Awesome Breach Intelligence
Breach Lookup & Monitoring
Dark Web Monitoring
OSINT Tools
Threat Intelligence Platforms
Password Security
Data Leak Search Engines
News & Research
Forums & Communities
API & Developer Tools
Training & Resources
https://t.co/EttLPZB2mh
Here's the exploit in action, using the RedSun PoC
(note this is demostrated in virtual machines and this is purely for educational purposes, please don't repilcate the exploit on any systems you are not permited to do so)
๐๐๐๐ข๐๐ ๐จ๐ ๐ญ๐ก๐ ๐๐ซ๐ข๐ง๐๐ข๐ฉ๐๐ฅ ๐๐๐ข๐๐ง๐ญ๐ข๐๐ข๐ ๐๐๐ฏ๐ข๐ฌ๐๐ซ ๐ญ๐จ ๐ญ๐ก๐ ๐๐จ๐ฏ๐๐ซ๐ง๐ฆ๐๐ง๐ญ ๐จ๐ ๐๐ง๐๐ข๐ ๐ก๐๐ฌ ๐ซ๐๐ฅ๐๐๐ฌ๐๐ ๐ ๐๐ก๐ข๐ญ๐ ๐๐๐ฉ๐๐ซ ๐จ๐ง ๐๐๐ฆ๐จ๐๐ซ๐๐ญ๐ข๐ฌ๐ข๐ง๐ ๐๐๐๐๐ฌ๐ฌ ๐ญ๐จ ๐๐ ๐๐ง๐๐ซ๐๐ฌ๐ญ๐ซ๐ฎ๐๐ญ๐ฎ๐ซ๐.
With AI becoming central to innovation and economic progress, access to compute, datasets, and model ecosystems must be made broad, affordable, and inclusive. These resources are concentrated in a few global firms and urban centres, limiting equitable participation.
For India, democratising access means treating AI infrastructure as a shared national resource, empowering innovators across regions to build local-language tools, adapt assistive technologies, and create solutions aligned with Indiaโs diverse needs.
The White Paper highlights key enablers aligned with Indiaโs AI governance vision:
๐น Expanding access to high-quality, representative datasets
๐น Providing affordable and reliable computing resources
๐น Integrating AI with Digital Public Infrastructure (DPI)
Read the White Paper here:
https://t.co/KZbBuNXAAW
๐ EvilProxy - msftdocs[.]com
Using https://t.co/HcY9MJ5MEz threat intelligence, a domain just 3 days oldโlinked to the EvilProxy infrastructureโwas recently identified. To all fellow defenders: if you have access to the associated domains and IPs, you know what to do. ๐ซก
The National Police Agency (NPA) of Japan recent documentation of state-sponsored Threat Actors from China is interesting.
A group they believe to be a subset of APT10, abuses WSB (Windows Sandbox) by creating a .wsb configuration file and using it to spin up an instance of the Windows Sandbox.
This is interesting because Windows Defender cannot access the Windows Sandbox (image 1).
The payload enables folder sharing, network access, clipboard access, microphone access, and video access.
tl;dr abusing the sandbox, sandbox as a c2
Discord Database Reportedly Leaked
A recent leak allegedly exposes a Discord database, including official Discord account passwords as of December 2024. This raises significant concerns regarding user data security and platform vulnerabilities.
https://t.co/iWIkCKGs9H
#cybersecurity #databreach #Discord #privacy #security
Cybercriminals can leverage the vendor-agnostic #LDAP for lateral movement and to target critical assets. Stay informed about the risks and learn how to detect and mitigate LDAP-based attacks. https://t.co/ys6TUst0cg
This research utilizes a novel graph-based investigation pipeline to analyze 19 new TLDs, revealing a direct correlation between their release dates, popularity, and an increase in cyber threats such as phishing and malware distribution. https://t.co/ZP5p6LhNkW