Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

BeyondMachines :verified:

@beyondmachines1@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Enabling Good Cybersecurity for Everyone:
Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes.
Because cybersecurity shouldn't be an enterprise feature.

Sometimes a bot, sometimes not.

2473 Followers
707 Following
50 Posts
Joined May 22, 2023
Website:
https://beyondmachines.net
Linkedin:
https://www.linkedin.com/company/73905832/
GitHub:
https://github.com/BeyondMachines
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 2w ago
Boosted by @trending@homestead.social
War going Agile
647
1
424
0
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 1mo ago
Boosted by @trending@homestead.social

AliExpress Silent WebAudio Fingerprinting Uses Bluetooth Hardware

AliExpress uses hidden WebAudio graphs to fingerprint devices, which blocks Bluetooth multipoint headphones from switching audio sources. The tracking relies on obfuscated scripts that maintain an active audio pipeline even when muted.

If you shop on AliExpress and your Bluetooth headphones stop switching between devices, this is caused by hidden tracking scripts on the site, not broken hardware. Install uBlock Origin and add filter rules to block collina.js and fireyejs.js on aliexpress.com, then close all open AliExpress tabs and reload the site for the fix to take effect. #cybersecurity #infosec #knowledge #awareness https://beyondmachines.net/event_details/aliexpress-silent-webaudio-fingerprinting-uses-bluetooth-hardware-9-o-c-m-i/gD2P6Ple2L

AliExpress Silent WebAudio Fingerprinting Uses Bluetooth Hardware
BeyondMachines

AliExpress Silent WebAudio Fingerprinting Uses Bluetooth Hardware

AliExpress uses hidden WebAudio graphs to fingerprint devices, which blocks Bluetooth multipoint headphones from switching audio sources. The tracking relies on obfuscated scripts that maintain an active audio pipeline even when muted.

285
0
412
0
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 2mo ago
The state of #AI
140
6
82
1
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 2mo ago
#AI Solutions looking for problems, version: IPO is coming!
43
4
34
0
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 1mo ago
#AI rules to live by
21
1
15
0
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 2w ago
Replying to
@citizen428@chaos.social given the number of concurrent wars, that numbering system will overflow. And what about wars spanning multiple years?
2
1
0
0
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 3w ago

Apple Patches Hundreds of Vulnerabilities in September 2026 Security Update

Apple's September 14, 2026 release of iOS 27, macOS Golden Gate 27, Safari 27 and its sibling updates patches over 200 CVEs, concentrated in WebKit, the kernel and drivers, and file-sharing/file-system code (SMB, WebDAV, autofs, disk images). The flaws enable universal XSS, root privilege escalation, kernel memory corruption from hostile servers or crafted volumes, Gatekeeper and sandbox bypasses, and arbitrary code execution from images and 3D models.

If you use any Apple devices: iPhone, iPad, Mac, Apple Watch, Apple TV or Vision Pro, update them ASAP to the latest version (iOS/iPadOS 27 or 26.7, macOS Golden Gate 27, Tahoe 26.7 or Sequoia 15.8, tvOS/watchOS/visionOS 27, and Safari 27). The September releases patch a huge number of issues. Until you've updated, be extra careful about visiting unfamiliar websites, opening files or images from strangers, and connecting to unknown file-sharing servers or Wi-Fi networks. #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/apple-patches-hundreds-of-vulnerabilities-in-september-2026-security-update-j-s-p-c-n/gD2P6Ple2L

Apple Patches Hundreds of Vulnerabilities in September 2026 Security Update
BeyondMachines

Apple Patches Hundreds of Vulnerabilities in September 2026 Security Update

Apple's September 14, 2026 release of iOS 27, macOS Golden Gate 27, Safari 27 and its sibling updates patches over 200 CVEs, concentrated in WebKit, the kernel and drivers, and file-sharing/file-system code (SMB, WebDAV, autofs, disk images). The flaws enable universal XSS, root privilege escalation, kernel memory corruption from hostile servers or crafted volumes, Gatekeeper and sandbox bypasses, and arbitrary code execution from images and 3D models.

1
0
2
0
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 2mo ago
3
0
2
0
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 2mo ago
Replying to
@david@voidposter.club Are we rewriting Neuromancer?
1
1
0
0
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 2mo ago
Replying to
@atlovato@mastodon.social not even fired
1
1
0
0
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 2mo ago
Cardiovascular Institute of New England Email Breach Exposes Patient and Employee Data The Cardiovascular Institute of New England disclosed a data breach involving unauthorized access to an email account containing personal, financial, and protected health information belonging to patients and employees. The organization is offering potentially affected individuals complimentary credit monitoring and identity restoration services through Epiq. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/cardiovascular-institute-of-new-england-email-breach-exposes-patient-and-employee-data-e-e-4-0-3/gD2P6Ple2L
Cardiovascular Institute of New England Email Breach Exposes Patient and Employee Data
BeyondMachines

Cardiovascular Institute of New England Email Breach Exposes Patient and Employee Data

The Cardiovascular Institute of New England disclosed a data breach involving unauthorized access to an email account containing personal, financial, and protected health information belonging to patients and employees. The organization is offering potentially affected individuals complimentary credit monitoring and identity restoration services through Epiq.

1
0
0
0
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 2mo ago
Nuneaton and Bedworth Borough Council Leaks Voter Data via Email Error Nuneaton and Bedworth Borough Council accidentally leaked the personal details and security codes of 2,900 voters after an administrative error included a link to a sensitive spreadsheet in a mass email. The council has since removed the data, notified the Information Commissioner's Office, and contacted affected residents. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/nuneaton-and-bedworth-borough-council-leaks-voter-data-via-email-error-6-8-a-m-o/gD2P6Ple2L
Nuneaton and Bedworth Borough Council Leaks Voter Data via Email Error
BeyondMachines

Nuneaton and Bedworth Borough Council Leaks Voter Data via Email Error

Nuneaton and Bedworth Borough Council accidentally leaked the personal details and security codes of 2,900 voters after an administrative error included a link to a sensitive spreadsheet in a mass email. The council has since removed the data, notified the Information Commissioner's Office, and contacted affected residents.

1
0
1
0
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 2mo ago

IBM Patches Critical Remote Code Execution and Privilege Escalation Flaws in WebSphere

IBM issued emergency patches for WebSphere Application Server to fix four vulnerabilities, including two critical flaws with CVSS scores of 9.8. These vulnerabilities allow unauthenticated attackers to execute code, escalate privileges, and perform server-side request forgery.

If you run IBM WebSphere Application Server (traditional 8.5 or 9.0) or WebSphere Liberty, plan a quick patch. Update to packs 9.0.5.29 or 8.5.5.31 for traditional WebSphere, or upgrade Liberty to 26.0.0.9. WebSphere systems may be exposed to the internet by design, so prioritize those systems. #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/ibm-patches-critical-remote-code-execution-and-privilege-escalation-flaws-in-websphere-7-h-7-4-3/gD2P6Ple2L

IBM Patches Critical Remote Code Execution and Privilege Escalation Flaws in WebSphere
BeyondMachines

IBM Patches Critical Remote Code Execution and Privilege Escalation Flaws in WebSphere

IBM issued emergency patches for WebSphere Application Server to fix four vulnerabilities, including two critical flaws with CVSS scores of 9.8. These vulnerabilities allow unauthenticated attackers to execute code, escalate privileges, and perform server-side request forgery.

1
0
0
0
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 2mo ago

GitLab Remote Code Execution Chain Exploits Long-Standing Memory Flaws in Oj Parser

GitLab patched a critical remote code execution chain involving two memory corruption flaws in the Oj Ruby JSON parser that allow authenticated users to take over servers via malicious Jupyter notebook diffs.

If you run self-managed GitLab, upgrade immediately to version 18.10.8, 18.11.5, or 19.0.2. There's a working exploit published and any user who can push code to a project can take over the server. If you're on version 15.2 through 18.9, those are no longer supported and won't get a patch, so you must move to a supported release to be protected. #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/gitlab-remote-code-execution-chain-exploits-long-standing-memory-flaws-in-oj-parser-q-z-g-i-b/gD2P6Ple2L

GitLab Remote Code Execution Chain Exploits Long-Standing Memory Flaws in Oj Parser
BeyondMachines

GitLab Remote Code Execution Chain Exploits Long-Standing Memory Flaws in Oj Parser

GitLab patched a critical remote code execution chain involving two memory corruption flaws in the Oj Ruby JSON parser that allow authenticated users to take over servers via malicious Jupyter notebook diffs.

1
0
0
0
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 2mo ago
Tribeca Film Festival Leaks Contact Details of Hollywood Elite in Database Misconfiguration The Tribeca Film Festival exposed over 666,000 records, including the private contact details of A-list celebrities, due to misconfigured databases that lacked password protection. The leak included email addresses, phone numbers, and device information, which could be used for targeted phishing and social engineering attacks. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/tribeca-film-festival-leaks-contact-details-of-hollywood-elite-in-database-misconfiguration-n-l-x-w-t/gD2P6Ple2L
Tribeca Film Festival Leaks Contact Details of Hollywood Elite in Database Misconfiguration
BeyondMachines

Tribeca Film Festival Leaks Contact Details of Hollywood Elite in Database Misconfiguration

The Tribeca Film Festival exposed over 666,000 records, including the private contact details of A-list celebrities, due to misconfigured databases that lacked password protection. The leak included email addresses, phone numbers, and device information, which could be used for targeted phishing and social engineering attacks.

1
0
0
0
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 2w ago
ShinyHunters Breaches Clop Ransomware Leak Site in Retaliatory Cyberattack ShinyHunters breached and defaced the Clop ransomware gang's leak site by exploiting a Grav CMS file upload vulnerability, allegedly stealing Tor private keys and system logs. The attack is a retaliatory move in an ongoing feud over a stolen Oracle E-Business Suite exploit. **** #cybersecurity #infosec #incident #ransomware https://beyondmachines.net/event_details/shinyhunters-breaches-clop-ransomware-leak-site-in-retaliatory-cyberattack-5-m-2-7-h/gD2P6Ple2L
ShinyHunters Breaches Clop Ransomware Leak Site in Retaliatory Cyberattack
BeyondMachines

ShinyHunters Breaches Clop Ransomware Leak Site in Retaliatory Cyberattack

ShinyHunters breached and defaced the Clop ransomware gang's leak site by exploiting a Grav CMS file upload vulnerability, allegedly stealing Tor private keys and system logs. The attack is a retaliatory move in an ongoing feud over a stolen Oracle E-Business Suite exploit.

0
0
0
0
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 2w ago

Critical Arbitrary File Upload Flaw in Gravity Forms Leads to Remote Code Execution

Gravity Forms patched a critical vulnerability (CVE-2026-84434) that allows unauthenticated attackers to upload executable files and gain remote code execution.

If you use Gravity Forms on WordPress, update it to version 3.1.1 or later ASAP. If you can't update immediately, disable file upload fields on any public forms, then check your upload folders for unexpected PHP files and your logs for suspicious activity. #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/critical-arbitrary-file-upload-flaw-in-gravity-forms-leads-to-remote-code-execution-3-5-o-c-z/gD2P6Ple2L

Critical Arbitrary File Upload Flaw in Gravity Forms Leads to Remote Code Execution
BeyondMachines

Critical Arbitrary File Upload Flaw in Gravity Forms Leads to Remote Code Execution

Gravity Forms patched a critical vulnerability (CVE-2026-84434) that allows unauthenticated attackers to upload executable files and gain remote code execution.

0
0
0
0
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 2w ago

WSO2 Warns of Active Exploitation Targeting Critical Authentication Bypass

WSO2 is warning of active exploitation of a critical authentication bypass vulnerability (CVE-2026-5430) that allows attackers to take over administrative accounts and steal sensitive API credentials. The flaw affects multiple middleware products and has been targeted in the wild since mid-September 2026.

If you run WSO2 API Manager, API Control Plane, Traffic Manager, or Universal Gateway, check for affected versions and patch immediately to the latest update level from WSO2. If you are using open source version apply the public GitHub fix. Attackers are already using forged tokens to gain full admin access. After patching, assume your secrets were exposed and rotate all API keys, backend credentials, consumer keys, and application secrets, and check your logs for suspicious access since September 13, 2026. #cybersecurity #infosec #attack #activeexploit https://beyondmachines.net/event_details/wso2-warns-of-active-exploitation-targeting-critical-authentication-bypass-6-5-6-k-k/gD2P6Ple2L

WSO2 Warns of Active Exploitation Targeting Critical Authentication Bypass
BeyondMachines

WSO2 Warns of Active Exploitation Targeting Critical Authentication Bypass

WSO2 is warning of active exploitation of a critical authentication bypass vulnerability (CVE-2026-5430) that allows attackers to take over administrative accounts and steal sensitive API credentials. The flaw affects multiple middleware products and has been targeted in the wild since mid-September 2026.

0
0
0
0
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 2mo ago
Michigan Surgical Center Reports Data Breach Following Ransomware Claims by The Gentlemen Group Michigan Surgical Center LLC disclosed a data breach on July 17, 2026, following ransomware claims by "The Gentlemen" group. The center is offering 24 months of free credit monitoring to affected individuals while investigating the extent of the unauthorized access. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/michigan-surgical-center-reports-data-breach-following-ransomware-claims-by-the-gentlemen-group-0-w-a-j-3/gD2P6Ple2L
Michigan Surgical Center Reports Data Breach Following Ransomware Claims by The Gentlemen Group
BeyondMachines

Michigan Surgical Center Reports Data Breach Following Ransomware Claims by The Gentlemen Group

Michigan Surgical Center LLC disclosed a data breach on July 17, 2026, following ransomware claims by "The Gentlemen" group. The center is offering 24 months of free credit monitoring to affected individuals while investigating the extent of the unauthorized access.

0
0
0
0
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 2mo ago

Veeam Patches Critical Credential Theft and RCE Flaws in Service Provider Console

Veeam patched four vulnerabilities in its Service Provider Console, including critical flaws (CVE-2026-58073 and CVE-2026-58072) that allow unauthenticated credential theft and remote code execution.

If you run Veeam Service Provider Console version 9.2.1.33875 or any earlier version 9 build, upgrade to version 9.3.0.35057 ASAP. These flaws let attackers take over the console that controls all of your customers' backups. Make sure to lock down the management portal so it's only reachable from a small list of trusted IP addresses, not the open internet. #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/veeam-patches-critical-credential-theft-and-rce-flaws-in-service-provider-console-y-k-8-e-6/gD2P6Ple2L

Veeam Patches Critical Credential Theft and RCE Flaws in Service Provider Console
BeyondMachines

Veeam Patches Critical Credential Theft and RCE Flaws in Service Provider Console

Veeam patched four vulnerabilities in its Service Provider Console, including critical flaws (CVE-2026-58073 and CVE-2026-58072) that allow unauthenticated credential theft and remote code execution.

0
0
0
0
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 2mo ago

JetBrains Fixes Critical TeamCity Authentication Bypass Allowing Remote Code Execution

JetBrains patched a critical authentication bypass (CVE-2026-63077) in TeamCity On-Premises that allows unauthenticated remote code execution. The flaw affects all on-premises versions and could lead to a full takeover of CI/CD pipelines.

If you run TeamCity On-Premises, urgently update to version 2025.11.7 or 2026.1.3 to patch CVE-2026-63077. All on-premises versions are vulnerable to a full server takeover. TeamCity Cloud is already patched and needs no action. If you can't update right away, install the security patch plugin (for versions 2017.1 and later) and restrict access to your TeamCity server to trusted internal networks or a VPN. #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/jetbrains-fixes-critical-teamcity-authentication-bypass-allowing-remote-code-execution-c-x-w-3-z/gD2P6Ple2L

beyondmachines.net
0
0
0
0
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 2mo ago
PEAR Ransomware Group Claims Breach of Arkansas Oral Surgery Practice Arkansas Oral & Maxillofacial Surgeons suffered a ransomware attack by the PEAR group, which claims to have stolen 2.1 terabytes of sensitive patient and corporate data. The practice confirmed the breach after an investigation and is now providing credit monitoring services to affected individuals. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/pear-ransomware-group-claims-breach-of-arkansas-oral-surgery-practice-k-d-4-y-9/gD2P6Ple2L
PEAR Ransomware Group Claims Breach of Arkansas Oral Surgery Practice
BeyondMachines

PEAR Ransomware Group Claims Breach of Arkansas Oral Surgery Practice

Arkansas Oral & Maxillofacial Surgeons suffered a ransomware attack by the PEAR group, which claims to have stolen 2.1 terabytes of sensitive patient and corporate data. The practice confirmed the breach after an investigation and is now providing credit monitoring services to affected individuals.

0
0
0
0
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 2mo ago
ShinyHunters Extortion Group Claims Massive Data Theft from Brinks Home Brinks Home suffered a data breach after the ShinyHunters group used a voice phishing attack to compromise a Microsoft Entra account and allegedly steal 4.9 million records from Salesforce and customer support systems. The company has engaged forensics experts and notified law enforcement. The company says its core alarm monitoring services is secure. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/shinyhunters-extortion-group-claims-massive-data-theft-from-brinks-home-y-m-g-2-a/gD2P6Ple2L
ShinyHunters Extortion Group Claims Massive Data Theft from Brinks Home
BeyondMachines

ShinyHunters Extortion Group Claims Massive Data Theft from Brinks Home

Brinks Home suffered a data breach after the ShinyHunters group used a voice phishing attack to compromise a Microsoft Entra account and allegedly steal 4.9 million records from Salesforce and customer support systems. The company has engaged forensics experts and notified law enforcement. The company says its core alarm monitoring services is secure.

0
0
0
0
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 2mo ago
Replying to
@campuscodi@mastodon.social Anthropic is still lying Chrome has more critical flaws EU is still playing lawyer Governments are doing banning as usual, some for good reasons some for less good reasons. The world keeps turning:
0
0
0
0
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 2mo ago
Lies, Damn Lies, Statistics and AI companies Still waiting for their leadership to be summarily fired after admitting to cybercrime.
0
0
0
0
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 2mo ago

State of (in)security - Week 30, 2026

During week 30 of 2026, cybersecurity monitoring recorded 7 advisories and 28 incidents/breaches affecting roughly 80 million individuals. The largest breach is Suno exposing 55.3 million users and AI training source code. Malware/ransomware and unauthorized access are the leading causes of incidents and healthcare and IT/software as the most-targeted industries.

Patch the actively exploited on-premises SharePoint (CVE-2026-50522), self-hosted ServiceNow, Fastjson 1.x Java apps, Oracle systems (July 2026 Critical Patch Update), and WordPress. Then update Firefox and Thunderbird and confirm your Adobe Acrobat Chrome extension is running version 26.5.2.3 or later. #cybersecurity #infosec #knowledge #weeklyreport https://beyondmachines.net/event_details/state-of-in-security-week-30-2026-w-0-e-b-i/gD2P6Ple2L

State of (in)security - Week 30, 2026
BeyondMachines

State of (in)security - Week 30, 2026

During week 30 of 2026, cybersecurity monitoring recorded 7 advisories and 28 incidents/breaches affecting roughly 80 million individuals. The largest breach is Suno exposing 55.3 million users and AI training source code. Malware/ransomware and unauthorized access are the leading causes of incidents and healthcare and IT/software as the most-targeted industries.

0
0
0
0
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 1mo ago
Kiewit Corporation Discloses Data Breach Following Microsoft 365 Account Compromise Kiewit Corporation reported a data breach after an unauthorized party accessed an employee's Microsoft 365 email account, exposing the personal and health information of employees and contractors. The company disabled the account, hired forensic experts, and is offering credit monitoring to the affected individuals. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/kiewit-corporation-discloses-data-breach-following-microsoft-365-account-compromise-p-c-d-8-y/gD2P6Ple2L
Kiewit Corporation Discloses Data Breach Following Microsoft 365 Account Compromise
BeyondMachines

Kiewit Corporation Discloses Data Breach Following Microsoft 365 Account Compromise

Kiewit Corporation reported a data breach after an unauthorized party accessed an employee's Microsoft 365 email account, exposing the personal and health information of employees and contractors. The company disabled the account, hired forensic experts, and is offering credit monitoring to the affected individuals.

0
0
0
0
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 2w ago
CrowdSec Source Code Leak Linked to TanStack npm Supply Chain Attack CrowdSec suffered a source code leak after attackers exploited a TanStack npm supply chain vulnerability to steal a former employee's GitHub credentials. The breach exposed 170 private repositories and personal data for 134 users and investors. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/crowdsec-source-code-leak-linked-to-tanstack-npm-supply-chain-attack-6-u-i-d-6/gD2P6Ple2L
CrowdSec Source Code Leak Linked to TanStack npm Supply Chain Attack
BeyondMachines

CrowdSec Source Code Leak Linked to TanStack npm Supply Chain Attack

CrowdSec suffered a source code leak after attackers exploited a TanStack npm supply chain vulnerability to steal a former employee's GitHub credentials. The breach exposed 170 private repositories and personal data for 134 users and investors.

0
0
0
0
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 1mo ago
MANTRA Chain Restores Block Production After Cosmos-EVM Module Exploit MANTRA Chain resumed operations after a 30-hour halt caused by an attacker exploiting a vulnerability in its Cosmos-EVM module's upstream dependencies. The incident affected two managed wallets but did not compromise user funds. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/mantra-chain-restores-block-production-after-cosmos-evm-module-exploit-z-b-z-7-s/gD2P6Ple2L
MANTRA Chain Restores Block Production After Cosmos-EVM Module Exploit
BeyondMachines

MANTRA Chain Restores Block Production After Cosmos-EVM Module Exploit

MANTRA Chain resumed operations after a 30-hour halt caused by an attacker exploiting a vulnerability in its Cosmos-EVM module's upstream dependencies. The incident affected two managed wallets but did not compromise user funds.

0
0
0
0
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 2mo ago
ExfilSquad Threat Group Steals 742,000 Records from UK Education and Police Databases The UK Department for Education and the Police National Legal Database suffered a data breach involving 742,000 records stolen by the ExfilSquad threat group. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/exfilsquad-threat-group-steals-742000-records-from-uk-education-and-police-databases-j-5-e-8-4/gD2P6Ple2L
ExfilSquad Threat Group Steals 742,000 Records from UK Education and Police Databases
BeyondMachines

ExfilSquad Threat Group Steals 742,000 Records from UK Education and Police Databases

The UK Department for Education and the Police National Legal Database suffered a data breach involving 742,000 records stolen by the ExfilSquad threat group.

0
0
0
0
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 1w ago
Park Place Behavioral Healthcare Data Breach Exposes Personal, Health, and Financial Information Park Place Behavioral Healthcare disclosed a data breach after an unauthorized party accessed its systems and copied files containing personal, health, and financial information. The organization reset account credentials and strengthened remote access controls. Park Place Behavioral Healthcare is offering complimentary credit monitoring and identity theft restoration services to affected individuals. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/park-place-behavioral-healthcare-data-breach-exposes-personal-health-and-financial-information-e-4-z-n-o/gD2P6Ple2L
Park Place Behavioral Healthcare Data Breach Exposes Personal, Health, and Financial Information
BeyondMachines

Park Place Behavioral Healthcare Data Breach Exposes Personal, Health, and Financial Information

Park Place Behavioral Healthcare disclosed a data breach after an unauthorized party accessed its systems and copied files containing personal, health, and financial information. The organization reset account credentials and strengthened remote access controls. Park Place Behavioral Healthcare is offering complimentary credit monitoring and identity theft restoration services to affected individuals.

0
0
0
0
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 1w ago
Vista Del Mar Child and Family Services Reports Data Breach Involving Personal and Health Information Vista Del Mar Child and Family Services disclosed a data breach after an unauthorized actor accessed systems containing personal and protected health information. The organization took its network offline, engaged cybersecurity experts, and is reviewing affected files to identify and notify potentially impacted individuals. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/vista-del-mar-child-and-family-services-reports-data-breach-involving-personal-and-health-information-c-o-8-r-w/gD2P6Ple2L
Vista Del Mar Child and Family Services Reports Data Breach Involving Personal and Health Information
BeyondMachines

Vista Del Mar Child and Family Services Reports Data Breach Involving Personal and Health Information

Vista Del Mar Child and Family Services disclosed a data breach after an unauthorized actor accessed systems containing personal and protected health information. The organization took its network offline, engaged cybersecurity experts, and is reviewing affected files to identify and notify potentially impacted individuals.

0
0
0
0
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 2mo ago

Django Patches High-Severity File-Write Flaw in GeoDjango and Three Other Vulnerabilities

Django 6.0.8 and 5.2.17 are out, fixing four security issues: most urgently a GeoDjango flaw (CVSS 8.8) that lets any staff user with view permission on a spatial-field model trigger SSRF or file writes, potentially leading to remote code execution.

If you run Django, upgrade now to Django 6.0.8 or 5.2.17. If you're on an older unsupported version like 5.1, 5.0 or 4.2, assume you're vulnerable and plan a move to a supported branch. If you use GeoDjango, test your spatial lookups before deploying because the fix intentionally breaks some old behaviour, and check who has staff/view access to models with map or location fields. That level of access is all an attacker needs for the most serious flaw. #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/django-patches-high-severity-file-write-flaw-in-geodjango-and-three-other-vulnerabilities-d-x-1-q-e/gD2P6Ple2L

Django Patches High-Severity File-Write Flaw in GeoDjango and Three Other Vulnerabilities
BeyondMachines

Django Patches High-Severity File-Write Flaw in GeoDjango and Three Other Vulnerabilities

Django 6.0.8 and 5.2.17 are out, fixing four security issues: most urgently a GeoDjango flaw (CVSS 8.8) that lets any staff user with view permission on a spatial-field model trigger SSRF or file writes, potentially leading to remote code execution.

0
0
0
0
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 2w ago
Alliance Environmental Group LLC Reports Cyberattack, Data Breach Alliance Environmental Group LLC reported a data breach involving unauthorized network access between April and May 2026, resulting in the acquisition of files containing names and other personal information. The company has secured its systems and is providing credit monitoring services to affected individuals. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/alliance-environmental-group-llc-reports-cyberattack-data-breach-j-2-j-x-2/gD2P6Ple2L
Alliance Environmental Group LLC Reports Cyberattack, Data Breach
BeyondMachines

Alliance Environmental Group LLC Reports Cyberattack, Data Breach

Alliance Environmental Group LLC reported a data breach involving unauthorized network access between April and May 2026, resulting in the acquisition of files containing names and other personal information. The company has secured its systems and is providing credit monitoring services to affected individuals.

0
0
0
0
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 2mo ago
Replying to
@sigi714@ruhr.social oh so very true https://x.com/_AlexHirsch/status/2083268104742924484
Alex Hirsch (@_AlexHirsch) on X
X (formerly Twitter)

Alex Hirsch (@_AlexHirsch) on X

@sama What if you just talked to your children

0
0
0
0
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 2mo ago
CHAOS Ransomware Group Claims Data Theft from Radia Inc. The CHAOS ransomware group claims to have stolen 655 gigabytes of sensitive data from Radia Inc., P.S., including patient medical records, corporate financial documents, and employee payroll information. Radia Inc. has not officially confirmed the breach or filed notifications with federal health authorities. **** #cybersecurity #infosec #incident #ransomware https://beyondmachines.net/event_details/chaos-ransomware-group-claims-data-theft-from-radia-inc-5-f-v-v-y/gD2P6Ple2L
CHAOS Ransomware Group Claims Data Theft from Radia Inc.
BeyondMachines

CHAOS Ransomware Group Claims Data Theft from Radia Inc.

The CHAOS ransomware group claims to have stolen 655 gigabytes of sensitive data from Radia Inc., P.S., including patient medical records, corporate financial documents, and employee payroll information. Radia Inc. has not officially confirmed the breach or filed notifications with federal health authorities.

0
0
0
0
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 2mo ago

Arista Patches Critical VeloCloud Orchestrator Zero-Day Under Active Attack

Arista Networks released an emergency advisory for a CVSS 10.0 OS command injection vulnerability in VeloCloud Orchestrator On-Prem that is currently being exploited in the wild. The flaw allows unauthenticated attackers to gain full control over the orchestrator and all managed SD-WAN edge devices.

Make sure all VeloCloud Orchestrator On-Prem devices are isolated from the internet and accessible only from trusted administrative networks. Then immediately upgrade to a fixed release (5.2.3.14, 6.1.3.4, 6.4.2.4, or 7.0.0.1) and block the known malicious IPs (8.19.75.217, 206.72.242.124, 206.72.242.162) at your firewall. After patching rotate all credentials and certificates so attackers can't reuse any potentially stolen data. #cybersecurity #infosec #attack #activeexploit https://beyondmachines.net/event_details/arista-patches-critical-velocloud-orchestrator-zero-day-under-active-attack-x-b-e-7-y/gD2P6Ple2L

Arista Patches Critical VeloCloud Orchestrator Zero-Day Under Active Attack
BeyondMachines

Arista Patches Critical VeloCloud Orchestrator Zero-Day Under Active Attack

Arista Networks released an emergency advisory for a CVSS 10.0 OS command injection vulnerability in VeloCloud Orchestrator On-Prem that is currently being exploited in the wild. The flaw allows unauthenticated attackers to gain full control over the orchestrator and all managed SD-WAN edge devices.

0
0
0
0
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 1w ago
CTOS Digital Discloses Unauthorized Access to Consumer Business Environment CTOS Digital disclosed unauthorized access to an environment supporting its consumer business, where a limited subset of processed consumer information was accessed. The company contained the incident, notified authorities, and temporarily disrupted some credit reporting services while an independent forensic investigation continues. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/ctos-digital-discloses-unauthorized-access-to-consumer-business-environment-1-g-4-n-s/gD2P6Ple2L
CTOS Digital Discloses Unauthorized Access to Consumer Business Environment
BeyondMachines

CTOS Digital Discloses Unauthorized Access to Consumer Business Environment

CTOS Digital disclosed unauthorized access to an environment supporting its consumer business, where a limited subset of processed consumer information was accessed. The company contained the incident, notified authorities, and temporarily disrupted some credit reporting services while an independent forensic investigation continues.

0
0
0
0
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 1w ago

Arista Networks Patches Critical VeloCloud Orchestrator Zero-Day Exploited in the Wild

Arista Networks disclosed a critical CVSS 10.0 vulnerability (CVE-2026-93952) in VeloCloud Orchestrator On-Prem that is being actively exploited to gain unauthenticated remote access to orchestrator hosts and managed edge devices.

If you run VeloCloud Orchestrator On-Prem, this is urgent. Make sure its web interface is not reachable from the internet and is accessible only from trusted admin networks, then update right away to a fixed version (5.2.3.16, 6.4.2.8 or later). Attackers are already using this flaw to take full control without any password. After patching, look for the hidden file /usr/local/sbin/.vcnode.js or the x-vc-opt header in your web logs, and if you find either, treat the orchestrator and every connected Edge device as compromised. #cybersecurity #infosec #attack #activeexploit https://beyondmachines.net/event_details/arista-networks-patches-critical-velocloud-orchestrator-zero-day-exploited-in-the-wild-4-k-v-7-w/gD2P6Ple2L

Arista Networks Patches Critical VeloCloud Orchestrator Zero-Day Exploited in the Wild
BeyondMachines

Arista Networks Patches Critical VeloCloud Orchestrator Zero-Day Exploited in the Wild

Arista Networks disclosed a critical CVSS 10.0 vulnerability (CVE-2026-93952) in VeloCloud Orchestrator On-Prem that is being actively exploited to gain unauthenticated remote access to orchestrator hosts and managed edge devices.

0
0
0
0
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 1mo ago

SonicWall Patches Chained Zero-Day Vulnerabilities in SMA 1000 Series VPNs

SonicWall has patched two zero-day vulnerabilities (CVE-2026-83548 and CVE-2026-83549) in its SMA 1000 series VPN appliances that attackers are chaining to achieve unauthenticated remote code execution.

If you run SonicWall SMA 1000 appliances (models 6210, 7210, or 8200v), update immediately to version 12.4.3-03526 or 12.5.0-02952. These devices are actively attacked to take over VPN gateways. After patching review your logs for signs of compromise, if anything looks suspicious, re-image the appliance, change all passwords and reset TOTP tokens, and only restore backups from before the breach. #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/sonicwall-patches-chained-zero-day-vulnerabilities-in-sma-1000-series-vpns-k-n-b-f-y/gD2P6Ple2L

SonicWall Patches Chained Zero-Day Vulnerabilities in SMA 1000 Series VPNs
BeyondMachines

SonicWall Patches Chained Zero-Day Vulnerabilities in SMA 1000 Series VPNs

SonicWall has patched two zero-day vulnerabilities (CVE-2026-83548 and CVE-2026-83549) in its SMA 1000 series VPN appliances that attackers are chaining to achieve unauthenticated remote code execution.

0
0
0
0
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 2mo ago
Liechtenstein Beneficial Ownership Register Breached, 31,000 Entities Exposed Liechtenstein's national register of beneficial owners (VwbP) used for anti-money laundering suffered a data breach on July 30, 2026, exposing the identity and ownership details of approximately 31,000 legal entities. A government crisis team is investigating the breach. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/liechtenstein-beneficial-ownership-register-breached-31000-entities-exposed-y-t-1-h-9/gD2P6Ple2L
Liechtenstein Beneficial Ownership Register Breached, 31,000 Entities Exposed
BeyondMachines

Liechtenstein Beneficial Ownership Register Breached, 31,000 Entities Exposed

Liechtenstein's national register of beneficial owners (VwbP) used for anti-money laundering suffered a data breach on July 30, 2026, exposing the identity and ownership details of approximately 31,000 legal entities. A government crisis team is investigating the breach.

0
0
0
0
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 2mo ago

Metabase Patches Critical Zero-Day SQL Injection Exploited in the Wild

Metabase patched a critical zero-day SQL injection vulnerability (GHSA-vwf4-m7j8-wcjf, CVSS 10.0) that is actively exploited to gain administrator access and steal database credentials.

If you run self-hosted Metabase (version 1.58 or newer), this is urgent. Your Metabase is under attack. Update immediately to the patched release for your branch (0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, or 0.63.5). if you can't patch right now, block all traffic to the /api/session/reset_password endpoint as a stopgap. After patching, check your application and ingress logs for a failed password-reset POST followed straight away by a successful /api/user/current request. Tf you see it, treat the instance as breached: clear the core_session table to log everyone out, rotate all connected database passwords, and check your admin accounts for anything you didn't create. #cybersecurity #infosec #attack #activeexploit https://beyondmachines.net/event_details/metabase-patches-critical-zero-day-sql-injection-exploited-in-the-wild-g-o-s-u-u/gD2P6Ple2L

Metabase Patches Critical Zero-Day SQL Injection Exploited in the Wild
BeyondMachines

Metabase Patches Critical Zero-Day SQL Injection Exploited in the Wild

Metabase patched a critical zero-day SQL injection vulnerability (GHSA-vwf4-m7j8-wcjf, CVSS 10.0) that is actively exploited to gain administrator access and steal database credentials.

0
0
0
0
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 2w ago
BigCommerce Data Breach Linked to Compromised Ribon App Keys Attackers used compromised Ribon application keys to access customer records and inject malicious scripts into BigCommerce storefronts. The breach exposed personal information including names, contact details, and addresses, but not passwords or payment card data. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/bigcommerce-data-breach-linked-to-compromised-ribon-app-keys-a-u-4-1-d/gD2P6Ple2L
BigCommerce Data Breach Linked to Compromised Ribon App Keys
BeyondMachines

BigCommerce Data Breach Linked to Compromised Ribon App Keys

Attackers used compromised Ribon application keys to access customer records and inject malicious scripts into BigCommerce storefronts. The breach exposed personal information including names, contact details, and addresses, but not passwords or payment card data.

0
0
0
0
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 2mo ago
Oak Hill Data Breach Exposes Sensitive Information of 1,556 Individuals The Connecticut Institute for the Blind, dba Oak Hill, disclosed a data breach affecting 1,556 individuals after unauthorized actors gained access to network accounts and servers. The incident, detected in October 2025, exposed sensitive medical, financial, and personal information, leading to a federal report and the provision of credit monitoring services. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/oak-hill-data-breach-exposes-sensitive-information-of-1556-individuals-k-1-a-d-t/gD2P6Ple2L
Oak Hill Data Breach Exposes Sensitive Information of 1,556 Individuals
BeyondMachines

Oak Hill Data Breach Exposes Sensitive Information of 1,556 Individuals

The Connecticut Institute for the Blind, dba Oak Hill, disclosed a data breach affecting 1,556 individuals after unauthorized actors gained access to network accounts and servers. The incident, detected in October 2025, exposed sensitive medical, financial, and personal information, leading to a federal report and the provision of credit monitoring services.

0
0
0
0
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 2mo ago

CISA Warns of Active Exploitation in Fortinet FortiOS SSL-VPN Patch Bypass

CISA reports active explotation of CVE-2025-68686, a flaw in Fortinet FortiOS that allows attackers to bypass security patches and maintain persistent access on compromised devices.

If you use Fortinet devices, make sure they are isolated from the internet and accessible only from trusted networks. Then update FortiOS ASAP to version 7.6.2, 7.4.7, or later. This flaw is combined with others, so make sure all your Fortinet devices are up-to-date. And check your devices for indicators of compromise, this flaw allowed hackers to maintain access over patch cycles. #cybersecurity #infosec #attack #activeexploit https://beyondmachines.net/event_details/cisa-warns-of-active-exploitation-in-fortinet-fortios-ssl-vpn-patch-bypass-h-6-5-r-8/gD2P6Ple2L

CISA Warns of Active Exploitation in Fortinet FortiOS SSL-VPN Patch Bypass
BeyondMachines

CISA Warns of Active Exploitation in Fortinet FortiOS SSL-VPN Patch Bypass

CISA reports active explotation of CVE-2025-68686, a flaw in Fortinet FortiOS that allows attackers to bypass security patches and maintain persistent access on compromised devices.

0
0
0
0
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 2mo ago
Handala Hacktivist Group Claims Disruption on SupraNet The Iranian-linked threat actor Handala claimed a disruptive cyberattack against SupraNet Communications, causing widespread internet outages for thousands of businesses and government entities in Wisconsin. **** #cybersecurity #infosec #incident #vulnerability https://beyondmachines.net/event_details/handala-hacktivist-group-claims-disruption-on-supranet-8-r-c-l-0/gD2P6Ple2L
Handala Hacktivist Group Claims Disruption on SupraNet
BeyondMachines

Handala Hacktivist Group Claims Disruption on SupraNet

The Iranian-linked threat actor Handala claimed a disruptive cyberattack against SupraNet Communications, causing widespread internet outages for thousands of businesses and government entities in Wisconsin.

0
0
0
0
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 2mo ago
Toss a coin to your trillionaire
0
1
0
0
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 2mo ago
Lifespark Management Services Discloses Email Data Breach Involving Personal and Health Information Lifespark Management Services disclosed a data breach after an unauthorized party accessed information within its email environment, potentially exposing personal, financial, and protected health information. The company detected suspicious activity in February 2026, hired third-party forensic specialists, and published a data breach notice in July. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/lifespark-management-services-discloses-email-data-breach-involving-personal-and-health-information-u-a-9-1-p/gD2P6Ple2L
beyondmachines.net
0
0
0
0
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 2mo ago

N-able Patches Critical N-central Authentication Bypass Exploited in the Wild

N-able issued an emergency hotfix for N-central after attackers bypassed previous patches to gain administrative control over MSP servers. The flaw allows remote actors to hijack managed endpoints and establish persistent access via Cloudflare tunnels.

If you are using N-able N-central, this is urgent. Upgrade immediately to version 2026.3.1.7. Attackers are already exploiting the product to take over admin accounts on both on-premises and cloud-hosted servers. After patching, run N-able's provided scan templates on your Windows endpoints to check for signs of compromise (especially unexpected Cloudflare tunnel services), turn on multi-factor authentication, and review all user accounts and policy changes for anything you didn't make yourself. #cybersecurity #infosec #attack #activeexploit https://beyondmachines.net/event_details/n-able-patches-critical-n-central-authentication-bypass-exploited-in-the-wild-7-r-o-r-u/gD2P6Ple2L

N-able Patches Critical N-central Authentication Bypass Exploited in the Wild
BeyondMachines

N-able Patches Critical N-central Authentication Bypass Exploited in the Wild

N-able issued an emergency hotfix for N-central after attackers bypassed previous patches to gain administrative control over MSP servers. The flaw allows remote actors to hijack managed endpoints and establish persistent access via Cloudflare tunnels.

0
0
0
0
Open post
BeyondMachines :verified: @beyondmachines1@infosec.exchange
· 2mo ago
Redtail Technology Social Engineering Attack Compromises Financial Client Data Redtail Technology suffered a data breach in May 2026 after a social engineering attack against an employee allowed an unauthorized actor to steal client data belonging to J.W. Cole Advisors. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/redtail-technology-social-engineering-attack-compromises-financial-client-data-9-3-4-i-r/gD2P6Ple2L
Redtail Technology Social Engineering Attack Compromises Financial Client Data
BeyondMachines

Redtail Technology Social Engineering Attack Compromises Financial Client Data

Redtail Technology suffered a data breach in May 2026 after a social engineering attack against an employee allowed an unauthorized actor to steal client data belonging to J.W. Cole Advisors.

0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 07:28:05 UTC