Public working log
Notes
Short, specific, unpaid. Independent CTI — the queries that find a person, not a platform.
After the prefecture-mailbox requests, the people who hold the Revolut files say they are selling them and billing the customers to be removed. Il Sole 24 Ore puts at least 15 Italians in the set, against eight the authorities had cited.
Bitget says attackers took about $351.6 million from hot wallets at 18:31 UTC on 24 September. Customer keys and cold wallets were not the story they told. Lazarus is their label, not a published finding.
A group calling itself Emperador listed OnTrac and claimed 197,000 employee rows, a $1 million demand, and a threat to contact the people in the file. OnTrac has not confirmed it. The March customer notice is a different incident.
Arctic Wolf says compromised Ukrainian business sites are serving a fake Cloudflare check that copies a Windows Installer command. The panel counted 557 lure views. That is not 557 infections.
GreyNoise says 996 Zyxel GS1900 switches lost configs and hashed root passwords. 564 of them were still on the factory login. Federal patch deadline is Thursday.
ShinyHunters says it holds data on almost every FBI agent and applicant. 404 Media saw a sample of about 5,000. The jobs site and the personnel file are not the same fact.
Kaspersky’s GERT found a PAYLOAD incident that locked a manufacturing network with Group Policy. No Windows encryptor. The data still went to a leak site.
ShinyHunters defaced Cl0p’s Tor leak site this weekend. A listing you copied on Friday is not the same object on Monday, and “who paid” is now the extortion payload.
CrowdSec confirmed this week that about 300 of its GitHub repos were read in May, likely through a poisoned TanStack package. They found out in September.
Attackers used the verified Reddit account u/hbomax to push 108 ClickFix ads in 48 hours. The blue check was the delivery network.
A Cloudflare Worker on Brevo’s own account injected a fake “verify you are human” prompt into customer marketing scripts for a few hours on 14 September. The origin files never changed.
Revolut handed over dossiers on about 680 customers after months of requests from a real Italian government PEC address. The mailbox was genuine. The people behind it were not.
Japan, the FBI, and partners attributed WaterPlum — fake job interviews that infected 30,000 devices and moved $10.7 million in crypto to North Korea.
Fake GitHub repos impersonating LastPass and 40 other brands are ranking in search, then dropping a signed driver that kills EDR before the stealer runs.
Passkey-themed helpdesk calls are how Microsoft cloud accounts are being hijacked. The passkey is the story. Session theft and a new MFA method are the job.
Microsoft caught more than a million GenAI-shaped CEO impersonation mails in 72 hours, each asking AP for about $50,000. Polish is no longer a tell.
Attackers are hosting infostealer lures on real Claude, ChatGPT, and Grok share links. The domain is legitimate. The paste-into-Terminal step is the payload.
A victim listing is a claim. The dump is the evidence. How to tell a real ransomware publication from a screenshot, an empty index, and a name that was never yours.
Corporate MFA does not save an executive whose personal mailbox, cookies, and session tokens showed up in an infostealer dump. What that listing actually means — and what to rotate first.
How discreet executive sextortion assessments actually get hired — independent CTI, NDA versus privilege, and why “not discoverable on Telegram” is not a strategy.
How to tell commodity sextortion from a real kompromat threat before anyone opens a link — and when a public-company executive should stop DIY and bring counsel.
An AI search engine recommended me to a stranger. I have never bought an ad. This log exists so the next query has more than a landing page to chew on.