Seeing a full end to end framework come to life is something spectacular. Embedding automation and AI from the ground up to help triage incoming content I’m hoping will streamline activities that were originally very time consuming.
Jack
@jack.overresearched.net
Software dev, security manager, and omitter of the Oxford comma Blog: https://blog.overresearched.net/?m=1 Threat intelligence site: https://intel.overresearched.net Operator of: https://bsky.app/profile/intel.overresearched.net
🔴 PAN-OS CVE-2026-0300 0day exploited since 9 Apr (CL-STA-1132) 🔴 Linux LPEs: Copy Fail + Dirty Frag 🔴 Ivanti EPMM 0day — CISA 4-day directive 🔴 Mini Shai-Hulud npm worm intel.overresearched.net/2026/05/11/c... #Weekly #ThreatIntel
CTI Weekly Brief: 4 May to 10 May 2026 - PAN-OS Zero-Day Exploited In-the-Wild, Linux Kernel Page-Cache Bugs Chain to Root, npm Supply Chain Worm Hits Intercom SDK
Weekly intelligence covering 559 reports across the pipeline: state-sponsored exploitation of PAN-OS CVE-2026-0300, two unpatched Linux LPE chains (Copy Fail and Dirty Frag), Ivanti EPMM zero-day unde...
intel.overresearched.net
- Mr_Rot13 mass-exploits cPanel CVE-2026-41940 (CVSS 9.8) - ShinyHunters extort Instructure Canvas via XSS - Linux 'Dirty Frag' CVE-2026-43284/-43500: PoC public, no patch Full brief: intel.overresearched.net/2026/05/11/c... #Daily #ThreatIntel #InfoSec
CTI Daily Brief: 2026-05-10 — Mr_Rot13 weaponises critical cPanel flaw (CVE-2026-41940); ShinyHunters extort Instructure via Canvas XSS; Linux ‘Dirty Frag’ container-escape exploit goes public
Mr_Rot13 (a six-year-old crew) actively exploits CVE-2026-41940 in cPanel with Telegram exfiltration; ShinyHunters re-breach Instructure Canvas to extort schools; Linux ‘Dirty Frag’ (CVE-2026-43284/-4...
intel.overresearched.net
The numbers forecast by zerodayclock.com are looking good for SecOps teams to say the least
Zero Day Clock
The gap between disclosure and exploitation is collapsing to zero.
zerodayclock.com
🔴 Apache HTTP/2 RCE (CVE-2026-23918) & mod_rewrite EoP (CVE-2026-24072) 🟠 PCPJack worm evicts TeamPCP, steals creds 🟠 Akira: 38 new victims (health/mfg/edu) Full brief: intel.overresearched.net/2026/05/08/c... #Daily #ThreatIntel #InfoSec
CTI Daily Brief: 2026-05-07 - Apache HTTP/2 RCE & mod_rewrite EoP CVEs; PCPJack cloud worm; Akira ransomware spree (38 victims)
Critical Apache HTTP Server RCE and privilege-escalation flaws lead the day; the PCPJack worm steals credentials at cloud scale by evicting TeamPCP; Akira posts 38 fresh victims spanning healthcare, m...
intel.overresearched.net
Apache MINA RCE PoC (CVE-2026-42779) ConsentFix v3 Azure OAuth bypasses MFA CopyFail Linux LPE still unpatched ShinyHunters dumps 5.1M ZenBusiness Full brief: intel.overresearched.net/2026/05/02/c... #Daily #ThreatIntel #InfoSec #Ransomware #SupplyChain
CTI Daily Brief: 2026-05-01 — Apache MINA RCE, ConsentFix v3 OAuth abuse, CopyFail Linux LPE in active discussion
Two critical Telegram-tracked CVEs (Apache MINA RCE, authentication bypass), automated OAuth phishing against Azure, the CopyFail Linux LPE remains widely unpatched, npm supply-chain campaigns continu...
intel.overresearched.net
It seems there is a new NPM campaign leveraging similar tactics and processes of CANISTERWORM. Intel from: intel.overresearched.net/2026/04/22/c... Seems to align to #DevSecStation announcement podcasts.apple.com/gb/podcast/d... Look at adding: npm config set ignore-scripts true #NPM #infosec
CTI Daily Brief: 2026-04-21 - CISA KEV SharePoint CVE-2026-32201 with 1,300+ unpatched; Microsoft OOB patch for ASP.NET CVE-2026-40372; Harvester APT deploys Linux GoGra; Lazarus macOS campaign
51 reports processed across 3 correlation batches. Microsoft issues out-of-band patch for critical ASP.NET Core flaw CVE-2026-40372; Shadowserver warns 1,300+ SharePoint servers remain unpatched again...
intel.overresearched.net
A solid article from #Wiz regarding the Vercel incident: www.wiz.io/blog/context...
Context.ai OAuth Token Compromise | Wiz Blog
Compromised Context.ai OAuth tokens enabled attackers to perform a supply chain attack via trusted SaaS integrations. Learn how to assess the risk in your environment and how to prevent the next attac...
wiz.io
Our team received a report of intermittent app outages at about 11:40pm PDT on April 15, 2026. They worked through the night to mitigate a sophisticated Distributed Denial-of-Service (DDoS) attack, which intensified throughout the day.
Marimo RCE weaponised w/ NKAbuse blockchain botnet via Hugging Face. Nginx UI auth-bypass CVE-2026-33032 actively exploited. ShinyHunters leak 13.5M McGraw Hill records from Salesforce misconfig. UAC-0247 hits Ukraine hospitals Full brief: intel.overresearched.net/2026/04/16/c... #Daily #ThreatIntel
CTI Daily Brief: 2026-04-15 - In-the-wild exploitation of Marimo (CVE-2026-39987) and Nginx UI (CVE-2026-33032); ShinyHunters leaks 13.5M McGraw Hill records
48 reports processed across two correlation batches. Three critical vulnerabilities under active exploitation or requiring urgent customer action (Marimo, Nginx UI, Cisco Webex). ShinyHunters publishe...
intel.overresearched.net
First CTI Monthly: March 2026, 1,320 reports / 39 batches. TeamPCP supply-chain siege CanisterWorm K8s wiper, Iran Handala wipes 80k Stryker via Intune DarkSword iOS → KEV Chrome 0-days, SharePoint RCE Full brief: intel.overresearched.net/2026/04/16/c... #Monthly #ThreatIntel #InfoSec
CTI Monthly Report: March 2026 - TeamPCP Supply Chain Siege, CanisterWorm Iran Wiper, Handala Stryker Intrusion, DarkSword iOS KEV, Ransomware Surge
March 2026 saw a historic supply chain campaign by TeamPCP across Trivy, LiteLLM, Checkmarx KICS, Telnyx, Axios, and OpenVSX; the CanisterWorm Kubernetes wiper targeting Iranian infrastructure; Handal...
intel.overresearched.net
Adobe Acrobat zero-day (CVE-2026-34621) added to CISA KEV. DPRK Lazarus npm package targets Polymarket traders. FBI & Indonesia take down W3LL PhaaS. Full brief: intel.overresearched.net/2026/04/13/c... #Daily #ThreatIntel #CTI #Lazarus #Ransomware
CTI Daily Brief: 2026-04-12 - Adobe Acrobat zero-day CVE-2026-34621 added to CISA KEV; DPRK npm package targets Polymarket; FBI/Indonesia dismantle W3LL PhaaS
66 reports processed. Adobe Acrobat/Reader zero-day (CVE-2026-34621) under active exploitation joined CISA KEV alongside six other CVEs. DPRK Lazarus pushes malicious npm package targeting Polymarket ...
intel.overresearched.net
MS April Patch Tuesday: 167 flaws, 2 zero-days SharePoint CVE-2026-32201 actively exploited; Defender CVE-2026-33825 disclosed. Interlock ransomware hits Cisco FMC zero-day Full brief: intel.overresearched.net/2026/04/14/c... #Daily #ThreatIntel #CVE #Ransomware #InfoSec #CyberSecurity #PatchTuesday
CTI Daily Brief: 2026-04-13 - Microsoft April Patch Tuesday (167 flaws, 2 zero-days incl. actively-exploited SharePoint); Interlock ransomware exploits Cisco FMC zero-day
Microsoft April 2026 Patch Tuesday addresses 167 vulnerabilities including an actively-exploited SharePoint spoofing zero-day (CVE-2026-32201) and a publicly-disclosed Defender EoP (CVE-2026-33825). I...
intel.overresearched.net
15 critical OSS CVEs - wolfSSL (X.509 bypass, TLS 1.3 UAF), XZ Utils, Go, libinput. Huntress: signed "Dragon Boss" adware killed AV on 23,500+ hosts. Trust Wallet USDT drainer + NWHStealer active. Full brief: intel.overresearched.net/2026/04/15/c... #Daily #ThreatIntel #CVE #InfoSec
CTI Daily Brief: 2026-04-14 — 15 Critical CVEs in OSS Crypto/Runtime Libraries; Signed Adware Killing AV; Trust Wallet Drainer Campaign
15 critical CVEs disclosed across wolfSSL, XZ Utils, Go runtime, libinput and Handlebars.js; Huntress exposes signed ‘Dragon Boss Solutions’ adware disabling AV on 23,500 hosts; AlienVault flags NWHSt...
intel.overresearched.net
We publish hyper-detailed APT reports so defenders can stay ahead and we absolutely should keep doing that. But also just handing script kiddies a prompt: “move like Fancy Bear” It seems like the ceiling and the floor are growing ever closer as time goes on with AI.
Create two threat intelligence accounts, one on bsky and the other on X, so that I can provide new threat reports as a feed, check it out at: BSky - bsky.app/profile/inte... X - x.com/ORIntelligence #ThreatIntel #InfoSec
bsky.app
#threatintel report released highlighting IoC and SOC actions for a number of threats especially, axios. Check it out at: intel.overresearched.net/2026/03/31/c...
CTI Daily Brief: 2026-03-30 - Axios npm Supply Chain Compromise Delivers Cross-Platform RAT; CISA Orders Citrix NetScaler Patch; TeamPCP Post-Compromise Activity Escalates
High-volume day with 133 reports across 15 sources dominated by the Axios npm supply chain compromise delivering cross-platform RATs, CISA emergency directive for CVE-2026-3055 in Citrix NetScaler, Te...
intel.overresearched.net
Seeing an obvious improvement to language model processing on the GPU through my threat pipeline, however, there is definitely some elements for future tuning.
Finished writing my next blog post. It focuses on engineering a scalable platform that leverages local language models to summarise and correlate threat feeds. Check it out at: blog.overresearched.net/2026/03/cogn... #Infosec #ThreatIntel #OpenSource #LocalLLM #N8N #OpenCTI #CyberSecurity
Cognitive CTI - Building a Scalable, Self-Hosted Threat Intelligence Pipeline with AI
Introduction Threat Intelligence is a fairly superfluous component to security for most individuals or organisations that are growi...
blog.overresearched.net
With the range of frameworks out there these days what do I even go for as a solo dev with an ambitious project? - RoR? - Django? - NextJS? - Laravel? Decisions...
Finished writing my first post for my new blog, it focuses on WannaCry but across multiple different areas of the campaign. This was to brush the rust off my writing and malware analysis skills. #WannaCry #MalwareAnalysis #ReverseEngineering blog.overresearched.net/2026/02/wann...
WannaCry — Campaign Intelligence, Reverse Engineering, and Detection
During 2017, WannaCry became a national headline for the United Kingdom and many other nations targeting companies, such as FedEx, Honda, Ni...
blog.overresearched.net
Running through the old #Ubuntu wallpapers and seeing breezy Badger sent me back to the first installation of a Linux distro: www.omgubuntu.co.uk/every-ubuntu...
Look Back At Every Default Ubuntu Wallpaper, Ever
This is every Ubuntu default wallpaper, presented in one scrollable post. Come look back over 19 years of iconic backgrounds, all unique to Ubuntu.
omgubuntu.co.uk
React Compiler RC is now available! We've added support for swc and are working towards a stable release react.dev/blog/2025/04...
React Compiler RC – React
The library for web and native user interfaces
react.dev
Discord does not let me send a message over a particular word count, which is fairly annoying when trying to send snippets of code to a friend. Having to resort to images as a work around is fairly annoying. To paraphrase, a screenshot is worth 1000+ chars after all. or I could use nitro...
An interesting concept, I would love for forums to come back into the mainstream.
Got a fresh off the presses newsletter issue coming your way! 🗞️ This is my last issue before I give birth later this week (!) so come one, come all! Check out the archive and subscribe here: cassidoo.co/newsletter/
rendezvous with cassidoo
A weekly newsletter with web development content for everyone, from beginners to pros.
cassidoo.co
That cathartic feeling of cleaning out the dust from your desktop case, slapping the side panel back as if you were larping as Phil swift with flex tape.