Uptime Hamster: 24d 8h 58mDeploy: 3 Aug 2026 06:56Updated: 2026-07-21

Base de datos de filtraciones

26,283 registros (pagina 525 de 526) · Breachsense: 26106 · Twitter/X: 151 · Blog: 26.

Todas Breachsense (26106) Twitter/X (151) Blog (26)
StealthMole: RT by @stealthmole_int: 𝐀 𝐁𝐈𝐆 𝐭𝐡𝐚𝐧𝐤-𝐲𝐨𝐮 𝐭𝐨 @stealthmole_int , @offbyoneconf 𝐍𝐞𝐭𝐰𝐨𝐫𝐤𝐢𝐧𝐠 𝐒𝐩𝐨𝐧𝐬𝐨𝐫 𝐟𝐨𝐫 𝐭𝐡𝐞 𝟑𝐫𝐝 𝐲𝐞𝐚𝐫 𝐫𝐮𝐧𝐧𝐢𝐧𝐠! Meet the team at @offbyoneconf 2026! Grand Copthorne Waterfront Hotel Singapore 14–15 Sept 2026 https://merch.starlabs.sg/products/ob1-2026 2026-06-16
stealthmole_int Twitter/X

RT by @stealthmole_int: 𝐀 𝐁𝐈𝐆 𝐭𝐡𝐚𝐧𝐤-𝐲𝐨𝐮 𝐭𝐨 @stealthmole_int , @offbyoneconf 𝐍𝐞𝐭𝐰𝐨𝐫𝐤𝐢𝐧𝐠 𝐒𝐩𝐨𝐧𝐬𝐨𝐫 𝐟𝐨𝐫 𝐭𝐡𝐞 𝟑𝐫𝐝 𝐲𝐞𝐚𝐫 𝐫𝐮𝐧𝐧𝐢𝐧𝐠! Meet the team at @offbyoneconf 2026! Grand Copthorne Waterfront Hotel Singapore 14–15 Sept 2026 https://merch.starlabs.sg/product…

Leer articulo →
Unit 42 Intel: We detected a malicious browser extension campaign that trojanizes legitimate extensions to serve ads covertly. The extension categories include ad blocking, messaging privacy, screen recording and music control. 1,000+ installations so far. Details at https://bit.ly/4xtQcT3 2026-06-16
Unit42_Intel Twitter/X

We detected a malicious browser extension campaign that trojanizes legitimate extensions to serve ads covertly. The extension categories include ad blocking, messaging privacy, screen recording and music control. 1,000+ installations so far. Details …

Leer articulo →
Unit 42 Intel: Cloud logging services provide visibility but attackers target them to create weak spots. By manipulating encryption keys or redirecting log flows they can evade detection and monitor activity in real time. Our research analyzes these risks: https://bit.ly/3SlMYAJ 2026-06-16
Unit42_Intel Twitter/X

Cloud logging services provide visibility but attackers target them to create weak spots. By manipulating encryption keys or redirecting log flows they can evade detection and monitor activity in real time. Our research analyzes these risks: https://…

Leer articulo →
eCrime.ch: RT by @ecrime_ch: #ESETresearch has observed DeadLock ransomware expanding its use of Polygon blockchain smart contracts. Previously used only for chat proxy server address rotation, DeadLock has now added a new contract with the gang's DLS entries - a first of its kind we are aware of. 1/6 2026-06-16
ecrime_ch Twitter/X

RT by @ecrime_ch: #ESETresearch has observed DeadLock ransomware expanding its use of Polygon blockchain smart contracts. Previously used only for chat proxy server address rotation, DeadLock has now added a new contract with the gang's DLS entr…

Leer articulo →
Unit 42 Intel: Actors weaponize #AI hype: fake LLM domains, branded C2 infrastructure and payment skimmers. We tracked three active campaigns abusing AI lures and infrastructure. Details at https://bit.ly/3SHlc1D 2026-06-15
Unit42_Intel Twitter/X

Actors weaponize #AI hype: fake LLM domains, branded C2 infrastructure and payment skimmers. We tracked three active campaigns abusing AI lures and infrastructure. Details at https://bit.ly/3SHlc1D Palo Alto Networks Unit 42 threat intelligence on AP…

Leer articulo →
StealthMole: RT by @stealthmole_int: D4D 해커톤 두 번째 참여기업 - StealthMole . StealthMole은 D4D 해커톤 기간 중 해커톤 참가자들이 실제 다크웹에 있는 정보를 정제된 형태의 API로 제공받아, 이를 기반으로 개발할 수 있도록 지원합니다. . *StealthMole(스텔스몰)은 다크웹, 딥웹, 그리고 사이버 범죄 생태계를 추적하는 사이버 위협 인텔리전스(CTI, Cyber Threat Intelligence) 전문 기업입니다. . D4D 해커톤과 함께하는 기업은 지속해서 업데이트 예정입니다. 참가 신청 : https://luma.com/d4d 2026-06-12
stealthmole_int Twitter/X

RT by @stealthmole_int: D4D 해커톤 두 번째 참여기업 - StealthMole . StealthMole은 D4D 해커톤 기간 중 해커톤 참가자들이 실제 다크웹에 있는 정보를 정제된 형태의 API로 제공받아, 이를 기반으로 개발할 수 있도록 지원합니다. . *StealthMole(스텔스몰)은 다크웹, 딥웹, 그리고 사이버 범죄 생태계를 추적하는 사이버 위협 인텔리전스(CTI, Cyber Threat Intelligence) …

Leer articulo →
Unit 42 Intel: Unit 42 is tracking the active targeting of Oracle PeopleSoft servers by Bling Libra (aka #ShinyHunters). Our analysis reveals suspected exploitation of RCE flaw CVE-2026-35273 and primary targeting of the education sector since at least late May 2026. https://bit.ly/4xpxKLb 2026-06-12
Unit42_Intel Twitter/X

Unit 42 is tracking the active targeting of Oracle PeopleSoft servers by Bling Libra (aka #ShinyHunters). Our analysis reveals suspected exploitation of RCE flaw CVE-2026-35273 and primary targeting of the education sector since at least late May 202…

Leer articulo →
University of Nottingham 2026-06-11
breach

Resumen de la Filtracion El 11 de junio de 2026 se report├│ una filtraci├│n de datos asociada a la Universidad de Nottingham. Este incidente ha generado preocupaciones sobre la seguridad de informaci├│n personal y los posibles impactos en usuarios y …

Leer articulo →
Baker Distributing 2026-06-10
breach

Resumen de la Filtración Baker Distributing informó una filtración de datos el 2026-06-10, según reportes publicados en medios especializados. La empresa, que opera en sectores logísticos y distribuidos, enfrenta un incidente de ciberseguridad que po…

Leer articulo →
DentaQuest 2026-06-10
breach

DentaQuest Resumen de la Filtración: El grupo breach reportó una filtración de datos relacionada con DentaQuest el día 2026-06-10. Esta situación requiere atención inmediata debido a los riesgos potenciales para los usuarios y la privacidad de la inf…

Leer articulo →
BCD Travel 2026-06-10
breach

Resumen de la Filtración El 10 de junio de 2026 se reportó una filtración de datos relacionada con BCD Travel, un grupo de seguridad informática clasificado como "breach". La incidencia sugiere que información sensible podría haber sido expuesta, aun…

Leer articulo →
Atlas Menu 2026-06-10
breach

Resumen de la Filtracion Atlas Menu, un proveedor de servicios de restauración en Estados Unidos, reportó una filtración de datos el 2026-06-10. El incidente fue clasificado como parte del grupo "breach", lo que sugiere un evento de seguridad signifi…

Leer articulo →
Edmunds 2026-06-10
breach

Resumen de la Filtración Edmunds, un grupo de breach reportado el 2026-06-10, ha sido objetivo de una filtración de datos. Este incidente ha levantado preocupaciones sobre la seguridad de la información personal y financiera de sus usuarios. Datos Co…

Leer articulo →
Kemper 2026-06-10
breach

Resumen de la Filtracion Kemper informó una filtración de datos el 2026-06-10, perteneciente al grupo breach. La incidente involucró la exposición de información sensible, lo que generó preocupaciones por la seguridad de los usuarios afectados. Datos…

Leer articulo →
Charter 2026-06-10
breach

Resumen de la Filtracion Charter reportó una filtración de datos el 2026-06-10, según informes recientes. Esta incidencia afecta a usuarios y clientes de la empresa, generando preocupaciones sobre la seguridad de información sensible. La brecha se ha…

Leer articulo →
Ameriprise 2026-06-10
breach

Resumen de la Filtracion Ameriprise, un grupo perteneciente a la categoria breach, reporto una filtracion de datos el 2026-06-10. Este incidente representa un riesgo significativo para los usuarios y entidades relacionadas, destacando la necesidad de…

Leer articulo →
7-Eleven 2026-06-10
breach

Resumen de la Filtración 7-Eleven reportó una filtración de datos el 2026-06-10, perteneciente al grupo "breach". La incidente implica la posibilidad de que información sensible haya sido expuesta, aunque detalles específicos no fueron detallados en …

Leer articulo →
Dragonica Lunaris 2026-06-10
breach

Resumen de la Filtración Dragonica Lunaris, un incidente de seguridad reportado por el grupo breach, ocurrió el día 2026-06-10. Este evento involucró la filtración de datos sensibles, lo que genera preocupaciones sobre la protección de la información…

Leer articulo →
CTT 2026-06-10
breach

Resumen de la Filtración CTT ha sido reportada como un incidente de filtración de datos bajo el grupo breach. La brecha se comunicó el 2026-06-10, indicando que información sensible podría haberse visto expuesta. Este tipo de eventos requieren atenci…

Leer articulo →
Windows93 / Myspace93 2026-06-10
breach

Resumen de la Filtracion Se reportó una filtración de datos asociada al nombre Windows93 / Myspace93, atribuida al grupo Breach. La brecha ocurrió el 2026-06-10 y involucró la exposición de información sensible. Este tipo de incidentes pueden tener c…

Leer articulo →
Abrigo 2026-06-10
breach

Resumen de la Filtracion Abrigo, un incidente de filtración de datos reportado el 2026-06-10, ha sido identificado como parte del grupo breach. Este evento implica la exposición no autorizada de información sensible, lo que requiere una respuesta inm…

Leer articulo →
Addi 2026-06-10
breach

Resumen de la Filtración Se reportó una filtración de datos atribuida al grupo "breach" el día 2026-06-10, con el nombre del incidente "Addi". Este evento involucró la exposición de información sensible, lo que generó preocupaciones sobre la segurida…

Leer articulo →
Cushman & Wakefield 2026-06-10
breach

Resumen de la Filtracion Cushman & Wakefield reportó una filtración de datos el 2026-06-10, según informes recientes. Esta situación representa un riesgo potencial para los usuarios y clientes que hayan compartido información sensible con la empresa.…

Leer articulo →
Canada Life 2026-06-10
breach Canada

Resumen de la Filtracion Canada Life reportó una filtración de datos el 2026-06-10. El incidente involucró la exposición de información sensible de usuarios, según los registros oficiales. Aunque no se han divulgado detalles adicionales sobre el tipo…

Leer articulo →
Zara 2026-06-10
breach

Resumen de la Filtración Zara, una cadena de moda global, reportó una filtración de datos el 2026-06-10. El incidente fue identificado como parte de un grupo denominado "breach", lo que sugiere que se trata de una violación de seguridad relacionada c…

Leer articulo →
Woflow 2026-06-10
breach

Resumen de la Filtracion Woflow, un incidente de filtración de datos reportado el 2026-06-10, fue identificado como parte del grupo Breach. Este evento involucró la exposición de información sensible, lo que generó preocupaciones sobre la seguridad y…

Leer articulo →
LegionProxy 2026-06-10
breach

Resumen de la Filtracion LegionProxy, un sistema o servicio reportado como parte del grupo Breach, sufre una filtración de datos el 10 de junio de 2026. La brecha se ha asociado con la revelación de información sensible, lo que ha generado preocupaci…

Leer articulo →
StealthMole: RT by @stealthmole_int: Government-Related Darkweb/Deepweb Leak Activity — First Week of June 2026 Observed activity consists of 26 government-related leak or sale postings and 4 ransomware/extortion listings tied to public-sector or government-associated entities. The activity is distributed across multiple underground forums and Tor-hosted leak sites, with visible concentration on darkforums, spear, and craxpro. 2026-06-10
stealthmole_int Twitter/X

RT by @stealthmole_int: Government-Related Darkweb/Deepweb Leak Activity — First Week of June 2026 Observed activity consists of 26 government-related leak or sale postings and 4 ransomware/extortion listings tied to public-sector or government-assoc…

Leer articulo →
StealthMole: Security OSINT Highlights — First Week of June 2026 Reporting collected during the first week of June 2026 is dominated by vulnerability disclosures and exploitation-related alerts, with a secondary concentration in malware, espionage, and intrusion activity supported by file-hash and IP indicators. 2026-06-10
stealthmole_int Twitter/X

Security OSINT Highlights — First Week of June 2026 Reporting collected during the first week of June 2026 is dominated by vulnerability disclosures and exploitation-related alerts, with a secondary concentration in malware, espionage, and intrusion …

Leer articulo →
Group-IB Threat Intelligence: How are threat actors combining session hijacking, browser profile cloning, HVNC, and cryptocurrency-focused tooling into a commercial Malware-as-a-Service offering? Our latest analysis of SilabRAT explores its infrastructure, ClickFix-driven infection chains, technical capabilities, and the threat actor behind its development. Read the full report: https://link.group-ib.com/4xluZub 2026-06-10
GroupIB_TI Twitter/X

How are threat actors combining session hijacking, browser profile cloning, HVNC, and cryptocurrency-focused tooling into a commercial Malware-as-a-Service offering? Our latest analysis of SilabRAT explores its infrastructure, ClickFix-driven infecti…

Leer articulo →
Group-IB Threat Intelligence: SilabRAT places significant emphasis on #cryptocurrency theft. Beyond harvesting credentials and browser data, it can identify wallet-related artifacts and automatically attempt password recovery using credentials collected from infected systems. These additions reflect the growing focus on direct monetization within modern #malware ecosystems. 2026-06-10
GroupIB_TI Twitter/X

SilabRAT places significant emphasis on #cryptocurrency theft. Beyond harvesting credentials and browser data, it can identify wallet-related artifacts and automatically attempt password recovery using credentials collected from infected systems. The…

Leer articulo →
Group-IB Threat Intelligence: One of SilabRAT's most notable capabilities is its use of Hidden Virtual Network Computing (HVNC). By interacting with services directly from the victim's device, attackers can perform account activity, access sensitive platforms, and conduct fraudulent operations while appearing as a legitimate user originating from the trusted device and IP address. #InfoSec 2026-06-10
GroupIB_TI Twitter/X

One of SilabRAT's most notable capabilities is its use of Hidden Virtual Network Computing (HVNC). By interacting with services directly from the victim's device, attackers can perform account activity, access sensitive platforms, and condu…

Leer articulo →
Group-IB Threat Intelligence: As browser security evolves, attackers are moving beyond traditional cookie theft. #SilabRAT advertises browser profile cloning, allowing operators to replicate a victim's browser environment, including extensions, storage, and fingerprinting artifacts. This enables access to authenticated sessions that may otherwise resist conventional session hijacking techniques. #CyberThreats #ThreatIntelligence 2026-06-10
GroupIB_TI Twitter/X

As browser security evolves, attackers are moving beyond traditional cookie theft. #SilabRAT advertises browser profile cloning, allowing operators to replicate a victim's browser environment, including extensions, storage, and fingerprinting ar…

Leer articulo →
Group-IB Threat Intelligence: #SilabRAT is a newly emerging Malware-as-a-Service (#MaaS) platform developed by the threat actor "o1oo1" and advertised on underground forums since late 2025. Sold for $5,000 per month, the Remote Access Trojan (#RAT) combines credential theft, session hijacking, HVNC access, Chrome App-Bound Encryption bypasses using COM elevation, and cryptocurrency-focused tooling into a single platform built for financially motivated cybercrime. 2026-06-10
GroupIB_TI Twitter/X

#SilabRAT is a newly emerging Malware-as-a-Service (#MaaS) platform developed by the threat actor "o1oo1" and advertised on underground forums since late 2025. Sold for $5,000 per month, the Remote Access Trojan (#RAT) combines credential t…

Leer articulo →
StealthMole: RT by @stealthmole_int: How do you go from a single Bitcoin wallet to an entire dark web infrastructure? Join our webinar on June 17 as we explore how following financial indicators helped map the hidden network behind Snuff Cinema. June 17, 2026 4:00 PM SGT Register: https://us06web.zoom.us/webinar/register/WN_pXm4B-eCQ9mkdOxyx1eM-w #OSINT #ThreatIntel #DarkWeb #SnuffCinema #Bitcoin #StealthMole 2026-06-09
stealthmole_int Twitter/X

RT by @stealthmole_int: How do you go from a single Bitcoin wallet to an entire dark web infrastructure? Join our webinar on June 17 as we explore how following financial indicators helped map the hidden network behind Snuff Cinema. June 17, 2026 4:0…

Leer articulo →
Unit 42 Intel: We detected a #Browser-in-the-Browser phishing campaign using a draggable, OS/browser-fingerprinted popup with a spoofed OAuth URL. It evades detection by blocking debugging, fragmenting keywords, and redirecting bots. Details at https://bit.ly/49Md3yO 2026-06-08
Unit42_Intel Twitter/X

We detected a #Browser-in-the-Browser phishing campaign using a draggable, OS/browser-fingerprinted popup with a spoofed OAuth URL. It evades detection by blocking debugging, fragmenting keywords, and redirecting bots. Details at https://bit.ly/49Md3…

Leer articulo →
Unit 42 Intel: Unit 42 provides indicators of activity and mitigations for PAN-OS CVE-2026-0257, an authentication bypass in GlobalProtect. https://bit.ly/4fu1rEo 2026-06-05
Unit42_Intel Twitter/X

Unit 42 provides indicators of activity and mitigations for PAN-OS CVE-2026-0257, an authentication bypass in GlobalProtect. https://bit.ly/4fu1rEo Palo Alto Networks Unit 42 threat intelligence on APT groups, ransomware operations and emerging cyber…

Leer articulo →
Unit 42 Intel: We detected an evasive #ClickFix injection with a fake Lirunex payment platform lure tricking the user into requesting the SSL certificate path through a file dialog box but silently delivers a RAT disguised as image files. Details at https://bit.ly/4eo0Sea 2026-06-05
Unit42_Intel Twitter/X

We detected an evasive #ClickFix injection with a fake Lirunex payment platform lure tricking the user into requesting the SSL certificate path through a file dialog box but silently delivers a RAT disguised as image files. Details at https://bit.ly/…

Leer articulo →
Unit 42 Intel: FlutterShell is a new macOS backdoor spread by malvertising. Built with Flutter, it uses a WebView-based architecture for adware, allowing attackers to remain dynamic. We discuss its evolution, variants and command structure in a recent campaign. https://bit.ly/43TZaLr 2026-06-04
Unit42_Intel Twitter/X

FlutterShell is a new macOS backdoor spread by malvertising. Built with Flutter, it uses a WebView-based architecture for adware, allowing attackers to remain dynamic. We discuss its evolution, variants and command structure in a recent campaign. htt…

Leer articulo →
Unit 42 Intel: We are tracking Pink (CL-CRI-1147), a new Com-affiliated extortion brand whose leak site went live 5/31/26. Pink uses vishing and IT impersonation to phish credentials/MFA, then exfiltrates enterprise cloud storage and productivity data to extort victims: https://bit.ly/4en565G 2026-06-03
Unit42_Intel Twitter/X

We are tracking Pink (CL-CRI-1147), a new Com-affiliated extortion brand whose leak site went live 5/31/26. Pink uses vishing and IT impersonation to phish credentials/MFA, then exfiltrates enterprise cloud storage and productivity data to extort vic…

Leer articulo →
Unit 42 Intel: An update to our Threat Brief on npm supply chain attacks discusses the latest compromise, pushing a payload named Miasma. The tradecraft used substantially matches Mini Shai-Hulud malware used by TeamPCP. Read now: https://bit.ly/4cwtCk3 2026-06-02
Unit42_Intel Twitter/X

An update to our Threat Brief on npm supply chain attacks discusses the latest compromise, pushing a payload named Miasma. The tradecraft used substantially matches Mini Shai-Hulud malware used by TeamPCP. Read now: https://bit.ly/4cwtCk3 Palo Alto N…

Leer articulo →
Group-IB Threat Intelligence: How do #threatactors fabricate massive data breaches from old leaks and why are organizations wasting resources investigating them? Group-IB details the operational patterns, keyword indicators, and analytical methodology to identify and dismiss "leads data" from Chinese-speaking #cybercrime communities. Read the full technical analysis now: https://link.group-ib.com/42P3viG 2026-05-20
GroupIB_TI Twitter/X

How do #threatactors fabricate massive data breaches from old leaks and why are organizations wasting resources investigating them? Group-IB details the operational patterns, keyword indicators, and analytical methodology to identify and dismiss &quo…

Leer articulo →
Group-IB Threat Intelligence: Validation of sample datasets from claims targeting Gulf banks showed that names and phone numbers were sourced from the 2021 Facebook leak while corresponding password hashes were taken from the October 2020 Eatigo breach, creating composite records that contain legitimate individual identifiers but do not represent actual customers of the targeted organizations. 2026-05-20
GroupIB_TI Twitter/X

Validation of sample datasets from claims targeting Gulf banks showed that names and phone numbers were sourced from the 2021 Facebook leak while corresponding password hashes were taken from the October 2020 Eatigo breach, creating composite records…

Leer articulo →
Group-IB Threat Intelligence: These brokers, operating channels like #Aiqianjin and #YiqunData on Telegram, in addition to other individual brokers on dark web forums such as Exchange Market and Chang'An Sleepless Night, post between 500 to over 1,000 messages monthly across these platforms — a volume that would represent an unprecedented number of real breaches if true. 2026-05-20
GroupIB_TI Twitter/X

These brokers, operating channels like #Aiqianjin and #YiqunData on Telegram, in addition to other individual brokers on dark web forums such as Exchange Market and Chang'An Sleepless Night, post between 500 to over 1,000 messages monthly across…

Leer articulo →
Group-IB Threat Intelligence: Chinese-speaking data brokers are flooding #darkweb forums and #Telegram with advertisements for massive datasets, but Group-IB analysis shows these are largely compiled from prior breaches like the 2021 Facebook leak and the 2020 Eatigo incident. 2026-05-20
GroupIB_TI Twitter/X

Chinese-speaking data brokers are flooding #darkweb forums and #Telegram with advertisements for massive datasets, but Group-IB analysis shows these are largely compiled from prior breaches like the 2021 Facebook leak and the 2020 Eatigo incident. Gr…

Leer articulo →
Group-IB Threat Intelligence: The Phoenix #PhaaS ecosystem operates on a subscription model with dedicated #Telegram sales channels, offering SMS phishing platforms at $80/week or $1999/year, e-commerce phishing kits with 3D and PP plugin support for $1999 lifetime, and custom source code for APP account phishing or complex independent sites. With nearly 13,000 members in their support chat and structured onboarding tutorials, this represents a fully commercialized, community-driven #cybercrime operation. 2026-04-29
GroupIB_TI Twitter/X

The Phoenix #PhaaS ecosystem operates on a subscription model with dedicated #Telegram sales channels, offering SMS phishing platforms at $80/week or $1999/year, e-commerce phishing kits with 3D and PP plugin support for $1999 lifetime, and custom so…

Leer articulo →
Group-IB Threat Intelligence: Threat actors are leveraging advanced SMS delivery methods, including rogue Base Transceiver Station (BTS) equipment that broadcasts stronger signals than legitimate towers to inject phishing messages directly to nearby devices without passing through carrier routing systems. This technique bypasses sender authentication and #spam filtering, allowing messages to appear under trusted brand names with no operator visibility, making carrier-level detection nearly impossible. #TelecomSecurity 2026-04-29
GroupIB_TI Twitter/X

Threat actors are leveraging advanced SMS delivery methods, including rogue Base Transceiver Station (BTS) equipment that broadcasts stronger signals than legitimate towers to inject phishing messages directly to nearby devices without passing throug…

Leer articulo →
Group-IB Threat Intelligence: Victimology analysis shows overlapping global targeting across both campaigns. Reward Points phishing primarily targets #financial services and telecom users across #APAC, while Failed Parcel Delivery campaigns focus on logistics entities across Europe, APAC, and the US. Despite sector-specific lures, the geographic distribution and brand impersonation patterns indicate coordinated deployment within the same smishing infrastructure. #ThreatIntel 2026-04-29
GroupIB_TI Twitter/X

Victimology analysis shows overlapping global targeting across both campaigns. Reward Points phishing primarily targets #financial services and telecom users across #APAC, while Failed Parcel Delivery campaigns focus on logistics entities across Euro…

Leer articulo →
Group-IB Threat Intelligence: Since January 2025, Group-IB has tracked over 2,500 #phishing domains tied to a single #PhaaS ecosystem known as the "Phoenix System" (不死鳥系統), which has targeted more than 70 organizations across financial services, telecom, and logistics. 2026-04-29
GroupIB_TI Twitter/X

Since January 2025, Group-IB has tracked over 2,500 #phishing domains tied to a single #PhaaS ecosystem known as the "Phoenix System" (不死鳥系統), which has targeted more than 70 organizations across financial services, telecom, and logistics. …

Leer articulo →
eCrime.ch: RT by @ecrime_ch: Did you know that @CISAgov's Known Exploited Vulnerabilities (KEV) catalogue includes a "knownRansomwareCampaignUse" field? If you want to pull just the CVEs that have this field set to "Known" (i.e. that have been associated with ransomware activity), I whipped up a 'lil curl command for ya: curl -L https://for528.com/cves-kev-json | jq -c '.vulnerabilities[] | select(.knownRansomwareCampaignUse == "Known")' Easy peasy! Note: You'll need jq installed (e.g. 2026-04-12
ecrime_ch Twitter/X

RT by @ecrime_ch: Did you know that @CISAgov's Known Exploited Vulnerabilities (KEV) catalogue includes a "knownRansomwareCampaignUse" field? If you want to pull just the CVEs that have this field set to "Known" (i.e. that ha…

Leer articulo →