Iván Altamirano G.
23.2K posts

Iván Altamirano G.
@IvanAltamiranoG
Ser Humano, Soñador! Creo en la gente y en la comunidad - Mons. Proaño - Un mundo mas Justo, Humano y Solidario, es Posible!






Saludamos a la hermosa provincia de #Tungurahua en el aniversario de su provincialización. Reconocemos el espíritu emprendedor de sus habitantes y su invaluable aporte al desarrollo económico, social y cultural del país. ¡Felicidades en su día! 🇪🇨 #Ecuador

‘¿La República del Miedo?’. Lea #EstoNoEsPolítico de María Sol Borja (@mariasolborja). prim.ec/4kpp50Zg6fY


🚨 CYBER INTELLIGENCE ALERT: ALLEGED SALE OF ACTIVE INITIAL ACCESS — ECUADOR 🇪🇨 [STATUS: INFRASTRUCTURE EXPOSED / UNCONFIRMED / / SOURCE: UNDERGROUND FORUM] THREATENING ACTOR OFFERS VPN TOKENS AND ACTIVE DIRECTORY CREDENTIALS FOR THE "INTI WASI" COOPERATIVE A threat actor identified by the alias CoronelPe has posted an advertisement on an underground cybercrime forum offering for sale valid logical access and authentication credentials belonging to the "Inti Wasi" Savings and Credit Cooperative, a financial institution in the popular and solidarity economy sector in Ecuador. The attacker claims that the access is active and validated until June 20, 2026, covering internal corporate environments such as Active Directory (AD) servers, VPN tunnels, and administrative panels. 🏢 Allegedly Affected Entity: Inti Wasi Savings and Credit Cooperative 👤 Threat Actor / Access Broker: CoronelPe ⚔️ Potential Attack Vector: Compromise of employee terminals via information-stealing Trojans (Infostealers), password spraying attacks on Single Sign-On (SSO) endpoints, or exposure of perimeter network configurations. 🔍 Verification Status: UNCONFIRMED. The financial institution has not issued public alerts regarding infrastructure compromise or technological incidents. However, the signal presents a high level of risk due to structural forensic consistency, given the explicit samples of logical data, VPN sessions, and indexed personnel lists in the screenshot. 🗂️ FORENSIC ANALYSIS OF EXPOSED SAMPLES AND SCHEMAS The preliminary technical examination of the three exposed data blocks details the logical components the attacker claims to control: 📊 1. Customer and Branch Segmentation (.csv) The first section presents a structured customer control extract containing core financial variables: Fields: customer_ref, account_ref, segment, branch, status, balance_bucket, note. Geographic and Account Data: Records link simulated audit references to actual branches and offices within Ecuador, such as Otavalo, Latacunga, Quito-Sur, Quito-Norte, and Riobamba. Segments include classifications such as Savings, Credit, Microcredit, and SME, alongside estimated balance ranges. 👤 2. Employee File and Identity Control The second block reveals a direct list of corporate email accounts and identities belonging to the cooperative's staff: Log Structure: employee_id, full_name, username, email, department, role, mfa_status, last_password_change, record_type. Compromised Personnel: Displays real names associated with accounts under the @intiwasi.fin.ec domain within sensitive departments. Internal Cybersecurity Mapping: The attacker directly exposes accounts assigned to the cooperative's technology defense personnel, labeled under the Cybersecurity department (with Manager and Auditor roles). Password change timestamps show recent dates extending up to May 2026, indicating an active operational status. 🛡️ TECHNICAL RECOMMENDATIONS AND RESPONSE PROTOCOL 🛑 Perimeter Connection and VPN Audit (SOC Action): Network administrators at Inti Wasi Cooperative are urged to immediately conduct a thorough inspection of authentication logs for their VPN gateways. They should look for connections established using the user accounts listed in the sample, paying particular attention to geolocation anomalies or concurrent bursts recorded from mid-June 2026 onwards. 🔄 Global Session Revocation and AD Credential Reset: Force the termination of all active sessions on Single Sign-On (SSO) gateways and mandate a password rotation for all administrative staff; proactively disable temporary VPN tokens and tighten Multi-Factor Authentication (MFA) policies. 📊 MONITORING AND EVALUATION Intelligence System: analyzer.vecert.io Quickly assess your website's security at: monitor.vecert.io #CyberSecurity #Ecuador #IntiWasi #CreditUnionBreach #VPNTokens #ActiveDirectory #DataLeak #FintechSecurity #CoronelPe #ThreatIntelligence #CyberAlert #VECERT #Infosec #UnverifiedBreach

🚨 CYBER INTELLIGENCE ALERT: POTENTIAL CRITICAL DATA BREACH - NATIONAL ELECTORAL COUNCIL (CNE) OF 🇨🇴 COLOMBIA ⚠️ STATUS: UNDER INVESTIGATION; LIMITED REPORT, SAMPLES VIEWED A cyber incursion against the National Electoral Council (CNE) of Colombia has been identified, perpetrated by the actor identified as Hydr0gen, under the banner of the EsqueleSquad collective. 📋 INCIDENT SUMMARY Access Vector: The actors claim to have gained direct access to the CNE's servers, extracting classified material that compromises the institution's confidentiality. Scope of Exfiltrated Information: The group claims to possess: Confidential internal documents, including audit reports and formal complaints regarding irregularities in the electoral process. Sensitive correspondence between CNE officials and campaign teams. Financial records from the 2026 campaigns, including donor lists, money transfers, and significant financial discrepancies. Evidence: The group has shared screenshots showing CNE administrative management interfaces and detailed campaign income and expenditure forms, along with an external link to verify the data's legitimacy. 🛡️ SECURITY RECOMMENDATIONS Given the seriousness of this breach, the competent authorities and the public are urged to consider the following measures: Immediate Containment: The CNE must conduct an urgent forensic audit to close the access vector, revoke compromised access, and secure the affected endpoints. Information Verification: Electoral entities and oversight bodies must issue official statements to verify or refute the authenticity of the leaked documents and prevent the spread of misinformation. ⚡Strategic Monitoring Tools Intelligence Platform: analyzer.vecert.io Security Verification: monitor.vecert.io #CyberSecurity #DataBreach #Colombia #CNE #ThreatIntelligence #EsqueleSquad #IncidentResponse #Infosec #CiberSeguridad

"Me han bloqueado todas las tarjetas por emitir la orden de arresto contra Netanyahu, no puede comprar ni tomar un avión ni alquilar una habitación de hotel". Nicolas Gouyou, juez francés de la Corte Penal Internacional, quien emitió una orden de arresto contra Netanyahu, afirma que "Israel" y EEUU han bloqueado todas sus cuentas y están hundiéndole la vida solo por intentar que el sionismo rinda cuenta. Esta es su "justicia internacional" donde los pocos jueces que intenten hacer rendir cuentas a "Israel" son perseguidos y hundidos por el sionismo, todo esto de los tribunales internacionales es una farsa que solo sirve para perseguir a países enemigos de EEUU.







