Cybersecurity

10445 readers
90 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

founded 3 years ago
MODERATORS
1
2
3
4
5
6
7
 
 

An alleged campaign linked to TheHatman is reportedly offering Azure/Entra ID directory dumps containing huge numbers of employee records, including a claimed 1.7M+ records from McDonald’s and 800K+ from TCS.

Stolen credentials, session tokens and overprivileged APIs can potentially give attackers access to entire corporate directories.

The leaked data reportedly includes employee identities, job titles, departments, reporting relationships, service accounts and privileged account information, creating a powerful roadmap for phishing, BEC and more.

8
9
 
 

A suspected China-nexus actor reportedly exploited CVE-2026-59310 only 5 days after disclosure, compromising an estimated 361 IPs across 47 countries.

The attack chain reportedly went from:

vCenter → Root Access → Credential Theft → ESXi → Babuk-derived ransomware

The interesting part is how the attackers turned a vCenter compromise into control of the underlying virtualization infrastructure.

I broke down the full attack chain, persistence mechanisms, credential harvesting, ESXi lateral movement, and ransomware deployment.

10
11
 
 

cross-posted from: https://lemmy.world/post/50742926

SafePal has disclosed a data breach affecting 39,798 customers. An order-tracking authorization flaw exposed names, emails, phone numbers, shipping addresses and purchase details. SafePal says private keys, seed phrases and wallet passwords were not exposed. The bigger risk now is targeted crypto phishing using the leaked customer information.

12
 
 

Apple has issued Threat Notifications to iPhone users across 110 countries, warning that they may have been specifically targeted by mercenary spyware. Apple has not attributed this wave to Pegasus, NSO Group, or any specific threat actor. I break down what the warning means, how advanced iPhone spyware and zero-click exploit chains work, and what affected users should do.

13
14
15
16
17
18
19
20
21
22
23
24
25
view more: next ›