CTI Updates
236 subscribers
159 photos
1 video
3 files
21 links
Updates about all things threat intel & updates about stuffs going on in the cybersec, OSINT, and hacking communities.
Download Telegram
XSS forum is down atm
😒2
OGUser.com is having some downtime atm
πŸ‘2πŸ‘1
The average HackForums post
😭3πŸ™ˆ2
CoinbaseCartel ransomware group lists Carter’s, Ralph Lauren, and Helzberg as victims.

Carter’s is a children’s clothing retailer, Ralph Lauren is a fashion and apparel brand, and Helzberg is a jewelry retailer specializing in diamonds and gold.
🐳3πŸ‘€2πŸ’―1
the 0APT ransomware silly willy who got busted for posting fake victims and being a larp has came back with a post extorting another ransomware group, Krybit, and threatening to expose who they are if they do not pay
🀣5😐2
Ryan LLC has been removed from the ShinyHunters DLS
πŸ‘1
PEAR ransomware group lists Colorado-based Colorado Pulmonary Intensivists (CPI / UCHealth), claiming to have stolen 2.3 TB of data. The group says the haul includes financials, HR files, provider and vendor data, patient PII/PHI, email correspondence, and cloud-stored data.
🐳1πŸ‘€1
Vect ransomware group mentions Airbnb and Booking.com
❀2πŸ‘€2🐳1
Krybit ransomware group responds to 0APTs claim of hacking them
Cognizant listed by the Coinbasecartel ransomware group this morning
πŸ‘€2
The financial fraud website Altenens is offline atm
πŸ‘1
Vect / TeamPCP added two new victims from their Trivy/LiteLLM campaign.

S&P Global and Guesty
πŸ‘2
XSS is derped atm
πŸ‘€2πŸ‘1
Pitney Bowes
7-11 (the gas station)
Medronic PLC
The Canada Life Assurance Company
Zara

All listed by ShinyHunters just now. Looks to be a continuation of their Salesforce pwnage
πŸŽ„3πŸ‘€2
Carding forum Altenens is closed with a notice of

"forum is closed We will back soon please keep remember your ID and password of Altenens.is"
❀2
Citizens Bank & Frost Bank listed by the Everest ransomware group
πŸ‘1
Coinbasecartel posted an update to the Cognizant listing on their DLS
πŸ‘€1
Vimeo listed by ShinyHunters on their DLS
πŸ‘€2
RansomHouse has listed a "Cybersecurity Vendor"
πŸ‘€1
CMD ransomware group seems to be a fake it til you make it group.

They listed Cytek Biosciences but the Rhysida ransomware group listed this same victim 1/25/26 and used the same images.
πŸ‘2