At Black Hat, security researcher @evstykas reveals what he found by lurking inside North Korean hackers’ infrastructure for nearly two years: They got footholds inside 1,640 networks, by his count. About half of those intrusions were serious breaches. https://t.co/lJt3ksAthx
🚨🚨 Iran-Israel War Cybertracker #3 🚨🚨
22 June 2025 update for hacktivist activity related to the ongoing Iran-Israel War.
- There are now 120 hacktivist groups who are active from this geopolitical flashpoint.
- There are 9 pro-Russian hacktivist groups supporting Iran. Most notably - Noname057(16) have joined the DDoS attacks on Israel.
- Infighting and internet shutdowns might be disrupting some pro-Iran hacktivist activity
- DDoS remains the main attack vector, however claimed hack and leak and targeting of operational technology is also present.
After the United States strikes on Iran, 7 pro-Iran hacktivists groups have declared they will target the United States.
#Iran #IranIsraelConflict #IranVsIsrael #IsraeliranWar #IsraelIranConflict #Israel
Actors that bear the hallmarks of Scattered Spider are now targeting the insurance industry. They have a habit of working their way through a sector. Insurance companies should be on the lookout for social engineering schemes targeting their call centers.
🚨 Iran and Israel War Cybertracker #1 🚨🚨
I have been monitoring the hacktivist landscape over the past 48 hours to gather all hacktivist groups engaged in cyber activities in relation to the ongoing Iran-Israel tensions.
Overall there are currently 83 groups active, but I expect that to increase.
There are more 'Anti-Iran" groups than there are pro-Israel groups. Traditionally Israel has less hacktivist support but the number of Anti-Iran groups is notable.
There are currently three active pro-Russian groups supporting Iran.
Cyber attack claims include: DDoS, Defacements, data breach's, Doxing, social media take-downs, ransomware and targeting operational technology.
Notable state-linked actors returned within hours of missile strikes, including Handala Hack for Iran.
#Iran
#iranisraelwar #Israel #cybertracker
HOW I SETUP A HONEYPOT ON CLOUD AND RECORDED 75K+ BRUTE-FORCE ATACKS IN 24 HOURS & HOW I MAPPED EVERYONE OF THEM WITH MICROSOFT SENTINEL (A thread 🧵)
I exposed a Windows VM to the internet.
Waited.
Thousands of brute-force attacks came flooding in.
So I built a custom attack map in Microsoft Sentinel.
Here’s the exact process — step-by-step
Two vulnerabilities that CISA warned about in January are being exploited by a new ransomware operation with ties to the LockBit ransomware group https://t.co/vWPWiZQXCV
Employees at the Cybersecurity and Infrastructure Security Agency tell WIRED they’re struggling to protect the US while the administration dismisses their colleagues and poisons their partnerships.
https://t.co/i3dZXOtkDq
China's Salt Typhoon hackers are still breaching telecoms worldwide, including two in the US in Dec-Jan, says Recorded Future. Lately they're exploiting Cisco devices with unpatched 2023 bugs and seem undeterred by high profile exposure and sanctions. https://t.co/0SZ9A3Cbrd
In the last quarter of 2024, Microsoft Threat Intelligence observed developments in the ransomware ecosystem that researchers and defenders should watch for in 2025. 🧵
Chinese hackers (actually, cyber operators) gained control to shut down U.S. ports, power grids, and other critical infrastructure. Intrusions were severe, with key details lost permanently due to erased logs and inadequate tracking.
These are the top 5 #ransomware groups by the number of public attacks in 2024. While it is over for #LockBit, #Ransomhub enters 2025 as the biggest threat to cybersecurity and humanity.
Ransomware is a national security and public health crisis.
“The company… produces aortic stent grafts, surgical sealants, mechanical heart valves and implantable cardiac and vascular human tissues.”
“…it will incur additional costs that will not be covered by insurance.”
FBI made a new arrest related to the cybercrime group Scattered Spider case, a 19-year-old hacker living in Fort Worth, Texas — and he's talking. They were behind the Caesars and MGM hacks. https://t.co/mqT2SWvhIN
After a few people asked if I had seen any hacktivist activity around Syria in recent days, I decided to make a quick #cybertracker
You will note that there are limited groups involved, I could only see 11 that had claimed attacks or claimed they would be doing attacks.
Considering there are over 100 hacktivist groups involved in the ongoing Israel and Palestine tensions the number if low.
I will continue to keep an eye on the situation for those that are interested.
#cybersecurity #SyrianCivilWar #Syria
🇨🇳 Salt Typhoon 🇨🇳
“…eight telecommunications giants in the U.S. were breached…”
“The campaign ‘has been underway … likely one to two years’ and has compromised telecoms in the Indo-Pacific region, Europe and elsewhere.”
(via @TheRecord_Media) https://t.co/CduavIxMiJ