Dominic Alvieri

13.3K posts

Dominic Alvieri banner
Dominic Alvieri

Dominic Alvieri

@AlvieriD

Cybersecurity Analyst | Security Researcher | CTI Deleted my own Facebook and hacked yours. https://t.co/jpm0COr5fY

127.0.0.1 Katılım Temmuz 2015
329 Takip Edilen19.3K Takipçiler
Dominic Alvieri
Dominic Alvieri@AlvieriD·
By popular demand ShinyHunters active onion /shnyhntww34phqoa6dcgnvps2yu7dlwzmy5lkvejwjdo6z7bmgshzayd[.]onion Enjoy!
Dominic Alvieri tweet media
Filipino
4
21
213
14.3K
Anubis
Anubis@Anubis__media·
@AlvieriD @pchdotcom The Anubis team has asked us to convey their apologies regarding your grandmother. They are not to blame for this; rather, it is due to a lack of security at PCH.
English
1
0
0
80
Dominic Alvieri
Dominic Alvieri@AlvieriD·
Publishers Clearing House breached My meemaw might be getting leaked by Anubis Ransomware - she loves PCH > interesting samples included < 1.4TB in 843,320 files @pchdotcom
Dominic Alvieri tweet mediaDominic Alvieri tweet mediaDominic Alvieri tweet media
English
1
6
25
2.3K
Dominic Alvieri retweetledi
vx-underground
vx-underground@vxunderground·
Iran is not fucking around, they just bombed AWS infrastructure (again) in Bahrain. No, this isn't an April Fools gag, Iran unironically is bombing AWS infrastructure because of the roll it plays in the United States
English
78
386
5.7K
142.6K
Dominic Alvieri
Dominic Alvieri@AlvieriD·
The next phase is monetization 5 great YARA rules ⤵️
Nextron Research ⚡️@nextronresearch

🚨 Vect ransomware has partnered with #TeamPCP, the group behind the Trivy, Checkmarx, LiteLLM & Telnyx supply chain compromises. The next phase looks like monetization: turning TeamPCP’s estimated ~300 GB credential haul into ransomware deployments. A first confirmed Vect deployment using TeamPCP-sourced creds has already been reported. We spotted a Vect Linux/ESXi sample with our threat hunting YARA rules while AV detection on VirusTotal was still minimal. 5 YARA rule hits ⚡ SUSP_RANSOM_Indicators_Sep24_1 ⚡ SUSP_SCRIPT_FlushIptables_Sep21 ⚡ SUSP_RANSOM_ESX_Indicators_Feb23_1 ⚡ SUSP_LNX_RANSOM_Ransomware_Indicators_Sep22_1 ⚡ SUSP_LOL_ESXi_Commands_Oct24 At the time of analysis, VirusTotal showed only 2 detections for the sample. Our hunting rules still caught it. 🎯 Samples virustotal.com/gui/file/a7ead… virustotal.com/gui/file/8ee4e… How to scan VMware ESXi systems with THOR / THOR Thunderstorm nextron-systems.com/2023/02/14/how… nextron-systems.com/2021/06/07/ana… Reference helpnetsecurity.com/2026/03/30/tea…

English
0
1
4
1.3K
Dominic Alvieri
Dominic Alvieri@AlvieriD·
Keep an eye on Vect Ransomware ShinyHunters is NOT TeamPCP but allegedly working with Vect Ransomware and TeamPCP Developing DragonBall Z situation @vxunderground /vectordntlcrlmfkcm4alni734tbcrnd5lk44v6sp4lqal6noqrgnbyd[.]onion
Dominic Alvieri tweet media
English
5
11
63
5.2K
vx-underground
vx-underground@vxunderground·
The streets are speaking [1] and word on the street is ShinyHunters dislike TeamPCP [2] [1] The streets is stinky nerds wearing Naruto pajamas in internet chatrooms [2] It is alleged ShinyHunters call TeamPCP "SkidPCP", a very unique and novel insult
English
19
12
384
21.9K
Dominic Alvieri
Dominic Alvieri@AlvieriD·
BREAKING New Cisco Update Cisco source code and data was stolen by ShinyHunters claiming 3 breaches Salesforce, Aura and AWS buckets
Dominic Alvieri tweet media
English
6
37
127
15.2K
vx-underground
vx-underground@vxunderground·
Chat, look what images just appeared ON THE DARK WEB (Telegram, where all crime happens on the internet apparently). ShinyHunters posted it. Is this actual stuff from the alleged Cisco data compromise as a result of the Trivy supply chain attack? Are these images unrelated? How sensitive is this data? How is ShinyHunters involved with TeamPCP? Is this even real? Find out on the next action packed episode of Dragon Ball Z
vx-underground tweet mediavx-underground tweet mediavx-underground tweet media
English
19
69
794
55.8K
vx-underground
vx-underground@vxunderground·
CISCO DATA STOLEN BITCH ITS TUESDAY STOP
vx-underground tweet media
English
67
495
3.7K
113.9K
Dominic Alvieri
Dominic Alvieri@AlvieriD·
Recent Nissan history includes: Akira Ransomware 2023 Qilin Ransomware 2024 Crimson Collective 2025 ShinyHunters involved 2025 New alleged Everest claims in 2026
English
1
2
10
1.1K
Dominic Alvieri
Dominic Alvieri@AlvieriD·
New Nissan alleged customer data breach Most recent files dated January 3, 2026 Auto loan data from Nissan Financial Services - US and Canadian customers 2.5 million unique records - Full names - emails - Phone numbers - Full home addresses Everest Ransom Team chat logs included @Nissan
Dominic Alvieri tweet mediaDominic Alvieri tweet media
English
4
18
57
6.1K
Dominic Alvieri retweetledi
Feross
Feross@feross·
🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now. Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that: • Deobfuscates embedded payloads and operational strings at runtime • Dynamically loads fs, os, and execSync to evade static analysis • Executes decoded shell commands • Stages and copies payload files into OS temp and Windows ProgramData directories • Deletes and renames artifacts post-execution to destroy forensic evidence If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.
English
534
4.1K
16.3K
12M
Dominic Alvieri
Dominic Alvieri@AlvieriD·
Mercor AI has allegedly been breached by Lapsus 939GB of source code 4TB of data in total All data from their TailScale VPN @mercor_ai
Dominic Alvieri tweet media
English
110
160
1.6K
1.4M