Sign in

IFIN

@ifin-intel.org
214 followers 35 following 241 posts

The Independent Federated Intelligence Network. Our mission: Empower organizations to independently collect, analyze, and disseminate relevant cyber threat intelligence through training, open source tools, and a decentralized intelligence sharing network.

PostsRepliesMedia
IFIN @ifin-intel.org · 18h
New swag in the shop. #TIIMA
ifin-shop.fourthwall.com
TIIMA Sticker
Say it loud, say it proud, say it on your laptop lid. TIIMA. And a lil IFIN logo as a bonus!
020
Reposted by IFIN
IFIN @ifin-intel.org · 29/09/2026
If you're involved in vulnerability management/VulnOps, the last several months have been overwhelming. But take heart: there is a path forward, despite the madness surrounding us.
ifin-intel.org
Finding the Signal in the Vulnerability Noise | IFIN
The flood of new CVEs can make it hard to know what matters. But there are tools to help find our way.
086
IFIN @ifin-intel.org · 29/09/2026
If you're involved in vulnerability management/VulnOps, the last several months have been overwhelming. But take heart: there is a path forward, despite the madness surrounding us.
ifin-intel.org
Finding the Signal in the Vulnerability Noise | IFIN
The flood of new CVEs can make it hard to know what matters. But there are tools to help find our way.
086
IFIN @ifin-intel.org · 29/09/2026
We've been continuously updating this post with the latest information—now including details on exploitation of CVE-2026-88772. And all relevant indicators have been added to our MISP feed. ifin.network/t/multi... #ThreatIntel #ThreatIntelligence #IFIN
ifin.network
Multiple Citrix Netscaler 0-Days Exploited
Last Updated: 2026-09-29T14:53:55Z (UTC) What’s Happening Citrix has disclosed 8 critical CVEs. https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096 There’s also an associated blog post. Affected Versions Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 BEFORE 14.1-73.37 Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 BEFORE 13.1-64.23 Citrix NetScaler ADC FIPS BEFORE 14.1-73.37 FIPS Citrix NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.279 Indicato...
285
IFIN @ifin-intel.org · 28/09/2026
Based on our data y'all sure do love to link us in Teams chats. We're very sorry you have to use Teams.
150
IFIN @ifin-intel.org · 27/09/2026
Patches are available and updated versions are now listed.
073
IFIN @ifin-intel.org · 27/09/2026
We have updated our coverage of the new #Citrix #Netscaler vulnerabilities with the vendor's advisory. ifin.network/t/multi... #IFIN #ThreatIntel #ThreatIntelligence
ifin.network
Multiple Citrix Netscaler 0-Days Exploited
Last Updated: 2026-09-27T15:49:52Z (UTC) What’s Happening Citrix has disclosed 8 critical CVEs. https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096 Vulnerability Severity (CVSS 4) Preconditions CVE-2026-88771 9.5 None CVE-2026-88772 9.5 DTLS config enabled (enabled by default on VPN) CVE-2026-88773 9.3 HTTP Configuration enabled CVE-2026-88774 7.0 Any policy with HTTP URL-based expression CVE-2026-88775 8.8 ADC or Gateway configured as Gateway/A...
030
Reposted by IFIN
IFIN @ifin-intel.org · 27/09/2026
We are tracking the story about undisclosed 0-days in Citrix Netscaler devices. We have confirmation from multiple source now about the veracity of the claims, although few details from Citrix themselves. This is a developing story. ifin.network/t/citri... #ThreatIntel #ThreatIntelligence #IFIN
ifin.network
Citrix Advises Shutdown Due to New, Undisclosed Netscaler 0-Days
Last Updated: 2026-09-26T23:22:28Z (UTC) What’s Happening On 2026-09-26T07:00:00Z (UTC), a Reddit posts in the Citrix community indicated that the presence of two 0-day vulnerabilities in Citrix Netscaler devices. The poster was apparently advised to shut down external devices. Research firm WatchTowr corroborated the report, as did researcher Kevin Beaumont. Both Beaumont and WatchTowr doubled down on the claim later in the day. WatchTowr, while unable to confirm sourcing, stated t...
11912
IFIN @ifin-intel.org · 27/09/2026
We are tracking the story about undisclosed 0-days in Citrix Netscaler devices. We have confirmation from multiple source now about the veracity of the claims, although few details from Citrix themselves. This is a developing story. ifin.network/t/citri... #ThreatIntel #ThreatIntelligence #IFIN
ifin.network
Citrix Advises Shutdown Due to New, Undisclosed Netscaler 0-Days
Last Updated: 2026-09-26T23:22:28Z (UTC) What’s Happening On 2026-09-26T07:00:00Z (UTC), a Reddit posts in the Citrix community indicated that the presence of two 0-day vulnerabilities in Citrix Netscaler devices. The poster was apparently advised to shut down external devices. Research firm WatchTowr corroborated the report, as did researcher Kevin Beaumont. Both Beaumont and WatchTowr doubled down on the claim later in the day. WatchTowr, while unable to confirm sourcing, stated t...
11912
IFIN @ifin-intel.org · 24/09/2026
Apologies for the noise on the news feed today. We added the excellent Objective-See macOS research blog. Unfortunately, FreshRSS is struggling with parsing its publication dates, so the whole feed was marked as published today. Won't be a problem moving forward. news.ifin.network
020
Reposted by IFIN
Robert Wilson @frcolumba.bsky.social · 23/09/2026
We are seeing a big uptick all at once on this for clickfix first stage. Must’ve just been added to a toolkit. Almost all of it is still up I think.
121
IFIN @ifin-intel.org · 23/09/2026
The best time to block the finger protocol (port 79/tcp) outbound from your network was like…the second Clinton administration? But now's a good time too. #ThreatIntel #ThreatIntelligence #IFIN
2104
Reposted by IFIN
Taggart @taggart-tech.com · 23/09/2026
You know, if tech companies are looking for a, uh, less *problematic* non-profit to fund, I have some thoughts...
ifin-intel.org
IFIN | The Independent Federated Intelligence Network
A not-for-profit organization dedicated to the teaching of best practices in cyber threat intelligence, and the mutual sharing of timely, actionable, and relevant intelligence among the community.
0104
IFIN @ifin-intel.org · 23/09/2026
A format string vulnerability in Shrubbery's TACACS+ library (and Facebook's archived fork of it) can lead to secret disclosure, DoS, and potentially remote code execution. No, Cisco gear isn't affected, but many other devices will be. As of now, no CVE has been assigned.
ifin.network
CVE pending: pre-auth format-string bug in tac_plus (Shrubbery Networks)
Last Updated: 2026-09-23T15:47:14Z (UTC) CVE: TBA CVSSv3: tentative 9.8 (per vuln publisher, not ratified) What’s Happening Research firm elttam has disclosed a vulnerability in the Shrubbery fork of the tac_plus TACACS+ authentication library used in multiple networking devices. The vulnerability, if fully exploited, can lead to remote code execution on target devices. Crashing systems is also a possibility. Secret disclosure is a natural result of this vulnerability. The post is long,...
032
IFIN @ifin-intel.org · 22/09/2026
Completing our tour of new known-exploited vulns today, here is Arista's perfect-10. ifin.network/t/arist... #ThreatIntel #ThreatIntelligence #IFIN
ifin.network
Arista CVE-2026-93952 Auth Bypass Exploited in the Wild
Last Updated: 2026-09-22T22:18:11Z (UTC) Arista published a security advisory today regarding its VeloCloud Orchestrator. The perfect-10 CVSS vulnerability: …may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Yes, it “may” indeed. It’s now confirmed exploited and on CISA’s KEVs as of today. Ther...
031
IFIN @ifin-intel.org · 22/09/2026
When it rains, it pours. F5 BIG-IP APM also has an exploited CVE! ifin.network/t/f5-bi... #ThreatIntel #ThreatIntelligence #IFIN
ifin.network
F5 BIG-IP CVE-2026-94127 RCE Exploited
Last Updated: 2026-09-22T20:36:25Z (UTC) What’s Happening A F5 advisory published 2026-09-22 details CVE-2026-94127 (CVSSv3 9.8). When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). It is unknown how common this configuration is as of this writing. Affected Products/Versions The affected product is BIG-IP APM (Access Policy Manager), versions: 21.1.0, patched in Hotfix-BIGIP-21.1.0...
052
IFIN @ifin-intel.org · 22/09/2026
Two Check Point critical vulnerabilities are now listed as exploited in the wild. ifin.network/t/cve-2... #ThreatIntel #ThreatIntelligence #IFIN
ifin.network
CVE-2026-85102 and 93616 - Check Point Security Gateway RCE/Path Traversal Exploited
Last updated: 2026-09-22T19:41:29Z (UTC) CVSSv3: 9.8 What’s Happening In what’s-old-is-new-again news, two CVEs were released today for Checkpoint Security Gateway management toolsets, including a pre-auth remote code execution and a path traversal in the management web service. Here are Check Points internal support center details: Since I started writing this Check Point posted notification of exploitation on their blog. Actions Check the advisories above for affected versions and o...
033
Reposted by IFIN
IFIN @ifin-intel.org · 17/09/2026
Got a #cybersecurity question? Don't ask AI. Ask people who know. Join us at ifin.network.
ifin.network
IFIN
The Independent Federated Intelligence Network
032
IFIN @ifin-intel.org · 18/09/2026
Rust maintainers are targeted (again), but good news: the same defenses as always apply. ifin.network/t/rust-... #ThreatIntel #ThreatIntelligence #IFIN #Rustlang
ifin.network
Rust Package Maintainers Targeted with Social Engineering, Repo Takeover
Last Updated: 2026-09-18T12:35:00Z (UTC) What’s Happening According to the Rust language security response working group, maintainers of rust-lang (the repo comprising the Rust language itself) and popular packages (crates) are being targeted by social engineering attacks intended to compromise the repository. Per the post: A video call is set up for something positive — maybe for a job, maybe for a project, maybe for a contract opportunity — and then that’s used as a vector to either g...
031
IFIN @ifin-intel.org · 17/09/2026
Got a #cybersecurity question? Don't ask AI. Ask people who know. Join us at ifin.network.
ifin.network
IFIN
The Independent Federated Intelligence Network
032
Reposted by IFIN
IFIN @ifin-intel.org · 16/09/2026
Based on a community tip (we love those!), we discovered yet another malware family that's bringing its own Python interpreter—and a few other tricks. Bring-Your-Own-Python is *so hot right now* ifin.network/t/quick... #ThreatIntel #ThreatIntelligence #IFIN
ifin.network
QuickFix: Yet Another Bring-Your-Own-Python Payload
Last Updated: 2026-09-16T14:53:57Z (UTC) What’s Happening TL;DR: `fileupdates.blob.core.windows[.]net is hosting “QuickFix,”, a new-ish installer file with PowerShell that installs its own Python interpreter, then activates a light C2 beacon for Python commands send via JSON. The detection opportunity is Python executing outside of expected directories. This was a tip from Fedi and turned into a really fun investigation. The tipper was surprised that Microsoft even allowed that blob storage...
044
IFIN @ifin-intel.org · 16/09/2026
Based on a community tip (we love those!), we discovered yet another malware family that's bringing its own Python interpreter—and a few other tricks. Bring-Your-Own-Python is *so hot right now* ifin.network/t/quick... #ThreatIntel #ThreatIntelligence #IFIN
ifin.network
QuickFix: Yet Another Bring-Your-Own-Python Payload
Last Updated: 2026-09-16T14:53:57Z (UTC) What’s Happening TL;DR: `fileupdates.blob.core.windows[.]net is hosting “QuickFix,”, a new-ish installer file with PowerShell that installs its own Python interpreter, then activates a light C2 beacon for Python commands send via JSON. The detection opportunity is Python executing outside of expected directories. This was a tip from Fedi and turned into a really fun investigation. The tipper was surprised that Microsoft even allowed that blob storage...
044
IFIN @ifin-intel.org · 16/09/2026
An ISP outage is interrupting access to the forum. Apologies for the inconvenience! We should be back online within two hours.
120
Reposted by IFIN
Ian Campbell @neurovagrant.bsky.social · 14/09/2026
Updated the @ifin@infosec.exchange thread here. Blackfile-suspected list (attached) up to 59. Medium-high confidence. Also attached CSV of 134 domains connected or adjacent to Blackfile/ShinyHunters from Sept 11-14, all worth blocking preemptively. ifin.network/t/blackfile-...
ifin.network
Blackfile & Related emerging domains
Blackfile-suspected list (attached) up to 59. Medium-high confidence. Also attached CSV of 134 domains connected or adjacent to Blackfile/ShinyHunters from Sept 11-14, all worth blocking preemptively...
111
Reposted by IFIN
IFIN @ifin-intel.org · 14/09/2026
Our new project: IFIN Lists is a curated set of permanent blocks and perennial hunts that go beyond traditional indicators to include abused "legitimate" services that most organizations should not tolerate. ifin-intel.org/blog/... #ThreatIntel #ThreatIntelligence #TIIMA
ifin-intel.org
Announcing IFIN Lists | IFIN
IFIN Lists is a project to build a well curated, community driven set of permanent block lists for all to use.
175
Reposted by IFIN
IFIN @ifin-intel.org · 14/09/2026
One of our first lists is the cryptocurrency RPC Nodes lists. You want to block these right now to neutralized #Etherhiding attacks! lists.ifin.network/lists/rpc-no...
lists.ifin.network
RPC Nodes - IFIN Lists
A curated collection of long-term block lists and hunting targets for all organizations, along with documentation and explanations.
055
IFIN @ifin-intel.org · 14/09/2026
Our new project: IFIN Lists is a curated set of permanent blocks and perennial hunts that go beyond traditional indicators to include abused "legitimate" services that most organizations should not tolerate. ifin-intel.org/blog/... #ThreatIntel #ThreatIntelligence #TIIMA
ifin-intel.org
Announcing IFIN Lists | IFIN
IFIN Lists is a project to build a well curated, community driven set of permanent block lists for all to use.
175
IFIN @ifin-intel.org · 12/09/2026
The "Lorem Ipsum" malware family is still alive and kickin', delivered by our old pals ClickFix and Etherhiding. ifin.network/t/lorem... #ThreatIntel #ThreatIntelligence #IFIN
ifin.network
Lorem Ipsum Malware Alive and Well
Last Updated: 2026-09-12T15:06:12Z (UTC) What’s Happening While reviewing some recent ClickFix/Etherhiding domains on ThreatFox, I noticed a bizarre sample with weirdo strings in it. Turns out it was part of the Lorem Ipsum malware family, which uses nonsense strings as a sort of encoding mechanism for its C2 commands. This is a known technique. Also known is the use of letsdiskuss[.]com, an Indian social media site, to host C2 data. For example, this user profile. The malware’s ...
021
Reposted by IFIN
Ian Campbell @neurovagrant.bsky.social · 10/09/2026
I've updated both the @ifin-intel.org thread and @domaintools.bsky.social Investigations Github with a new list of medium-high confidence domains in this Blackfile campaign, 55 in all. Added Unit42 and Microsoft lists to my own.
031
IFIN @ifin-intel.org · 10/09/2026
Block abliteration[.]ai right now #ThreatIntel #ThreatIntelligence #IFIN
110
Reposted by IFIN
Ian Campbell @neurovagrant.bsky.social · 09/09/2026
Seeing a few places go loud with Blackfile-related domain lists, most of which are missing multiple entries. Dropped two CSVs over at @ifin-intel.org - 32 domains associated with Blackfile with high confidence, and a larger list of domains observed while hunting. ifin.network/t/blackfile-...
ifin.network
Blackfile & Related emerging domains
Hey folks, Been tracking the Blackfile passkey/mfa campaign for weeks or months now. Saw a recent listing from Unit42 that was missing a few domains I have, and had a few domains I missed. blackfile...
132
IFIN @ifin-intel.org · 08/09/2026
The new BigBear2 reverse proxy phishing campaign has some interesting tricks up its sleeve. #threatintel #threatintelligence #IFIN
231
IFIN @ifin-intel.org · 08/09/2026
Turns out Entra password protection may not be all it's cracked up to be. A deep dive by one our community members found significant holes.
ifin.network
Entra Password Protection.....isn't
Thank you The vast majority of the research is from Microsoft’s own documentation: On-Prem Entra Password Protection for AD DS Eliminate bad passwords using Entra Password Protection It should be noted that at the very bottom of the second article, MS outlines this exact scenario: Let’s look a slightly different example to show how more complexity in a password can build the required number of points to be accepted. In the following example scenario, a user changes their password to “Conto...
033
IFIN @ifin-intel.org · 07/09/2026
Tonight, we will be migrating the forum from `discourse.ifin.network` to `ifin.network`. The old domain should work fine, but the community has become the root of our efforts, and the domain should reflect that.
discourse.ifin.network
IFIN
The Independent Federated Intelligence Network
100
IFIN @ifin-intel.org · 04/09/2026
FalconFlank is not really a new vulnerability... #ThreatIntel #ThreatIntelligence #IFIN
111
IFIN @ifin-intel.org · 03/09/2026
So we're trying short form video now don't hate us www.tiktok.com/@ifin...
140
IFIN @ifin-intel.org · 02/09/2026
We've yet again updated our post with the latest patched versions and techniques for identifying vulnerable servers.
021
IFIN @ifin-intel.org · 01/09/2026
We're thrilled to announce that we'll be at @jawncon.bsky.socialon October 16th in Philly! Taggart will be presenting "Threat Intel is Mutual Aid: Building a People-First Sharing Network," telling IFIN's story and our work so far. Also, y'know, swag. Hope to see you there!
030
IFIN @ifin-intel.org · 28/08/2026
We've updated this post with more patches from PaperCut and reports from Huntress.
031
IFIN @ifin-intel.org · 27/08/2026
PaperCut has released emergency patches for PaperCut NG/MF, with potential indicators for an active exploitation of a 0-day vulnerability. discourse.ifin.netwo... #ThreatIntel #ThreatIntelligence #IFIN
discourse.ifin.network
PaperCut Emergency Patch
Ouch. Last Updated: 2026-08-27T19:46:03Z (UTC) What’s Happening PaperCut has released an urgent security advisory for PaperCut NG and PaperCut MF Security Advisory Actions Immediately disconnect PaperCut NG and PaperCut MF services that are accessible from the internet, ensuring they can only be accessed by trusted IP addresses even if no suspicious activity has been observed. Apply the emergency patch that has been released for customers are unable to take other mitigating actions. URGE...
032
Reposted by IFIN
IFIN @ifin-intel.org · 26/08/2026
PoCs verified, but also details about the exploitation conditions added. Bottom line: you're probably fine, but check the details.
001
IFIN @ifin-intel.org · 26/08/2026
We have some breaking news. A potential RCE in Apache #Log4J 2 (yes, really) appears to have proofs-of-concept. We have the details, the initial bug report, and mitigation recommendations. We are verifying the PoCs currently. discourse.ifin.netwo... #ThreatIntel #ThreatIntel #IFIN
discourse.ifin.network
Log4j2 Allowlist Bypass Could Allow for RCE
Last Updated: 2026-08-26T17:05:28Z (UTC) What’s Happening A currently unconfirmed vulnerability in Apache Log4j could allow remote code execution (RCE) by bypassing the allowlist enforced by FilteredObjectInputStream (FOIS) during Java deserialization. Exploitation requires an uncommon configuration in which an application or logging service accepts serialized Log4j LogEvent objects through an FOIS-based receiver, as well as a suitable deserialization gadget on the target classpath. Unlik...
181
IFIN @ifin-intel.org · 25/08/2026
IFIN has an ambitious set of goals for our first year. Learn about the plan and how you can help us succeed. ifin-intel.org/blog/... #IFIN #ThreatIntel #ThreatIntelligence #TIIMA
ifin-intel.org
IFIN's First Year: An Action Plan | IFIN
As we begin this journey, we have a clear plan to achieve our goals. They all need support from people like you.
062
IFIN @ifin-intel.org · 24/08/2026
We have the details on the recent MacSync infostealer malware family. discourse.ifin.netwo... #ThreatIntel #ThreatIntelligence #IFIN
discourse.ifin.network
MacSync infostealer Infrastructure and TTPs
Last Updated: 2026-08-24T19:42:12Z (UTC) What’s Happening Microsoft expands on reporting by RST Cloud on macOS infostealer infrastructure and TTPs, in which they connected over 30 additional domains to the activity. Rather than hunting on the large amount of quickly rotating domains used, Microsoft relates repeated execution patterns including request paths, headers, curl arguments, and upload parameters, tracking the malware’s entire attack chain. https://www.microsoft.com/en-us/securit...
031
IFIN @ifin-intel.org · 24/08/2026
Expel's recent discovery of SynkLoader combined lots of fun behaviors into a single malware sample. There are a couple strong detection opportunities worth reviewing. discourse.ifin.netwo... #IFIN #ThreatIntel #ThreatIntelligence
discourse.ifin.network
SynkLoader: Windows Loader Malware Brings its Own Python and Lock Screen
Last Updated: 2026-08-24T14:49:19Z (UTC) What’s Happening The latest research from Marcus Hutchins (malwaretech) at Expel is a humdinger of a read, with some really creative behaviors. First, we have Teams phishing as a delivery mechanism. I don’t know how many folks have reviewed their external access Teams policies, but the more you can lock them down, the better. Then you have obfuscated PowerShell (a classic), that creates Script Blocks via [System.Management.Automation.ScriptBlock]:...
021
IFIN @ifin-intel.org · 22/08/2026
We have a breakdown of recent Citrix vulnerabilities for you. Again. Not a series we wanted to make, but here we are.
discourse.ifin.network
Recent Citrix Netscaler Vulnerability Roundup: 2026-08-22
This is starting to become a series. I was about to write up something about a specific recent Netscaler vulnerability, but as I was gathering information, I realized that there’s just been a deluge of exploited and not-yet-exploited critical vulnerabilities in Citrix Netscalers. Let’s get into it. CVE-2026-8452 CVSSv3: 9.8 Exploited: Unconfirmed, but probably soon This is a memory corruption bug in the ADC and Gateway SAML handler. Now this advisory is from June, but has seen recent re...
032
IFIN @ifin-intel.org · 20/08/2026
Rust joins the supply chain party with a set of compromised packages and account takeovers/impersonations today. discourse.ifin.netwo... #ThreatIntel #ThreatIntelligence #IFIN #RustLang
discourse.ifin.network
Rust Supply-Chain Attack: arrayref, internment, and append-only-vec Poisoned by proc-macro2 typosquat
Last Updated: 2026-08-20T16:23:19Z (UTC) What’s Happening This morning (01:55:34 UTC, 2026-08-20), an attacker impersonating (dtolney) the developer account (dtolnay) for proc-macro2 published a typosquat package named proc-macro1. This malicious package was a clone of the original with a malicious build script later added. Simultaneously, the attacker published an update to arrayref with the compromised author account (droundy), referencing the typosquat proc-macro1package. When building,...
062
IFIN @ifin-intel.org · 18/08/2026
Iranian-backed "313 Team" (a front for MOIS operations) has claimed credit for both GitHub and Bluesky DDoS attacks yestderday.
discourse.ifin.network
Iranian-backed 313 Team claims GitHub, Bluesky DDoS attacks
Putting this here in Cyber News because there is nothing actionable. It’s just interesting. Yesterday, both Github and Bluesky experienced several hours of outage yesterday. Both were due to sustained DDoS attacks. Iranian-backed “313 Team,” aka the “Islamic Cyber Resistance in Iraq” claimed both attacks on their Telegram channel. Worth noting that in the past, 313 used Beamed, Cloudflare-protected booter for their operations. Since June, they have pivoted to using booters protecte...
094
IFIN @ifin-intel.org · 14/08/2026
We have received reports that this VMWare vulnerability is currently exploited in the wild. Our MISP feed has the existing indicators, including the YARA rule for dropped artifacts. discourse.ifin.netwo... #ThreatIntel #ThreatIntelligence #IFIN
discourse.ifin.network
CVE-2026-59309: Critical Auth Bypass in Broadcom VMware vCenter
Last Updated: Friday, August 14, 2026 5:45 PM (UTC) CVSSv3: 9.8 What’s Happening There is a critical Auth Bypass vulnerability in Broadcom’s VMware vCenter, CVE-2026-59309. Published in Broadcom’s July 29th, 2026 security advisory, the security researchers who discovered the vulnerability published a walkthrough for it on the same day. There is a patch available for the vulnerability. There is no other workaround. It has been reported as EITW by independant sources. The vulnerability bypas...
132
Reposted by IFIN
Aleks Char @alekschar.bsky.social · 11/08/2026
I'm so honored to be a part of @ifin-intel.org. I'm happy to announce that IFIN has achieved tax-exempt status under section 501(c)(3) of the US Tax Code. Put simply, we're a nonprofit! Read more here: ifin-intel.org/blog/nonprof...
ifin-intel.org
It's Official: We're a Recognized Non-Profit | IFIN
IFIN has achieved 501(c)(3) status. What this means for us, and for you.
041