Mastodon Digest
for the past
scorer
threshold
Posts

🚨 Google confirms Pixel phones targeted in zero-click zero-day attacks

Google has patched CVE-2026-58704, a high-severity vulnerability in Pixel phones' cellular modem that the company says was already under "limited, targeted exploitation."
β €
The flaw is caused by a logic error that can allow an attacker to bypass permission checks and escalate privileges beyond the modem's isolated environment.
β €
Most importantly, exploitation requires no interaction from the victim.

No malicious link needs to be clicked and no file needs to be opened, making it a zero-click attack.
β €
Google has not disclosed:

β€’ Who carried out the attacks
β€’ How many Pixel owners were targeted
β€’ How the victims were selected
β€’ What tools or spyware may have been deployed
β €
CISA has added CVE-2026-58704 to its Known Exploited Vulnerabilities catalog and set a September 19 remediation deadline for affected federal systems.
β €
Google says Pixel devices with the September 5, 2026 security patch level or later are protected.

Pixel owners should update their devices immediately.

Source: techcrunch.com/2026/09/16/goog

pass the bong

PS: Google fired this guy for misconduct, so Microsoft hired him.

Hey so does each mastodon server have their own polycule or how does that work

🚨πŸ‡ͺπŸ‡Έ Endesa dataset allegedly exposing 20M+ individuals offered for sale
β €
Endesa is one of Spain’s largest electricity and gas companies, providing energy services to residential and business customers across the country.
β €
A forum actor using the handle "spain" claims to have compromised Endesa and is offering what they describe as one of the largest Spanish energy datasets for sale, allegedly containing information tied to more than 20 million individuals.
β €
The actor claims the collection totals approximately 1.06 TB and includes numerous SQL exports containing customer, account, billing, contract, contact, and energy service information.
β €
Claimed exposed material includes:
β €
β€’ Customer names
β€’ First and last names
β€’ NIF / identity information
β€’ Email addresses
β€’ Mobile and telephone numbers
β€’ Cities and countries
β€’ IBANs
β€’ CUPS electricity and gas identifiers
β€’ Postal information
β€’ Account records
β€’ Contact and relationship data
β€’ Billing profiles
β€’ Contracts
β€’ Account history
β€’ Case records
β€’ Asset information
β€’ Customer status and risk-related fields
β€’ Commercial and service metadata
β €
Files shown in the listing include account, IBAN, CUPS, contact, billing, contract, asset, case, and account history datasets, with several individual SQL files reportedly ranging from multiple gigabytes to more than 250 GB.
β €
The actor also claims other parties are reselling the data and states they were responsible for the original compromise. Pricing is listed as negotiable.
β €
The breach claim, 20M+ affected-person figure, total dataset size, authenticity of the samples, origin of the information, and full scope of the alleged compromise have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing

🚨πŸ‡ͺπŸ‡Έ Naturgy dataset allegedly exposing 1.8M+ customers offered for sale
β €
Naturgy is a Spanish multinational energy company providing electricity and natural gas services to residential and commercial customers.
β €
A forum actor using the handle "spain" claims to be selling a 74.2 GB dataset associated with Naturgy, allegedly containing information tied to more than 1.8 million customers.
β €
Claimed exposed data includes:
β €
β€’ Customer names
β€’ NIF / identity numbers
β€’ First and last names
β€’ IBANs
β€’ Email addresses
β€’ Telephone numbers
β€’ Postal codes
β€’ Street addresses
β€’ Cities and localities
β€’ Provinces
β€’ Electricity and gas CUPS identifiers
β€’ Document types
β€’ Contract and account identifiers
β€’ Product and tariff information
β€’ Contract signing dates
β€’ Account modification dates
β€’ Customer service and call-related metadata
β €
The actor published a full-row sample showing numerous customer, billing, service, contract, and account-related fields.
β €
The breach claim, stated 1.8M+ customer count, 74.2 GB size, authenticity of the sample, source of the information, and full scope of the exposed dataset have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing