GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 02-Oct-2025 18:40:36 JST Kevin Beaumont Kevin Beaumont

    Crimson Collective are trying to extort Redhat

    They've stolen about 500gb of data related to corporate customers. File list:

    https://archive.ph/0MwqJ

    #threatintel

    In conversation about a year ago from cyberplace.social permalink
    • Embed this notice
      Greem (Graeme. Not Graham!) (greem@cyberplace.social)'s status on Thursday, 02-Oct-2025 18:48:56 JST Greem (Graeme. Not Graham!) Greem (Graeme. Not Graham!)
      in reply to

      @GossiTheDog This has Big Oof written all over it.

      It could get very messy very quickly.

      In conversation about a year ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 03-Oct-2025 02:06:33 JST Kevin Beaumont Kevin Beaumont
      in reply to
      • BrianKrebs
      • :mastodon: decio

      @briankrebs @decio also posts by “antonio howell”, name of a British actor. Crimson Collective’s first victim is Claro - a telco which was one of the first victims of.. drumroll.. LAPSUS$

      In conversation about a year ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/115/305/662/303/821/781/original/90fb094149981eb7.png
    • Embed this notice
      BrianKrebs (briankrebs@infosec.exchange)'s status on Friday, 03-Oct-2025 02:06:34 JST BrianKrebs BrianKrebs
      in reply to
      • :mastodon: decio

      @decio @GossiTheDog I haven't seen anyone else mention this, but the posts from the Crimson Collective were signed "Miku", which is a nickname used by Thalha Jubair, the 19 y/o in the UK I wrote about last week who was charged in a ton of Scattered Spider ransom activity https://krebsonsecurity.com/2025/09/feds-tie-scattered-spider-duo-to-115m-in-ransoms/

      In conversation about a year ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: krebsonsecurity.com
        Feds Tie ‘Scattered Spider’ Duo to $115M in Ransoms
        U.S. prosecutors last week levied criminal hacking charges against 19-year-old U.K. national Thalha Jubair for allegedly being a core member of Scattered Spider, a prolific cybercrime group blamed for extorting at least $115 million in ransom payments from victims. The…
    • Embed this notice
      :mastodon: decio (decio@infosec.exchange)'s status on Friday, 03-Oct-2025 02:06:35 JST :mastodon: decio :mastodon: decio
      in reply to

      @GossiTheDog 👍 thx

      the 2nd proof link https://archive.ph/WqCdu

      In conversation about a year ago permalink

      Attachments


      1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/304/585/216/294/012/original/43df970a0f6a261a.png

    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 03-Oct-2025 06:56:40 JST Kevin Beaumont Kevin Beaumont
      in reply to

      It’s not 570gb that was stolen btw, there’s group said they were still compressing at that point - they claim it was about half way. Also, it’s compressed so uncompressed.. it’s a lot more either way.

      In conversation about a year ago permalink
    • Embed this notice
      apth (apth@infosec.exchange)'s status on Friday, 03-Oct-2025 07:24:32 JST apth apth
      in reply to

      @GossiTheDog thank you VERY much for continuing to post this stuff. Definitely making my life better. If there's a way I can support you, let me know

      In conversation about a year ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 03-Oct-2025 19:41:35 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Redhat statement:

      https://www.redhat.com/en/blog/security-update-incident-related-red-hat-consulting-gitlab-instance

      In conversation about a year ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: www.redhat.com
        Security update: Incident related to Red Hat Consulting GitLab instance
        We are writing to provide an update regarding a security incident related to a specific GitLab environment used by our Red Hat Consulting team. Red Hat takes the security and integrity of our systems and the data entrusted to us extremely seriously, and we are addressing this issue with the highest priority.
    • Embed this notice
      #/usr/sbin/rtheren (rtheren@social.linux.pizza)'s status on Friday, 03-Oct-2025 19:57:07 JST #/usr/sbin/rtheren #/usr/sbin/rtheren
      in reply to

      @GossiTheDog So it's just a GitLab instance that was breached? Ok...could've been much worse.

      In conversation about a year ago permalink
    • Embed this notice
      kjpax (kjpax@cyberplace.social)'s status on Friday, 03-Oct-2025 22:45:34 JST kjpax kjpax
      in reply to

      @GossiTheDog Always makes me laugh when they say, "We have now implemented additional hardening measures"

      Why not just harden it properly in the first place 😂

      In conversation about a year ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Monday, 06-Oct-2025 06:36:56 JST Kevin Beaumont Kevin Beaumont
      in reply to

      LAPSUS$ have now listed the breach at Redhat on their portal.

      They have posted CER - Consulting Engagement Requests, very sensitive info, for AMEX, Atos, HSBC, Walmart, NHS Scotland amongst others. I have authenticated the data is real.

      In conversation about a year ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/115/323/704/199/156/340/original/b2e6cfea31fcd4b4.png
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Monday, 06-Oct-2025 06:38:47 JST Kevin Beaumont Kevin Beaumont
      in reply to
      • BrianKrebs

      Shout out to @briankrebs btw who noted, correctly, that the nickname being used for Crimson Collective posts was prior linked to a member of LAPSUS$ in the UK (who is supposed to be remanded in custody - the NCA may want to check he doesn't an Amazon Fire stick in his cell.

      https://infosec.exchange/@briankrebs/115305533621595786

      In conversation about a year ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Monday, 06-Oct-2025 06:45:28 JST Kevin Beaumont Kevin Beaumont
      in reply to

      This is the portal post btw, basically the extortion note (not all of it).

      In conversation about a year ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/115/323/738/776/018/612/original/5ed7b002d9888b60.png
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Monday, 06-Oct-2025 07:11:36 JST Kevin Beaumont Kevin Beaumont
      in reply to

      The LAPSUS$ Red Hat dump also has a file tree up - 370,852 directories, 3,438,976 files

      In conversation about a year ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Monday, 06-Oct-2025 20:56:35 JST Kevin Beaumont Kevin Beaumont
      in reply to

      The Red Hat Consulting LAPSUS$ saga continues - in the past hour they've released a 2.2gb ZIP file.

      In conversation about a year ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Monday, 06-Oct-2025 23:28:12 JST Kevin Beaumont Kevin Beaumont
      in reply to

      I think a whole bunch of orgs probably need to start rotating certificates and such. #threatintel

      In conversation about a year ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/115/327/686/479/381/271/original/8b436620865de6f1.png
    • Embed this notice
      0xF21D (0xf21d@infosec.exchange)'s status on Tuesday, 07-Oct-2025 05:02:52 JST 0xF21D 0xF21D
      in reply to

      @GossiTheDog that file tree is now zero length by the way. I tried downloading it multiple times and each time I end up with nothing.

      In conversation about a year ago permalink
    • Embed this notice
      0xF21D (0xf21d@infosec.exchange)'s status on Tuesday, 07-Oct-2025 05:10:39 JST 0xF21D 0xF21D

      @GossiTheDog alright, thanks. I was looking at the txt file becuase it said "tree" at the end.

      In conversation about a year ago permalink
    • Embed this notice
      0xF21D (0xf21d@infosec.exchange)'s status on Wednesday, 08-Oct-2025 00:28:49 JST 0xF21D 0xF21D
      in reply to

      @GossiTheDog did you see all the Ansible playbooks for Apache Guacamole?

      In conversation about a year ago permalink

      Attachments


      1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/333/458/491/059/644/original/a1add85634ac3289.png

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.