theins.ru/news/286794
theins.ru/news/286794
Relies on Salesforce 🤣
Der vom russischen FSB kontrollierte staatliche Messenger MAX wurde wahrscheinlich gehackt. 46,2 Millionen Datensätze sollen gestohlen worden sein. Hacker veröffentlichte Beispielzeilen aus der Datenbank im Dark Web.
Relies on Salesforce 🤣
www.welivesecurity.com/en/eset-rese...
www.welivesecurity.com/en/eset-rese...
Seqrite reported an attack on the Kazakhstani oil company KazMunayGas attributed to a new group NoisyBear www.seqrite.com/blog/operati...
Yet the company later argued that this was a simulated attack orda.kz/planovoe-mer...
This looks plausible:
1/2
Seqrite reported an attack on the Kazakhstani oil company KazMunayGas attributed to a new group NoisyBear www.seqrite.com/blog/operati...
Yet the company later argued that this was a simulated attack orda.kz/planovoe-mer...
This looks plausible:
1/2
www.kommersant.ru/doc/7991253
www.kommersant.ru/doc/7991253
blog.talosintelligence.com/static-tundra/
blog.talosintelligence.com/static-tundra/
gru.dossier.center
www.microsoft.com/en-us/securi...
www.microsoft.com/en-us/securi...
↘️
checkfirst.network/decoding-sec...
↘️
checkfirst.network/decoding-sec...
↘️
checkfirst.network/decoding-sec...
- this cluster tried to re-establish relationships after we disabled their accounts by creating new, similarly named accounts. very persistent!
- if you thought their device linking phase was over, think again! susp apt29 groups looove this & want to make it seem more legit
They continued the ASP campaign with evidence they responded to our initial publication.
They were doing some sneaky calendar stuff that lead to adding a device to the target's O365 tenant.
Citizen Lab worked closely with one of the targets and shared their work on it also: citizenlab.ca/2025/06/russ...
- this cluster tried to re-establish relationships after we disabled their accounts by creating new, similarly named accounts. very persistent!
- if you thought their device linking phase was over, think again! susp apt29 groups looove this & want to make it seem more legit