@2Worklyi
iAccount based inIsrael
About this account
- Account based in
- Israel
- Connected via
- Israel Android App
Account-level information from X, not a live location or the device used for a specific post.
Helping SOC, detection, and CTI teams stay ahead with cybersecurity news, CTI reporting, and IOC coverage they can act on.
Joined August 2026
- Tweets626
- Following0
- Followers2
- Likes0
Cameron Wagenius (kiberphant0m) received 70 months for hacking AT&T and Verizon using SSH brute-force tooling alongside Judische and John Erin Binns. securityweek.com/prison-sent… 2workly.com #2workly #CTI
Carbonato botnet compromises exposed Docker port 2375 daemons to drop the Hermes Agent framework, orchestrating credential theft and worm-like lateral scans via Telegram. Source: thehackernews.com/2026/09/ca… More: 2workly.com #2workly
ShinyHunters leaked medical records and staff data linked to FBI recruitment systems in a non-financial extortion campaign. Details: malwarebytes.com/blog/data-b… Track threat actor campaigns and operationalize CTI: 2workly.com #2workly
Kiteworks urged shutdowns of self-hosted servers after federal warnings of threat activity targeting a flaw in its Advanced Forms module. Review instances, isolate the module, and verify release 9.5.1 securityweek.com/kiteworks-u… 2workly.com
CISA added two critical Citrix NetScaler flaws to KEV (CVE-2026-88771 and CVE-2026-88772, CVSS 9.5) amid active global exploitation for unauthenticated RCE. Prioritize patching and inspect DTLS configs thehackernews.com/2026/09/ci… 2workly.com
Citrix patched 2 NetScaler zero-days under active exploit: CVE-2026-88771 (unauth RCE) & CVE-2026-88772 (DTLS overflow). CVSS 9.5. Check IOCs before patching. Details: securityweek.com/citrix-conf… Intel to enforcement: 2workly.com #2workly
Active exploitation observed for Microsoft SharePoint RCE (CVE-2026-65660), with actors deploying webshell backdoors. CISA added to KEV. Patch now and monitor SharePoint directories. Details: securityweek.com/microsoft-s… Intel: 2workly.com #2workly
Two unpatched Citrix NetScaler RCE zero-days are under active exploitation with no fix yet released. Restrict management interfaces immediately and preserve logs/core dumps if investigating compromise thehackernews.com/2026/09/wa… 2workly.com
Lunex Stealer uses BYOVD via AMD driver PDFWKRNL.sys (CVE-2023-20598) to zero EDR kernel callbacks, blinding telemetry while bypassing default blocklists. Enforce custom WDAC driver rules. thehackernews.com/2026/09/lu… 2workly.com #2workly
UNC6240 exploits Oracle PeopleSoft CVE-2026-35273 via /%50SEMHUB/ WAF bypass to deploy web shells and SIDEEYE. Hunt WebLogic logs for encoded URI paths and block C2 162.219.30[.]165. Source: thehackernews.com/2026/09/at… 2workly.com #2workly
x47.c botnet uses xAI Grok for host persistence and introduces AI API draining attacks to burn victim credits via stolen keys. C2 uses fast-flux routing. Track and enforce IOCs with 2workly.com Source: securityweek.com/new-x47-c-w… #2workly
A CSRF flaw in Elementor 4.3.0/4.3.1 lets attackers create rogue WordPress admins via crafted REST API requests with "elementor/v1/events/" in the URI. Patch to 4.3.2 and monitor logs. Details: thehackernews.com/2026/09/el… More: 2workly.com #2workly
CISA added SharePoint CVE-2026-65660 & MikroTik CVE-2026-67279 to KEV. The MikroTrick chain enables unauthenticated admin takeover on exposed RouterOS devices. Patch perimeter assets now. Details: thehackernews.com/2026/09/sh… 2workly.com #2workly
Kiteworks urged customers to execute a 9-hour system shutdown after federal intel warned of imminent attacks. Ensure instances are updated to 9.5.1 and monitor edge logs. Details: thehackernews.com/2026/09/ki… More at 2workly.com #2workly
DOJ sentenced threat actor Cameron Wagenius (kiberphant0m) to 70 months for extortion campaigns tied to the 2024 Snowflake breaches and SSH credential theft. Track identity-based cloud threats: Source cyberscoop.com/cameron-wagen… 2workly.com
Compromised GitHub Actions tied to Mini Shai-Hulud resumed harvesting CI secrets after repos were re-enabled. Pin actions to full commit SHAs, rotate exposed secrets, and block t.m-kosche[.]com. Intel: More thehackernews.com/2026/09/co… 2workly.com
Actor "Kiberphant0m" sentenced to 70 months for telecom extortions via compromised cloud credentials lacking MFA. Identity telemetry and mandatory MFA remain vital controls against bulk data exfiltration krebsonsecurity.com/2026/09/… 2workly.com
Kothamine RAT evades network blocks by using Tailscale tailcat to tunnel C2 traffic over local ports. Detect execution of tailcat.exe forward commands and Defender exclusions in AppData. Intel: Enforce via malwarebytes.com/blog/threat… 2workly.com
Kiteworks urges customers to shut down internet-facing file transfer servers amid warnings of an imminent zero-day threat. Isolate edge instances and monitor logs. Details: techcrunch.com/2026/09/25/ki… Intel: 2workly.com #2workly
Only 26% of detected CISA KEV flaws get remediated, with median fix times reaching 43 days. Attackers actively exploit cataloged CVEs left open for years. Connect CTI to enforcement faster at 2workly.com. Source: hackread.com/26-detected-cis… #2workly