#initialaccessbroker — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #initialaccessbroker, aggregated by home.social.
-
Email bombing, finto IT support e un’estensione Edge che evade la sandbox: la tradecraft di UNC6692
eSentire TRU ricostruisce la catena d'attacco dell'initial access broker UNC6692: email bombing, impersonificazione IT su Microsoft Teams, Quick Assist e l'estensione malevola Edgecution, capace di evadere la sandbox del browser per conto della syndicate ransomware Payouts King. -
Email bombing, finto IT support e un’estensione Edge che evade la sandbox: la tradecraft di UNC6692
eSentire TRU ricostruisce la catena d'attacco dell'initial access broker UNC6692: email bombing, impersonificazione IT su Microsoft Teams, Quick Assist e l'estensione malevola Edgecution, capace di evadere la sandbox del browser per conto della syndicate ransomware Payouts King. -
KongTuke Hackers Exploit Microsoft Teams for Rapid Corporate Breaches
KongTuke hackers have found a lightning-fast way to breach corporations, exploiting Microsoft Teams to go from initial contact to persistent foothold in under five minutes. This alarming new tactic is part of KongTuke's evolving social engineering toolkit, complementing its previous web-based attacks.
#MicrosoftTeams #Kongtuke #SocialEngineering #InitialAccessBroker #EmergingThreats
-
Phishing Campaign Exploits Legitimate RMM Tools to Hit 80+ Orgs
A sneaky phishing campaign has infiltrated over 80 organizations, mostly in the US, by exploiting legitimate remote monitoring and management (RMM) tools like SimpleHelp and ScreenConnect. The attackers cleverly used customized versions of these tools, already installed by the victims, to bypass defenses and…
#RemoteMonitoringAndManagement #PhishingCampaign #InitialAccessBroker #Ransomware #Venomoushelper
-
📬 Ransomware-Epidemie: Warum herkömmlicher Schutz versagt und Cyber-Resilienz zur Überlebensfrage wird
#Empfehlungen #Gastartikel #CyberResilienz #Domänencontroller #InitialAccessBroker #LateralMovement #PatchManagement #RansomwareEpidemie #Zugriffsanfrage https://sc.tarnkappe.info/da9594 -
📬 Ransomware-Epidemie: Warum herkömmlicher Schutz versagt und Cyber-Resilienz zur Überlebensfrage wird
#Empfehlungen #Gastartikel #CyberResilienz #Domänencontroller #InitialAccessBroker #LateralMovement #PatchManagement #RansomwareEpidemie #Zugriffsanfrage https://sc.tarnkappe.info/da9594 -
A recent guilty plea provides a detailed look at the role of initial access brokers in modern cybercrime operations.
Court documents describe how network access was sold via exploited perimeter systems and paired with malware capable of disabling endpoint defenses. Investigators tied the activity to broader criminal impact over time.
Key defensive implications:
• Initial access often precedes major incidents by months
• Brokered access accelerates follow-on attacks
• Patch management and exposure monitoring remain criticalHow are teams adjusting controls to disrupt early-stage access brokers?
Source: https://therecord.media/guilty-plea-initial-access-broker-r1z
Engage with the discussion and follow TechNadu for objective InfoSec coverage.
#InfoSec #ThreatIntel #InitialAccessBroker #EDR #NetworkSecurity #CyberDefense #TechNadu
-
Imagine someone selling hacked access like real estate—unwitting gateways to ransomware attacks worth millions. The Volkov case lifts the veil on this shadowy cyber trade. Curious how it all unfolds?
#initialaccessbroker
#ransomware
#cybercrime
#volkovcase
#yanluowang
#lockbit
#cryptocurrency
#cybersecuritytrends
#lawenforcement -
Imagine someone selling hacked access like real estate—unwitting gateways to ransomware attacks worth millions. The Volkov case lifts the veil on this shadowy cyber trade. Curious how it all unfolds?
#initialaccessbroker
#ransomware
#cybercrime
#volkovcase
#yanluowang
#lockbit
#cryptocurrency
#cybersecuritytrends
#lawenforcement -
ESXi Root and Domain Admin Access to Vietnamese Private Company Allegedly for Sale https://dailydarkweb.net/esxi-root-and-domain-admin-access-to-vietnamese-private-company-allegedly-for-sale/ #UnauthorizedAccesses #InitialAccessBroker #activedirectory #PrivateCompany #cyberattack #databreach #Vietnam #ESXi
-
ESXi Root and Domain Admin Access to Vietnamese Private Company Allegedly for Sale https://dailydarkweb.net/esxi-root-and-domain-admin-access-to-vietnamese-private-company-allegedly-for-sale/ #UnauthorizedAccesses #InitialAccessBroker #activedirectory #PrivateCompany #cyberattack #databreach #Vietnam #ESXi
-
Nike USA Allegedly Compromised – Initial Network Access Offered for $5,000 https://dailydarkweb.net/nike-usa-allegedly-compromised-initial-network-access-offered-for-5000/ #UnauthorizedAccesses #InitialAccessBroker #CyberSecurity #cyber-attack #databreach #darkweb #exploit #shell #Nike #IAB #USA
-
Nike USA Allegedly Compromised – Initial Network Access Offered for $5,000 https://dailydarkweb.net/nike-usa-allegedly-compromised-initial-network-access-offered-for-5000/ #UnauthorizedAccesses #InitialAccessBroker #CyberSecurity #cyber-attack #databreach #darkweb #exploit #shell #Nike #IAB #USA
-
A user of DarkForums is selling an initial access to a Finnish video gaming company.
Access Type: SMB
OS: Windows
Revenue: 27.5 Million $
Price: 1,1k (XMR) -
A user of DarkForums is selling an initial access to a Finnish video gaming company.
Access Type: SMB
OS: Windows
Revenue: 27.5 Million $
Price: 1,1k (XMR) -
Major Argentinian Telecom Giant Allegedly Breached – Attacker Sells Network Access https://dailydarkweb.net/major-argentinian-telecom-giant-allegedly-breached-attacker-sells-network-access/ #UnauthorizedAccesses #InitialAccessBroker #cyberattack #databreach #Argentina #darkweb #Telecom #IAB
-
Major Argentinian Telecom Giant Allegedly Breached – Attacker Sells Network Access https://dailydarkweb.net/major-argentinian-telecom-giant-allegedly-breached-attacker-sells-network-access/ #UnauthorizedAccesses #InitialAccessBroker #cyberattack #databreach #Argentina #darkweb #Telecom #IAB
-
Network Access to Major $400M+ Indian Corporation Allegedly for Sale https://dailydarkweb.net/network-access-to-major-400m-indian-corporation-allegedly-for-sale/ #UnauthorizedAccesses #InitialAccessBroker #CyberSecurity #cyberattack #darkweb #India #RDP #VPN
-
Network Access to Major $400M+ Indian Corporation Allegedly for Sale https://dailydarkweb.net/network-access-to-major-400m-indian-corporation-allegedly-for-sale/ #UnauthorizedAccesses #InitialAccessBroker #CyberSecurity #cyberattack #darkweb #India #RDP #VPN
-
Trojanized KeePass opens doors for ransomware attackers https://www.helpnetsecurity.com/2025/05/20/trojanized-keepass-keeloader-ransomware/ #initialaccessbroker #typosquatting #malvertising #opensource #ransomware #WithSecure #Don'tmiss #Hotstuff #KeePass #malware #News
-
Trojanized KeePass opens doors for ransomware attackers https://www.helpnetsecurity.com/2025/05/20/trojanized-keepass-keeloader-ransomware/ #initialaccessbroker #typosquatting #malvertising #opensource #ransomware #WithSecure #Don'tmiss #Hotstuff #KeePass #malware #News
-
SAP NetWeaver zero-day allegedly exploited by an initial access broker – Source: securityaffairs.com https://ciso2ciso.com/sap-netweaver-zero-day-allegedly-exploited-by-an-initial-access-broker-source-securityaffairs-com/ #rssfeedpostgeneratorecho #informationsecuritynews #ITInformationSecurity #InitialAccessBroker #SecurityAffairscom #CyberSecurityNews #PierluigiPaganini #SecurityAffairs #SecurityAffairs #CVE-2025-31324 #BreakingNews #SAPNetweaver #SecurityNews #hackingnews #hacking #zeroday
-
SAP NetWeaver zero-day allegedly exploited by an initial access broker – Source: securityaffairs.com https://ciso2ciso.com/sap-netweaver-zero-day-allegedly-exploited-by-an-initial-access-broker-source-securityaffairs-com/ #rssfeedpostgeneratorecho #informationsecuritynews #ITInformationSecurity #InitialAccessBroker #SecurityAffairscom #CyberSecurityNews #PierluigiPaganini #SecurityAffairs #SecurityAffairs #CVE-2025-31324 #BreakingNews #SAPNetweaver #SecurityNews #hackingnews #hacking #zeroday
-
ToyMaker Activity Detection: Initial Access Brokers Compromise Hosts in Critical Infrastructure Organizations via SSH and File Transfer Utilities – Source: socprime.com https://ciso2ciso.com/toymaker-activity-detection-initial-access-brokers-compromise-hosts-in-critical-infrastructure-organizations-via-ssh-and-file-transfer-utilities-source-socprime-com/ #rssfeedpostgeneratorecho #InitialAccessBroker #CyberSecurityNews #Cactusransomware #Latestthreats #socprimecom #socprime #ToyMaker #LAGTOY
-
ToyMaker Activity Detection: Initial Access Brokers Compromise Hosts in Critical Infrastructure Organizations via SSH and File Transfer Utilities – Source: socprime.com https://ciso2ciso.com/toymaker-activity-detection-initial-access-brokers-compromise-hosts-in-critical-infrastructure-organizations-via-ssh-and-file-transfer-utilities-source-socprime-com/ #rssfeedpostgeneratorecho #InitialAccessBroker #CyberSecurityNews #Cactusransomware #Latestthreats #socprimecom #socprime #ToyMaker #LAGTOY
-
SAP Zero-Day Possibly Exploited by Initial Access Broker https://www.securityweek.com/sap-zero-day-possibly-exploited-by-initial-access-broker/ #initialaccessbroker #Vulnerabilities #exploited #Featured #ZeroDay #SAP
-
SAP Zero-Day Possibly Exploited by Initial Access Broker https://www.securityweek.com/sap-zero-day-possibly-exploited-by-initial-access-broker/ #initialaccessbroker #Vulnerabilities #exploited #Featured #ZeroDay #SAP
-
SAP Zero-Day Possibly Exploited by Initial Access Broker https://www.securityweek.com/sap-zero-day-possibly-exploited-by-initial-access-broker/ #initialaccessbroker #Vulnerabilities #exploited #Featured #ZeroDay #SAP
-
SAP Zero-Day Possibly Exploited by Initial Access Broker https://www.securityweek.com/sap-zero-day-possibly-exploited-by-initial-access-broker/ #initialaccessbroker #Vulnerabilities #exploited #Featured #ZeroDay #SAP
-
North Korean hackers pave the way for Play ransomware https://www.helpnetsecurity.com/2024/10/31/north-korean-hackers-play-ransomware/ #initialaccessbroker #PaloAltoNetworks #enterprise #NorthKorea #ransomware #Don'tmiss #Hotstuff #News
-
North Korean hackers pave the way for Play ransomware https://www.helpnetsecurity.com/2024/10/31/north-korean-hackers-play-ransomware/ #initialaccessbroker #PaloAltoNetworks #enterprise #NorthKorea #ransomware #Don'tmiss #Hotstuff #News
-
Zscaler swats claims of a significant breach https://www.helpnetsecurity.com/2024/05/09/zscaler-access-for-sale/ #initialaccessbroker #databreach #Don'tmiss #Hotstuff #Zscaler #News
-
Zscaler swats claims of a significant breach https://www.helpnetsecurity.com/2024/05/09/zscaler-access-for-sale/ #initialaccessbroker #databreach #Don'tmiss #Hotstuff #Zscaler #News
-
New Latrodectus loader steps in for Qbot https://www.helpnetsecurity.com/2024/04/09/latrodectus-initial-access/ #initialaccessbroker #Proofpoint #Don'tmiss #TeamCymru #Hotstuff #malware #News
-
New Latrodectus loader steps in for Qbot https://www.helpnetsecurity.com/2024/04/09/latrodectus-initial-access/ #initialaccessbroker #Proofpoint #Don'tmiss #TeamCymru #Hotstuff #malware #News
-
Hundreds of orgs targeted with emails aimed at stealing NTLM authentication hashes https://www.helpnetsecurity.com/2024/03/05/steals-ntlm-hashes-email/ #initialaccessbroker #authentication #Proofpoint #Don'tmiss #Hotstuff #phishing #Varonis #Windows #News
-
Découvrez le rôle des "Initial Access Brokers", ces courtiers de l'ombre qui vendent des accès illégaux à des systèmes informatiques, à l'instar d'agents immobiliers vendant des propriétés, mais dans la cybercriminalité. 🕵️♂️ Ces intermédiaires facilitent les cyberattaques en réduisant le travail des hackers, rendant la prévention et la détection des menaces plus cruciales que jamais pour les entreprises. 🛡️ #Cybersécurité #InitialAccessBroker #Cybermenaces
https://www.lemagit.fr/conseil/Cybercriminalite-quest-ce-quun-courtier-en-acces-initial -
Découvrez le rôle des "Initial Access Brokers", ces courtiers de l'ombre qui vendent des accès illégaux à des systèmes informatiques, à l'instar d'agents immobiliers vendant des propriétés, mais dans la cybercriminalité. 🕵️♂️ Ces intermédiaires facilitent les cyberattaques en réduisant le travail des hackers, rendant la prévention et la détection des menaces plus cruciales que jamais pour les entreprises. 🛡️ #Cybersécurité #InitialAccessBroker #Cybermenaces
https://www.lemagit.fr/conseil/Cybercriminalite-quest-ce-quun-courtier-en-acces-initial -
The cyber crims are working through the holidays, and so are we. Here's Monday's newsletter on all the developments in infosec, just for you:
https://opalsec.substack.com/p/soc-goulash-weekend-wrap-up-744?sd=pf
International law enforcement agencies notched up another win last week, having successfully taken down the notorious Initial Access Broker Genesis Marketplace last week - or did they? The site remains active and the admins appear to have gotten away unscathed, so what victory was there to be had?
#Microsoft, in collaboration with #Fortra and the Health ISAC, are commencing work to dismantle infrastructure used by actors abusing cracked versions of the offensive Cobalt Strike framework. It'll be an uphill battle, and it remains to be seen if they can make a dent in the sprawling global footprint achieved by the cyber crim's implant of choice.
Be warned - a PoC exploit has been released for a CVSS 10.0 Sandbox Escape vulnerability impacting the VM2 JavaScript Sandbox, which itself has >16 million monthly downloads on #npm. Researchers have also uncovered a vulnerability in #WiFi APs that could allow hijacking and snooping of client traffic; #Apple patches two actively exploited 0-days in #iOS, #iPadOS and #macOS, and #CISA urges patching of #Zimbra bugs exploited by Russian APTs.
The #redteam have some great tooling and tradecraft to help with Microsoft #MFA enumeration and performing port forwarding on compromised #Cisco gear, while the #blueteam are again spoiled for choice - a new database of exploited drivers, research on abuse of SFX archives for persistence, and threat models for #AWS KMS and CI/CD pipelines - take your pick!
Check out the newsletter and catch all this and much more excellent threat and tradecraft research, to help you gear up for the week ahead:
https://opalsec.substack.com/p/soc-goulash-weekend-wrap-up-744?sd=pf
Happy Easter Monday to everyone lucky enough to be enjoying the holiday, I hope you're all having a great break wherever you are, and a reminder that if you're travelling on the roads, to please drive safe!
#infosec #cyber #news #cybernews #infosec #infosecnews #informationsecurity #cybersecurity #newsletter #hacking #security #technology #hacker #vulnerability #vulnerabilities #exploit #PoC #malware #ransomware #dfir #soc #threatintel #threatintelligence #DarkWeb #CobaltStrike #IAB #InitialAccessBroker #GenesisMarketplace
-
The cyber crims are working through the holidays, and so are we. Here's Monday's newsletter on all the developments in infosec, just for you:
https://opalsec.substack.com/p/soc-goulash-weekend-wrap-up-744?sd=pf
International law enforcement agencies notched up another win last week, having successfully taken down the notorious Initial Access Broker Genesis Marketplace last week - or did they? The site remains active and the admins appear to have gotten away unscathed, so what victory was there to be had?
#Microsoft, in collaboration with #Fortra and the Health ISAC, are commencing work to dismantle infrastructure used by actors abusing cracked versions of the offensive Cobalt Strike framework. It'll be an uphill battle, and it remains to be seen if they can make a dent in the sprawling global footprint achieved by the cyber crim's implant of choice.
Be warned - a PoC exploit has been released for a CVSS 10.0 Sandbox Escape vulnerability impacting the VM2 JavaScript Sandbox, which itself has >16 million monthly downloads on #npm. Researchers have also uncovered a vulnerability in #WiFi APs that could allow hijacking and snooping of client traffic; #Apple patches two actively exploited 0-days in #iOS, #iPadOS and #macOS, and #CISA urges patching of #Zimbra bugs exploited by Russian APTs.
The #redteam have some great tooling and tradecraft to help with Microsoft #MFA enumeration and performing port forwarding on compromised #Cisco gear, while the #blueteam are again spoiled for choice - a new database of exploited drivers, research on abuse of SFX archives for persistence, and threat models for #AWS KMS and CI/CD pipelines - take your pick!
Check out the newsletter and catch all this and much more excellent threat and tradecraft research, to help you gear up for the week ahead:
https://opalsec.substack.com/p/soc-goulash-weekend-wrap-up-744?sd=pf
Happy Easter Monday to everyone lucky enough to be enjoying the holiday, I hope you're all having a great break wherever you are, and a reminder that if you're travelling on the roads, to please drive safe!
#infosec #cyber #news #cybernews #infosec #infosecnews #informationsecurity #cybersecurity #newsletter #hacking #security #technology #hacker #vulnerability #vulnerabilities #exploit #PoC #malware #ransomware #dfir #soc #threatintel #threatintelligence #DarkWeb #CobaltStrike #IAB #InitialAccessBroker #GenesisMarketplace
-
Ares group selling access to the Mexican police system. Advertised capabilities are identifying and tracking gang members.
#CyberCrime #IAB #InitialAccessBroker #Gangcrime #InfoSec #Mexico
-
Ares group selling access to the Mexican police system. Advertised capabilities are identifying and tracking gang members.
#CyberCrime #IAB #InitialAccessBroker #Gangcrime #InfoSec #Mexico
-
Who is the Network Access Broker ‘Wazawaka?’ https://krebsonsecurity.com/2022/01/who-is-the-network-access-broker-wazawaka/ #ConstellaIntelligence #devdelphi@yandex.ru #initialaccessbroker #Ne'er-Do-WellNews #MikhailMixMatveev #mix@devilart.net #mixfb@yandex.ru #Uhodiransomware #MikhailMatveev #cs-arena.org #Breadcrumbs #domaintools #Ransomware #Flashpoint #ransomware #ddosis.ru #Kopyovo-a #DarkSide #Wazawaka #LockBit #902228 #Abakan #Abaza