I regret to inform the community that all that the source code for Vector has been leaked.
This has been tough on the team, most likely, it's being auctioned on the dark web.
🧵 Whoever purchases it will regret it for the reasons in this thread.
⚠️ Our team at Google is releasing more details on the recent NPM #axios supply chain attack. Notably, we now attribute this activity to #UNC1069, a financially motivated North Korean 🇰🇵 nexus threat actor active since at least 2018.
My scoop: PornHub extorted by ShinyHunters for the theft of over 200 million activity data records for Premium members.
The data is detailed linking member's emails to what videos they watched, downloaded, and searched for.
https://t.co/EwiVHyCvO1
🚨PornHub is being extorted by the ShinyHunters extortion group over the theft of over 200 million Premum member activity data records.
Both PornHub and ShinyHunters claim the data was stolen in the recent Mixpanel breach.
https://t.co/M1mrL20jYd
The Clop ransomware gang confirmed to BleepingComputer they are behind the emails, claiming they exploited an Oracle bug to steal the data.
“We not prepared to discuss details at this time. Soon all will become
obvious that Oracle bugged up their core product and once again, the task is on clop to save the day. We do not damage to systems and only expect payment for services we provide to protect hundreds of biggest companies in world.”
The XSS forum community is actively discussing the situation. However, it appears that moderators are removing all content where the admin (LARVA-27) is being discussed. This was confirmed in a Telegram chat by moderator LARVA-466 (Rehub). The goal is to suppress any narrative that could turn the situation into a newsworthy event and to "troll" Westerners in the process. However, while the xss[.]is domain displays a seizure notice, the backup domain xss[.]as, the .onion site, and the Jabber service at thesecure[.]biz are still online and functioning.
🚨 Don’t miss our upcoming BleepingComputer webinar with @specopssoftware and @SCMagazine!
We'll discuss how stolen credentials and identity-based attacks have become a favorite way to break into networks.
🗓️July 9th at 2 PM ET
➡️Register here: https://t.co/AIuQIqoZLc
Original leak of stolen 2021 AT&T data had three files, a MASTER file containing encrypted SSNs and date of births, and two other files mapping the encrypted data to the plain text SSNs and DOBs. The new repackaged leak adds the unencrypted SSNs and DOBs to each customer record.
FYI, the repackaged AT&T data breach leak on XSS is from the 2021 breach, not the April 2024 Snowflake data theft attacks.
Data matches the 2021 data leaked in March 2024.
https://t.co/UuvgaxzyIb
ShinyHunters is the threat cluster to track this year.
They, or threat actors claiming to be, are behind a lot of the attacks we are seeing.
https://t.co/80tJLcdWs8
🚨 How was Black Basta structured? What were its members’ roles? How did its infrastructure operate?
Leaked chats reveal a highly organized ransomware group with defined leadership, internal teams, and external affiliates.
More in my article ⬇️
https://t.co/YJHXxf5H4n
I’ve had a few people flag this with me as a “data breach”. It’s not, it’s authorised access. Not liking that authorisation does not make it a data breach. If one of these guys then accidentally leaks it all over the place to unauthorised parties, *then* it’s a data breach!