Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

dilshad

@dilshad@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange
0 Followers
0 Following
3 Posts
Joined July 14, 2026
Open post
dilshad @dilshad@infosec.exchange
· 2mo ago
FortiBleed credentials came out of FortiGate config backups, not a device exploit. The old-password field keeps the previous SHA-256 hash inside the config even after the PBKDF2 upgrade. Invisible in the UI, present in any super_admin backup. https://darkwiser.com/blog/how-86-644-fortigate-credentials-were-stolen-and-sold
darkwiser.com
0
0
0
0
Open post
dilshad @dilshad@infosec.exchange
· 2mo ago
Zero to owned: Credential stealer to corporate breach The breach doesn't start with your infrastructure. It starts on a device you don't control. One dataset of 15 million infostealer logs held 687 million cookies, 43.87 million of them still active session tokens that hand over an account without ever tripping MFA. Your second factor doesn't matter if the attacker inherits the session. https://darkwiser.com/blog/zero-to-owned-mapping-the-lifecycle-of-a-credential-stealer-to-corporate-breach #Infostealer #SessionHijacking #MFA #CredentialTheft #dark_web
Zero to Owned Mapping the Lifecycle of a Credential Stealer to Corporate Breach
DarkWiser

Zero to Owned Mapping the Lifecycle of a Credential Stealer to Corporate Breach

Zero to Owned Mapping the Lifecycle of a Credential Stealer to Corporate Breach

0
0
0
0
Open post
dilshad @dilshad@infosec.exchange
· 2mo ago
NPM account takeovers via expired maintainer domains You don't need to exploit npm to poison it. Buy the expired email domain behind a maintainer's account, reset the password, and the package is yours. We scanned 2.1 million packages, extracted 6.7 million maintainer emails, and found 675 expired domains leaving 2,843 packages open to takeover. Those packages sit under 257,000+ dependent repos and 93,000 downstream packages. One lapsed domain renewal, a supply chain full of blast radius. https://laburity.com/research-npm-account-takeovers/ #SupplyChainSecurity #npm #AccountTakeover #AppSec #Laburity
laburity.com
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 21:33:08 UTC