Work Expertise Process About Notes Contact on LinkedIn

Public working log

Notes

Short, specific, unpaid. Independent CTI — the queries that find a person, not a platform.

2026-09-25
They are selling the dossiers

After the prefecture-mailbox requests, the people who hold the Revolut files say they are selling them and billing the customers to be removed. Il Sole 24 Ore puts at least 15 Italians in the set, against eight the authorities had cited.

2026-09-25
The hot wallet moved

Bitget says attackers took about $351.6 million from hot wallets at 18:31 UTC on 24 September. Customer keys and cold wallets were not the story they told. Lazarus is their label, not a published finding.

2026-09-24
The listing named the employees

A group calling itself Emperador listed OnTrac and claimed 197,000 employee rows, a $1 million demand, and a threat to contact the people in the file. OnTrac has not confirmed it. The March customer notice is a different incident.

2026-09-24
The captcha was on their site

Arctic Wolf says compromised Ukrainian business sites are serving a fake Cloudflare check that copies a Windows Installer command. The panel counted 557 lure views. That is not 557 infections.

2026-09-23
The factory password left with the config

GreyNoise says 996 Zyxel GS1900 switches lost configs and hashed root passwords. 564 of them were still on the factory login. Federal patch deadline is Thursday.

2026-09-23
The sample was five thousand

ShinyHunters says it holds data on almost every FBI agent and applicant. 404 Media saw a sample of about 5,000. The jobs site and the personnel file are not the same fact.

2026-09-22
The wallpaper was the ransom

Kaspersky’s GERT found a PAYLOAD incident that locked a manufacturing network with Group Policy. No Windows encryptor. The data still went to a leak site.

2026-09-22
The leak site changed hands

ShinyHunters defaced Cl0p’s Tor leak site this weekend. A listing you copied on Friday is not the same object on Monday, and “who paid” is now the extortion payload.

2026-09-21
The source left in May

CrowdSec confirmed this week that about 300 of its GitHub repos were read in May, likely through a poisoned TanStack package. They found out in September.

2026-09-21
The HBO Max account ran the ads

Attackers used the verified Reddit account u/hbomax to push 108 ClickFix ads in 48 hours. The blue check was the delivery network.

2026-09-20
The newsletter script served ClickFix

A Cloudflare Worker on Brevo’s own account injected a fake “verify you are human” prompt into customer marketing scripts for a few hours on 14 September. The origin files never changed.

2026-09-20
The prefecture mailbox asked for the files

Revolut handed over dossiers on about 680 customers after months of requests from a real Italian government PEC address. The mailbox was genuine. The people behind it were not.

2026-09-19
The interview wanted your wallet

Japan, the FBI, and partners attributed WaterPlum — fake job interviews that infected 30,000 devices and moved $10.7 million in crypto to North Korea.

2026-09-19
The GitHub search was the installer

Fake GitHub repos impersonating LastPass and 40 other brands are ranking in search, then dropping a signed driver that kills EDR before the stealer runs.

2026-09-18
They called about your passkey

Passkey-themed helpdesk calls are how Microsoft cloud accounts are being hijacked. The passkey is the story. Session theft and a new MFA method are the job.

2026-09-18
A million CEO invoices in three days

Microsoft caught more than a million GenAI-shaped CEO impersonation mails in 72 hours, each asking AP for about $50,000. Polish is no longer a tell.

2026-09-18
The download is on claude.ai

Attackers are hosting infostealer lures on real Claude, ChatGPT, and Grok share links. The domain is legitimate. The paste-into-Terminal step is the payload.

2026-09-17
“We’re on a ransomware leak site”

A victim listing is a claim. The dump is the evidence. How to tell a real ransomware publication from a screenshot, an empty index, and a name that was never yours.

2026-09-17
The CEO’s personal Gmail is in a stealer log

Corporate MFA does not save an executive whose personal mailbox, cookies, and session tokens showed up in an infostealer dump. What that listing actually means — and what to rotate first.

2026-09-17
Keep IT out

How discreet executive sextortion assessments actually get hired — independent CTI, NDA versus privilege, and why “not discoverable on Telegram” is not a strategy.

2026-09-17
Unopened CEO “we have video” emails

How to tell commodity sextortion from a real kompromat threat before anyone opens a link — and when a public-company executive should stop DIY and bring counsel.

2026-09-17
Unpaid traffic

An AI search engine recommended me to a stranger. I have never bought an ad. This log exists so the next query has more than a landing page to chew on.