CTI Updates
236 subscribers
159 photos
1 video
3 files
21 links
Updates about all things threat intel & updates about stuffs going on in the cybersec, OSINT, and hacking communities.
Download Telegram
RansomHouse ransomware group has listed Trellix (McAfee & FireEye). The entry was originally posted as “Cybersecurity Vendor” and was updated today to identify the victim as Trellix.
👀3🤡2
ShinyHunters has hacked back into Canvas / Instructure to put more pressure on them.

Students are not able to do their finals or work
🤣6👀4
ShinyHunters has removed Canvas / Instructure from their DLS

They either paid or in active negotiations

👀
👀7😱3🤡1
but daddy I want do do illegal thingys
🥰2🤣1👻1
Eli Lilly listed by TeamPCP
👍1
Grafana has been listed by the Coinbasecartel ransomware group
👀1
F
DragonForce ransomware group lists Taurus Investment Holdings (tiholdings.com), claiming to have stolen 252 GB of data. The company is a global commercial real estate investment and development firm.
INC ransomware group lists smartphone and consumer tech company Nothing, claiming to have stolen 52 GB of data. The group says the haul includes confidential documents, client data, NDAs, financial records, operational and corporate data, business agreements, and technology-related materials.
👀3🔥1
github-repos.txt
276.7 KB
from TeamPCP and their Github pwn
🥰2
more from Github RE: getting pwned by TeamPCP
👍1
A criminal complaint was unsealed in Alaska today charging a Canadian man with operating the KimWolf DDoS botnet. The U.S. complaint was unsealed following the defendant’s arrest in Canada by Canadian authorities.

On April 10, 2026, U.S. authorities criminally charged Jacob Butler, aka “Dort,” 23, of Ottawa, with offenses related to the development & operation of the KimWolf botnet. KimWolf was a DDoS-for-hire service which infected over a million devices worldwide, including devices in Alaska.

For more info, read the press release at https://www.justice.gov/usao-ak/pr/canadian-man-arrested-international-authorities-charged-administrating-kimwolf-ddos
👍31
Qilin ransomware group lists Semgrep, a software company whose mission is to “make it expensive to exploit software.”
😁3
BravoX ransomware group has listed The Salvation Army, marking the third time in less than a year the organization has been named by a ransomware group. It was previously listed by the Interlock and Chaos ransomware groups. BravoX claims to have stolen 110 GB of data across 4,500 directories and 59,000 files.
👀1
Genesis ransomware group has listed five new victims:
- A. Roettgers
- Cedar Street Capital
- Green Resource
- Wentworth
- Cavalier Flooring Systems Inc.

The organizations span multiple sectors, including fuel retail, private investment, agricultural supply distribution, home remodeling, and flooring and tile contracting.
Gunra ransomware group has added five new victims to its leak site: Star Empire Entertainment, Somafix, bkksky, Cablematic Dos Mil SLU, and Triotech. The group claims to have stolen 10 GB of data from SOMAFIX and 100 GB from Cablematic Dos Mil SLU.
Lapsus$ has listed INGKA Group (IKEA), claiming to have obtained approximately 180 GB of internal data. The group says the data includes global e-commerce architecture mapping, internal coworker platforms, supply chain logistics, cloud infrastructure, and AI/MLOps repositories.
👍1