๐จ WARNING: Over 80,000 files with passwords and keys from governments, banks, and tech firms were found online โ all pasted into public code tools like JSONFormatter and CodeBeautify.
Hackers are already scraping and using the data.
And yes โ itโs still live.
Details here โ https://t.co/TyrWneqt3G
๐จ Latest Scattered Spider update:
The actor is now claiming โthe US government paid a ransomโ a classic scare-tactic with zero evidence, in line with their long-running disinformation playbook.
They also warn IR teams about more potential attack.
This isnโt credible intel itโs threat theater designed to trigger panic, shape narratives, and keep attention on their Salesforce/Salesloft campaign.
High noise. Low signal. Same psychological ops.
EvilBytecode/GoDefender: Anti Virtulization, Anti Debugging, AntiVM, Anti Virtual Machine, Anti Debug, Anti Sandboxie, Anti Sandbox, VM Detect package. Windows ONLY. - https://t.co/ZkgTVh3dXO
SilentButDeadly - a network communication blocker specifically designed to neutralize EDR/AV software by preventing their cloud connectivity using Windows Filtering Platform (WFP).
https://t.co/AASfirUTEi
A new phishing technique dubbed 'CoPhish' weaponizes Microsoft Copilot Studio agents to deliver fraudulent OAuth consent requests via legitimate and trusted Microsoft domains.
Microsoft told BleepingComputer they plan on fixing it in a future update.
https://t.co/BeJY6YazJy
#malware
"clipup.exe" in System32 is very powerful. It can destroy the executable file of the EDR service ๐. Experimenting with overwriting the MsMpEng.exe file
github: /2x7EQ13/CreateProcessAsPPL
#redteam#BlueTeam
๐ญ๐ฒ๐ฟ๐ผ ๐๐น๐ถ๐ฐ๐ธ, ๐ข๐ป๐ฒ ๐ก๐ง๐๐ : ๐ ๐ถ๐ฐ๐ฟ๐ผ๐๐ผ๐ณ๐ ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ ๐ฃ๐ฎ๐๐ฐ๐ต ๐๐๐ฝ๐ฎ๐๐
A newly discovered zero-click vulnerability, CVE-2025-50154, bypasses a Microsoft patch, allowing attackers to steal NTLM hashes without user interaction. Microsoft has issued patch in August Patch Tuesday and here's a KQL to detect this bypass. .๐ซก
https://t.co/DBrJZyRceQ
https://t.co/try0CTqdeN
Detection: https://t.co/6uPWdVCxKU
#cybersecurity #vulnerability #NTLMLeak
๐จAlleged Sale of Fortinet 0-Day RCE Exploit
โข Industry: N/A
โข Threat Actor: WISDOM
โข Network: Clearnet, Dark Web
โข Price: 0.5 BTC
โข Details: A threat actor claims to be selling a 0-day remote code execution (RCE) exploit affecting FortiOS VPN versions 7.4 to 7.6. The listing includes a proof of concept (PoC) available to serious buyers with deposit or established reputation.