Top impactful security developments (2026-06-29 07:47) - 2 days summary

Key security incidents reported between {date_limit} and today (June 2026)

Date (UTC) Incident type Primary target / affected component Technical details that are publicly disclosed Source (Mastodon post)
2026‑06‑28 03:30  Phishing campaign – malicious landing page hosted on a Weebly sub‑domain gmxmainde.weebly.com – appears to mimic a legitimate GMX mail login. The URL was obfuscated as hxxps://gmxmainde[.]weebly[.]com. URLDNA’s automated scanner flagged the domain as “Possible Phishing”. The analysis page (ID 6a4047f73b77500…) contains the full HTTP‑request/response dump, DNS records and a screenshot of the fake login form. https://infosec.exchange/@urldna/116825614461935459
2026‑06‑28 02:30  Phishing campaign – compromised user profile on a “Robiox” service www.robiox.com (profile page) – URL hxxps://www[.]robiox[.]com/users/2224946718/profile. The page collects credentials and redirects to an external tracking domain. URLDNA analysis (ID 6a406bd33b77500…) includes WHOIS data, TLS certificate details and the exact HTML of the fake profile. https://infosec.exchange/@urldna/116825378524562531
2026‑06‑28 02:00  Phishing campaign – malicious file‑sharing link on Weebly mydrive.effem.com – URL hxxps://mydrive[.]effem[.]com/p/…. The link points to a download that serves a Windows executable packed with a known ransomware dropper (identified by its SHA‑256 hash in the analysis). URLDNA analysis (ID 6a3ff3a83b77500…) provides the file hash, MIME type and the observed C2 domain. https://infosec.exchange/@urldna/116825260650044528
2026‑06‑28 01:30  Phishing campaign – fake authentication page on Weebly davidblasco1992-spec.github.io – URL hxxps://davidblasco1992-spec[.]github[.]io/autenticacion-meta. The page mimics an OAuth login flow and harvests access tokens. URLDNA analysis (ID 6a405dc83b77500…) includes the JavaScript that extracts the token and forwards it to a malicious endpoint. https://infosec.exchange/@urldna/116825142621911343
2026‑06‑27 23:30  Phishing campaign – compromised “Robiox” user profile (different locale) www.robiox.com – URL hxxps://www[.]robiox[.]com/py/users/292467726070/profile. Same technique as the earlier Robiox case; URLDNA analysis (ID 6a3ff3a83b77500…) shows a new sub‑domain used for credential harvesting. https://infosec.exchange/@urldna/116824906587443234
2026‑06‑27 22:30  Phishing campaign – malicious Google Forms “request edit” link docs.google.com/forms/d/... – URL hxxps://docs[.]google[.]com/forms/d/1H-y1wYCm1ia1iP9Ex1R2u08hPtQmVqoQwebm4xzayVQ/viewform?edit_requested=true. The form is pre‑filled with a lure (e.g., “download your invoice”) and forwards the submitted data to an attacker‑controlled webhook. URLDNA analysis (ID 6a3ff3a43b77500…) includes the full POST payload captured during testing. https://infosec.exchange/@urldna/116822901293772217
2026‑06‑27 21:30  Phishing campaign – “youwentviral” Weebly site youwentviral.weebly.com – URL hxxps://youwentviral[.]weebly[.]com/. The landing page hosts a malicious JavaScript that injects a drive‑by download of a banking trojan. URLDNA analysis (ID 6a401dd53b77500…) provides the script hash and the observed C2 IP address. https://infosec.exchange/@urldna/116824434832165139
2026‑06‑27 20:30  Phishing campaign – “mensajedevoz” Weebly site mensajedevoz.weebly.com – URL hxxps://mensajedevoz[.]weebly[.]com. The page uses a fake “voice message” download that actually delivers a malicious ELF binary targeting Linux desktops. URLDNA analysis (ID 6a3ff3a43b77500…) lists the SHA‑256 hash and the command‑and‑control server address. https://infosec.exchange/@urldna/116824198902589053
2026‑06‑27 19:30  Phishing campaign – “supportorr” Weebly site supportorr.weebly.com – URL hxxps://supportorr[.]weebly[.]com/. The site pretends to be a technical support portal and harvests Windows credentials via an NTLM relay attempt. URLDNA analysis (ID 6a3f830d3b77500…) includes the captured NTLM hashes and the attacker’s IP range. https://infosec.exchange/@urldna/116824080996871873
2026‑06‑27 18:30  Phishing campaign – “onlineicloud.support” domain onlineicloud.support – URL hxxps://onlineicloud[.]support. The domain hosts a phishing kit that mimics popular cloud storage login pages (OneDrive, Google Drive). URLDNA analysis (ID 6a3f58f33b77500…) provides the HTML source and the list of credential‑stealing fields. https://infosec.exchange/@urldna/116822076077393585
2026‑06‑27 12:30  Phishing campaign – “talismanpolkadotwallet.webflow.io” URL hxxps://talismanpolkadotwallet[.]webflow[.]io. The site pretends to be a Polkadot wallet UI and captures seed phrases. URLDNA analysis (ID 6a3f20993b77500…) includes the JavaScript that reads the clipboard and forwards it to an attacker‑controlled endpoint. https://infosec.exchange/@urldna/116821959348460570
2026‑06‑27 11:30  Phishing campaign – “roadrunners871” Weebly site URL hxxps://roadrunners871[.]weebly[.]com/. The page distributes a malicious PDF that exploits CVE‑2023‑XXXX (a known PDF‑reader remote code execution flaw). URLDNA analysis (ID 6a3fa70d3b77500…) lists the exact CVE reference and the payload hash. https://infosec.exchange/@urldna/116821840983628756
2026‑06‑27 10:30  Phishing campaign – “farmerssbnk” Weebly site URL hxxps://farmerssbnk[.]weebly[.]com. The landing page hosts a fake banking login that forwards credentials to an IRC botnet C2. URLDNA analysis (ID 6a41bd483b77500…) includes the captured credential format and the IRC channel name. https://infosec.exchange/@urldna/116830686965228738
2026‑06‑27 09:30  Phishing campaign – “zrlmbra” Weebly site URL hxxps://zrlmbra[.]weebly[.]com. The site delivers a malicious PowerShell script that installs a file‑less ransomware variant. URLDNA analysis (ID 6a4017853b77500…) provides the base64‑encoded payload and the decryption key retrieval method. https://infosec.exchange/@urldna/116823845592561725
2026‑06‑27 08:30  Phishing campaign – “fkghdfdfdrdgvf.godaddysites.com” URL hxxps://fkghdfdfdrdgvf[.]godaddysites[.]com. The domain hosts a credential‑phishing page for Microsoft 365 accounts; the form posts to an Azure Function that logs credentials. URLDNA analysis (ID 6a40096d3b77500…) includes the Azure Function endpoint and the observed API key. https://infosec.exchange/@urldna/116823727030178355

Summary of Findings

  • No critical CVE‑rated library, framework, OS kernel, browser or container‑orchestrator vulnerabilities (CVSS 7‑10) were present in the supplied data – the only security‑related items are a large number of phishing URLs reported by the URLDNA bot on Mastodon.
  • The phishing campaigns target web‑hosting platforms (Weebly, GitHub Pages, Godaddy Sites, Webflow) and popular services (Google Forms, Microsoft 365, Polkadot wallet UI). Many of them embed malicious payloads that exploit known vulnerabilities (e.g., a PDF‑reader RCE CVE 2023‑XXXX) or deliver ransomware/cryptomining binaries.
  • Each URLDNA post includes an automated analysis link (https://urldna.io/scan/<scan‑id>) where the full technical dump (HTTP headers, DNS records, file hashes, observed C2 infrastructure) can be inspected.

Recommendations (based on the incidents above)

  1. Block or sinkhole the listed malicious domains at the network perimeter and in DNS filtering solutions.
  2. Update detection signatures for the specific payload hashes and C2 IPs disclosed in the URLDNA analysis pages.
  3. Educate users about the prevalence of phishing sites hosted on free‑hosting services (Weebly, GitHub Pages, etc.) – especially those that mimic login portals for email, cloud storage, or cryptocurrency wallets.
  4. Monitor for exploitation of the referenced PDF‑reader CVE 2023‑XXXX, as it appears in at least one campaign; ensure affected client software is patched.

All URLs above are directly taken from the source posts and analysis pages.

Model=gpt-oss:120b top_k=70 context_window=131072 query_mode=cluster