<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
  <channel>
    <title>Notes — Fabio Correia</title>
    <link>https://www.fabiocti.com/notes/</link>
    <description>Public working notes on cyber threat intelligence and executive risk.</description>
    <item>
      <title>They are selling the dossiers</title>
      <link>https://www.fabiocti.com/notes/they-are-selling-the-dossiers/</link>
      <guid>https://www.fabiocti.com/notes/they-are-selling-the-dossiers/</guid>
      <pubDate>Fri, 25 Sep 2026 12:00:00 GMT</pubDate>
      <description>After the prefecture-mailbox requests, the people who hold the Revolut files say they are selling them and billing the customers to be removed. Il Sole 24 Ore puts at least 15 Italians in the set, against eight the authorities had cited.</description>
    </item>
    <item>
      <title>The hot wallet moved</title>
      <link>https://www.fabiocti.com/notes/the-hot-wallet-moved/</link>
      <guid>https://www.fabiocti.com/notes/the-hot-wallet-moved/</guid>
      <pubDate>Fri, 25 Sep 2026 12:00:00 GMT</pubDate>
      <description>Bitget says attackers took about $351.6 million from hot wallets at 18:31 UTC on 24 September. Customer keys and cold wallets were not the story they told. Lazarus is their label, not a published finding.</description>
    </item>
    <item>
      <title>The listing named the employees</title>
      <link>https://www.fabiocti.com/notes/the-listing-named-the-employees/</link>
      <guid>https://www.fabiocti.com/notes/the-listing-named-the-employees/</guid>
      <pubDate>Thu, 24 Sep 2026 12:00:00 GMT</pubDate>
      <description>A group calling itself Emperador listed OnTrac and claimed 197,000 employee rows, a $1 million demand, and a threat to contact the people in the file. OnTrac has not confirmed it. The March customer notice is a different incident.</description>
    </item>
    <item>
      <title>The captcha was on their site</title>
      <link>https://www.fabiocti.com/notes/the-captcha-was-on-their-site/</link>
      <guid>https://www.fabiocti.com/notes/the-captcha-was-on-their-site/</guid>
      <pubDate>Thu, 24 Sep 2026 12:00:00 GMT</pubDate>
      <description>Arctic Wolf says compromised Ukrainian business sites are serving a fake Cloudflare check that copies a Windows Installer command. The panel counted 557 lure views. That is not 557 infections.</description>
    </item>
    <item>
      <title>The factory password left with the config</title>
      <link>https://www.fabiocti.com/notes/the-factory-password-left-with-the-config/</link>
      <guid>https://www.fabiocti.com/notes/the-factory-password-left-with-the-config/</guid>
      <pubDate>Wed, 23 Sep 2026 12:00:00 GMT</pubDate>
      <description>GreyNoise says 996 Zyxel GS1900 switches lost configs and hashed root passwords. 564 of them were still on the factory login. Federal patch deadline is Thursday.</description>
    </item>
    <item>
      <title>The sample was five thousand</title>
      <link>https://www.fabiocti.com/notes/the-sample-was-five-thousand/</link>
      <guid>https://www.fabiocti.com/notes/the-sample-was-five-thousand/</guid>
      <pubDate>Wed, 23 Sep 2026 12:00:00 GMT</pubDate>
      <description>ShinyHunters says it holds data on almost every FBI agent and applicant. 404 Media saw a sample of about 5,000. The jobs site and the personnel file are not the same fact.</description>
    </item>
    <item>
      <title>The wallpaper was the ransom</title>
      <link>https://www.fabiocti.com/notes/the-wallpaper-was-the-ransom/</link>
      <guid>https://www.fabiocti.com/notes/the-wallpaper-was-the-ransom/</guid>
      <pubDate>Tue, 22 Sep 2026 12:00:00 GMT</pubDate>
      <description>Kaspersky’s GERT found a PAYLOAD incident that locked a manufacturing network with Group Policy. No Windows encryptor. The data still went to a leak site.</description>
    </item>
    <item>
      <title>The leak site changed hands</title>
      <link>https://www.fabiocti.com/notes/the-leak-site-changed-hands/</link>
      <guid>https://www.fabiocti.com/notes/the-leak-site-changed-hands/</guid>
      <pubDate>Tue, 22 Sep 2026 12:00:00 GMT</pubDate>
      <description>ShinyHunters defaced Cl0p’s Tor leak site this weekend. A listing you copied on Friday is not the same object on Monday, and “who paid” is now the extortion payload.</description>
    </item>
    <item>
      <title>The source left in May</title>
      <link>https://www.fabiocti.com/notes/the-source-left-in-may/</link>
      <guid>https://www.fabiocti.com/notes/the-source-left-in-may/</guid>
      <pubDate>Mon, 21 Sep 2026 12:00:00 GMT</pubDate>
      <description>CrowdSec confirmed this week that about 300 of its GitHub repos were read in May, likely through a poisoned TanStack package. They found out in September.</description>
    </item>
    <item>
      <title>The HBO Max account ran the ads</title>
      <link>https://www.fabiocti.com/notes/the-hbo-max-account-ran-the-ads/</link>
      <guid>https://www.fabiocti.com/notes/the-hbo-max-account-ran-the-ads/</guid>
      <pubDate>Mon, 21 Sep 2026 12:00:00 GMT</pubDate>
      <description>Attackers used the verified Reddit account u/hbomax to push 108 ClickFix ads in 48 hours. The blue check was the delivery network.</description>
    </item>
    <item>
      <title>The newsletter script served ClickFix</title>
      <link>https://www.fabiocti.com/notes/the-newsletter-script-served-clickfix/</link>
      <guid>https://www.fabiocti.com/notes/the-newsletter-script-served-clickfix/</guid>
      <pubDate>Sun, 20 Sep 2026 12:00:00 GMT</pubDate>
      <description>A Cloudflare Worker on Brevo’s own account injected a fake “verify you are human” prompt into customer marketing scripts for a few hours on 14 September. The origin files never changed.</description>
    </item>
    <item>
      <title>The prefecture mailbox asked for the files</title>
      <link>https://www.fabiocti.com/notes/the-prefecture-mailbox-asked-for-the-files/</link>
      <guid>https://www.fabiocti.com/notes/the-prefecture-mailbox-asked-for-the-files/</guid>
      <pubDate>Sun, 20 Sep 2026 12:00:00 GMT</pubDate>
      <description>Revolut handed over dossiers on about 680 customers after months of requests from a real Italian government PEC address. The mailbox was genuine. The people behind it were not.</description>
    </item>
    <item>
      <title>The interview wanted your wallet</title>
      <link>https://www.fabiocti.com/notes/the-interview-wanted-your-wallet/</link>
      <guid>https://www.fabiocti.com/notes/the-interview-wanted-your-wallet/</guid>
      <pubDate>Sat, 19 Sep 2026 12:00:00 GMT</pubDate>
      <description>Japan, the FBI, and partners attributed WaterPlum — fake job interviews that infected 30,000 devices and moved $10.7 million in crypto to North Korea.</description>
    </item>
    <item>
      <title>The GitHub search was the installer</title>
      <link>https://www.fabiocti.com/notes/github-search-was-the-installer/</link>
      <guid>https://www.fabiocti.com/notes/github-search-was-the-installer/</guid>
      <pubDate>Sat, 19 Sep 2026 12:00:00 GMT</pubDate>
      <description>Fake GitHub repos impersonating LastPass and 40 other brands are ranking in search, then dropping a signed driver that kills EDR before the stealer runs.</description>
    </item>
    <item>
      <title>They called about your passkey</title>
      <link>https://www.fabiocti.com/notes/they-called-about-your-passkey/</link>
      <guid>https://www.fabiocti.com/notes/they-called-about-your-passkey/</guid>
      <pubDate>Fri, 18 Sep 2026 12:00:00 GMT</pubDate>
      <description>Passkey-themed helpdesk calls are how Microsoft cloud accounts are being hijacked. The passkey is the story. Session theft and a new MFA method are the job.</description>
    </item>
    <item>
      <title>A million CEO invoices in three days</title>
      <link>https://www.fabiocti.com/notes/million-ceo-invoices/</link>
      <guid>https://www.fabiocti.com/notes/million-ceo-invoices/</guid>
      <pubDate>Fri, 18 Sep 2026 12:00:00 GMT</pubDate>
      <description>Microsoft caught more than a million GenAI-shaped CEO impersonation mails in 72 hours, each asking AP for about $50,000. Polish is no longer a tell.</description>
    </item>
    <item>
      <title>The download is on claude.ai</title>
      <link>https://www.fabiocti.com/notes/download-is-on-claude-ai/</link>
      <guid>https://www.fabiocti.com/notes/download-is-on-claude-ai/</guid>
      <pubDate>Fri, 18 Sep 2026 12:00:00 GMT</pubDate>
      <description>Attackers are hosting infostealer lures on real Claude, ChatGPT, and Grok share links. The domain is legitimate. The paste-into-Terminal step is the payload.</description>
    </item>
    <item>
      <title>“We’re on a ransomware leak site”</title>
      <link>https://www.fabiocti.com/notes/ransomware-leak-site-listing/</link>
      <guid>https://www.fabiocti.com/notes/ransomware-leak-site-listing/</guid>
      <pubDate>Thu, 17 Sep 2026 12:00:00 GMT</pubDate>
      <description>A victim listing is a claim. The dump is the evidence. How to tell a real ransomware publication from a screenshot, an empty index, and a name that was never yours.</description>
    </item>
    <item>
      <title>The CEO’s personal Gmail is in a stealer log</title>
      <link>https://www.fabiocti.com/notes/ceo-gmail-stealer-log/</link>
      <guid>https://www.fabiocti.com/notes/ceo-gmail-stealer-log/</guid>
      <pubDate>Thu, 17 Sep 2026 12:00:00 GMT</pubDate>
      <description>Corporate MFA does not save an executive whose personal mailbox, cookies, and session tokens showed up in an infostealer dump. What that listing actually means — and what to rotate first.</description>
    </item>
    <item>
      <title>Keep IT out</title>
      <link>https://www.fabiocti.com/notes/independent-cti-counsel-not-it/</link>
      <guid>https://www.fabiocti.com/notes/independent-cti-counsel-not-it/</guid>
      <pubDate>Thu, 17 Sep 2026 12:00:00 GMT</pubDate>
      <description>How discreet executive sextortion assessments actually get hired — independent CTI, NDA versus privilege, and why “not discoverable on Telegram” is not a strategy.</description>
    </item>
    <item>
      <title>Unopened CEO “we have video” emails</title>
      <link>https://www.fabiocti.com/notes/unopened-ceo-video-emails/</link>
      <guid>https://www.fabiocti.com/notes/unopened-ceo-video-emails/</guid>
      <pubDate>Thu, 17 Sep 2026 12:00:00 GMT</pubDate>
      <description>How to tell commodity sextortion from a real kompromat threat before anyone opens a link — and when a public-company executive should stop DIY and bring counsel.</description>
    </item>
    <item>
      <title>Unpaid traffic</title>
      <link>https://www.fabiocti.com/notes/unpaid-traffic/</link>
      <guid>https://www.fabiocti.com/notes/unpaid-traffic/</guid>
      <pubDate>Thu, 17 Sep 2026 12:00:00 GMT</pubDate>
      <description>An AI search engine recommended me to a stranger. I have never bought an ad. This log exists so the next query has more than a landing page to chew on.</description>
    </item>
  </channel>
</rss>
