CTI Updates
236 subscribers
159 photos
1 video
3 files
21 links
Updates about all things threat intel & updates about stuffs going on in the cybersec, OSINT, and hacking communities.
Download Telegram
ShinyHunters has hacked back into Canvas / Instructure to put more pressure on them.

Students are not able to do their finals or work
🀣6πŸ‘€4
ShinyHunters has removed Canvas / Instructure from their DLS

They either paid or in active negotiations

πŸ‘€
πŸ‘€7😱3🀑1
but daddy I want do do illegal thingys
πŸ₯°2🀣1πŸ‘»1
Eli Lilly listed by TeamPCP
πŸ‘1
Grafana has been listed by the Coinbasecartel ransomware group
πŸ‘€1
F
DragonForce ransomware group lists Taurus Investment Holdings (tiholdings.com), claiming to have stolen 252 GB of data. The company is a global commercial real estate investment and development firm.
INC ransomware group lists smartphone and consumer tech company Nothing, claiming to have stolen 52 GB of data. The group says the haul includes confidential documents, client data, NDAs, financial records, operational and corporate data, business agreements, and technology-related materials.
πŸ‘€3πŸ”₯1
github-repos.txt
276.7 KB
from TeamPCP and their Github pwn
πŸ₯°2
more from Github RE: getting pwned by TeamPCP
πŸ‘1
A criminal complaint was unsealed in Alaska today charging a Canadian man with operating the KimWolf DDoS botnet. The U.S. complaint was unsealed following the defendant’s arrest in Canada by Canadian authorities.

On April 10, 2026, U.S. authorities criminally charged Jacob Butler, aka β€œDort,” 23, of Ottawa, with offenses related to the development & operation of the KimWolf botnet. KimWolf was a DDoS-for-hire service which infected over a million devices worldwide, including devices in Alaska.

For more info, read the press release at https://www.justice.gov/usao-ak/pr/canadian-man-arrested-international-authorities-charged-administrating-kimwolf-ddos
πŸ‘3❀1
Qilin ransomware group lists Semgrep, a software company whose mission is to β€œmake it expensive to exploit software.”
😁3
BravoX ransomware group has listed The Salvation Army, marking the third time in less than a year the organization has been named by a ransomware group. It was previously listed by the Interlock and Chaos ransomware groups. BravoX claims to have stolen 110 GB of data across 4,500 directories and 59,000 files.
πŸ‘€1
Genesis ransomware group has listed five new victims:
- A. Roettgers
- Cedar Street Capital
- Green Resource
- Wentworth
- Cavalier Flooring Systems Inc.

The organizations span multiple sectors, including fuel retail, private investment, agricultural supply distribution, home remodeling, and flooring and tile contracting.
Gunra ransomware group has added five new victims to its leak site: Star Empire Entertainment, Somafix, bkksky, Cablematic Dos Mil SLU, and Triotech. The group claims to have stolen 10 GB of data from SOMAFIX and 100 GB from Cablematic Dos Mil SLU.
Lapsus$ has listed INGKA Group (IKEA), claiming to have obtained approximately 180 GB of internal data. The group says the data includes global e-commerce architecture mapping, internal coworker platforms, supply chain logistics, cloud infrastructure, and AI/MLOps repositories.
πŸ‘1
BravoX ransomware group has listed AcademyHealth.

AcademyHealth is based in Washington, D.C. and focuses on advancing health services research and health policy.

The group claims to have obtained 975 GB of data.
πŸ‘1
A threat actor has allegedly posted 341K records from the Indonesian National Police Database also while claiming they arrested the wrong person?? lol no idea
❀1πŸ‘1