CTI Updates

118 posts

CTI Updates banner
CTI Updates

CTI Updates

@CTI__Updates

Updates about all things threat intelligence & updates about stuffs going on in the cybersec, ransomware, OSINT, SOCMINT, and hacking communities #threatintel

in the wires शामिल हुए Ocak 2026
1.1K फ़ॉलोइंग430 फ़ॉलोवर्स
spencer
spencer@techspence·
@gcvftw Honestly sounds kinda British
English
0
0
2
32
spencer
spencer@techspence·
Phishing emails go hard in 2026
spencer tweet media
English
14
4
46
2.6K
sysengineer
sysengineer@_sysengineer·
I paid $4 for a verification here so I could DM Hunter Biden and he didn’t respond. lol
English
8
1
82
3.1K
CTI Updates रीट्वीट किया
Anurag
Anurag@Malwarehunterr·
Open directory indexing on a website exposed multiple phishing templates - Fake #SharePoint document portal - Multiple #Microsoft email verification pages - Fake #Outlook login page - #ConnectWise executable delivered as a document download URLs: brcee[.]com brcee[.]com/test/ brcee[.]com/test2/ brcee[.]com/test3/ synergyconsulting[.]com[.]br/zmsso/ synergyconsulting[.]com[.]br/docu-zconnecting/ SHA256: 5172c183e2a809439aeea23980e8168dbff4c23fd603d7e217821413a6da81e8 @500mk500 @skocherhan #credentialharvesting #malware
Anurag tweet mediaAnurag tweet mediaAnurag tweet mediaAnurag tweet media
English
1
4
14
818
CTI Updates
CTI Updates@CTI__Updates·
a threat actor named Nemoris_Hacking claims they have access to NCIC (National Criminal Information Center) and that they have exfil'd data from correctional facilities across the US #lawenforcement #NCIC #threatintel #osint
CTI Updates tweet media
English
0
0
1
90
shenetworks
shenetworks@shenetworks·
If I went to jail, what would you assume it was for?
English
37
0
31
3.8K
CTI Updates
CTI Updates@CTI__Updates·
FulcrumSec popped Novo Nordisk and leaked 264GB of their stuffs "Their pharmacovigilance middleware — the system that processes reports of patients dying, having strokes, going into comas, or attempting suicide while on their drugs — is encrypted with the password novo123. A second master key, p_assw0?rd, protects the TLS keystore. These passwords are hardcoded across at least four production MuleSoft repositories. We wish we were joking." yikes #osint #threatintel #medical
CTI Updates tweet media
English
0
0
1
107
How To Prompt
How To Prompt@HowToPrompt__·
Someone open-sourced a tool that takes any username or email and finds every account linked to it across 600+ social networks in seconds. Just one command and it scans every platform, runs free AI profiling to build a full behavioral profile of the target, and exports the whole thing as a clean PDF report. → 600+ sites scanned → free AI profiling included → username OR email lookup → low false positive rate → PDF + CSV exports → runs from one CLI 100% Open Source.
How To Prompt tweet media
English
18
90
631
27.9K
GlobalGenre
GlobalGenre@GlobalGenre·
Filed with IC3 on behalf of my elderly folks that were scammed approximately 1yr ago. They lost a decent chunk of their nest egg. Never heard from IC3, police don’t do cybercrimes, there is literally no recourse. However @theNovacyberqfs came to my Rescue
M I@godofthemusic12

1 and 2 weeks have been past since my withdrawal request. Currently they never answer to my ticket and just reject my withdrawal request. I plan to make videos. @ascendex @George_AscendEX @cz_binance

English
1
2
3
186
CTI Updates
CTI Updates@CTI__Updates·
Nova ransomware group lists SUNASS, Peru’s water and sanitation services regulator, claiming to have stolen 175 GB of data.
CTI Updates tweet media
English
0
0
0
129
CTI Updates
CTI Updates@CTI__Updates·
they was cookin'
CTI Updates tweet media
English
0
0
0
41
CTI Updates
CTI Updates@CTI__Updates·
ShinyHunters must be cookin' up something 🤔
CTI Updates tweet media
English
1
0
7
380
ThreatMon
ThreatMon@MonThreat·
🚨 Betterment Data Breach Exposes PII of 1.4 Million Customers via Social Engineering A data breach involving US-based digital wealth management firm Betterment LLC has compromised the personally identifiable information (PII) of approximately 1.4 million customers. The incident, attributed to a social engineering attack, resulted in the exposure of over 2 million records containing sensitive client data. Betterment, founded in 2008 and headquartered in New York City, is a prominent robo-advisor and fintech company managing over $30 billion in assets for more than 2.5 million customers. The compromised dataset represents a substantial portion of the firm's user base. According to threat intelligence, the leaked data includes names, email addresses, phone numbers, physical addresses, and dates of birth for a subset of the affected accounts. Passwords were reportedly not included in the dump. The extensive sample data reveals a comprehensive CRM and sales database, likely extracted from Betterment's internal customer relationship management systems. Fields exposed include detailed 401(k) plan information, lead scoring metrics, account manager contacts, payroll integration statuses, and various customer lifecycle and engagement data points. The breach was publicized on the Telegram channel @dataseller247. Social engineering attacks on financial institutions often target employee credentials to gain unauthorized access to internal databases. The exposure of such granular client and operational data could facilitate targeted phishing campaigns, identity theft, and further corporate espionage. Betterment has not yet issued a public statement regarding the incident. Financial regulators and cybersecurity experts are likely to scrutinize the firm's security protocols following the disclosure. Customers are advised to monitor their accounts for suspicious activity and remain vigilant against potential phishing attempts leveraging the compromised information. #BettermentBreach #FintechSecurity #DataLeak #SocialEngineering #InvestmentFirm #CyberThreat #DarkWeb
ThreatMon tweet media
English
3
1
7
1.1K
CTI Updates
CTI Updates@CTI__Updates·
@sayodotfun do no contact them back at all. they are asking you questions they already know the answers too and are just fishing for info to see how you respond. only talk to them via a lawyer, never directly. its a trap. fuck the FBI.
English
2
0
8
437
Sayo
Sayo@sayodotfun·
1) what
Sayo tweet media
English
6
0
23
5.2K
CTI Updates
CTI Updates@CTI__Updates·
Qilin ransomware group lists MAVA Healthcare, also known as MAVA Behavioral Health. MAVA Behavioral Health provides mental health services for children, teens, and adults, including care for anxiety, depression, ADHD, bipolar disorder, PTSD, and other conditions. #threatintel #osint #healthcare #hipaa
CTI Updates tweet media
English
0
1
0
173
CTI Updates रीट्वीट किया
PurpleOps
PurpleOps@PurpleOps_io·
Scattered Lapsus$ Hunters just listed its largest target yet: Sysco, the world's biggest food distributor at $83B revenue, alongside Kodak and Houston Community College. SLSH's US-heavy extortion run, already through Charter, Nexstar and Ralph Lauren this month, is now reaching Fortune 500 scale. Sysco has drawn ransomware claims before, so treat attribution with care - this listing is unconfirmed and nothing is published yet.
PurpleOps tweet media
English
0
1
3
165
CTI Updates रीट्वीट किया
lain
lain@lainshawty·
i may, or may not have found an RCE in Jellyfin... 👀
English
14
5
142
19.3K
CTI Updates
CTI Updates@CTI__Updates·
Threat actor Orcinus orca claims to have hacked the FBI .gov website #osint #threatintel
CTI Updates tweet mediaCTI Updates tweet media
English
2
5
25
4.9K