New extortion group "ExfilSquad" claims they have compromised Microsoft. However, these claims currently lack sufficient evidence to establish credibility. Will share once I have more information, but at the moment this is seeming a lot like another APT0 situation.
Attackers are using hotel & conference Wi-Fi captive portals to access Microsoft 365 accounts—no malware or phishing needed. Travelers: use always-on, full-tunnel VPN. See how agentic defense helps:
https://t.co/yVN4OsFGXX
It appears that @kernelstub has been banned from @github for reverse engineering Flock Cameras publicly.
The entire github account is gone, not just the repository in question.
ReliaQuest has observed threat actors actively exploiting CVE-2026-12569, a critical unsafe deserialization vulnerability (CVSS 9.3) affecting PTC Windchill and FlexPLM. Exploitation enables unauthenticated remote code execution and JSP web shell deployment for remote command execution and sensitive product data exfiltration.
The actor behind these attacks remains unconfirmed. however, the observed tradecraft shares characteristics with previous Cl0p campaigns targeting enterprise applications and high-value data repositories.
Immediate mitigations:
🔴 Apply PTC's vendor patch (CS473270)
🔴 Place Windchill and FlexPLM interfaces behind a VPN or trusted access gateway where possible
🔴 If exploitation is suspected, isolate the affected server, preserve forensic artifacts, and rotate exposed credentials before restoring service
AWH HELL NAH
THEY BANNED SPIDER?!
Don't even trip, dawg. I'm unironically gonna hit up my Xitter connections (actual employees) and get this sorted out.
Please hold.
New Kongtuke #ClickFix campaign sideloads Havoc C2 using signed WinWrapIDE binary. The evasive loader uses window cloaking, sandbox sleep, and native callback evasion to run a memory-only #infostealer. Details at https://t.co/YUeLe97wM2
Imagine getting intel from the FBI and immediately going "Babe, you won't BELIEVE what I heard at work today".
Her love language must be unauthorized disclosures.
Extra extra read all about it! 📰 Ben has addressed Huntress’s public statement regarding the insider! Also allegedly the insider and Devman are engaged?! Can this get any better??
O, DevMan, DevMan! Wherefore art thou DevMan?
Deny thy ransomware and refuse thy leak site
Or, if thou wilt not, be but sworn my love
And I'll no longer be a Huntress💍
He runs a RaaS. She hunts it. Devman and the @HuntressLabs insider are allegedly engaged to be married according to multiple sources
Photo of this cute Panda from Russia is totally unrelated. Allegedly.
I am exposing the systematic failure of their triage process, the proof of a critical BOLA, and how leadership prioritized vendor PR over security.
Read the full disclosure here: https://t.co/Iart9ff2N0
#bugbounty#cybersecurity#infosec