Make a deal with Darses
🔒 Paid proposals held safely in escrow — released only when the work's approved.
📊 Post engagement
🔥 Top post: @shadowserver New SharePoint webshell are dropped from CVE-2026 · 2 likes + reposts
📊 Activity & format
Recent posts
View on Mastodon ↗
Photo post
@shadowserver
Checkout my Nuclei PR for detecting two types of Javascript loaders seen on compromised Wordpress websites. https://github.com/projectdiscovery/nuclei-templates/pull/16603
Now at 2707 websites. First website seen was on 2026-03-12 (or one/two days before). First certificate for h1-analytics[.]com was on 2026-03-10. So who has the logs to know what Wordpress attack campaign was starting around that time?
I have a public Nuclei template is anyone wants to scan some Wordpress sites: https://github.com/darses/nuclei-templates/blob/main/other/tds-la02.yaml
By the way, one thing that complicates this analysis is that some websites are infected multiple times. This may be confusing. This is not another ErrTraffic or ClearFake thing.
Do I know anyone that has looked at this "la02" Javascript loader before? Seen on (suspected) compromised Wordpress website. Most C2 domains are 'known malicious' but without further details of payloads, attribution or anything else. I cou…
#Lantronix released new a bunch of new firmware, fixing both CVE-2025-67038 and the second actively exploited vulnerability without #CVE identifier.
I did not check all the firmware uploads nor do I have devices to actually test the fixed …
@ifin @mttaggart
If you have any LuCI-based #Lantronix Serial-to-Ethernet device exposed on the internet, then you may want to kickoff your incident response plan.
My suspicion is that the unauthenticated Remote Code Execution vulnerability CVE-2025-67038 …
@basisbeveiliging
Enige kans dat de scanner IP's in een machine readable formaat online gepubliceerd kunnen worden? Zie https://github.com/MISP/misp-warninglists/issues/336#issuecomment-4563049199
🐘 Community & instance
💡 Facts
🛡️ Audience credibility
- Est. 97% real, active audience · Low fake-follower risk.
- Strong engagement (~7.1% of followers engage each post) — an active, real audience.
- Established account (3+ years old).
Heuristic estimate from engagement, follower ratios, account age & growth — a screening signal, not a guarantee.
About
🔀 Audience overlap
EstimatedEstimated shared audience with similar creators — useful for avoiding overlap (or doubling down) when planning a campaign.
More like this
Find more →✉ Message Darses
Reaching out to influencers is a Pro feature. Upgrade to message any influencer directly — perfect for brands and agencies booking sponsorships.
- ✓ Message any influencer from their listing
- ✓ The influencer gets notified by email
- ✓ Manage every conversation in one inbox
Already Pro? Log in.
🎤 Event / appearance with Darses
Booking an event / appearance is a Pro feature. Upgrade to book Darses for an in-person or virtual appearance — payment held safely in escrow until the event is done.
- ✓ Book them for events, livestreams, panels & more
- ✓ Darses gets notified by email
- ✓ Fee held in escrow, released after the appearance
Already Pro? Log in.
You're out of free requests this month
Free accounts get 5 per month. Go Pro for unlimited sponsor pitches, collab requests & sponsorship deals — plus featured placement, the Verified badge, free withdrawals and more.
Upgrade to Pro — $9.95/mo →Your free limit resets on the 1st of next month.