#Group LunarisSec Hi Friends, We found LegalPlace's METABASE token SETUP
which allows for extensive access to several sensitive files
Author : Morphyne, Pwn2dd #legalplace#Op#LunarisSec#Look#French
Lunarissec uncovered a critical vulnerability affecting https://t.co/aFaKzlwE6z. An exposed Supabase configuration may disclose API keys and allow unauthorized access to sensitive application data and internal resources.
Pwn2dd, Morhpyn, N0vaq.
🔴 Digital Avocat : plus de 132 000 avocats et clients potentiellement exposés après la découverte d'une faille.
Le groupe LunarisSec affirme qu'une API exposée permettait l'accès à des données personnelles, administratives et financières, incluant notamment des coordonnées, mandats, factures et IBAN.
L'étendue réelle de l'incident reste à confirmer.
https://t.co/XroaAkycIH
#LunariSsec uncovered a critical vulnerability affecting https://t.co/cNUU7DKKHe.
The flaw may allow access to sensitive data (≈5.7GB SQL database + 130MB access logs).
m0rphyn, pwn2d.
#LunarisSec uncovered a XSS REFLECTED Injection vulnerability affecting https://t.co/bv37f0792Q
The flaw We were able to extract and intercept all user cookies, which gives access to the token and more. accounts, and user credentials.
m0rphyn, pwn2d,CybΞr
🚨 STRATEGIC CYBER INTELLIGENCE ALERT: EXPOSURE OF ACADEMIC DATA AND SESSIONS DUE TO A VULNERABILITY IN THE GRAPHQL API — CNFDI (FRANCE) 🇫🇷
⚠️ THE "#LUNARISSEC" COLLECTIVE EXPOSES A CONFIGURATION FLAW WITH THE RISK OF ACCOUNT KIDNAPPING
[STATUS: / UNCONFIRMED, VISUAL EVIDENCE]
Through proactive monitoring of vulnerability disclosure channels and offensive cybersecurity platforms, a critical vulnerability affecting the Centre National Privé de Formation à Distance (CNFDI) in France was detected on May 27, 2026, specifically on its virtual campus platform (https://t.co/QYWx2odgu5).
The LunarisSec collective, identified as m0rphyn and pwn2d, under the LunarisSec banner, has disclosed the successful exploitation of a vulnerability in the campus GraphQL API interface. The published proof-of-concept (PoC) evidence demonstrates that the attackers were able to bypass authorization controls to directly query the database of users, sessions, and email logs.
🛡️ MITIGATIONS AND PREVENTIVE RECOMMENDATIONS
🛑 Disable Introspection in Production: CNFDI should immediately disable GraphQL introspection (graphql-introspection) in its production environment, limiting API schema visibility to authorized developers.
🔒 Implement Authorization in Resolvers: Configure strict field-level authorization policies in GraphQL schemas, ensuring that queries to session, registration, and mail nodes strictly require valid authentication tokens with system administrator privileges.
#CyberSecurity #DataBreach #France #CNFDI #GraphQL #LunarisSec #APIvulnerability #SessionHijacking #FinancialFraud #ThreatIntelligence #CyberAlert #VECERT #Infosec #ConfirmedPoC
#LunarisSec uncovered a Blind SQL Injection vulnerability affecting https://t.co/0Ac1Ec7vfz
The flaw exposed 41 tables containing internal data, admin accounts, and user credentials.
The audit also revealed PHP 5.3.3, Nginx 1.14.2, and MySQL 5.
m0rphyn, pwn2d
#LunarisSec uncovered a API GraphQL vulnerability affecting https://t.co/xpq29KRBLM Centre National Privé de Formation à Distance
acces , articles, articles_tags, tags, block, event, event_type, page, session, registration, mail
users scale of the compromise
By m0rphyn & pwn2d
#LunarisSec uncovered a devastating SQL Injection vulnerability affecting https://t.co/4MYTSMbsiM (Centre national de ressources textuelles et lexicales).
The flaw allowed database exfiltration with access to 30+ tables, revealing the scale of the compromise.
By m0rphyn & pwn2d
@cybergrp_111 Bon je ne sais pas quel troudballe et tu sont démotivation bien sûre nous avons la méthode pour by-pass le Waf qui et protège pars Akamai je n’ai pas que sa à faire de fake pour sachant que tu doit je ne sais quel trdc du web mais bon
#LunarisSec identified a critical vulnerability affecting an official French government website https://t.co/K3r2x4Qcop and responsibly disclosed it.
@gouvernementFR
By CybΞr, Night, LastNodemReal
#Algeria#France#Gouvernement
@ydbzk811 right now I'm analyzing a French government website. I've found several interesting things, including endpoints, cached URLs, files, and other vuln.
@ydbzk811 No, I'm just replying because you sound really stupid, talking about the Algerian mafia 😂 Those are two different things, by the way: IT and real life. This organization is criminal; they attack websites, breach them, pwn them, leak data, claim responsibility, deface them,