CTI Updates
236 subscribers
161 photos
1 video
3 files
21 links
Updates about all things threat intel & updates about stuffs going on in the cybersec, OSINT, and hacking communities.
Download Telegram
Kash Patel be leaving Google Reviews from his old Gmail account
👍1
patelkpp[@]gmail[.]com
INC ransomware group lists the city government of Meriden Connecticut
BreachForums[.]sb drama lol

Owned by ShinyHunters and asking for $7,000
😁2👀1
the NightSpire ransomware group announces they will publish the files of Anbogen Therapeutics Inc for free. 300 GB of data.
👍1
🤔💭
Del Monte Foods hit by PayoutsKing ransomware group

RIP to all the 🍎🍏🍉🍇🥭🍑🍒🍓🍌🍊🍍
🍓1
the block is hot
Forwarded from vx-underground
The streets are speaking [1] and word on the street is ShinyHunters dislike TeamPCP [2]

[1] The streets is stinky nerds wearing Naruto pajamas in internet chatrooms

[2] It is alleged ShinyHunters call TeamPCP "SkidPCP", a very unique and novel insult
Anubis ransomware group lists Publishers Clearing House
🫡1
the Beast ransomware group lists the China based company Xiamen Tungsten Co. (XTC).

they are selling the data for 20BTC aka $1.3M USD.

claims to have 160 GB of data.
👍1
ShinyHunters has just removed Hallmark as a victim on their DLS
Qilin ransomware group lists the Arkansas-based Faulkner County Sheriff's Office
2🔥2👍1
ShinyHunters has removed Cisco as a victim from their DLS
👀1
Popular carding forum ASCarding is down atm
If you're running OpenClaw, you probably got hacked in the last week

CVE-2026-33579 is actively exploitable and hits hard.
😁1
DragonForce ransomware group lists AUG Pharma of Giza, Egypt, claiming to have stolen 890 GB of data. The company develops, manufactures, and commercializes pharmaceutical products aimed at improving public health.
👍3🔥1
A threat actor on XSS forum is selling a VirusTotal Enterprise account for $5,000 USD

"Selling a VT Enterprise GUI account to a single buyer. Brute-force account, inactive, in a group, non-admin access. IT company. I will not disclose the email address until the purchase! No guarantees after account receipt."
😁3👍1
a XSS forum user is selling a style of ClickFix that involves pasting into the File Explorer address bar

"Your Payload is in an image that is cached by the browser. The site determines which browser the user is using, selects the appropriate command to extract the binary and launch it. When the button is clicked, the command is placed in the buffer and the file explorer opens. The disguised command is executed via the address bar of the file explorer."
👍2👀2