Dalle notizie c'è Collins Aerospace, che fornisce check-in e boarding pass, dietro i ritardi all'aeroporto di Bruxelles, Berlino e Londra.
La stessa azienda era stata rivendicata dalla gang ransomware BianLian a luglio 2023. Non si ha notizia che i dati siano mai stati pubblicati
Veramente c'è ancora qualcuno che parla di problemi tecnici di #cybersecurity quando è ormai evidente che nella migliore delle ipotesi si tratta di corruzione e nella peggiore di sciatteria?
New from 404 Media: someone put facial recognition on Meta's smart glasses to instantly dox strangers. You look at them, sends face to a facial recognition tool. LLM infers name, sends to people site. Gets phone number, address. I've seen it in action https://t.co/3e6tC5juN6
RockYou2024 è un aggiornamento, di dubbia qualità, della wordlist circolata originariamente nel 2021. Infatti, la versione pubblicata dall'utente "ObamaCare", tra le 9,94 miliardi di righe del file si trovano caratteri che paiono solo rumore senza senso. 4/4
Se avete letto della pubblicazione di #RockYou2024 non dovete preoccuparvi. È una wordlist di circa 9 miliardi di (sole) password, quindi non è associato a nessun altro identificatore (user, email, telefono, ecc..). 🧵THREAD 1/4
Tale archivio è composto da password estratte da precedenti databreach o rubate tramite malware, è questo, qualora la vostra password si trovi all'interno, che deve preoccupare. 3/4
Stessa campagna tramite @Arubait PEC, differenti IOC
IOC:
comunicazioni.servizio.cliente.lntesa@pec[.]it
https://dhiiikaa[.]blogspot[.]com/
https://eoz[.]psw[.]mybluehost[.]me/home/intesasanpaolo/login.php
Continua una campagna phishing ai danni di Banca Intesa Sanpaolo tramite caselle @Arubait PEC fraudolente
IOC:
avvisi.comunicazione.lntesa@pec[.]it
https://agc[.]dhy[.]mybluehost[.]me/wp-content/it
https://agc[.]dhy[.]mybluehost[.]me/it/intesasanpaolo/web/login.php
Christie’s has reported to client the data breach resulting from a ransomware attack claimed by RansomHub. The compromised data includes details displayed on the ID. The attackers have issued a countdown, with 4 days remaining, threatening to release the stolen info.
Breach Forums return to Clearnet and Dark Web despite FBI seizure + An Email from the FBI reveals how the hackers managed to regain the seized domains!
Read: https://t.co/Uhw7axEveo
#CyberSecurity#CyberCrime#BreachForums#DarkWeb
Concerning the data sample from an alleged attack on Bitfinex by FSociety on the (alleged) DLS, there is a 100% match of the data present with that known from (old) combolists. And in addition, as reported by @paoloardoino not all the emails present are Bitfinex users
Everyone panicking for a potential database breach on bitfinex.
Tldr: seems fake.
The alleged hackers have posted 2 mega links with sample data contains 22.5k records of email and passwords.
- we don't store plaintext passwords, nor 2FA secrets in clear text.
- only 5k of 22.5k emails are matching with bitfinex users. If that was part of our database we would expect 100% matching
- the alleged hackers didn't contact us. Their post was published the 25th of April, giving 7 days to contact them. Yet we discovered about this claim only yesterday. If they had any real information they would have asked a ramson through our bug bounty, customer support ticket, emails, twitter etc. We couldn't find any request.
Different security researchers rushed to hype the breach. Yet from what we could gather, the hackers collected a database of emails/passwords likely from different crypto breaches. Most of users unfortunately use same email/passwords across multiple sites.
We're performing deep analysis of our systems and no breach was found currently.
Also the KYC platform has heavy rate limiting that would disallow downloading in bulk.
While we believe this is pure FUD we'll keep reviewing information to ensure no stone remains unturned.
Funds are safe.
Is this the end of Blackcat/ALPHV RaaS? A thread 🧵
Some hours ago the FBI seized the last remaining active hidden service of Alphv/Blackcat, which was in operation until yesterday.
Is this the end of Blackcat/ALPHV RaaS? A thread 🧵
Some hours ago the FBI seized the last remaining active hidden service of Alphv/Blackcat, which was in operation until yesterday.
On 3 March, a user on the RAMP forum, which is affiliated with Blackcat itself, reported that he had not received the agreed remuneration for the attack on Change Healtcare, and also indicated that the wallet of the RaaS admin had been emptied.
Every single known Lockbit ransomware group website is either offline or displaying a seized by EUROPOL page.
It appears law enforcement has seized and/or taken down, at minimum, 22 Tor sites, in what is labeled 'Operation Cronos'.