CTI Updates
236 subscribers
159 photos
1 video
3 files
21 links
Updates about all things threat intel & updates about stuffs going on in the cybersec, OSINT, and hacking communities.
Download Telegram
Cognizant listed by the Coinbasecartel ransomware group this morning
👀2
The financial fraud website Altenens is offline atm
👍1
Vect / TeamPCP added two new victims from their Trivy/LiteLLM campaign.

S&P Global and Guesty
👍2
XSS is derped atm
👀2👍1
Pitney Bowes
7-11 (the gas station)
Medronic PLC
The Canada Life Assurance Company
Zara

All listed by ShinyHunters just now. Looks to be a continuation of their Salesforce pwnage
🎄3👀2
Carding forum Altenens is closed with a notice of

"forum is closed We will back soon please keep remember your ID and password of Altenens.is"
2
Citizens Bank & Frost Bank listed by the Everest ransomware group
👍1
Coinbasecartel posted an update to the Cognizant listing on their DLS
👀1
Vimeo listed by ShinyHunters on their DLS
👀2
RansomHouse has listed a "Cybersecurity Vendor"
👀1
CMD ransomware group seems to be a fake it til you make it group.

They listed Cytek Biosciences but the Rhysida ransomware group listed this same victim 1/25/26 and used the same images.
👍2
Handala taunting LE
👍1
xvxv made a post on XSS looking for high quality data providers for crypto exchanges Coinbase, Gemini, Kraken, and hardware wallet providers.
👀1
a Tox powered p2p botnet posted by socks4secure

"Me again with another P2P concept 😁


Inspiration was definitely from toxnet however more conceptually than code wise.

In the end I've been able to make a C++ client that can interact with the tox network in order to connect to a master tox id which sends out commands and the client can execute them, very basic at the moment but I wanted to explore the concept of it than actual usage"
👀1
The Qilin ransomware group has just listed Sysco, the popular wholesale restaurant food distributor
🌭1
Forwarded from Cracked Status
Hello,

We regret to inform you that the Cracked.ax domain has been suspended or disabled at the registry level. At this time, restoration is unlikely. However, we will continue exploring any possible options for recovery, including implementing a redirect if it becomes a possibility.

Our new domain is Cracked.st

Please also note that in case of similar incidents in the future, Cracked.sh will be used to redirect users to our active domains.

Thank you for your understanding and continued support.
The founder of the popular open source CTI tool OpenCTI was arrested and charged with CSAM.

Samuel Hassine, head of the startup Filigran, which specializes in anticipating cyber threats, is suspected of having purchased child pornography images and videos through a darknet child pornography platform called "Alice with Violence CP."

https://www.leparisien.fr/faits-divers/pedopornographie-un-patron-de-la-french-tech-prevu-dans-la-delegation-demmanuel-macron-en-asie-mis-en-cause-apres-un-vaste-coup-de-filet-03-04-2026-CULCDDQMQNFB5NQQ4WXV2UHEPQ.php
🤣4🤡3
RansomHouse ransomware group has listed Trellix (McAfee & FireEye). The entry was originally posted as “Cybersecurity Vendor” and was updated today to identify the victim as Trellix.
👀3🤡2