CTI Updates

108 posts

CTI Updates banner
CTI Updates

CTI Updates

@CTI__Updates

Updates about all things threat intelligence & updates about stuffs going on in the cybersec, ransomware, OSINT, SOCMINT, and hacking communities #threatintel

in the wires Присоединился Ocak 2026
1.1K Подписки419 Подписчики
CTI Updates
CTI Updates@CTI__Updates·
they was cookin'
CTI Updates tweet media
English
0
0
0
23
CTI Updates
CTI Updates@CTI__Updates·
ShinyHunters must be cookin' up something 🤔
CTI Updates tweet media
English
1
0
7
354
ThreatMon
ThreatMon@MonThreat·
🚨 Betterment Data Breach Exposes PII of 1.4 Million Customers via Social Engineering A data breach involving US-based digital wealth management firm Betterment LLC has compromised the personally identifiable information (PII) of approximately 1.4 million customers. The incident, attributed to a social engineering attack, resulted in the exposure of over 2 million records containing sensitive client data. Betterment, founded in 2008 and headquartered in New York City, is a prominent robo-advisor and fintech company managing over $30 billion in assets for more than 2.5 million customers. The compromised dataset represents a substantial portion of the firm's user base. According to threat intelligence, the leaked data includes names, email addresses, phone numbers, physical addresses, and dates of birth for a subset of the affected accounts. Passwords were reportedly not included in the dump. The extensive sample data reveals a comprehensive CRM and sales database, likely extracted from Betterment's internal customer relationship management systems. Fields exposed include detailed 401(k) plan information, lead scoring metrics, account manager contacts, payroll integration statuses, and various customer lifecycle and engagement data points. The breach was publicized on the Telegram channel @dataseller247. Social engineering attacks on financial institutions often target employee credentials to gain unauthorized access to internal databases. The exposure of such granular client and operational data could facilitate targeted phishing campaigns, identity theft, and further corporate espionage. Betterment has not yet issued a public statement regarding the incident. Financial regulators and cybersecurity experts are likely to scrutinize the firm's security protocols following the disclosure. Customers are advised to monitor their accounts for suspicious activity and remain vigilant against potential phishing attempts leveraging the compromised information. #BettermentBreach #FintechSecurity #DataLeak #SocialEngineering #InvestmentFirm #CyberThreat #DarkWeb
ThreatMon tweet media
English
3
1
7
900
CTI Updates
CTI Updates@CTI__Updates·
@sayodotfun do no contact them back at all. they are asking you questions they already know the answers too and are just fishing for info to see how you respond. only talk to them via a lawyer, never directly. its a trap. fuck the FBI.
English
2
0
7
261
Sayo
Sayo@sayodotfun·
1) what
Sayo tweet media
English
5
0
20
2.9K
CTI Updates
CTI Updates@CTI__Updates·
Qilin ransomware group lists MAVA Healthcare, also known as MAVA Behavioral Health. MAVA Behavioral Health provides mental health services for children, teens, and adults, including care for anxiety, depression, ADHD, bipolar disorder, PTSD, and other conditions. #threatintel #osint #healthcare #hipaa
CTI Updates tweet media
English
0
1
0
140
CTI Updates ретвитнул
PurpleOps
PurpleOps@PurpleOps_io·
Scattered Lapsus$ Hunters just listed its largest target yet: Sysco, the world's biggest food distributor at $83B revenue, alongside Kodak and Houston Community College. SLSH's US-heavy extortion run, already through Charter, Nexstar and Ralph Lauren this month, is now reaching Fortune 500 scale. Sysco has drawn ransomware claims before, so treat attribution with care - this listing is unconfirmed and nothing is published yet.
PurpleOps tweet media
English
0
1
2
116
CTI Updates ретвитнул
lain
lain@lainshawty·
i may, or may not have found an RCE in Jellyfin... 👀
English
14
5
140
19.3K
CTI Updates
CTI Updates@CTI__Updates·
Threat actor Orcinus orca claims to have hacked the FBI .gov website #osint #threatintel
CTI Updates tweet mediaCTI Updates tweet media
English
2
5
25
4.8K
CTI Updates ретвитнул
Nightmare Eclipse
Nightmare Eclipse@ChaoticEclipse0·
Welp it's official, blogger started removing my posts as well, crazy how even google is hating me now. Is that like supposed to make stop ? Kinda feeling even more motivated.
English
55
134
1.6K
46.5K
UNIT4713‍🏴‍☠️
UNIT4713‍🏴‍☠️@kraytovsupp·
@CTI__Updates @NASA I don't think this is really a leak, it could be public data, for example there are many PDFs on the NASA website, so it could be wrong or a trick?
English
1
0
1
63
CTI Updates
CTI Updates@CTI__Updates·
Insomnia ransomware group lists Texas-based The Vant Group, an M&A advisory firm founded in 1999. The company provides valuations, sell-side and buy-side advisory, and employee/partner buyout services for businesses up to $250M in revenue. #raas #osint #threatintel #ransomware
CTI Updates tweet media
English
0
1
6
396
X3r0Day
X3r0Day@X3r0DaySec·
They "fixed" my last Indian Govt data dump by encrypting it (srsly lol?) Bypassed that too lmao 48,593 contacts. 37,598 users. All decrypted with a PoC. (IP, Pass, Aadhaar..) CERT-In has been notified. Not dropping full details until it's actually fixed. x.com/X3r0DaySec/sta…
X3r0Day tweet media
X3r0Day@X3r0DaySec

I Hacked an Indian Government Website Found Users’ Passwords,Aadhaar Numbers,IP Address, Address,phone no,email This is a serious data privacy failure. Reported to CERT-In. Will release full technical details once its fixed. Got more in my Bag 👀 1 vuln each week series? ;))

English
3
12
58
4.7K
CTI Updates
CTI Updates@CTI__Updates·
@NASA the ss is them running a WordPress exploit (lol) so not really sure what important info they could have even got. good one to keep an eye on.
English
0
0
4
198
CTI Updates
CTI Updates@CTI__Updates·
Georgian authorities, in cooperation with Polish and American officials, have detained two foreigners (a Ukrainian and a Russian) in Georgia who are responsible for the AudiA6 crypto exchange and the Dark2Web forum #osint #threatintel #darkweb #deepweb #tor
CTI Updates tweet mediaCTI Updates tweet mediaCTI Updates tweet media
English
1
4
22
2K
CTI Updates
CTI Updates@CTI__Updates·
ShinyHunters lists two new victims - Nexstar Media Group - Ralph Lauren Corporation
CTI Updates tweet media
English
0
0
8
848