Sam Stones(Tiger)👨💻
9K posts

Sam Stones(Tiger)👨💻
@SamTechwest
Offensive Security 👩💻 Red-team🎩🎩| Penetration Testing😁😁😁😁.

Every other day, there's a supply chain attack on software packages. Is this the effect of AI? I mean its not uncommon for these things to happen but now it's occurring every week and maybe twice a week to very popular packages.

Keep pushing the pivots of the axios supply chain compromise Three attacker domains identified (all confirmed): 1. sfrclak.com — Active C2, Namecheap, registered 16:03 UTC 2. callnrwise.com — Same IP 142.11.206.73, Dynadot, registered 53 min earlier (15:10 UTC). Name = "call nrwise" referencing attacker npm account 3. nrwise.com — Same Namecheap registrant (WHOIS hash 37bfbc24cafea5d2 matches sfrclak.com). Registered 2.5 months earlier

The same guys (ByteToBreach) that hacked Sterling just breached Remita allegedly. SEVERAL banks in Nigeria have reportedly been affected too. Not much information has been released yet. If you're in financial services in Nigeria, you should pay attention to this. IoC👇🏾

The only IoC I'm aware of is the C2 IP they in the attack against Sterling: IP 196.41.84.201

‼️🇳🇬 A massive breach allegedly from Remita, a major Nigerian payment processing platform, has been leaked on a popular cybercrime forum. ▪️ Total Size: ~3TB of S3 storage ▪️ Data Includes: 800GB+ of KYC documents (IDs, passports, photos, bank statements, electricity bills), MySQL/Postgres databases, logs, docker registries, source codes, government HSM keys, GitKraken to S3 backups ▪️ Source codes, 35,000+ password hashes, and three databases

You would see some security engineers go quiet soon Don't say anything just order item7 for them it is bloody out there Also some of them will go quiet because they will do jail CEO go soon lock some engineers up Brazy days ahead




This on going security breach is crazy! When we advise on intensive pen testing and security testing they’ll say “we recently completed this” show us evidence and you’ll see PowerPoint presentation slides from whoever conducted the test. 😂 you’ll still be making corrections and requesting more evidence. I hope they learn, hire expert security professionals, conduct regular pentesting, train your employees etc… it’s not by presentation and being the most patronized organization. It’s deeper than all that.





Again if you can JAPA please JAPA without any apology. Even if it is Jamaica 🇯🇲, Barbados 🇧🇧, Namibia 🇳🇦, Seychelles 🇸🇨! Pls JAPA oooooo!










