Bob Diachenko 🇺🇦

1.7K posts

Bob Diachenko 🇺🇦 banner
Bob Diachenko 🇺🇦

Bob Diachenko 🇺🇦

@MayhemDayOne

Cyber Threat Intelligence @ https://t.co/fC73RSevWP, journalist, OSINT | Responsible disclosures | Security consultancy | Contact me: [email protected]

Germany/Ukraine 🇺🇦 Katılım Şubat 2016
534 Takip Edilen18K Takipçiler
Bob Diachenko 🇺🇦
Bob Diachenko 🇺🇦@MayhemDayOne·
Thing is that this (or similar) data has been sitting in open elasticsearch cluster at least since April 2025. Company did not care about closing it, despite my alerts. See below (don't be distracted by 'raaga-users' numbers, other collections contain sensitive data too, hence 10M).
Bob Diachenko 🇺🇦 tweet media
English
1
0
2
451
Have I Been Pwned
Have I Been Pwned@haveibeenpwned·
New breach: Indian streaming music service Raaga allegedly had 10M records breached last month. Data included email, name, gender, age, postcode and unsalted MD5 password hash. 60% were already in @haveibeenpwned. Read more: haveibeenpwned.com/Breach/Raaga
English
5
22
60
15.2K
Bob Diachenko 🇺🇦
Bob Diachenko 🇺🇦@MayhemDayOne·
Is anyone still here? please reply to this thread to let me know if it is still worth publishing reports/news on this platform as I have almost migrated to linkedin.
English
5
0
11
1.5K
Bob Diachenko 🇺🇦
Bob Diachenko 🇺🇦@MayhemDayOne·
This is NOT a single source. It's not about the number (scary!), but the scale and raise of infostealers infections today. What this number reflects is the size of of different infostealers logs exposed publicly since the beginning of this year alone. cybernews.com/security/billi…
English
6
9
18
5.9K
Bob Diachenko 🇺🇦
Bob Diachenko 🇺🇦@MayhemDayOne·
RU-hosted Troyan-As-A-Service infrastructure config (accidentally exposed).
Bob Diachenko 🇺🇦 tweet media
English
0
2
11
3.2K
Bob Diachenko 🇺🇦
Bob Diachenko 🇺🇦@MayhemDayOne·
As per my knowledge, no US or EU citizen was on this list.
English
0
0
1
2.4K
Bob Diachenko 🇺🇦
Bob Diachenko 🇺🇦@MayhemDayOne·
Apparently, it was very limited and was part of The Kingdom of Bahrain's Joint Counter Terrorism Centre (JCTC) responsible for gathering and analysing information regarding terrorist organisations and affiliated individuals.
English
1
2
1
2.5K
Bob Diachenko 🇺🇦
Bob Diachenko 🇺🇦@MayhemDayOne·
It's been more than 3 years ago but this post keeps popping up and my DM is full of requests from people who think they are on this list. Let me assure you are not. There's been a development since then regarding the owner of this list.
Bob Diachenko 🇺🇦@MayhemDayOne

Apparently, this is the TSC (Terrorist Screening Centre) dataset publicly exposed (tsc_id is the only clue), with 1.9M+ records. In any case, any thoughts as of where to responsibly report?

English
1
3
6
3.8K
AWS Support
AWS Support@AWSSupport·
@MayhemDayOne I sincerely apologize for the frustration this has caused, Bob. We do have a team that handles these reports, this documentation explains how to forward the information to them: go.aws/report. ^BD
English
1
0
1
51
Bob Diachenko 🇺🇦
Bob Diachenko 🇺🇦@MayhemDayOne·
"В целях исключения сбора информации о критических уязвимостях ресурсов, индексирования персональных данных и использования собранной информации в зарубежных моделях машинного обучения и анализа".
Русский
1
1
2
3.7K
Bob Diachenko 🇺🇦
Bob Diachenko 🇺🇦@MayhemDayOne·
Interesting. Here is the list of recommended websites configuration sent by russian "Center for Monitoring and Managing the Public Telecommunications Network" to the critical infrastructure enterprises. In total, 653 search bots and crawlers are to be blocked.
Bob Diachenko 🇺🇦 tweet mediaBob Diachenko 🇺🇦 tweet mediaBob Diachenko 🇺🇦 tweet media
English
1
1
6
4.3K
Bob Diachenko 🇺🇦
Bob Diachenko 🇺🇦@MayhemDayOne·
@xeraa a lot of developers sincerely think that changing a default port makes the instance secured
English
1
0
0
96
Philipp Krenn
Philipp Krenn@xeraa·
@MayhemDayOne I just wish everyone kept the security by default enabled (or at least not change the port binding to a public interface) 🫠
English
1
0
1
67
Bob Diachenko 🇺🇦
Bob Diachenko 🇺🇦@MayhemDayOne·
Raysharp also provided a really weird comment when asked about the exposure which I would like to bring up here: “Elasticsearch is an open-source log service system, with port 9500 only used for log queries during product development. Under normal circumstances, it is not necessary to use it. Only when there is an abnormality in the product, it is necessary to query the product log through port 9500 to assist in locating the problem. At present, the service on port 9500 is temporarily suspended. After resolving the issue of this vulnerability, it can be opened again”.
English
1
2
4
5.4K
Bob Diachenko 🇺🇦
Bob Diachenko 🇺🇦@MayhemDayOne·
Recently I reported very interesting leak related to Raysharp (a Chinese manufacturer of video cameras, recorders, and other surveillance products). While it may not be a household name in every corner of the world, it has established itself as a reputable provider of security surveillance solutions in certain regions or markets. Such as Russia, for example. Thread below:
Bob Diachenko 🇺🇦 tweet media
English
3
2
13
6.7K
Bob Diachenko 🇺🇦
Bob Diachenko 🇺🇦@MayhemDayOne·
Raysharp has its production server with filebeat logs exposed where more than 3 Billion (!) records stored. Of course, it was not super sensitive as passwords or even emails, but still - these data points could tell someone a good story:
Bob Diachenko 🇺🇦 tweet media
English
1
0
2
505
Bob Diachenko 🇺🇦
Bob Diachenko 🇺🇦@MayhemDayOne·
We are working with @cybersecdawg and @4353_37 on a project that should help companies quickly respond to the fast-growing issue with API keys leaks. Unfortunately, @Shopify, @stripe, @PayPal and other industry players underestimate this problem and prefer not to mention numerous exposures (and not all of them re-surface on greyweb forums, most are privately sold).
English
0
0
5
5.4K