CTI Updates
236 subscribers
161 photos
1 video
3 files
21 links
Updates about all things threat intel & updates about stuffs going on in the cybersec, OSINT, and hacking communities.
Download Telegram
πŸ€”πŸ’­
Del Monte Foods hit by PayoutsKing ransomware group

RIP to all the πŸŽπŸπŸ‰πŸ‡πŸ₯­πŸ‘πŸ’πŸ“πŸŒπŸŠπŸ
πŸ“1
the block is hot
Forwarded from vx-underground
The streets are speaking [1] and word on the street is ShinyHunters dislike TeamPCP [2]

[1] The streets is stinky nerds wearing Naruto pajamas in internet chatrooms

[2] It is alleged ShinyHunters call TeamPCP "SkidPCP", a very unique and novel insult
Anubis ransomware group lists Publishers Clearing House
🫑1
the Beast ransomware group lists the China based company Xiamen Tungsten Co. (XTC).

they are selling the data for 20BTC aka $1.3M USD.

claims to have 160 GB of data.
πŸ‘1
ShinyHunters has just removed Hallmark as a victim on their DLS
Qilin ransomware group lists the Arkansas-based Faulkner County Sheriff's Office
❀2πŸ”₯2πŸ‘1
ShinyHunters has removed Cisco as a victim from their DLS
πŸ‘€1
Popular carding forum ASCarding is down atm
If you're running OpenClaw, you probably got hacked in the last week

CVE-2026-33579 is actively exploitable and hits hard.
😁1
DragonForce ransomware group lists AUG Pharma of Giza, Egypt, claiming to have stolen 890 GB of data. The company develops, manufactures, and commercializes pharmaceutical products aimed at improving public health.
πŸ‘3πŸ”₯1
A threat actor on XSS forum is selling a VirusTotal Enterprise account for $5,000 USD

"Selling a VT Enterprise GUI account to a single buyer. Brute-force account, inactive, in a group, non-admin access. IT company. I will not disclose the email address until the purchase! No guarantees after account receipt."
😁3πŸ‘1
a XSS forum user is selling a style of ClickFix that involves pasting into the File Explorer address bar

"Your Payload is in an image that is cached by the browser. The site determines which browser the user is using, selects the appropriate command to extract the binary and launch it. When the button is clicked, the command is placed in the buffer and the file explorer opens. The disguised command is executed via the address bar of the file explorer."
πŸ‘2πŸ‘€2
weird takedown thingy posted on the Kairos ransomware groups DLS page. Claimed by the "SBU Cyber Department" ?

nerqnacjmdy3obvevyol7qhazkwkv57dwqvye5v46k5bcujtfa6sduad[.]onion
πŸ‘2
Akira ransomware group lists Minnesota Health Insurance Network, a provider of individual and family plans, group and small business coverage, Medicare, dental and vision insurance, and short-term health insurance.
πŸ‘3
Insomnia ransomware group lists United Medical Doctors (UMD), an independent multi-specialty medical-surgical group with 70+ Southern California locations and 40+ specialties focused on patient care, outpatient surgery, and clinical research.
πŸ‘€3
The Qilin ransomware group lists 7 new victims

Β°,ΒΈ Higashiyama Industries Co.,Ltd.
Β°,ΒΈ Guerin Glass
Β°,ΒΈ TIS
Β°,ΒΈ Sonn Law Group
Β°,ΒΈ Autogalerie Heister
Β°,ΒΈ Saam Towage
Β°,ΒΈ Nan Lui Enterprises
πŸ”₯2πŸ‘1
XSS forum is down atm
😒2