๐จ Allianz allegedly targeted in ~500 internal Docker images leak
A threat actor on an underground forum is claiming to release a full dump of roughly 500 Docker images, totaling around 40 GB, allegedly originating from Allianz internal infrastructure.
The actor claims the images contain exposed configuration files, source code, credentials, and private keys.
๐ช๐ต๐ฎ๐'๐ ๐ฎ๐น๐น๐ฒ๐ด๐ฒ๐ฑ๐น๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ:
โข Exposed configuration files with API keys, DB passwords, and service tokens
โข Internal microservices with source code
โข Hardcoded credentials for staging and prod environments
โข TLS private keys and internal CA certs
๐๐ฒ๐๐ฎ๐ถ๐น๐:
๐ง๐ฎ๐ฟ๐ด๐ฒ๐: Allianz
๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ: Insurance / Financial Services
๐๐ฐ๐๐ผ๐ฟ: hackformetome
๐๐น๐ฎ๐ถ๐บ: Full dump of internal Docker images
๐๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ: ~500 Docker images (~40 GB)
๐ฃ๐ฟ๐ถ๐ฐ๐ฒ: 10 Points
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฒ๐ฑ: May 28, 2026
๐ฅ Stop guessing what's redacted. Paid subscribers see everything: https://t.co/281Qjc6p2J
๐๐ท๐บInside Russia's elite Bauman University, a secret department trains the GRU's next-gen hackers, saboteurs & spies. Now, 2,000+ leaked docs expose how its graduates feed the units behind Russia's cyberattacks, election interference, and NATO sabotage. https://t.co/EBC2DLb8HC
๐จ Two US cybersecurity professionals have been sentenced for moonlighting as ALPHV BlackCat ransomware affiliates.
Ryan Goldberg, 40, of Georgia, and Kevin Martin, 36, of Texas, deployed BlackCat ransomware against multiple US victims between April and December 2023. They paid the operators a 20% cut for access to the platform, hit medical and engineering firms, leaked patient data to pressure payment, and split a $1.2 million Bitcoin ransom three ways with co-conspirator Angelo Martino.
Martino had a second job. He worked as a ransomware negotiator for victims, and used that role to leak confidential victim information to the attackers to push ransom prices up.
When Goldberg tried to flee abroad, the FBI tracked him through 10 countries before he was caught.
Both men were sentenced yesterday. Martino is sentenced July 9.
After 11 years of silence at Black Hat, I am delivering a speech today.
In memory of a legendary APT Hunter, Mr Sergey Mineev, who passed away 40 days ago.
If you cannot attend, here is the write-up: https://t.co/JUO4VBtnSZ
A security researcher just documented a large-scale counterfeit Ledger Nano S Plus operation selling compromised devices across multiple online marketplaces.
The fake units look identical to the real thing but contain completely different hardware. Instead of Ledger's secure element chip, the counterfeits run an ESP32 microcontroller with modified firmware labeled "Nano S+ V2.1." Seeds and PINs are stored in plain text and transmitted to attacker-controlled servers. Any wallet initialized on the device is drained.
The operation goes beyond the hardware. The sellers also distribute a fake version of Ledger Live built with React Native and signed with a debug certificate. It intercepts transactions and exfiltrates sensitive data to multiple command-and-control servers. The campaign spans five attack vectors: compromised hardware, Android APKs, Windows executables, macOS installers, and iOS apps distributed through TestFlight to bypass App Store review.
This comes days after ZachXBT documented a separate fake Ledger Live app that made it through Apple's Mac App Store review process. That operation drained over $9.5 million from more than 50 victims, including musician G. Love, who lost 5.92 BTC after entering his recovery phrase into what he believed was the legitimate app.
The pattern is clear: the attack surface for hardware wallet users has shifted from firmware exploits to supply chain and distribution fraud. The devices themselves remain secure. The problem is that users are being intercepted before they ever touch a real one.
Ledger's own "genuine check" feature can be bypassed when the hardware itself is compromised at the source, which makes where you buy the device as important as how you use it.
The rules haven't changed, but they've never been more important: buy hardware wallets only from the manufacturer. Never enter your recovery phrase into any software. If a companion app asks for your 24 words on a screen, it's a scam. Every time.
IMHO, the most interesting section of this report is this one: "Finding a Writable Crontab"
The ability for attackers to use LLMs to find unique and target-specific exploitable mis-configs is the development that scares me the most. It's harder for defenders b/c no easy tools.
Ex-BND (German Foreign Intelligence Service) deputy chief Arndt Freytag von Loringhoven received a message from fake Signal โsupportโ asking for his PIN. He typed it in.
His contacts then got a malicious link through his hijacked account.
Heโs a former NATO intelligence chief, and the author of a book called Putinโs Attack on Germany, where he apparently covers Russian cyberattacks.
He fell for a fake customer service message.
Anthropic identified industrial-scale campaigns by three AI laboratoriesโDeepSeek, Moonshot, and MiniMaxโto illicitly extract Claudeโs capabilities to improve their own models.
#CopyCat#MadeInChina
https://t.co/p45uNtO528
Weโve identified industrial-scale distillation attacks on our models by DeepSeek, Moonshot AI, and MiniMax.
These labs created over 24,000 fraudulent accounts and generated over 16 million exchanges with Claude, extracting its capabilities to train and improve their own models.
Can LNK files ever be trusted?
โก My latest blog post demonstrates several new LNK abuse methods, allowing you to fully spoof the target shown in Explorer. It also introduces tools to create your own LNKs, and detected spoofed ones yourself.
๐ฌ https://t.co/VZYVaEfO07
A forum thread advertising Qilin RaaS activity alongside Cry0 has been spotted.
The post openly recruits affiliates and outlines ransomware capabilities including selective encryption modes and shadow copy removal.
jprrin6bqe3flvtpyxkt4zsmzc3u6vvn7ahgtcbul224w3xn4h3gawid[.]onion
t1eron3[.]vip
Remember when Windows added a new โNotepadโ app with CoPilot and forced the good old notepad.exe to open the new app instead of itself even if you donโt want it?
Well, a new feature just dropped.
๐A Data-Driven Approach to Windows Advanced Audit Policy โ What to Enable and Why.
Excited to share my latest @splunk blog!
Check it out ๐ https://t.co/ZDUTVkAZ3B
I spent time digging into multiple sources and analyzing data to cut through the noise around Windows Advanced Audit Policy. This post is for anyone who's ever wondered what to enable and why.
The goal? Help users make informed, purposeful audit decisions based on data and evidence, not just defaults or random guesswork.
The whole approach has also been streamlined via the Eventlog Compendium Policy Generator - https://t.co/6W4jhptRVR