faal
faal.dev
faal
@faal.dev
I'm a Danish software engineer and security researcher turned founder, with a passion for exploring how automation and data collection intersect to solve complex problems.
DeepSeek, a Chinese AI platform, left a critical database exposed online, leaking over 1 million records, including user prompts, system logs, and API authentication tokens.

#cybersecurity #databreach #at #DeepSeek #infosec #security #leak
Exposed DeepSeek Database Revealed Chat Prompts and Internal Data
China-based DeepSeek has exploded in popularity, drawing greater scrutiny. Case in point: Security researchers found more than 1 million records, including user data and API keys, in an open database.
www.wired.com
February 13, 2025 at 10:11 PM
FakeUpdates malware continues to dominate, deceiving users with fake browser updates to install malicious software.

#cybersecurity #fakeupdates #malware #infosec #browsersecurity #security
January 2025’s Most Wanted Malware: FakeUpdates Continues to Dominate - Check Point Blog
Check Point Software’s latest threat index highlights that FakeUpdates continues to pose a significant threat in the cyber landscape, playing a crucial
blog.checkpoint.com
February 13, 2025 at 3:55 PM
A cybercrime group named Triplestrength is deploying ransomware, hijacking cloud accounts, and illicitly mining cryptocurrency, posing a multifaceted threat to organizations.

#cybersecurity #ransomware #cloudsecurity #cryptomining #infosec
Triplestrength hits with ransomware, cloud crypto mining
These crooks have no chill
www.theregister.com
February 12, 2025 at 8:42 AM
Law enforcement agencies have arrested four Russian nationals in Phuket, Thailand, suspected of deploying Phobos ransomware to extort payments from victims in Europe and beyond. The operation also led to the seizure of 8Base's dark web sites.

#cybersecurity #ransomware #lawenforcement #infosec
Thai-Swiss-US Operation Nets Hackers Behind 1,000+ Cyber Attacks
Thai police arrested four European hackers in Phuket who allegedly stole $16 million through ransomware attacks affecting over 1,000 victims worldwide. The suspects, wanted by Swiss and US authorities
www.khaosodenglish.com
February 11, 2025 at 3:54 PM
Authorities have arrested four distributors of the encrypted communication service Sky ECC in Spain and the Netherlands. Sky ECC has been widely used by criminal organizations for illicit activities.

#cybersecurity #skyecc #encryption #crime #infosec #lawenforcement #security
Sky ECC encrypted service distributors arrested in Spain, Netherlands
Four distributors of the encrypted communications service Sky ECC, used extensively by criminals, were arrested in Spain and the Netherlands.
www.bleepingcomputer.com
February 11, 2025 at 9:23 AM
Over 12,000 GFI KerioControl firewalls are exposed to a critical remote code execution flaw (CVE-2024-52875), leaving systems vulnerable to attacks.

#cybersecurity #keriocontrol #rce #vulnerability #infosec #firewall
Over 12,000 KerioControl firewalls exposed to exploited RCE flaw
Over twelve thousand GFI KerioControl firewall instances are exposed to a critical remote code execution vulnerability tracked as CVE-2024-52875.
www.bleepingcomputer.com
February 11, 2025 at 7:17 AM
Reposted by faal
A global law enforcement operation targeting the Phobos ransomware gang has led to the arrest of four suspected hackers in Phuket, Thailand, and the seizure of 8Base's dark web sites. The suspects are accused of conducting cyberattacks on over 1,000 victims worldwide.
Police arrests 4 Phobos ransomware suspects, seizes 8Base sites
A global law enforcement operation targeting the Phobos ransomware gang has led to the arrest of four suspected hackers in Phuket, Thailand, and the seizure of 8Base's dark web sites. The suspects are accused of conducting cyberattacks on over 1,000 victims worldwide.
www.bleepingcomputer.com
February 10, 2025 at 4:51 PM
Magecart attackers are exploiting Google Tag Manager to inject card-skimming code into Magento-based e-commerce sites, compromising customer payment data.

#cybersecurity #magecart #ecommerce #databreach #infosec #google #magento
Magecart Attackers Abuse Google Ad Tool to Steal Data
Attackers are smuggling payment card-skimming malicious code into checkout pages on Magento-based e-commerce sites by abusing the Google Tag Manager ad tool.
www.darkreading.com
February 10, 2025 at 3:28 PM
A massive brute force attack is using 2.8 million IPs to target VPN devices, putting credentials at risk. 🌐🔓

#cybersecurity #vpnsecurity #bruteforceattack #infosec #botnet #security
Massive brute force attack uses 2.8 million IPs to target VPN devices
A large-scale brute force password attack using almost 2.8 million IP addresses is underway, attempting to guess the credentials for a wide range of networking devices, including those from Palo Alto ...
www.bleepingcomputer.com
February 9, 2025 at 12:11 PM
SparkCat stealer found in App Store & Google Play, sneaking after crypto wallets 🕵️‍♂️📱

#cybersecurity #malware #sparkcat #cryptosecurity #appstore #googleplay #security #netset #cti
SparkCat crypto stealer in Google Play and App Store
Kaspersky experts discover iOS and Android apps infected with the SparkCat crypto stealer in Google Play and the App Store. It steals crypto wallet data using an OCR model.
securelist.com
February 5, 2025 at 8:26 AM
🚨New article by Krebs on Security🚨

Brian Krebs uncovers the operators behind seized cybercrime forums 'Cracked' and 'Nulled'. Allegedly linked to '1337 Services GmbH' and e-commerce platforms, these forums trafficked in stolen data and hacking tools. #cybersecurity #cti #hacking #osint #crime
Who’s Behind the Seized Forums ‘Cracked’ & ‘Nulled’?
The FBI joined authorities across Europe last week in seizing domain names for Cracked and Nulled, English-language cybercrime forums with millions of users that trafficked in stolen data, hacking too...
krebsonsecurity.com
February 4, 2025 at 8:51 PM
Now, this is some awesome research - and it sure gives some great ideas for future (cool) side projects 😍😈

#cyber #netsec #reverseengineering #cybersecurity #malware
ScatterBrain: Unmasking the Shadow of PoisonPlug's Obfuscator | Google Cloud Blog
We been tracking multiple espionage operations conducted by China-nexus actors utilizing POISONPLUG.SHADOW malware.
cloud.google.com
February 3, 2025 at 1:01 PM