🇨🇴 Bogotá Mobility Authority Allegedly Compromised
A threat actor claims to have compromised the Secretaría Distrital de Movilidad (Bogotá Mobility Authority) and is advertising what they describe as a database containing approximately 4.6 million records.
* According to the post, the alleged data includes:
* Traffic fines and violation records
* Photos and videos associated with traffic infractions
* User information linked to enforcement records
* The threat actor further claims the breach was enabled through an Insecure Direct Object Reference (IDOR) vulnerability followed by Broken Function Level Authorization (BFLA), allegedly allowing unauthorized access to modify, create, and delete traffic citations as well as monitor Bogotá's speed camera system.
* These technical claims have not been independently verified and should be treated as unconfirmed until validated by the affected organization or independent researchers.
* Daily Dark Web has not independently verified the authenticity of the dataset or the threat actor's claims.
Analyst Note: If the reported IDOR and authorization flaws are confirmed, this incident would extend beyond data exposure into a potential integrity compromise, where attackers could manipulate official records rather than merely access them.
#DDW #Intelligence #DarkWeb #Colombia
New breach: JCPenney was targeted by a ShinyHunters extortion campaign that allegedly obtained then leaked data including 368k email addresses, names, SSNs and other HR records on current and former staff. 31% were already in @haveibeenpwned. More: https://t.co/83Zf5flTof
New breach: ShinyHunters claimed Pitney Bowes as an extortion victim last week before later dumping 8.2M email addresses publicly. Data also included name, physical address, phone number and employee job title. 53% were already in @haveibeenpwned. More: https://t.co/PrnVvRw9xy
Awesome Breach Intelligence
Breach Lookup & Monitoring
Dark Web Monitoring
OSINT Tools
Threat Intelligence Platforms
Password Security
Data Leak Search Engines
News & Research
Forums & Communities
API & Developer Tools
Training & Resources
https://t.co/EttLPZB2mh
I've got students messaging me asking if cybersecurity is still a "safe" field to go into because of the advancements of AI
Dawg, our career value has fucking EXPLODED. Are you fuckin' with me right now?
- AI vibe coded slop as far as the eye can see
- AI deep fakes as far as the eye can see
- AI written emails, scams, as far as the eye can see
On top of that, due to how accessible the internet is now, there is a "cyber attack" literally every god damn second. It's nonstop. The internet is still very much the wild, wild, west.
Like, bro, this shitty little malware website I run brings in 20,000+ malwares a day with a budget of $15, a slice of pizza, and cat pictures. Do you have any fucking clue how widespread cybercrime is?
Don't even fucking start me on crypto theft
I'll lose my mind writing this post, bro. It's literally nonstop, around the clock, weekends and holidays. It never ends. Cybersecurity is only getting bigger.
@vibeautomater Thanks man! I’m thinking the next step is picking up another mini PC, likely the Minisforum UM790 Pro with a Ryzen 9 so I can run LLMs locally. Also considering a couple more Pis to experiment with clustering, plus a few other projects I’ve got in mind.
Got the Zimaboard 2 all set up and added to my rack... this was a grsat addition. Currently running Tailscale, Pi-Hole, Vaultwarden, n8n, and a few other tools/services.
My Zimaboard 2 showed up today. I originally backed it on Kickstarter just for the NAS, but now I’m seeing how it can offload services and free up my Pi’s for other projects. Pretty cool.