OSINT Updates for November 23 , 2024

https://twitter.com/CovertShores/status/1860215391114657830 https://twitter.com/bamitav/status/1860135386091045318 https://twitter.com/DailyRansomware/status/1860174991288881252 https://twitter.com/SriLankaTweet/status/1860150865379860564 https://twitter.com/hornbilltv/status/1860256208420225052 https://twitter.com/OmegaMagnusTV/status/1860266368110579929 https://twitter.com/rtehrani/status/1860158839179403382

Investigating a SharePoint Compromise: IR Tales from the Field

CategoryDetailsThreat ActorsUnnamed attacker exploiting SharePoint CVE-2024-38094.Campaign OverviewExploited SharePoint vulnerability (CVE-2024-38094) for initial access; compromised Exchange…

Royal Thai Police Database Breached, Claims Dark Web Actor

CategoryDetailsThreat ActorsDark web actor (identity unspecified).Campaign OverviewBreach of the PhpMyAdmin database of the Royal Thai…

T-Mobile Breached in Major Chinese Cyber-Attack on Telecoms

CategoryDetailsThreat ActorsSalt Typhoon (Chinese state-sponsored hacking group).Campaign OverviewLarge-scale cyber-espionage campaign targeting US and international telecom…

Exploring Rhysida Ransomware

CategoryDetailsThreat ActorsRhysida Ransomware group (possible connection to Vice Society Ransomware group).Campaign OverviewRhysida ransomware attacks targeted…

RansomHub Targets Mexican Government

CategoryDetailsThreat ActorsRansomHub, a likely Russian ransomware group with a history of global cyberattacks.Campaign OverviewRansomHub compromised…

  • APT
  • November 22, 2024
UK drinking water supplies disrupted by record number of undisclosed cyber incidents

Category Details Threat Actors Not explicitly named; likely a mix of cybercriminals and nation-state actors…

OSINT Updates for November 22 , 2024

https://twitter.com/SecAI_AI/status/1859770564296225267 https://twitter.com/ClefTheHacker/status/1859892350392422731 https://twitter.com/FalconFeedsio/status/1859820207201714499 https://twitter.com/cyberfeeddigest/status/1859868387976806582 https://twitter.com/cyberfeeddigest/status/1859876230989857234 https://twitter.com/DailyRansomware/status/1859872936619802914 https://twitter.com/jamessecuritytr/status/1859854138881999316 https://twitter.com/DailyRansomware/status/1859845914887704755

  • APT
  • November 22, 2024
China-linked hackers target Linux systems with new spying malware

CategoryDetailsThreat ActorsGelsemium (China-linked state-sponsored threat actor).Campaign OverviewEspionage campaign targeting Linux systems, deploying malware strains WolfsBane…

Threat Brief: Operation Lunar Peek, Activity Related to CVE-2024-0012 and CVE-2024-9474 (Updated Nov. 22)

CategoryDetailsThreat ActorsUnnamed actors exploiting CVE-2024-0012 and CVE-2024-9474; activity includes manual/automated scans, web shells, and C2…