

Dominic Alvieri
13.3K posts

@AlvieriD
Cybersecurity Analyst | Security Researcher | CTI Deleted my own Facebook and hacked yours. https://t.co/jpm0COr5fY









🚨 Vect ransomware has partnered with #TeamPCP, the group behind the Trivy, Checkmarx, LiteLLM & Telnyx supply chain compromises. The next phase looks like monetization: turning TeamPCP’s estimated ~300 GB credential haul into ransomware deployments. A first confirmed Vect deployment using TeamPCP-sourced creds has already been reported. We spotted a Vect Linux/ESXi sample with our threat hunting YARA rules while AV detection on VirusTotal was still minimal. 5 YARA rule hits ⚡ SUSP_RANSOM_Indicators_Sep24_1 ⚡ SUSP_SCRIPT_FlushIptables_Sep21 ⚡ SUSP_RANSOM_ESX_Indicators_Feb23_1 ⚡ SUSP_LNX_RANSOM_Ransomware_Indicators_Sep22_1 ⚡ SUSP_LOL_ESXi_Commands_Oct24 At the time of analysis, VirusTotal showed only 2 detections for the sample. Our hunting rules still caught it. 🎯 Samples virustotal.com/gui/file/a7ead… virustotal.com/gui/file/8ee4e… How to scan VMware ESXi systems with THOR / THOR Thunderstorm nextron-systems.com/2023/02/14/how… nextron-systems.com/2021/06/07/ana… Reference helpnetsecurity.com/2026/03/30/tea…




BREAKING New Cisco Update Cisco source code and data was stolen by ShinyHunters claiming 3 breaches Salesforce, Aura and AWS buckets












