151 registros (pagina 2 de 4) · Twitter/X: 151.
Ransomware Monitor: Actor: #incransom Victim: Life Bridges Date: 2026-06-26 05:08:35 UTC+3 According to #DarkWeb #Ransomware activity detected by the ThreatMon Threat Intelligence Team. The “#incransom” Ransomware group has added Life Bridges to its victims.
2026-06-26
TMRansomMon Twitter/X
Actor: #incransom Victim: Life Bridges Date: 2026-06-26 05:08:35 UTC+3 According to #DarkWeb #Ransomware activity detected by the ThreatMon Threat Intelligence Team. The “#incransom” Ransomware group has added Life Bridges to its victims. Ransomware …
Ransomware Monitor: Actor: #nightspire Victim: Grupo Riquelme Date: 2026-06-26 03:15:53 UTC+3 According to #DarkWeb #Ransomware activity detected by the ThreatMon Threat Intelligence Team. The “#nightspire” Ransomware group has added Grupo Riquelme to its victims.
2026-06-26
TMRansomMon Twitter/X
Actor: #nightspire Victim: Grupo Riquelme Date: 2026-06-26 03:15:53 UTC+3 According to #DarkWeb #Ransomware activity detected by the ThreatMon Threat Intelligence Team. The “#nightspire” Ransomware group has added Grupo Riquelme to its victims. Ranso…
Hackmanac: RT by @H4ckmanac: Cyber Alert ‼ Spain - 𝗟𝗲𝗿𝗼𝘆 𝗠𝗲𝗿𝗹𝗶𝗻 𝗘𝘀𝗽𝗮ñ𝗮 The threat actor Saturne claimed to have leaked a database belonging to Leroy Merlin Spain, allegedly exposing 54,723 customer records. The leaked data reportedly includes personal, contact, billing, store card, address, and Spanish DNI information.
2026-06-26
H4ckmanac Twitter/X
RT by @H4ckmanac: Cyber Alert ‼ Spain - 𝗟𝗲𝗿𝗼𝘆 𝗠𝗲𝗿𝗹𝗶𝗻 𝗘𝘀𝗽𝗮ñ𝗮 The threat actor Saturne claimed to have leaked a database belonging to Leroy Merlin Spain, allegedly exposing 54,723 customer records. The leaked data reportedly includes personal, contact,…
Hackmanac: #RiskFriday 𝟏𝟕-𝟐𝟑/𝟎𝟔/𝟐𝟎𝟐𝟔 Here’s this week’s snapshot from https://hackrisk.io based on our proprietary 𝐄𝐒𝐈𝐗© (𝐸𝑠𝑡𝑖𝑚𝑎𝑡𝑒𝑑 𝑆𝑒𝑣𝑒𝑟𝑖𝑡𝑦 𝐼𝑛𝑑𝑒𝑥) metric that measures operational, financial (direct & indirect), technical and reputational impact of cyber attacks. 𝐓𝐡𝐢𝐬 𝐰𝐞𝐞𝐤 𝐫𝐞𝐜𝐨𝐫𝐝𝐬 𝐚 𝐬𝐢𝐠𝐧𝐢𝐟𝐢𝐜𝐚𝐧𝐭 𝐝𝐞𝐜𝐫𝐞𝐚𝐬𝐞 𝐢𝐧 𝐚𝐧𝐚𝐥𝐲𝐬𝐞𝐝 𝐜𝐲𝐛𝐞𝐫 𝐚𝐭𝐭𝐚𝐜𝐤𝐬 𝐚𝐥𝐨𝐧𝐠𝐬𝐢𝐝𝐞 𝐚 𝐬𝐥𝐢𝐠𝐡𝐭 𝐝𝐞𝐜𝐥𝐢𝐧𝐞 𝐢𝐧 𝐭𝐡𝐞 𝐆𝐥𝐨𝐛𝐚𝐥 𝐀𝐯𝐞𝐫𝐚𝐠𝐞 𝐄𝐒𝐈𝐗©, 𝐢𝐧𝐝𝐢𝐜𝐚𝐭𝐢𝐧𝐠 𝐥𝐨𝐰𝐞𝐫 𝐚𝐜𝐭𝐢𝐯𝐢𝐭𝐲 𝐰𝐢𝐭𝐡 𝐥𝐚𝐫𝐠𝐞𝐥𝐲 𝐬𝐭𝐚𝐛𝐥𝐞 𝐢𝐦𝐩𝐚𝐜𝐭 𝐥𝐞𝐯𝐞𝐥𝐬.
2026-06-26
H4ckmanac Twitter/X
#RiskFriday 𝟏𝟕-𝟐𝟑/𝟎𝟔/𝟐𝟎𝟐𝟔 Here’s this week’s snapshot from https://hackrisk.io based on our proprietary 𝐄𝐒𝐈𝐗© (𝐸𝑠𝑡𝑖𝑚𝑎𝑡𝑒𝑑 𝑆𝑒𝑣𝑒𝑟𝑖𝑡𝑦 𝐼𝑛𝑑𝑒𝑥) metric that measures operational, financial (direct & indirect), technical and reputational impact of cyber a…
Hackmanac: Cyber Alert ‼ USA - 𝗣𝗼𝗹𝘆𝗺𝗮𝗿𝗸𝗲𝘁 Polymarket confirmed a third-party compromise that enabled attackers to inject malicious code into its website, leading to the theft of user funds. The company contained the incident and will refund affected users. Around the same time, researchers reported a phishing campaign targeting Polymarket users that allegedly stole about US$3 million in cryptocurrency.
2026-06-26
H4ckmanac Twitter/X
Cyber Alert ‼ USA - 𝗣𝗼𝗹𝘆𝗺𝗮𝗿𝗸𝗲𝘁 Polymarket confirmed a third-party compromise that enabled attackers to inject malicious code into its website, leading to the theft of user funds. The company contained the incident and will refund affected users. Arou…
Hackmanac: Cyber Alert ‼ USA - 𝗖𝗮𝗹 𝗔𝗜 A threat actor using the name "calaibreached" claimed to be selling a database allegedly belonging to Cal AI, containing 12,002,324 records. Threat actor: calaibreached Sector: ICT Data exposure (claimed): 12,002,324 records Data type: CSV records Observed: Jun 26, 2026 Status: Pending verification ESIX©: 6.34 Full details and impact assessment on http://HackRisk.io
2026-06-26
H4ckmanac Twitter/X
Cyber Alert ‼ USA - 𝗖𝗮𝗹 𝗔𝗜 A threat actor using the name "calaibreached" claimed to be selling a database allegedly belonging to Cal AI, containing 12,002,324 records. Threat actor: calaibreached Sector: ICT Data exposure (claimed): 12,002,…
Hackmanac: @heiseonline @golem @etguenni
2026-06-26
H4ckmanac Twitter/X
@heiseonline @golem @etguenni Threat intelligence and cyber alert feed covering data breaches, ransomware incidents and vulnerability disclosures. @heiseonline @golem @etguenni Referencias Tweet original en X Perfil de @H4ckmanac
Hackmanac: Cyber Alert ‼ Dominican Republic - 𝗣𝗢𝗟𝗜𝗧𝗨𝗥 Krybit hacking group claims to have breached POLITUR. Allegedly, the attackers exfiltrated 154 GB of data. Threat actor: Krybit Sector: Gov / Mil / LE Data exposure (claimed): 154 GB of data Data type: Not specified Observed: Jun 25, 2026 Status: Pending verification ESIX©: 5.94 Full details and impact assessment on http://HackRisk.io
2026-06-26
H4ckmanac Twitter/X
Cyber Alert ‼ Dominican Republic - 𝗣𝗢𝗟𝗜𝗧𝗨𝗥 Krybit hacking group claims to have breached POLITUR. Allegedly, the attackers exfiltrated 154 GB of data. Threat actor: Krybit Sector: Gov / Mil / LE Data exposure (claimed): 154 GB of data Data type: Not s…
Hackmanac: Cyber Alert ‼ Germany - 𝗔𝘁𝗹𝗮𝘀 𝗘𝗹𝗲𝗸𝘁𝗿𝗼𝗻𝗶𝗸 The Gentlemen hacking group claims to have breached Atlas Elektronik. Threat actor: The Gentlemen Sector: Manufacturing Data exposure (claimed): Not specified Data type: Not specified Observed: Jun 25, 2026 Status: Pending verification ESIX©: 5.94 Full details and impact assessment on http://HackRisk.io
2026-06-26
H4ckmanac Twitter/X
Cyber Alert ‼ Germany - 𝗔𝘁𝗹𝗮𝘀 𝗘𝗹𝗲𝗸𝘁𝗿𝗼𝗻𝗶𝗸 The Gentlemen hacking group claims to have breached Atlas Elektronik. Threat actor: The Gentlemen Sector: Manufacturing Data exposure (claimed): Not specified Data type: Not specified Observed: Jun 25, 2026 St…
StealthMole: 𝗗𝗮𝘆 𝟮 𝗶𝘀 𝗶𝗻 𝗳𝘂𝗹𝗹 𝘀𝘄𝗶𝗻𝗴 𝗮𝘁 𝗜𝗻𝘁𝗲𝗿𝗻𝗮𝘁𝗶𝗼𝗻𝗮𝗹 𝗣𝗼𝗹𝗶𝗰𝗲 𝗘𝘅𝗽𝗼 𝟮𝟬𝟮𝟲! The best part of an event isn't the presentations. It's the conversations happening in between. Day 2 has been full of great discussions, new connections, and live demos at the StealthMole booth. Thank you to everyone who's stopped by so far! If you're at the expo today, come visit us at 𝗕𝗼𝗼𝘁𝗵 𝗔𝟮𝟯. There's still plenty of time to connect, exchange ideas, and see StealthMole in action.
2026-06-25
stealthmole_int Twitter/X
𝗗𝗮𝘆 𝟮 𝗶𝘀 𝗶𝗻 𝗳𝘂𝗹𝗹 𝘀𝘄𝗶𝗻𝗴 𝗮𝘁 𝗜𝗻𝘁𝗲𝗿𝗻𝗮𝘁𝗶𝗼𝗻𝗮𝗹 𝗣𝗼𝗹𝗶𝗰𝗲 𝗘𝘅𝗽𝗼 𝟮𝟬𝟮𝟲! The best part of an event isn't the presentations. It's the conversations happening in between. Day 2 has been full of great discussions, new connections, and live demos at the Steal…
StealthMole: One thing we've learned from 𝗗𝗮𝘆 𝟭 𝗮𝘁 𝗜𝗻𝘁𝗲𝗿𝗻𝗮𝘁𝗶𝗼𝗻𝗮𝗹 𝗣𝗼𝗹𝗶𝗰𝗲 𝗘𝘅𝗽𝗼 𝟮𝟬𝟮𝟲 The best part of any event isn't the booth. It's the people you meet. Today was filled with conversations, new perspectives, and plenty of great moments with visitors, partners, and friends from across the industry. Thank you to everyone who spent time with us at 𝗕𝗼𝗼𝘁𝗵 𝗔𝟮𝟯.
2026-06-25
stealthmole_int Twitter/X
One thing we've learned from 𝗗𝗮𝘆 𝟭 𝗮𝘁 𝗜𝗻𝘁𝗲𝗿𝗻𝗮𝘁𝗶𝗼𝗻𝗮𝗹 𝗣𝗼𝗹𝗶𝗰𝗲 𝗘𝘅𝗽𝗼 𝟮𝟬𝟮𝟲 The best part of any event isn't the booth. It's the people you meet. Today was filled with conversations, new perspectives, and plenty of great moments with visitors…
Unit 42 Intel: We identified a deceptive browser extension campaign involved in affiliate marketing fraud, impersonating consumer brands (streaming, productivity, music, etc) with typosquatted .shop domains. 2,000-plus installations so far. Details at https://bit.ly/4uRmWCZ
2026-06-25
Unit42_Intel Twitter/X
We identified a deceptive browser extension campaign involved in affiliate marketing fraud, impersonating consumer brands (streaming, productivity, music, etc) with typosquatted .shop domains. 2,000-plus installations so far. Details at https://bit.l…
Ido Cohen: Stormous is back with increased activity. Recent victims have had their public websites defaced with a ransomware message displayed directly on the homepage—a pressure tactic sometimes used by ransomware groups to increase urgency and force negotiations. DarkFeed makes it easy to compare a ransomware group's leak site with the victim's public website in one place, helping analysts quickly identify attacks like these.
2026-06-25
ido_cohen2 Twitter/X
Stormous is back with increased activity. Recent victims have had their public websites defaced with a ransomware message displayed directly on the homepage—a pressure tactic sometimes used by ransomware groups to increase urgency and force negotiati…
Ido Cohen: Country Spotlight: Canada Over the past 7 days, our AI-powered platform tracked ransomware and cyber extortion attacks targeting Canada.
2026-06-25
ido_cohen2 Twitter/X
Country Spotlight: Canada Over the past 7 days, our AI-powered platform tracked ransomware and cyber extortion attacks targeting Canada. Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitat…
Ido Cohen: Sector Spotlight: HealthCare Over the past 7 days, our AI-powered platform tracked ransomware and cyber extortion groups actively targeting the HealthCare sector.
2026-06-25
ido_cohen2 Twitter/X
Sector Spotlight: HealthCare Over the past 7 days, our AI-powered platform tracked ransomware and cyber extortion groups actively targeting the HealthCare sector. Independent cyber threat research covering malware campaigns, phishing infrastructure a…
Group-IB Threat Intelligence: How is the Millenium RAT developer "ShinyEnigma" enabling widespread access to this threat through a low-cost MaaS model? Read our full technical analysis on the command structure, persistence mechanisms, and complete MITRE ATT&CK mapping to protect your organization: https://link.group-ib.com/4eGkRE1
2026-06-25
GroupIB_TI Twitter/X
How is the Millenium RAT developer "ShinyEnigma" enabling widespread access to this threat through a low-cost MaaS model? Read our full technical analysis on the command structure, persistence mechanisms, and complete MITRE ATT&CK mappi…
Group-IB Threat Intelligence: The Y2K Operators threat actor is using sophisticated #socialengineering lures, disguising payloads as legitimate software, cracked applications, gaming cheat tools (e.g., Roblox), and used PDF decoy documents.
2026-06-25
GroupIB_TI Twitter/X
The Y2K Operators threat actor is using sophisticated #socialengineering lures, disguising payloads as legitimate software, cracked applications, gaming cheat tools (e.g., Roblox), and used PDF decoy documents. Group-IB Threat Intelligence feed featu…
Group-IB Threat Intelligence: Group-IB telemetry has identified over 62,000 compromised endpoints across more than 160 countries infected with #MilleniumRAT (4.x). The infection velocity is alarming, with over 39,000 of these detections occurring in Q1 2026 alone, representing 64% of all infections. This demonstrates a rapidly accelerating global campaign.
2026-06-25
GroupIB_TI Twitter/X
Group-IB telemetry has identified over 62,000 compromised endpoints across more than 160 countries infected with #MilleniumRAT (4.x). The infection velocity is alarming, with over 39,000 of these detections occurring in Q1 2026 alone, representing 64…
Group-IB Threat Intelligence: Pinned: #MilleniumRAT (v4.x) marks a significant evolution in the threat landscape. The #malware has been completely rewritten from .NET to a native C++ application, removing .NET dependencies. This architectural shift enables greater stealth and resilience, making detection more challenging. The #Telegram Bot API remains the core C2 mechanism.
2026-06-25
GroupIB_TI Twitter/X
Pinned: #MilleniumRAT (v4.x) marks a significant evolution in the threat landscape. The #malware has been completely rewritten from .NET to a native C++ application, removing .NET dependencies. This architectural shift enables greater stealth and res…
Hackmanac: RT by @H4ckmanac: Cyber Alert ‼ Spain: 𝗠𝘂𝘁𝘂𝗮 𝗠á𝘀 - 𝗘𝗹𝗣𝗮𝗿𝗸𝗶𝗻𝗴 Mutua Más disclosed a data breach affecting its ElParking app after unauthorised access, exposing user email addresses, phone numbers, licence plates, and DNI numbers. Threat actor: Not specified Sector: ICT Data exposure (claimed): Not specified Data type: Email addresses, phone numbers, licence plates, and DNI numbers Observed: Jun 14, 2026 Status: Confirmed ESIX©: 5.15 Full details and impact assessment on http://HackRisk.io
2026-06-25
H4ckmanac Twitter/X
RT by @H4ckmanac: Cyber Alert ‼ Spain: 𝗠𝘂𝘁𝘂𝗮 𝗠á𝘀 - 𝗘𝗹𝗣𝗮𝗿𝗸𝗶𝗻𝗴 Mutua Más disclosed a data breach affecting its ElParking app after unauthorised access, exposing user email addresses, phone numbers, licence plates, and DNI numbers. Threat actor: Not spe…
Hackmanac: Source: https://www.democrata.es/en/economy/data-breach-at-mutua-mas-s-elparking-emails-phone-numbers-license-plates-and-national-id-numbers-of-users-exposed/
2026-06-25
H4ckmanac Twitter/X
Source: https://www.democrata.es/en/economy/data-breach-at-mutua-mas-s-elparking-emails-phone-numbers-license-plates-and-national-id-numbers-of-users-exposed/ Threat intelligence and cyber alert feed covering data breaches, ransomware incidents and v…
Hackmanac: Cyber Alert ‼ Italy - 𝗣𝗜𝗡𝗞𝗢 betway threat actor claims to have breached PINKO, allegedly exfiltrating 3,000,000 records related to customers. Threat actor: betway Sector: Wholesale / Retail Data exposure (claimed): 3,000,000 records Data type: Customer data Observed: Jun 23, 2026 Status: Pending verification ESIX©: 6.52 Full details and impact assessment on http://HackRisk.io
2026-06-25
H4ckmanac Twitter/X
Cyber Alert ‼ Italy - 𝗣𝗜𝗡𝗞𝗢 betway threat actor claims to have breached PINKO, allegedly exfiltrating 3,000,000 records related to customers. Threat actor: betway Sector: Wholesale / Retail Data exposure (claimed): 3,000,000 records Data type: Custom…
Hackmanac: Cyber Alert ‼ Peru - 𝗢𝘀𝗶 𝗠𝗲𝗱𝗶𝗰𝗮𝗹 𝗖𝗲𝗻𝘁𝗲𝗿 Kazu threat actor claimed a data breach on Peru’s Centro Médico Especializado OSI, allegedly exfiltrating data from 159,824 users across 504,413 files. Threat actor: Kazu Sector: Healthcare Data exposure (claimed): 159,824 users across 504,413 files Data type: User data Observed: Jun 24, 2026 Status: Pending verification ESIX©: 6.57 Full details and impact assessment on http://HackRisk.io
2026-06-25
H4ckmanac Twitter/X
Cyber Alert ‼ Peru - 𝗢𝘀𝗶 𝗠𝗲𝗱𝗶𝗰𝗮𝗹 𝗖𝗲𝗻𝘁𝗲𝗿 Kazu threat actor claimed a data breach on Peru’s Centro Médico Especializado OSI, allegedly exfiltrating data from 159,824 users across 504,413 files. Threat actor: Kazu Sector: Healthcare Data exposure (claim…
StealthMole: RT by @stealthmole_int: Following the Money: Mapping KidBin's Cryptocurrency Infrastructure Across Darkweb Note: When visiting this blog, you may see a "Sensitive Content" warning from Blogger. This warning is automatically generated by Google's systems based on the topics discussed on the site and does not necessarily indicate the presence of graphic or inappropriate material.
2026-06-24
stealthmole_int Twitter/X
RT by @stealthmole_int: Following the Money: Mapping KidBin's Cryptocurrency Infrastructure Across Darkweb Note: When visiting this blog, you may see a "Sensitive Content" warning from Blogger. This warning is automatically generated b…
StealthMole: Security OSINT Highlights — Third Week of June 2026 The reporting set is dominated by vulnerability activity, with repeated coverage of actively exploited flaws, broad multi-CVE product advisories, and several clusters affecting browsers, enterprise software, network infrastructure, and developer tooling. A smaller but notable portion covers phishing, supply-chain compromise, malware delivery, and credential theft infrastructure.
2026-06-24
stealthmole_int Twitter/X
Security OSINT Highlights — Third Week of June 2026 The reporting set is dominated by vulnerability activity, with repeated coverage of actively exploited flaws, broad multi-CVE product advisories, and several clusters affecting browsers, enterprise …
Unit 42 Intel: We detected a Browser-in-the-Browser phishing kit for malware delivery rather than credential theft. It uses a draggable pop-up with a spoofed URL to serve a fake "software out of date" warning. It sends malware that it instructs users to run. Details at https://bit.ly/3SFpmHp
2026-06-24
Unit42_Intel Twitter/X
We detected a Browser-in-the-Browser phishing kit for malware delivery rather than credential theft. It uses a draggable pop-up with a spoofed URL to serve a fake "software out of date" warning. It sends malware that it instructs users to r…
Ido Cohen: We continue to monitor additional sources in the darknet. Here are some of the events that were added to our platform in the last week. 1 A major breach exposed over 500GB of sensitive personal information from job seekers, posing a high risk of identity theft and fraud. 2 Remote access to POS systems is being sold, threatening financial data and sensitive customer information across large retail businesses globally.
2026-06-24
ido_cohen2 Twitter/X
We continue to monitor additional sources in the darknet. Here are some of the events that were added to our platform in the last week. 1 A major breach exposed over 500GB of sensitive personal information from job seekers, posing a high risk of iden…
Ido Cohen: The Gentleman is on another victim-publishing spree. Today alone, the group added victims across multiple sectors and regions, including: Construction, Healthcare Retail Manufacturing Media & Culture Engineering & IT Services Real Estate Business Services Mining & Resources Several of the affected organizations operate in critical supply chains, industrial services, healthcare, and national economic sectors. The Gentleman continues to be one of the most active ransomware groups of 2026.
2026-06-24
ido_cohen2 Twitter/X
The Gentleman is on another victim-publishing spree. Today alone, the group added victims across multiple sectors and regions, including: Construction, Healthcare Retail Manufacturing Media & Culture Engineering & IT Services Real Estate Busi…
Ido Cohen: 24H Cyber Pulse — ransomware & breach activity snapshot Total Attacks (24h): 18 Top Countries (24h): United States: 6 Brazil: 2 Colombia: 1 Myanmar: 1 South Korea: 1 Top Sectors (24h): Financial: 3 HealthCare: 2 Retail: 2 Technology: 1 Legal: 1 Top Groups (24h): APT73: 3 RALord: 2 INC: 2 Akira: 2 Lapsus: 1 https://darkfeed.io/get-started/ #CyberSecurity #Ransomware #ThreatIntelligence #InfoSec
2026-06-24
ido_cohen2 Twitter/X
24H Cyber Pulse — ransomware & breach activity snapshot Total Attacks (24h): 18 Top Countries (24h): United States: 6 Brazil: 2 Colombia: 1 Myanmar: 1 South Korea: 1 Top Sectors (24h): Financial: 3 HealthCare: 2 Retail: 2 Technology: 1 Legal: 1 T…
Hackmanac: RT by @H4ckmanac: Cyber Alert ‼ Japan - 𝗞𝗗𝗗𝗜 KDDI warned users to change their passwords after disclosing unauthorised access to its email system used by six internet service providers (ISPs), potentially exposing up to 14.22 million email accounts. The compromised information may include email addresses and passwords.
2026-06-24
H4ckmanac Twitter/X
RT by @H4ckmanac: Cyber Alert ‼ Japan - 𝗞𝗗𝗗𝗜 KDDI warned users to change their passwords after disclosing unauthorised access to its email system used by six internet service providers (ISPs), potentially exposing up to 14.22 million email accounts. …
Hackmanac: Cyber Alert ‼ Kuwait - 𝗗𝗵𝗼𝘄 𝗜𝗻𝘁𝗲𝗿𝗻𝗮𝘁𝗶𝗼𝗻𝗮𝗹 𝗛𝗼𝗹𝗱𝗶𝗻𝗴 The Gentlemen ransomware group claims to have breached Dhow International Holding. Threat actor: The Gentlemen Sector: Financial Data exposure (claimed): Not specified Data type: Not specified Observed: Jun 24, 2026 Status: Pending verification ESIX©: 5.76 Full details and impact assessment on http://HackRisk.io
2026-06-24
H4ckmanac Twitter/X
Cyber Alert ‼ Kuwait - 𝗗𝗵𝗼𝘄 𝗜𝗻𝘁𝗲𝗿𝗻𝗮𝘁𝗶𝗼𝗻𝗮𝗹 𝗛𝗼𝗹𝗱𝗶𝗻𝗴 The Gentlemen ransomware group claims to have breached Dhow International Holding. Threat actor: The Gentlemen Sector: Financial Data exposure (claimed): Not specified Data type: Not specified Observe…
Hackmanac: Source: https://www.47news.jp/14513146.html
2026-06-24
H4ckmanac Twitter/X
Source: https://www.47news.jp/14513146.html Threat intelligence and cyber alert feed covering data breaches, ransomware incidents and vulnerability disclosures. Source: 47news.jp/14513146.html Link 速報1422万件メール情報漏えいとKDDI KDDIは23日プロバイダー6社に提供するメールシステムに不…
StealthMole: RT by @stealthmole_int: Government-Related Leak and Sale Activity Observed Across Dark Web and Deep Web Sources — 3rd Week of June 2026 Observed activity shows a broad set of government-related leak, sale, and extortion-related postings distributed across forum threads, paste sites, and ransomware leak sites. The activity spans multiple regions, with recurring exposure involving government institutions, police-related data, judicial bodies, health-sector entities, and government domains.
2026-06-23
stealthmole_int Twitter/X
RT by @stealthmole_int: Government-Related Leak and Sale Activity Observed Across Dark Web and Deep Web Sources — 3rd Week of June 2026 Observed activity shows a broad set of government-related leak, sale, and extortion-related postings distributed a…
Unit 42 Intel: The latest macOS ClickFix variant invisibly mounts DMG images in the background to execute a macOS infostealer and hijack cryptocurrency wallet info. Details at https://bit.ly/4ahgmhJ
2026-06-23
Unit42_Intel Twitter/X
The latest macOS ClickFix variant invisibly mounts DMG images in the background to execute a macOS infostealer and hijack cryptocurrency wallet info. Details at https://bit.ly/4ahgmhJ Palo Alto Networks Unit 42 threat intelligence on APT groups, rans…
Ido Cohen: The Icarus supply chain extortion campaign continues to unfold. The group has now added 5 additional victims, all with their identities partially concealed. The guessing game has officially begun. How many organizations were impacted through this supply chain incident? And are we witnessing the emergence of a serious competitor to CLOP in the supply chain extortion arena? We'll know more soon.
2026-06-23
ido_cohen2 Twitter/X
The Icarus supply chain extortion campaign continues to unfold. The group has now added 5 additional victims, all with their identities partially concealed. The guessing game has officially begun. How many organizations were impacted through this sup…
Ido Cohen: APT73 continues to expand its operations. The group has added 3 new victims to its leak site, including a government entity in South America and a major international airport operator in Central Europe serving tens of millions of passengers annually. APT73 was added to the DarkFeed platform in mid-2024 and has since claimed 110+ victims.
2026-06-23
ido_cohen2 Twitter/X
APT73 continues to expand its operations. The group has added 3 new victims to its leak site, including a government entity in South America and a major international airport operator in Central Europe serving tens of millions of passengers annually.…
Ido Cohen: Meet Wallstreet — not the financial market, but the latest ransomware group added to our monitoring platform. The group's leak site currently lists a single victim: a manufacturing company from India. With 1,000+ ransomware and cyber extortion victims already tracked since the beginning of the year, keeping up with the threat landscape is becoming increasingly challenging.
2026-06-23
ido_cohen2 Twitter/X
Meet Wallstreet — not the financial market, but the latest ransomware group added to our monitoring platform. The group's leak site currently lists a single victim: a manufacturing company from India. With 1,000+ ransomware and cyber extortion v…
Hackmanac: #HackTuesday Hack Tuesday: Week 17 - 23 Jun 2026 374 cyber attacks across 62 countries The most active threat actor last week was NoName057(16) claiming responsibility for 38 cyber attacks. The USA is the most affected country, accounting for 21.4% of incidents, with 80 cyber attacks. The Gov / Mil / LE sector is the most targeted, accounting for 19.5% of incidents with 73 cyber attacks. The estimated Critical cyber attacks account to 54 (14.4% of the total).
2026-06-23
H4ckmanac Twitter/X
#HackTuesday Hack Tuesday: Week 17 - 23 Jun 2026 374 cyber attacks across 62 countries The most active threat actor last week was NoName057(16) claiming responsibility for 38 cyber attacks. The USA is the most affected country, accounting for 21.4% o…
Unit 42 Intel: An evolved deepfake video campaign is distributing an AI-generated instructional video that guides social media users through stealing their own session cookies via the browser's DevTools. Abuse of 6 SaaS platforms with 800+ lure pages so far. Details at https://bit.ly/4vYxmle
2026-06-22
Unit42_Intel Twitter/X
An evolved deepfake video campaign is distributing an AI-generated instructional video that guides social media users through stealing their own session cookies via the browser's DevTools. Abuse of 6 SaaS platforms with 800+ lure pages so far. D…
Unit 42 Intel: FortiBleed is a large-scale password spraying and credential theft campaign targeting Fortinet, Sophos and MSSQL devices. Threat actors are using a curated password list developed through previous breaches and vulnerability exploits. We detail mitigations: https://bit.ly/4eDxSxY
2026-06-22
Unit42_Intel Twitter/X
FortiBleed is a large-scale password spraying and credential theft campaign targeting Fortinet, Sophos and MSSQL devices. Threat actors are using a curated password list developed through previous breaches and vulnerability exploits. We detail mitiga…
Ido Cohen: Threat Group Update Prinz Eugen has launched a newly redesigned leak site and updated its public profile. According to the group's latest statement, it describes itself as a for-profit organization that "specializes in hacking" while claiming it currently does not operate a Ransomware-as-a-Service (RaaS) program. The group also stated that membership intake is currently closed and limited to existing core members.
2026-06-22
ido_cohen2 Twitter/X
Threat Group Update Prinz Eugen has launched a newly redesigned leak site and updated its public profile. According to the group's latest statement, it describes itself as a for-profit organization that "specializes in hacking" while c…
Ido Cohen: Qilin remains one of the most active ransomware groups in the threat landscape. The group has recently claimed a new victim from Libya's financial sector, continuing its aggressive pace of operations. Over the past year, Qilin has consistently published dozens of victims every month and remains a leading ransomware operation globally. Track ransomware activity with us: https://darkfeed.io/get-started/ #Ransomware #Qilin #CyberSecurity #ThreatIntel #FinancialSector
2026-06-22
ido_cohen2 Twitter/X
Qilin remains one of the most active ransomware groups in the threat landscape. The group has recently claimed a new victim from Libya's financial sector, continuing its aggressive pace of operations. Over the past year, Qilin has consistently p…
Ido Cohen: Weekly Ransomware & Cyber Extortion Intelligence Report Our platform continuously monitors ransomware groups and darknet activity worldwide.
2026-06-22
ido_cohen2 Twitter/X
Weekly Ransomware & Cyber Extortion Intelligence Report Our platform continuously monitors ransomware groups and darknet activity worldwide. Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability e…
Hackmanac: RT by @H4ckmanac: #MondayPoll: What worries you most for H2 2026?
2026-06-22
H4ckmanac Twitter/X
RT by @H4ckmanac: #MondayPoll: What worries you most for H2 2026? Threat intelligence and cyber alert feed covering data breaches, ransomware incidents and vulnerability disclosures. #MondayPoll: What worries you most for H2 2026? Poll 25% — Ransomwa…
Ido Cohen: Supply Chain Extortion Alert The Icarus ransomware group has escalated pressure tactics against a major Canadian consulting and competitive intelligence provider. After initially naming the organization, the group is now threatening to release data belonging to the company's clients, giving them a deadline to make contact before publication begins.
2026-06-21
ido_cohen2 Twitter/X
Supply Chain Extortion Alert The Icarus ransomware group has escalated pressure tactics against a major Canadian consulting and competitive intelligence provider. After initially naming the organization, the group is now threatening to release data b…
Ido Cohen: New Ransomware Groups Added to DarkFeed Over the past few days, we added two new ransomware/extortion groups to the DarkFeed intelligence platform: SevyWare A newly launched RaaS operation claiming ties to former members of established ransomware groups. The operators are actively recruiting Initial Access Brokers and insiders while promoting an aggressive affiliate-focused model.
2026-06-21
ido_cohen2 Twitter/X
New Ransomware Groups Added to DarkFeed Over the past few days, we added two new ransomware/extortion groups to the DarkFeed intelligence platform: SevyWare A newly launched RaaS operation claiming ties to former members of established ransomware gro…
Ido Cohen: A new ransomware-linked vulnerability has recently been added to DarkFeed's CISA KEV monitoring. CVE-2026-35273 affects Oracle PeopleSoft Enterprise PeopleTools and allows unauthenticated attackers to potentially gain control over vulnerable systems. The vulnerability is already listed in CISA's Known Exploited Vulnerabilities catalog and has been associated with ransomware activity. Organizations using PeopleSoft should prioritize patching and exposure assessment.
2026-06-20
ido_cohen2 Twitter/X
A new ransomware-linked vulnerability has recently been added to DarkFeed's CISA KEV monitoring. CVE-2026-35273 affects Oracle PeopleSoft Enterprise PeopleTools and allows unauthenticated attackers to potentially gain control over vulnerable sys…
Unit 42 Intel: We identified a vulnerability in the Google Cloud Vertex AI SDK for Python involving predictable staging bucket names. This flaw enabled remote code execution through bucket squatting and pickle deserialization. Read our analysis for technical details: https://bit.ly/3QGwFxY
2026-06-19
Unit42_Intel Twitter/X
We identified a vulnerability in the Google Cloud Vertex AI SDK for Python involving predictable staging bucket names. This flaw enabled remote code execution through bucket squatting and pickle deserialization. Read our analysis for technical detail…
StealthMole: NEET Exam Leak: We Saw It Coming StealthMole AI Agent detected a 430% surge in NEET-related dark web activity before the leak went public.
2026-06-18
stealthmole_int Twitter/X
NEET Exam Leak: We Saw It Coming StealthMole AI Agent detected a 430% surge in NEET-related dark web activity before the leak went public. StealthMole cyber threat intelligence on ransomware, data leaks and criminal underground ecosystems. NEET Exam …
Unit 42 Intel: A large email #phishing campaign impersonates popular retail stores with expiring reward points as a lure. Emails are likely generated from a shared kit with LLM-crafted text, unique nonce padding to evade classifiers, hidden with CSS tricks. Details at https://bit.ly/4vRN8yb
2026-06-18
Unit42_Intel Twitter/X
A large email #phishing campaign impersonates popular retail stores with expiring reward points as a lure. Emails are likely generated from a shared kit with LLM-crafted text, unique nonce padding to evade classifiers, hidden with CSS tricks. Details…