search
cybersecurity community
Trends
- 1Italian cyber briefing rounds up daily security news●☕ CYBERBRIEFING MATTUTINO — Mercoledì 30 settembre 2026 👉 Leggi tutti gli aggiornamenti delle ultime 24 ore: https:// il
A morning cybersecurity briefing dated Wednesday, September 30, 2026, has been published via Il Punto Cyber, an Italian newsletter aggregating the past 24 hours of security updates. The roundup, shared by the Italian tech community account poliversity.it, collects links and summaries of recent cybersecurity developments for Italian-speaking readers.
- 2Cloudflare launches free agentic threat intelligence tooling▼Introducing Threat Signals: agentic skills for open-source threat intelligence, free for every Cloudflare account
Cloudflare has introduced Threat Signals, a set of agentic skills for open-source threat intelligence that the company says will be free for every Cloudflare account. The announcement, made on the Cloudflare blog, positions the tooling as a way for customers of all sizes to tap into threat intelligence capabilities without additional cost. Reaction so far has focused on the free availability and the use of agentic AI in security operations.
- 3Fake Exodus wallet support page flagged as phishing site▼Possible Phishing 🎣 on: ⚠️hxxps[:]//exodus-help-wlt-chiky[.]wasmer[.]app 🧬 Analysis at: https:// urldna.io/scan/6abc910c
Cybersecurity researchers are warning about a phishing site impersonating Exodus wallet support, hosted at exodus-help-wlt-chiky.wasmer.app. The domain was defanged and shared with a link to a URLDNA analysis so others can inspect it. The site follows a common pattern of fraudulent crypto wallet help pages designed to steal users' seed phrases or credentials.
- 4New Cross-Platform Attack Tracks Users Without Elevated Privileges●New Attack Can Track You Across Operating Systems Without Elevated Privileges https://www. privacyguides.org/news/2026/0
Privacy Guides reports a newly disclosed attack capable of tracking users across different operating systems, including Linux, Windows, macOS, Android and iOS, without requiring elevated privileges. The finding is drawing attention in cybersecurity and privacy communities, where users are discussing what the technique means for device tracking and how effectively current system protections can defend against it.
- 5Security Researchers Flag Possible Phishing Site on Weebly▼Possible Phishing 🎣 on: ⚠️hxxps[:]//nnbxv[.]weebly[.]com 🧬 Analysis at: https:// urldna.io/scan/6abc7b5a3b77500 00653a6c
Cybersecurity observers are warning about a suspected phishing page hosted at a Weebly web address, sharing a link to a detailed technical analysis of the site on the URLDNA scanning platform. The address has been defanged to prevent accidental clicks. The warning is being circulated in information security communities alongside standard scam and phishing alert tags.
- 6Two Critical Citrix NetScaler Zero-Days Exploited in the Wild●⚠️ CRITICAL: Dual NetScaler Zero-Days Trigger Chaos for Citrix Customers Two critical zero-day vulnerabilities in Citrix
Security researchers report two critical zero-day vulnerabilities in Citrix NetScaler that are being actively exploited. Attackers can gain broad network access on affected systems, with default configurations said to be especially exposed. Citrix customers are urged to check their appliances and apply mitigations immediately as details of the flaws spread through the cybersecurity community.
- 7
Visa has released an AI-powered cyber defence tool as open source, making the technology freely available to security teams and developers outside the company. The move lets organisations inspect, adapt and deploy the tool in their own fraud and threat-detection systems, and is being covered by technology publications as a notable example of a major payments company sharing proprietary security software with the wider community.
- 8CrowdSec typo leaves cybersecurity user embarrassed●Wanted to type @ CrowdSec into my browser and ended up with crowdsex. Don’t judge me! # InfoSec
A user in the infosec community shared a slip of the fingers while trying to visit the website of CrowdSec, a cybersecurity company, accidentally landing on a lookalike address reading 'crowdsex' instead. The anecdote was shared lightheartedly, inviting others not to judge, and highlights how easily security-related domain names can be mistyped.
- 9Jakarta IP flagged for exploiting known CVEs●🕵️ 𝗜𝗣 𝗰𝗵𝗲𝗹𝗼𝘂 𝗱𝘂 𝗷𝗼𝘂𝗿 🕵️ **Fiche : "Le Brocanteur de CVEs de Jakarta"** 📍 103.63.101.24 | AS150273 🇮🇩 🔫 5 frappes : Think
A cybersecurity observer has published a profile of IP address 103.63.101.24, hosted on Indonesian network AS150273 in Jakarta, dubbing it 'the CVE broker of Jakarta'. The address is said to have launched five attacks targeting known flaws in ThinkPHP, PHPUnit's eval-stdin, and Apache path traversal vulnerabilities CVE-2021-41773 and CVE-2021-42013, using the libredtail-http user agent and encoded traversal sequences seeking a shell.
- 10Security researchers flag possible phishing site on weebly.com▼Possible Phishing 🎣 on: ⚠️hxxps[:]//general-trading[.]weebly[.]com 🧬 Analysis at: https:// urldna.io/scan/6abc66db3b7750
Cybersecurity observers are warning about a suspected phishing page hosted at general-trading.weebly.com, sharing the address in defanged form so others do not accidentally visit it. A technical scan of the URL has been published on urldna.io for analysts to review. The alerts are circulating in infosec communities with tags for phishing, scams and general cybersecurity awareness.
- 11New CVE issued for U-Boot bootloader●CVE Alert: CVE-2026-74222 - u-boot - u-boot - https://www. redpacketsecurity.com/cve-aler t-cve-2026-74222-u-boot-u-boot
A new vulnerability identifier, CVE-2026-74222, has been published concerning U-Boot, the widely used open-source bootloader for embedded systems. Threat-intelligence feeds are circulating the alert, though technical details about the flaw, its severity, and affected versions remain sparse in initial reporting. Security teams monitoring U-Boot deployments are advised to track the advisory for updates as more information becomes available.
- 12Fake Wells Fargo login page flagged as phishing site▼Possible Phishing 🎣 on: ⚠️hxxps[:]//sites[.]google[.]com/view/wellsfargologinu 🧬 Analysis at: https:// urldna.io/scan/6a
Security researchers are flagging a fraudulent Wells Fargo login page hosted on a Google Sites address, designed to steal customers' banking credentials. The link has been defanged to prevent accidental clicks, and a public scan on URLDNA lets others inspect the site's characteristics. The warning has circulated among infosec community members tracking phishing campaigns.
- 13Newly exposed host spotted in Fremont data centre●ASN: 63949 Location: Fremont, US Added: 2026-09-29T13:59 # shodansafari # infosec
Security researchers are flagging an internet-facing host registered to ASN 63949, a network range operated by Linode in Fremont, California, that was indexed on 29 September 2026. The finding circulated in information security circles under the shodansafari hashtag, where practitioners share and discuss newly exposed servers, open ports and misconfigured devices discovered through internet-wide scanning.
- 14Security researchers flag phishing site hosted on Weebly▼Possible Phishing 🎣 on: ⚠️hxxps[:]//esnetdeskfreenetserverservicesdkx[.]weebly[.]com 🧬 Analysis at: https:// urldna.io/s
Cybersecurity researchers are warning about a possible phishing site operating through a Weebly-hosted page that impersonates network or helpdesk services. The suspicious link has been defused and shared with a technical analysis via urldna.io so that other security professionals can inspect the domain and its infrastructure. The report has circulated in infosec communities, which frequently post such alerts to warn the public about scam pages before they spread more widely.
- 15Critical CVSS 10 flaw CVE-2026-71379 allows unauthenticated data export●🚨 CVE-2026-71379 — CVSS 10 CRITICAL The file export endpoint allows any unauthenticated attacker to export arbitrary dat
A vulnerability tracked as CVE-2026-71379, rated CVSS 10, is drawing attention in the cybersecurity community. The flaw lies in a file export endpoint that lets any unauthenticated attacker export arbitrary database tables via a crafted POST request. Security feeds are flagging it as maximum-severity, urging organizations to check whether their systems are affected and patch promptly.
- 16Google warns hackers are using AI agents for attacks●"Google Threat Intelligence Group reported this week that it has observed adversaries moving beyond basic prompting into
Google Threat Intelligence Group reported this week that adversaries are moving beyond basic prompting into agentic workflows and AI-enabled automation. The finding suggests cyber attackers are now deploying autonomous AI systems to carry out parts of their operations, not just relying on simple AI queries. Security professionals are sharing the report as a signal that AI-driven threats are escalating.
- 17BSidesVI cybersecurity conference wraps up with community thanks▼But most of all… Thank you to everyone who showed up. BSidesVI isn’t a corporation putting on a conference. It’s a commu
Organisers of BSidesVI, a community-run cybersecurity conference in the US Virgin Islands, have thanked attendees for turning out, stressing that the event is built by a community of security professionals rather than a corporation. They described Friday's gathering as a strong showing of people who care about the industry coming together to build something themselves.
- 18Security Researchers Flag Phishing Site Hosted on Google Sites▼Possible Phishing 🎣 on: ⚠️hxxps[:]//sites[.]google[.]com/view/oiuiruieor98490krejjkljklejkef/home 🧬 Analysis at: https:/
Cybersecurity researchers are warning about a phishing page hosted on Google Sites, sharing a defanged link and a scan report on urlDNA for analysis. The alerts circulated in infosec channels, with warnings that the site is designed to deceive visitors into handing over credentials or personal data. The use of a legitimate Google domain highlights how attackers exploit trusted hosting services.