πŸ”ͺ Slice For Life - Part 2 πŸ”ͺ
4.7K subscribers
1.08K photos
59 videos
972 links
Download Telegram
β€ΌοΈπŸ‡¬πŸ‡§ FulcrumSec announces Manchester Airports Group (MAG)

πŸ‡¬πŸ‡§ Manchester Airports Group (MAG) - A UK airport operator managing Manchester Airport, London Stansted Airport, and East Midlands Airport.

The listing claims approximately 550 GB of data, including 8,672,291 customer profiles, 1.169 billion marketing events, 2,482,763 purchases, 461,433 SMS messages, 108,077 vehicle registrations, platform configuration data, and future booking information.

The group claims access was obtained through exposed Iterable administrative keys in the airports’ frontend code.
🚨πŸ‡ͺπŸ‡Έ Reig Jofre dataset allegedly stolen and offered for sale on a cybercrime forum, WordPress records and internal data claimed
β €
Laboratorio Reig Jofre, a Spanish pharmaceutical company, is allegedly affected by a security breach after a threat actor claimed to have compromised an internal asset, extracted company data and subsequently deleted the underlying dataset.
β €
The advertised material includes:
β €
β€’ Full WordPress SQL dataset
β€’ Approximately 6,098 user records
β€’ Full names
β€’ Email addresses
β€’ Hashed passwords
β€’ Pharmacy names
β€’ CIF/NIF identifiers
β€’ Postal codes
β€’ Phone numbers
β€’ Professional categories
β€’ Contact form submissions
β€’ Client and prospect communications
β€’ Administrative and scheduler logs
β€’ Cookie scan records
β€’ Internal operational data
β€’ Pharmacy professional and partner information
β€’ Internal employee references
β€’ Communication logs
β€’ Custom WordPress tables and metadata
β €
The actor claims the material includes multiple form submissions containing personal data and requests, alongside structured records associated with pharmacy professionals and partner organizations.
β €
A password-protected sample was published as alleged proof of the dataset and access. The actor states the complete material is now being offered for sale.
β €
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
πŸš¨πŸ‡¦πŸ‡· Access to Argentinian insurance company allegedly offered for sale on a cybercrime forum for $2,000
β €
An unnamed insurance company in Argentina, with claimed annual revenue of approximately $30 million, is allegedly compromised after a threat actor advertised access to its corporate environment.
β €
The advertised access includes:
β €
β€’ Domain user access
β€’ VNC remote access
β€’ Access to a domain-joined system
β€’ Microsoft Defender present on the environment
β€’ Insurance sector organization
β€’ Privately held company
β €
The actor is asking $2,000 for the access. The listing does not identify the affected company or provide additional information regarding the size of the network or level of privileges available.
β €
The seller's claims and the authenticity, scope and current validity of the allegedly compromised access have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ If you are receiving a large number of unsolicited password reset emails on X, make sure you have β€œPassword Reset Protect” enabled.

I also highly recommend enabling an authenticator app, or even better, using a security key.
I meant to release the OpSec Failures page in early August, but thought of some last second ideas that I'm currently implementing. I'm pretty sure sometime in September I will release this. No paid subscription required.
❀1πŸ”₯1
‼️ An actor is seeking to purchase undisclosed 0day vulnerabilities affecting Veeam products, with particular interest in RCE.
Forwarded from Dark Web Informer - Private
‼️ DOJ Press Release
━━━━━━━━━━━━━━━━━━━━━

Honeywell Aerospace Inc. Agrees to Pay Over $2M to Settle False Claims Act Allegations of Failing to Comply with Cybersecurity Requirements in a U.S. Department of Defense Contract

Full Press Release β†’ justice.gov

━━━━━━━━━━━━━━━━━━━━━
πŸ•΅οΈ Dark Web Informer β€’ DOJ Monitor

Note: DOJ articles that are not Cyber related will be removed manually.
β€ΌοΈπŸ‡­πŸ‡Ί Rhysida Ransomware claims a new victim

πŸ‡­πŸ‡Ί SzΓ©chenyi Programiroda Nonprofit Kft. - A Hungarian development-policy organization involved in planning and implementing programs funded through EU and domestic sources.

The listing includes samples appearing to contain identity documents and other sensitive records, with the dataset being offered for 20 BTC.
This media is not supported in your browser
VIEW IN TELEGRAM
Reminds me of the β€œif it’s not broken, don’t fix it” motto.
😁7
Please open Telegram to view this post
VIEW IN TELEGRAM