#datatheft — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #datatheft, aggregated by home.social.
-
Grok AI Chatbot Tricked Into Leaking Private Chats Through Encrypted Prompt Injection
Security researchers at Adversa AI found a zero-click flaw in xAI's Grok that hides malicious instructions inside encrypted text to steal names, locations, and chat history. The attack needs no clicks from the victim and exposes a broader weakness in how AI agents handle untrusted content. -
Grok AI Chatbot Tricked Into Leaking Private Chats Through Encrypted Prompt Injection
Security researchers at Adversa AI found a zero-click flaw in xAI's Grok that hides malicious instructions inside encrypted text to steal names, locations, and chat history. The attack needs no clicks from the victim and exposes a broader weakness in how AI agents handle untrusted content. -
Grok AI Chatbot Tricked Into Leaking Private Chats Through Encrypted Prompt Injection
Security researchers at Adversa AI found a zero-click flaw in xAI's Grok that hides malicious instructions inside encrypted text to steal names, locations, and chat history. The attack needs no clicks from the victim and exposes a broader weakness in how AI agents handle untrusted content. -
Grok AI Chatbot Tricked Into Leaking Private Chats Through Encrypted Prompt Injection
Security researchers at Adversa AI found a zero-click flaw in xAI's Grok that hides malicious instructions inside encrypted text to steal names, locations, and chat history. The attack needs no clicks from the victim and exposes a broader weakness in how AI agents handle untrusted content. -
Grok AI Chatbot Tricked Into Leaking Private Chats Through Encrypted Prompt Injection
Security researchers at Adversa AI found a zero-click flaw in xAI's Grok that hides malicious instructions inside encrypted text to steal names, locations, and chat history. The attack needs no clicks from the victim and exposes a broader weakness in how AI agents handle untrusted content. -
Discover how the CoSnitch exploit chain manipulated Microsoft Copilot Personal to steal sensitive emails, calendar events, and files through a single malicious link.
#MicrosoftCopilot #Cybersecurity #DataTheft #InfoSec #Vulnerability
-
Discover how the CoSnitch exploit chain manipulated Microsoft Copilot Personal to steal sensitive emails, calendar events, and files through a single malicious link.
#MicrosoftCopilot #Cybersecurity #DataTheft #InfoSec #Vulnerability
-
Discover how the CoSnitch exploit chain manipulated Microsoft Copilot Personal to steal sensitive emails, calendar events, and files through a single malicious link.
#MicrosoftCopilot #Cybersecurity #DataTheft #InfoSec #Vulnerability
-
Clop Returns with Custom Implant in Mass-Extortion Campaign
The Clop threat group has returned to mass exploitation tactics by leveraging CVE-2026-12569 in PTC Windchill, deploying a sophisticated custom web shell designed specifically for data theft and extortion. This purpose-built implant provides immediate full data-theft capability without requiring additional tooling, featuring built-in credential harvesting, database enumeration, and a custom Java class loader for executing arbitrary code in memory. The web shell decrypts credentials from Windchill's keystore, including LDAP manager passwords that could enable enterprise-wide compromise. Its application-specific design allows malicious activity to blend seamlessly with legitimate traffic, making detection significantly more challenging. The implant targets sensitive intellectual property and engineering data stored in Windchill installations across manufacturing enterprises globally.
Pulse ID: 6a85530dde3c55da4658c63b
Pulse Link: https://otx.alienvault.com/pulse/6a85530dde3c55da4658c63b
Pulse Author: AlienVault
Created: 2026-08-19 06:54:05Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CredentialHarvesting #CyberSecurity #DataTheft #Extortion #ICS #InfoSec #Java #Manufacturing #OTX #OpenThreatExchange #Password #Passwords #RAT #SSL #Word #bot #AlienVault
-
Clop Returns with Custom Implant in Mass-Extortion Campaign
The Clop threat group has returned to mass exploitation tactics by leveraging CVE-2026-12569 in PTC Windchill, deploying a sophisticated custom web shell designed specifically for data theft and extortion. This purpose-built implant provides immediate full data-theft capability without requiring additional tooling, featuring built-in credential harvesting, database enumeration, and a custom Java class loader for executing arbitrary code in memory. The web shell decrypts credentials from Windchill's keystore, including LDAP manager passwords that could enable enterprise-wide compromise. Its application-specific design allows malicious activity to blend seamlessly with legitimate traffic, making detection significantly more challenging. The implant targets sensitive intellectual property and engineering data stored in Windchill installations across manufacturing enterprises globally.
Pulse ID: 6a85530dde3c55da4658c63b
Pulse Link: https://otx.alienvault.com/pulse/6a85530dde3c55da4658c63b
Pulse Author: AlienVault
Created: 2026-08-19 06:54:05Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CredentialHarvesting #CyberSecurity #DataTheft #Extortion #ICS #InfoSec #Java #Manufacturing #OTX #OpenThreatExchange #Password #Passwords #RAT #SSL #Word #bot #AlienVault
-
Clop Returns with Custom Implant in Mass-Extortion Campaign
The Clop threat group has returned to mass exploitation tactics by leveraging CVE-2026-12569 in PTC Windchill, deploying a sophisticated custom web shell designed specifically for data theft and extortion. This purpose-built implant provides immediate full data-theft capability without requiring additional tooling, featuring built-in credential harvesting, database enumeration, and a custom Java class loader for executing arbitrary code in memory. The web shell decrypts credentials from Windchill's keystore, including LDAP manager passwords that could enable enterprise-wide compromise. Its application-specific design allows malicious activity to blend seamlessly with legitimate traffic, making detection significantly more challenging. The implant targets sensitive intellectual property and engineering data stored in Windchill installations across manufacturing enterprises globally.
Pulse ID: 6a85530dde3c55da4658c63b
Pulse Link: https://otx.alienvault.com/pulse/6a85530dde3c55da4658c63b
Pulse Author: AlienVault
Created: 2026-08-19 06:54:05Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CredentialHarvesting #CyberSecurity #DataTheft #Extortion #ICS #InfoSec #Java #Manufacturing #OTX #OpenThreatExchange #Password #Passwords #RAT #SSL #Word #bot #AlienVault
-
Clop Returns with Custom Implant in Mass-Extortion Campaign
The Clop threat group has returned to mass exploitation tactics by leveraging CVE-2026-12569 in PTC Windchill, deploying a sophisticated custom web shell designed specifically for data theft and extortion. This purpose-built implant provides immediate full data-theft capability without requiring additional tooling, featuring built-in credential harvesting, database enumeration, and a custom Java class loader for executing arbitrary code in memory. The web shell decrypts credentials from Windchill's keystore, including LDAP manager passwords that could enable enterprise-wide compromise. Its application-specific design allows malicious activity to blend seamlessly with legitimate traffic, making detection significantly more challenging. The implant targets sensitive intellectual property and engineering data stored in Windchill installations across manufacturing enterprises globally.
Pulse ID: 6a85530dde3c55da4658c63b
Pulse Link: https://otx.alienvault.com/pulse/6a85530dde3c55da4658c63b
Pulse Author: AlienVault
Created: 2026-08-19 06:54:05Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CredentialHarvesting #CyberSecurity #DataTheft #Extortion #ICS #InfoSec #Java #Manufacturing #OTX #OpenThreatExchange #Password #Passwords #RAT #SSL #Word #bot #AlienVault
-
Clop Returns with Custom Implant in Mass-Extortion Campaign
The Clop threat group has returned to mass exploitation tactics by leveraging CVE-2026-12569 in PTC Windchill, deploying a sophisticated custom web shell designed specifically for data theft and extortion. This purpose-built implant provides immediate full data-theft capability without requiring additional tooling, featuring built-in credential harvesting, database enumeration, and a custom Java class loader for executing arbitrary code in memory. The web shell decrypts credentials from Windchill's keystore, including LDAP manager passwords that could enable enterprise-wide compromise. Its application-specific design allows malicious activity to blend seamlessly with legitimate traffic, making detection significantly more challenging. The implant targets sensitive intellectual property and engineering data stored in Windchill installations across manufacturing enterprises globally.
Pulse ID: 6a85530dde3c55da4658c63b
Pulse Link: https://otx.alienvault.com/pulse/6a85530dde3c55da4658c63b
Pulse Author: AlienVault
Created: 2026-08-19 06:54:05Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CredentialHarvesting #CyberSecurity #DataTheft #Extortion #ICS #InfoSec #Java #Manufacturing #OTX #OpenThreatExchange #Password #Passwords #RAT #SSL #Word #bot #AlienVault
-
C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2
In July 2026, a new Rust-based malware family called C2Looper was identified, likely used by ransomware-related threat actors. The malware is assessed with low to medium confidence to be delivered through multi-stage ClickFix infection chains. C2Looper provides backdoor capabilities including remote shell execution, reconnaissance, and deploying additional payloads. It dynamically resolves Windows APIs and encrypts strings using XOR operations. The malware communicates via plaintext HTTP initially, but an evolved version uses GitHub repositories for command-and-control operations, storing commands and exfiltrated data in JSON files. Version 2 introduces additional commands such as reconnaissance collection, drive enumeration, shellcode injection, and file listing. The malware demonstrates active development with refined capabilities, likely serving initial access brokers for data theft and ransomware deployment.
Pulse ID: 6a8322da43ee19a9f60899af
Pulse Link: https://otx.alienvault.com/pulse/6a8322da43ee19a9f60899af
Pulse Author: AlienVault
Created: 2026-08-17 15:03:54Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CodeInjection #CyberSecurity #DataTheft #GitHub #HTTP #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RansomWare #Rust #ShellCode #Windows #bot #AlienVault
-
C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2
In July 2026, a new Rust-based malware family called C2Looper was identified, likely used by ransomware-related threat actors. The malware is assessed with low to medium confidence to be delivered through multi-stage ClickFix infection chains. C2Looper provides backdoor capabilities including remote shell execution, reconnaissance, and deploying additional payloads. It dynamically resolves Windows APIs and encrypts strings using XOR operations. The malware communicates via plaintext HTTP initially, but an evolved version uses GitHub repositories for command-and-control operations, storing commands and exfiltrated data in JSON files. Version 2 introduces additional commands such as reconnaissance collection, drive enumeration, shellcode injection, and file listing. The malware demonstrates active development with refined capabilities, likely serving initial access brokers for data theft and ransomware deployment.
Pulse ID: 6a8322da43ee19a9f60899af
Pulse Link: https://otx.alienvault.com/pulse/6a8322da43ee19a9f60899af
Pulse Author: AlienVault
Created: 2026-08-17 15:03:54Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CodeInjection #CyberSecurity #DataTheft #GitHub #HTTP #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RansomWare #Rust #ShellCode #Windows #bot #AlienVault
-
C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2
In July 2026, a new Rust-based malware family called C2Looper was identified, likely used by ransomware-related threat actors. The malware is assessed with low to medium confidence to be delivered through multi-stage ClickFix infection chains. C2Looper provides backdoor capabilities including remote shell execution, reconnaissance, and deploying additional payloads. It dynamically resolves Windows APIs and encrypts strings using XOR operations. The malware communicates via plaintext HTTP initially, but an evolved version uses GitHub repositories for command-and-control operations, storing commands and exfiltrated data in JSON files. Version 2 introduces additional commands such as reconnaissance collection, drive enumeration, shellcode injection, and file listing. The malware demonstrates active development with refined capabilities, likely serving initial access brokers for data theft and ransomware deployment.
Pulse ID: 6a8322da43ee19a9f60899af
Pulse Link: https://otx.alienvault.com/pulse/6a8322da43ee19a9f60899af
Pulse Author: AlienVault
Created: 2026-08-17 15:03:54Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CodeInjection #CyberSecurity #DataTheft #GitHub #HTTP #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RansomWare #Rust #ShellCode #Windows #bot #AlienVault
-
C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2
In July 2026, a new Rust-based malware family called C2Looper was identified, likely used by ransomware-related threat actors. The malware is assessed with low to medium confidence to be delivered through multi-stage ClickFix infection chains. C2Looper provides backdoor capabilities including remote shell execution, reconnaissance, and deploying additional payloads. It dynamically resolves Windows APIs and encrypts strings using XOR operations. The malware communicates via plaintext HTTP initially, but an evolved version uses GitHub repositories for command-and-control operations, storing commands and exfiltrated data in JSON files. Version 2 introduces additional commands such as reconnaissance collection, drive enumeration, shellcode injection, and file listing. The malware demonstrates active development with refined capabilities, likely serving initial access brokers for data theft and ransomware deployment.
Pulse ID: 6a8322da43ee19a9f60899af
Pulse Link: https://otx.alienvault.com/pulse/6a8322da43ee19a9f60899af
Pulse Author: AlienVault
Created: 2026-08-17 15:03:54Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CodeInjection #CyberSecurity #DataTheft #GitHub #HTTP #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RansomWare #Rust #ShellCode #Windows #bot #AlienVault
-
C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2
In July 2026, a new Rust-based malware family called C2Looper was identified, likely used by ransomware-related threat actors. The malware is assessed with low to medium confidence to be delivered through multi-stage ClickFix infection chains. C2Looper provides backdoor capabilities including remote shell execution, reconnaissance, and deploying additional payloads. It dynamically resolves Windows APIs and encrypts strings using XOR operations. The malware communicates via plaintext HTTP initially, but an evolved version uses GitHub repositories for command-and-control operations, storing commands and exfiltrated data in JSON files. Version 2 introduces additional commands such as reconnaissance collection, drive enumeration, shellcode injection, and file listing. The malware demonstrates active development with refined capabilities, likely serving initial access brokers for data theft and ransomware deployment.
Pulse ID: 6a8322da43ee19a9f60899af
Pulse Link: https://otx.alienvault.com/pulse/6a8322da43ee19a9f60899af
Pulse Author: AlienVault
Created: 2026-08-17 15:03:54Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CodeInjection #CyberSecurity #DataTheft #GitHub #HTTP #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RansomWare #Rust #ShellCode #Windows #bot #AlienVault
-
DATE: August 17, 2026 at 06:06PM
SOURCE: HEALTHCARE INFO SECURITYDirect article link at end of text block below.
Hack on #Medical Software Firm Hits Half of #Poland's Population: 19M Patients Affected by #DataTheft Including National ID Numbers https://t.co/rJ2D1JKoYF
Here are any URLs found in the article text:
Articles can be found by scrolling down the page at https://www.healthcareinfosecurity.com/ under the title "Latest"
-------------------------------------------------
Private, vetted email list for mental health professionals: https://www.clinicians-exchange.org
Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.
-------------------------------------------------
#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering
-
DATE: August 17, 2026 at 06:06PM
SOURCE: HEALTHCARE INFO SECURITYDirect article link at end of text block below.
Hack on #Medical Software Firm Hits Half of #Poland's Population: 19M Patients Affected by #DataTheft Including National ID Numbers https://t.co/rJ2D1JKoYF
Here are any URLs found in the article text:
Articles can be found by scrolling down the page at https://www.healthcareinfosecurity.com/ under the title "Latest"
-------------------------------------------------
Private, vetted email list for mental health professionals: https://www.clinicians-exchange.org
Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.
-------------------------------------------------
#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering
-
DATE: August 17, 2026 at 06:06PM
SOURCE: HEALTHCARE INFO SECURITYDirect article link at end of text block below.
Hack on #Medical Software Firm Hits Half of #Poland's Population: 19M Patients Affected by #DataTheft Including National ID Numbers https://t.co/rJ2D1JKoYF
Here are any URLs found in the article text:
Articles can be found by scrolling down the page at https://www.healthcareinfosecurity.com/ under the title "Latest"
-------------------------------------------------
Private, vetted email list for mental health professionals: https://www.clinicians-exchange.org
Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.
-------------------------------------------------
#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering
-
DATE: August 17, 2026 at 06:06PM
SOURCE: HEALTHCARE INFO SECURITYDirect article link at end of text block below.
Hack on #Medical Software Firm Hits Half of #Poland's Population: 19M Patients Affected by #DataTheft Including National ID Numbers https://t.co/rJ2D1JKoYF
Here are any URLs found in the article text:
Articles can be found by scrolling down the page at https://www.healthcareinfosecurity.com/ under the title "Latest"
-------------------------------------------------
Private, vetted email list for mental health professionals: https://www.clinicians-exchange.org
Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.
-------------------------------------------------
#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering
-
https://www.europesays.com/videos/78314/ French taxpayers warned after personal data stolen in major hack • FRANCE 24 English #cyberattack #cybersecurity #DataBreach #DataTheft #France #FRANCE24 #FRANCE24English #FRANCE24 #FRANCE24English #fraud #FrenchGovernment #FrenchTaxpayers #GovernmentData #IdentityTheft #OnlineScams #PersonalData #SébastienLecornu #StolenData #TaxInformation
-
Phantom Stealer Malware Uses Steganography and Process Injection to Data Theft
Phantom Stealer is a .NET based information-stealing malware that uses
PNG steganography, PowerShell-based process injection and defense evasion techniques to steal browser credentials, cryptocurrency wallets, cookies and sensitive files. The malware also uses clipboard manipulation to redirect cryptocurrency transactions and employs multiple techniques to avoid detection.Pulse ID: 6a82666881d78521845bd0af
Pulse Link: https://otx.alienvault.com/pulse/6a82666881d78521845bd0af
Pulse Author: cryptocti
Created: 2026-08-17 01:39:52Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Clipboard #Cookies #CyberSecurity #DataTheft #InfoSec #Malware #NET #OTX #OpenThreatExchange #PowerShell #Steganography #bot #cryptocurrency #cryptocti
-
Phantom Stealer Malware Uses Steganography and Process Injection to Data Theft
Phantom Stealer is a .NET based information-stealing malware that uses
PNG steganography, PowerShell-based process injection and defense evasion techniques to steal browser credentials, cryptocurrency wallets, cookies and sensitive files. The malware also uses clipboard manipulation to redirect cryptocurrency transactions and employs multiple techniques to avoid detection.Pulse ID: 6a82666881d78521845bd0af
Pulse Link: https://otx.alienvault.com/pulse/6a82666881d78521845bd0af
Pulse Author: cryptocti
Created: 2026-08-17 01:39:52Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Clipboard #Cookies #CyberSecurity #DataTheft #InfoSec #Malware #NET #OTX #OpenThreatExchange #PowerShell #Steganography #bot #cryptocurrency #cryptocti
-
Phantom Stealer Malware Uses Steganography and Process Injection to Data Theft
Phantom Stealer is a .NET based information-stealing malware that uses
PNG steganography, PowerShell-based process injection and defense evasion techniques to steal browser credentials, cryptocurrency wallets, cookies and sensitive files. The malware also uses clipboard manipulation to redirect cryptocurrency transactions and employs multiple techniques to avoid detection.Pulse ID: 6a82666881d78521845bd0af
Pulse Link: https://otx.alienvault.com/pulse/6a82666881d78521845bd0af
Pulse Author: cryptocti
Created: 2026-08-17 01:39:52Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Clipboard #Cookies #CyberSecurity #DataTheft #InfoSec #Malware #NET #OTX #OpenThreatExchange #PowerShell #Steganography #bot #cryptocurrency #cryptocti
-
Phantom Stealer Malware Uses Steganography and Process Injection to Data Theft
Phantom Stealer is a .NET based information-stealing malware that uses
PNG steganography, PowerShell-based process injection and defense evasion techniques to steal browser credentials, cryptocurrency wallets, cookies and sensitive files. The malware also uses clipboard manipulation to redirect cryptocurrency transactions and employs multiple techniques to avoid detection.Pulse ID: 6a82666881d78521845bd0af
Pulse Link: https://otx.alienvault.com/pulse/6a82666881d78521845bd0af
Pulse Author: cryptocti
Created: 2026-08-17 01:39:52Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Clipboard #Cookies #CyberSecurity #DataTheft #InfoSec #Malware #NET #OTX #OpenThreatExchange #PowerShell #Steganography #bot #cryptocurrency #cryptocti
-
Phantom Stealer Malware Uses Steganography and Process Injection to Data Theft
Phantom Stealer is a .NET based information-stealing malware that uses
PNG steganography, PowerShell-based process injection and defense evasion techniques to steal browser credentials, cryptocurrency wallets, cookies and sensitive files. The malware also uses clipboard manipulation to redirect cryptocurrency transactions and employs multiple techniques to avoid detection.Pulse ID: 6a82666881d78521845bd0af
Pulse Link: https://otx.alienvault.com/pulse/6a82666881d78521845bd0af
Pulse Author: cryptocti
Created: 2026-08-17 01:39:52Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Clipboard #Cookies #CyberSecurity #DataTheft #InfoSec #Malware #NET #OTX #OpenThreatExchange #PowerShell #Steganography #bot #cryptocurrency #cryptocti
-
AmnesiaStealer malware is targeting macOS users through fake GitHub pages, tricking them into running malicious Terminal commands that lead to data theft. Users should verify download sources and exercise caution to protect their systems.
#AmnesiaStealer #macOS #CyberSecurity #Malware #GitHub #DataTheft
https://thedailytechfeed.com/amnesiastealer-targets-macos-users-via-fake-github-pages/
-
https://www.europesays.com/dk/145393/ Extortion Gang Leaks Novo Nordisk’s ‘AI and ML Ecosystem’ #AIModels #DataTheft #DrugMaker #fulcrumsec #HuggingFace #IntellectualProperty #LeeKim #NovoNordisk
-
South Korea, US warn of Gunra ransomware targeting healthcare, finance and critical infrastructure
South Korean police and US cybersecurity agencies have issued a joint warning over Gunra ransomware, which has evolved…
#EuropeSays #Korea #KR #cyberdefence #cybersecurity #datatheft #FBI #Gunraransomware #Korean #NSA #ransomware-as-a-service #SouthKorea
https://www.europesays.com/korea/115374/ -
Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments
UNC6671 continues conducting data theft extortion operations despite the alleged retirement of the BlackFile brand in May 2026. The threat actor has diversified across multiple extortion fronts including Redact, Pink, Helix, and Falcon. They employ voice phishing tactics, posing as IT helpdesk staff to contact employees on personal mobile devices, directing them to spoofed login portals with Adversary-in-the-Middle infrastructure that intercepts credentials and multi-factor authentication tokens. Once access is established, automated scripts exfiltrate data from enterprise cloud environments including Microsoft 365 and Okta. Infrastructure analysis reveals shared phishing panels, overlapping victim targeting, and connected domains across all brands. Recent targeting has evolved toward financial services, private equity, legal, and professional services sectors. Between January and May 2026, Bitcoin wallet analysis showed approximately $10.69 million USD in ransom payments, with demands typically ranging fr...
Pulse ID: 6a75078f7b8e057bc29b8769
Pulse Link: https://otx.alienvault.com/pulse/6a75078f7b8e057bc29b8769
Pulse Author: AlienVault
Created: 2026-08-06 22:15:43Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AdversaryInTheMiddle #BitCoin #Cloud #CyberSecurity #DataTheft #Extortion #ICS #InfoSec #Microsoft #OTX #OpenThreatExchange #Phishing #RAT #RCE #bot #AlienVault
-
Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments
UNC6671 continues conducting data theft extortion operations despite the alleged retirement of the BlackFile brand in May 2026. The threat actor has diversified across multiple extortion fronts including Redact, Pink, Helix, and Falcon. They employ voice phishing tactics, posing as IT helpdesk staff to contact employees on personal mobile devices, directing them to spoofed login portals with Adversary-in-the-Middle infrastructure that intercepts credentials and multi-factor authentication tokens. Once access is established, automated scripts exfiltrate data from enterprise cloud environments including Microsoft 365 and Okta. Infrastructure analysis reveals shared phishing panels, overlapping victim targeting, and connected domains across all brands. Recent targeting has evolved toward financial services, private equity, legal, and professional services sectors. Between January and May 2026, Bitcoin wallet analysis showed approximately $10.69 million USD in ransom payments, with demands typically ranging fr...
Pulse ID: 6a75078f7b8e057bc29b8769
Pulse Link: https://otx.alienvault.com/pulse/6a75078f7b8e057bc29b8769
Pulse Author: AlienVault
Created: 2026-08-06 22:15:43Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AdversaryInTheMiddle #BitCoin #Cloud #CyberSecurity #DataTheft #Extortion #ICS #InfoSec #Microsoft #OTX #OpenThreatExchange #Phishing #RAT #RCE #bot #AlienVault
-
Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments
UNC6671 continues conducting data theft extortion operations despite the alleged retirement of the BlackFile brand in May 2026. The threat actor has diversified across multiple extortion fronts including Redact, Pink, Helix, and Falcon. They employ voice phishing tactics, posing as IT helpdesk staff to contact employees on personal mobile devices, directing them to spoofed login portals with Adversary-in-the-Middle infrastructure that intercepts credentials and multi-factor authentication tokens. Once access is established, automated scripts exfiltrate data from enterprise cloud environments including Microsoft 365 and Okta. Infrastructure analysis reveals shared phishing panels, overlapping victim targeting, and connected domains across all brands. Recent targeting has evolved toward financial services, private equity, legal, and professional services sectors. Between January and May 2026, Bitcoin wallet analysis showed approximately $10.69 million USD in ransom payments, with demands typically ranging fr...
Pulse ID: 6a75078f7b8e057bc29b8769
Pulse Link: https://otx.alienvault.com/pulse/6a75078f7b8e057bc29b8769
Pulse Author: AlienVault
Created: 2026-08-06 22:15:43Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AdversaryInTheMiddle #BitCoin #Cloud #CyberSecurity #DataTheft #Extortion #ICS #InfoSec #Microsoft #OTX #OpenThreatExchange #Phishing #RAT #RCE #bot #AlienVault
-
Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments
UNC6671 continues conducting data theft extortion operations despite the alleged retirement of the BlackFile brand in May 2026. The threat actor has diversified across multiple extortion fronts including Redact, Pink, Helix, and Falcon. They employ voice phishing tactics, posing as IT helpdesk staff to contact employees on personal mobile devices, directing them to spoofed login portals with Adversary-in-the-Middle infrastructure that intercepts credentials and multi-factor authentication tokens. Once access is established, automated scripts exfiltrate data from enterprise cloud environments including Microsoft 365 and Okta. Infrastructure analysis reveals shared phishing panels, overlapping victim targeting, and connected domains across all brands. Recent targeting has evolved toward financial services, private equity, legal, and professional services sectors. Between January and May 2026, Bitcoin wallet analysis showed approximately $10.69 million USD in ransom payments, with demands typically ranging fr...
Pulse ID: 6a75078f7b8e057bc29b8769
Pulse Link: https://otx.alienvault.com/pulse/6a75078f7b8e057bc29b8769
Pulse Author: AlienVault
Created: 2026-08-06 22:15:43Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AdversaryInTheMiddle #BitCoin #Cloud #CyberSecurity #DataTheft #Extortion #ICS #InfoSec #Microsoft #OTX #OpenThreatExchange #Phishing #RAT #RCE #bot #AlienVault
-
Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments
UNC6671 continues conducting data theft extortion operations despite the alleged retirement of the BlackFile brand in May 2026. The threat actor has diversified across multiple extortion fronts including Redact, Pink, Helix, and Falcon. They employ voice phishing tactics, posing as IT helpdesk staff to contact employees on personal mobile devices, directing them to spoofed login portals with Adversary-in-the-Middle infrastructure that intercepts credentials and multi-factor authentication tokens. Once access is established, automated scripts exfiltrate data from enterprise cloud environments including Microsoft 365 and Okta. Infrastructure analysis reveals shared phishing panels, overlapping victim targeting, and connected domains across all brands. Recent targeting has evolved toward financial services, private equity, legal, and professional services sectors. Between January and May 2026, Bitcoin wallet analysis showed approximately $10.69 million USD in ransom payments, with demands typically ranging fr...
Pulse ID: 6a75078f7b8e057bc29b8769
Pulse Link: https://otx.alienvault.com/pulse/6a75078f7b8e057bc29b8769
Pulse Author: AlienVault
Created: 2026-08-06 22:15:43Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AdversaryInTheMiddle #BitCoin #Cloud #CyberSecurity #DataTheft #Extortion #ICS #InfoSec #Microsoft #OTX #OpenThreatExchange #Phishing #RAT #RCE #bot #AlienVault
-
UNC6671 Automates Microsoft 365 Data Theft After Hijacking Employee Sessions
Indicators extracted from public reporting. Source: https://cybersecuritynews.com/unc6671-automates-microsoft-365/
Pulse ID: 6a75abf8c9b00b0de18d1947
Pulse Link: https://otx.alienvault.com/pulse/6a75abf8c9b00b0de18d1947
Pulse Author: CyberHunter_NL
Created: 2026-08-07 09:57:12Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DataTheft #HTTP #HTTPS #InfoSec #Microsoft #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
UNC6671 Automates Microsoft 365 Data Theft After Hijacking Employee Sessions
Indicators extracted from public reporting. Source: https://cybersecuritynews.com/unc6671-automates-microsoft-365/
Pulse ID: 6a75abf8c9b00b0de18d1947
Pulse Link: https://otx.alienvault.com/pulse/6a75abf8c9b00b0de18d1947
Pulse Author: CyberHunter_NL
Created: 2026-08-07 09:57:12Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DataTheft #HTTP #HTTPS #InfoSec #Microsoft #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
UNC6671 Automates Microsoft 365 Data Theft After Hijacking Employee Sessions
Indicators extracted from public reporting. Source: https://cybersecuritynews.com/unc6671-automates-microsoft-365/
Pulse ID: 6a75abf8c9b00b0de18d1947
Pulse Link: https://otx.alienvault.com/pulse/6a75abf8c9b00b0de18d1947
Pulse Author: CyberHunter_NL
Created: 2026-08-07 09:57:12Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DataTheft #HTTP #HTTPS #InfoSec #Microsoft #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
UNC6671 Automates Microsoft 365 Data Theft After Hijacking Employee Sessions
Indicators extracted from public reporting. Source: https://cybersecuritynews.com/unc6671-automates-microsoft-365/
Pulse ID: 6a75abf8c9b00b0de18d1947
Pulse Link: https://otx.alienvault.com/pulse/6a75abf8c9b00b0de18d1947
Pulse Author: CyberHunter_NL
Created: 2026-08-07 09:57:12Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DataTheft #HTTP #HTTPS #InfoSec #Microsoft #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
UNC6671 Automates Microsoft 365 Data Theft After Hijacking Employee Sessions
Indicators extracted from public reporting. Source: https://cybersecuritynews.com/unc6671-automates-microsoft-365/
Pulse ID: 6a75abf8c9b00b0de18d1947
Pulse Link: https://otx.alienvault.com/pulse/6a75abf8c9b00b0de18d1947
Pulse Author: CyberHunter_NL
Created: 2026-08-07 09:57:12Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DataTheft #HTTP #HTTPS #InfoSec #Microsoft #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
Cyberattack Targets Travelers' Data via Compromised Hotel Wi-Fi Networks
📰 Original title: Russia-Linked 'Midnight Blizzard' Group Hijacks Hotel Wi-Fi With CaptiveCrunch
🤖 IA: It's clickbait ⚠️
👥 Users: It's clickbait ⚠️View full AI summary https://en.killbait.com/cyberattack-targets-travelers-data-via-compromised-hotel-wi-fi-networks.html?utm_source=mastodon_world&utm_medium=social&utm_campaign=killbait.mastodon_world
-
Cyberattack Targets Travelers' Data via Compromised Hotel Wi-Fi Networks
📰 Original title: Russia-Linked 'Midnight Blizzard' Group Hijacks Hotel Wi-Fi With CaptiveCrunch
🤖 IA: It's clickbait ⚠️
👥 Users: It's clickbait ⚠️View full AI summary https://en.killbait.com/cyberattack-targets-travelers-data-via-compromised-hotel-wi-fi-networks.html?utm_source=mastodon_world&utm_medium=social&utm_campaign=killbait.mastodon_world
-
Cyberattack Targets Travelers' Data via Compromised Hotel Wi-Fi Networks
📰 Original title: Russia-Linked 'Midnight Blizzard' Group Hijacks Hotel Wi-Fi With CaptiveCrunch
🤖 IA: It's clickbait ⚠️
👥 Users: It's clickbait ⚠️View full AI summary https://en.killbait.com/cyberattack-targets-travelers-data-via-compromised-hotel-wi-fi-networks.html?utm_source=mastodon_world&utm_medium=social&utm_campaign=killbait.mastodon_world
-
Cyberattack Targets Travelers' Data via Compromised Hotel Wi-Fi Networks
📰 Original title: Russia-Linked 'Midnight Blizzard' Group Hijacks Hotel Wi-Fi With CaptiveCrunch
🤖 IA: It's clickbait ⚠️
👥 Users: It's clickbait ⚠️View full AI summary https://en.killbait.com/cyberattack-targets-travelers-data-via-compromised-hotel-wi-fi-networks.html?utm_source=mastodon_world&utm_medium=social&utm_campaign=killbait.mastodon_world
-
Cyberattack Targets Travelers' Data via Compromised Hotel Wi-Fi Networks
📰 Original title: Russia-Linked 'Midnight Blizzard' Group Hijacks Hotel Wi-Fi With CaptiveCrunch
🤖 IA: It's clickbait ⚠️
👥 Users: It's clickbait ⚠️View full AI summary https://en.killbait.com/cyberattack-targets-travelers-data-via-compromised-hotel-wi-fi-networks.html?utm_source=mastodon_world&utm_medium=social&utm_campaign=killbait.mastodon_world
-
DATE: July 31, 2026 at 05:33PM
SOURCE: HEALTHCARE INFO SECURITYDirect article link at end of text block below.
#DentaQuest #DataTheft #Hack Affects 15M Patients:
Number of Victims Is 5 Times Higher Than Claims by #ShinyHunters #Ransomware Gang
https://t.co/IYHEq9giN6
#HIPAA #databreach #sunlifeHere are any URLs found in the article text:
Articles can be found by scrolling down the page at https://www.healthcareinfosecurity.com/ under the title "Latest"
-------------------------------------------------
Private, vetted email list for mental health professionals: https://www.clinicians-exchange.org
Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.
-------------------------------------------------
#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering
-
DATE: July 31, 2026 at 05:33PM
SOURCE: HEALTHCARE INFO SECURITYDirect article link at end of text block below.
#DentaQuest #DataTheft #Hack Affects 15M Patients:
Number of Victims Is 5 Times Higher Than Claims by #ShinyHunters #Ransomware Gang
https://t.co/IYHEq9giN6
#HIPAA #databreach #sunlifeHere are any URLs found in the article text:
Articles can be found by scrolling down the page at https://www.healthcareinfosecurity.com/ under the title "Latest"
-------------------------------------------------
Private, vetted email list for mental health professionals: https://www.clinicians-exchange.org
Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.
-------------------------------------------------
#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering
-
DATE: July 31, 2026 at 05:33PM
SOURCE: HEALTHCARE INFO SECURITYDirect article link at end of text block below.
#DentaQuest #DataTheft #Hack Affects 15M Patients:
Number of Victims Is 5 Times Higher Than Claims by #ShinyHunters #Ransomware Gang
https://t.co/IYHEq9giN6
#HIPAA #databreach #sunlifeHere are any URLs found in the article text:
Articles can be found by scrolling down the page at https://www.healthcareinfosecurity.com/ under the title "Latest"
-------------------------------------------------
Private, vetted email list for mental health professionals: https://www.clinicians-exchange.org
Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.
-------------------------------------------------
#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering
-
DATE: July 31, 2026 at 05:33PM
SOURCE: HEALTHCARE INFO SECURITYDirect article link at end of text block below.
#DentaQuest #DataTheft #Hack Affects 15M Patients:
Number of Victims Is 5 Times Higher Than Claims by #ShinyHunters #Ransomware Gang
https://t.co/IYHEq9giN6
#HIPAA #databreach #sunlifeHere are any URLs found in the article text:
Articles can be found by scrolling down the page at https://www.healthcareinfosecurity.com/ under the title "Latest"
-------------------------------------------------
Private, vetted email list for mental health professionals: https://www.clinicians-exchange.org
Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.
-------------------------------------------------
#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering
-
RE: https://vt.social/@lina/116975435851200366
I deleted my #GitHub account since @huggingface.co stole my code (15 repos) in 2025, and happily moved to @Codeberg
Now I can’t opt-out. 🤦🏻♂️
To everybody working for or using #HuggingFace: I do not consent to any use of my code for training, calibration, (partial) extrusion or whatever you want to call your bullshit theft and grifting.
This means you effectively cannot use any part of this dataset for any means whatsoever, at least not without being a total arsehole.
-
RE: https://vt.social/@lina/116975435851200366
I deleted my #GitHub account since @huggingface.co stole my code (15 repos) in 2025, and happily moved to @Codeberg
Now I can’t opt-out. 🤦🏻♂️
To everybody working for or using #HuggingFace: I do not consent to any use of my code for training, calibration, (partial) extrusion or whatever you want to call your bullshit theft and grifting.
This means you effectively cannot use any part of this dataset for any means whatsoever, at least not without being a total arsehole.
-
RE: https://vt.social/@lina/116975435851200366
I deleted my #GitHub account since @huggingface.co stole my code (15 repos) in 2025, and happily moved to @Codeberg
Now I can’t opt-out. 🤦🏻♂️
To everybody working for or using #HuggingFace: I do not consent to any use of my code for training, calibration, (partial) extrusion or whatever you want to call your bullshit theft and grifting.
This means you effectively cannot use any part of this dataset for any means whatsoever, at least not without being a total arsehole.
-
RE: https://vt.social/@lina/116975435851200366
I deleted my #GitHub account since @huggingface.co stole my code (15 repos) in 2025, and happily moved to @Codeberg
Now I can’t opt-out. 🤦🏻♂️
To everybody working for or using #HuggingFace: I do not consent to any use of my code for training, calibration, (partial) extrusion or whatever you want to call your bullshit theft and grifting.
This means you effectively cannot use any part of this dataset for any means whatsoever, at least not without being a total arsehole.
-
RE: https://vt.social/@lina/116975435851200366
I deleted my #GitHub account since @huggingface.co stole my code (15 repos) in 2025, and happily moved to @Codeberg
Now I can’t opt-out. 🤦🏻♂️
To everybody working for or using #HuggingFace: I do not consent to any use of my code for training, calibration, (partial) extrusion or whatever you want to call your bullshit theft and grifting.
This means you effectively cannot use any part of this dataset for any means whatsoever, at least not without being a total arsehole.
-
Settra ransomware group claims American Color Imaging after weeklong Iowa outage #Settra #AmericanColorImaging #Ransomware #DataTheft #DoubleExtortion #Iowa https://dysruptionhub.com/settra-american-color-imaging-iowa-outage/
-
Settra ransomware group claims American Color Imaging after weeklong Iowa outage #Settra #AmericanColorImaging #Ransomware #DataTheft #DoubleExtortion #Iowa https://dysruptionhub.com/settra-american-color-imaging-iowa-outage/
-
Once again, the man and the party that Australians thought would rescue them, has betrayed them, this time to A.I. leeches and "international investors". #australia #ausgov #ai #datatheft #watertheft #environment #climatecrisis https://www.theguardian.com/technology/2026/jul/14/anthony-albanese-promises-fast-track-approvals-for-datacentres-to-shore-up-ai-investment
-
Once again, the man and the party that Australians thought would rescue them, has betrayed them, this time to A.I. leeches and "international investors". #australia #ausgov #ai #datatheft #watertheft #environment #climatecrisis https://www.theguardian.com/technology/2026/jul/14/anthony-albanese-promises-fast-track-approvals-for-datacentres-to-shore-up-ai-investment
-
Once again, the man and the party that Australians thought would rescue them, has betrayed them, this time to A.I. leeches and "international investors". #australia #ausgov #ai #datatheft #watertheft #environment #climatecrisis https://www.theguardian.com/technology/2026/jul/14/anthony-albanese-promises-fast-track-approvals-for-datacentres-to-shore-up-ai-investment