Red Hot Cyber
Cybersecurity is about sharing. Recognize the risk, combat it, share your experiences, and encourage others to do better than you.
Search
Banner Ransomfeed 320x100 1
2nd Edition GlitchZone RHC 970x120 2

Tag: cybercrime

Meow ransomware claims attack in its Data Leak Site at HPE giant

Introduction Today, the ransomware gang known as Meow has claimed responsibility for a cyberattack on the multinational giant Hewlett Packard Enterprise (HPE). The claim was published on their Data Leak Site (DLS), where the group offered access to an alleged confidential HPE database for $199. HPE Hewlett Packard Enterprise (HPE) is one of the leading global technology companies, established as a result of the split of Hewlett-Packard Company in November 2015. Hewlett-Packard, founded by Bill Hewlett and Dave Packard in 1939, was divided into two separate entities: HP Inc., which focuses primarily on printers and personal computers, and Hewlett Packard Enterprise, which

The Threat Actor 888 claimed a compromise against Microsoft

On July 9, 2024, a user known as “888” posted on BreachForums claiming to have leaked sensitive data of Microsoft employees. This alleged breach has exposed personal information of 2,073 company employees, reportedly due to a flaw in a third-party system. Details of the Breach According to the post published by “888,” the compromised data includes: The extent of the breach is significant, as the disclosed information can be used for a range of malicious activities, including phishing, fraud, and targeted attacks. Situation Analysis At the moment, we cannot precisely confirm the veracity of the breach. Microsoft has not released any official

The Threat Actor 888 claims responsibility for a breach at Nokia.

A malicious actor, known by the alias “888,” recently claimed responsibility for disclosing sensitive data belonging to Nokia. The attack, which occurred in July 2024, compromised a wide range of information, raising significant concerns about data security and the protection of personal information. Breach Details According to 888’s statements, the breach led to the exposure of several sensitive data points. Among the compromised information are: Current Status At this time, we cannot confirm the exact accuracy of the breach claims, as the organization has yet to release any official press statement on its website regarding the incident. Therefore, this article should be

Massive Data Exposure on X (Twitter) Affects 200 Million Users

Recently, X (Twitter) experienced a massive data exposure, compromising nearly 200 million user records. This incident could be one of the largest user data exposures in recent history, jeopardizing the security and privacy of millions of users. In this article, we analyze the details of the exposure, its implications, and the potential risks for the affected users. Currently, we are unable to accurately confirm the veracity of the breach, as no press release has been issued on the official website regarding the incident. Therefore, this article should be used as an “intelligence source.” Scope and Source of the Data Leak The leaked

Alleged NATO Data BreachAlleged NATO Data Breach: 643 CSV Files with User Data and Server Details Leaked

A threat actor claims to have leaked sensitive data from NATO – TIDE (Think-Tank for Information Decision and Execution Superiority). NATO-TIDE (Think-Tank for Information Decision and Execution Superiority) is a specialized division of NATO (North Atlantic Treaty Organization), focused on enhancing decision-making and execution capabilities through advanced use of information. This organization aims to optimize the collection, analysis, and use of data to support military and strategic operations. The actor, identified by the username “natohub” on an online forum, posted an announcement on July 7, 2024, claiming to have obtained and shared 643 CSV files containing user data, user groups, physical and

Access to UK Accounting System for Sale: 600 Clients and 1TB of Data at Risk

A malicious actor is allegedly selling access to an RDWeb system in the United Kingdom, belonging to an accounting firm. This breach represents a serious threat to the security of sensitive data for over 600 clients, containing tax return files and other confidential documents. Offer Details The ad posted on an online forum details access to the compromised system: The advertiser claims that the files contain tax return documents and other related documents for over 600 clients. It is specified that there are many other unverified files, suggesting the possible presence of additional sensitive data. Access Price Access to the RDWeb system

Ticketmaster Breach: 30,000 Free Tickets Released

After claiming to have stolen 170,000 tickets for Taylor Swift’s ERAS Tour, the hacker group Sp1d3rHunters today announced they have distributed over 30,000 more tickets for high-profile events. The allegedly leaked tickets today include events for: Sp1d3rHunters, known for their illicit activities in the cybercrime world, posted a detailed message on a dark forum claiming they had breached Ticketmaster’s security. Reportedly, the flaw exploited by the hacker group allows them to print physical tickets (Ticketfast, e-tickets, and tickets sent via mail) which, unlike Ticketmaster’s dynamic electronic tickets, cannot be automatically updated. How To: 4-Step Guide to Creating Your Own Ticketfast Tickets Current

Threat Actors Steal 5.90 GB of Sensitive Data from the Fiscalía General del Estado de Veracruz!

In an era where cybersecurity has become crucial for protecting sensitive data, a recent leak has revealed an alleged security breach at the Fiscalía General del Estado de Veracruz. A malicious actor known as “dwShark” claimed to have stolen the database of the Office of the Attorney General of the State of Veracruz, exposing sensitive data such as names, phone numbers, emails, and other personal information. Fiscalía General del Estado de Veracruz The Fiscalía General del Estado de Veracruz (FGE Veracruz) is the entity responsible for administering criminal justice in the state of Veracruz, Mexico. This institution plays a crucial role in

Dangerous 0day Windows LPE Vulnerability for Sale in the Underground

A malicious actor, under the name “tikila”, has posted an advertisement on a hacking forum for the sale of a local privilege escalation (LPE) vulnerability for Windows. According to the post, this vulnerability has been tested and confirmed to work on various versions of Windows, including Windows 10, Windows 11, and several Windows Server versions (2008, 2012, 2016, 2019, 2022). Vulnerability Details The announcement claims that the vulnerability is 100% reliable and does not cause system crashes, ensuring process continuity. The author specifies that the vulnerability has been tested on fully updated and patched systems, implying it might exploit an unknown zero-day

Europol Breached: Secret Documents for Sale on the Dark Web

July 6, 2024: A well-known user of the BreachForums, IntelBroker, has recently announced the sale of a collection of crypto-related documents stolen from Europol’s EPE platform. The data breach, which occurred in May 2024, involved the theft of critical files and documents. Breach Details The EPE (Europol Platform for Experts) platform is a secure system used by Europol for sharing sensitive information among European law enforcement agencies. The breach allowed hackers to access valuable information, potentially jeopardizing several ongoing investigations. Reportedly, IntelBroker has uploaded a small amount of these documents to the forum as proof of the successful breach. In a post