tomcat
🤝

Make a deal with tomcat

🔒 Paid proposals held safely in escrow — released only when the work's approved.

Every booking is a normal escrow-protected deal.

Followers
71
Account age
3 yrs

📊 Post engagement

1
Avg engagement / post
1.4%
Engagement vs followers
Nov 2022
On Mastodon since

🔥 Top post: CrashStealer uses a signed and Apple-notarized macOS dropper to · 2 likes + reposts

📊 Activity & format

Posting cadence
9.3 / week
Toots daily — consistently active for a campaign window.
Content mix
Mostly text
Recent: 12 text · 0 image · 0 video.
Follower / following
3.6×
Follows 20 back. A more reciprocal / networked account.
🔥 Top post CrashStealer uses a signed and Apple-notarized macOS dropper to pass Gatekeeper checks. Once launched, it can steal browser credentials, wallet data, password manager records, files, and keychain material. How the attack chain works: https://thehackernews.com/2026/07/crashsteale… ★ 2
🚨 A malware operator left its server wide open, exposing a 1,048-file phishing toolkit. A live campaign used a fake Mexican government site and WebDAV to drop an in-memory infostealer. The recovered files point to an AI-assisted build-and-… ★ 1 It appears the bridge TeleSwap had a $735K+ exploit on July 15, 2026 and still has not disclosed the incident publicly after five days. Shortly after the suspicious outflows its Bitcoin hot wallet stopped processing transactions. Two hours… ★ 1 🛑 Hugging Face, the world’s largest AI model repository, says an autonomous AI agent breached its production systems through a malicious dataset. It accessed internal data and service credentials, then moved across several clusters through… ★ 1 🕷 Bugs Alerts ━━━━━━━━━━━━━━━━━━━━━ 🚨 New Vulnerability! 🆔 CVE ID: CVE-2026-12228 📊 Severity: 🟠 HIGH 📈 CVSS Score: 8.7 📅 Published: 2026-07-18 21:17 UTC 📝 Description: A stored cross-site scripting (XSS) vulnerability exists in the POST /a… ★ 1 ⚡ UPDATE: #wp2shell now has two CVEs, and a working proof-of-concept is public. > CVE-2026-63030 breaks REST batch routing > CVE-2026-60137 injects SQL Chained, they give an anonymous attacker code execution on affected WordPress sites. Ho… ★ 1 🛑 URGENT - A single anonymous HTTP request can run code on an unpatched #WordPress 6.9 or 7.0 site, even on a default install with zero plugins. The new wp2shell flaw sits in core and still has no CVE for scanners to match. Affected releas… ★ 1 🛑 Two Scattered Spider hackers have been sentenced to 5.5 years each for the £29 million TfL attack. The intrusion left 148 systems inoperable, disrupted Dial-a-Ride and payment services, and forced all 27,000 employees into the office for… ★ 1 ⚠️ Researchers found raw LLM reasoning and an AI safety disclaimer left inside TuxBot v3 Evolution. The unfinished IoT botnet packs 1,496 Telnet credential pairs and exploit code for more than 30 device families. What already works: https:… ★ 1 🔥 Microsoft patched a record 622 CVEs, including two exploited zero-days in SharePoint Server and AD FS. The SharePoint flaw allows remote, unauthenticated privilege escalation. The AD FS bug lets authenticated attackers elevate privileges… ★ 1 🚨 Four malware clusters targeted Pakistani police with PlugX, ShadowPad, Remcos, and Cobalt Strike. At Balochistan Police, attackers used a hacked complaint portal to deliver malware. Read the full report: https://thehackernews.com/2026/07… ★ 1 🚨 Zimbra has fixed a critical stored XSS flaw in its Classic Web Client. A crafted email could run malicious code when opened and expose mailbox information, session data, or account settings. Read the full story on THN 🠖 https://thehacker… ★ 1

🐘 Community & instance

Home server
infosec.exchange
A cybersecurity & infosec server — its members and audience skew toward that niche, so expect a community-aligned, engaged following.
✅ Link-verified
Verified link
Proved ownership of a website linked on their profile — Mastodon's green-check verification, a real identity signal rather than a paid badge.
On Mastodon since
Nov 2022
Joined in the Twitter-exodus wave of late 2022 — part of the migration that made Mastodon a real destination.

💡 Facts

🗓️Joined Mastodon in 2022 — 3 years ago.
👁️Averages 1 views per post.
📤Posts about 9.3× per week.

🛡️ Audience credibility

89/100 Excellent
  • Est. 99% real, active audience · Low fake-follower risk.
  • Strong engagement (~1.4% of followers engage each post) — an active, real audience.
  • Verified account.
  • Established account (3+ years old).
Est. authentic audience
99%
Fake-follower risk
Low
Data confidence
High

Heuristic estimate from engagement, follower ratios, account age & growth — a screening signal, not a guarantee.

About

If olive oil comes from olives 🫒 where does baby oil come from? 🤔 🥸

✉ Message tomcat

Reaching out to influencers is a Pro feature. Upgrade to message any influencer directly — perfect for brands and agencies booking sponsorships.

See Pro $9.95/mo →

Already Pro? Log in.

🎤 Event / appearance with tomcat

Booking an event / appearance is a Pro feature. Upgrade to book tomcat for an in-person or virtual appearance — payment held safely in escrow until the event is done.

See Pro $9.95/mo →

Already Pro? Log in.