retroericg.bsky.social
@retroericg.bsky.social
All things Cyber Security!
Reposted
ShinyHunters Launches Data Leak Site: Trinity of Chaos Announces New Ransomware Victims
ShinyHunters Launches Data Leak Site: Trinity of Chaos Announces New Ransomware Victims
Trinity of Chaos, tied to Lapsus$, Scattered Spider & ShinyHunters, hit 39 firms via Salesforce flaws, launching a TOR data leak site.
securityaffairs.com
October 3, 2025 at 11:24 PM
Reposted
More than 90 state, local governments targeted using Microsoft SharePoint vulnerability, group says reut.rs/41kCV0l
More than 90 state, local governments targeted using Microsoft SharePoint vulnerability, group says
More than 90 state and local governments have been targeted using the recently revealed vulnerability in Microsoft server software, according to a U.S. group devoted to helping local authorities collaborate against hacking threats.
reut.rs
July 30, 2025 at 8:10 PM
Reposted
Week in review: Botnet hits M365 accounts, PoC for Ivanti Endpoint Manager vulnerabilities released
Week in review: Botnet hits M365 accounts, PoC for Ivanti Endpoint Manager vulnerabilities released - Help Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Massive botnet hits Microsoft 365 accounts A recently
www.helpnetsecurity.com
March 2, 2025 at 1:50 PM
Reposted
Will the Real Msiexec Please Stand Up? Exploit Leads to Data Exfiltration

➡️Initial Access: CVE-2021-44077 exploited
➡️Execution: Web shell
➡️Credential Access: WDigest + MiniDump
➡️Lat Movement: RDP using Plink
➡️Exfiltration: Sensitive data exfilled

thedfirreport.com/2022/06/06/w...
Will the Real Msiexec Please Stand Up? Exploit Leads to Data Exfiltration
In this multi-day intrusion, we observed a threat actor gain initial access to an organization by exploiting a vulnerability in ManageEngine SupportCenter Plus. The threat actor, discovered files o…
thedfirreport.com
February 5, 2025 at 5:23 PM
Reposted
"Mastering Sysmon: Deploying, Configuring, and Fine-Tuning"
A free mini eBook for #DFIR professionals with practical steps to deploy, fine-tune, and start logging with Sysmon.

dfirinsights.com/2024/11/27/m...

#infosec #blueteam
Mastering Sysmon free DFIR e-book release - DFIR Insights
Today is the day! I'm announcing the release of my guide: "Mastering Sysmon: Deploying, Configuring, and Fine-Tuning", a free mini eBook designed specifically for digital forensics and incident respon...
dfirinsights.com
December 16, 2024 at 11:18 AM
Reposted
Hackers compromise senior leadership email accounts of Microsoft via forgotten account
Hackers compromise senior leadership email accounts of Microsoft via forgotten account
Microsoft's corporate email system was breached by the Midnight Blizzard hacking group, through compromising a forgotten test account that lacked 2FA/MFA. The compromise led to a month-long unauthorized access to and theft of emails from leadership and cybersecurity teams.
beyondmachines.net
January 20, 2024 at 9:50 PM
Reposted
Number of hacked Cisco IOS XE devices plummets from 50K to hundreds
Number of hacked Cisco IOS XE devices plummets from 50K to hundreds
The number of Cisco IOS XE devices hacked with a malicious backdoor implant has mysteriously plummeted from over 50,000 impacted devices to only a few hundred, with researchers unsure what is causing the sharp decline.
www.bleepingcomputer.com
October 22, 2023 at 5:48 PM