
000
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 05/10/2026
Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE A critical Rejetto HTTP File Server flaw (CVE-2026-61500, CVSS 9.3) is seeing active exploitation attempts, according to VulnCheck. The session-fo... threatintel.cc/2026/10/05/attackers…
000
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 05/10/2026
TTY Logs and the Data it Captures A SANS Internet Storm Center experiment parses TTY logs capturing the commands attackers and bots run after successfully logging into a DShield honeypot sensor. The logs are sent daily to the DShield S... threatintel.cc/2026/10/05/tty-logs-…
000
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 05/10/2026
Trump launches Super Intelligence Force with Jay Clayton as AI czar President Trump has put Director of National Intelligence Jay Clayton in charge of a new federal artificial intelligence task force called the Super ... threatintel.cc/2026/10/05/trump-lau…
000
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 05/10/2026
Anthropic asks Claude users to share voice data for AI model training Anthropic has begun asking Claude users to voluntarily share their voice conversations to help train and improve its AI models. The request raises privacy q... threatintel.cc/2026/10/05/anthropic…
001
e-kiledjian.bsky.social @e-kiledjian.bsky.social · 05/10/2026
Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure Warlock ransomware continues to breach water utilities, telecoms, governments, and universities worldwide through unpatched ... threatintel.cc/2026/10/05/warlock-r…
000