OSINT Updates for November 23 , 2024
https://twitter.com/CovertShores/status/1860215391114657830 https://twitter.com/bamitav/status/1860135386091045318 https://twitter.com/DailyRansomware/status/1860174991288881252 https://twitter.com/SriLankaTweet/status/1860150865379860564 https://twitter.com/hornbilltv/status/1860256208420225052 https://twitter.com/OmegaMagnusTV/status/1860266368110579929 https://twitter.com/rtehrani/status/1860158839179403382
Investigating a SharePoint Compromise: IR Tales from the Field
CategoryDetailsThreat ActorsUnnamed attacker exploiting SharePoint CVE-2024-38094.Campaign OverviewExploited SharePoint vulnerability (CVE-2024-38094) for initial access; compromised Exchange…
Royal Thai Police Database Breached, Claims Dark Web Actor
CategoryDetailsThreat ActorsDark web actor (identity unspecified).Campaign OverviewBreach of the PhpMyAdmin database of the Royal Thai…
T-Mobile Breached in Major Chinese Cyber-Attack on Telecoms
CategoryDetailsThreat ActorsSalt Typhoon (Chinese state-sponsored hacking group).Campaign OverviewLarge-scale cyber-espionage campaign targeting US and international telecom…
Exploring Rhysida Ransomware
CategoryDetailsThreat ActorsRhysida Ransomware group (possible connection to Vice Society Ransomware group).Campaign OverviewRhysida ransomware attacks targeted…
RansomHub Targets Mexican Government
CategoryDetailsThreat ActorsRansomHub, a likely Russian ransomware group with a history of global cyberattacks.Campaign OverviewRansomHub compromised…
UK drinking water supplies disrupted by record number of undisclosed cyber incidents
Category Details Threat Actors Not explicitly named; likely a mix of cybercriminals and nation-state actors…
OSINT Updates for November 22 , 2024
https://twitter.com/SecAI_AI/status/1859770564296225267 https://twitter.com/ClefTheHacker/status/1859892350392422731 https://twitter.com/FalconFeedsio/status/1859820207201714499 https://twitter.com/cyberfeeddigest/status/1859868387976806582 https://twitter.com/cyberfeeddigest/status/1859876230989857234 https://twitter.com/DailyRansomware/status/1859872936619802914 https://twitter.com/jamessecuritytr/status/1859854138881999316 https://twitter.com/DailyRansomware/status/1859845914887704755
China-linked hackers target Linux systems with new spying malware
CategoryDetailsThreat ActorsGelsemium (China-linked state-sponsored threat actor).Campaign OverviewEspionage campaign targeting Linux systems, deploying malware strains WolfsBane…
Threat Brief: Operation Lunar Peek, Activity Related to CVE-2024-0012 and CVE-2024-9474 (Updated Nov. 22)
CategoryDetailsThreat ActorsUnnamed actors exploiting CVE-2024-0012 and CVE-2024-9474; activity includes manual/automated scans, web shells, and C2…