Joined November 2023
55 Photos and videos
Another bleeding-edge version of VEDAS is out now 🎉🥳 Many network-exploitable vulnerabilities, such as CVE-2025-47188, remains delayed, poorly documented and lack meaningful enrichment. Despite being actively exploited since May 2025, this vulnerability is still not enriched by NVD, EPSS or proprietary vulnerability databases. VEDAS can be used for Mining Exploit Intelligence linked to vulnerability identifiers like CVE, EUVD, CNNVD, and BDU and can be helpful in developing custom Nuclei templates and extending its coverage, supporting the growing community of security teams, researchers, and ASM providers. Read More: osintteam.com/mining-exploit…
1
697
ARPSyndicate is proud to support CSAI’s Cyber Security Centre for Research & Innovations (C3IR) in this initiative. As part of our involvement with C3IR, we are actively hiring interns for this Offensive Security Research Internship. If you are passionate about CVE analysis, vulnerability research, reverse engineering, embedded security, or low-level software analysis, applications are welcome. All details are in the link below. linkedin.com/posts/nkgoyals_…
58
ARPSyndicate - Cyber & Open Source Intelligence retweeted
We welcome esteemed guest from @arpsyndicate as an Industry Partner for #BharatDefenceTechShow2026 (BDTS 2026). In an era where cyber dominance, digital warfare, and strategic innovation define national security, ARPSyndicate brings deep expertise in cybersecurity intelligence, threat research, and next-generation defence solutions. At BDTS 2026, the convergence of: 🔹 Innovation 🔹 Future Warfare Technologies 🔹 Global Collaboration will drive meaningful dialogue between defence leaders, technology pioneers, policymakers, and global industry stakeholders. 📅 February 16–17, 2026 📍 Manekshaw Centre, Delhi, India Together, we strengthen the ecosystem powering #AtmanirbharBharat and next-generation defence readiness. We look forward to impactful collaborations and strategic partnerships at #BDTS2026. @DefenceMinIndia @makeinindia @investindia @SpokespersonMoD @DefProdnIndia #BDTS2026 #BharatDefenceTechShow #DefenceInnovation #CyberSecurity #FutureWarfare #MakeInIndia #DefenceTechnology #StrategicPartnerships #GlobalDefence #MilitaryTechnology #Aerospace #HomelandSecurity #InnovationEcosystem #IndiaDefence #Defe
1
1
200
ARPSyndicate - Cyber & Open Source Intelligence retweeted
The API only gets 100 at a time, but I partially vibe coded this script to get beyond that. You can obviously scrape this entire API by refining the code. If someone has access to this, they have access to a wealth of info even if the SSNs are partial. Data brokers love data.
Sitting here staring at an open API that allows you to search for Swedish citizen data.. full names, ssns, postal codes, etc. If a TA knows about this, holy. I have no idea what company this belongs to nor can I share the url.
4
2
51
24,533
ARPSyndicate - Cyber & Open Source Intelligence retweeted
absolutely fantastic
6
16
158
29,069
ARPSyndicate - Cyber & Open Source Intelligence retweeted
MEAWFY Advanced MegaNZ File Search Engine 9M indexed files meawfy.com/
5
30
235
30,220
ARPSyndicate - Cyber & Open Source Intelligence retweeted
It's crazy how hallucinated AI CVE PoCs keep ending up in @NIST NVD references. One recent example is CVE-2026-21962, a 10.0 CVE in Oracle HTTP Server / Apache Proxy Plugin. nvd.nist.gov/vuln/detail/CVE… links to a GitHub repository with a fake PoC. This also propagates to @github advisories: github.com/advisories/GHSA-4… Meanwhile, some blue teams are injecting AI slop rules to prevent this and thinking they are protected, but they are not.
4
27
98
16,303
ARPSyndicate - Cyber & Open Source Intelligence retweeted
Yes, we've heard a little noise about the semi-popular #ChatMoss #VSCode extension that appears to be malicious. We reported it on 31. Oct 2025, in fact; shortly after we began our ongoing campaign to monitor the VSCode and OpenVSX marketplaces. The extension ID is WhenSunset[.]chatgpt-china ; for whatever reason, in this case the marketplace folks decided to take no action. It's not new, it's not news, but it is a good reminder to be cautious; marketplace maintainers can be reluctant to remove things without "smoking gun" evidence of malice. #WhenSunset #VSCodeExtension #Malware #SupplyChainSecurity #OpenSourceSecurity
3
5
466
ARPSyndicate - Cyber & Open Source Intelligence retweeted
Well that’s a big one:
‼️🇺🇸 Nike has been named a victim to World Leaks Ransomware
7
9
71
14,530
ARPSyndicate - Cyber & Open Source Intelligence retweeted
CVE-2025-2294🚨 The Gateway was allowing unauthenticated users to inject and execute arbitrary code via SpEL.🔥 #bugbountytips :Hit a 403? Use /..;/ or X-Original-URL header to bypass WAF and reach hidden endpoints. 💸 #bugbounty #bugbountytip #EthicalHacking
1
24
226
12,472
ARPSyndicate - Cyber & Open Source Intelligence retweeted
Jan 22

190
1,995
8,999
11,250,812
ARPSyndicate - Cyber & Open Source Intelligence retweeted
GNU InetUtils telnetd Argument Injection Authentication Bypass Leads to RCE (CVE-2026-24061) USER="-f root" telnet -a 127.0.0.1 2323 Try reproduce this issue using #Vulhub github.com/vulhub/vulhub/tre…
3
54
176
15,383
ARPSyndicate - Cyber & Open Source Intelligence retweeted
Jan 21
⚠️⚠️ CVE-2026-21962 (CVSS 10.0): Oracle Fusion Middleware to unauthenticated remote total takeover via HTTP 🔗FOFA Link: en.fofa.info/result?qbase64=… 🎯5.3k Results are found on the en.fofa.info nearly year. FOFA Query: app="Oracle-Fusion-Middleware" 🔖Refer: securityonline.info/total-ta… #OSINT #FOFA #CyberSecurity #Vulnerability
1
57
184
18,573
ARPSyndicate - Cyber & Open Source Intelligence retweeted
Cloudflare Zero day 💀
Our latest research is out! If you missed a good write-up for nice vulnerabilities, I brought you one! Enjoy the reading! @FearsOff @Cloudflare
8
85
730
88,131
ARPSyndicate - Cyber & Open Source Intelligence retweeted
Something funky going on at @Zendesk, I’ve received the same junk myself. Anyone else?
There’s some exploit or mass-scale abuse with @Zendesk right now… I just got EIGHT HUNDRED emails from them over the course of about an hour. They’re all scams sent from different Zendesk instances. Many bypassed iCloud’s Junk filters.
14
35
210
56,705
ARPSyndicate - Cyber & Open Source Intelligence retweeted
Some additional domains: redvds[.]su, redvds[.]ru
Microsoft Threat Intelligence observed the rapid proliferation of RedVDS, a virtual dedicated server (VDS) provider used by financially motivated threat actors for BEC, phishing, account takeover, and financial fraud campaigns spanning multiple sectors. msft.it/6016t7J5m
3
22
76
15,588
ARPSyndicate - Cyber & Open Source Intelligence retweeted
Great aggregator website to live track Iran related news and updates. iranmonitor.org/
14
34
5,216
ARPSyndicate - Cyber & Open Source Intelligence retweeted
Continued insight into the PRC cyber ecosystem where Chinese companies play a big role and even run cyber intrusions for the state. Knownsec is only one of many commercial actors that underpin troublesome hacks.
🇨🇳 THE KNOWNSEC LEAK: Yet Another Leak of China’s Contractor-Driven Cyber-Espionage Ecosystem 01/09/2026 dti.domaintools.com/the-know…
6
34
162
25,785