home.social

#datatheft — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #datatheft, aggregated by home.social.

fetched live
  1. Grok AI Chatbot Tricked Into Leaking Private Chats Through Encrypted Prompt Injection

    Security researchers at Adversa AI found a zero-click flaw in xAI's Grok that hides malicious instructions inside encrypted text to steal names, locations, and chat history. The attack needs no clicks from the victim and exposes a broader weakness in how AI agents handle untrusted content.

    securebulletin.com/grok-ai-cha

  2. Grok AI Chatbot Tricked Into Leaking Private Chats Through Encrypted Prompt Injection

    Security researchers at Adversa AI found a zero-click flaw in xAI's Grok that hides malicious instructions inside encrypted text to steal names, locations, and chat history. The attack needs no clicks from the victim and exposes a broader weakness in how AI agents handle untrusted content.

    securebulletin.com/grok-ai-cha

  3. Grok AI Chatbot Tricked Into Leaking Private Chats Through Encrypted Prompt Injection

    Security researchers at Adversa AI found a zero-click flaw in xAI's Grok that hides malicious instructions inside encrypted text to steal names, locations, and chat history. The attack needs no clicks from the victim and exposes a broader weakness in how AI agents handle untrusted content.

    securebulletin.com/grok-ai-cha

  4. Grok AI Chatbot Tricked Into Leaking Private Chats Through Encrypted Prompt Injection

    Security researchers at Adversa AI found a zero-click flaw in xAI's Grok that hides malicious instructions inside encrypted text to steal names, locations, and chat history. The attack needs no clicks from the victim and exposes a broader weakness in how AI agents handle untrusted content.

    securebulletin.com/grok-ai-cha

  5. Grok AI Chatbot Tricked Into Leaking Private Chats Through Encrypted Prompt Injection

    Security researchers at Adversa AI found a zero-click flaw in xAI's Grok that hides malicious instructions inside encrypted text to steal names, locations, and chat history. The attack needs no clicks from the victim and exposes a broader weakness in how AI agents handle untrusted content.

    securebulletin.com/grok-ai-cha

  6. Clop Returns with Custom Implant in Mass-Extortion Campaign

    The Clop threat group has returned to mass exploitation tactics by leveraging CVE-2026-12569 in PTC Windchill, deploying a sophisticated custom web shell designed specifically for data theft and extortion. This purpose-built implant provides immediate full data-theft capability without requiring additional tooling, featuring built-in credential harvesting, database enumeration, and a custom Java class loader for executing arbitrary code in memory. The web shell decrypts credentials from Windchill's keystore, including LDAP manager passwords that could enable enterprise-wide compromise. Its application-specific design allows malicious activity to blend seamlessly with legitimate traffic, making detection significantly more challenging. The implant targets sensitive intellectual property and engineering data stored in Windchill installations across manufacturing enterprises globally.

    Pulse ID: 6a85530dde3c55da4658c63b
    Pulse Link: otx.alienvault.com/pulse/6a855
    Pulse Author: AlienVault
    Created: 2026-08-19 06:54:05

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CredentialHarvesting #CyberSecurity #DataTheft #Extortion #ICS #InfoSec #Java #Manufacturing #OTX #OpenThreatExchange #Password #Passwords #RAT #SSL #Word #bot #AlienVault

  7. Clop Returns with Custom Implant in Mass-Extortion Campaign

    The Clop threat group has returned to mass exploitation tactics by leveraging CVE-2026-12569 in PTC Windchill, deploying a sophisticated custom web shell designed specifically for data theft and extortion. This purpose-built implant provides immediate full data-theft capability without requiring additional tooling, featuring built-in credential harvesting, database enumeration, and a custom Java class loader for executing arbitrary code in memory. The web shell decrypts credentials from Windchill's keystore, including LDAP manager passwords that could enable enterprise-wide compromise. Its application-specific design allows malicious activity to blend seamlessly with legitimate traffic, making detection significantly more challenging. The implant targets sensitive intellectual property and engineering data stored in Windchill installations across manufacturing enterprises globally.

    Pulse ID: 6a85530dde3c55da4658c63b
    Pulse Link: otx.alienvault.com/pulse/6a855
    Pulse Author: AlienVault
    Created: 2026-08-19 06:54:05

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CredentialHarvesting #CyberSecurity #DataTheft #Extortion #ICS #InfoSec #Java #Manufacturing #OTX #OpenThreatExchange #Password #Passwords #RAT #SSL #Word #bot #AlienVault

  8. Clop Returns with Custom Implant in Mass-Extortion Campaign

    The Clop threat group has returned to mass exploitation tactics by leveraging CVE-2026-12569 in PTC Windchill, deploying a sophisticated custom web shell designed specifically for data theft and extortion. This purpose-built implant provides immediate full data-theft capability without requiring additional tooling, featuring built-in credential harvesting, database enumeration, and a custom Java class loader for executing arbitrary code in memory. The web shell decrypts credentials from Windchill's keystore, including LDAP manager passwords that could enable enterprise-wide compromise. Its application-specific design allows malicious activity to blend seamlessly with legitimate traffic, making detection significantly more challenging. The implant targets sensitive intellectual property and engineering data stored in Windchill installations across manufacturing enterprises globally.

    Pulse ID: 6a85530dde3c55da4658c63b
    Pulse Link: otx.alienvault.com/pulse/6a855
    Pulse Author: AlienVault
    Created: 2026-08-19 06:54:05

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CredentialHarvesting #CyberSecurity #DataTheft #Extortion #ICS #InfoSec #Java #Manufacturing #OTX #OpenThreatExchange #Password #Passwords #RAT #SSL #Word #bot #AlienVault

  9. Clop Returns with Custom Implant in Mass-Extortion Campaign

    The Clop threat group has returned to mass exploitation tactics by leveraging CVE-2026-12569 in PTC Windchill, deploying a sophisticated custom web shell designed specifically for data theft and extortion. This purpose-built implant provides immediate full data-theft capability without requiring additional tooling, featuring built-in credential harvesting, database enumeration, and a custom Java class loader for executing arbitrary code in memory. The web shell decrypts credentials from Windchill's keystore, including LDAP manager passwords that could enable enterprise-wide compromise. Its application-specific design allows malicious activity to blend seamlessly with legitimate traffic, making detection significantly more challenging. The implant targets sensitive intellectual property and engineering data stored in Windchill installations across manufacturing enterprises globally.

    Pulse ID: 6a85530dde3c55da4658c63b
    Pulse Link: otx.alienvault.com/pulse/6a855
    Pulse Author: AlienVault
    Created: 2026-08-19 06:54:05

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CredentialHarvesting #CyberSecurity #DataTheft #Extortion #ICS #InfoSec #Java #Manufacturing #OTX #OpenThreatExchange #Password #Passwords #RAT #SSL #Word #bot #AlienVault

  10. Clop Returns with Custom Implant in Mass-Extortion Campaign

    The Clop threat group has returned to mass exploitation tactics by leveraging CVE-2026-12569 in PTC Windchill, deploying a sophisticated custom web shell designed specifically for data theft and extortion. This purpose-built implant provides immediate full data-theft capability without requiring additional tooling, featuring built-in credential harvesting, database enumeration, and a custom Java class loader for executing arbitrary code in memory. The web shell decrypts credentials from Windchill's keystore, including LDAP manager passwords that could enable enterprise-wide compromise. Its application-specific design allows malicious activity to blend seamlessly with legitimate traffic, making detection significantly more challenging. The implant targets sensitive intellectual property and engineering data stored in Windchill installations across manufacturing enterprises globally.

    Pulse ID: 6a85530dde3c55da4658c63b
    Pulse Link: otx.alienvault.com/pulse/6a855
    Pulse Author: AlienVault
    Created: 2026-08-19 06:54:05

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CredentialHarvesting #CyberSecurity #DataTheft #Extortion #ICS #InfoSec #Java #Manufacturing #OTX #OpenThreatExchange #Password #Passwords #RAT #SSL #Word #bot #AlienVault

  11. C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2

    In July 2026, a new Rust-based malware family called C2Looper was identified, likely used by ransomware-related threat actors. The malware is assessed with low to medium confidence to be delivered through multi-stage ClickFix infection chains. C2Looper provides backdoor capabilities including remote shell execution, reconnaissance, and deploying additional payloads. It dynamically resolves Windows APIs and encrypts strings using XOR operations. The malware communicates via plaintext HTTP initially, but an evolved version uses GitHub repositories for command-and-control operations, storing commands and exfiltrated data in JSON files. Version 2 introduces additional commands such as reconnaissance collection, drive enumeration, shellcode injection, and file listing. The malware demonstrates active development with refined capabilities, likely serving initial access brokers for data theft and ransomware deployment.

    Pulse ID: 6a8322da43ee19a9f60899af
    Pulse Link: otx.alienvault.com/pulse/6a832
    Pulse Author: AlienVault
    Created: 2026-08-17 15:03:54

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CodeInjection #CyberSecurity #DataTheft #GitHub #HTTP #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RansomWare #Rust #ShellCode #Windows #bot #AlienVault

  12. C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2

    In July 2026, a new Rust-based malware family called C2Looper was identified, likely used by ransomware-related threat actors. The malware is assessed with low to medium confidence to be delivered through multi-stage ClickFix infection chains. C2Looper provides backdoor capabilities including remote shell execution, reconnaissance, and deploying additional payloads. It dynamically resolves Windows APIs and encrypts strings using XOR operations. The malware communicates via plaintext HTTP initially, but an evolved version uses GitHub repositories for command-and-control operations, storing commands and exfiltrated data in JSON files. Version 2 introduces additional commands such as reconnaissance collection, drive enumeration, shellcode injection, and file listing. The malware demonstrates active development with refined capabilities, likely serving initial access brokers for data theft and ransomware deployment.

    Pulse ID: 6a8322da43ee19a9f60899af
    Pulse Link: otx.alienvault.com/pulse/6a832
    Pulse Author: AlienVault
    Created: 2026-08-17 15:03:54

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CodeInjection #CyberSecurity #DataTheft #GitHub #HTTP #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RansomWare #Rust #ShellCode #Windows #bot #AlienVault

  13. C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2

    In July 2026, a new Rust-based malware family called C2Looper was identified, likely used by ransomware-related threat actors. The malware is assessed with low to medium confidence to be delivered through multi-stage ClickFix infection chains. C2Looper provides backdoor capabilities including remote shell execution, reconnaissance, and deploying additional payloads. It dynamically resolves Windows APIs and encrypts strings using XOR operations. The malware communicates via plaintext HTTP initially, but an evolved version uses GitHub repositories for command-and-control operations, storing commands and exfiltrated data in JSON files. Version 2 introduces additional commands such as reconnaissance collection, drive enumeration, shellcode injection, and file listing. The malware demonstrates active development with refined capabilities, likely serving initial access brokers for data theft and ransomware deployment.

    Pulse ID: 6a8322da43ee19a9f60899af
    Pulse Link: otx.alienvault.com/pulse/6a832
    Pulse Author: AlienVault
    Created: 2026-08-17 15:03:54

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CodeInjection #CyberSecurity #DataTheft #GitHub #HTTP #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RansomWare #Rust #ShellCode #Windows #bot #AlienVault

  14. C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2

    In July 2026, a new Rust-based malware family called C2Looper was identified, likely used by ransomware-related threat actors. The malware is assessed with low to medium confidence to be delivered through multi-stage ClickFix infection chains. C2Looper provides backdoor capabilities including remote shell execution, reconnaissance, and deploying additional payloads. It dynamically resolves Windows APIs and encrypts strings using XOR operations. The malware communicates via plaintext HTTP initially, but an evolved version uses GitHub repositories for command-and-control operations, storing commands and exfiltrated data in JSON files. Version 2 introduces additional commands such as reconnaissance collection, drive enumeration, shellcode injection, and file listing. The malware demonstrates active development with refined capabilities, likely serving initial access brokers for data theft and ransomware deployment.

    Pulse ID: 6a8322da43ee19a9f60899af
    Pulse Link: otx.alienvault.com/pulse/6a832
    Pulse Author: AlienVault
    Created: 2026-08-17 15:03:54

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CodeInjection #CyberSecurity #DataTheft #GitHub #HTTP #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RansomWare #Rust #ShellCode #Windows #bot #AlienVault

  15. C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2

    In July 2026, a new Rust-based malware family called C2Looper was identified, likely used by ransomware-related threat actors. The malware is assessed with low to medium confidence to be delivered through multi-stage ClickFix infection chains. C2Looper provides backdoor capabilities including remote shell execution, reconnaissance, and deploying additional payloads. It dynamically resolves Windows APIs and encrypts strings using XOR operations. The malware communicates via plaintext HTTP initially, but an evolved version uses GitHub repositories for command-and-control operations, storing commands and exfiltrated data in JSON files. Version 2 introduces additional commands such as reconnaissance collection, drive enumeration, shellcode injection, and file listing. The malware demonstrates active development with refined capabilities, likely serving initial access brokers for data theft and ransomware deployment.

    Pulse ID: 6a8322da43ee19a9f60899af
    Pulse Link: otx.alienvault.com/pulse/6a832
    Pulse Author: AlienVault
    Created: 2026-08-17 15:03:54

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CodeInjection #CyberSecurity #DataTheft #GitHub #HTTP #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RansomWare #Rust #ShellCode #Windows #bot #AlienVault

  16. DATE: August 17, 2026 at 06:06PM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    Hack on #Medical Software Firm Hits Half of #Poland's Population: 19M Patients Affected by #DataTheft Including National ID Numbers t.co/rJ2D1JKoYF

    Here are any URLs found in the article text:

    t.co/rJ2D1JKoYF

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  17. DATE: August 17, 2026 at 06:06PM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    Hack on #Medical Software Firm Hits Half of #Poland's Population: 19M Patients Affected by #DataTheft Including National ID Numbers t.co/rJ2D1JKoYF

    Here are any URLs found in the article text:

    t.co/rJ2D1JKoYF

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  18. DATE: August 17, 2026 at 06:06PM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    Hack on #Medical Software Firm Hits Half of #Poland's Population: 19M Patients Affected by #DataTheft Including National ID Numbers t.co/rJ2D1JKoYF

    Here are any URLs found in the article text:

    t.co/rJ2D1JKoYF

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  19. DATE: August 17, 2026 at 06:06PM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    Hack on #Medical Software Firm Hits Half of #Poland's Population: 19M Patients Affected by #DataTheft Including National ID Numbers t.co/rJ2D1JKoYF

    Here are any URLs found in the article text:

    t.co/rJ2D1JKoYF

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  20. Phantom Stealer Malware Uses Steganography and Process Injection to Data Theft

    Phantom Stealer is a .NET based information-stealing malware that uses
    PNG steganography, PowerShell-based process injection and defense evasion techniques to steal browser credentials, cryptocurrency wallets, cookies and sensitive files. The malware also uses clipboard manipulation to redirect cryptocurrency transactions and employs multiple techniques to avoid detection.

    Pulse ID: 6a82666881d78521845bd0af
    Pulse Link: otx.alienvault.com/pulse/6a826
    Pulse Author: cryptocti
    Created: 2026-08-17 01:39:52

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Clipboard #Cookies #CyberSecurity #DataTheft #InfoSec #Malware #NET #OTX #OpenThreatExchange #PowerShell #Steganography #bot #cryptocurrency #cryptocti

  21. Phantom Stealer Malware Uses Steganography and Process Injection to Data Theft

    Phantom Stealer is a .NET based information-stealing malware that uses
    PNG steganography, PowerShell-based process injection and defense evasion techniques to steal browser credentials, cryptocurrency wallets, cookies and sensitive files. The malware also uses clipboard manipulation to redirect cryptocurrency transactions and employs multiple techniques to avoid detection.

    Pulse ID: 6a82666881d78521845bd0af
    Pulse Link: otx.alienvault.com/pulse/6a826
    Pulse Author: cryptocti
    Created: 2026-08-17 01:39:52

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Clipboard #Cookies #CyberSecurity #DataTheft #InfoSec #Malware #NET #OTX #OpenThreatExchange #PowerShell #Steganography #bot #cryptocurrency #cryptocti

  22. Phantom Stealer Malware Uses Steganography and Process Injection to Data Theft

    Phantom Stealer is a .NET based information-stealing malware that uses
    PNG steganography, PowerShell-based process injection and defense evasion techniques to steal browser credentials, cryptocurrency wallets, cookies and sensitive files. The malware also uses clipboard manipulation to redirect cryptocurrency transactions and employs multiple techniques to avoid detection.

    Pulse ID: 6a82666881d78521845bd0af
    Pulse Link: otx.alienvault.com/pulse/6a826
    Pulse Author: cryptocti
    Created: 2026-08-17 01:39:52

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Clipboard #Cookies #CyberSecurity #DataTheft #InfoSec #Malware #NET #OTX #OpenThreatExchange #PowerShell #Steganography #bot #cryptocurrency #cryptocti

  23. Phantom Stealer Malware Uses Steganography and Process Injection to Data Theft

    Phantom Stealer is a .NET based information-stealing malware that uses
    PNG steganography, PowerShell-based process injection and defense evasion techniques to steal browser credentials, cryptocurrency wallets, cookies and sensitive files. The malware also uses clipboard manipulation to redirect cryptocurrency transactions and employs multiple techniques to avoid detection.

    Pulse ID: 6a82666881d78521845bd0af
    Pulse Link: otx.alienvault.com/pulse/6a826
    Pulse Author: cryptocti
    Created: 2026-08-17 01:39:52

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Clipboard #Cookies #CyberSecurity #DataTheft #InfoSec #Malware #NET #OTX #OpenThreatExchange #PowerShell #Steganography #bot #cryptocurrency #cryptocti

  24. Phantom Stealer Malware Uses Steganography and Process Injection to Data Theft

    Phantom Stealer is a .NET based information-stealing malware that uses
    PNG steganography, PowerShell-based process injection and defense evasion techniques to steal browser credentials, cryptocurrency wallets, cookies and sensitive files. The malware also uses clipboard manipulation to redirect cryptocurrency transactions and employs multiple techniques to avoid detection.

    Pulse ID: 6a82666881d78521845bd0af
    Pulse Link: otx.alienvault.com/pulse/6a826
    Pulse Author: cryptocti
    Created: 2026-08-17 01:39:52

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Clipboard #Cookies #CyberSecurity #DataTheft #InfoSec #Malware #NET #OTX #OpenThreatExchange #PowerShell #Steganography #bot #cryptocurrency #cryptocti

  25. AmnesiaStealer malware is targeting macOS users through fake GitHub pages, tricking them into running malicious Terminal commands that lead to data theft. Users should verify download sources and exercise caution to protect their systems.

    #AmnesiaStealer #macOS #CyberSecurity #Malware #GitHub #DataTheft

    thedailytechfeed.com/amnesiast

  26. South Korea, US warn of Gunra ransomware targeting healthcare, finance and critical infrastructure

    South Korean police and US cybersecurity agencies have issued a joint warning over Gunra ransomware, which has evolved…
    #EuropeSays #Korea #KR #cyberdefence #cybersecurity #datatheft #FBI #Gunraransomware #Korean #NSA #ransomware-as-a-service #SouthKorea
    europesays.com/korea/115374/

  27. Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments

    UNC6671 continues conducting data theft extortion operations despite the alleged retirement of the BlackFile brand in May 2026. The threat actor has diversified across multiple extortion fronts including Redact, Pink, Helix, and Falcon. They employ voice phishing tactics, posing as IT helpdesk staff to contact employees on personal mobile devices, directing them to spoofed login portals with Adversary-in-the-Middle infrastructure that intercepts credentials and multi-factor authentication tokens. Once access is established, automated scripts exfiltrate data from enterprise cloud environments including Microsoft 365 and Okta. Infrastructure analysis reveals shared phishing panels, overlapping victim targeting, and connected domains across all brands. Recent targeting has evolved toward financial services, private equity, legal, and professional services sectors. Between January and May 2026, Bitcoin wallet analysis showed approximately $10.69 million USD in ransom payments, with demands typically ranging fr...

    Pulse ID: 6a75078f7b8e057bc29b8769
    Pulse Link: otx.alienvault.com/pulse/6a750
    Pulse Author: AlienVault
    Created: 2026-08-06 22:15:43

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #BitCoin #Cloud #CyberSecurity #DataTheft #Extortion #ICS #InfoSec #Microsoft #OTX #OpenThreatExchange #Phishing #RAT #RCE #bot #AlienVault

  28. Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments

    UNC6671 continues conducting data theft extortion operations despite the alleged retirement of the BlackFile brand in May 2026. The threat actor has diversified across multiple extortion fronts including Redact, Pink, Helix, and Falcon. They employ voice phishing tactics, posing as IT helpdesk staff to contact employees on personal mobile devices, directing them to spoofed login portals with Adversary-in-the-Middle infrastructure that intercepts credentials and multi-factor authentication tokens. Once access is established, automated scripts exfiltrate data from enterprise cloud environments including Microsoft 365 and Okta. Infrastructure analysis reveals shared phishing panels, overlapping victim targeting, and connected domains across all brands. Recent targeting has evolved toward financial services, private equity, legal, and professional services sectors. Between January and May 2026, Bitcoin wallet analysis showed approximately $10.69 million USD in ransom payments, with demands typically ranging fr...

    Pulse ID: 6a75078f7b8e057bc29b8769
    Pulse Link: otx.alienvault.com/pulse/6a750
    Pulse Author: AlienVault
    Created: 2026-08-06 22:15:43

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #BitCoin #Cloud #CyberSecurity #DataTheft #Extortion #ICS #InfoSec #Microsoft #OTX #OpenThreatExchange #Phishing #RAT #RCE #bot #AlienVault

  29. Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments

    UNC6671 continues conducting data theft extortion operations despite the alleged retirement of the BlackFile brand in May 2026. The threat actor has diversified across multiple extortion fronts including Redact, Pink, Helix, and Falcon. They employ voice phishing tactics, posing as IT helpdesk staff to contact employees on personal mobile devices, directing them to spoofed login portals with Adversary-in-the-Middle infrastructure that intercepts credentials and multi-factor authentication tokens. Once access is established, automated scripts exfiltrate data from enterprise cloud environments including Microsoft 365 and Okta. Infrastructure analysis reveals shared phishing panels, overlapping victim targeting, and connected domains across all brands. Recent targeting has evolved toward financial services, private equity, legal, and professional services sectors. Between January and May 2026, Bitcoin wallet analysis showed approximately $10.69 million USD in ransom payments, with demands typically ranging fr...

    Pulse ID: 6a75078f7b8e057bc29b8769
    Pulse Link: otx.alienvault.com/pulse/6a750
    Pulse Author: AlienVault
    Created: 2026-08-06 22:15:43

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #BitCoin #Cloud #CyberSecurity #DataTheft #Extortion #ICS #InfoSec #Microsoft #OTX #OpenThreatExchange #Phishing #RAT #RCE #bot #AlienVault

  30. Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments

    UNC6671 continues conducting data theft extortion operations despite the alleged retirement of the BlackFile brand in May 2026. The threat actor has diversified across multiple extortion fronts including Redact, Pink, Helix, and Falcon. They employ voice phishing tactics, posing as IT helpdesk staff to contact employees on personal mobile devices, directing them to spoofed login portals with Adversary-in-the-Middle infrastructure that intercepts credentials and multi-factor authentication tokens. Once access is established, automated scripts exfiltrate data from enterprise cloud environments including Microsoft 365 and Okta. Infrastructure analysis reveals shared phishing panels, overlapping victim targeting, and connected domains across all brands. Recent targeting has evolved toward financial services, private equity, legal, and professional services sectors. Between January and May 2026, Bitcoin wallet analysis showed approximately $10.69 million USD in ransom payments, with demands typically ranging fr...

    Pulse ID: 6a75078f7b8e057bc29b8769
    Pulse Link: otx.alienvault.com/pulse/6a750
    Pulse Author: AlienVault
    Created: 2026-08-06 22:15:43

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #BitCoin #Cloud #CyberSecurity #DataTheft #Extortion #ICS #InfoSec #Microsoft #OTX #OpenThreatExchange #Phishing #RAT #RCE #bot #AlienVault

  31. Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments

    UNC6671 continues conducting data theft extortion operations despite the alleged retirement of the BlackFile brand in May 2026. The threat actor has diversified across multiple extortion fronts including Redact, Pink, Helix, and Falcon. They employ voice phishing tactics, posing as IT helpdesk staff to contact employees on personal mobile devices, directing them to spoofed login portals with Adversary-in-the-Middle infrastructure that intercepts credentials and multi-factor authentication tokens. Once access is established, automated scripts exfiltrate data from enterprise cloud environments including Microsoft 365 and Okta. Infrastructure analysis reveals shared phishing panels, overlapping victim targeting, and connected domains across all brands. Recent targeting has evolved toward financial services, private equity, legal, and professional services sectors. Between January and May 2026, Bitcoin wallet analysis showed approximately $10.69 million USD in ransom payments, with demands typically ranging fr...

    Pulse ID: 6a75078f7b8e057bc29b8769
    Pulse Link: otx.alienvault.com/pulse/6a750
    Pulse Author: AlienVault
    Created: 2026-08-06 22:15:43

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #BitCoin #Cloud #CyberSecurity #DataTheft #Extortion #ICS #InfoSec #Microsoft #OTX #OpenThreatExchange #Phishing #RAT #RCE #bot #AlienVault

  32. UNC6671 Automates Microsoft 365 Data Theft After Hijacking Employee Sessions

    Indicators extracted from public reporting. Source: cybersecuritynews.com/unc6671-

    Pulse ID: 6a75abf8c9b00b0de18d1947
    Pulse Link: otx.alienvault.com/pulse/6a75a
    Pulse Author: CyberHunter_NL
    Created: 2026-08-07 09:57:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DataTheft #HTTP #HTTPS #InfoSec #Microsoft #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  33. UNC6671 Automates Microsoft 365 Data Theft After Hijacking Employee Sessions

    Indicators extracted from public reporting. Source: cybersecuritynews.com/unc6671-

    Pulse ID: 6a75abf8c9b00b0de18d1947
    Pulse Link: otx.alienvault.com/pulse/6a75a
    Pulse Author: CyberHunter_NL
    Created: 2026-08-07 09:57:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DataTheft #HTTP #HTTPS #InfoSec #Microsoft #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  34. UNC6671 Automates Microsoft 365 Data Theft After Hijacking Employee Sessions

    Indicators extracted from public reporting. Source: cybersecuritynews.com/unc6671-

    Pulse ID: 6a75abf8c9b00b0de18d1947
    Pulse Link: otx.alienvault.com/pulse/6a75a
    Pulse Author: CyberHunter_NL
    Created: 2026-08-07 09:57:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DataTheft #HTTP #HTTPS #InfoSec #Microsoft #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  35. UNC6671 Automates Microsoft 365 Data Theft After Hijacking Employee Sessions

    Indicators extracted from public reporting. Source: cybersecuritynews.com/unc6671-

    Pulse ID: 6a75abf8c9b00b0de18d1947
    Pulse Link: otx.alienvault.com/pulse/6a75a
    Pulse Author: CyberHunter_NL
    Created: 2026-08-07 09:57:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DataTheft #HTTP #HTTPS #InfoSec #Microsoft #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  36. UNC6671 Automates Microsoft 365 Data Theft After Hijacking Employee Sessions

    Indicators extracted from public reporting. Source: cybersecuritynews.com/unc6671-

    Pulse ID: 6a75abf8c9b00b0de18d1947
    Pulse Link: otx.alienvault.com/pulse/6a75a
    Pulse Author: CyberHunter_NL
    Created: 2026-08-07 09:57:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DataTheft #HTTP #HTTPS #InfoSec #Microsoft #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  37. Cyberattack Targets Travelers' Data via Compromised Hotel Wi-Fi Networks

    📰 Original title: Russia-Linked 'Midnight Blizzard' Group Hijacks Hotel Wi-Fi With CaptiveCrunch

    🤖 IA: It's clickbait ⚠️
    👥 Users: It's clickbait ⚠️

    View full AI summary en.killbait.com/cyberattack-ta

    #technology #datatheft #networkattacks

  38. Cyberattack Targets Travelers' Data via Compromised Hotel Wi-Fi Networks

    📰 Original title: Russia-Linked 'Midnight Blizzard' Group Hijacks Hotel Wi-Fi With CaptiveCrunch

    🤖 IA: It's clickbait ⚠️
    👥 Users: It's clickbait ⚠️

    View full AI summary en.killbait.com/cyberattack-ta

    #technology #datatheft #networkattacks

  39. Cyberattack Targets Travelers' Data via Compromised Hotel Wi-Fi Networks

    📰 Original title: Russia-Linked 'Midnight Blizzard' Group Hijacks Hotel Wi-Fi With CaptiveCrunch

    🤖 IA: It's clickbait ⚠️
    👥 Users: It's clickbait ⚠️

    View full AI summary en.killbait.com/cyberattack-ta

    #technology #datatheft #networkattacks

  40. Cyberattack Targets Travelers' Data via Compromised Hotel Wi-Fi Networks

    📰 Original title: Russia-Linked 'Midnight Blizzard' Group Hijacks Hotel Wi-Fi With CaptiveCrunch

    🤖 IA: It's clickbait ⚠️
    👥 Users: It's clickbait ⚠️

    View full AI summary en.killbait.com/cyberattack-ta

    #technology #datatheft #networkattacks

  41. Cyberattack Targets Travelers' Data via Compromised Hotel Wi-Fi Networks

    📰 Original title: Russia-Linked 'Midnight Blizzard' Group Hijacks Hotel Wi-Fi With CaptiveCrunch

    🤖 IA: It's clickbait ⚠️
    👥 Users: It's clickbait ⚠️

    View full AI summary en.killbait.com/cyberattack-ta

    #technology #datatheft #networkattacks

  42. DATE: July 31, 2026 at 05:33PM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    #DentaQuest #DataTheft #Hack Affects 15M Patients:
    Number of Victims Is 5 Times Higher Than Claims by #ShinyHunters #Ransomware Gang
    t.co/IYHEq9giN6
    #HIPAA #databreach #sunlife

    Here are any URLs found in the article text:

    t.co/IYHEq9giN6

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  43. DATE: July 31, 2026 at 05:33PM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    #DentaQuest #DataTheft #Hack Affects 15M Patients:
    Number of Victims Is 5 Times Higher Than Claims by #ShinyHunters #Ransomware Gang
    t.co/IYHEq9giN6
    #HIPAA #databreach #sunlife

    Here are any URLs found in the article text:

    t.co/IYHEq9giN6

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  44. DATE: July 31, 2026 at 05:33PM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    #DentaQuest #DataTheft #Hack Affects 15M Patients:
    Number of Victims Is 5 Times Higher Than Claims by #ShinyHunters #Ransomware Gang
    t.co/IYHEq9giN6
    #HIPAA #databreach #sunlife

    Here are any URLs found in the article text:

    t.co/IYHEq9giN6

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  45. DATE: July 31, 2026 at 05:33PM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    #DentaQuest #DataTheft #Hack Affects 15M Patients:
    Number of Victims Is 5 Times Higher Than Claims by #ShinyHunters #Ransomware Gang
    t.co/IYHEq9giN6
    #HIPAA #databreach #sunlife

    Here are any URLs found in the article text:

    t.co/IYHEq9giN6

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  46. RE: vt.social/@lina/11697543585120

    I deleted my #GitHub account since @huggingface.co stole my code (15 repos) in 2025, and happily moved to @Codeberg

    Now I can’t opt-out. 🤦🏻‍♂️

    To everybody working for or using #HuggingFace: I do not consent to any use of my code for training, calibration, (partial) extrusion or whatever you want to call your bullshit theft and grifting.

    This means you effectively cannot use any part of this dataset for any means whatsoever, at least not without being a total arsehole.

    #Codeberg #DataTheft #LLM #AI

  47. RE: vt.social/@lina/11697543585120

    I deleted my #GitHub account since @huggingface.co stole my code (15 repos) in 2025, and happily moved to @Codeberg

    Now I can’t opt-out. 🤦🏻‍♂️

    To everybody working for or using #HuggingFace: I do not consent to any use of my code for training, calibration, (partial) extrusion or whatever you want to call your bullshit theft and grifting.

    This means you effectively cannot use any part of this dataset for any means whatsoever, at least not without being a total arsehole.

    #Codeberg #DataTheft #LLM #AI

  48. RE: vt.social/@lina/11697543585120

    I deleted my #GitHub account since @huggingface.co stole my code (15 repos) in 2025, and happily moved to @Codeberg

    Now I can’t opt-out. 🤦🏻‍♂️

    To everybody working for or using #HuggingFace: I do not consent to any use of my code for training, calibration, (partial) extrusion or whatever you want to call your bullshit theft and grifting.

    This means you effectively cannot use any part of this dataset for any means whatsoever, at least not without being a total arsehole.

    #Codeberg #DataTheft #LLM #AI

  49. RE: vt.social/@lina/11697543585120

    I deleted my #GitHub account since @huggingface.co stole my code (15 repos) in 2025, and happily moved to @Codeberg

    Now I can’t opt-out. 🤦🏻‍♂️

    To everybody working for or using #HuggingFace: I do not consent to any use of my code for training, calibration, (partial) extrusion or whatever you want to call your bullshit theft and grifting.

    This means you effectively cannot use any part of this dataset for any means whatsoever, at least not without being a total arsehole.

    #Codeberg #DataTheft #LLM #AI

  50. RE: vt.social/@lina/11697543585120

    I deleted my #GitHub account since @huggingface.co stole my code (15 repos) in 2025, and happily moved to @Codeberg

    Now I can’t opt-out. 🤦🏻‍♂️

    To everybody working for or using #HuggingFace: I do not consent to any use of my code for training, calibration, (partial) extrusion or whatever you want to call your bullshit theft and grifting.

    This means you effectively cannot use any part of this dataset for any means whatsoever, at least not without being a total arsehole.

    #Codeberg #DataTheft #LLM #AI